Signature hiding identifier privacy

By filling and encrypting the Subscription Hidden Identifier (SUCI) in 5G wireless communication networks, the problem of user privacy information leakage is solved, and more efficient user privacy protection is achieved.

CN114651461BActive Publication Date: 2026-05-01TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Filing Date
2020-10-29
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

In 5G wireless communication networks, the mechanism for calculating Subscription Hidden Identifier (SUCI) poses a security risk, leading to the leakage of user privacy information. Attackers can identify users through the length or content of the SUCI.

Method used

By inserting a padding bit string into the Subscribed Permanent Identifier (SUPI) and encrypting it, a Padding Identifier (SUCI) is generated to reduce the correlation between the SUPI length and the SUCI length, thereby reducing information leakage.

Benefits of technology

It significantly reduces the difficulty for attackers to track or identify users through SUCI, improves user privacy protection, and reduces the risk of information leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114651461B_ABST
    Figure CN114651461B_ABST
Patent Text Reader

Abstract

A user equipment (“UE”) in a wireless communication network can generate a padded identifier by inserting a string of padding bits in a field of an identifier associated with the UE. The UE can further encrypt the padded identifier to generate a hidden padded identifier. The UE can further transmit the hidden padded identifier to a network node operating in the wireless communication network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure generally relates to communications, and more specifically, to the protection of operations of a Subscribed Hidden Identifier (SUCI) transmitted over the air in a wireless communication network. Background Technology

[0002] The fifth-generation (“5G”) wireless communication network is the next generation of mobile networks developed by a standards development organization known as the Third Generation Partnership Project (“3GPP”). Earlier generations of mobile networks were known as fourth-generation (“4G”) / Long Term Evolution (“LTE”), third-generation (“3G”) / Universal Mobile Telecommunications Service (“UMTS”), and second-generation (“2G”) / Global System for Mobile Communications (“GSM”).

[0003] 5G networks are maintained and services are provided by mobile network operators (“MNOs”). MNOs can be distinguished from each other by two types of codes: Mobile Country Code (“MCC”) and Mobile Network Code (“MNC”). “Domain” can also distinguish MNOs. To use a specific 5G network provided by a specific MNO, a user is required to establish a contractual relationship with that MNO. This relationship can be referred to as a contract. In cases where a user is not contracted with a specific MNO (e.g., in a so-called roaming scenario), this relationship can be established through a roaming agreement between the MNO to which the user is contracted (e.g., the user’s home network (“HN”)) and the MNO to which the user is being served (e.g., the serving network (“SN”)). The term network can be used to refer to either HN or SN. SN can also be referred to as a visited network or a roaming network.

[0004] In a 5G network, each subscription in an MNO can be identified by a unique long-term identifier called a Subscription Permanent Identifier (“SUPI”). Users can access the 5G network wirelessly over the air using a wireless device or user equipment (“UE”). Before providing any service, the 5G network may need to identify the user (e.g., identify the subscription of the user behind the UE). For this identification purpose, UEs in earlier generations of mobile networks (e.g., 4G, 3G, and 2G) used to transmit the user's unique long-term identifier over the air. This was considered a privacy concern because users could be tracked or identified by any unauthorized entity capable of intercepting messages over the air or acting as a man-in-the-middle. However, in a 5G network, each MNO has the ability to provide better privacy to its users by making their unique long-term identifier (e.g., the user's SUPI) invisible over the air. This capability comes from a mechanism in which the UE does not transmit the SUPI but instead calculates a hidden identifier and transmits it over the air, which may be called a Subscription Hidden Identifier (“SUCI”). The MNO makes all the information required for the calculation of the SUCI (marked as encrypted parameters) available to the UE. Summary of the Invention

[0005] According to some embodiments, a method for operating a wireless device / user equipment (“UE”) in a wireless communication network is provided. The method may include generating a padding identifier by inserting a padding bit string into a field of an identifier associated with the UE. The method may also include encrypting the padding identifier to generate a hidden padding identifier. The method may further include sending the hidden padding identifier to a network node operating in the wireless communication network.

[0006] According to other embodiments, a method for operating a network node in a wireless communication network is provided. The method may include determining a padding technique that can be used by a UE in the wireless communication network to insert a padding bit string into a field of an identifier before the UE encrypts an identifier associated with the UE. The method may also include receiving a hidden padding identifier from the UE. The method may further include decrypting the hidden padding identifier to generate a padding identifier. The method may further include determining the content of an identifier separate from the padding bit string based on the padding technique.

[0007] According to other embodiments, a network node, user equipment, computer program and / or computer program product is provided for performing one or more of the methods described above, wherein the network node is a radio network node or a core network node.

[0008] The various embodiments described herein can reduce the correlation between the SUPI length and the SUCI length. Padding the SUPI before encryption prevents the identification of sensitive information based on the length of the SUCI. This can significantly reduce the leakage of information about users from the SUCI, making it more difficult for attackers to track or identify users. Attached Figure Description

[0009] The accompanying drawings, included to provide a further understanding of this disclosure and incorporated in and forming part of this application, illustrate certain non-limiting embodiments of the inventive concept. In the drawings:

[0010] Figure 1 This is a signal flow graph of an example of user equipment (“UE”) (also referred to herein as a wireless device) registering using a subscription hidden identifier (“SUCI”) according to some embodiments of this disclosure;

[0011] Figure 2 This is a block diagram illustrating an example of encryption at a UE based on an elliptic curve integrated encryption scheme (“ECIES”) according to some embodiments of the present disclosure;

[0012] Figure 3 This is a signal flow diagram illustrating an example of UE-Serving Network (“SN”) encryption of SUCI according to some embodiments of this disclosure;

[0013] Figure 4 This is a block diagram illustrating an example of a UE according to some embodiments of the present disclosure;

[0014] Figure 5 This is a block diagram illustrating examples of radio access network (“RAN”) nodes (e.g., base station eNB / gNB) according to some embodiments of the present disclosure;

[0015] Figure 6 This is a block diagram illustrating examples of core network (“CN”) nodes (e.g., AMF nodes, SMF nodes, OAM nodes, etc.) according to some embodiments of the present disclosure;

[0016] Figures 7 to 9 This is a flowchart illustrating an example of an operation performed by a UE to populate the UE's identifier according to some embodiments of this disclosure;

[0017] Figures 10 to 15 This is a flowchart illustrating an example of an operation performed by a network node to receive a padding identifier from a UE according to some embodiments of this disclosure;

[0018] Figure 16 This is a block diagram of a wireless network according to some embodiments;

[0019] Figure 17 This is a block diagram of a user equipment according to some embodiments;

[0020] Figure 18 This is a block diagram of a virtualized environment according to some embodiments;

[0021] Figure 19 This is a block diagram of a telecommunications network connected to a host computer via an intermediate network, according to some embodiments;

[0022] Figure 20 This is a block diagram illustrating communication between a host computer and a user equipment via a base station through a partial wireless connection, according to some embodiments.

[0023] Figure 21 It is a block diagram of a method implemented in a communication system including a host computer, a base station and a user equipment according to some embodiments;

[0024] Figure 22 It is a block diagram of a method implemented in a communication system including a host computer, a base station and a user equipment according to some embodiments;

[0025] Figure 23 This is a block diagram of a method implemented in a communication system including a host computer, a base station, and a user equipment, according to some embodiments; and

[0026] Figure 24This is a block diagram of a method implemented in a communication system including a host computer, a base station, and a user equipment, according to some embodiments. Detailed Implementation

[0027] The inventive concept will now be described more fully below with reference to the accompanying drawings, in which examples of embodiments illustrating the inventive concept are shown. However, the inventive concept can be implemented in many different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be exhaustive and complete, and will fully convey the scope of the inventive concept to those skilled in the art. It should also be noted that these embodiments are not mutually exclusive. Components from one embodiment may be assumed by default to be presented / used in another embodiment.

[0028] The computation of SUCI can refer to the UE encrypting SUPI, which can be performed before the SUCI is transmitted over the air between the UE and the 5G network. Encryption can be asymmetric and can use the public key of HN (denoted as the HN public key). HN makes the HN public key available to the UE. Various ways exist to asymmetrically encrypt SUPI for SUCI computation; these are denoted as encryption schemes. Some examples of encryption schemes include the ElGamal encryption scheme, Elliptic Curve Integration Encryption Scheme (“ECIES”), and Rivest-Shamir-Adleman (“RSA”) encryption, as well as various quantum-resistant schemes. Multiple variations of the same scheme can also exist; for example, different elliptic curves can be used with the ECIES scheme, such as secp256r1, secp384r1, and curve25519. There also exists a special encryption scheme known as the “null-scheme.” This null-scheme does not perform any actual encryption but produces the same output as the input. This actually means that the SUCI computed using the "empty scheme" will include the information in the SUPI in plaintext. The HN public key and the encryption scheme are two examples of encryption parameters. Other examples are, for example, the length of the intermediate key, field lengths (e.g., the Message Authentication Code ("MAC") field), and cryptographic primitives (e.g., which hash function). The term "field" can be used to refer to all types of information elements included in the SUPI and SUCI.

[0029] Figure 1 This is a high-level sequence diagram illustrating an example message flow including a SUCI. In operation 110, UE 102 connects over the air to 5G radio base station (“gNB”) 104 and sends a registration request message including a SUCI calculated by UE 102. gNB 104 may be part of a 5G radio access network (“RAN”). In operation 120, gNB 104 forwards the received registration request message to a core network (“CN”) node. Figure 1 The core network nodes are interchangeably represented as the Access and Mobility Management Function (“AMF”) or the Security Anchoring Function (“SEAF”). gNB 104 and AMF / SEAF 106 can be jointly identified as the Serving Network (“SN”). SEAF further identifies the Authentication Server Function (“AUSF”) 108. Then, in operation 130, SEAF 106 creates a 5G Authentication Information Request (“AIR”) and sends it to AUSF 108, which may include the received SUCI among other information. Then, in operation 140, AUSF 108 contacts the Unified Data Management (“UDM”) or Subscription Identifier Dehiding Function (“SIDF”) 109. AUSF 108 and UDM / SIDF 109 can be jointly identified as the Home Network (“HN”).

[0030] In the case of roaming, SN and HN belong to different MNOs; otherwise, SN and HN belong to the same MNO. Registration may include comparisons... Figure 1 The message shown provides more operations. Figure 1 An example of how SUCI travels on a network is shown. Further details can be found in 3GPP TS 33.501 v.16.0.0.

[0031] The above describes wireless access to the 5G core via 3GPP 5G access. Devices can also connect to the 5G core via non-3GPP access, which can be wireless or wired. SUCI protection is currently defined only for 5G; however, if SUCI is defined for other generations of networks (such as future 6G, 4G, 3G, and 2G), the mechanism will be similar.

[0032] Example definitions for SUPI can be found in 3GPP TS 23.003 v.16.0.0. Examples of SUPI and SUCI formats are outlined below; however, these formats may be updated in the future.

[0033] SUPI can include the following parts (shown with "||" as a connection): SUPI type || SUPI value.

[0034] The SUPI value can currently be either an International Mobile Subscriber Identity (“IMSI”) or a Network Specific Identifier (sometimes also referred to as a Network Access Identifier (“NAI”)). Other SUPI types may be defined in the future. In either case, the SUPI value may include a Home Network Identifier and a Subscription Identifier. The Subscription Identifier can be hidden within the SUCI.

[0035] If the SUPI is of type IMSI, the home network identifier may include MCC and MNC, and the contract identifier may be referred to as MSIN. Therefore, an IMSI may include the following parts (separated by ||): MCC||MNC||MSIN.

[0036] If SUPI is a network-specific identifier type, the home network identifier is typically represented by the so-called "realm," and the contract identifier is typically represented by the so-called "username." Therefore, NAI can look like: username@realm.

[0037] SUCI can include the following parts (separated by ||): SUPI type || home network identifier || other parameters || hidden subscription identifier.

[0038] 3GPP TS 33.501 v.16.0.0 specifies that for a SUPI containing an IMSI, the SUCI has the following fields: SUPI type; Home network identifier; Route indicator; Protection scheme identifier; Home network public key identifier; and Scheme output. The SUPI type identifier, as defined in 3GPP TS 23.003 v.16.0.0, is hidden within the SUCI. The Home network identifier is set to the IMSI's MCC and MNC, as specified in 3GPP TS 23.003 v.16.0.0. The Route indicator is specified in 3GPP TS 23.003 v.16.0.0. The Protection scheme identifier is specified in Annex C of 3GPP TS 33.501 v.16.0.0. The home network public key identifier is specified in 3GPP TS 33.501 v.16.0.0 and detailed in TS 23.003 v.16.0.0. The scheme output is specified herein and detailed in 3GPP TS 23.003 v.16.0.0.

[0039] Furthermore, 3GPP TS 33.501 v.16.0.0 specifies that for SUPIs containing network-specific identifiers, SUCIs in NAI format have the following fields: a domain portion and a username portion. The domain portion of the SUCI is set to the domain portion of the SUPI. The username portion of the SUCI is formatted according to 3GPP TS 23.003 v.16.0.0 using the SUPI type, routing indicator, protection scheme identifier, home network public key identifier, and scheme output.

[0040] 3GPP TS 33.501 v.16.0.0 has specified three standardized hiding scheme identifiers: the empty scheme; profile A (based on Elliptic Curve Integrated Cryptography (ECIES) and using Curve25519); and profile B (also based on ECIES and using secp256r1).

[0041] Furthermore, 3GPP TS 33.501 v.16.0.0 has reserved 9 placeholders to identify hiding schemes that will be standardized in the future. In addition, it has reserved 4 placeholders to identify proprietary hiding schemes.

[0042] Figure 2 An example of ECIES-based encryption at the UE is shown, as presented in Figure C.3.2-1 of 3GPP TS 33.501 v.16.0.0. 3GPP TS 33.501 v.16.0.0 specifies the output size from these hiding schemes. For the empty scheme, the output size is equal to the input size. For profile A, the output size is equal to the total size of the 256-bit public key, the 64-bit MAC, and the input size. For profile B, the output size is equal to the total size of the 264-bit public key, the 64-bit MAC, and the input size. For proprietary schemes, the maximum output size is 3000 octets plus the total size of the input. The input sizes mentioned above refer to the size of the username used in the NAI format or the size of the MSIN used in the IMSI format.

[0043] The term UE is used herein without loss of generality. A UE refers to a number of parts or components that collectively enable a user of the UE to access services provided by a network. At a high level, it may include at least a General User Identity Module (“USIM”) and a Mobile Equipment (“ME”). Examples of UEs are provided in […]. Figure 4 and Figure 16 It is shown in the figure and described further below.

[0044] SUCI is designed to hide privacy-sensitive information, such as subscription identifiers (e.g., MSIN or username). However, some mechanisms for calculating SUCI (e.g., those standardized by 3GPP, see 3GPP TS 33.501 v.16.0.0) still pose security risks that could lead to the leakage of privacy-sensitive information from the SUCI.

[0045] In some examples, SUCI encrypts only the user-identifying portion of the SUPI, without encrypting any other portions, such as information elements identifying the home network (e.g., MCC, MNC, or domain). This can lead to information leakage regarding the SUPI. Furthermore, different SUPI types can include different information elements. Therefore, how privacy-sensitive these portions or SUPIs are depends on where the SUCI is used. If only a small subset of users at a particular location use a specific information element (e.g., MCC, MNC, or domain), it can help attackers track and / or identify specific users.

[0046] In some examples, SUCI directly or indirectly reveals user-specific information, such as the length of the plaintext (e.g., MSIN or username), the length or content of the public key (e.g., HN can provide a special public key for certain users), a special routing identifier, or a special scheme identifier. New fields that directly or indirectly reveal user-specific information may also be added to SUCI. Therefore, information about SUCI can be leaked. The implications of such disclosure can be minimal or catastrophic, depending on how helpful they are to an attacker. For example, if only a small subset of users at a certain location have plaintext of a specific length (e.g., MSIN or username), it can be used by an attacker to track and / or identify specific users.

[0047] In some examples, the MSIN is fixed at 9 or 10 digits within a single MNC. This means that if the MNC is sent in plaintext, the length of the MSIN does not reveal any new information to a well-informed attacker. If the MNC is encrypted between the UE and the SN, the length of the MSIN reveals information about the MNC. Longer and variable-length IMSIs with new fields may be introduced in the future. For example, the MSIN could have a variable length, such as between 9 and 20 digits. In this case, even after some type of encryption, the length of the MSIN can reveal contract-specific information to an attacker because some symmetric encryption algorithms produce an output of the same length as the input.

[0048] Usernames within a single domain's NAI typically have variable lengths. In one example, a network might be provided with only two users and the following NAIs: NAI1 = thanos@example.com and NAI2 = theodor@example.com. Given SUCI protection using the same protection scheme, the two users' SUCIs will always have different lengths because the usernames have different lengths. Theodor's SUCI will always be one byte longer than Thanos's SUCI. Therefore, an attacker with knowledge of the username distribution will be able to distinguish between Thanos's and Theodor's SUCIs. In practical applications, this distribution can be more complex; however, attackers can use additional information such as location and time of day to identify or track users. Even if an attacker cannot identify a user, they can still correlate different SUCIs from the same user and use it, for example, to sell advertisements.

[0049] The various embodiments described herein enable the UE (in the USIM or in the ME portion of the UE) to calculate the SUCI (or encrypted SUPI) in such a way that fewer fields are transmitted unencrypted and less information about other information elements (e.g., the length of those fields) is leaked. This is achieved by enabling the UE to add padding to the fields to be encrypted (whether in the SUPI or separate from the SUPI) and by enabling the UE to encrypt the additional information elements. Padding can be added according to several different procedures, wherein these procedures are determined by the UE (in the USIM or in the ME portion of the UE), by a human user, or by the network (HN or SN), or by a non-human user in the case of headless IoT devices, or by an automated policy, or by any entity / party belonging to or outside the 3GPP network.

[0050] In some embodiments, the HN and SN (or network functions within the HN / SN) can decrypt portions of the SUCI and recover any missing information elements in the SUPI. In additional or alternative embodiments, the SN (or network functions within the SN) can provide the UE with a key for encrypting some additional information elements. In additional or alternative embodiments, the SN (or network functions within the SN) can decrypt additional fields in the SUCI. In additional or alternative embodiments, the HN (or network functions within the HN) can ensure that the UE calculates the SUCI according to HN operator preferences when encountering padding and encryption of additional fields.

[0051] The various embodiments described herein can significantly reduce the leakage of user information from SUCI. This makes it more difficult for attackers to track or identify users.

[0052] In some embodiments, before encrypting a portion of the SUPI, the UE may pad the information element to be encrypted with zero or more bits of padding. Padding may be added to the end, beginning, or middle of a field. Padding may be added individually to each padding field, or with a single padding covering multiple fields (e.g., a padding for all fields in the SUPI). SUPI and SUCI may also be fields. The padding mechanism may be applied to the field before or after it is encoded into a byte string or bit string, prior to encryption. The padding mechanism may be deterministic, pseudo-randomized, randomized, or a combination thereof. The choice of padding mechanism may be determined, for example, by the UE or HN, and may depend on the type of SUPI, the length of the information element in the SUPI, statistics about the distribution of the SUPI in the HN or other operators, or external factors (such as time of day), or user type.

[0053] The UE may be able to include padding, and the network may be able to remove the padding after decrypting the SUCI. In some embodiments, a delimiter (e.g., bit string 0b0111, the character "@", or byte value 0xFF) is used in the plaintext before encryption to separate the remainder of the padding from the remainder of the plaintext, meaning the delimiter is ultimately encrypted and included in the SUCI. The padding itself can be any bit string, such as a bit string consisting of zeros or a bit string with repeating delimiters. The delimiter can be standardized or dynamically determined / negotiated.

[0054] In additional or alternative embodiments, the UE may select delimiters from a set of delimiters (e.g., randomly from "@", "?", "*"). This set may be standardized or dynamically determined / negotiated.

[0055] In additional or alternative embodiments, the HN knows the exact padding mechanism used by the UE (e.g., always padding 5 bytes, or padding 3 bytes and 5 bytes alternately depending on information such as weekday, location, or weather).

[0056] In an additional or alternative embodiment, the length of the padding (e.g., padding length = 3) is included in the plaintext before encryption, meaning that the length of the padding is ultimately encrypted and included in the SUCI.

[0057] In additional or alternative embodiments, two delimiters may be used to indicate the start and end of the padding. The padding may also have a more complex pattern (e.g., "@#€@#€@#€") that allows HN to separate the padding from the information elements. In this way, the padding may also be embedded within the content of the field being filled.

[0058] In additional or alternative embodiments, the length of the padding is included unencrypted in the SUCI.

[0059] In additional or alternative embodiments, the delimiter is included unencrypted in the SUCI.

[0060] In some embodiments, the SUCI may include multiple paddings, for example, one used between the UE and the SN, and one used between the UE and the HN. The SUCI may also include multiple paddings for different fields within the SUCI. For example, the SUCI may include separate paddings for the MSIN or username, separate paddings for the routing indicator, and separate paddings for the public key.

[0061] Padding techniques may include padding instructions that can be used to pad information elements in a SUPI. Padding instructions can indicate the length of the padding. In some examples, N1 bits can be used to pad information elements in a SUPI; for example, 256 bits can be added to pad the information element. In supplementary or alternative examples, padding can be used to pad information elements in a SUPI where the padding length is randomly, pseudo-randomly, or deterministically selected from an integer interval [N2, N3]. For example, deterministically, it could be a function of weekday, location, and / or weather. In supplementary or alternative examples, padding can be used to pad information elements in a SUPI where the padding length is randomly, pseudo-randomly, or deterministically selected from a statistical distribution. In supplementary or alternative examples, information elements in a SUPI can be padded up to N4 bits. In this example, information elements can be padded until their length becomes a total of 256 bits. In other words, if an information element has a length of 150 bits, an additional 106 bits will be padded to get a total length of 256 bits. In supplementary or alternative examples, information elements in a SUPI can be padded to the next multiple of N5 bits. In additional or alternative examples, the information elements in the SUPI can be padded up to N6 bits, where N6 is selected randomly, pseudo-randomly, or deterministically from a statistical distribution. In additional or alternative examples, the information elements in the SUPI can be padded up to multiples of the next N7 bits, where N7 is selected randomly, pseudo-randomly, or deterministically from a statistical distribution.

[0062] In the examples above, Ni can be an integer. The examples above are not an exhaustive list. Furthermore, padding methods can be combined to obtain more complex padding methods. For example, information elements in SUPI can be padded first to multiples of the next 64 bits, and then supplemented with additional padding, where the length of the additional padding is chosen randomly, pseudo-randomly, or deterministically from a statistical distribution. The padding process can also be chosen probabilistically, for example, using a first padding process with a 60% chance and a second padding process with a 40% chance.

[0063] In addition to the length of the padding, the padding technique can also specify the content of the padding. Those skilled in the art will understand that one or more examples described for the length of the padding will also apply to the selection of the padding content. In some examples, the padding content can use a constant, such as bits of 1 or bits of 0. In supplemental or alternative examples, the padding content can use a constant 8-bit character for all multiples of 8 bits, padding the remainder with bits of 1. For example, if the padding length is 20 bits, the first 8 bits could be the character "A", the second 8 bits could also be the character "A", and the remaining 4 bits could be four bits of 1. In supplemental or alternative examples, the padding content can use random, pseudo-random, or deterministic bits or numbers. In supplemental or alternative examples, the padding content can use the same character or bit string used for the delimiter.

[0064] In addition to the length and content of the padding, padding techniques can also indicate which information elements are being filled. For example, any combination of MSIN, username, routing identifier, public key identifier, and scheme identifier, as well as other existing or new fields, can be filled.

[0065] Below are examples of SUCI with and without padding.

[0066] Assuming IMSI 234150999999999, where MCC = 234, MNC = 15, MSIN = 0999999999, routing indicator 678, and home network public key identifier 27, the NAI format for SUCI conceptually takes the following form.

[0067] No padding for configuration file A protection scheme:

[0068] type0.rid678.schid1.hnkey27.ecckey<ECC ephemeral public key> .cip<encryption of byteencode(0999999999)> .mac<MAC tag value>

[0069] Byte-encode is a function that encodes MSIN into a byte string. The byte-encode function can be, for example, BCD encoding. This is a conceptual example; byte-encode can be another function in the relevant 3GPP standard.

[0070] For configuration file A protection scheme, padding is required:

[0071] type0.rid678.schid1.hnkey27.ecckey<ECC ephemeral public key> .cip<encryption of byte-encode(0999999999)||0xFF||0x00||…||0x00> .mac<MAC tagvalue>

[0072] Here, 0xFF||0x00||…||0x00 is a byte string of length Ni / 8 bytes, where Ni is the padding length in bits (which happens to always be a multiple of 8 in this example). In this particular example, 0xFF is used as a delimiter and is assumed to be a byte value that is not included in any byte string within the range of the byte encoding function. Further, the remaining padding uses the byte 0x00.

[0073] Assuming a network-specific identifier user17@example.com, a routing indicator 678, and a home network public key identifier 27, the NAI format used for SUCI conceptually takes the following form.

[0074] For configuration file protection scheme A:

[0075] type1.rid678.schid1.hnkey27.eckey<ECC ephemeral public key> .cip<encryption of byte-encode(user17)> .mac<MAC tag value> @example.com Here, byte-encode is a function that encodes the username as a byte string. The byte-encode function can be, for example, ASCII encoding with a leading 0 bit. This is a conceptual example; byte-encode can be some other function in the relevant 3GPP standard.

[0076] For configuration file A protection scheme, there is padding:

[0077] type1.rid678.schid1.hnkey27.eckey<ECC ephemeral public key> .cip<encryption of byte-encode(user17@@...@)> .mac<MAC tag value> @example.com

[0078] Here, "@@...@" is a string that adds Ni / 8 bytes to the byte length of byte-encode(user17@@...@), compared to byte-encode(user17), where Ni is the padding length in bits (which happens to always be a multiple of 8 in this example). In this particular example, @ is used as a delimiter and is assumed to be a character not included in any username. Furthermore, the character @ is used in the remaining padding.

[0079] In some embodiments, the UE selects or determines the padding technology. This decision may be based on information it possesses or obtains from elsewhere.

[0080] In additional or alternative embodiments, the HN selects or determines the padding technique. The HN may have more information about username length distribution in its user database (such as HSS or UDM), and therefore, the HN may be able to make a better padding decision than the UE. To enable the HN to determine the padding technique used by the UE, the HN can configure the UE to use a specific padding technique. The padding technique configuration can be pre-configured in the UE (UICC or ME) or can be provided / downloaded at a later time. This later provisioning / downloading can be done using certain signaling protocols such as Radio Resource Control (RRC) or Non-Access Stratum (NAS). The configuration can be that the HN selects from a pre-configured list of padding techniques, or the HN configures a script to calculate the padding length based on a set of input parameters. Examples of input parameters are information about the user's subscription, user preferences, and operator policies.

[0081] In additional or alternative embodiments, the UE user can select the padding technology. This would mean that either a human user or a non-human user can select the padding technology.

[0082] In additional or alternative embodiments, the SN selects a padding technique. The SN can then indicate this selection to the UE and / or HN via signaling using protocols such as Radio Resource Control (“RRC”), Non-Access Stratum (“NAS”), HTTP, some other protocols running on IP, or some other protocols that may be used in a Service-Based Interface (“SBI”).

[0083] In additional or alternative embodiments, a network function, entity, or party, either internal or external to the 3GPP network, selects a padding technique. Examples may include a dedicated network function for an external authentication, authorization, and accounting (“AAA”) server that handles padding, or an existing network function such as a subscription identifier de-hiding function (“SIDF”). The network function, entity, or party can then indicate the selection to the UE and / or SN and / or HN using signaling such as RRC, NAS, HTTP, some other protocol running on IP, or some other protocol that can be used in the SBI.

[0084] In some embodiments, the UE can encrypt information elements included in the SUCI (e.g., domain, MCC, and / or MNC, even MSIN or username, or other information like routing identifiers, public keys, and scheme identifiers) in a manner that makes the SN decryptable. The UE can obtain the encryption key from the SN or from the HN. Protection can be provided using a symmetric key or a public / private key pair. The encryption key can be pre-configured in the UE (UICC or ME) or downloaded at a later time. In additional or alternative embodiments, the encryption key can be distributed via NAS, AS, HTTP, or some other protocol. Where the additional encrypted information element is the domain, MCC, and / or MNC, the SN can use the decrypted information to route messages to the HN.

[0085] In some embodiments, in addition to the padding used in UE-HN encryption, UE-SN encryption may also include padding as described above. UE-SN encryption may be performed in parallel with UE-HN SUPI encryption or after UE-HN SUPI encryption. In the first case, two ciphertexts are sent to the SN. In the second case, the UE-HN ciphertext is included in the plaintext encrypted by the UE-SN. The SN may forward the information it receives from the UE unencrypted, or it may decrypt and construct the SUCI sent to the HN.

[0086] Figure 3 An example is shown where UE-SN encryption is performed after UE-HN SUPI encryption, and then SN is decrypted to construct the SUCI sent to HN.

[0087] At operation 310, UE 302 constructs and / or obtains the SUPI. At operation 320, UE 302 encrypts the SUPI to generate a UE-HN encrypted SUCI. In some embodiments, UE 302 encrypts the SUPI using a key available to HN. At operation 330, UE 302 further encrypts the UE-HN encrypted SUCI to generate a UE-SN encrypted SUCI. In some embodiments, UE 302 further encrypts the UE-HN encrypted SUCI using a key available to SN.

[0088] In some embodiments, the UE-SN encrypted SUCI may include the following portion (shown as a connection using "||"): parameter || ciphertext. The parameter may be a set of unencrypted fields, such as an identifier for the encryption key, an identifier for the encryption algorithm, and inputs to the encryption algorithm (e.g., a random number). The ciphertext may be an encryption of the SUCI using a symmetric or public-key encryption algorithm, such as E(key, SUCI). The encryption algorithm may include integrity protection, and the ciphertext may be longer than the SUCI.

[0089] At operation 340, UE 302 sends the UE-SN encrypted SUCI to SN 304. At operation 350, SN 304 decrypts the UE-SN encrypted SUCI. In some embodiments, SN 304 obtains the decrypted fields including the UE-HN encrypted SUCI. In additional or alternative embodiments, the SN constructs / enriches (e.g., adds some fields to) the UE-HN encrypted SUCI.

[0090] At operation 360, SN 304 sends the UE-HN encrypted SUCI to HN 306. At operation 370, HN 306 decrypts the received UE-HN encrypted SUCI.

[0091] In some embodiments, the padding technique may include a padding instruction that instructs a delimiter to be inserted into a field of the identifier, followed by the insertion of k bytes of padding, wherein k is randomly selected from [0, n] for some positive integer n. When the padding is randomly selected to have a length of 0, only the delimiter is added. Otherwise, the padding is randomly selected to have a non-zero length. In some examples, the delimiter may be considered part of the padding, such that when the delimiter is used, the padding is always at least one bit.

[0092] In some embodiments, when the user / subscription identifier has a variable length, the network (home or serving network) can assign a fixed-length identifier by already adding padding. For example, if there are two users and their usernames are ABC (length 3) and QRST (length 4), the network may have already assigned the fixed-length usernames as ABC0000000 (length 10) and QRST000000 (length 10). This is pre-padding done by the network. This means that when the IMSI and NAI are provided in the UE (USIM, SIM card, or mobile phone), those identifiers have already been padded. Now the UE may not need to perform any additional operations to generate the SUCI on top of what it has already done.

[0093] In some embodiments, the SUCI can be calculated using both the USIM and the mobile phone. When the mobile phone calculates the SUCI, it can request a SUPI from the USIM. In the future, when padding is used, older mobile phones may not know how to pad even if the USIM has been padded. Therefore, when the mobile phone is calculating the SUCI and requesting a SUPI from the USIM, the USIM can return the padded SUPI (padded MSIN or padded username) to the mobile phone. In this way, the mobile phone no longer needs to perform any additional operations on top of what it has already done to generate the SUCI.

[0094] In some embodiments, neither the USIM nor the mobile phone may have yet implemented a new padding technique for the identifier. In that case, the network can periodically update the identifier (e.g., using over-the-air (OTA) updates, remote file management, etc.) so that neither the USIM nor the mobile phone needs to perform any additional steps on top of what it is already doing to generate the SUCI.

[0095] Figure 4 This is a block diagram illustrating elements of a wireless device UE 400 (also referred to as a mobile terminal, mobile communication terminal, wireless communication device, wireless terminal, wireless communication terminal, user equipment UE, user equipment node / terminal / device, etc.) configured to provide wireless communication according to an embodiment of the present invention. (The wireless device 400 may be provided as, for example, as described below regarding...) Figure 16 (As discussed in the wireless device 4110.) As shown in the figure, the wireless device UE may include an antenna 407 (e.g., corresponding to...) Figure 16 Antenna 4111) and transceiver circuitry 601 including transmitter and receiver (also referred to as transceiver, for example, corresponding to Figure 16 The transceiver circuitry (interface 4114) is configured to provide communication with one or more base stations (e.g., corresponding to) a radio access network. Figure 16The network node 4160) provides uplink and downlink radio communication. The wireless device UE may also include processing circuitry 403 (also referred to as a processor, for example, corresponding to...) coupled to the transceiver circuitry. Figure 16 The processing circuit 4120) and the memory circuit 405 (also referred to as memory, for example, corresponding to the processing circuit) coupled to the processing circuit. Figure 16 The device-readable medium 4130. Memory circuitry 405 may include computer-readable program code that, when executed by processing circuitry 403, causes the processing circuitry to perform operations according to embodiments disclosed herein. According to other embodiments, processing circuitry 403 may be defined to include memory so that a separate memory circuitry is not required. The wireless device UE may also include an interface (such as a user interface) coupled to processing circuitry 403, and / or the wireless device UE may be integrated into a vehicle.

[0096] As discussed herein, the operation of the wireless device UE can be performed by processing circuitry 403 and / or transceiver circuitry 401. For example, processing circuitry 403 can control transceiver circuitry 401 to send communications to a radio access network node (also known as a base station) via transceiver circuitry 401 on the radio interface and / or to receive communications from a RAN node via transceiver circuitry 401 on the radio interface. Furthermore, modules can be stored in memory circuitry 405, and these modules can provide instructions such that when the instructions of the modules are executed by processing circuitry 403, processing circuitry 403 performs the corresponding operations.

[0097] Figure 5 This is a block diagram illustrating elements of a radio access network (RAN) node 500 (also referred to as a network node, base station, eNodeB / eNB, gNodeB / gNB, etc.) configured to provide cellular communication, according to an embodiment of the present invention. (RAN node 500 may be provided as, for example, as described below regarding...) Figure 16 (As discussed in the network node 4160.) As shown in the figure, the RAN node may include transceiver circuitry 501 (also referred to as a transceiver, for example, corresponding to...) Figure 16 The interface 4190 (a portion thereof) includes a transmitter and a receiver and is configured to provide uplink and downlink radio communication with the mobile terminal. The RAN node may include network interface circuitry 507 (also referred to as a network interface, for example, corresponding to...). Figure 16 The interface 4190 is configured to provide communication with other nodes in the RAN and / or core network CN (e.g., other base stations). The network node may also include processing circuitry 503 (also referred to as a processor, e.g., corresponding to processing circuitry 4170) coupled to the transceiver circuitry and memory circuitry 505 (also referred to as a memory, e.g., corresponding to...) coupled to the processing circuitry. Figure 16The device-readable medium 4180. The memory circuitry 505 may include computer-readable program code that, when executed by the processing circuitry 503, causes the processing circuitry to perform operations according to embodiments disclosed herein. According to other embodiments, the processing circuitry 503 may be defined to include memory, thereby eliminating the need for separate memory circuitry.

[0098] As discussed herein, the operation of the RAN node can be performed by processing circuitry 503, network interface 507, and / or transceiver 501. For example, processing circuitry 503 can control transceiver 501 to transmit downlink communications to one or more mobile terminal UEs via the radio interface and / or receive uplink communications from one or more mobile terminal UEs via the radio interface. Similarly, processing circuitry 503 can control network interface 507 to transmit communications to one or more other network nodes via the network interface and / or receive communications from one or more other network nodes via the network interface. Moreover, modules can be stored in memory 505, and these modules can provide instructions such that when the instructions of the modules are executed by processing circuitry 503, processing circuitry 503 performs the corresponding operations.

[0099] According to some other embodiments, the network node can be implemented as a core network (CN) node without a transceiver. In this embodiment, transmissions to the wireless device (UE) can be initiated by the network node, such that transmissions to the wireless device are provided via a network node including a transceiver (e.g., via a base station or RAN node). According to embodiments where the network node is an RAN node including a transceiver, initiating a transmission may include sending via the transceiver.

[0100] Figure 6 This is a block diagram illustrating elements of a core network CN node 600 (e.g., an SMF node, an AMF node, etc.) of a communication network configured to provide cellular communication according to an embodiment of the present invention. As shown, the CN node 600 may include network interface circuitry 607 (also referred to as a network interface) configured to provide communication with other nodes in the core network and / or radio access network (RAN). The CN node 600 may also include processing circuitry 603 (also referred to as a processor) coupled to the network interface circuitry and memory circuitry 605 (also referred to as a memory) coupled to the processing circuitry. The memory circuitry 605 may include computer-readable program code that, when executed by the processing circuitry 603, causes the processing circuitry to perform operations according to the embodiments disclosed herein. According to other embodiments, the processing circuitry 603 may be defined to include memory, thereby eliminating the need for a separate memory circuitry.

[0101] As discussed herein, the operation of CN node 600 can be performed by processing circuitry 603 and / or network interface circuitry 607. For example, processing circuitry 603 can control network interface circuitry 607 to send communications to or / or receive communications from one or more other network nodes via network interface circuitry 607. Furthermore, modules can be stored in memory 605, and these modules can provide instructions such that when the instructions of the modules are executed by processing circuitry 603, processing circuitry 603 performs the corresponding operations.

[0102] As discussed herein, the operation of UE 400 can be performed by processing circuitry 403 and / or transceiver 401. For example, processing circuitry 403 can control transceiver 401 to send communications to or receive communications from one or more network nodes via antenna 407. Furthermore, modules can be stored in memory 405, and these modules can provide instructions such that when the instructions of the modules are executed by processing circuitry 403, processing circuitry 403 performs the corresponding operations.

[0103] Some embodiments of the present invention will now be referred to. Figures 7 to 9 Discuss the operation of UE 400. For example, modules (also called cells) can be stored... Figure 4 The modules are stored in memory 405, and these modules can provide instructions such that when the instructions of the modules are executed by processor 403, processor 403 executes... Figures 7 to 9 The corresponding operations in the flowchart.

[0104] Figures 7 to 9 A flowchart illustrating an example of the process for operating a UE 400 in a wireless communication network is provided.

[0105] exist Figure 7 In block 710, processor 403 generates a padding identifier by inserting a padding bit string into a field of an identifier associated with the UE. The padding bit string may include one or more bits. In some embodiments, the identifier may be a Subscription Permanent Identifier (SUPI). The SUPI may include at least one of MSIN, username, routing identifier, public key identifier, and scheme identifier.

[0106] In some embodiments, processor 403 may generate a padding identifier based on padding instructions. Figure 8 In block 810, processor 403 receives a padding instruction from the network node via transceiver 401, and in block 820, processor 403 pads the identifier based on the padding instruction. Figure 9In block 820, processor 403 receives a fill instruction from the user via a user interface, and in block 820, processor 403 fills the identifier based on the fill instruction.

[0107] In some embodiments, generating a padding identifier includes inserting a delimiter before or after the padding bit string. The delimiter may be a pre-defined bit string that separates the padding bit string from the content of the identifier. In additional or alternative embodiments, the delimiter includes a first delimiter and a second delimiter, and inserting the delimiter includes inserting the first delimiter before the padding bit string and the second delimiter after the padding bit string. In additional or alternative embodiments, the padding bit string includes one or more pre-defined bit strings forming the delimiter and / or the delimiter itself.

[0108] In some embodiments, at least one of the length and content of the padding bit string is dynamically determined by the processor 403 based on variable conditions. Examples of variable conditions may include date, time, the location of the UE, or the weather of the UE's environment.

[0109] At box 720, processor 403 encrypts the padding identifier to generate a hidden padding identifier. In some embodiments, the hidden padding identifier is a contract hidden identifier (SUCI).

[0110] At block 730, processor 403 sends a hidden padding identifier to a network node (e.g., RAN node 500 or CN node 600) via transceiver 401. In some embodiments, processor 403 sends the hidden padding identifier to the network node during UE registration with the wireless communication network. In additional or alternative embodiments, processor 403 receives a request for the identifier from the network node and, in response to receiving the request, sends the hidden padding identifier.

[0111] In some embodiments, the wireless communication network is a home network, and the network nodes are home network nodes. In additional or alternative embodiments, the wireless communication network is a serving network, and the network nodes are serving network nodes.

[0112] For some embodiments, Figures 7 to 9 The various operations can be optional. For example, regarding Example 1, Figure 8 Boxes 810 and 820 and Figure 9 Boxes 910 and 920 can be optional.

[0113] Some embodiments of the present invention will now be referred to. Figures 10 to 15 The operation of RAN node 500 is discussed. For example, modules (also called cells) can be stored... Figure 5The modules are stored in memory 505, and these modules can provide instructions such that when the instructions of the modules are executed by processor 503, processor 503 executes... Figures 10 to 15 The corresponding operations in the flowchart.

[0114] exist Figure 10 In block 1010, processor 503 determines a padding technique available from the user equipment to insert a padding bit string into a field of the identifier before encrypting the identifier associated with the UE (e.g., UE 400). The padding bit string may include one or more bits. In some embodiments, the identifier is a Subscription Permanent Identifier (SUPI) that includes at least one of MSIN, username, routing identifier, public key identifier, and scheme identifier.

[0115] In some embodiments, processor 503 receives a padding instruction to notify a network node of the padding technique used by the UE. In additional or alternative embodiments, processor 503 sends the padding technique to the UE before receiving a hidden padding identifier from the UE.

[0116] At block 1020, processor 503 receives a hidden padding identifier from the UE via transceiver 501. In some embodiments, the hidden padding identifier is a subscription hidden identifier (SUCI). In additional or alternative embodiments, the hidden padding identifier is received from the UE during the registration process or in response to a request for an identifier sent by a network node.

[0117] At box 1030, processor 503 decrypts the hidden padding identifier to generate the padding identifier.

[0118] At box 1040, processor 503 determines the content of the padding identifier, which is separate from the padding bit string, based on padding techniques.

[0119] In some embodiments, the content of the padding identifier is determined based on the padding technique determined in box 1010. Figures 11 to 14 Some specific examples are shown.

[0120] exist Figure 11 In box 1110, processor 503 determines whether a delimiter can be inserted before or after the padding bit string. In box 1142, processor 503 identifies the delimiter in the padding identifier. In box 1144, processor 503 removes the delimiter and the padding bit string before or after the delimiter.

[0121] exist Figure 12In block 1210, processor 503 determines that the first delimiter can be inserted before the padding bit string and the second delimiter can be inserted after the padding bit string. In block 1242, processor 503 identifies the first and second delimiters in the padding identifier. In block 1244, processor 503 removes the first delimiter, the second delimiter, and the padding bit string between the delimiters.

[0122] exist Figure 13 In block 1310, processor 503 determines at least one of the length and content of the padding bit string, which is dynamically determined by the UE based on variable conditions. In block 1342, processor 503 determines the variable conditions at the time the UE generates the padding identifier. In block 1344, processor 503 determines at least one of the length and content of the padding bit string based on the variable conditions. In block 1346, processor 503 removes the padding bit string based on the determination of at least one of the length and content of the padding bit string.

[0123] exist Figure 14 In block 1410, processor 503 determines that multiple padding bit strings can be inserted by the UE into multiple fields of the identifier. In block 1442, processor 503 removes multiple padding bit strings from the multiple fields of the identifier.

[0124] In some embodiments, the network node is an SN node. Figure 15 In box 1542, processor 503 can determine only a portion of the content in the padding identifier. In box 1544, processor 503 can send the hidden padding identifier to the HN node in HN.

[0125] Although the above description of RAN node 500 Figures 10 to 15 However, these operations can be performed by CN node 600. Furthermore, Figures 10 to 15 Some of the operations shown can be performed by any suitable HN node or SN node.

[0126] For some embodiments, Figures 10 to 15 The various operations can be optional. For example, regarding embodiment 17, Figure 11 Boxes 1110, 1142, and 1144; Figure 12 Boxes 1210, 1242, and 1244; Figure 13 Boxes 1310, 1342, 1344, and 1346; Figure 14 Boxes 1410 and 1442; and Figure 15 Boxes 1542 and 1550 can be optional.

[0127] The following discussion focuses on exemplary embodiments. Reference numerals / letters are provided in parentheses by way of example / illustration, and the exemplary embodiments are not limited to the specific elements indicated by the reference numerals / letters.

[0128] Example 1. A method for operating a user equipment (UE) in a wireless communication network, the method comprising:

[0129] The (710) padding identifier is generated by inserting a padding bit string into the field of the identifier associated with the UE;

[0130] Encrypt (720) the padding identifier to produce a hidden padding identifier; and

[0131] Send (730) hidden padding identifier to network nodes operating in the wireless communication network.

[0132] Example 2. According to the method of Example 1, wherein the UE includes at least one of a Universal User Identity Module (USIM) and a Mobile Equipment (ME).

[0133] The padding bit string includes one or more bits.

[0134] Among them, the identifier is the signed permanent identifier SUPI, and

[0135] Among them, the hidden padding identifier is the signed hidden identifier SUCI.

[0136] Example 3. According to the method of Example 2, wherein the SUPI includes at least one of the following: Mobile Subscriber Identity Number (MSIN); Username; Routing Identifier; Public Key Identifier; and Scheme Identifier, and

[0137] The process of generating the padding identifier includes padding at least one of the following: MSIN; username; route identifier; public key identifier; and scheme identifier.

[0138] Example 4. The method according to any one of Examples 1 to 3, wherein generating the padding identifier includes inserting a delimiter before or after the padding bit string, the delimiter being a pre-defined bit string that separates the padding bit string from the content of the identifier.

[0139] Example 5. According to the method of Example 4, wherein the delimiter includes a first delimiter and a second delimiter, and

[0140] The insertion of delimiters includes: inserting a first delimiter before the padding bit string and inserting a second delimiter after the padding bit string.

[0141] Example 6. The method according to any one of Examples 4 to 5, wherein the filling bit string includes one or more pre-defined bit strings forming delimiters.

[0142] Example 7. The method according to any one of Examples 1 to 6 further includes: dynamically determining at least one of the length and content of the padding bit string based on variable conditions.

[0143] Example 8. According to the method of Example 7, the variable conditions include at least one of date, time, UE location, and weather conditions of the UE environment.

[0144] Example 9. The method according to any one of Examples 1 to 8, wherein generating the padding identifier includes: inserting a plurality of padding bit strings into a plurality of fields of the identifier.

[0145] Example 10. A method according to any one of Examples 1 to 9, wherein sending a hidden padding identifier to a network node operating in a wireless communication network includes: sending a hidden padding identifier to a network node operating in a wireless communication network during an operation of the UE for registering the UE with the wireless communication network.

[0146] Example 11. The method according to any one of Examples 1 to 10 further includes: receiving a request for an identifier from a network node.

[0147] Sending a hidden padding identifier to a network node operating in a wireless communication network includes: in response to receiving a request from a network node, sending a hidden padding identifier to a network node operating in a wireless communication network.

[0148] Example 12. The method according to any one of Examples 1 to 11, wherein generating the padding identifier includes:

[0149] Receive (810) a padding instruction from the network node, the padding instruction indicating at least one of the following: length, content, or a delimiter that the UE can use to pad the identifier; and

[0150] The (820) identifier is filled based on the fill instruction.

[0151] Example 13. The method according to any one of Examples 1 to 12, wherein generating the padding identifier includes:

[0152] (910) A padding instruction is received from the user of the UE via the UE's user interface, the padding instruction indicating at least one of the following: length, content, or a delimiter that can be used by the UE to pad the identifier; and

[0153] The identifier (920) is filled based on the fill instruction.

[0154] Example 14. The method according to any one of Examples 1 to 13, wherein the wireless communication network includes a home network, and the network node is a home network node.

[0155] Example 15. The method according to any one of Examples 1 to 13, wherein the wireless communication network includes a serving network, and the network node is a serving network node.

[0156] Example 16. A method according to any one of Examples 1 to 13, wherein the wireless communication network includes a home network and a serving network, and the network nodes include home network nodes and serving network nodes, and

[0157] Sending a hidden padding identifier to a network node includes: sending a hidden padding identifier to a serving network node so that it can be partially decrypted and then further sent by the serving network node to the home network node for further decryption.

[0158] Example 17. A method for operating a network node in a wireless communication network, the method comprising:

[0159] Determine (1010) a padding technique that can be used by a user equipment (UE) in a wireless communication network to insert a padding bit string into the field of the identifier before the E encrypts the identifier associated with the UE;

[0160] Receive (1020) hidden padding identifier from UE;

[0161] Decrypt (1030) the hidden padding identifier to generate the padding identifier; and

[0162] The content of the identifier (1040) is determined based on the padding technique and separated from the padding bit string.

[0163] Example 18. The method according to Example 17, wherein the UE includes at least one of a Universal Subscriber Identity Module (USIM) and a Mobile Equipment (ME).

[0164] The padding bit string includes one or more bits.

[0165] Among them, the identifier is the signed permanent identifier SUPI, and

[0166] Among them, the hidden padding identifier is the signed hidden identifier SUCI.

[0167] Example 19. The method according to Example 18, wherein the SUPI includes at least one of the following: Mobile Subscriber Identity Number (MSIN); Username; Routing Identifier; Public Key Identifier; and Scheme Identifier, and

[0168] The determination of the identifier includes determining at least one of the following: MSIN; username; routing identifier; public key identifier; and scheme identifier.

[0169] Example 20. A method according to any one of Examples 17 to 19, wherein determining the padding technique includes: determining (1110) a delimiter that can be inserted before or after the padding bit string, the delimiter being a pre-positioned string that separates the padding bit string from the content of the identifier, and

[0170] The content of the identifier includes:

[0171] Identify the (1142) delimiter in the padding identifier; and

[0172] Remove the (1144) delimiter and the padding bit string before or after the delimiter.

[0173] Example 21. According to the method of Example 20, determining the filling technique includes: determining that the (1210) delimiter includes a first delimiter and a second delimiter.

[0174] The first delimiter can be inserted before the padding bit string, and the second delimiter can be inserted after the padding bit string.

[0175] The content of the identifier includes:

[0176] Identify (1242) the first delimiter and the second delimiter in the padding identifier; and remove (1244) the first delimiter, the second delimiter, and the padding bit string between the first delimiter and the second delimiter.

[0177] Example 22. The method according to any one of Examples 20 to 21, wherein determining the padding technique includes: determining that the padding bit string includes one or more predefined bit strings.

[0178] Example 23. A method according to any one of Examples 17 to 22, wherein determining the padding technique includes: determining (1310) at least one of the length and content of the padding bit string dynamically determined by the UE based on variable conditions, and

[0179] The content of the identifier includes:

[0180] Determine (1342) the variable conditions at which the UE generates the padding identifier;

[0181] Based on the variable condition of when the UE generates the padding identifier, at least one of the length and content of the (1344) padding bit string is determined; and

[0182] Based on determining at least one of the length and content of the padding bit string, remove (1346) padding bit strings.

[0183] Example 24. A method according to any one of Examples 17 to 23, wherein determining the padding technique includes: determining (1410) a plurality of padding bit strings that can be inserted by the UE into a plurality of fields of an identifier, and

[0184] The determination of the identifier's content includes: removing (1442) multiple padding bit strings from multiple fields of the identifier.

[0185] Example 25. The method according to any one of Examples 17 to 24 further includes: in response to determining the padding technique and before receiving the hidden padding identifier, sending a padding instruction to the UE to notify the UE of the padding technique.

[0186] Example 26. A method according to any one of Examples 17 to 24, wherein determining the padding technique includes: receiving a padding instruction that notifies a network node of a padding instruction available to the UE.

[0187] Example 27. The method according to any one of Examples 17 to 26, wherein receiving the hidden padding identifier from the UE includes: receiving the hidden padding identifier from the UE as part of the UE's registration request to join the wireless communication network.

[0188] Example 28. The method according to any one of Examples 17 to 26 further includes: sending a request for an identifier to the UE.

[0189] The process of receiving a hidden padding identifier from the UE includes receiving a hidden padding identifier from the UE in response to sending a request to the UE.

[0190] Example 29. The method according to any one of Examples 17 to 28, wherein the wireless communication network includes a home network, and the network node is a home network node.

[0191] Example 30. According to the method of Example 29, wherein determining the content of the identifier separated from the padding bit string based on the padding technique includes: determining only a portion of the (1542) content in the padding identifier.

[0192] The method also includes sending a (1550) hidden padding identifier to the service network nodes in the service network.

[0193] Example 31. The method according to any one of Examples 17 to 28, wherein the wireless communication network includes a serving network, and the network node is a serving network node.

[0194] Example 32. A user equipment (UE) (400) operating in a wireless communication network, comprising:

[0195] Processing circuit (403); and

[0196] Memory (405), coupled to the processing circuitry and storing instructions therein, which can be executed by the processing circuitry to cause the UE to perform operations, including:

[0197] The (710) padding identifier is generated by inserting a padding bit string into the field of the identifier associated with the UE;

[0198] Encrypt (720) the padding identifier to produce a hidden padding identifier; and

[0199] Send (730) hidden padding identifier to network nodes operating in the wireless communication network.

[0200] Example 33. The UE according to Example 32, wherein the operation further includes any one of the operations in Examples 2 to 16.

[0201] Example 34. A user equipment (UE) (400) operates in a wireless communication network and is adapted to perform operations including:

[0202] The (710) padding identifier is generated by inserting a padding bit string into the field of the identifier associated with the UE;

[0203] Encrypt (720) the padding identifier to produce a hidden padding identifier; and

[0204] Send (730) hidden padding identifier to network nodes operating in the wireless communication network.

[0205] Example 35. The UE according to Example 34 is also configured to perform any of the operations in Examples 2 to 16.

[0206] Example 36. A computer program comprising program code to be executed by processing circuitry (403) of a user equipment (UE) (400) operating in a wireless communication network, wherein execution of the program code causes the UE to perform an operation including:

[0207] The (710) padding identifier is generated by inserting a padding bit string into the field of the identifier associated with the UE;

[0208] Encrypt (720) the padding identifier to produce a hidden padding identifier; and

[0209] Send (730) hidden padding identifier to network nodes operating in the wireless communication network.

[0210] Example 37. According to the computer program of Example 36, the operation also includes any one of the operations in Examples 2 to 16.

[0211] Example 38. A computer program product including a non-transitory storage medium, the non-transitory storage medium including program code to be executed by processing circuitry (403) of a user equipment (UE) (400) operating in a wireless communication network, wherein execution of the program code causes the UE to perform operations including:

[0212] The (710) padding identifier is generated by inserting a padding bit string into the field of the identifier associated with the UE;

[0213] Encrypt (720) the padding identifier to produce a hidden padding identifier; and

[0214] Send (730) hidden padding identifier to network nodes operating in the wireless communication network.

[0215] Example 39. According to the computer program product of Example 38, the operation further includes any one of the operations in Examples 2 to 16.

[0216] Example 40. A network node (500, 600) operating in a wireless communication network, the network node comprising:

[0217] Processing circuits (503, 603); and

[0218] Memory (505, 605), coupled to the processing circuitry and storing instructions therein, which can be executed by the processing circuitry to cause the network node to perform operations, including:

[0219] Determine (1010) a padding technique that can be used by a user equipment (UE) in a wireless communication network to insert a padding bit string into a field of the identifier before the UE encrypts the identifier associated with the UE;

[0220] Receive (1020) hidden padding identifier from UE;

[0221] Decrypt (1030) the hidden padding identifier to generate the padding identifier; and

[0222] The content of the identifier (1040) is determined based on the padding technique and separated from the padding bit string.

[0223] Example 41. According to the network node of Example 40, the operation also includes any one of the operations in Examples 18 to 31.

[0224] Example 42. A network node (500, 600) operating in a wireless communication network, the network node being adapted to perform operations including:

[0225] Determine (1010) a padding technique that can be used by a user equipment (UE) in a wireless communication network to insert a padding bit string into a field of the identifier before the UE encrypts the identifier associated with the UE;

[0226] Receive (1020) hidden padding identifier from UE;

[0227] Decrypt (1030) the hidden padding identifier to generate the padding identifier; and

[0228] The content of the identifier (1040) is determined based on the padding technique and separated from the padding bit string.

[0229] Example 43. According to the network node of Example 42, the operation also includes any one of the operations in Examples 18 to 31.

[0230] Example 44. A computer program comprising program code to be executed by processing circuitry (503, 603) of a network node (500, 600) operating in a wireless communication network, wherein execution of the program code causes the network node to perform an operation including:

[0231] Determine (1010) a padding technique that can be used by a user equipment (UE) in a wireless communication network to insert a padding bit string into a field of the identifier before the UE encrypts the identifier associated with the UE;

[0232] Receive (1020) hidden padding identifier from UE;

[0233] Decrypt (1030) the hidden padding identifier to generate the padding identifier; and

[0234] The content of the identifier (1040) is determined based on the padding technique and separated from the padding bit string.

[0235] Example 45. According to the computer program of Example 44, the operation further includes any one of the operations in Examples 18 to 31.

[0236] Example 46. A computer program product including a non-transitory storage medium, the non-transitory storage medium including program code to be executed by processing circuitry (503, 603) of a network node (500, 600) operating in a wireless communication network, wherein execution of the program code causes the network node to perform operations including:

[0237] Determine (1010) a padding technique that can be used by a user equipment (UE) in a wireless communication network to insert a padding bit string into a field of the identifier before the UE encrypts the identifier associated with the UE;

[0238] Receive (1020) hidden padding identifier from UE;

[0239] Decrypt (1030) the hidden padding identifier to generate the padding identifier; and

[0240] The content of the identifier (1040) is determined based on the padding technique and separated from the padding bit string.

[0241] Example 47. According to the computer program product of Example 46, the operation further includes any one of the operations in Examples 18 to 31.

[0242] Additional notes are provided below.

[0243] Generally, all terms used herein will be interpreted according to their common meaning in the relevant art, unless a different meaning is explicitly given and / or implied in the context of their use. Unless otherwise expressly stated, all references to elements, devices, components, methods, steps, etc., will be openly interpreted as referring to at least one instance of an element, device, component, method, step, etc. The steps of any method disclosed herein are not necessarily to be performed in the exact order disclosed, unless a step is explicitly described as occurring after or before another step and / or it is implied that a step must occur after or before another step. Any feature of any embodiment disclosed herein may be applied to any other embodiment, where appropriate. Similarly, any advantage of any embodiment may be applied to any other embodiment, and vice versa. Other objects, features, and advantages of the disclosed embodiments will be apparent from the following description.

[0244] Some embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. However, other embodiments are also included within the scope of the subject matter disclosed herein, and the disclosed subject matter should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided merely as examples to convey the scope of the subject matter to those skilled in the art.

[0245] Figure 16 A wireless network according to some embodiments is shown.

[0246] While the subject matter described herein can be implemented in any suitable type of system using any appropriate components, the embodiments disclosed herein are relative to wireless networks (such as...). Figure 16 The example wireless network shown is used for description. For simplicity, Figure 16The wireless network depicted only includes network 4106, network nodes 4160 and 4160b, and WD 4110, 4110b, and 4110c (also referred to as mobile terminals). In practice, the wireless network may also include any additional elements suitable for supporting communication between wireless devices or between a wireless device and another communication device (such as a landline telephone, service provider, or any other network node or terminal device). Among the components shown, network node 4160 and wireless device (WD) 4110 are depicted in additional detail. The wireless network can provide communication and other types of services to one or more wireless devices to facilitate access to and / or use of services provided by or via the wireless network.

[0247] Wireless networks may include or interface with any type of communications, telecommunications, data, cellular, and / or radio network or other similar system. In some embodiments, a wireless network may be configured to operate according to a specific standard or other type of predefined rules or procedures. Thus, specific embodiments of a wireless network may implement communication standards such as Global System for Mobile Communications (GSM), Universal Mobile Telecommunications System (UMTS), Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, or 5G standards; wireless local area network (WLAN) standards such as the IEEE 802.11 standard; and / or any other suitable wireless communication standard such as WiMax, Bluetooth, Z-Wave, and / or ZigBee standards.

[0248] Network 4106 may include one or more backhaul networks, core networks, IP networks, public switched telephone networks (PSTN), packet data networks, optical networks, wide area networks (WAN), local area networks (LAN), wireless local area networks (WLAN), wired networks, wireless networks, metropolitan area networks, and other networks that enable communication between devices.

[0249] Network node 4160 and WD 4110 include various components described in more detail below. These components work together to provide network node and / or wireless device functionality, such as providing wireless connectivity in a wireless network. In various embodiments, the wireless network may include any number of wired or wireless networks, network nodes, base stations, controllers, wireless devices, relay stations, and / or any other components or systems that may facilitate or participate in communication of data and / or signals via wired or wireless connections.

[0250] As used herein, a network node is a device that is capable of, configured, positioned, and / or operable to communicate directly or indirectly with wireless devices and / or with other network nodes or devices in a wireless network to enable and / or provide wireless access to wireless devices and / or perform other functions (e.g., management) in a wireless network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points) and base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs), and NR Node Bs (gNBs)). Base stations can be classified based on the coverage they provide (or, in other words, their transmit power levels) and may also be referred to as femtocells, picocells, microcells, or macrocells. A base station can be a relay node or a relay donor node that controls a relay. A network node may also include one or more (or all) portions of a distributed radio base station, such as a centralized digital unit and / or a remote radio unit (RRU) (sometimes referred to as a remote radio head (RRH)). Such a remote radio unit may or may not be integrated with an antenna as an antenna-integrated radio. A portion of a distributed radio base station may also be referred to as a node in a distributed antenna system (DAS). Further examples of network nodes include multi-standard radio (MSR) equipment (such as an MSR BS), network controllers (such as a radio network controller (RNC) or base station controller (BSC)), base transceiver stations (BTS), transport points, transport nodes, multi-cell / multicast coordination entities (MCEs), core network nodes (e.g., MSC, MME), O&M nodes, OSS nodes, SON nodes, location nodes (e.g., E-SMLC), and / or MDTs. As another example, a network node can be a virtual network node, as described in more detail below. However, more generally, a network node can represent any suitable device (or group of devices) capable of, configured, deployed, and / or operable to enable and / or provide access to a wireless network to wireless devices or to provide some service to wireless devices already connected to the wireless network.

[0251] exist Figure 16 In this network node 4160, processing circuitry 4170, device-readable medium 4180, interface 4190, auxiliary equipment 4184, power supply 4186, power supply circuitry 4187, and antenna 4162 are included. Although in Figure 16The network node 4160 shown in the example wireless network can represent a device including a combination of the hardware components shown; however, other embodiments may include network nodes with different combinations of components. It should be understood that a network node includes any suitable combination of hardware and / or software required to perform the tasks, features, functions, and methods disclosed herein. Furthermore, while the components of network node 4160 are depicted as a single box located within a larger box or nested within multiple boxes, in practice, a network node may include multiple different physical components that make up a single illustrated component (e.g., device-readable medium 4180 may include multiple separate hard disk drives and multiple RAM modules).

[0252] Similarly, network node 4160 may include multiple physically separate components (e.g., node B components and RNC components, or BTS components and BSC components, etc.), each of which may have its own corresponding components. In some scenarios where network node 4160 includes multiple separate components (e.g., BTS and BSC components), one or more separate components may be shared among multiple network nodes. For example, a single RNC may control multiple node Bs. In such scenarios, in some instances, each unique node B and RNC pair may be considered a single, separate network node. In some embodiments, network node 4160 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate device-readable media 4180 for different RATs), and some components may be reused (e.g., the same antenna 4162 may be shared by RATs). Network node 4160 may also include multiple sets of illustrated components for various wireless technologies integrated into network node 4160, such as, for example, GSM, WCDMA, LTE, NR, WiFi, or Bluetooth wireless technologies. These wireless technologies can be integrated into the same or different chips or chip sets within network node 4160.

[0253] Processing circuitry 4170 is configured to perform any determination, calculation, or similar operation (e.g., certain acquisition operations) described herein as being provided by a network node. These operations performed by processing circuitry 4170 may include processing information acquired by processing circuitry 4170 by, for example, converting the acquired information into other information, comparing the acquired or converted information with information stored in the network node, and / or performing one or more operations based on the acquired or converted information; and making a determination as a result of said processing.

[0254] Processing circuitry 4170 may include one or more of the following: a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field-programmable gate array, or any other suitable computing device, resource, or combination of hardware, software, and / or coded logic operable alone or in combination with other network node 4160 components (such as device-readable medium 4180) to provide the functionality of network node 4160. For example, processing circuitry 4170 may execute instructions stored in device-readable medium 4180 or in memory within processing circuitry 4170. Such functionality may include providing any of the various wireless features, functions, or benefits discussed herein. In some embodiments, processing circuitry 4170 may include a system-on-a-chip (SoC).

[0255] In some embodiments, the processing circuitry 4170 may include one or more of a radio frequency (RF) transceiver circuitry 4172 and a baseband processing circuitry 4174. In some embodiments, the RF transceiver circuitry 4172 and the baseband processing circuitry 4174 may be on separate chips (or chipsets), boards, or units (such as radio units and digital units). In other alternative embodiments, some or all of the RF transceiver circuitry 4172 and the baseband processing circuitry 4174 may be on the same chip or chipset, board, or unit.

[0256] In some embodiments, some or all of the functions described herein as being provided by a network node, base station, eNB, or other such network device can be executed by processing circuitry 4170 by executing instructions stored on device-readable medium 4180 or in memory within processing circuitry 4170. In alternative embodiments, some or all of the functions can be provided by processing circuitry 4170 without executing instructions stored on separate or independent device-readable media, such as in a hard-wired manner. In any of those embodiments, processing circuitry 4170 can be configured to perform the described functions regardless of whether instructions stored on device-readable storage media are executed. The benefits provided by such functions are not limited solely to processing circuitry or other components of network node 4160, but are enjoyed by network node 4160 in general and / or typically by end users and the wireless network.

[0257] Device-readable medium 4180 may include any form of volatile or non-volatile computer-readable storage, including but not limited to persistent storage devices, solid-state storage, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (e.g., hard disk), removable storage media (e.g., flash drives, optical discs (CDs), or digital video discs (DVDs)), and / or any other volatile or non-volatile non-transitory device-readable storage device and / or computer-executable memory device that stores information, data, and / or instructions usable by processing circuitry 4170. Device-readable medium 4180 may store any suitable instructions, data, or information, including computer programs, software, applications including one or more of logic, rules, code, tables, etc., and / or other instructions executable by processing circuitry 4170 and utilized by network node 4160. Device-readable medium 4180 may be used to store any calculations performed by processing circuitry 4170 and / or any data received via interface 4190. In some embodiments, the processing circuitry 4170 and the device-readable medium 4180 may be considered integrated.

[0258] Interface 4190 is used in wired or wireless communication of signaling and / or data between network node 4160, network 4106, and / or WD 4110. As shown, interface 4190 includes, for example, one or more ports / terminals 4194 for sending and receiving data to and from network 4106 via a wired connection. Interface 4190 also includes radio front-end circuitry 4192, which may be coupled to antenna 4162 or, in some embodiments, is part of antenna 4162. Radio front-end circuitry 4192 includes filter 4198 and amplifier 4196. Radio front-end circuitry 4192 may be connected to antenna 4162 and processing circuitry 4170. Radio front-end circuitry may be configured to modulate the signal transmitted between antenna 4162 and processing circuitry 4170. Radio front-end circuitry 4192 may receive digital data to be transmitted wirelessly to other network nodes or WD. The radio front-end circuit 4192 can use a combination of filter 4198 and / or amplifier 4196 to convert digital data into radio signals with appropriate channel and bandwidth parameters. The radio signals can then be transmitted via antenna 4162. Similarly, when receiving data, antenna 4162 can collect radio signals, which are then converted into digital data by the radio front-end circuit 4192. The digital data can be passed to processing circuitry 4170. In other embodiments, the interface may include different components and / or different combinations of components.

[0259] In some alternative embodiments, network node 4160 may not include a separate radio front-end circuitry 4192; instead, processing circuitry 4170 may include radio front-end circuitry and may be connected to antenna 4162 without requiring a separate radio front-end circuitry 4192. Similarly, in some embodiments, all or part of RF transceiver circuitry 4172 may be considered part of interface 4190. In other embodiments, interface 4190 may include one or more ports or terminals 4194, radio front-end circuitry 4192, and RF transceiver circuitry 4172 as part of a radio unit (not shown), and interface 4190 may communicate with baseband processing circuitry 4174, which is part of a digital unit (not shown).

[0260] Antenna 4162 may include one or more antennas or an antenna array configured to transmit and / or receive wireless signals. Antenna 4162 may be coupled to radio front-end circuitry 4192 and may be any type of antenna capable of wirelessly transmitting and receiving data and / or signals. In some embodiments, antenna 4162 may include one or more omnidirectional, sector, or planar antennas operable to transmit / receive radio signals, for example, between 2 GHz and 66 GHz. Omnidirectional antennas can be used to transmit / receive radio signals in any direction, sector antennas can be used to transmit / receive radio signals from devices within a specific area, and planar antennas can be line-of-sight antennas for transmitting / receiving radio signals along a relatively straight line. In some instances, the use of more than one antenna may be referred to as MIMO. In some embodiments, antenna 4162 may be detachable from network node 4160 and may be connected to network node 4160 via an interface or port.

[0261] Antenna 4162, interface 4190, and / or processing circuitry 4170 can be configured to perform any receive operation and / or certain acquire operation described herein as being performed by a network node. Any information, data, and / or signals can be received from a wireless device, another network node, and / or any other network device. Similarly, antenna 4162, interface 4190, and / or processing circuitry 4170 can be configured to perform any transmit operation described herein as being performed by a network node. Any information, data, and / or signals can be transmitted to a wireless device, another network node, and / or any other network device.

[0262] Power supply circuitry 4187 may include or be coupled to power management circuitry and is configured to supply power to components of network node 4160 for performing the functions described herein. Power supply circuitry 4187 may receive power from power source 4186. Power source 4186 and / or power supply circuitry 4187 may be configured to supply power to various components of network node 4160 in a manner suitable for the respective components (e.g., at the voltage and current levels required by each respective component). Power source 4186 may be included in power supply circuitry 4187 and / or network node 4160, or may be external to power supply circuitry 4187 and / or network node 4160. For example, network node 4160 may be connected to an external power source (e.g., an electrical outlet) via input circuitry or an interface (such as a cable), whereby the external power source supplies power to power supply circuitry 4187. As another example, power source 4186 may include a power source in the form of a battery or battery pack, which is connected to or integrated into power supply circuitry 4187. The battery can provide backup power in the event of an external power failure. Other types of power sources, such as photovoltaic devices, may also be used.

[0263] Alternative embodiments of network node 4160 may include, in addition to Figure 16 Additional components, other than those shown, may be responsible for providing certain aspects of the functionality of the network node, including any of the functions described herein and / or any functionality required to support the topics described herein. For example, network node 4160 may include a user interface device that allows information to be input into and output from network node 4160. This can allow users to perform diagnostic, maintenance, repair, and other management functions for network node 4160.

[0264] As used herein, a wireless device (WD) means a device capable of, configured, positioned, and / or operable to wirelessly communicate with network nodes and / or other WDs. Unless otherwise stated, the term WD may be used interchangeably with User Equipment (UE) herein. Wireless communication may involve sending and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for transmitting information through the air. In some embodiments, a WD may be configured to send and / or receive information without direct human interaction. For example, a WD may be designed to send information to a network according to a predetermined schedule when triggered by an internal or external event or in response to a request from the network. Examples of WDs include, but are not limited to, smartphones, mobile phones, cell phones, Voice over IP (VoIP) phones, wireless local loop phones, desktop computers, personal digital assistants (PDAs), wireless cameras, game consoles or devices, music storage devices, playback devices, wearable terminal devices, wireless endpoints, mobile stations, tablet computers, laptops, laptop embedded devices (LEEs), laptop mounted devices (LMEs), smart devices, wireless client equipment (CPEs), vehicle-mounted wireless terminal equipment, etc. A WD can support device-to-device (D2D) communication, for example by implementing 3GPP standards for secondary link communication, vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), and vehicle-to-everything (V2X), and in this case can be referred to as a D2D communication device. As another specific example, in the Internet of Things (IoT) scenario, a WD can represent a machine or other device that performs monitoring and / or measurement and sends the results of such monitoring and / or measurement to another WD and / or network node. In this case, the WD can be a machine-to-machine (M2M) device, which can be referred to as an MTC device in the 3GPP context. As a specific example, a WD can be a UE that implements the 3GPP Narrowband Internet of Things (NB-IoT) standard. Specific examples of such machines or devices are sensors, metering devices (such as electricity meters), industrial machinery, or household or personal appliances (e.g., refrigerators, televisions, etc.), and personal wearable devices (e.g., watches, fitness trackers, etc.). In other scenarios, a WD can represent a vehicle-to-everything (V2X) or other device capable of monitoring and / or reporting its operational status or other functions associated with its operation. As described above, WD can represent a wireless connection endpoint, in which case the device can be referred to as a wireless terminal. Furthermore, as described above, WD can be mobile, in which case the WD can also be referred to as a mobile device or mobile terminal.

[0265] As shown in the figure, wireless device 4110 includes an antenna 4111, an interface 4114, processing circuitry 4120, a device-readable medium 4130, a user interface device 4132, auxiliary devices 4134, a power supply 4136, and a power supply circuitry 4137. WD 4110 may include multiple sets of the shown components for one or more of the different wireless technologies supported by WD 4110, such as, for example, GSM, WCDMA, LTE, NR, WiFi, WiMAX, or Bluetooth wireless technologies, to name a few. These wireless technologies may be integrated into a chip or chipset within WD 4110 that may be the same as or different from the other components.

[0266] Antenna 4111 may include one or more antennas or an antenna array, configured to transmit and / or receive wireless signals, and connected to interface 4114. In some alternative embodiments, antenna 4111 may be detached from WD 4110 and may be connected to WD 4110 via an interface or port. Antenna 4111, interface 4114, and / or processing circuitry 4120 may be configured to perform any receive or transmit operations described herein as being performed by a WD. Any information, data, and / or signals may be received from a network node and / or another WD. In some embodiments, radio front-end circuitry and / or antenna 4111 may be considered as an interface.

[0267] As shown in the figure, interface 4114 includes radio front-end circuitry 4112 and antenna 4111. Radio front-end circuitry 4112 includes one or more filters 4118 and amplifiers 4116. Radio front-end circuitry 4112 is connected to antenna 4111 and processing circuitry 4120 and is configured to modulate the signal transmitted between antenna 4111 and processing circuitry 4120. Radio front-end circuitry 4112 may be coupled to antenna 4111 or a portion thereof. In some embodiments, WD 4110 may not include separate radio front-end circuitry 4112; instead, processing circuitry 4120 may include radio front-end circuitry and may be connected to antenna 4111. Similarly, in some embodiments, all or some of RF transceiver circuitry 4122 may be considered part of interface 4114. Radio front-end circuitry 4112 can receive digital data to be transmitted wirelessly to other network nodes or WD. Radio front-end circuitry 4112 may use a combination of filters 4118 and / or amplifiers 4116 to convert digital data into radio signals with appropriate channel and bandwidth parameters. The radio signals can then be transmitted via antenna 4111. Similarly, when receiving data, antenna 4111 can collect radio signals, which are then converted into digital data by radio front-end circuitry 4112. The digital data can then be passed to processing circuitry 4120. In other embodiments, the interface may include different components and / or different combinations of components.

[0268] Processing circuitry 4120 may include one or more of the following: a microprocessor, a controller, a central processing unit, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array, or any other suitable computing device, resource, or combination of hardware, software, and / or coded logic operable alone or in combination with other WD 4110 components (such as device-readable medium 4130) to provide WD 4110 functionality. Such functionality may include providing any of the various wireless features or benefits discussed herein. For example, processing circuitry 4120 may execute instructions stored in device-readable medium 4130 or in memory within processing circuitry 4120 to provide the functionality disclosed herein.

[0269] As shown in the figure, the processing circuit 4120 includes one or more of an RF transceiver circuit 4122, a baseband processing circuit 4124, and an application processing circuit 4126. In other embodiments, the processing circuit may include different components and / or different combinations of components. In some embodiments, the processing circuit 4120 of WD 4110 may include a System-on-a-Chip (SOC). In some embodiments, the RF transceiver circuit 4122, the baseband processing circuit 4124, and the application processing circuit 4126 may be on a separate chip or chipset. In alternative embodiments, a portion or all of the baseband processing circuit 4124 and the application processing circuit 4126 may be combined into a single chip or chipset, and the RF transceiver circuit 4122 may be on a separate chip or chipset. In other alternative embodiments, a portion or all of the RF transceiver circuit 4122 and the baseband processing circuit 4124 may be on the same chip or chipset, and the application processing circuit 4126 may be on a separate chip or chipset. In other alternative embodiments, some or all of the RF transceiver circuitry 4122, baseband processing circuitry 4124, and application processing circuitry 4126 may be combined in a single chip or chipset. In some embodiments, the RF transceiver circuitry 4122 may be part of interface 4114. The RF transceiver circuitry 4122 may modulate RF signals for use by processing circuitry 4120.

[0270] In some embodiments, some or all of the functions described herein as being performed by WD may be provided by processing circuitry 4120 executing instructions stored on device-readable medium 4130 (which may be a computer-readable storage medium in some embodiments). In alternative embodiments, some or all of the functions may be provided by processing circuitry 4120 without executing instructions stored on a separate or independent device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, processing circuitry 4120 may be configured to perform the described functions, whether or not instructions stored on a device-readable storage medium are executed. The benefits provided by such functions are not limited solely to processing circuitry 4120 or other components of WD 4110, but are enjoyed by WD 4110 in general and / or typically by end users and wireless networks.

[0271] Processing circuitry 4120 may be configured to perform any determination, calculation, or similar operation (e.g., certain acquisition operations) described herein as being performed by WD. Such operations performed by processing circuitry 4120 may include: processing information acquired by processing circuitry 4120 by, for example, converting the acquired information into other information, comparing the acquired or converted information with information stored by WD 4110, and / or performing one or more operations based on the acquired or converted information; and making a determination as a result of the processing.

[0272] Device-readable medium 4130 may be operable to store computer programs, software, applications, including one or more of logic, rules, code, tables, etc., and / or other instructions executable by processing circuitry 4120. Device-readable medium 4130 may include computer memory (e.g., random access memory (RAM) or read-only memory (ROM)), mass storage media (e.g., hard disk), removable storage media (e.g., optical disc (CD) or digital video disc (DVD)), and / or any other volatile or non-volatile, non-transitory computer-readable and / or computer-executable memory device that stores information, data, and / or instructions usable by processing circuitry 4120. In some embodiments, processing circuitry 4120 and device-readable medium 4130 may be considered integrated.

[0273] User interface device 4132 can provide components that allow a human user to interact with WD 4110. Such interaction can take many forms, such as visual, auditory, tactile, etc. User interface device 4132 can be operable to produce outputs to the user and allow the user to provide inputs to WD 4110. The type of interaction can vary depending on the type of user interface device 4132 installed in WD 4110. For example, if WD 4110 is a smartphone, interaction can be via a touchscreen; if WD 4110 is a smart meter, interaction can be via a screen providing usage (e.g., the number of gallons used) or a speaker providing audible alarms (e.g., if smoke is detected). User interface device 4132 may include input interfaces, devices, and circuitry, as well as output interfaces, devices, and circuitry. User interface device 4132 is configured to allow information to be input into WD 4110 and is connected to processing circuitry 4120 to allow processing circuitry 4120 to process the input information. User interface device 4132 may include, for example, a microphone, proximity or other sensors, keys / buttons, a touch display, one or more cameras, a USB port, or other input circuitry. User interface device 4132 is also configured to allow output of information from WD 4110, and to allow processing circuitry 4120 to output information from WD 4110. User interface device 4132 may include, for example, a speaker, display, vibration circuitry, a USB port, a headphone jack, or other output circuitry. Using one or more input and output interfaces, devices, and circuitry of user interface device 4132, WD 4110 can communicate with end users and / or wireless networks, allowing them to benefit from the functionality described herein.

[0274] The auxiliary device 4134 is operable to provide more specific functions that may not typically be performed by the WD. This may include specialized sensors for measurements for various purposes, interfaces for additional types of communication (such as wired communication), etc. The inclusion and type of components of the auxiliary device 4134 may vary depending on the embodiment and / or scenario.

[0275] In some embodiments, power supply 4136 may be in the form of a battery or battery pack. Other types of power sources may also be used, such as an external power source (e.g., an electrical outlet), a photovoltaic device, or a battery. WD 4110 may also include power circuitry 4137 for supplying power from power supply 4136 to portions of WD 4110 that require power from power supply 4136 to perform any of the functions described or indicated herein. In some embodiments, power circuitry 4137 may include power management circuitry. Additionally or alternatively, power circuitry 4137 may be operable to receive power from an external power source; in this case, WD 4110 may be connected to an external power source (such as an electrical outlet) via input circuitry or an interface such as a power cable. In some embodiments, power circuitry 4137 may also be operable to supply power from an external power source to power supply 4136. This may be used, for example, for charging power supply 4136. Power circuitry 4137 may perform any formatting, conversion, or other modifications on the power from power supply 4136 to adapt the power to the corresponding components of WD 4110 that are supplying it.

[0276] Figure 17 A user device according to some embodiments is shown.

[0277] Figure 17 An embodiment of a UE according to the aspects described herein is illustrated. As used herein, a user equipment or UE may not necessarily have to be a user in the sense of a human user who owns and / or operates the associated equipment. Instead, a UE may represent a device intended to be sold to or operated by a human user but which may not or initially may not be associated with a particular human user (e.g., a smart sprinkler controller). Alternatively, a UE may represent a device not intended to be sold to or operated by an end user but which may be associated with or operated for the benefit of a user (e.g., a smart meter). UE 4200 may be a UE identified by the 3rd Generation Partnership Project (3GPP), including NB-IoT UEs, Machine Type Communication (MTC) UEs, and / or Enhanced MTC (eMTC) UEs. Figure 17 As shown, UE 4200 is an example of a WD configured to communicate according to one or more communication standards (such as 3GPP's GSM, UMTS, LTE, and / or 5G standards) issued by the 3rd Generation Partnership Project (3GPP). As previously mentioned, the terms WD and UE can be used interchangeably. Therefore, although... Figure 17 This is for UE, but the components discussed in this article also apply to WD, and vice versa.

[0278] exist Figure 17In this embodiment, UE 4200 includes processing circuitry 4201 operatively coupled to an input / output interface 4205, a radio frequency (RF) interface 4209, a network connectivity interface 4211, a memory 4215 (including random access memory (RAM) 4217, read-only memory (ROM) 4219, and storage medium 4221, etc.), a communication subsystem 4231, a power supply 4213, and / or any other component, or any combination thereof. Storage medium 4221 includes an operating system 4223, application programs 4225, and data 4227. In other embodiments, storage medium 4221 may include other similar types of information. Some UEs may utilize... Figure 17 The components shown may be all or only a subset of the components. The degree of integration between components may vary depending on the UE. Furthermore, some UEs may contain multiple instances of components, such as multiple processors, memories, transceivers, transmitters, receivers, etc.

[0279] exist Figure 17 In this embodiment, processing circuitry 4201 can be configured to process computer instructions and data. Processing circuitry 4201 can be configured to implement any sequential state machine operable to execute machine instructions stored as a machine-readable computer program in memory, such as one or more hardware-implemented state machines (e.g., in discrete logic, FPGA, ASIC, etc.); programmable logic along with appropriate firmware; one or more stored programs, general-purpose processors such as microprocessors or digital signal processors (DSPs), along with appropriate software; or any combination of the foregoing. For example, processing circuitry 4201 may include two central processing units (CPUs). Data may be information in a form suitable for use by a computer.

[0280] In the depicted embodiments, the input / output interface 4205 can be configured to provide a communication interface to an input device, an output device, or both. The UE 4200 can be configured to use an output device via the input / output interface 4205. The output device can use an interface port of the same type as the input device. For example, a USB port can be used to provide input to and output from the UE 4200. The output device can be a speaker, sound card, video card, display, monitor, printer, actuator, transmitter, smart card, another output device, or any combination thereof. The UE 4200 can be configured to use an input device via the input / output interface 4205 to allow a user to capture information into the UE 4200. The input device may include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, digital video camera, webcam, etc.), a microphone, a sensor, a mouse, a trackball, a steering wheel, a scroll wheel, a smart card, etc. A presence-sensitive display may include a capacitive or resistive touch sensor that senses input from the user. Sensors can be, for example, accelerometers, gyroscopes, tilt sensors, force sensors, magnetometers, optical sensors, proximity sensors, another similar sensor, or any combination thereof. For example, input devices can be accelerometers, magnetometers, digital cameras, microphones, and optical sensors.

[0281] exist Figure 17 In this configuration, RF interface 4209 can be configured to provide a communication interface to RF components such as transmitters, receivers, and antennas. Network connectivity interface 4211 can be configured to provide a communication interface to network 4243a. Network 4243a may encompass wired and / or wireless networks, such as local area networks (LANs), wide area networks (WANs), computer networks, wireless networks, telecommunications networks, another similar network, or any combination thereof. For example, network 4243a may include a Wi-Fi network. Network connectivity interface 4211 can be configured to include receiver and transmitter interfaces for communicating with one or more other devices over the communication network according to one or more communication protocols such as Ethernet, TCP / IP, SONET, ATM, etc. Network connectivity interface 4211 can implement receiver and transmitter functions suitable for communication network links (e.g., optical, electrical, etc.). Transmitter and receiver functions may share circuit components, software, or firmware, or alternatively may be implemented separately.

[0282] RAM 4217 can be configured to interface with processing circuitry 4201 via bus 4202 to provide storage or cache of data or computer instructions during the execution of software programs (such as operating systems, application programs, and device drivers). ROM 4219 can be configured to provide computer instructions or data to processing circuitry 4201. For example, ROM 4219 can be configured to store invariant low-level system code or data for basic system functions, such as basic input and output (I / O), boot, or receive signals from a keyboard, stored in non-volatile memory. Storage medium 4221 can be configured to include memory such as RAM, ROM, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), disk, optical disk, floppy disk, hard disk, removable disk, or flash drive. In one example, storage medium 4221 can be configured to include operating system 4223, application program 4225 (such as a web browser application, widget or accessory engine, or another application), and data file 4227. Storage medium 4221 can store any of a variety of different operating systems or combinations of operating systems for use by UE 4200.

[0283] Storage medium 4221 can be configured to include multiple physical drive units, such as a redundant array of independent disks (RAID), a floppy disk drive, flash memory, a USB flash drive, an external hard disk drive, a thumb drive, a pen drive, a key drive, a high-density digital universal optical disc (HD-DVD) drive, an internal hard disk drive, a Blu-ray disc drive, a holographic digital data storage (HDDS) disc drive, an external mini dual in-line memory module (DIMM), synchronous dynamic random access memory (SDRAM), external micro DIMM SDRAM, smart card memory such as a user identity module (or a removable subscriber identity (SIM / RUIM) module), other memory, or any combination thereof. Storage medium 4221 can allow UE 4200 to access computer-executable instructions, applications, etc., stored on transient or non-transient storage media to unload or upload data. Articles of manufacture (such as articles utilizing communication systems) can be tangibly implemented in storage medium 4221, which may include device-readable media.

[0284] exist Figure 17In this embodiment, processing circuitry 4201 can be configured to communicate with network 4243b using communication subsystem 4231. Networks 4243a and 4243b can be the same one or more networks or different one or more networks. Communication subsystem 4231 can be configured to include one or more transceivers for communicating with network 4243b. For example, communication subsystem 4231 can be configured to include one or more remote transceivers for communicating with another device (such as another WD, UE, or base station of a radio access network (RAN)) capable of wireless communication according to one or more communication protocols (such as IEEE 802.11, CDMA, WCDMA, GSM, LTE, UTRAN, WiMax, etc.). Each transceiver can include transmitter 4233 and / or receiver 4235, respectively implementing transmitter or receiver functions suitable for RAN links (e.g., frequency allocation, etc.). Further, transmitter 4233 and receiver 4235 of each transceiver can share circuit components, software, or firmware, or alternatively can be implemented separately.

[0285] In the illustrated embodiment, the communication functions of the communication subsystem 4231 may include data communication, voice communication, multimedia communication, short-range communication (such as Bluetooth, near-field communication), location-based communication (such as using a Global Positioning System (GPS) to determine location), another similar communication function, or any combination thereof. For example, the communication subsystem 4231 may include cellular communication, Wi-Fi communication, Bluetooth communication, and GPS communication. The network 4243b may encompass wired and / or wireless networks, such as a local area network (LAN), a wide area network (WAN), a computer network, a wireless network, a telecommunications network, another similar network, or any combination thereof. For example, the network 4243b may be a cellular network, a Wi-Fi network, and / or a near-field network. The power supply 4213 may be configured to provide alternating current (AC) or direct current (DC) power to the components of the UE 4200.

[0286] The features, benefits, and / or functions described herein may be implemented in one of the components of UE 4200 or divided among multiple components of UE 4200. Further, the features, benefits, and / or functions described herein may be implemented in any combination of hardware, software, or firmware. In one example, communication subsystem 4231 may be configured to include any of the components described herein. Further, processing circuitry 4201 may be configured to communicate with any of such components via bus 4202. In another example, any such component may be represented by program instructions stored in memory that, when executed by processing circuitry 4201, perform the corresponding functions described herein. In another example, the functionality of any such component may be divided between processing circuitry 4201 and communication subsystem 4231. In another example, the non-computationally intensive functions of any such component may be implemented in software or firmware, and the computationally intensive functions may be implemented in hardware.

[0287] Figure 18 A virtualized environment according to some embodiments is shown.

[0288] Figure 18 This is a schematic block diagram illustrating a virtualization environment 4300 in which functionality implemented by some embodiments can be virtualized. In the present context, virtualization means creating a virtual version of a device or apparatus, which may include virtualized hardware platforms, storage devices, and network resources. As used herein, virtualization can be applied to nodes (e.g., virtualized base stations or virtualized radio access nodes) or devices (e.g., UEs, wireless devices, or any other type of communication equipment) or components thereof, and involves at least a portion of functionality implemented therein as an implementation of one or more virtual components (e.g., via one or more applications, components, functions, virtual machines, or containers executed on one or more physical processing nodes in one or more networks).

[0289] In some embodiments, some or all of the functionality described herein may be implemented as virtual components executed by one or more virtual machines implemented in one or more virtual environments 4300 hosted in one or more hardware nodes 4330. Further, in embodiments where the virtual node is not a radio access node or does not require a radio connection (e.g., a core network node), the network node may be fully virtualized.

[0290] The functionality may be implemented by one or more applications 4320 (which may alternatively be referred to as software instances, virtual devices, network functions, virtual nodes, virtual network functions, etc.), which are operable to implement some of the features, functions, and / or benefits of the embodiments disclosed herein. Application 4320 runs in a virtualization environment 4300 that provides hardware 4330 including processing circuitry 4360 and memory 4390. Memory 4390 contains instructions 4395 executable by processing circuitry 4360, wherein application 4320 is operable to provide one or more of the features, benefits, and / or functions disclosed herein.

[0291] The virtualization environment 4300 includes general-purpose or special-purpose network hardware devices 4330, which include one or more processors or processing circuitry 4360, which may be commercial off-the-shelf (COTS) processors, application-specific integrated circuits (ASICs), or any other type of processing circuitry including digital or analog hardware components or special-purpose processors. Each hardware device may include a memory 4390-1, which may be a non-persistent memory for temporarily storing instructions 4395 or software executed by the processing circuitry 4360. Each hardware device may include one or more network interface controllers (NICs) 4370 (also referred to as network interface cards), which include physical network interfaces 4380. Each hardware device may also include a non-transitory persistent machine-readable storage medium 4390-2 in which software 4395 and / or instructions executable by the processing circuitry 4360 are stored. Software 4395 may include any type of software, including software for instantiating one or more virtualization layers 4350 (also referred to as a hypervisor), software for executing virtual machine 4340, and software that allows the execution of the functions, features, and / or benefits described in relation to some of the embodiments described herein.

[0292] Virtual machine 4340 includes virtual processing, virtual memory, virtual networking or interface, and virtual storage, and can be run by a corresponding virtualization layer 4350 or hypervisor. Different embodiments of instances of virtual device 4320 may be implemented on one or more virtual machines 4340, and these implementations may be carried out in different ways.

[0293] During operation, the processing circuitry 4360 executes the software 4395 of the instantiation management program or virtualization layer 4350, which may sometimes be referred to as the virtual machine monitor (VMM). The virtualization layer 4350 can present a virtual operating platform that appears to be network hardware to the virtual machine 4340.

[0294] like Figure 18As shown, hardware 4330 can be a standalone network node with general or specific components. Hardware 4330 may include antenna 43225 and may implement some functions via virtualization. Alternatively, hardware 4330 may be part of a larger hardware cluster (e.g., in a data center or customer premises equipment (CPE)) in which many hardware nodes work together and are managed via management and orchestration (MANO) 43100, which in particular oversees the lifecycle management of application 4320.

[0295] Hardware virtualization is sometimes referred to as Network Functions Virtualization (NFV). NFV can be used to consolidate many types of network devices into industry-standard high-capacity server hardware, physical switches, and physical storage devices, which can reside in data centers and client terminal devices.

[0296] In the context of NFV, a virtual machine 4340 can be a software implementation of a physical machine, and its programs run as if they were executing on a physical, non-virtualized machine. Each virtual machine 4340 and the portion of hardware 4330 that executes that virtual machine (i.e., hardware dedicated to that virtual machine and / or hardware shared by that virtual machine and other virtual machines 4340) form a separate virtual network element (VNE).

[0297] Still within the context of NFV, a Virtual Network Function (VNF) is responsible for handling specific network functions running in one or more virtual machines 4340 on top of the hardware network infrastructure 4330, and corresponds to... Figure 18 Application 4320.

[0298] In some embodiments, one or more radio units 43200, each including one or more transmitters 43220 and one or more receivers 43210, may be coupled to one or more antennas 43225. The radio unit 43200 may communicate directly with the hardware node 4330 via one or more suitable network interfaces and may be combined with virtual components to provide a radio-capable virtual node, such as a radio access node or base station.

[0299] In some embodiments, some signaling may be implemented using the control system 43230; alternatively, the control system 43230 may be used for communication between the hardware node 4330 and the radio unit 43200.

[0300] Figure 19 A telecommunications network connected to a host computer via an intermediate network is shown according to some embodiments.

[0301] refer to Figure 19According to an embodiment, the communication system includes a telecommunications network 4410, such as a 3GPP-type cellular network, which includes an access network 4411 (such as a radio access network) and a core network 4414. The access network 4411 includes multiple base stations 4412a, 4412b, and 4412c, such as NB, eNB, GNB, or other types of wireless access points, each base station 4412a, 4412b, and 4412c defining a corresponding coverage area 4413a, 4413b, and 4413c. Each base station 4412a, 4412b, and 4412c can be connected to the core network 4414 via a wired or wireless connection 4415. A first UE 4491 located in coverage area 4413c is configured to wirelessly connect to or be paged by the corresponding base station 4412c. A second UE 4492 located in coverage area 4413a can wirelessly connect to the corresponding base station 4412a. Although multiple UEs 4491 and 4492 are shown in this example, the disclosed embodiments are equally applicable to situations where there is only one UE in the coverage area or a single UE connected to the corresponding base station 4412.

[0302] Telecommunications network 4410 is itself connected to host computer 4430, which may be implemented in the hardware and / or software of a standalone server, a cloud-implemented server, a distributed server, or as a processing resource in a server cluster. Host computer 4430 may be owned or controlled by a service provider, or may be operated by or on behalf of a service provider. Connections 4421 and 4422 between telecommunications network 4410 and host computer 4430 may extend directly from core network 4414 to host computer 4430 or may be made via optional intermediate network 4420. Intermediate network 4420 may be one or more public, private, or host networks; if any, intermediate network 4420 may be a backbone network or the Internet; in particular, intermediate network 4420 may include two or more subnetworks (not shown).

[0303] Figure 19The communication system as a whole enables connectivity between the connected UEs 4491 and 4492 and the host computer 4430. This connectivity can be described as an over-the-top (OTT) connection 4450. The host computer 4430 and the connected UEs 4491 and 4492 are configured to use access network 4411, core network 4414, any intermediate network 4420, and possible further infrastructure (not shown) as intermediaries to transmit data and / or signaling via OTT connection 4450. OTT connection 4450 can be transparent in the sense that the participating communication devices traversed by OTT connection 4450 are unaware of the routes of uplink and downlink communications. For example, base station 4412 may not be informed, or need not be informed, of the past routes of incoming downlink communications originating from host computer 4430 to be forwarded (e.g., handed over) to connected UE 4491. Similarly, base station 4412 does not need to know the future route of outgoing uplink communication from UE 4491 to host computer 4430.

[0304] Figure 20 A host computer is shown communicating with a user equipment via a base station through a partial wireless connection, according to some embodiments.

[0305] Now refer to Figure 20 Example implementations of the UE, base station, and host computer discussed in the preceding paragraphs according to embodiments are described. In the communication system 4500, the host computer 4510 includes hardware 4515, which includes a communication interface 4516 configured to establish and maintain wired or wireless connections with different communication devices of the communication system 4500. The host computer 4510 also includes processing circuitry 4518, which may have storage and / or processing capabilities. In particular, the processing circuitry 4518 may include one or more programmable processors, application-specific integrated circuits, field-programmable gate arrays, or combinations of these (not shown) suitable for executing instructions. The host computer 4510 also includes software 4511, which is stored in or accessible by the host computer 4510 and executable by the processing circuitry 4518. The software 4511 includes a host application 4512. Host application 4512 is operable to provide services to remote users, such as UE 4530 connected via OTT connection 4550 terminated at UE 4530 and host computer 4510. When providing services to remote users, host application 4512 can provide user data sent using OTT connection 4550.

[0306] The communication system 4500 also includes a base station 4520, which is provided in the telecommunications system and includes hardware 4525 enabling the base station 4520 to communicate with the host computer 4510 and the UE 4530. Hardware 4525 may include a communication interface 4526 for establishing and maintaining wired or wireless connections with different communication devices of the communication system 4500, and for establishing and maintaining connections at least with areas within the coverage area served by the base station 4520 (in... Figure 20 The radio interface 4527 of the UE 4530 (not shown) is for the wireless connection 4570. The communication interface 4526 can be configured to facilitate a connection 4560 to the host computer 4510. The connection 4560 can be direct or it can traverse the core network of the telecommunications system (in...). Figure 20 (Not shown) and / or one or more intermediate networks outside the telecommunications system. In the illustrated embodiment, the hardware 4525 of the base station 4520 also includes processing circuitry 4528, which may include one or more programmable processors, application-specific integrated circuits, field-programmable gate arrays, or combinations of these (not shown) adapted to execute instructions. The base station 4520 also includes software 4521 stored internally or accessible via an external connection.

[0307] The communication system 4500 also includes the previously mentioned UE 4530. Its hardware 4535 may include a radio interface 4537 configured to establish and maintain a radio connection 4570 with a base station serving the coverage area where the UE 4530 is currently located. The hardware 4535 of the UE 4530 also includes processing circuitry 4538, which may include one or more programmable processors, application-specific integrated circuits, field-programmable gate arrays, or combinations thereof (not shown) suitable for executing instructions. The UE 4530 also includes software 4531, which is stored in or accessible by the UE 4530 and executable by the processing circuitry 4538. The software 4531 includes a client application 4532. The client application 4532 may be operable to provide services to human or non-human users via the UE 4530 with the support of a host computer 4510. In host computer 4510, the executing host application 4512 can communicate with the executing client application 4532 via an OTT connection 4550 terminated at UE 4530 and host computer 4510. When providing services to a user, client application 4532 can receive request data from host application 4512 and provide user data in response to the request data. OTT connection 4550 can transmit both request data and user data. Client application 4532 can interact with the user to generate the user data it provides.

[0308] It should be noted that Figure 20The host computer 4510, base station 4520, and UE 4530 shown can be respectively connected to Figure 19 One of the host computer 4430, base stations 4412a, 4412b, and 4412c, and one of the UEs 4491 and 4492 are similar to or the same. That is to say, the internal workings of these entities can be as follows: Figure 20 As shown, and independently, the surrounding network topology can be Figure 19 The network topology.

[0309] exist Figure 20 In this diagram, the OTT connection 4550 is abstractly depicted to illustrate communication between the host computer 4510 and the UE 4530 via the base station 4520, without explicitly referencing any intermediate devices and the precise routes of messages via those devices. The network infrastructure can determine the route, which can be configured to conceal it from the UE 4530 or the service provider operating the host computer 4510, or both. While the OTT connection 4550 is active, the network infrastructure can also make decisions to dynamically change the route (e.g., based on network load balancing considerations or reconfiguration).

[0310] The wireless connection 4570 between UE 4530 and base station 4520 is based on the teachings of the embodiments described throughout this disclosure. One or more of the various embodiments can improve the performance of OTT services provided to UE 4530 using an OTT connection 4550, in which the wireless connection 4570 forms the final segment. More specifically, the teachings of these embodiments can improve random access speed and / or reduce random access failure rate, and thus provide benefits such as faster and / or more reliable random access.

[0311] The measurement process can be provided for the purpose of monitoring data rates, latency, and other factors improved by one or more embodiments. Optional network functions may also exist for reconfiguring the OTT connection 4550 between the host computer 4510 and the UE 4530 in response to changes in measurement results. The measurement process and / or the network functions for reconfiguring the OTT connection 4550 may be implemented in the software 4511 and hardware 4515 of the host computer 4510, or in the software 4531 and hardware 4535 of the UE 4530, or both. In embodiments, sensors (not shown) may be deployed in or associated with communication equipment through which the OTT connection 4550 traverses; the sensors may participate in the measurement process by supplying values ​​of the monitored quantities illustrated above, or by supplying values ​​of other physical quantities that the software 4511, 4531 can calculate or estimate the monitored quantities. Reconfiguration of the OTT connection 4550 may include message formatting, retransmission settings, preferred routing, etc.; reconfiguration does not need to affect the base station 4520, and the reconfiguration may be unknown or imperceptible to the base station 4520. Such processes and functions are known and practiced in the art. In some embodiments, the measurement results may involve proprietary UE signaling that facilitates measurements of throughput, propagation time, latency, etc., of the host computer 4510. The measurements can be implemented in the software 4511 and 4531 such that messages (particularly empty or “fake” messages) are sent using the OTT connection 4550 while simultaneously measuring and monitoring propagation time, errors, etc.

[0312] Figure 21 Methods implemented in a communication system including a host computer, a base station, and a user equipment, according to some embodiments, are illustrated.

[0313] Figure 21 This is a flowchart illustrating a method implemented in a communication system according to one embodiment. The communication system includes a host computer, a base station, and a UE, which may be a reference... Figures 19 to 20 The host computer, base station, and UE described herein. For the sake of simplicity in this disclosure, only the host computer, base station, and UE are included in this section. Figure 21 Reference numerals are used in the accompanying drawings. In step 4610, the host computer provides user data. In sub-step 4611 of step 4610 (which may be optional), the host computer provides user data by executing a host application. In step 4620, the host computer initiates a transmission carrying user data to the UE. In step 4630 (which may be optional), in accordance with the teachings of the embodiments described throughout this disclosure, the base station sends the user data carried in the transmission initiated by the host computer to the UE. In step 4640 (which may also be optional), the UE executes a client application associated with the host application executed by the host computer.

[0314] Figure 22Methods implemented in a communication system including a host computer, a base station, and a user equipment, according to some embodiments, are illustrated.

[0315] Figure 22 This is a flowchart illustrating a method implemented in a communication system according to one embodiment. The communication system includes a host computer, a base station, and a UE, which may be a reference... Figures 19 to 20 The host computer, base station, and UE described herein. For the sake of simplicity in this disclosure, only the host computer, base station, and UE are included in this section. Figure 22 Reference numerals are used in the accompanying drawings. In step 4710 of the method, the host computer provides user data. In an optional sub-step (not shown), the host computer provides user data by executing a host application. In step 4720, the host computer initiates a transmission carrying user data to the UE. Based on the teachings of the embodiments described throughout this disclosure, the transmission may be carried out via a base station. In step 4730 (which may be optional), the UE receives the user data carried in the transmission.

[0316] Figure 23 Methods implemented in a communication system including a host computer, a base station, and a user equipment, according to some embodiments, are illustrated.

[0317] Figure 23 This is a flowchart illustrating a method implemented in a communication system according to one embodiment. The communication system includes a host computer, a base station, and a UE, which may be a reference... Figures 19 to 20 The host computer, base station, and UE described herein. For the sake of simplicity in this disclosure, only the host computer, base station, and UE are included in this section. Figure 23 Reference numerals are used in the accompanying drawings. In step 4810 (which may be optional), the UE receives input data provided by the host computer. Additionally or alternatively, in step 4820, the UE provides user data. In sub-step 4821 of step 4820 (which may be optional), the UE provides user data by executing a client application. In sub-step 4811 of step 4810 (which may be optional), the UE executes a client application that provides user data in response to the received input data provided by the host computer. When providing user data, the executed client application may also consider user input received from the user. Regardless of the specific manner in which user data is provided, in sub-step 4830 (which may be optional), the UE initiates the transmission of user data to the host computer. In step 4840 of the method, in accordance with the teachings of the embodiments described throughout this disclosure, the host computer receives user data sent from the UE.

[0318] Figure 24 Methods implemented in a communication system including a host computer, a base station, and a user equipment, according to some embodiments, are illustrated.

[0319] Figure 24 This is a flowchart illustrating a method implemented in a communication system according to one embodiment. The communication system includes a host computer, a base station, and a UE, which may be a reference... Figures 19 to 20 The host computer, base station, and UE described herein. For the sake of simplicity in this disclosure, only the host computer, base station, and UE are included in this section. Figure 24 Reference numerals are used in the accompanying drawings. In step 4910 (which may be optional), the base station receives user data from the UE in accordance with the teachings of the embodiments described throughout this disclosure. In step 4920 (which may be optional), the base station initiates a transmission of the received user data to the host computer. In step 4930 (which may be optional), the host computer receives the user data carried in the transmission initiated by the base station.

[0320] Any suitable steps, methods, features, functions, or benefits disclosed herein may be performed by one or more functional units or modules of one or more virtual devices. Each virtual device may include a plurality of such functional units. These functional units may be implemented via processing circuitry, which may include one or more microprocessors or microcontrollers, as well as other digital hardware, including digital signal processors (DSPs), application-specific digital logic, etc. The processing circuitry may be configured to execute program code stored in memory, which may include one or more types of memory, such as read-only memory (ROM), random access memory (RAM), cache memory, flash memory devices, optical storage devices, etc. The program code stored in memory includes program instructions for executing one or more telecommunications and / or data communication protocols and instructions for executing one or more of the techniques described herein. In some embodiments, the processing circuitry may be used to cause corresponding functional units to perform corresponding functions according to one or more embodiments of this disclosure.

[0321] As used herein, the term "unit" may have the conventional meaning in the field of electronic devices, electrical equipment, and / or electronic equipment, and may include, for example, electrical and / or electronic circuits, devices, modules, processors, memories, logic solid-state and / or discrete devices, computer programs or instructions for performing corresponding tasks, processes, calculations, outputs, and / or display functions, as described herein.

[0322] Further definitions and examples are discussed below.

[0323] In the above description of various embodiments of the inventive concept, it should be understood that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the inventive concept. Unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art to which the inventive concept pertains. It will also be understood that unless expressly defined herein, terms (such as those defined in commonly used dictionaries) should be interpreted as having the same meaning as in the context of this specification and the relevant field and will not be interpreted in an idealized or overly formal sense.

[0324] When an element is referred to as being “connected,” “coupled,” “responding,” or a variation thereof to another element, it may be directly connected, coupled, or responding to the other element, or an intermediate element may be present. Conversely, when an element is referred to as being “directly connected,” “directly coupled,” “directly responding,” or a variation thereof to another element, no intermediate element is present. The same numbers refer to the same element throughout. Furthermore, as used herein, “coupled,” “connected,” “responding,” or a variation thereof may include wireless coupling, connection, or response. As used herein, unless the context clearly indicates otherwise, the singular forms “a,” “an,” and “the” are intended to also include the plural forms. Well-known functions or structures may not be described in detail for the sake of brevity and / or clarity. The term “and / or” (abbreviated “ / ”) includes any and all combinations of one or more of the associated list items.

[0325] It will be understood that although the terms first, second, third, etc., may be used herein to describe various elements / operations, these elements / operations should not be limited by these terms. These terms are only used to distinguish one element / operation from another. Therefore, without departing from the teachings of the inventive concept, a first element / operation in some embodiments may be referred to as a second element / operation in other embodiments. The same reference numerals or the same reference indicators refer to the same or similar elements throughout the specification.

[0326] As used herein, the terms “comprising,” “including,” “having,” “possessing,” “having,” or variations thereof are open-ended and include one or more of the stated features, integrals, elements, steps, components, or functions, but do not exclude the presence or addition of one or more other features, integrals, elements, steps, components, functions, or combinations thereof. Furthermore, as used herein, the common phrase “for example,” derived from the Latin phrase “for instance,” can be used to introduce or specify a general example or illustration of previously mentioned items and is not intended to limit such items. The common phrase “that is,” derived from the Latin phrase “that is,” can be used to specify a particular item from a more general description.

[0327] This document describes exemplary embodiments with reference to block diagrams and / or flowcharts illustrating computer-implemented methods, apparatus (systems and / or devices), and / or computer program products. It should be understood that blocks in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented by computer program instructions executed by one or more computer circuits. These computer program instructions can be provided to processor circuitry of general-purpose computer circuitry, special-purpose computer circuitry, and / or other programmable data processing circuitry to generate a machine that causes instructions executed via a processor of a computer and / or other programmable data processing apparatus to transform and control transistors, values ​​stored in memory locations, and other hardware components within such circuitry to implement the functions / actions specified in the block diagrams and / or (one or more) flowcharts, thereby producing means (functions) and / or structures for implementing the functions / actions specified in the block diagrams and / or (one or more) flowcharts.

[0328] These computer program instructions may also be stored in a tangible computer-readable medium that can direct a computer or other programmable data processing apparatus to operate in a particular manner such that the instructions stored in the computer-readable medium produce an article of writing including instructions that implement the functions / actions specified in block diagrams and / or (one or more) flowchart blocks. Therefore, embodiments of the inventive concept can be implemented in hardware and / or software (including firmware, resident software, microcode, etc.) running on a processor (such as a digital signal processor), which may be collectively referred to as a "circuit," a "module," or a variation thereof.

[0329] It should also be noted that in some alternative embodiments, the functions / actions indicated in the boxes may not occur in the order shown in the flowchart. For example, two boxes shown consecutively may be executed substantially concurrently, or the boxes may sometimes be executed in reverse order, depending on the functions / actions involved. Moreover, the function of a given box in the flowchart and / or block diagram may be divided into multiple boxes, and / or the functions of two or more boxes in the flowchart and / or block diagram may be at least partially integrated. Finally, other boxes may be added / inserted between the boxes shown, and / or boxes / actions may be omitted without departing from the scope of the inventive concept. Furthermore, although some figures include arrows on communication paths indicating the main direction of communication, it should be understood that communication may occur in the direction opposite to the depicted arrows.

[0330] Many variations and modifications can be made to the embodiments without substantially departing from the principles of the inventive concept. All such variations and modifications are intended to be included within the scope of the inventive concept herein. Therefore, the subject matter disclosed above is to be considered illustrative rather than restrictive, and the examples of embodiments are intended to cover all such modifications, enhancements, and other embodiments falling within the spirit and scope of the inventive concept. Thus, to the fullest extent permitted by law, the scope of the inventive concept will be determined by the widest permissible interpretation of this disclosure, including examples of embodiments and their equivalents, and should not be limited or restricted by the foregoing detailed description.

[0331] The following provides explanations for the abbreviations from the above-mentioned public information.

[0332] Abbreviation Explanation

[0333] 1G First Generation

[0334] 2G Second Generation

[0335] 3G (Third Generation)

[0336] 3GPP Third Generation Partnership Project

[0337] 4G fourth generation

[0338] 5G (Fifth Generation)

[0339] AAA authentication, authorization, and accounting server

[0340] AIR Authentication Information Request

[0341] AMF Access and Mobility Management Functions

[0342] AUSF Authentication Server Functionality

[0343] CN Core Network

[0344] ECIES Elliptic Curve Integrated Encryption Scheme

[0345] Radio base stations in gNB NR

[0346] GSM Global Mobile Communication System

[0347] HN Home Network

[0348] IMS International Mobile Subscriber Identity

[0349] LTE Long Term Evolution

[0350] MAC Message Authentication Code

[0351] MCC Mobile Country Code

[0352] ME mobile devices

[0353] MNC Mobile Network Code

[0354] MNO mobile network operator

[0355] NAI Network Access Identifier

[0356] NAS Non-Access Layer

[0357] NR New Radio

[0358] RAN (Radio Access Network)

[0359] RRC Radio Resource Control

[0360] RSA Rivest-Shamir-Adleman

[0361] SBI Service-Based Interface

[0362] SEAF Safety Anchoring Function

[0363] SIDF Signature Identifier Hiding Functionality

[0364] SN service network

[0365] SUCI Contract Hidden Identifier

[0366] SUPI Permanent Contract Identifier

[0367] UDM Unified Data Management

[0368] UE (Wireless Equipment or User Equipment)

[0369] UMTS Universal Mobile Telecommunications Service

[0370] USIM (Universal User Identification Module)

Claims

1. A method for operating a user equipment (UE) in a wireless communication network, the method comprising: A padding identifier (710) is generated by inserting a padding bit string into a field of an identifier associated with the UE, wherein the identifier is a Subscription Permanent Identifier (SUPI), wherein the field of the SUPI includes at least one of the following: Mobile Subscriber Identity Number (MSIN); Username; Routing Identifier; Public Key Identifier; or Scheme Identifier, wherein generating the padding identifier includes padding at least one of the following: the MSIN; the Username; the Routing Identifier; the Public Key Identifier; or the Scheme Identifier, wherein generating the padding identifier includes inserting a delimiter before or after the padding bit string, the delimiter being a pre-positioned string that separates the padding bit string from the unpadded content in the field of the identifier, wherein the delimiter includes a first delimiter and a second delimiter, and wherein inserting the delimiter includes inserting the first delimiter before the padding bit string and inserting the second delimiter after the padding bit string; Encrypt (720) the padding identifier to produce a hidden padding identifier; and Send (730) the hidden padding identifier to the network node operating in the wireless communication network.

2. The method according to claim 1, wherein, The UE includes at least one of a Universal User Identity Module (USIM) and a Mobile Equipment (ME). The padding bit string includes one or more bits. The hidden padding identifier is the Subscription Hidden Identifier (SUCI).

3. The method according to any one of claims 1 to 2, wherein, Sending the hidden padding identifier to the network node operating in the wireless communication network includes: during the UE's operation of registering the UE with the wireless communication network, sending the hidden padding identifier to the network node operating in the wireless communication network.

4. The method according to any one of claims 1 to 2, further comprising: Receive a request for the identifier from the network node. Sending the hidden padding identifier to the network node operating in the wireless communication network includes: sending the hidden padding identifier to the network node operating in the wireless communication network in response to receiving the request from the network node.

5. The method according to any one of claims 1 to 2, wherein, Generating the padding identifier includes: The network node receives (810) a padding instruction, the padding instruction indicating that the UE can use to pad the identifier with at least one of the following: length, content, or the delimiter; and Based on the filling instruction, fill in (820) the identifier.

6. The method according to any one of claims 1 to 2, wherein, Generating the padding identifier includes: A fill instruction (910) is received from the user of the UE via the user interface of the UE, the fill instruction indicating that the identifier can be filled by the UE with at least one of the following: length, content, or the delimiter; and Based on the filling instruction, fill in (920) the identifier.

7. The method according to any one of claims 1 to 2, wherein, The wireless communication network includes a home network and a serving network, and the network nodes include home network nodes and serving network nodes. Sending the hidden padding identifier to the network node includes: sending the hidden padding identifier to the serving network node for partial decryption and then sending it from the serving network node to the home network node for further decryption.

8. A method for operating a network node in a wireless communication network, the method comprising: Determine (1010) a padding technique usable by a user equipment (UE) in the wireless communication network to insert a padding bit string into a field of the identifier before the UE encrypts an identifier associated with the UE, wherein the identifier is a Subscribed Permanent Identifier (SUPI), wherein the field of the SUPI includes at least one of the following: Mobile Subscriber Identification Number (MSIN); Username; Routing Identifier; Public Key Identifier; or Scheme Identifier, wherein the padding technique includes padding at least one of the following: the MSIN; the Username; the Routing Identifier; the Public Key Identifier; or the Scheme Identifier, wherein the padding technique includes inserting a delimiter before or after the padding bit string, the delimiter being a pre-positioned string that separates the padding bit string from the unpadded content in the field of the identifier, wherein the delimiter includes a first delimiter and a second delimiter, and wherein inserting the delimiter includes inserting the first delimiter before the padding bit string and inserting the second delimiter after the padding bit string; Receive (1020) hidden padding identifier from the UE; Decrypt (1030) the hidden padding identifier to generate the padding identifier; and Based on the padding technique, the content of the identifier (1040) separated from the padding bit string is determined.

9. The method according to claim 8, wherein, The UE includes at least one of a Universal User Identity Module (USIM) and a Mobile Equipment (ME). The padding bit string includes one or more bits. The hidden padding identifier is the Subscription Hidden Identifier (SUCI).

10. The method according to any one of claims 8 to 9, wherein, Determining the padding technique includes: determining (1110) the delimiter that can be inserted before or after the padding bit string, and The determination of the content of the identifier includes: Identify the delimiter (1142) in the filling identifier; and Remove the delimiter (1144) and the padding bit string before or after the delimiter.

11. The method according to any one of claims 8 to 9, further comprising: In response to determining the padding technique and before receiving the hidden padding identifier, a padding instruction is sent to the UE, the padding instruction notifying the UE of the padding technique.

12. The method according to any one of claims 8 to 9, wherein, Determining the padding technique includes: receiving a padding instruction, the padding instruction notifying the network node that the padding instruction can be used by the UE.

13. The method according to any one of claims 8 to 9, wherein, Receiving the hidden padding identifier from the UE includes receiving the hidden padding identifier from the UE as part of the UE's registration request to join the wireless communication network.

14. The method according to any one of claims 8 to 9, further comprising: Send a request for the identifier to the UE. Receiving the hidden padding identifier from the UE includes: receiving the hidden padding identifier from the UE in response to sending the request to the UE.

15. A user equipment (UE) (400) operating in a wireless communication network, comprising: Processing circuit (403); as well as A memory (405) coupled to the processing circuit and storing instructions therein, which can be executed by the processing circuit to cause the UE to perform the method of any one of claims 1 to 7.

16. A computer program product comprising a non-transitory storage medium, the non-transitory storage medium including program code to be executed by processing circuitry (403) of a user equipment (UE) (400) operating in a wireless communication network, wherein, The execution of the program code causes the UE to perform the method of any one of claims 1 to 7.

17. A network node (500, 600) operating in a wireless communication network, the network node comprising: Processing circuits (503, 603); as well as A memory (505, 605) coupled to the processing circuitry and storing instructions therein, which can be executed by the processing circuitry to cause the network node to perform the method of any one of claims 8 to 14.

18. A computer program product comprising a non-transitory storage medium, the non-transitory storage medium including program code to be executed by processing circuitry (503, 603) of a network node (500, 600) operating in a wireless communication network, wherein, The execution of the program code causes the network node to perform the method of any one of claims 8 to 14.