Configuration of a specific network slice

By providing frequency priority information and updating subscription data for specific services in the UE, the configuration problem of UE accessing specific services in non-public mobile networks is solved, and efficient network slicing access and stable registration process are achieved.

CN115362715BActive Publication Date: 2026-04-21LENOVO (SINGAPORE) PTE LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
LENOVO (SINGAPORE) PTE LTD
Filing Date
2020-04-07
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

In non-public mobile networks, how can UEs efficiently configure frequency priorities to access specific services and avoid registration failures and secondary authentication issues, especially when network slicing support is unclear?

Method used

By providing frequency priority information for specific services in the UE, combined with default subscription and update subscription data, and using UDM and AMF for configuration and cell reselection, the UE can be ensured to efficiently access specific network slices.

Benefits of technology

This enables UEs to efficiently access specific services in non-public mobile networks, reducing the risk of registration failures and secondary authentication, and improving system stability and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115362715B_ABST
    Figure CN115362715B_ABST
Patent Text Reader

Abstract

Apparatus, methods, and systems for utilizing information provision to a UE to access a specific service are disclosed. An apparatus 500 includes a transceiver 525 communicating with a mobile communication network and a processor 505 sending a first registration request 705 to the mobile communication network, the mobile communication network supporting multiple network slices. The processor 505 receives configuration information 705 from the mobile communication network, the configuration information enabling the apparatus to use at least one network slice from the multiple network slices, wherein the configuration information includes frequency priorities for the at least one network slice. The processor 505 performs cell reselection 715 using at least the frequency priorities, and after performing cell reselection, sends a second registration request 720 to the mobile communication network, wherein the second registration request registers with the at least one network slice.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The topics disclosed herein generally relate to wireless communication, and more specifically to, for example, configuring a UE for a specific service in a non-public mobile network. Background Technology

[0002] The following abbreviations and acronyms are defined herein, and at least some of them will be referenced in the following description.

[0003] 3rd Generation Partnership Project (“3GPP”), 5th Generation Core (“5GC”), Access and Mobility Management Function (“AMF”), Access Point Name (“APN”), Access Layer (“AS”), Application Programming Interface (“API”), Service Support System (“BSS”), Data Network Name (“DNN”), Downlink (“DL”), Enhanced Mobile Broadband (“eMBB”), Evolved Node B (“eNB”), Evolved Packet Core (“EPC”), Evolved UMTS Terrestrial Radio Access Network (“E-UTRAN”), Fully Qualified Domain Names (“FQDN”), Home Subscriber Server (“HSS”), IP Multimedia Subsystem (“IMS”, also known as “IP Multimedia Core Network Subsystem”), Internet Protocol (“IP”), Long Term Evolution (“LTE”), LTE-Advanced (“LTE-A”), Media Access Control (“MAC”), Mobile Network Operator (“MNO”), Mobility Management Entity (“MME”), Non-Access Stratum (“NAS”), Narrowband (“NB”), Network Functions (“NF”), Network Access Identifier (“NAI”), Next Generation (e.g., 5G) Node B (“FQDN”), Home Subscriber Server (“HSS”), IP Multimedia Subsystem (“IMS”, also known as “IP Multimedia Core Network Subsystem”), Internet Protocol (“IP”), Long Term Evolution (“LTE”), LTE-A Advanced (“LTE-A”), Media Access Control (“MAC”), Mobile Network Operator (“MNO”), Mobility Management Entity (“MME”), Non-Access Stratum (“NAS”), Narrowband (“NB”), Network Functions (“NF”), Network Access Identifier (“NAI”), Next Generation (e.g., 5G) Node B (“Non-Access Stratum”), gNB”, Next Generation Radio Access Network (“NG-RAN”), New Radio (“NR”), Operations Management and Maintenance (“OAM”), Policy Control Function (“PCF”), Packet Data Network (“PDN”), Packet Data Unit (“PDU”), PDN Gateway (“PGW”), Public Land Mobile Network (“PLMN”), Quality of Service (“QoS”), Radio Access Network (“RAN”), Radio Access Technology (“RAT”), Radio Resource Control (“RRC”), Receive (“Rx”), Single Network Slice Selection Auxiliary Signals Information (“S-NSSAI”), Serving Gateway (“SGW”), Session Management Function (“SMF”), Subscription Permanent Identifier (“SUPI”), Transmission Control Protocol (“TCP”), Transmission (“Tx”), Unified Data Management (“UDM”), User Entity / Equipment (Mobile Terminal) (“UE”), Uplink (“UL”), User Plane (“UP”), Universal Mobile Telecommunications System (“UMTS”), User Datagram Protocol (“UDP”), Wireless Local Area Network (“WLAN”), and Global Microwave Access Interoperability (“WiMAX”).

[0004] In some embodiments, a non-public network (NPN) is deployed to serve dedicated (i.e., non-public) customers and / or services. If the NPN has an agreement with a PLMN or is connected to a PSTN, it can also provide public services (public telephone service or emergency services). Summary of the Invention

[0005] Methods for providing information to a UE to access a specific service are disclosed. Apparatus and systems also perform the functions of these methods.

[0006] A method for a UE, for example, to provide information to the UE to access a specific service, includes sending a first registration request to a mobile communication network, the mobile network supporting multiple network slices. The method includes receiving configuration information from the mobile communication network, the configuration information enabling the UE to use at least one network slice from the multiple network slices, wherein the configuration information includes frequency priorities for the at least one network slice. The method includes performing cell reselection using at least the frequency priorities, and sending a second registration request to the mobile communication network after performing the cell reselection, wherein the second registration request registers with the at least one network slice.

[0007] A method of AMF, for example, for supplying a UE with information to access a specific service, includes receiving a first registration request to register the UE with a mobile communication network. The method includes receiving subscription information of the UE from the mobile communication network and determining configuration information to supply the UE. Here, the subscription information and configuration information enabling the UE to use the specific service include at least frequency priorities for each of a plurality of network slices. The method includes supplying the UE with the configuration information and receiving a second registration request from the UE in response to supplying the UE.

[0008] A method of UDM, for example, for supplying information to a UE to access a specific service, includes storing at least default subscription information and updated subscription information for the UE. Here, the default subscription information enables the UE to access a default service, and the updated subscription information enables the UE to use a specific service. The method includes receiving a request for subscription data for the UE from an AMF, and determining the type of subscription data that the UE needs to be supplied and determining the type of subscription data to be sent to the AMF. Here, the type of subscription data can be either default subscription information or updated subscription information. The method also includes sending subscription data to the AMF to configure the UE and the network (e.g., the AMF and RAN) to use a specific service. Attached Figure Description

[0009] A more specific description of the embodiments briefly described above will be presented with reference to specific embodiments illustrated in the accompanying drawings. It should be understood that these drawings depict only a few embodiments and should not be considered as limiting the scope. The embodiments will be described and explained with additional specificity and detail using the drawings, in which:

[0010] Figure 1 This is a block diagram illustrating an embodiment of a wireless communication system for supplying information to a UE to access a specific service;

[0011] Figure 2 This diagram illustrates one embodiment of a network deployment used to supply information to a UE to access a specific service;

[0012] Figure 3A This is a signal flow diagram illustrating one embodiment of signaling used to supply a UE with new service subscription data;

[0013] Figure 3B yes Figure 3A The continuation of the process described in the text;

[0014] Figure 3C yes Figures 3A to 3B The continuation of the process described in the text;

[0015] Figure 4A This is a signal flow diagram illustrating one embodiment of the signaling process for activating / deactivating a UE service subscription;

[0016] Figure 4B yes Figure 5 A continuation of the process described in section A;

[0017] Figure 4C yes Figure 5 A continuation of the process described in A through 5B;

[0018] Figure 5 This is a block diagram illustrating one embodiment of a user equipment apparatus for supplying information to a UE to access a specific service;

[0019] Figure 6 This is a block diagram illustrating one embodiment of a network device apparatus for supplying information to a UE to access a specific service;

[0020] Figure 7 This is a flowchart illustrating an embodiment of a first method for providing information to a UE to access a specific service;

[0021] Figure 8 This is a flowchart illustrating an embodiment of a second method for providing information to a UE to access a specific service; and

[0022] Figure 9This is a flowchart illustrating an embodiment of a third method for providing information to a UE to access a specific service. Detailed Implementation

[0023] As those skilled in the art will understand, aspects of the embodiments can be embodied as a system, apparatus, method, or program product. Therefore, embodiments can take the form of a completely hardware embodiment, a completely software embodiment (including firmware, resident software, microcode, etc.), or an embodiment combining software and hardware aspects.

[0024] For example, the disclosed embodiments can be implemented as hardware circuits including custom-designed very large-scale integrated circuit (“VLSI”) circuits or gate arrays, such as logic chips, transistors, or other discrete components of off-the-shelf semiconductors. The disclosed embodiments can also be implemented in programmable hardware devices such as field-programmable gate arrays, programmable array logic, programmable logic devices, etc. As another example, the disclosed embodiments may include one or more physical or logical blocks of executable code, which may, for example, be organized as objects, procedures, or functions.

[0025] Furthermore, embodiments may take the form of a program product embodied in one or more computer-readable storage devices stored in machine-readable code, computer-readable code, and / or program code, referred to below as code. The storage device may be tangible, non-transitory, and / or non-transferable. The storage device may not embody signals. In one embodiment, the storage device employs only signals for accessing the code.

[0026] Any combination of one or more computer-readable media may be used. A computer-readable medium may be a computer-readable storage medium. A computer-readable storage medium may be a storage device for storing code. A storage device may be, for example, but not limited to, electronic, magnetic, optical, electromagnetic, infrared, holographic, micromechanical, or semiconductor systems, apparatuses, or devices, or any suitable combination thereof.

[0027] More specific examples of storage devices (a non-exhaustive list) will include the following: electrical connections having one or more cables, portable computer disks, hard disks, random access memory (“RAM”), read-only memory (“ROM”), erasable programmable read-only memory (“EPROM” or flash memory), portable optical disc read-only memory (“CD-ROM”), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing. In the context of this document, a computer-readable storage medium can be any tangible medium capable of containing or storing programs for use by or in connection with an instruction execution system, apparatus, or device.

[0028] References to "an embodiment," "embodiment," or similar language in this specification mean that a particular feature, structure, or characteristic described in connection with that embodiment is included in at least one embodiment. Therefore, unless expressly specified otherwise, throughout this specification, the phrases "in an embodiment," "in an embodiment," and similar language may, but not necessarily all, refer to the same embodiment, but rather mean "one or more, but not all, embodiments." Unless expressly specified otherwise, the terms "comprising," "including," "having," and variations thereof mean "including, but not limited to,". Unless expressly specified otherwise, the list of enumerated items does not imply that any or all items are mutually exclusive. Unless expressly specified otherwise, the terms "a," "an," and "the" also mean "one or more".

[0029] As used herein, a list connected with "and / or" includes any single item in the list or a combination of items in the list. For example, a list of A, B, and / or C includes only A, only B, only C, a combination of A and B, a combination of B and C, a combination of A and C, or a combination of A, B, and C. As used herein, a list using the term "one or more of" includes any single item in the list or a combination of items in the list. For example, one or more of A, B, and C includes only A, only B, only C, a combination of A and B, a combination of B and C, a combination of A and C, or a combination of A, B, and C. As used herein, a list using the term "one of" includes one and only one of any single item in the list. For example, "one of A, B, and C" includes only A, only B, or only C and excludes combinations of A, B, and C. As used herein, "selected from the group consisting of A, B, and C" includes one and only one of A, B, or C and excludes combinations of A, B, and C. As used in this article, “selecting members of a group consisting of A, B, and C and their combinations” includes only A, only B, only C, combinations of A and B, combinations of B and C, combinations of A and C, or combinations of A, B, and C.

[0030] Furthermore, the features, structures, or characteristics of the described embodiments can be combined in any suitable manner. In the following description, numerous specific details, such as examples of programming, software modules, user selection, network transactions, database queries, database structures, hardware modules, hardware circuits, hardware chips, etc., are provided to provide a thorough understanding of the embodiments. However, those skilled in the art will recognize that the embodiments can be practiced without one or more specific details, or using other methods, components, materials, etc. In other instances, well-known structures, materials, or operations have not been shown or described in detail to avoid obscuring aspects of the embodiments.

[0031] The following description of aspects of embodiments is based on schematic flowcharts and / or schematic block diagrams of methods, apparatus, systems, and program products according to embodiments. It will be understood that each block of the schematic flowcharts and / or schematic block diagrams, and combinations of blocks in the schematic flowcharts and / or schematic block diagrams, can be implemented by code. This code can be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus to generate a machine, such that instructions executable via the processor of the computer or other programmable data processing apparatus create means for implementing the functions / actions specified in the schematic flowcharts and / or schematic block diagrams.

[0032] The code can also be stored in a storage device that can instruct a computer, other programmable data processing device or other device to operate in a particular manner, such that the instructions stored in the storage device produce an article of art including instructions that implement the functions / actions specified in the schematic flowchart and / or schematic block diagram.

[0033] The code may also be loaded onto a computer, other programmable data processing apparatus or other device, causing a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer-implemented process, such that the code executing on the computer or other programmable apparatus provides a process for implementing the function / action specified in the schematic flowchart and / or schematic block diagram.

[0034] The schematic flowcharts and / or schematic block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, system, method, and program products according to various embodiments. In this regard, each block in the schematic flowcharts and / or schematic block diagrams may represent a module, segment, or portion of code, which includes one or more executable instructions for implementing one or more specified logical functions.

[0035] It should also be noted that in some alternative embodiments, the functions annotated in the boxes may occur in a different order than those annotated in the figures. For example, two boxes shown successively may actually be performed substantially simultaneously, or these boxes may sometimes be performed in reverse order, depending on the functionality involved. Other steps and methods that are functionally, logically, or effectively equivalent to one or more boxes or portions thereof in the illustrated figures are conceivable.

[0036] The description of the elements in each figure can be referenced to the elements in the preceding figures. Throughout all figures, the same reference numerals refer to the same elements, including alternative embodiments of the same elements.

[0037] Methods, apparatus, and systems for providing information to a UE to access a specific service are disclosed.

[0038] A Non-Public Network (NPN) is a network deployed with respect to a 5G system (5GS) to serve dedicated (i.e., non-public) customers and / or services. If the NPN has an agreement with a PLMN or accesses the PSTN, it can also provide public services (public telephone service or emergency service). NPNs can be deployed in different ways, such as 1) Standalone (SNPN) or 2) Public Network Integration (PNI-NPN). An SNPN can be operated by the NPN operator without relying on network functionality provided by the PLMN. In contrast, a PNI-NPN is deployed via a Public Land Mobile Network (PLMN) using a Private Data Network Name (DNN) or through one (or more) network slice instances allocated to the NPN. In the case of a PNI-NPN, the UE has a subscription to the PLMN. Typically, a network customer can request the PLMN to set up a PNI-NPN to use specific customer services. The network customer is referred to as an "NPN customer" in this specification.

[0039] A UE can have a default subscription for a network (e.g., a PLMN or SNPN provided in the UE and the network). With a default subscription, the UE can register to the PLMN for some default services, but the UE will not be able to use NPN customer services. For example, an NPN customer can purchase equipment provided with a default subscription for a given PLMN. To use NPN customer services (e.g., provided via PNI-NPN), equipment should be provided accordingly to enable NPN customer service.

[0040] In another scenario, it's possible to deploy specific customer services (via PNI-NPN or dedicated network slicing) in a specific frequency band. For example, cells in this frequency band can be reserved for one or more specific customer services (NPN services) implemented via network slicing. One of the attributes in the GST documented in GSMA 5GJA NG.116 is "Radio Spectrum," and it is defined as "This attribute defines the radio spectrum supported by network slicing. This is important information because some terminals may be restricted in terms of the frequencies they can use." This attribute can be used by network slicing customers to request which frequencies can be used to access the network slice.

[0041] The UE will have to attempt to select 5G-AN until S-NSSAI is permitted, without knowing whether 5G-AN supports it. However, one issue in this scenario is how to configure the UE for a specific frequency band for a particular customer service. For example, the UE has a default subscription to the PLMN and needs to be provisioned with dedicated subscription / configuration parameters. Currently, the UE performs network selection and cell selection procedures without considering network slice support (or network slice configuration within the network). However, it is unclear how to provision (i.e., reconfigure or onboard) the UE to efficiently use specific services (e.g., specific slices for NPN customers) with minimal impact on the 5GS system. See the reference below. Figures 3A to 3C Describe the solution used for supplying UE.

[0042] Additionally, it is unclear how to avoid registration failures for specific services (e.g., specific S-NSSAI / DNN) due to failed secondary authentication and authorization. See the reference below. Figures 4A to 4C Describe a solution to avoid registration failure.

[0043] In 3GPP Release 16, it is specified that HPLMN can configure or reconfigure a Closed Access Group (CAG) identifier for a UE to access a specific reserved radio cell for PNI-NPN. A Closed Access Group (CAG) can be used to apply access control for PNI-NPN. A CAG identifies a group of subscribers that are permitted to access a CAG cell. A CAG is used to prevent a UE that is not permitted to access PNI-NPN via an associated cell from selecting and accessing an associated cell. CAG information can be 1) pre-provided in the UE or 2) configured in the UE using the UE configuration update procedure for access and mobility management related parameters as described in Clause 4.2.4.2 of TS 23.502 [3].

[0044] This disclosure describes how subscription-related information (e.g., S-NSSAI, DNN, equivalent PLMN, preferred frequency per PLMN) can be provided in the UE. The proposed solution is based on the following assumptions:

[0045] 1) The UE has a default subscription / credential that allows access to the default services of a network (e.g., PLMN or SNPN). This network can be referred to as the default subscription owner network.

[0046] 2) The default subscription owner network (e.g., PLMN or SNPN) stores the default subscription / credentials that allow the UE to be authenticated and authorized to access default services (e.g., IP connections to the Internet and SMS).

[0047] 3) The default subscription owner network (e.g., PLMN, SNPN) enters into a service agreement with a specific service customer (e.g., NPN customer or service) to update / provision some UEs to use a specific service.

[0048] The main idea of ​​the solution is that the default subscription owner network (e.g., the UDR or UDM of a PLMN) is configured with: 1) a list of default subscribers (UEs with default subscriptions) to log in for a specific network service (e.g., where an NPN customer or slice customer is a service provider) and 2) new service subscription data specific to the network service customer. The new service subscription data can be stored separately from the default subscription data (i.e., the default subscription data corresponds to the current UE default configuration). A specific network service may require the use of at least one of the following: a dedicated S-NSSAI or a dedicated DNN or a newly allowed CAG list or a new PLMN list.

[0049] Figure 1 A wireless communication system 100 for registering with a mobile network via another mobile network is depicted according to embodiments of the present disclosure. In one embodiment, the wireless communication system 100 includes at least one remote unit 105, at least one base station unit 110, at least one access network (“AN”) 115, a mobile core network 130 in a PLMN, and a non-public network (“NPN”) service 140. AN 115 may be comprised of at least one base station unit 110. The remote unit 105 may communicate with the access network 115 using 3GPP communication links and / or non-3GPP communication links, depending on the radio access technology deployed by AN 115. Although Figure 1 The document describes a specific number of remote units 105, base station units 110, AN 115, mobile core network 130, and NPN services 140, but those skilled in the art will recognize that the wireless communication system 100 may include any number of remote units 105, base station units 110, AN 115, mobile core network 130, and NPN services 140.

[0050] In one implementation, the wireless communication system 100 conforms to the 5G system specified in the 3GPP specification. However, more generally, the wireless communication system 100 may implement other open or proprietary communication networks, such as LTE / EPC (referred to as 4G) or WiMAX, and other networks. This disclosure is not intended to be limited to any particular wireless communication system architecture or protocol implementation.

[0051] In one embodiment, remote unit 105 may include computing devices such as desktop computers, laptop computers, personal digital assistants (“PDAs”), tablet computers, smartphones, smart TVs (e.g., internet-connected TVs), smart appliances (e.g., internet-connected appliances), set-top boxes, game consoles, security systems (including security cameras), in-vehicle computers, network devices (e.g., routers, switches, modems), etc. In some embodiments, remote unit 105 includes wearable devices such as smartwatches, fitness bands, optical head-mounted displays, etc. Furthermore, remote unit 105 may be referred to as a UE, subscriber unit, mobile, mobile station, user, terminal, mobile terminal, fixed terminal, subscriber station, user terminal, wireless transmit / receive unit (“WTRU”), device, or by other terms used in the art.

[0052] Remote unit 105 can directly communicate with one or more base station units 110 in access network 115 via uplink (“UL”) and downlink (“DL”) communication signals. Furthermore, the UL and DL communication signals can be carried on communication link 113. Note that access network 115 is an intermediate network providing remote unit 105 with access to mobile core network 130 and / or NPN service 140. Note that NPN service 140 can be provided via PNI-NPN 141, which is implemented via access network 115 and mobile core network 130. In some embodiments, NPN service 140 can be provided via standalone NPN (SNPN), which... Figure 1 It is not shown in the document.

[0053] In some embodiments, remote unit 105 communicates with an application server (or other communication peer) via a network connection to mobile core network 130 and / or PNI-NPN 141. For example, an application in remote unit 105 (e.g., a web browser, media client, telephony / VoIP application) can trigger remote unit 105 to establish a PDU session (or other data connection) with mobile core network 130 using access network 115. Mobile core network 130 then uses the PDU session to relay traffic between remote unit 105 and data network 150 (e.g., the application server). Note that remote unit 105 may establish one or more PDU sessions (or other data connections) with mobile core network 130. Accordingly, remote unit 105 may have at least one PDU session for communicating with data network 150. Remote unit 105 may establish additional PDU sessions for communicating with other data networks and / or other communication peers.

[0054] As discussed in further detail below, the signaling connection between remote unit 105 and mobile core network 130 can be used to register remote unit 105 with mobile core network 130. Specifically, remote unit 105 can use the signaling connection to register with mobile core network 130 in order to receive configuration information for updated connectivity to NPN service 140, as described in further detail below.

[0055] Base station unit 110 may be distributed across a geographical area. In some embodiments, base station unit 110 may also be referred to as an access terminal, access point, base station, base station, node B, eNB, gNB, home node B, relay node, device, or any other term used in the art. Base station unit 110 is typically part of a radio access network (“RAN”) such as access network 115, which may include one or more controllers communicatively coupled to one or more corresponding base station units 110. These and other elements of the radio access network are not illustrated but are generally well known to those skilled in the art. Base station unit 110 is connected to mobile core network 130 and NPN service 140 via access network 115.

[0056] Base station unit 110 can serve multiple remote units 105 within a service area, such as a cell or cell sector, via communication link 113. Base station unit 110 can communicate directly with one or more remote units 105 via communication signals. Typically, base station unit 110 transmits DL communication signals to serve remote units 105 in the time, frequency, and / or spatial domains. Furthermore, DL communication signals can be carried on communication link 113. Communication link 113 can be any suitable carrier in the licensed or unlicensed radio spectrum. Communication link 113 facilitates communication between one or more remote units 105 and / or one or more base station units 110.

[0057] In one embodiment, the mobile core network 130 is a 5G core (“5GC”) or an evolved packet core (“EPC”) that can be coupled to a data network (e.g., data network 150, such as the Internet and private data networks, as well as other data networks). The remote unit 105 may utilize the public mobile core network 130 and have a subscription or other account. Furthermore, the remote unit 105 may have a subscription or other account with PNI-NPN 141. This disclosure is not intended to limit implementation to any particular wireless communication system architecture or protocol.

[0058] Mobile core network 130 includes several network functions (“NFs”). As depicted, mobile core network 130 includes at least one user plane function (“UPF”) 131 that serves access network 115. Mobile core network 130 also includes multiple control plane functions, including but not limited to access and mobility management functions (“AMF”) 133, session management functions (“SMF”) 135, internal provisioning server (“I-PS”) 136, policy control functions (“PCF”) 137, network exposure functions 138, and unified data management / unified data repository (“UDM / UDR”) 139. In some embodiments, mobile core network 130 may also include authentication server functions (“AUSF”), network repository functions (“NRF”) (used by various NFs for discovery and communication with each other via API), or other NFs defined for 5GC. PNI-NPN 141 is implemented by access network 115 and mobile core network 130.

[0059] PNI-NPN 141 is a non-public network integrated with a public network. Note that PNI-NPN 141 may share spectrum with the PLMN or may have a different operating frequency than the PLMN. In various embodiments, PNI-NPN 141 shares RAN 115 with the PLMN but maintains a core network separate from the mobile core network 130. Here, PNI-NPN 141 may include one or more U-plane NFs and one or more C-plane NFs as described above. In some embodiments, PNI-NPN 141 also shares a control plane with the PLMN. Here, one or more C-plane NFs in the mobile core 130 may serve both the PLMN and PNI-NPN 141. In some embodiments, PNI-NPN 141 also shares a user plane with the PLMN. Here, one or more U-plane NFs in the mobile core 130 may serve both the PLMN and PNI-NPN 141. In some embodiments, PNI-NPN 141 is implemented as a network slice within the mobile core 130.

[0060] In various embodiments, the mobile core network 130 supports different types of mobile data connections and different types of network slices, wherein each mobile data connection utilizes a specific network slice. Each network slice includes a set of CP and UP network functions, wherein each network slice is optimized for a certain type of service or service category. For ease of illustration, in Figure 1Different network slices are not shown, but their support is assumed. In one example, each network slice includes SMF135 and UPF 131, but the individual network slices share AMF 133, PCF 137, and UDM 139. In another example, each network slice includes AMF 133, SMF 135, and UPF 131. Although in Figure 1 A specific number and type of network functions are described, but those skilled in the art will recognize that any number and type of network functions may be included in the mobile core network 130.

[0061] To utilize information provided to remote unit 105 (i.e., UE) for NPN service 140, this disclosure proposes a solution that enables remote unit 105 to receive updated configuration information after registering with mobile core network 130. Note that mobile core network 130 is the default subscription owner of remote unit 105. In various solutions, UDM / UDR 139 or internal provisioning server (I-PS) 136 is configured with: 1) a list of default subscribers (UEs with default subscriptions) to log in for a specific network service (e.g., where NPN customers or slice customers are service providers) and 2) new service subscription data specific to the network service customer. The new service subscription data may be stored separately from the default subscription data (i.e., the default subscription data corresponds to the current UE default configuration). A specific network service may require the use of at least one of the following: a dedicated S-NSSAI or a dedicated DNN or a newly allowed CAG list or a new PLMN list.

[0062] The following examples or use cases are covered by the proposed solution: 1) A network slice customer (e.g., an enterprise (similar to a utility company) or service provider) has subscribed to use a PLMN (or SNPN) service and a dedicated network slice is provided to the customer. 2) An NPN customer is using a PNI-NPN, such as an NPN service integrated into the PLMN. In other words, the PLMN identifies a remote unit 105 with a default subscription to log in for a new service (e.g., PNI-NPN). The PLMN (e.g., UDM / UDR139) identifies the remote unit 105 to log in (based on a configured list) and the network (e.g., UDM / UDR139) performs a process to update the subscription parameters of the remote unit 105. 3) An NPN customer uses an SNPN managed by the PLMN operator. The SNPN subscription data of the remote unit 105 in the network is stored in the corresponding SNPN, but the PLMN can use its provisioning server (and other provisioning infrastructure) to provision the remote unit 105 to use the SNPN using the subscription profile. In all the above cases, when remote unit 105 is unreachable, i.e., when remote unit 105 is in a deregistered state, the subscription data of remote unit 105 can be updated in the network.

[0063] During the (initial or mobility) registration process, UDM / UDR 139 may determine to supply remote unit 105 with information such as S-NSSAI, DNN, and cell selection information parameters. UDM / UDR 139 then triggers a UE parameter update process to configure the remote unit 105 with the new UE configuration information. Upon receiving the new (updated) information, remote unit 105 triggers a re-registration process for the mobile core network 130 to apply the new UE configuration information.

[0064] The new UE configuration information may include at least one of the following: A) a new or updated S-NSSAI; B) a new or updated DNN; C) a list of allowed CAGs; D) a preferred frequency (or target carrier frequency per S-NSSAI) for cell selection to choose the correct cell to provide a specific service; and E) security parameters (identifiers and security credentials) for service subscription (i.e., associated with the S-NSSAI / DNN). Note that the security parameters may be stored in the mobile core network 130 (i.e., in the UDM / UDR 139).

[0065] In various embodiments, if a vertical client (e.g., an NPN client as a third party or the PLMN's own service) requires secondary authentication, or if the subscription profile of remote unit 105 needs to be updated (e.g., USIM provisioning), one of the following processes can be used: A) The updated (e.g., service / vertical subscription) is activated in the network and provided to the UE after providing the UE with security information for secondary authentication / authorization (SAA) or IMS authentication associated with the updated service subscription; B) The UDM determines whether a U-plane or C-plane connection is desired for a particular UE. Here, the provisioning connection type (U-plane or C-plane) can be determined based on a request from the provisioning server.

[0066] If security parameters are supplied from an external provisioning server (E-PS), the E-PS can subscribe to a network notification (e.g., via NEF 138) when remote unit 105 is reachable via the control plane. Upon receiving notification of remote unit reachability, the E-PS initiates a process for supplying UE ID / credentials for communication between remote unit 105 and the E-PS. In one embodiment, this is similar to providing data from the E-PS via non-IP data delivery (“NIDD”) communication via NEF 138 and AMF 133.

[0067] Figure 2 The diagram depicts a network deployment 200 including UE 205, which registers with 5G system 201 (i.e., PLMN) via access network 207. New subscription data is provisioned to 5G system 201 using PNI-NPN 220. Recall that PNI-NPN 220 can be deployed using a Private Data Network Name (DNN) 221 or via one or more Private Network Slice instances 223 allocated to the NPN. In various embodiments, PNI-NPN service 220 includes application functions and / or external provisioning servers (shown as AF / E-PS 225) that provide service requests to 5G system 201. Service requests are translated into subscription data and / or configuration parameters in the 5GS. Updated subscription data and NPN configuration parameters can be stored in UDM 213. PCF 215 can derive policy rules, i.e., UE routing policy (“URSP”) rules, using the updated subscription data and / or NPN-specific configuration parameters. When UE205 registers with 5G system 201 via AMF 211, UDM 213 and AMF 211 supply UE 205 with updated configuration information, as shown below. Figures 3A to 3C And 4A to 4C in more detail. The updated configuration information enables UE 205 to use specific services.

[0068] UE 205 can receive updated configuration information, including frequency resources associated with the network slice identifier (which will be stored in subscription information and / or ME configuration data). Additionally, UE 205 can perform a cell (re)selection procedure (considering the frequency resources of the selected slice to be requested) and initiate a registration procedure to request access to the selected slice.

[0069] AMF 211 can receive requests for a device ID (e.g., a PEI from UDM 213) and respond with the device ID of UE 205. AMF 211 can be configured with frequency information associated with a network slice ID (e.g., via an OAM system or from the NSSF). AMF 211 can derive new slice configuration information to be sent to UE 205; however, the slice configuration information includes at least the frequency priority associated with the network slice. If AMF 211 sends a newly configured NSSAI to UE 205 that needs to re-register UE 205, AMF 211 can defer (i.e., omit) the NSSAA (S-NSSAI for subscriptions requiring NSSAA). As a result, AMF 211 also omits including pending NSSAIs in the registration acceptance message.

[0070] UDM 213 may receive (e.g., from the OAM system or NEF 219) and maintain at least one of the following: 1) a list of device identities (e.g., UEs identified via SUPI, PEI, MSISDN, or external ID) for supplying subscription information for a specific (vertical or NPN) service; 2) a second type of subscription information (e.g., subscription information for a specific service) to enable UE 205 to use the specific service.

[0071] UDM 213 can determine whether UE 205 is the subject of provisioning by mapping signaling exchanges during the registration process (e.g., subscription retrieval from AMF 211) to the received identity list. UDM 213 can determine whether provisioning is performed using the U-plane or the C-plane. UDM 213 can perform a UE parameter update process based on service subscription information and new configuration information.

[0072] Figures 3A to 3C This disclosure describes a process 300 for using information provisioning to enable UE 205 to access a specific service, according to embodiments of the present disclosure. Process 300 relates to UE 205 (e.g., an embodiment of remote unit 105), RAN 207, AMF 211, UDM 213, and PCF 215. Process 300 details how the signaling flow of UE 205 can be configured (or reconfigured) based on specific service subscription data. Note that... Figures 3A to 3CThis demonstrates how various alternatives can be (re)configured for UE 205 based on specific service subscription data (corresponding to vertical subscriptions in UDM 213). The choice of which alternative to apply depends on when UDM213 triggers the UE service subscription update process.

[0073] Note that Application Functionality (“AF”) or External Provisioning Server (“E-PS”) is intended to refer to a vertical / service provider, such as a network slice customer like an enterprise or NPN customer. Note that an E-PS can also be considered an AF from a 5GS perspective. An AF can reside in a third party with whom the network operator may or may not have a trusted relationship (e.g., outside the service network domain).

[0074] refer to Figure 3A Process 300 begins with step 0, where UE 205 stores (i.e., maintains) its subscription to the PLMN (see box 301). This subscription (USIM profile) can be called the default subscription and can be stored in the UICC (eUICC) or in the secure storage (secure element) within the ME portion of UE 205. The default subscription allows UE 205 to use default services in the PLMN (or in the roaming partner's network). For example, UE 205 can obtain IP connectivity to the Internet, SMS services, and / or other control plane services.

[0075] In step 1, the network (5GC, or UDM, or UDR, or USIM internal provisioning server) is configured with subscription information (see box 303). Here, the subscription information includes at least the following: 1) a default subscription corresponding to the default subscription profile in the UE and 2) a second type of subscription information for providing specific services to one or more UEs. It is assumed that the network (i.e., RAN, 5GC NF) has been configured (e.g., by the OAM system) to provide the corresponding network slice (identified via S-NSSAI) and / or data network (identified via DNN). See below for reference. Figure 4A Describes the details of the subscription information for the network provisioning / configuration service.

[0076] Service subscriptions (e.g., vertical subscription information) are associated with one or more of the following: service ID; associated S-NSSAI and / or DNN; and the external ID of the UE (e.g., the one to be provisioned / updated). Alternatively, an external group ID can be used, however, the external group ID is associated with the group of the UE to be provisioned / updated. The external ID can have the following forms: A) global or external subscriber identity; or B) hardware identity. Examples of global / external subscriber identities include: Universal Public Subscription Identifier (GPSI) and Integrated Services Digital Network Number for Mobile Subscribers (MSISDN, e.g., telephone number). Here, the external ID can be in the form of a Network Access Identifier (NAI) with a syntax similar to “user@realm”. Examples of hardware identities include: International Mobile Station Equipment Identity (IMEI) and Permanent Equipment Identity (PEI). If the hardware identity is used as the external ID, specific behavior is described below. Figure 2 Step 1 in the document details how to provide a service subscription to UDM 213.

[0077] UDM 213 stores at least one of the following: Option 1: UDM 213 stores both A) UE default subscription data and B) updated subscription data, which are stored separately. By storing or processing the two types of subscription data separately, UDM 213 can first apply the default subscription data to allow successful UE registration with the default subscription profile. Subsequently, UDM 213 can trigger a subscription data update process for AMF, which includes updating the subscription data with service subscription.

[0078] Option 2: Update the UE subscription data based on step 1. The subscription data will have the flag "Subscription Change" that will be indicated to the AMF.

[0079] Vertical subscription information can include at least one of the following: slice subscription information [including preferred frequencies per S-NSSAI], mobility restrictions (permitted CAG information), and connection type for USIM provisioning [C-plane or U-plane]. Some vertical subscription information may be UE- and network-related (i.e., should be provided to the UE and AMF), while other vertical subscription information may be UE-related only.

[0080] In the case of UE-related vertical subscription information only, independent of option 1 or option 2, UDM 213 can provide the resulting configuration / provisioning information to the UE. This information can be at least one of the following: the default configured NSSAI, security parameters (associated with a specific application or slice / DNN), and the default connection type [C-plane or U-plane] used to provision the UE USIM or to provision security parameters associated with the application of the UE. The provisioning of UE-related vertical subscription information to the UE is illustrated in step 5 (Alternative D).

[0081] In step 2a, the UE initiates a registration procedure for the selected network based on the default USIM data in UE 205 (see message 305). If this is an initial registration request, the UE will include the SUCI. In step 2b, the network (e.g., AMF and AUSF) performs a network (i.e., primary) access authentication and authorization procedure (see message 307). In one embodiment, the network performs the primary access authentication and authorization procedure as specified in 3GPP TS 23.501 / TS33.501.

[0082] Step 3 illustrates the signaling for alternative A 309 for UE configuration based on service subscription data. In step 3a, the AMF retrieves the UE subscription from UDM 213 (see box 311). The current AMF may retrieve partial UE subscription data (e.g., access and mobility subscription data or network slice subscription data) to determine whether the current AMF is capable of serving the UE and whether AMF relocation is required. The AMF uses the Nudm_SDM_Get operation. If AMF relocation is required due to the subscribed S-NSSAI, the current AMF performs an AMF relocation to the target AMF. The target AMF (or the current AMF if no AMF relocation is required) retrieves the entire UE subscription data (shown in step 5a).

[0083] In alternative A 309, UDM 213 provides a default subscription, i.e., subscription data corresponding to the default configuration in the UE. The UDM responds with a Nudm_SDM_Get response that sends the UE subscription data. The UDM can send the default UE subscription data to the AMF, i.e., without including vertical subscription information. In this case, the UDM maintains an internal flag that the UE's subscription data will be updated later (e.g., in step 3d). For example, this later point in time could be after a successful registration process. After the AMF successfully registers with the UDM as the serving AMF, the UDM will trigger a UE subscription data update (notification request) sent to the serving AMF.

[0084] In step 3b, at some point after successful registration, AMF 211 notifies UDM 213 that AMF 211 is the serving AMF for this UE 205 and that AMF 211 subscribes to further notifications related to the subscription data (see Message Passing 313). AMF 211 can subscribe to further notifications using the Nudm_SDM_Subscribe() service operation.

[0085] In step 3c, AMF 211 sends a registration acceptance message to UE 205, which includes the required configuration based on the default subscription, such as allowed NSSAI, mobility restrictions, etc. (see Message Passing 315).

[0086] In step 3d, UDM 213 initiates a UE subscription update procedure to send updated subscription information to allow UE 205 to use specific services. In some embodiments, UDM 213 uses the Nudm_SDM_Notification service operation (see message 317). Here, message parameters include the newly subscribed S-NSSAI, a "Network Slice Subscription Change" indication, new mobility restrictions (i.e., CAG information), and roaming turnaround (SoR) information. In one embodiment, a preferred frequency per S-NSSAI is included in message 317.

[0087] Alternatively, UDM 213 can be sent in a transparent container to be sent to UE 205, wherein the container contains 1) the default configured NSSAI and includes the preferred frequency per S-NSSAI and / or 2) security parameters for the UE's application (e.g., security parameters associated with a specific application or S-NSSAI and / or DNN). The container (security parameters) is transparently delivered to UE 205.

[0088] In step 3e, AMF 211 triggers a UE Configuration Update (UCU) procedure to update the UE configuration (see box 319). The UCU command sent from AMF 211 to UE 205 may include at least: a new enhanced configuration NSSAI (for this PLMN), including preferred frequency information per S-NSSAI, mobility restrictions (e.g., with updated CAG information), a default connection type [C-plane or U-plane] for security parameters used to supply the UE USIM or the application supplying the UE, and (if received in step 3d) a transparent container such as that received from the UDM (e.g., including security parameters), a request for re-registration, etc.

[0089] In some embodiments, the UCU command sent to UE 205 does not contain an allowed NSSAI because the UE is assumed to immediately perform the registration process, whereby the UE can send a requested NSSAI based on the configured NSSAI. The allowed NSSAI received in step 3c can be used in UE 205. Further details are described in step 4b.

[0090] If the updated NSSAI configuration (i.e., applicable to this PLMN) and / or the updated CAG information do not match the frequency or CAG configuration of the current cell to which the UE is currently connected, then UE 205 enters a limited service state in the current cell with RM registration status. UE 205 then attempts the cell reselection process as described below in step 9.

[0091] Note that AMF 211 is also capable of determining preferred frequency information for each S-NSSAI. In one embodiment, AMF 211 determines the preferred frequency band through the network configuration in AMF 211. In another embodiment, AMF 211 queries NSSF and NSSF then provides preferred frequency information for each S-NSSAI. If the current AMF 211 is serving an S-NSSAI subscribed to by the UE as received in the updated subscription in step 3d, AMF 211 is capable of determining the preferred frequency band for each S-NSSAI. If the current AMF cannot serve an updated subscription S-NSSAI, the current AMF can trigger an AMF relocation procedure to a target AMF. The preferred frequency information may be a parameter comprising a list of target carrier frequencies (or bands) containing one or more entries, and may also be associated with a carrier frequency priority index for each entry (e.g., a priority index indicating the priority for scanning / selecting carrier frequencies). Please note that not all S-NSSAIs that are part of the list of subscribed S-NSSAIs (and the NSSAIs used to determine which are configured and allowed) can be associated with preferred frequency information. For example, UE 205 can subscribe to S-NSSAI#a and S-NSSAI#b, but only S-NSSAI#b can be associated with preferred frequency information.

[0092] The default (or provisioning) connection type (i.e., C-plane or U-plane) is used by UE 205 when requesting a PDU session to provision USIM or to provide security parameters for applications used by the UE. The provisioning connection type indicator / parameter can contain multiple elements or values, such as control plane or user plane, DNN, S-NSSAI. The provisioning connection type parameter can also contain the data network name (DNN) or network slice ID (e.g., S-NSSAI) to be used for providing the data connection (e.g., PDU session) for UE 205. UE 205 can include one or more connection type parameter elements in a NASMM or NAS SM message (or both) when requesting a connection for provisioning (e.g., sending a PDU session establishment request message). When UE 205 triggers data connection establishment, the provisioning connection type parameter elements, i.e., [C-plane or U-plane], S-NSSAI, and / or DNN, can also be implemented in the network (e.g., in AMF 211). In this case, AMF 211 applies the parameter elements for this data connection.

[0093] At UE 205, upon receiving security parameters (associated with an application and / or slice / DNN), the UE's NAS layer forwards the security information to higher layers (e.g., associated applications like the EAP client in UE 205) and also includes the associated S-NSSAA or DNN. The security information can be used in applications on the UE for various purposes, such as 1) for NSSAA procedures; or 2) to establish a secure connection with AF / E-PS225 to supply UE 205 or for IMS registration as described in further detail below.

[0094] In step 3f, AMF 211 notifies UDM 213 whether the UE configuration update process has succeeded or failed (see message 321). This step is considered a response to 3d, where UDM 213 may have requested an affirmative response regarding a successful update of UE 205. AMF 211 can operate using the Nudm_SDM_Info(Ack) service.

[0095] exist Figure 3B Continuing, step 4 illustrates the signaling for alternative B1 323 for UE configuration based on service subscription data. In step 4a, AMF 211 retrieves the UE subscription from UDM 213, similar to step 3a (see box 325). In alternative B1, UDM 213 determines to reply with the updated UE subscription data. Therefore, UDM 213 sends a Nudm_SDM_Get response including the UE subscription data.

[0096] In one embodiment, UDM 213 may send updated UE subscription data to AMF 211. The updated UE subscription data may include 1) a general indication that the UE subscription data has been updated or 2) one or more specific indications that slice data (e.g., the subscribed S-NSSAI and the associated preferred frequency band for each slice), mobility restriction data (e.g., CAG) or other data has been updated.

[0097] Similar to step 3d, UDM 213 may send: a newly subscribed S-NSSAI, a "Network Slice Subscription Change" indication, a new mobility restriction (CAG information), SoR information, and a transparent container including security parameters. Optionally, the Nudm_SDM_Get response may include a preferred frequency per S-NSSAI.

[0098] If UDM 213 knows the connection type used for USIM / security provisioning of UE 205, UDM 213 can provide such an indication to AMF 211. This indication is used in AMF 211 to determine, as described in step 3e, whether to apply a C-plane or U-plane PDU session when establishing a (default) PDU session from UE 205.

[0099] In step 4b, AMF 211 determines that the UE configuration needs to be updated before the registration process is completed (i.e., before sending the registration accept / reject message). AMF 211 initiates a UCU procedure during the registration process (see box 327). In this case, the UCU procedure is integrated into the registration process. The content of the UCU command sent to UE 205 and further processing are as described above in step 3e.

[0100] In some embodiments, the UCU command sent to UE 205 does not include the allowed NSSAI because UE 205 is assumed to immediately perform the registration process, where UE 205 can send the requested NSSAI based on the configured NSSAI included in the UCU command. In other words, if the AMF includes the updated configured NSSAI in the UE and no established PDU session exists, the AMF can omit including the allowed NSSAI in the UCU command message because the UE is expected to initiate the registration process immediately after completing the UCU process. In step 4c, AMF 211 sends an affirmative response to UDM 213 (see message passing 329), as discussed above in step 3f.

[0101] In step 4d, AMF 211 sends a registration rejection message to UE 205 (see Message Passing 331). The reason for the registration rejection is that UE 205 cannot access the subscribed service via the current cell or tracking area (TA) (e.g., a specific service subscribed to in S-NSSAI). In some embodiments, the registration rejection message may include an indication that re-registration is required. Note that NAS registration rejection messages are typically not acknowledged by UE 205; therefore, updates to slice configurations (e.g., configured NSSAI) or mobility restriction configurations (e.g., allowed CAG lists) are not possible because the UE cannot acknowledge the configuration. Optionally, the registration rejection message may include a new specific rejection reason (e.g., NAS 5GMM rejection reason) indicating to the UE that access to the subscribed service via the current cell / TA is not possible and cell reselection is required.

[0102] Step 5 illustrates the signaling for Alternative B2 333 for UE configuration based on service subscription data. In step 5a, AMF 211 retrieves the UE subscription from UDM 213, similar to step 4a (see box 335). Again, in Alternative B2, UDM 213 determines to reply with the updated UE subscription data.

[0103] In step 5b-1, AMF 211 completes the registration process based on the subscription information received in step 5a (see message 337). If AMF 211 is provided with an indication that network slice subscription data has changed and that one or more subscribed S-NSSAIs and one or more of the subscribed S-NSSAIs require NSSAA, AMF 211 may determine to skip the NSSAA process and omit including the pending NSSAIs in the registration acceptance message. AMF 211 may skip including the "NSSAA to be performed" indicator to the UE.

[0104] If AMF 211 determines that it must send a newly configured NSSAI to UE 205 (either including frequency information per S-NSSAI or not) and registration (re-registration) is required immediately after the registration process, AMF 211 can skip sending the allowed NSSAI to UE 205 (similar to step 4b). The rationale is that UE 205 will use the newly configured NSSAI to construct the requested NSSAI in a subsequent registration process, and therefore does not immediately require the allowed NSSAI. In one embodiment, AMF 211 skips sending the (default) allowed NSSAI by alternatively sending an empty parameter (i.e., an "empty" allowed NSSAI).

[0105] AMF 211 sends a registration acceptance message to UE 205. The registration acceptance message may contain at least one of the following: an allowed NSSAI (i.e., default or empty), a configured NSSAI (including the frequency priority per S-NSSAI, which is a part of the configured NSSAI), a network slice subscription change indication, mobility restrictions (CAG information), SoR information, a provisioning connection type (i.e., C-plane or U-plane) for providing security parameters for the UE USIM or the application providing the UE, and a transparent container including security parameters (associated with a specific application or slice / DNN).

[0106] If the current cell or tracking area in which UE 205 initiates registration cannot be used for any of the subscribed S-NSSAIs, but other cells or tracking areas exist nearby, AMF 211 may decide to include the empty registration area parameter in the registration acceptance message.

[0107] In step 5b-2, UE 205 can confirm successful reception of the registration acceptance message or indicate failure (see message 339). AMF 211 can further indicate to UDM 213 that UE 205 has been successfully updated. In step 5c, AMF 211 sends an affirmative response to UDM 213 (see message 341), as discussed above in steps 4c and 3f.

[0108] As will be apparent from the above description, both alternatives B1 and B2 share the commonality that UDM 213 provides AMF 211 with updated UE subscription data (including service subscription data). This updated UE subscription data requires a configuration update to UE 205. The main difference between alternatives B1 and B2 lies in the manner / order in which AMF 211 provides the configuration update to UE 205: in alternative B1, AMF 211 decides to update the UE configuration before rejecting the registration process; however, in alternative B2, AMF 211 decides to update the UE configuration upon successful registration and via the UCU procedure, either within or immediately after the registration acceptance message.

[0109] AMF 211 may determine whether to apply B1 or B2 depending on at least one of the following conditions: 1) the current AMF can serve the updated subscription S-NSSAI, for example, if the current AMF cannot serve UE 205 and a new AMF needs to be selected, the current AMF decides to apply alternative B1 to allow the selection of a new AMF during the re-registration process; and 2) the current cell allows UE 205 to use the updated subscription S-NSSAI or the updated CAG information.

[0110] For example, if the updated UE subscription parameters (e.g., S-NSSAI of the subscription with corresponding frequency priority or CAG information) require UE 205 to reselect another cell, AMF 211 can determine to apply alternative B1 because UE 205 cannot be registered in the current cell or tracking area. If the AMF can currently serve UE 205 with the updated UE subscription data or can use the current cell or tracking area, AMF 211 can apply alternative C as follows.

[0111] exist Figure 3C Continuing, step 6 illustrates the signaling for alternative C 343 for UE configuration based on service subscription data. In step 6a, UE 205 and the network perform the registration process according to any of alternatives A, B1, or B2 (see box 345). If it is necessary to update specific UE service subscription data, UDM 213 may have already sent the data to AMF 211 as shown in alternatives A, B, or C. However, UDM 213 may need to update UE 205 with UE-specific parameters that do not affect network behavior / configuration.

[0112] In step 6b, UDM 213 initiates a UE parameter update procedure (see message 347). An example of a UE parameter update procedure is described in Clause 4.20 of 3GP TS 23.502. UDM 213 includes UDM update data (UUD, including new or updated UE parameters) in a container encapsulated within a Nudm_SDM_Notification service operation for AMF 211. The UUD is transparently delivered to the UE via NAS signaling. The UUD contains at least one of the following new parameters: the new or updated S-NSSAI of the subscription, the new or updated DNN of the subscription, the allowed CAG list; the preferred frequency for cell selection to select the correct cell to provide a specific service, the provisioning connection type, and security parameters. The UUD may also include whether UE 205 needs to send a positive response to UDM 213 and whether UE 205 needs to re-register after the update data.

[0113] AMF 211 includes the received UUD in the DL NAS TRANSPORT message of UE 205. UE 205 verifies the received UUD, i.e., the UDM update data is provided by a trusted UDM 213 in the HPLMN. In one embodiment, verification is based on the mechanism defined in 3GPP TS 33.501. After successful verification, UE 205 either stores the information and uses those parameters from then on, or forwards the information to the USIM.

[0114] Security parameters are associated with an application ID or network slice (e.g., S-NSSAI) or DNN; that is, the parameters / containers sent by signaling from UDM 213 include one of the associated parameters, such as the application ID, S-NSSAI, or DNN. UDM 213 can obtain security parameters containing user IDs and credentials; UDM 213 can create associations between security parameters and application IDs, S-NSSAI, or DNNs. For example, UDM 213 can use a service ID (as described in step 1) to associate security parameters with S-NSSAI and / or DNN.

[0115] UE 205 can send an affirmative response to UDM 213 regarding the successful update of UE subscription / configuration parameters. Upon receiving the affirmative response, UDM 213 can reset the flag indicating that the UE subscription data needs to be updated.

[0116] In step 7a, AMF 211 requests PCF 215 to create UE policy control information, such as UE policy information that may include URSP information (see message 349). For example, AMF 211 can create the request using Npcf_UEPolicyControl (an empty PSI if the UE has not sent any PSIs). If AMF 211 has not yet received any PSIs from UE 205, or if AMF 211 has received a UE subscription update from UDM 213 and the subscription update affects the subscribed S-NSSAI / DNN (e.g., during step 5b), then AMF 211 includes an "empty PSI" to indicate that a new UE policy should be provided to UE 205. This allows the URSP in UE 205 to include the updated subscribed S-NSSAI / DNN.

[0117] In step 7b, PCF 215 may send a Namf_Communication_N1N2MessageTransfer message containing the new URSP information to AMF 211 (see Message Passing 351). In step 7c, AMF 211 sends the updated URSP information to UE 205 (see Message Passing 353).

[0118] In step 8, AMF 211 requests 5G-AN (RAN 207 or a non-3GPP access node) to release the connection to UE 205 so as to allow UE 205 to switch to idle mode (see message 355).

[0119] In step 9, UE 205 updates its subscription / configuration parameters 1) (e) the USIM in the UICC or 2) the subscription stored in the ME (see box 357) and / or NAS tier configuration. UE 205 applies the newly updated subscription / configuration information. UE 205 determines which S-NSSAIs it wants to register with (i.e., the S-NSSAIs to be included in the requested NSSAIs). Then, UE 205 performs a cell selection procedure considering the frequency priority of the S-NSSAIs to be included in the requested NSSAIs.

[0120] UE 205 may first create a requested NSSAI (e.g., based on a configured NSSAI) to be included in a second registration request message. UE 205 may then consider a list of target carrier frequencies for the S-NSSAI values ​​included in the requested NSSAI. If more than one S-NSSAI exists in the requested NSSAI, UE 205 may prioritize the S-NSSAI, and therefore, prioritize the bearer frequencies (bands) to be used for cell selection. The prioritization of S-NSSAI depends on the UE's internal configuration (e.g., from a higher layer) or user priority.

[0121] In step 10, UE 205 initiates a registration process in the cell selected according to step 9, and UE 205 constructs a registration request by applying the updated subscription / configuration parameters (see message 359). AMF 211 continues to register UE 205 using the updated subscription / configuration parameters; that is, AMF 211 uses the Nudm_SDM_Get service operation to retrieve the UE subscription from UDM 213 (see message 361). Although the depicted embodiment shows AMF 211 receiving a second registration request, note that the AMF receiving the second registration request may be a different AMF than AMF 211, depending on the requested NSSAI used in the second registration request.

[0122] Note that UE 205 may be supplied with (non-3GPP) "security parameters" by 5GC during step 6 (Alternative C) or alternatively during steps 3, 4, or 5. In other embodiments, security parameters may be supplied from a third-party server, as referenced below. Figures 4A-4C As described, "security parameters" can be third-party parameters / credentials. "Security parameters" include at least: a user ID, at least one of [security token, password, certificate, or other credentials], and an association with a 3GPP service ID (e.g., application ID or S-NSSAI / DNN) or an external third-party service ID (see below). Figures 4A-4C (Discussion) related.

[0123] Security parameters can be applied to 1) a group of UEs, such as a group of UEs to be provided with a specific service, in which case this is group security; or 2) each individual UE 205, i.e., each UE 205 has its own security parameters to use. If the security parameters are applicable to an individual UE, then in step 1 the AF will use an individual external ID so that each UE 205 supplies data to the network and the UDM / UDR should store the security parameters associated with the individual default UE subscription.

[0124] Because security parameters can be used for secondary authentication with external service / vertical providers, they can also be referred to as non-3GPP security parameters. The association of security parameters with 3GPP service IDs (e.g., application ID, S-NSSAI, or DNN) is used in UE 205 to identify which authentication process to apply the supplied security parameters to. For example, multiple sets of security parameters may exist, each associated with a fundamentally different service ID (e.g., application ID, S-NSSAI, or DNN); and UE 205 determines the specific set of security parameters to use based on the 3GPP service ID.

[0125] "Security parameters" can be used for at least one of the following purposes: A) establishing a secure connection to the AF / E-PS (e.g., for login, provisioning, or updating of a USIM or secure storage subscription); or B) secondary authentication and / or authorization ("SAA") for an S-NSSAI (also known as NSSAA) or PDU session; or C) IMS registration, for example, for IMS authentication and authorization to use IMS services. Note that for A), secure storage can be a secure element (SE) within the device used for the storage, management, and operation of subscriptions and credentials (including 3GPP credentials or non-3GPP credentials or both). For C), the security parameters used as IMS credentials can be different from USIM-based IMS credentials. Such security parameters can be used for registration with the IMS system of the NPN. See below for reference. Figures 4A to 4C Discuss the details of the SAA for each option B).

[0126] If a service subscription (e.g., vertical subscription information, as in step 1) is associated with an external ID in the form of a device identity (e.g., PEI or IMEI), then UDM 213 can request AMF 211 to provide the PEI / IMEI of UE 205. The request from UDM 213 to AMF 211 can be performed by AMF 211 during UE subscription data retrieval, for example, as shown in steps 3a, 4a, or 5a. If AMF 211 does not know the PEI / IMEI of UE 205, then AMF 211 can perform a UE identity request procedure together with UE 205. AMF 211 provides the UE device identity to UDM 213.

[0127] As an alternative to or supplement to sending the frequency priority of per-S-NSSAI, which is part of the configured NSSAI (e.g., as shown in steps 3f, 4b, 5b, or 6b in procedure 300), AMF 211 may include the frequency priority of per-S-NSSAI in the permitted NSSAI information. The frequency priority of per-S-NSSAI can be used in UE 205 to derive frequencies as additional criteria for cell selection purposes in idle mode. UE 205 can be in idle mode for re-registration (as shown in steps 8 and 9 in procedure 300), and UE 205 can also be registered to 5GS and perform idle-state mobility, wherein UE 205 uses per-network-slice frequency preferences during the service request process. This mechanism can be described as network-slice-based cell selection, wherein UE 205 performs slice selection taking into account the frequency priority of per-S-NSSAI as an additional slice selection criterion (in addition to signal strength and other cell selection criteria).

[0128] An example scenario could be: UE 205 is registered for network slices S-NSSAI#a (with a preferred frequency "band a") and S-NSSAI#b (with a preferred frequency "band b"), where both "band a" and "band b" are parts of the same registration area. Assume UE 205 is currently camped on a cell using frequency "band a," for example, because the signal strength of "band a" is higher than that of "band b." If an application associated with S-NSSAI#b triggers a service request procedure, UE 205 can determine to select a cell operating in frequency "band b" before initiating RRC connection establishment. UE 205 then initiates the RACH procedure and the RRC connection establishment procedure in the cell operating in frequency "band b."

[0129] Please note that some of the alternatives A, B1, B2, and C can be used simultaneously (or therefore in the same registration process or in consecutive registration processes). For example, any of alternatives A, B1, and B2 can be used to configure network slicing information (e.g., configured NSSAI, etc.) and mobility restrictions (e.g., allowed CAGIDs), while alternative C can be used to send security parameters to UE 205. Generally, alternative C can be used to send security parameters that are only relevant to UE 205, i.e., the default configured NSSAI, to UE 205; however, other parameters that affect both UE 205 and the network (e.g., subscribed S-NSSAI, allowed CAGIDs) can be supplied via one of alternatives A, B1, or B2.

[0130] Beneficially, process 300 enhances UE configuration updates by providing additional information to UE 205 (e.g., frequency information or security parameters per slice). Figures 3A-3C The solution also allows the use of device identities from (e.g., third-party) AFs to identify subscriptions (or subscription groups) within the network.

[0131] Figures 4A to 4C A process 400 for registering with a mobile network via another mobile network according to embodiments of this disclosure is described. Process 400 involves UE 205, AMF 211, UDM 213, a Business Support System (“BSS”) 401 (referred to as “OAM / BSS” 401) in the Operations Administration and Management (“OAM”) plane, NEF 219, and AF / E-PS 225. Process 400 details the signaling flow of Solution B, in which UE 205 connects to a 4G-Residential Gateway (5G-RG) 405 in PLMN-1 and registers with PLMN-2 via this 4G-RG 405. PLMN-1 provides an IP channel enabling communication between UE 205 and PLMN-2 in a manner similar to the IP channel provided by the SNPN in Solution A, which enables communication between UE 205 and PLMN.

[0132] Two-factor authentication and authorization (“SAA”) can be applied during registration (e.g., performed by the AMF and referred to as Network Slice Secondary Authentication and Authorization (NSAA), associated with S-NSSAI) or during PDU session establishment (performed by the SMF and associated with the DNN, referred to as Secondary Authentication Acting on the PDU Session). If the UE 205 does not hold security credentials for the SAA, the SAA process will fail. This causes the AMF / SMF to initiate the SAA process, but it will fail because the UE does not even hold the user ID associated with the S-NSSAI / DNN topic of the SAA. Note that alternatively, security parameters can be used for IMS registration instead of the SAA process; and it is possible to use the same security parameters as those used in the SAA process. Figures 4A to 4C The same signaling flow.

[0133] Process 400 details the signaling flow used to resolve this issue by not activating (or not performing the provisioning in the network and corresponding UE configuration) UE service subscription data (e.g., S-NSSAI or DNN associated with a specific / vertical service ID#x and indicated as requiring SAA, S-NSSAI#x / DNN#x) unless the corresponding security parameters are provided to UE 205. In various embodiments, the specific service subscription data (in UDM 213) is in a dormant (or deactivated) state. Therefore, when dormant, the specific service subscription data (e.g., S-NSSAI#x / DNN#x) is not sent in the subscription data to other NFs (e.g., to AMF 211).

[0134] Another feature of the solution is that service subscription activation in UDM 213 can be dynamically performed by AF / E-PS 225 via exposed network provisioning capabilities (e.g., via the N33 interface between NEF 219 and AF / E-PS 225). For example, AF can use the N33 interface service to activate or deactivate services identified by ID#x. Such exposed network provisioning capabilities are new and require support from the network (e.g., NEF, UDM / UDR) and AF.

[0135] An alternative for activating a service subscription is a semi-static method, where an AF / E-PS225 request is made to activate or deactivate the service ID#x (S-NSSAI#x / DNN#x) via the OAM system.

[0136] Furthermore, this solution proposes Figures 3A to 3C This paper proposes alternative methods for providing security parameters to the UE. It suggests that a third-party server (e.g., Application Function (AF) or External Provisioning Server E-PS) can utilize the N33 interface service. This N33 interface service can be an existing or new service.

[0137] Figures 4A to 4C Details of this embodiment are described below. Note that process 400 can also be applied to supply further information to UE 205 (i.e., in addition to security parameters). For example, if the third-party server is a supply server (e.g., E-PS) capable of accessing the UE's subscription data, the third-party server can also supply new subscription profiles or change existing subscription profiles in UE 205 and subscription information in the network (e.g., UDM / UDR 139).

[0138] exist Figure 4A In this process, process 400 begins with step 0, in which UE 205 stores (i.e., maintains) its subscription to the PLMN (see box 405). This subscription (USIM profile) can be called a default subscription and can be stored in the UICC (eUICC) or in secure storage within the ME portion of UE 205. The default subscription allows UE 205 to use default services in the PLMN (or in the roaming partner's network). For example, UE 205 can obtain IP connectivity to the Internet, SMS services, and / or other control plane services.

[0139] In step 1, the service provider (e.g., AF / E-SP 225) enters into a contract with the network operator to provide a specific service to a set of devices / UEs. The AF / E-SP 225 learns the external ID of the UE / subscriber who should use the service. It is also possible to assign a service identifier, such as service ID#x. The rationale for using service ID#x is that multiple services with different service characteristics and subscriptions can exist under the same AF / E-SP 225. Alternatives A and B below illustrate different possible communication methods between the AF / E-SP 225 and the UDM 213.

[0140] Alternative Option A (Step 1a): AF / E-PS 225 uses a Service Level Agreement (“SLA”) to request a service subscription (see box 407). Typically, the SLA is stored at OAM / BSS 401. OAM / BSS 401 can configure vertical subscription information for UDM 213. Additionally, AF / E-SP 225 can negotiate with the network operator (e.g., mobile network operator MNO) whether the service subscription should be activated or deactivated. Note that in Figures 3A to 3C In this context, it is assumed that the service subscription is activated; however, in Figures 4A to 4C In this case, it is assumed (although negotiated with the MNO) that the service subscription is not provided in the corresponding UE subscription data. In other words, the service subscription is disabled or dormant. The network (UDM 213) is provided with default subscription data for UE 205 and only the default subscription data is active in UDM 213.

[0141] Alternative B (steps 1b and 1c): The AF / E-PS 225 requests provisioning of a UE or a group of UEs to be permitted to use a specific NPN / vertical service, such as network services exposed using N33. The UE or UE group is identified by an external ID or a list of UE external IDs or group external IDs. Additionally, the AF / E-PS 225 is capable of providing a provisioning connection type (e.g., control plane or user plane) that can be used to provision UE 205 (e.g., the UE's USIM) from the provisioning server. The AF / E-PS 225 is also capable of providing third-party (group) security parameters to be sent to the UDM 213 for provisioning authentication. The AF / E-PS 225 is capable of establishing an association with the NEF 219 of the network (e.g., PLMN or NPN). The AF / E-PS 225 performs at least one of steps 1b and 1c (see box 407).

[0142] In step 1b, the AF / E-PS 225 subscribes to the 5GS (e.g., UDM 213) to be notified when the UE (identified by an external ID) becomes reachable. Recall the reference above. Figure 3AExternal IDs are discussed. In step 1c, AF / E-PS 225 instructs 5GS (e.g., the target is UDM 213) that a service subscription must be created or updated. In one embodiment, AF / E-PS 225 uses the Nnef_ParameterProvision_Create service operation on NEF 219 to create or update the service parameter. In another embodiment, AF / E-PS 225 uses the Nnef_ParameterProvision_Update service operation on NEF 219 to update the service parameter. In still other embodiments, AF / E-PS 225 uses the Nnef_ParameterProvision_Delete Request service operation on NEF 219 to update the service parameter for NEF 219.

[0143] For either Alternative A or B, the following information can be sent from the AF / E-PS 225 to the network: 1) a service identifier (e.g., service ID#x, used to identify the service between the service provider (AF / E-PS 225) and the network operator); 2) a list of one or more external IDs of the UE (e.g., associated with a specific service) or external group IDs; 3) an explicit indication of whether the service should be activated or deactivated. A reason for deactivation could be incomplete provisioning of security parameters; 4) service subscription parameters, which can be, for example, generic slice template (GST) attributes as specified in GSMA 5GJA NG.116. Such parameters are used by the network (e.g., the OAM system) to instantiate, configure, or provision the RAN and core network with the required network slices and / or data network parameters; and 5) third-party security parameters (e.g., as referenced above). Figures 3A-3C As described.

[0144] As an example of explicit indication, the AF service can be associated with the S-NSSAI (e.g., S-NSSAI#x) and / or data network name (e.g., DNN#x) as the subject of Secondary Authentication and Authorization (SAA). The security parameters are still not provided in UE 205 or should be provided to UE 205. This is an indication of UDM 213 that the corresponding S-NSSAI#x / DNN#x should be "inactive" in the subscription data, i.e., should not be included in the UE subscription data sent to other NFs.

[0145] In step 2, UDM 213 stores at least the following states: 1) It is necessary to notify AF / E-PS 225 when UE 205 becomes reachable; and 2) S-NSSAI#x / DNN#x should be "inactive" in the subscription data, that is, it should not be included in the UE subscription data sent to NF (see box 411).

[0146] In step 3, UE 205 initiates a registration process for the selected network based on the default USIM data in UE 205 (see message 413). If this is an initial registration request, UE 205 will include the SUCI. In step 4, the network (e.g., AMF211 and AUSF) performs a network (i.e., primary) access authentication and authorization process (see message 415). In one embodiment, the network performs the primary access authentication and authorization process as specified in 3GPP TS 23.501 / TS33.501.

[0147] In step 5, AMF 211 retrieves the default subscription from UDM 213 (see message 417). In some embodiments, UDM 213 maintains an internal flag indicating that the UE's subscription data will be updated later. AMF 211 can retrieve the subscription data using the Nudm_SDM_Get operation. For example, in the above... Figure 3A Additional details are described in step 3a. In step 6, AMF 211 sends a registration acceptance message to UE 205, which includes the required configuration based on the default subscription, such as allowed NSSAI, mobility restrictions, etc. (see Message Passing 419).

[0148] exist Figure 4B Continuing, in step 7, UDM 213 notifies AF / E-PS 225 of UE reachability via NEF 219 (i.e., instructs UE 205 to be reachable via the control plane (“C plane”); see message 421). In step 8, AF / E-PS 225 initiates a C plane procedure to either 1) update the UE with security parameters to enable SAA provisioning via the U plane or 2) perform SAA provisioning via the C plane.

[0149] Two alternative procedures for the C-plane process are described. In Alternative 8A (see box 423): communication between the AF and the UE is on the path AF<-->NEF<-->AMF<-->UE. In Alternative 8B (see box 425): communication between the AF and the UE is on the path AF<-->NEF<-->UDM<-->UE; here, signaling between UDM 213 and UE 205 is via AMF211 and similar to the above reference. Figure 3CStep 6b describes the UE parameter update process. In optional step 9, if needed, UE 205 (e.g., the application in UE 205) may trigger a U-plane procedure to supply the security parameters required by the SAA (see message 427). In an alternative to step 9, AF / E-PS 225 may trigger the provisioning of a new subscription profile or change an existing subscription profile in UE 205.

[0150] Alternatively, the AF / E-PS 225 may trigger application-layer signaling to provision UE 205. Security credential parameters can be referred to as non-3GPP security parameters because they are not used for primary authentication. Since these parameters can be provisioned via legacy protocols, they may not be associated with the UE's service subscription. In UE 205, security parameters will be associated with service subscriptions identified by service IDs (e.g., application ID, S-NSSAI, DNN, or other IDs) to allow UE 205 to distinguish among multiple sets of security parameters. When provisioning services in the network, the AF / E-PS 225 can learn the service ID of the subscribed service during step 1. In this case, the AF / E-PS 225 includes the service ID in the U-plane signaling exchange.

[0151] Alternatively, if the AF / E-SP 225 is unaware of the 3GPP service ID used in the 3GPP network (e.g., application ID, S-NSSAI, DNN), but the AF / E-SP 225 uses its own third-party service ID (which may be the same as the user ID or proprietary application ID), then the security parameters sent to the UE 205 in step 9 include the third-party service ID. The third-party service ID is provided to the 5GC (3GPP network) during step 1 and stored in the UDM 213 along with the service subscription. The third-party service ID is provided to the UE 205 in one of the following ways:

[0152] A) Third-party service IDs can be used in network slicing configurations (e.g., configured NSSAI or allowed NSSAI or URSP rules), enabling UE 205 to establish associations between third-party service IDs and 3GPP service IDs (e.g., S-NSSAI or DNN).

[0153] B) During the triggering of the SAA procedure, the 3GPP network function that triggered the SAA procedure (e.g., AMF, SMF, or AUSF) includes a third-party service ID (along with S-NSSAI or DNN) in the authentication request. Note that the authentication request is typically encapsulated in a NAS Protocol Data Unit (NAS PDU). Upon receiving the authentication request, UE 205 uses the third-party service ID to map the authentication request to stored security parameters identified by the same third-party service ID.

[0154] exist Figure 4C Continuing in step 10, after successfully providing credentials for the SAA or a new / updated subscription profile in UE 205, AF / E-PS 225 initiates a procedure to update the service subscription status in UDM 213, i.e., to "activate" the service subscription ID#x in the UE's subscription data (see message 429). For this purpose, AF / E-PS 225 can use 1) the N33 interface service for NEF 219 (such as...) Figure 4C (as shown); or 2) communication via the OAM system (in Figure 4C Not shown in the image, but similar to... Figure 3A Step 1a).

[0155] The information sent from AF / E-PS 225 can include at least: the UE's external ID; the service ID; an instruction to activate a service subscription for the UE; an instruction to activate a SAA for the corresponding S-NSSAI or DNN; target AAA server information (e.g., FQDN or IP address); etc. Note that the instruction to activate a service subscription for UE 205 corresponds to the instruction to deactivate a service subscription in step 1a or 1c. For example, this instruction or parameter can have at least two values, such as "on" and "off". Alternatively, if AF / E-SP 225 has already created a new subscription profile in UE 205, AF / E-SP 225 can create new subscription data in UDM 213. Note that the subscription profile in UE 205 and the subscription data in UDM 213 are identified by subscriber identity (e.g., SUPI).

[0156] In step 11, UDM 213 updates (or activates or creates) the service subscription associated with the identifier ID#x in the UE 205 subscription data (see box 431). UDM 213 is able to map the service subscription identifier ID#x to the corresponding parameter S-NSSAI#x / DNN#x used in EPS to distinguish network functions configured to use a specific service. UDM 213 updates the parameter S-NSSAI#x / DNN#x in the UE's subscription data. In addition, UDM 213 marks S-NSSAI#x / DNN#x with the SAA indication subject, which is used in the target network function (e.g., AMF 211 or SMF145) to trigger the SAA procedure for UE 205.

[0157] In step 12, UDM 213 initiates a process to update the UE subscription data in the corresponding NF (see message passing 433). For example, UDM 213 initiates an update for the AMF using the Nudm Notification service operation. UDM 213 includes a new list of indications that the network slice subscription has changed and the subscription's S-NSSAI, as well as indications of whether SAA (i.e., NSSAA) is required.

[0158] In step 13, AMF 211 performs a UCU procedure for UE 205 to update the network slice configuration with the required registration (e.g., configured NSSAI, allowed NSSAI) (see box 435). The UCU procedure can be substantially as described above. Figure 3A As described in step 3e. In step 14, after the internal application of the updated configuration and possibly cell reselection, UE205 performs the NSSAI registration procedure, which includes an update request (see message 437). The target AMF (if AMF relocation is required) performs the NSSAA procedure for S-NSSAI#x.

[0159] The advantage of performing UE service subscription updates via exposed network capabilities (e.g., control plane interface N33) is that service providers can update a specific UE's subscription individually after the UE has already logged in / configured at the application level (e.g., using security parameters for SAA or a new / updated subscription profile). This coordination between service subscription activation and UE provisioning avoids the need to perform potentially failed NSSAA procedures or secondary authentication of PDU sessions, since the UE has not yet been provided with the relevant security parameters.

[0160] Figure 5 This description depicts one embodiment of a user equipment device 500, which can be used to register with a mobile network via another mobile network, according to embodiments of the present disclosure. The user equipment device 500 may be an embodiment of a remote unit 105 and / or a UE 205. Furthermore, the user equipment device 500 may include a processor 505, a memory 510, an input device 515, an output device 520, and a transceiver 525. In some embodiments, the input device 515 and the output device 520 are combined into a single device, such as a touchscreen. In some embodiments, the user equipment device 500 may not include any input device 515 and / or output device 520.

[0161] As depicted, transceiver 525 includes at least one transmitter 530 and at least one receiver 535. Here, transceiver 525 communicates with a mobile core network (e.g., 5GC) via an access network. Furthermore, transceiver 525 may support at least one network interface 540. Here, at least one network interface 540 facilitates communication with an eNB or gNB (e.g., using a "Uu" interface). Additionally, at least one network interface 540 may include an interface for communication with an AMF, SMF, and / or UPF.

[0162] In one embodiment, processor 505 may include any known controller capable of executing computer-readable instructions and / or performing logical operations. For example, processor 505 may be a microcontroller, microprocessor, central processing unit (“CPU”), graphics processing unit (“GPU”), auxiliary processing unit, field-programmable gate array (“FPGA”), or similar programmable controller. In some embodiments, processor 505 executes instructions stored in memory 510 to perform the methods and routines described herein. Processor 505 is communicatively coupled to memory 510, input device 515, output device 520, and transceiver 525.

[0163] In various embodiments, processor 505 controls user equipment device 500 to implement the UE behavior described above. In some embodiments, processor 505 controls transceiver 525 to send a first registration request to a mobile communication network that supports multiple network slices. Via transceiver 525, processor 505 receives configuration information from the mobile communication network that enables user equipment device 500 to use specific services (e.g., from at least one of the multiple network slices). In one embodiment, the configuration information includes the frequency priority of at least one network slice. In another embodiment, the configuration information may include the frequency priority of each of the multiple network slices. Processor 505 performs cell reselection using at least the frequency priorities and sends a second registration request to the mobile communication network after performing cell reselection. In one embodiment, the second registration request registers with at least one network slice.

[0164] In some embodiments, the configuration information includes network slice configuration data and mobility restriction configuration data, which includes cell restrictions for closed access groups. Here, the network slice configuration data includes permitted network slice information and (i.e., enhanced) configured network slice information for the mobile communication network. In such embodiments, receiving the configuration information may include receiving information from the AMF in the mobile communication network.

[0165] In some embodiments, the configuration information includes (i.e., by default) the frequency priority of configured network slice information. In some embodiments, the configuration information includes at least one security parameter for secondary authentication, the at least one security parameter including: an identifier, credentials, and an association with a service identifier. Here, the service identifier may be S-NSSAI, DNN, and / or an application.

[0166] In some embodiments, processor 505 stores the received configuration information in a subscription profile (e.g., in a USIM). In other embodiments, processor 505 stores the received configuration information in a mobile device configuration (e.g., at the NAS layer or at the application).

[0167] In one embodiment, memory 510 is a computer-readable storage medium. In some embodiments, memory 510 includes volatile computer storage media. For example, memory 510 may include RAM, including dynamic RAM (“DRAM”), synchronous dynamic RAM (“SDRAM”), and / or static RAM (“SRAM”). In some embodiments, memory 510 includes non-volatile computer storage media. For example, memory 510 may include a hard disk drive, flash memory, or any other suitable non-volatile computer storage device. In some embodiments, memory 510 includes both volatile and non-volatile computer storage media. In some embodiments, memory 510 stores data related to registration with a mobile network via another mobile network, such as security environment, IP address, etc. In some embodiments, memory 510 also stores program code and related data, such as an operating system (“OS”) or other controller algorithms and one or more software applications running on user equipment device 500.

[0168] In one embodiment, input device 515 may include any known computer input device, including a touch panel, button, keyboard, stylus, microphone, etc. In some embodiments, input device 515 may be integrated with output device 520, for example, as a touchscreen or similar touch-sensitive display. In some embodiments, input device 515 includes a touchscreen, allowing text to be entered using a virtual keyboard displayed on the touchscreen and / or by handwriting on the touchscreen. In some embodiments, input device 515 includes two or more different devices, such as a keyboard and a touch panel.

[0169] In one embodiment, output device 520 may include any known electronically controllable display or display device. Output device 520 is designed to output visual, auditory, and / or tactile signals. In some embodiments, output device 520 includes an electronic display capable of outputting visual data to a user. For example, output device 520 may include, but is not limited to, LCD displays, LED displays, OLED displays, projectors, or similar display devices capable of outputting images, text, etc., to a user. As another non-limiting example, output device 520 may include wearable displays, such as smartwatches, smart glasses, heads-up displays, etc. Furthermore, output device 520 may be a component of a smartphone, personal digital assistant, television, desktop computer, laptop computer, personal computer, vehicle dashboard, etc.

[0170] In some embodiments, output device 520 includes one or more speakers for generating sound. For example, output device 520 may generate an auditory alarm or notification (e.g., a beep or ringtone). In some embodiments, output device 520 includes one or more haptic devices for generating vibration, motion, or other haptic feedback. In some embodiments, all or part of output device 520 may be integrated with input device 515. For example, input device 515 and output device 520 may form a touchscreen or similar touch-sensitive display. In other embodiments, all or part of output device 520 may be located near input device 515.

[0171] As discussed above, transceiver 525 communicates with one or more network functions of a mobile communication network via one or more access networks. Transceiver 525 operates under the control of processor 505 to transmit and receive messages, data, and other signals. For example, processor 505 may selectively activate the transceiver (or a portion thereof) at specific times to transmit and receive messages.

[0172] Transceiver 525 may include one or more transmitters 530 and one or more receivers 535. Although only one transmitter 530 and one receiver 535 are illustrated, user equipment device 500 may have any suitable number of transmitters 530 and receivers 535. Furthermore, the transmitter(s) 530 and receiver(s) 535 may be of any suitable type. In one embodiment, transceiver 525 includes a first transmitter / receiver pair for communicating with a mobile communication network on licensed radio spectrum and a second transmitter / receiver pair for communicating with a mobile communication network on unlicensed radio spectrum.

[0173] In some embodiments, a first transmitter / receiver pair for communicating with a mobile communication network on licensed radio spectrum and a second transmitter / receiver pair for communicating with a mobile communication network on unlicensed radio spectrum may be combined into a single transceiver unit, such as a single chip performing functions for both licensed and unlicensed radio spectrum. In some embodiments, the first transmitter / receiver pair and the second transmitter / receiver pair may share one or more hardware components. For example, certain transceivers 525, transmitters 530, and receivers 535 may be implemented as physically separate components that access shared hardware and / or software resources, such as, for example, a network interface 540.

[0174] In various embodiments, one or more transmitters 530 and / or one or more receivers 535 may be implemented and / or integrated into a single hardware component, such as a multi-transceiver chip, system-on-a-chip, ASIC, or other type of hardware component. In some embodiments, one or more transmitters 530 and / or one or more receivers 535 may be implemented and / or integrated into a multi-chip module. In some embodiments, other components such as network interface 540 or other hardware components / circuitets may be integrated with any number of transmitters 530 and / or receivers 535 into a single chip. In such embodiments, transmitters 530 and receivers 535 may be logically configured as a transceiver 525 using a more common control signal or as modular transmitters 530 and receivers 535 implemented in the same hardware chip or multi-chip module.

[0175] Figure 6 This description depicts one embodiment of a gateway device 600, which can be used to register with a mobile network via another mobile network, according to embodiments of the present disclosure. In some embodiments, the gateway device 600 may include an embodiment of 5G-RG. Furthermore, the gateway device 600 may include a processor 605, a memory 610, an input device 615, an output device 620, and a transceiver 625. In some embodiments, the input device 615 and the output device 620 are combined into a single device, such as a touchscreen. In some embodiments, the gateway device 600 may not include any input device 615 and / or output device 620.

[0176] As depicted, transceiver 625 includes at least one transmitter 630 and at least one receiver 635. Here, transceiver 625 communicates with one or more remote units 105. Additionally, transceiver 625 may support at least one network interface 640, such as the N1 interface depicted in FIG. 4. In some embodiments, transceiver 625 supports a first interface for communicating with RAN nodes, a second interface for communicating with one or more network functions in the mobile core network (e.g., 5GC), and a third interface for communicating with remote units (e.g., UEs).

[0177] In one embodiment, processor 605 may include any known controller capable of executing computer-readable instructions and / or performing logical operations. For example, processor 605 may be a microcontroller, microprocessor, central processing unit (“CPU”), graphics processing unit (“GPU”), auxiliary processing unit, field-programmable gate array (“FPGA”), or similar programmable controller. In some embodiments, processor 605 executes instructions stored in memory 610 to perform the methods and routines described herein. Processor 605 is communicatively coupled to memory 610, input device 615, output device 620, and first transceiver 625.

[0178] In various embodiments, processor 605 controls network device apparatus 600 to implement the AMF behavior described above. In some embodiments, transceiver 625 receives a first registration request to register a UE with a mobile communication network. Processor 605 receives subscription information of the UE from the mobile communication network, which enables the UE to use a specific service. Processor 605 determines configuration information to supply the UE. Here, the configuration information includes at least the frequency priority of each of a plurality of network slices. Processor 605 supplies the UE using the configuration information and receives a second registration request from the UE in response to supplying the UE.

[0179] In some embodiments, the processor 605 determines whether to supply the UE before sending the registration result to the UE or to supply the UE along with the registration result. In some embodiments, the processor 605 supplies the UE with configuration information by performing a UE configuration update procedure. In some embodiments, the processor 605 sends a registration rejection message to the UE in response to performing the UE configuration update procedure, wherein the registration rejection message triggers cell reselection and re-registration of the UE to the same mobile communication network.

[0180] In some embodiments, the processor 605 registers the UE in response to a first registration request. In such embodiments, registering the UE includes receiving default subscription information for the UE, wherein the default subscription information is for a default service (i.e., excluding specific service subscriptions). In some embodiments, the default subscription information is updated by subscription information enabling the UE to use specific services. In such embodiments, the processor 605 subscribes to notifications regarding UE subscriptions from the mobile communication network (i.e., UDM) and receives updated subscription information for the UE, wherein the updated subscription information includes subscription information for specific services. In some embodiments, the subscription information includes configuration information having frequency priorities for each of a plurality of network slices.

[0181] In some embodiments, processor 605 supplies configuration information to the UE by sending a registration accept message. In some embodiments, the registration accept message includes an empty set of allowed network slices. In some embodiments, at least one subscribed network slice requires secondary authentication. In such embodiments, processor 605 skips the secondary authentication process (i.e., the NSSAA process) after sending the registration accept message. Because the S-NSSAI undergoing NSSAA is included in the parameter "pending NSSAI" in the registration accept message, in one embodiment, skipping the secondary authentication process includes omitting the "Pending NSSAI" parameter in the registration accept message.

[0182] In some embodiments, the configuration information includes mobility restriction configuration data containing cell restrictions for closed access groups and at least one transparent container containing security parameters for secondary authentication of the UE. These security parameters include at least one of the following: an identifier, credentials, and an association with a service identifier. Here, the service identifier may be S-NSSAI, DNN, and / or an application. In some embodiments, the configuration information configures the second device, for example, by updating the closed access group ID of the allowed NSSAI.

[0183] In some embodiments, after successful registration, the processor 605 receives a container with updated UE parameters and forwards the container with updated UE parameters to the UE, wherein the updated UE parameters include at least one of the following: (i.e., enhanced) default configuration network slice information and security parameters, wherein the default configuration network slice information includes frequency priorities for each of a plurality of network slices. Note that a container is used here because the parameters received from the UDM are not processed in the AMF, but are transparently forwarded to the UE. Note that using a container to send updated UE parameters can be performed regardless of whether the UE needs to re-register, i.e., it can be performed after the UE has successfully registered once.

[0184] In some embodiments, the UE's service subscription is associated with the UE's device identity, wherein the processor 605 receives a request to provide an additional UE identity and provides the UE's device identity to the network.

[0185] In various embodiments, processor 605 controls network device apparatus 600 to implement the UDM / UDR behavior described above. In some embodiments, processor 605 stores UE subscription information. Processor 605 stores at least the UE's default subscription information and the UE's updated subscription information. Here, the default subscription information enables the UE to access the default service (see, for example...). Figure 3AStep 1a) and the updated subscription information enables the UE to use a specific service. Because both types of subscription information are stored, the UDM can dynamically activate or deactivate updated [service] subscription data, for example, based on a request from the AF (e.g., according to...). Figures 4A to 4C (Steps 1c and 10). Processor 605 receives a request for subscription data for the UE from the AMF and determines the type of subscription data to be sent to the AMF, which the UE needs to supply. Here, the type of subscription data can be default subscription information or updated subscription information. Note that the decision on whether to send the default subscription data first and then the updated subscription data is made in the UDM. For example, the updated [service] subscription data may be temporarily deactivated, causing the UDM to initially send the default subscription data to the AMF. When the updated subscription data is activated, processor 605 can then send the updated subscription data. Processor 605 sends subscription data to the AMF, for example, to configure the UE and the network (e.g., AMF and RAN) to use a specific service.

[0186] In some embodiments, the updated subscription information includes at least one of the following: a network slice identifier, a data network name, information for cell reselection, and a list of allowed closed access groups. In some embodiments, the updated subscription information includes a list of UE identities that provide the updated subscription information. In such embodiments, the list of identities may include a list of subscription identities and / or a list of device identities.

[0187] In some embodiments, the processor 605 sends a request for the UE's device identity to the AMF in response to a list of UE identities that includes a list of device identities. In some embodiments, determining that the UE needs to provide includes determining whether a first identity of the UE is found in the list of UE identities and mapping the first identity to a first subscription type, wherein the default subscription type is a topic updated with updated subscription information.

[0188] In some embodiments, processor 605 receives a second request to activate or deactivate updated subscription information, wherein the second request is received from an application function via NEF (e.g., see...). Figures 4A to 4C (Steps 1c and 10). In some embodiments, after successful registration, the processor 605 sends a container with updated UE parameters to the AMF, wherein the AMF forwards the container with updated UE parameters to the UE. In such embodiments, the updated UE parameters may include one or more of the following: security parameters and (i.e., enhanced) default configuration network slice information, wherein the default configuration network slice information includes the frequency priority of each of a plurality of network slices.

[0189] In one embodiment, memory 610 is a computer-readable storage medium. In some embodiments, memory 610 includes volatile computer storage media. For example, memory 610 may include RAM, including dynamic RAM (“DRAM”), synchronous dynamic RAM (“SDRAM”), and / or static RAM (“SRAM”). In some embodiments, memory 610 includes non-volatile computer storage media. For example, memory 610 may include a hard disk drive, flash memory, or any other suitable non-volatile computer storage device. In some embodiments, memory 610 includes both volatile and non-volatile computer storage media. In some embodiments, memory 610 stores data related to registration with a mobile network via another mobile network, such as security environment, IP address, UE environment, etc. In some embodiments, memory 610 also stores program code and related data, such as an operating system (“OS”) or other controller algorithms running on gateway device 600, and one or more software applications.

[0190] In one embodiment, input device 615 may include any known computer input device, including a touch panel, buttons, keyboard, stylus, microphone, etc. In some embodiments, input device 615 may be integrated with output device 620, for example, as a touchscreen or similar touch-sensitive display. In some embodiments, input device 615 includes a touchscreen, allowing text to be entered using a virtual keyboard displayed on the touchscreen and / or by handwriting on the touchscreen. In some embodiments, input device 615 includes two or more different devices, such as a keyboard and a touch panel.

[0191] In one embodiment, output device 620 may include any known electronically controllable display or display device. Output device 620 may be designed to output visual, auditory, and / or tactile signals. In some embodiments, output device 620 includes an electronic display or display device capable of outputting visual data to a user. For example, output device 620 may include, but is not limited to, LCD displays, LED displays, OLED displays, projectors, or similar display devices capable of outputting images, text, etc., to a user. As another non-limiting example, output device 620 may include wearable displays, such as smartwatches, smart glasses, heads-up displays, etc. Furthermore, output device 620 may be a component of a smartphone, personal digital assistant, television, desktop computer, laptop computer, personal computer, vehicle dashboard, etc.

[0192] In some embodiments, output device 620 includes one or more speakers for generating sound. For example, output device 620 may generate an auditory alarm or notification (e.g., a buzzer or ring). In some embodiments, output device 620 includes one or more haptic devices for generating vibration, motion, or other haptic feedback. In some embodiments, all or part of output device 620 may be integrated with input device 615. For example, input device 615 and output device 620 may form a touchscreen or similar touch-sensitive display. In other embodiments, all or part of output device 620 may be located near input device 615.

[0193] As discussed above, transceiver 625 can communicate with one or more remote units and / or with one or more interoperability functions that provide access to one or more PLMNs. Transceiver 625 can also communicate with one or more network functions (e.g., in mobile core network 130). Transceiver 625 operates under the control of processor 605 to transmit and receive messages, data, and other signals. For example, processor 605 can selectively activate the transceiver (or a portion thereof) at specific times to transmit and receive messages.

[0194] Transceiver 625 may include one or more transmitters 630 and one or more receivers 635. In some embodiments, one or more transmitters 630 and / or one or more receivers 635 may share transceiver hardware and / or circuitry. For example, one or more transmitters 630 and / or one or more receivers 635 may share antennas, antenna tuners, amplifiers, filters, oscillators, mixers, modulators / demodulators, power supplies, etc. In one embodiment, transceiver 625 implements multiple logical transceivers using different communication protocols or protocol stacks while using common physical hardware.

[0195] Figure 7 One embodiment of a method 700 for a UE to access a specific service using information provision according to embodiments of the present disclosure is described. In various embodiments, method 700 is performed by a UE, such as remote unit 105, UE 205, and / or user equipment device 500 as described above. In some embodiments, method 700 is performed by a processor, such as a microcontroller, microprocessor, CPU, GPU, auxiliary processing unit, FPGA, etc.

[0196] Method 700 begins and sends 705 a first registration request to register the UE with a mobile communication network, which supports multiple network slices. Method 700 includes receiving 710 configuration information from the mobile communication network, the configuration information enabling the UE to use at least one network slice from the multiple network slices. Method 700 includes performing 715 cell reselection using the configuration information, the configuration information including at least a frequency priority for at least one network slice. Method 700 includes sending 720 a second registration request to the mobile communication network after performing the cell reselection, wherein the second registration request registers with at least one network slice. Method 700 ends.

[0197] Figure 8 One embodiment of a method 800 for using information provision to a UE to access a specific service is described according to embodiments of the present disclosure. In various embodiments, method 800 is performed by an AMF, such as AMF 133, AMF 211 and / or network device device 600 as described above. In some embodiments, method 800 is performed by a processor, such as a microcontroller, microprocessor, CPU, GPU, auxiliary processing unit, FPGA, etc.

[0198] Method 800 begins and receives 805 a first registration request to register the UE with the mobile communication network. A second method includes receiving 810 subscription information of the UE from the mobile communication network. Here, the subscription information enables the UE to use a specific service. Method 800 includes determining 815 configuration information to be supplied to the UE. Here, the configuration information includes frequency priorities for at least each of a plurality of network slices. Method 800 includes supplying the UE using the configuration information. Method 800 includes receiving 825 a second registration request from the UE in response to supplying the UE. Method 800 ends.

[0199] Figure 9 One embodiment of a method 900 for using information provision to a UE to access a specific service is described according to embodiments of the present disclosure. In various embodiments, method 900 is performed by a subscription and user data manager, such as UDM / UDR 139, UDM 213 and / or network device device 600 as described above. In some embodiments, method 900 is performed by a processor, such as a microcontroller, microprocessor, CPU, GPU, auxiliary processing unit, FPGA, etc.

[0200] Method 900 begins and at least stores 905 the default subscription information and updated subscription information of the UE. Here, the default subscription information enables the UE to access a default service, and the updated subscription information enables the UE to use a specific service. Method 900 includes receiving 910 a request for subscription data from the AMF for the UE. Method 900 includes determining 915 that the UE needs to be supplied and determining the type of subscription data to be sent to the AMF. Here, the type of subscription data can be either default subscription information or updated subscription information. Method 900 includes sending 920 subscription data to the AMF to configure the UE to use a specific service. Method 900 ends.

[0201] According to embodiments of this disclosure, a first apparatus is disclosed for using information provision to a UE to access a specific service. The first apparatus may be implemented by a UE such as remote unit 105, UE 205, and / or user equipment apparatus 500. The first apparatus includes: a transceiver communicating with a mobile communication network; and a processor sending a first registration request to the mobile communication network, which supports multiple network slices. The processor receives configuration information from the mobile communication network that enables the apparatus to use a specific service (e.g., from at least one network slice among the multiple network slices). In one embodiment, the configuration information includes frequency priorities for the at least one network slice. In another embodiment, the configuration information includes frequency priorities for each of the multiple network slices. The processor uses at least the frequency priorities to perform cell reselection and, after performing cell reselection, sends a second registration request to the mobile communication network. In one embodiment, the second registration request registers with at least one network slice.

[0202] In some embodiments, the configuration information includes network slice configuration data and mobility restriction configuration data including cell restrictions on closed access groups. Here, the network slice configuration data includes allowed network slice information and (i.e., enhanced) configured network slice information of the mobile communication network. In such embodiments, receiving the configuration information may include receiving information from the AMF in the mobile communication network.

[0203] In some embodiments, the configuration information includes the frequency priority of network slice information for (i.e., by default) configuration. In some embodiments, the configuration information includes at least one security parameter for secondary authentication, the at least one security parameter including: an identifier, credentials, and an association with a service identifier. Here, the service identifier may be S-NSSAI, DNN, and / or an application.

[0204] In some embodiments, the processor stores the received configuration information in a subscription profile (e.g., in a USIM). In other embodiments, the processor stores the received configuration information in a mobile device configuration (e.g., at the NAS layer or at the application).

[0205] According to embodiments of this disclosure, a first method is disclosed for using information provision to a UE to access a specific service. The first method can be performed by a UE such as remote unit 105, UE 205, and / or user equipment device 500. The first method includes sending a first registration request to a mobile communication network that supports multiple network slices. The first method includes receiving configuration information from the mobile communication network that enables the UE to use the specific service, wherein the configuration information includes frequency priorities for each of the multiple network slices. The first method includes performing cell reselection using at least the frequency priorities and sending a second registration request to the mobile communication network after performing the cell reselection.

[0206] In some embodiments, the configuration information includes network slice configuration data and mobility restriction configuration data including cell restrictions on closed access groups. Here, the network slice configuration data includes allowed network slice information and (i.e., enhanced) configured network slice information of the mobile communication network. In such embodiments, receiving the configuration information may include receiving information from the AMF in the mobile communication network.

[0207] In some embodiments, the configuration information includes the frequency priority of network slice information for (i.e., by default) configuration. In some embodiments, the configuration information includes at least one security parameter for secondary authentication, which includes: an identifier, credentials, and an association with a service identifier. Here, the service identifier may be S-NSSAI, DNN, and / or an application.

[0208] In some embodiments, the first method includes storing the received configuration information in the UE's subscription profile (e.g., in a USIM). In other embodiments, the first method includes storing the received configuration information in the UE's mobile device configuration (e.g., at the NAS layer or at the application).

[0209] According to embodiments of this disclosure, a second apparatus is disclosed for supplying a UE with information to access a specific service. The second apparatus may be implemented by an AMF such as AMF 133, AMF 211, and / or network device apparatus 600. The second apparatus includes a network interface and a processor that receives a first registration request to register a UE with a mobile communication network. The processor receives subscription information of the UE from the mobile communication network, which enables the UE to use a specific service. The processor determines configuration information to supply the UE. Here, the configuration information includes frequency priorities for at least each of a plurality of network slices. The processor supplies the UE with the configuration information and receives a second registration request from the UE in response to supplying the UE.

[0210] In some embodiments, the processor determines whether to supply the UE before or along with the registration result. In some embodiments, the processor supplies the UE with configuration information by performing a UE configuration update procedure. In some embodiments, the processor sends a registration rejection message to the UE in response to performing the UE configuration update procedure, wherein the registration rejection message triggers cell reselection and re-registration of the UE to the same mobile communication network.

[0211] In some embodiments, the processor registers the UE in response to a first registration request. In such embodiments, registering the UE includes receiving default subscription information for the UE, wherein the default subscription information is for a default service (i.e., excluding service-specific subscriptions). In some embodiments, the default subscription information is updated by enabling the UE to use service-specific subscription information. In such embodiments, the processor subscribes to a mobile communication network (i.e., UDM) for notifications regarding UE subscriptions and receives updated subscription information from the UE, wherein the updated subscription information includes service-specific subscription information. In some embodiments, the subscription information includes configuration information having frequency priorities for each of a plurality of network slices.

[0212] In some embodiments, the processor supplies configuration information to the UE by sending a registration accept message. In some embodiments, the registration accept message includes an empty set of allowed network slices. In some embodiments, at least one subscribed network slice requires secondary authentication. In such embodiments, the processor skips the secondary authentication process (i.e., the NSSAA process) after sending the registration accept message. In one embodiment, skipping the secondary authentication process includes omitting the "Pending NSSAA" parameter in the registration accept message.

[0213] In some embodiments, the configuration information includes mobility restriction configuration data containing cell restrictions for closed access groups and at least one transparent container containing security parameters for secondary authentication of the UE. The security parameters include at least one of the following: an identifier, a credential, and an association with a service identifier. Here, the service identifier may be S-NSSAI, DNN, and / or an application. In some embodiments, the configuration information configures the second device, for example, by updating the closed access group ID of the allowed NSSAI.

[0214] In some embodiments, after successful registration, the processor receives a container with updated UE parameters and forwards the container with updated UE parameters to the UE, wherein the updated UE parameters include at least one of the following: (i.e., enhanced) default configuration network slice information and security parameters, wherein the default configuration network slice information includes frequency priorities for each of a plurality of network slices.

[0215] In some embodiments, the UE's service subscription is associated with the UE's device identity, wherein the processor receives a request to provide an additional UE identity and provides the UE's device identity to the network.

[0216] According to embodiments of this disclosure, a second method is disclosed for supplying information to a UE to access a specific service. The second method may be performed by an AMF such as AMF 133, AMF 211, and / or network device device 600. The second method includes receiving a first registration request to register the UE with a mobile communication network. The second method includes receiving subscription information of the UE from the mobile communication network and determining configuration information to be supplied to the UE. Here, the subscription information and configuration information enabling the UE to use the specific service include frequency priorities for at least each of a plurality of network slices. The second method includes supplying the UE with the configuration information and receiving a second registration request from the UE in response to supplying the UE.

[0217] In some embodiments, the second method includes determining whether to supply the UE before or with the registration result. In some embodiments, the second method includes supplying the UE with configuration information by performing a UE configuration update procedure. In some embodiments, the second method includes sending a registration rejection message to the UE in response to performing the UE configuration update procedure, wherein the registration rejection message triggers cell reselection and re-registration of the UE to the same mobile communication network.

[0218] In some embodiments, the second method includes registering the UE in response to a first registration request. In such embodiments, registering the UE includes receiving default subscription information for the UE, wherein the default subscription information is for a default service (i.e., excluding service-specific subscriptions). In some embodiments, the default subscription information is updated by enabling the UE to use service-specific subscription information. In such embodiments, the second method includes subscribing to a mobile communication network (i.e., UDM) for notifications regarding UE subscriptions and receiving updated subscription information for the UE, wherein the updated subscription information includes service-specific subscription information. In some embodiments, the subscription information includes configuration information having frequency priorities for each of a plurality of network slices.

[0219] In some embodiments, the second method includes supplying configuration information to the UE by sending a registration acceptance message. In some embodiments, the registration acceptance message includes an empty set of allowed network slices. In some embodiments, at least one subscribed network slice requires secondary authentication. In such embodiments, the second method includes skipping the secondary authentication process (i.e., the NSSAA process) after sending the registration acceptance message. In one embodiment, skipping the secondary authentication process includes omitting the "Pending NSSAA" parameter in the registration acceptance message.

[0220] In some embodiments, the configuration information includes mobility restriction configuration data containing cell restrictions for closed access groups and at least one transparent container containing security parameters for secondary authentication of the UE. The security parameters include at least one of the following: an identifier, a credential, and an association with a service identifier. Here, the service identifier may be S-NSSAI, DNN, and / or an application identifier. In some embodiments, the configuration information configures the second device, for example, by updating the closed access group ID of the allowed NSSAI.

[0221] In some embodiments, the second method includes receiving a container with updated UE parameters after successful registration and forwarding the container with updated UE parameters to the UE. Here, the updated UE parameters may include default configured network slice information and / or security parameters, wherein the default configured network slice information includes frequency priorities for each of a plurality of network slices.

[0222] In some embodiments, the UE's service subscription is associated with the UE's device identity, wherein the second method includes receiving a request to provide an additional UE identity and providing the UE's device identity to the network.

[0223] According to embodiments of this disclosure, a third apparatus is disclosed for supplying information to a UE to access a specific service. The third apparatus may be implemented by a subscription and user data manager such as UDM / UDR 139, UDM213, and / or network device apparatus 600. The third apparatus includes: a network interface for communicating with an AMF (Advanced Management Function) in at least a mobile communication network; and a processor for storing subscription information for the UE. The processor stores at least default subscription information and updated subscription information for the UE. Here, the default subscription information enables the UE to access a default service, and the updated subscription information enables the UE to use a specific service. The processor receives a request for subscription data from the AMF and determines that the UE needs to be supplied and determines the type of subscription data to be sent to the AMF. Here, the type of subscription data may be default subscription information or updated subscription information. The processor sends the subscription data to the AMF to configure the UE to use the specific service.

[0224] In various embodiments, the subscription data also configures the mobile communication network (e.g., AMF and / or RAN) to use specific services. For example, updated subscription information may be used by the network to update the list of allowed closed access group IDs or allowed NSSAIs stored in the AMF and sent to the access network. In some embodiments, the updated subscription information includes at least one of the following: network slice identity, data network name, information for cell reselection, and a list of allowed closed access groups. In some embodiments, the updated subscription information includes a list of UE identities supplied with the updated subscription information. In such embodiments, the list of identities may include a list of subscription identities and / or a list of device identities.

[0225] In some embodiments, the processor sends a request for the UE's device identity to the AMF in response to a list of UE identities that includes a list of device identities. In some embodiments, determining that the UE needs to provide includes determining whether a first identity of the UE is found in the list of UE identities and mapping the first identity to a first subscription type, wherein the default subscription type is a topic updated with updated subscription information.

[0226] In some embodiments, the processor receives a second request to activate or deactivate updated subscription information, wherein the second request is received from the application function via the NEF. In some embodiments, the processor sends a container with updated UE parameters to the AMF after successful registration, wherein the AMF forwards the container with updated UE parameters to the UE. In such embodiments, the updated UE parameters may include one or more of the following: security parameters and (i.e., enhanced) default configuration network slice information, wherein the default configuration network slice information includes frequency priorities for each of a plurality of network slices.

[0227] According to embodiments of this disclosure, a third method is disclosed for supplying information to a UE to access a specific service. The third method can be performed by a subscription and user data manager such as UDM / UDR 139, UDM213, and / or network device device 600. The third method includes storing at least default subscription information and updated subscription information of the UE. Here, the default subscription information enables the UE to access a default service, and the updated subscription information enables the UE to use a specific service. The third method includes receiving a request for subscription data for the UE from the AMF and determining that the UE needs to be supplied and determining the type of subscription data to be sent to the AMF. Here, the type of subscription data can be default subscription information or updated subscription information. The third method includes sending subscription data to the AMF to configure the UE to use the specific service.

[0228] In some embodiments, the updated subscription information includes at least one of the following: network slice identity, data network name, information for cell reselection, and a list of allowed closed access groups. In some embodiments, the updated subscription information includes a list of UE identities that have provided the updated subscription information. In such embodiments, the list of identities may include a list of subscription identities and / or a list of device identities.

[0229] In some embodiments, the third method includes sending a request for a device identity of the UE to the AMF in response to a list of UE identities that includes a list of device identities. In some embodiments, determining that the UE needs to provide includes determining whether a first identity of the UE is found in the list of UE identities and mapping the first identity to a first subscription type, wherein the default subscription type is a topic updated with updated subscription information.

[0230] In some embodiments, the third method includes receiving a second request to activate or deactivate updated subscription information, wherein the second request is received from the application function via the NEF. In some embodiments, the third method includes sending a container with updated UE parameters to the AMF after successful registration, wherein the AMF forwards the container with updated UE parameters to the UE. In such embodiments, the updated UE parameters may include one or more of the following: security parameters and (i.e., enhanced) default configuration network slice information, wherein the default configuration network slice information includes frequency priorities for each of a plurality of network slices.

[0231] The embodiments may be practiced in other specific forms. The described embodiments are to be considered in all respects as illustrative rather than restrictive. Therefore, the scope of the invention is indicated by the appended claims rather than by the foregoing description. All variations within the equivalent meaning and scope of the claims should be covered within their scope.

Claims

1. An apparatus for wireless communication, comprising: At least one memory; as well as At least one processor, coupled to the at least one memory, and configured to enable network functionality: Receive a first message about the reachability state of a user equipment (UE) associated with the provision of a set of credentials, wherein the set of credentials is used for network slice-specific authentication and authorization (NSSAA) or secondary authentication and authorization (SAA), or a combination thereof; The availability of the UE to the supply is determined at least in part based on the first message; and The notification that the UE is reachable is sent at least in part based on the determination. Receive a second message instructing the user equipment (UE) to register to a subscription network associated with the network function; Whether to supply the set of credentials to the UE is determined at least in part based on the received second message; as well as The set of credentials is supplied to the UE at least in part based on the determination.

2. The apparatus according to claim 1, wherein, The network functions include Unified Data Management (UDM).

3. The apparatus according to claim 1, wherein, The NSSAA is used to subscribe to network slices associated with the UE.

4. The apparatus according to claim 1, wherein, In order to receive the first message subscribing to the UE reachability, the at least one processor is configured to cause the network function to receive the first message from the provisioning server.

5. The apparatus according to claim 1, wherein, In order to send the notification that the UE is reachable, the at least one processor is configured to cause the network function to send the notification to the provisioning server.

6. The apparatus according to claim 1, wherein, To determine whether the UE is reachable for remote provisioning, the at least one processor is configured to enable the network function to determine that the UE can establish a user plane to the provisioning server.

7. The apparatus according to claim 1, wherein, User plane connectivity includes Protocol Data Unit (PDU) sessions.

8. A processor for wireless communication in a network function, comprising: At least one controller, coupled to at least one memory, and configured to cause the processor to: Receive a first message about the reachability state of a user equipment (UE) associated with the provision of a set of credentials, wherein the set of credentials is used for network slice-specific authentication and authorization (NSSAA) or secondary authentication and authorization (SAA), or a combination thereof; The availability of the UE to the supply is determined at least in part based on the first message; and The notification that the UE is reachable is sent at least in part based on the determination. Receive a second message instructing the user equipment (UE) to register to a subscription network associated with the network function; Whether to supply the set of credentials to the UE is determined at least in part based on the received second message; as well as The set of credentials is supplied to the UE at least in part based on the determination.

9. The processor according to claim 8, wherein, The network functions include Unified Data Management (UDM).

10. The processor according to claim 8, wherein, The NSSAA is used to subscribe to network slices associated with the UE.

11. The processor according to claim 8, wherein, In order to receive a first message about subscribing to the UE's reachability, the at least one controller is configured to cause the network function to receive the first message from the provisioning server.

12. The processor according to claim 8, wherein, In order to send the notification that the UE is reachable, the at least one controller is configured to cause the network function to send the notification to the provisioning server.

13. The processor according to claim 8, wherein, To determine whether the UE is reachable for remote provisioning, the at least one controller is configured to enable the network function to determine that the UE can establish a user plane to the provisioning server.

14. The processor according to claim 8, wherein, User plane connectivity includes Protocol Data Unit (PDU) sessions.

15. A method performed by a network function, the method comprising: Receive a first message about the reachability state of a user equipment (UE) associated with the provision of a set of credentials, wherein the set of credentials is used for network slice-specific authentication and authorization (NSSAA) or secondary authentication and authorization (SAA), or a combination thereof; The availability of the UE to the supply is determined at least in part based on the first message; and The notification that the UE is reachable is sent at least in part based on the determination. Receive a second message instructing the user equipment (UE) to register to a subscription network associated with the network function; Whether to supply the set of credentials to the UE is determined at least in part based on the received second message; as well as The set of credentials is supplied to the UE at least in part based on the determination.

16. The method according to claim 15, wherein, The network functions include Unified Data Management (UDM).

17. The method according to claim 15, wherein, The NSSAA is used to subscribe to network slices associated with the UE.

18. The method according to claim 15, wherein, The method of receiving a first message subscribing to the UE reachability includes receiving the first message from a provisioning server.

19. The method according to claim 15, wherein, Determining whether the UE is reachable for remote provisioning includes: determining that the UE is able to establish a user plane to the provisioning server.

20. The method of claim 15, wherein, Sending the notification that the UE is reachable, the method includes sending the notification to a provisioning server.

Citation Information

Patent Citations

  • Data Transmission over User Plane for Cellular IoT

    US20190306251A1