Amf node and method thereof
Managing the network slice identifier set in the UE context through the AMF node solves the problem of how to properly handle the identifier status during re-authentication and re-authorization, improving system security and signaling efficiency.
Patent Information
- Application Number
- CN202211018521.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-12-26
- Filing Date
- 2020-12-18
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2040-12-18
AI Technical Summary
In the AMF node, it is unclear how to properly manage the UE context when the Network Slice Specific Authentication and Authorization (NSSAA) re-authentication and re-authorization procedures are triggered, especially how to handle the stored state of the currently allowed network slice identifiers.
The AMF node includes a memory and a processor for managing the allowed and pending network slice identifier sets in the UE context and performing corresponding identifier state transitions during reauthentication and reauthorization, such as transferring from allowed NSSAI to pending NSSAI or remaining in allowed NSSAI.
The AMF node can properly manage the UE context during the re-authentication and re-authorization process, thereby improving the system security and signaling efficiency and reducing the occurrence of invalid signaling.
Smart Images

Figure CN115499835B_ABST
Abstract
Description
[0001] This application is a divisional application of the application with the application number 202080054992.X, the application date of 2020-12-18, and the title of “AMF node and method thereof”. TECHNICAL FIELD
[0002] The present application relates to cellular networks, and in particular to management of network slices allowed for a radio terminal. BACKGROUND
[0003] A 5G system (5GS) supports network slicing (see, for example, Non-Patent Literature 1 to 3, in particular, Section 5.15 of Non-Patent Literature 1). Network slicing uses network function virtualization (NFV) and software defined network (SDN) technologies, whereby multiple virtualized logical networks are created on a physical network. Each virtualized logical network is referred to as a network slice. A network slice provides specific network functions and network characteristics. To form a single network slice, a network slice instance (NSI) is defined as a collection of network function (NF) instances, resources (e.g., computer processing resources, storage, and network resources), and an access network (AN) (at least one of a next generation radio access network (NG-RAN) and a non-3GPP interworking function (N3IWF)).
[0004] A network slice is identified by an identifier called single network slice selection assistance information (S-NSSAI). An S-NSSAI consists of a slice / service type (SST) and a slice differentiator (SD). The SST refers to an expected network slice behavior in terms of features and services. The SD is optional information and complements the SST to differentiate multiple network slices of the same slice / service type.
[0005] An S-NSSAI can have a standard value or a non-standard value. Currently, standard SST values 1, 2, 3, and 4 are associated with enhanced mobile broadband (eMBB), ultra-reliable low-latency communication (URLLC), massive Internet of Things (MIoT), and vehicle-to-everything (V2X) slice types, respectively. A non-standard value of an S-NSSAI is used to identify a single network slice within a specific public land mobile network (PLMN). In other words, a non-standard value is a PLMN-specific value and is associated with a PLMN ID of a PLMN that has assigned the value. Each S-NSSAI ensures network isolation by selecting a specific NSI. An NSI can be selected via different S-NSSAIs. An S-NSSAI can be associated with different NSIs. A network slice can be uniquely identified by an S-NSSAI.
[0006] There are two types of S-NSSAI, which are referred to as S-NSSAI and mapped S-NSSAI. The S-NSSAI identifies a network slice served by a public land mobile network (PLMN) in which the UE is registered. The mapped S-NSSAI can be an S-NSSAI of a home PLMN (HPLMN) that is mapped to (associated with or applicable to) an S-NSSAI for identifying a network slice of a roaming network when the UE is roaming, or an S-NSSAI included in subscription information of the UE. Hereinafter, the S-NSSAI and the mapped S-NSSAI can be simply collectively referred to as S-NSSAI in the present specification.
[0007] In an aspect, a network slice selection assistance information (NSSAI) refers to a set of S-NSSAIs. Thus, one or more S-NSSAIs can be included in one NSSAI. There are various types of NSSAI, which are referred to as configured NSSAI, requested NSSAI, allowed NSSAI, rejected NSSAI, and pending NSSAI.
[0008] The configured NSSAI includes one or more S-NSSAIs each applicable to one or more PLMNs. For example, the configured NSSAI is configured by a serving PLMN and is applicable to the serving PLMN. Alternatively, the configured NSSAI can be a default configured NSSAI. The default configured NSSAI is configured by a home PLMN (HPLMN) and is applicable to any PLMN for which a specific configured NSSAI has not been provided. For example, the default configured NSSAI is provided from a unified data management (UDM) of the HPLMN to a radio terminal (user equipment (UE)) via an access and mobility management function (AMF).
[0009] The UE signals the requested NSSAI to the network, for example, in a registration procedure, thereby enabling the network to determine a serving AMF, at least one network slice, and at least one NSI for the UE.
[0010] The allowed NSSAI is provided by a serving PLMN to a UE and indicates one or more S-NSSAIs that the UE can use in a current registration area of the serving PLMN. The allowed NSSAI is determined by an AMF of the serving PLMN, for example, during a registration procedure. Thus, the allowed NSSAI is signaled by the network (i.e., the AMF) to the UE and stored in a (non-volatile) memory of both the AMF and the UE.
[0011] The rejected NSSAI includes one or more S-NSSAIs rejected by the current PLMN. The rejected NSSAI can be referred to as rejected S-NSSAIs. An S-NSSAI is rejected throughout the current PLMN or rejected in the current registration area. If the AMF rejects any of the one or more S-NSSAIs included in the requested NSSAI, for example, in the registration procedure of the UE, the AMF includes it in the rejected NSSAI. The rejected NSSAI is signaled to the UE by the network (i.e., the AMF) and stored in the (non-volatile) memory of both the AMF and the UE.
[0012] The pending NSSAI is newly negotiated in the Third Generation Partnership Project (3GPP) (see Non-Patent Literature 4). The pending NSSAI indicates one or more S-NSSAIs for which Network Slice Specific Authentication and Authorization (NSSAA) is pending. The serving PLMN should perform NSSAA for the S-NSSAIs of the HPLMN to be subjected to NSSAA based on the subscription information. To perform the NSSAA, the AMF invokes an Extensible Authentication Protocol (EAP)-based authorization procedure. The EAP-based authentication procedure takes a relatively long time to obtain its result. Therefore, while the AMF determines the allowed NSSAI during the registration procedure of the UE as described above, the S-NSSAIs subjected to the NSSAA are not included in the allowed NSSAI but included in the pending NSSAI. The pending NSSAI is signaled to the UE by the network (i.e., the AMF) and stored in the (non-volatile) memory of both the AMF and the UE.
[0013] The AMF manages the UE context of the UE in the Registration Management (RM) REGISTERED state. The UE context can be referred to but not limited to a Mobility Management (MM) context. The UE context can include one or more of the allowed NSSAI, the rejected NSSAI, and the pending NSSAI described above. On the other hand, the UE manages the UE NSSAI configuration, which includes the configured NSSAI, the allowed NSSAI, the rejected NSSAI, and the pending NSSAI described above. The UE NSSAI configuration is stored in the non-volatile memory in the UE (Mobile Equipment (ME) other than the Universal Subscriber Identity Module (USIM)). The memory or memory area in which the UE NSSAI configuration is stored is referred to as the NSSAI storage.
[0014] Section 5.15.10 of Non-Patent Literature 1 (3GPP TS 23.501) and Section 4.2.9 of Non-Patent Literature 2 (3GPP TS 23.502) specify Network Slice Specific Authentication and Authorization (NSSAA). More specifically, Section 5.15.10 of Non-Patent Literature 1 and Section 4.2.9.2 of Non-Patent Literature 2 describe NSSAA. Section 5.15.10 of Non-Patent Literature 1 and Section 4.2.9.3 of Non-Patent Literature 2 describe re-authentication and re-authorization triggered by an Authentication, Authorization and Accounting (AAA) Server (AAA-S). Section 5.15.10 of Non-Patent Literature 1 and Section 4.2.9.4 of Non-Patent Literature 2 describe revocation of slice specific authorization triggered by the AAA server. In addition, Non-Patent Literature 5 describes a proposed amendment to the revocation of slice specific authorization specified in Section 4.2.9.4 of Non-Patent Literature 2.
[0015] Bibliographic List
[0016] Non-Patent Literature
[0017] [Non-Patent Literature 1] 3GPP TS 23.501 V16.2.0 (2019-09) “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System Architecture for the 5G System (5GS); Stage 2 (Release 16)”, September 2019
[0018] [Non-Patent Literature 2] 3GPP TS 23.502 V16.2.0 (2019-09) “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS); Stage 2 (Release 16)”, September 2019
[0019] [Non-Patent Literature 3] 3GPP TS 24.501 V16.2.0 (2019-09) "3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Non-Access-Stratum (NAS) protocol for 5G System (5GS); Stage 3 (Release 16)", September 2019
[0020] [Non-Patent Literature 4] InterDigital, ZTE, vivo, NEC, "Introduction of pending NSSAI for network slice-specific authentication and authorization", C1-199044, 3GPP TSG-CT WG1 Meeting #121, Reno (NV), USA, 11-15 November 2019
[0021] [Non-Patent Literature 5] China Mobile, Nokia, Ericsson, Telecom Italia, "Service used for slice-specific re-authentication and revocation", S2-1912488, 3GPP TSG-SAWG2 Meeting #136, Reno NV, USA, 18-22 November 2019 SUMMARY
[0022] PROBLEMS TO BE SOLVED BY THE INVENTION
[0023] The AMF can re-perform network slice specific authentication and authorization (NSSAA) for one or more of the current allowed S-NSSAIs of the UE (see, for example, section 4.2.9 of Non-Patent Literature 2). More specifically, the AMF triggers initiation of NSSAA for one or more of the current allowed S-NSSAIs if an authentication, authorization, and accounting (AAA) server triggers re-authentication for the S-NSSAI(s). In addition, the AMF can determine that one or more of the current allowed S-NSSAIs of the UE requires re-authentication based on a change in subscription information of the UE. Furthermore, when the AMF receives a registration request message for a mobility registration update or periodic registration update from the UE, the AMF can determine that one or more of the current allowed S-NSSAIs requires re-authentication, for example, based on an operator policy. In addition, the AMF can determine that one or more of the current allowed S-NSSAIs requires re-authentication based on an operator policy, in addition to these conditions. In these cases, the AMF triggers initiation of NSSAA for the S-NSSAI(s) that requires re-authentication.
[0024] However, in a case where the AMF triggers initiation of a re-authentication and re-authorization procedure (i.e., NSSAA) for a specific current allowed S-NSSAI of a UE, it is unclear how the AMF should handle the UE context of the UE managed by the AMF. More specifically, it is unclear whether the AMF should (a) continue to store the specific S-NSSAI in the allowed NSSAI of the UE context used for the UE.
[0025] One of the objects of the embodiments disclosed herein is to provide devices, methods, and programs that facilitate enabling the AMF to appropriately manage the UE context in a case where the AMF triggers initiation of a re-authentication and re-authorization procedure for a specific network slice identifier (e.g., S-NSSAI) currently allowed for a UE. It should be noted that this object is only one of the objects of the embodiments disclosed herein. Other objects or problems and novel features will become clear from the following description and the attached drawings.
[0026] Solutions to the problems
[0027] In a first aspect, an AMF includes at least one memory and at least one processor coupled to the at least one memory. The at least one processor is configured to manage a UE context related to a UE. The UE context includes: a) a set of allowed network slice identifiers indicating one or more network slice identifiers currently allowed for the UE; and b) a set of pending network slice identifiers indicating one or more network slice identifiers pending a network slice specific authentication and authorization procedure, NSSAA procedure. The at least one processor is further configured to, in a case that the at least one processor triggers initiation of a re-authentication and re-authorization procedure for a first network slice identifier currently allowed for the UE, remove the first network slice identifier from the set of allowed network slice identifiers and store the first network slice identifier in the set of pending network slice identifiers.
[0028] In a second aspect, a method in an AMF includes the following steps:
[0029] (a) managing a user equipment context, UE context, related to a UE, wherein the UE context includes: a) a set of allowed network slice identifiers indicating at least one network slice identifier currently allowed for the UE; and b) a set of pending network slice identifiers indicating at least one network slice identifier pending a network slice specific authentication and authorization procedure, NSSAA procedure; and
[0030] (b) in a case that the AMF triggers initiation of a re-authentication and re-authorization procedure for a first network slice identifier currently allowed for the UE, removing the first network slice identifier from the set of allowed network slice identifiers and storing the first network slice identifier in the set of pending network slice identifiers.
[0031] In a third aspect, an AMF includes at least one memory and at least one processor coupled to the at least one memory. The at least one processor is configured to manage a UE context related to a UE. The UE context includes: a) a set of allowed network slice identifiers indicating one or more network slice identifiers currently allowed for the UE; and b) a set of pending network slice identifiers indicating one or more network slice identifiers pending a network slice specific authentication and authorization procedure, NSSAA procedure. The at least one processor is further configured to, in a case that the at least one processor triggers initiation of a re-authentication and re-authorization procedure for a first network slice identifier currently allowed for the UE, continue storing the first network slice identifier in the set of allowed network slice identifiers.
[0032] In a fourth aspect, a method in an AMF includes the following steps:
[0033] (a) managing a user equipment context, i.e., UE context, related to the UE, wherein the UE context includes: a) a set of allowed network slice identifiers indicating at least one network slice identifier currently allowed for the UE; and b) a set of pending network slice identifiers indicating at least one network slice identifier pending a network slice specific authentication and authorization procedure, i.e., NSSAA procedure; and
[0034] (b) in a case where the AMF triggers initiation of a re-authentication and re-authorization procedure for a first network slice identifier currently allowed for the UE, continuing to store the first network slice identifier in the set of allowed network slice identifiers.
[0035] In a fifth aspect, a program includes instructions (software code) that, when loaded into a computer, cause the computer to perform the method according to the above-described second aspect or fourth aspect.
[0036] Effects of the Invention
[0037] According to the above-described aspects, it is possible to provide a device, method, and program that contribute to enabling an AMF to appropriately manage a UE context in a case where the AMF triggers initiation of a re-authentication and re-authorization procedure for a specific network slice identifier, e.g., S-NSSAI, currently allowed for a UE. BRIEF DESCRIPTION OF DRAWINGS
[0038] Figure 1 is a diagram illustrating a structure example of a cellular network according to an embodiment;
[0039] Figure 2 is a flowchart illustrating an example of operations of an AMF according to an embodiment;
[0040] Figure 3 is a sequence diagram illustrating an example of operations of a UE, an AMF, and an AUSF according to an embodiment;
[0041] Figure 4 is a flowchart illustrating an example of operations of an AMF according to an embodiment;
[0042] Figure 5 is a flowchart illustrating an example of operations of an AMF according to an embodiment;
[0043] Figure 6 is a flowchart illustrating an example of operations of an AMF according to an embodiment;
[0044] Figure 7 is a flowchart illustrating an example of operations of an AMF according to an embodiment;
[0045] Figure 8is a sequence diagram showing an example of operations of a UE, an AMF, and an AUSF according to an embodiment;
[0046] Figure 9 is a flowchart illustrating an example of the operation of the AMF according to an embodiment;
[0047] Figure 10 is a flowchart illustrating an example of the operation of the AMF according to an embodiment;
[0048] Figure 11 is a flowchart illustrating an example of the operation of the AMF according to an embodiment;
[0049] Figure 12 is a block diagram showing a structural example of a UE according to an embodiment; and
[0050] Figure 13 is a block diagram showing a structural example of an AMF according to an embodiment. DETAILED DESCRIPTION
[0051] The specific embodiments will be described in detail below with reference to the accompanying drawings. In the entire drawings, the same or corresponding elements are represented by the same symbols, and for the sake of clarity, repeated descriptions are omitted when necessary.
[0052] Each embodiment described below can be used alone, or two or more embodiments can be appropriately combined. These embodiments include different novel features. Therefore, these embodiments help to achieve different purposes or solve different problems, and help to obtain different advantages.
[0053] The following description of the embodiments focuses primarily on the 3rd Generation Partnership Project (3GPP) fifth generation mobile communication system (5G system (5GS)). However, these embodiments may be applicable to other cellular communication systems that support network slicing similar to that in 5GS.
[0054] First embodiment
[0055] Figure 1 A structural example of a cellular network (i.e., 5GS) according to this embodiment is shown. Figure 1 The elements shown are network functions and provide interfaces as defined by the 3rd Generation Partnership Project (3GPP). Figure 1 The elements (network functions) shown may be implemented, for example, as network elements on dedicated hardware, as software instances running on dedicated hardware, or as virtual functions instantiated on an application platform.
[0056] Figure 1The illustrated cellular network can be provided by a mobile network operator (MNO), or the cellular network can be a non-public network (NPN) provided by a non-MNO. If Figure 1 The illustrated cellular network is a NPN, it can be a standalone network denoted as standalone non-public network (SNPN), or it can be a NPN linked to a MNO network denoted as public network integrated NPN.
[0057] The radio terminal (i.e., UE) 1 uses a 5G connectivity service and communicates with a data network (DN) 7. More specifically, the UE 1 connects to an access network (i.e., 5G access network (5GAN)) 5 and communicates with the DN 7 via a user plane function (UPF) 6 in a core network (i.e., 5G core network (5GC)). The AN 5 can comprise a next generation radio access network (NG-RAN) or a non-3GPP AN or both. The non-3GPP AN can be a network for handling wireless LAN (WiFi) communication or a network for handling wired communication referred to as wired 5G access network (W-5GAN). The UPF 6 can comprise a plurality of UPFs interconnected.
[0058] In the 5G architecture, the connectivity service between the UE 1 and the DN 7 is supported by one or more protocol data unit (PDU) sessions. A PDU session is an association, session or connection between the UE 1 and the DN 7. The PDU session is used to provide a PDU connectivity service (i.e., exchange of PDUs between the UE 1 and the DN 7). The UE 1 establishes one or more PDU sessions between the UE 1 and a UPF 6 (i.e., PDU session anchor point) to which the DN 7 is connected. In terms of data transfer, a PDU session consists of a tunnel in the 5GC (N9 tunnel), a tunnel between the 5GC and the AN 5 (N3 tunnel) and one or more radio bearers. Although not illustrated in Figure 1 The UE 1 can establish multiple PDU sessions with multiple UPFs (PDU session anchor points) 6 to simultaneously access multiple DNs 7.
[0059] The AMF 2 is one of the network functions in the control plane of the 5GC. The AMF 2 provides termination for RAN control plane (CP) interfaces (i.e., N2 interface). The AMF 2 terminates a single signaling connection (i.e., N1 NAS signaling connection) with a UE 1 and provides registration management, connection management, and mobility management. The AMF 2 provides NF services to NF consumers (e.g., other AMFs, a session management function (SMF) 3, and an authentication server function (AUSF) 4) over service-based interfaces (i.e., Namf interface). The NF services provided by the AMF 2 include communication services (Namf_Communication). The communication services enable a NF consumer (e.g., the SMF 3) to communicate with a UE 1 or an AN 5 via the AMF 2.
[0060] The SMF 3 is one of the network functions in the control plane of the 5GC. The SMF 3 manages PDU sessions. The SMF 3 sends and receives SM signaling messages (NAS-SM messages, N1 SM messages) with respect to a non-access stratum (NAS) session management (SM) layer of the UE 1 via the communication services provided by the AMF 2. The SMF 3 provides NF services to NF consumers (e.g., the AMF 2, other SMFs) over service-based interfaces (i.e., Nsmf interface). The NF services provided by the SMF 3 include PDU session management services (Nsmf_PDUSession) that enable a NF consumer (e.g., the AMF 2) to handle PDU sessions. The SMF 3 can be an intermediate SMF (I-SMF). In the case that a UPF 6 belongs to a different SMF service area and cannot be controlled by an original SMF 3, an I-SMF is inserted between the AMF 2 and the original SMF as needed.
[0061] The AUSF 4 is one of the network functions in the 5GC control plane. The AUSF 4 provides NF services to NF consumers (e.g., AMF 2, UDM 8) over a service-based interface (i.e., Nausf interface). The NF services provided by the AUSF 4 include UE authentication services (e.g., Nausf_UEAuthentication and Nausf_NSSAA_Authenticate). The Nausf_UEAuthentication service provides UE authentication and related key information (keying material) to the NF consumer (i.e., AMF). More specifically, the AUSF 4 cooperates with the UDM 8 and an authentication credential repository and processing function (ARPF) to authenticate using one of two authentication methods supported by the 5GS (i.e., 5G Authentication and Key Agreement (AKA) and EAP-based authentication). After authentication, the AUSF 4 replies to the AMF 2 with the authentication result and, in case of success, with the master key. The master key is used by the AMF 2 to derive NAS security keys and other security key(s). For UE authentication, the AUSF 4 works closely with the UDM 8. The Nausf_NSSAA_Authenticate service provides network slice specific authentication and authorization services between the UE 1 and an AAA server via the AUSF 4 to the NF consumer (e.g., AMF 2).
[0062] The UDM 8 is one of the network functions in the 5GC control plane. The UDM 8 provides access to databases (i.e., a user data repository (UDR)) that store subscriber data (subscription information). The UDM 8 provides NF services to NF consumers (e.g., AMF 2, AUSF 4, SMF 3) over a service-based interface (i.e., Nudm interface). The NF services provided by the UDM 8 include a subscriber data management service that enables NF consumers (e.g., AMF) to retrieve subscriber data and provide updated subscriber data to the NF consumer.
[0063] For ease of explanation, Figure 1 The structures in FIGS. 1 to 3 only show typical NFs. The cellular network according to the present embodiment can include other NFs not shown in FIGS. 1 to 3, such as a network slice selection function (NSSF) and a policy control function (PCF). Figure 1
[0064] Figure 2 is a flowchart showing an example of the operation of the AMF 2. In step 201, the AMF 2 manages a UE context of the UE 1 in an RM-REGISTERED state. The UE context includes allowed NSSAI and pending NSSAI. As described earlier, the UE context can include rejected NSSAI.
[0065] The UE context can include status information indicating the status of NSSAA permission for each S-NSSAI included in the allowed NSSAI, the rejected NSSAI, and the pending NSSAI. The status information for an S-NSSAI can indicate whether the current NSSAA permission for the S-NSSAI is still available (allowed to be used or permitted) or not available (not allowed to be used or not permitted) during reauthentication and reauthorization.
[0066] In some implementations, the AMF 2 can manage the status information with respect to the S-NSSAIs included in the allowed NSSAI. In other words, the status information can be associated with the allowed NSSAI. In other implementations, the AMF 2 can manage the current permission status of each S-NSSAI subject to NSSAA independently of the allowed NSSAI, the rejected NSSAI, and the pending NSSAI.
[0067] In some implementations, to indicate that the current permission for NSSAA for a particular S-NSSAI is still available during reauthentication and reauthorization, the status information can indicate that the particular S-NSSAI is activated (in an activated state), in a valid state, previously authorized, or subject to an ongoing (re)authorization (in a (re)authorization). On the other hand, to indicate that the current permission for NSSAA for a particular S-NSSAI is not available during reauthentication and reauthorization, the status information can indicate that the particular S-NSSAI is deactivated (in a deactivated state), in an invalid state, subject to an ongoing (re)authorization (in a (re)authorization), or not (yet) authorized.
[0068] That is, if the status information for a particular currently allowed S-NSSAI indicates that a (re)authorization is ongoing, this can mean in some implementations that the current authorization for the particular S-NSSAI is still “valid” during reauthentication and reauthorization, or this can mean in other implementations that the current authorization for the particular S-NSSAI is “invalid” during reauthentication and reauthorization.
[0069] Thus, in some implementations, the available status can include multiple statuses (sub-statuses), such as “authorized” and “in reauthentication and reauthorization.” In other implementations, the unavailable status can include multiple statuses (sub-statuses), such as “not authorized” and “in reauthentication and reauthorization.”
[0070] The status information indicating whether the current permission for the NSSAA for a specific S-NSSAI is previously granted, is under ongoing (re-)granting (in the process of (re-)granting), or is (yet) ungranted can be included in the data for managing the operation of the NSSAA related to the S-NSSAI. This data can be referred to as "S-NSSAI under Network Slice Specific Authentication and Authorization".
[0071] To indicate that the current permission for the NSSAA for a specific S-NSSAI is under (re-)granting, the status information can indicate that re-authentication of the S-NSSAI that is already granted is to be performed as a precaution.
[0072] To indicate that the current permission for the NSSAA for a specific S-NSSAI is ungranted, the status information can indicate that re-authentication and re-granting (additional authentication and authorization) of the S-NSSAI that is already granted is to be performed due to suspicion.
[0073] As previously described, the AMF 2 can again perform network slice specific authentication and authorization (NSSAA) for one or more currently allowed S-NSSAIs of the UE 1. More specifically, if the AAS server (AAA-S) triggers re-authentication of one or more currently allowed S-NSSAIs, the AMF 2 triggers initiation of the NSSAA for the S-NSSAIs. In addition, the AMF 2 can judge that one or more currently allowed S-NSSAIs of the UE 1 need re-authentication based on a change in subscription information of the UE 1. Further, when the AMF 2 receives a registration request message for a mobility registration update or a periodic registration update from the UE 1, the AMF 2 can judge that one or more currently allowed S-NSSAIs need re-authentication, for example, based on an operator policy. In addition, the AMF 2 can judge that one or more currently allowed S-NSSAIs need re-authentication, for example, based on an operator policy, in addition to these conditions. In these cases, the AMF 2 triggers initiation of the NSSAA for the S-NSSAI(s) that need re-authentication.
[0074] In step 202, when the AMF 2 triggers a re-authentication and re-authorization procedure (NSSAA again or additional NSSAA) for a specific S-NSSAI currently allowed for the UE 1, the AMF 2 removes the specific S-NSSAI from the allowed NSSAI and stores it in the pending NSSAI. In other words, the AMF 2 can change the specific S-NSSAI from the allowed NSSAI to the pending NSSAI. The AMF 2 initiates the re-authentication and re-authorization procedure due to the above reason or due to other reasons. More specifically, the AMF 2 can send an authentication request message to the AUSF 4 to initiate the re-authentication and re-authorization procedure (or trigger initiation of the re-authentication and re-authorization procedure). The authentication request message can be, for example, a Nausf_Communication_EAPMessage_Transfer message or a Nausf_NSSAA_Authenticate request message. The AMF 2 can send the S-NSSAI that needs (re)authentication to the AUSF 4 in the above message or in a separate message. The AMF 2 can send the EAP authentication UE user ID (EAP ID) for the S-NSSAI that needs (re)authentication to the AUSF 4 in the above message or in a separate message. The AMF 2 can send the generic public subscription identifier (GPSI) of the UE 1 to the AUSF 4 in the above message or in a separate message. The AMF 2 can send the address of the AAA-S to the AUSF 4 by including it in the above message, or the AMF 2 can send the address of the AAA-S to the AUSF 4 by other message. Prior to this, the AMF 2 can request the EAP ID for the relevant S-NSSAI from the UE 1.
[0075] As described above, the UE context of the UE 1 can include status information indicating the permission status of the NSSAA for the S-NSSAI. The status information of the S-NSSAI can indicate whether the current permission of the NSSAA for each S-NSSAI is still available (allowed to use or permitted) or not available (not allowed to use or not permitted) during the re-authentication and re-authorization. In this case, in step 202, the AMF 2 can change the status of the specific S-NSSAI from the available state to the unavailable state. Specifically, in step 202, the AMF 2 can move the specific S-NSSAI from the allowed NSSAI to the pending NSSAI, and can also change the status of the specific S-NSSAI from the available state to the unavailable state. Alternatively, the AMF 2 can move the specific S-NSSAI from the allowed NSSAI to the pending NSSAI, but maintain the status of the specific S-NSSAI in the available state.
[0076] Step 202 (i.e., removal of a particular S-NSSAI from the allowed NSSAI and addition of the particular S-NSSAI to the pending NSSAI) can occur before or after sending the authentication request message for NSSAA from the AMF 2 to the AUSF 4. For example, the AMF 2 can perform step 202 in response to the AAA-S requesting, via the AUSF 4, that a re-authentication event has occurred for a particular S-NSSAI. The AMF 2 can perform step 202 in response to determining, based on operator policy, that re-authentication is needed for a particular S-NSSAI. The AMF 2 can perform step 202 in response to determining, based on a change in operator policy, that re-authentication is needed for a particular S-NSSAI. The AMF 2 can perform step 202 in response to determining, based on a change in subscription information, that re-authentication is needed for a particular S-NSSAI. For example, the AMF 2 can perform step 202 in response to sending the authentication request message to the AUSF 4. For example, the AMF 2 can perform step 202 in response to requesting, from the UE 1, an EAP ID for a relevant S-NSSAI.
[0077] Figure 2 The procedures in FIGS. 1 1A and 1 1B, for example, can help improve security. For example, if the AMF 2 receives a request from the UE 1 to establish a new PDU session associated with a particular S-NSSAI while a re-authentication and re-authorization procedure for the particular S-NSSAI is ongoing, the AMF 2 can reject the received PDU session establishment request or suspend or inhibit the PDU session establishment procedure based on the fact that the particular S-NSSAI is included in the pending NSSAI.
[0078] For example, the AMF 2 can reject the received PDU session establishment request or suspend the PDU session establishment procedure based on information indicating a status related to the current permission for NSSAA for each S-NSSAI. More specifically, in a case where the AMF 2 receives a request from the UE 1 to establish a new PDU session associated with a particular S-NSSAI, the AMF 2 can reject the received PDU session establishment request or suspend the PDU session establishment procedure based on the fact that the status of the particular S-NSSAI is in an unavailable state.
[0079] In some implementations, the AAA-S can perform procedures similar to those described above with respect to the AMF 2. Figure 2The same actions as in step 201. Specifically, the AAA-S can store the allowed NSSAI and the pending NSSAI for UE 1, and can also store the rejected NSSAI for UE 1, as in step 201. As in step 202, when a re-authentication and re-authorization procedure (again NSSAA or additional NSSAA) is performed for a particular S-NSSAI currently allowed for UE 1, the AAA-S can remove the particular S-NSSAI from the allowed NSSAI and store it in the pending NSSAI. Alternatively, the AAA-S can change the particular S-NSSAI from the allowed NSSAI to the pending NSSAI. As described with respect to AMF 2, the AAA-S can also manage information indicating the status related to the current permission of NSSAA for the S-NSSAIs.
[0080] By enabling the AAA-S to manage the authorization status of NSSAA for S-NSSAIs, unnecessary signaling can be reduced. For example, during the execution of a re-authentication and re-authorization procedure for a particular S-NSSAI, the AAA-S can avoid sending signaling for a re-authentication and re-authorization request for the particular S-NSSAI.
[0081] Figure 3 An example of a re-authentication and re-authorization procedure initiated (or triggered) by the AAA-S is shown. In step 301, a particular S-NSSAI (in this case S-NSSAI#1) has been allowed for UE 1. Thus, S-NSSAI#1 is included in the allowed NSSAI in the UE context (302) for UE 1 managed by AMF 2.
[0082] In step 303, the AAA-S 9 requests re-authentication and re-authorization for the network slice identified by S-NSSAI#1. Specifically, the AAA-S 9 can send a re-authentication and re-authorization request message to AUSF 4. The message can be, for example, a Nausf_Re-Auth request message or a AAA protocol Re-Auth request message. The message indicates S-NSSAI#1 and also indicates the generic public subscription identifier (GPSI) for UE 1. The message can be sent directly from AAA-S 9 to AUSF 4, or can be sent to AUSF 4 via an AAA proxy (AAA-P) not shown.
[0083] In step 304, AUSF 4 notifies AMF 2 of a re-authentication and re-authorization event for S-NSSAI#1 of UE 1 that occurred via the NF service provided by AUSF 4. The notification can be, for example, a Namf_Re-Auth request message or a NAusf_NSSAA_Notify message. The notification indicates S-NSSAI#1 and also indicates the GPSI for UE 1.
[0084] In step 305, the AMF 2 removes the S-NSSAI#1 from the allowed NSSAI in the UE context of the UE 1 and stores (or adds) the S-NSSAI#1 to the pending NSSAI in the UE context of the UE 1. In other words, the AMF 2 can move (or change) the S-NSSAI#1 from the allowed NSSAI to the pending NSSAI.
[0085] As described above, the UE context of the UE 1 can include the status information indicating the permission status of the NSSAA for the S-NSSAI. The status information for the S-NSSAI can indicate whether the current permission of the NSSAA for each S-NSSAI is still available (allowed to use or permitted) or not available (not allowed to use or not permitted) during the re-authentication and re-authorization. In this case, in step 305, the AMF 2 can change the status of the S-NSSAI#1 from the available state to the unavailable state. More specifically, the AMF 2 can move the S-NSSAI#1 from the allowed NSSAI to the pending NSSAI and can also change the status of the S-NSSAI#1 from the available state to the unavailable state. Alternatively, in step 305, the AMF 2 can move the S-NSSAI#1 from the allowed NSSAI to the pending NSSAI, but maintain the status of the S-NSSAI#1 in the available state.
[0086] In step 306, the AMF 2 triggers the network slice specific authentication and authorization (NSSAA) procedure, which is the same as the existing NSSAA procedure. The existing NSSAA procedure is specified in section 4.2.9.1 of Non-Patent Literature 2.
[0087] The procedure of Figure 3 may be modified as appropriate. For example, step 305 can occur after step 306 has been initiated (i.e., during the execution of the NSSAA procedure).
[0088] Second Embodiment
[0089] This embodiment provides a variation of the first embodiment. The structure example of the cellular network according to this embodiment can be the same as the example shown in Figure 1 .
[0090] Figure 4 is a flowchart showing an example of the operation of the AMF 2. Figure 4 The operations described in Figure 2occurs after step 202 of the procedure of Figure 2. In step 401, the AMF 2 receives from the UE 1 a request for establishing a new PDU session associated with a specific S-NSSAI. More specifically, the AMF 2 receives from the UE 1 a NAS message (e.g., UL NAS transport message). The NAS message contains the specific S-NSSAI, the new PDU session ID and the N1 SM container (PDU session establishment request). For example, the AMF 2 can judge the reception of the new PDU session establishment request associated with the specific S-NSSAI based on the fact that the NAS message received in step 401 contains the specific S-NSSAI and the new PDU session ID.
[0091] In step 402, the AMF 2 checks the UE context of the UE 1. If the specific S-NSSAI is stored in the pending NSSAI, the AMF 2 rejects the received establishment request.
[0092] As mentioned above, the UE context of the UE 1 can include the status information indicating the permission status of the NSSAA for the S-NSSAI. The status information of the S-NSSAI can indicate whether the current permission of the NSSAA for each S-NSSAI is still available (allowed to use or permitted) or not available (not allowed to use or not permitted) during the re-authentication and re-authorization. In this case, in step 402, the AMF 2 can reject the received establishment request if the status of the specific S-NSSAI is in the not available state. Alternatively, in step 402, the AMF 2 can reject the received establishment request if the specific S-NSSAI is stored in the pending NSSAI and the status of the specific S-NSSAI is in the not available state.
[0093] Figure 4 The illustrated operations enable the AMF 2 to prevent the establishment of a new PDU session associated with a network slice for which the re-authentication and re-authorization procedure is ongoing.
[0094] Third embodiment
[0095] This embodiment provides a variant of the first embodiment. The structure example of the cellular network according to this embodiment can be the same as the one illustrated in the example of Figure 1
[0096] Figure 5 is a flowchart illustrating an example of the operations of the AMF 2. Figure 5 The operations described in Figure 2 occurs after step 202. In step 501, the AMF 2 receives from the UE 1 a request for establishing a new PDU session associated with the specific S-NSSAI. More specifically, the AMF 2 receives from the UE 1 a NAS message (e.g., UL NAS transport message). The NAS message contains the specific S-NSSAI, the new PDU session ID, and the N1 SM container (PDU session establishment request). The AMF 2 can judge the reception of the new PDU session establishment request associated with the specific S-NSSAI based on the fact that the NAS message received in step 501 contains the specific S-NSSAI and the new PDU session ID, for example.
[0097] In step 502, the AMF 2 checks the UE context of the UE 1. If the specific S-NSSAI is stored in the pending NSSAI, the AMF 2 suspends or suppresses the PDU session establishment procedure. The AMF 2 can suspend the PDU session establishment procedure at least until the result of the NSSAA procedure is obtained. Alternatively, the AMF 2 can suspend the PDU session establishment procedure until a predetermined time period has elapsed. Alternatively, the AMF 2 can suspend the PDU session establishment procedure until the AMF 2 receives again from the UE 1 a request for establishing a new PDU session associated with the specific S-NSSAI. If the NSSAA procedure is successful, the AMF 2 can resume the suspended PDU session establishment procedure.
[0098] Figure 5 The illustrated operations enable the AMF 2 to prevent the establishment of a new PDU session associated with a network slice for which the re-authentication and re- authorization procedure is ongoing.
[0099] As described above, the UE context of the UE 1 can include the status information indicating the permission status of the NSSAA for the S-NSSAI. The status information of the S-NSSAI can indicate whether the current permission of the NSSAA for each S-NSSAI is still available (allowed to use or permitted) or not available (not allowed to use or not permitted) during the re-authentication and re-authorization. In this case, in step 502, the AMF 2 can suspend the PDU session establishment procedure if the status of the specific S-NSSAI is in the not available state. Alternatively, in step 502, the AMF 2 can suspend the PDU session establishment procedure if the specific S-NSSAI is stored in the pending NSSAI and the status of the specific S-NSSAI is in the not available state. This enables the AMF 2 to control the establishment of the PDU session associated with the specific S-NSSAI based on whether the current permission of the NSSAA for the specific S-NSSAI is still available during the re-authentication and re-authorization.
[0100] Fourth embodiment
[0101] This embodiment provides a variant of the first embodiment. The structure example of the cellular network according to this embodiment can be the same as the one illustrated in Figure 1 .
[0102] Figure 6 is a flowchart illustrating an example of the operation of the AMF 2. Figure 6 Steps 601 and 602 in Figure 2 are the same as steps 201 and 202 in In step 603, the AMF 2 sends to the UE 1 a message indicating that a specific S-NSSAI is to be removed from the allowed NSSAI and included in the pending NSSAI. The message can be a message sent by the AMF 2 to the UE 1 to update the UE NSSAI configuration or any other UE configuration. The message can be a NAS message, or more specifically a UE configuration update command message. In response to receiving the message, the UE 1 updates the UE NSSAI configuration (NSSAI storage) stored in the (non-volatile) memory of the UE 1. Specifically, the UE 1 removes the specific S-NSSAI from the allowed NSSAI and stores it in the pending NSSAI within the UE NSSAI configuration (NSSAI storage).
[0103] Figure 6 The operations illustrated in enable the AMF 2 to control the UE 1 so that the UE NSSAI configuration (NSSAI storage) in the UE 1 is synchronized with the UE context in the AMF 2.
[0104] Fifth embodiment
[0105] The structure example of the cellular network according to this embodiment can be the same as the one illustrated in Figure 1 . This embodiment provides another example of the management of the UE context (allowed NSSAI and pending NSSAI) by the AMF 2.
[0106] Figure 7 is a flowchart illustrating an example of the operation of the AMF 2. Step 701 is the same as step 201 in Figure 2 . Specifically, in step 701, the AMF 2 manages the UE context of the UE 1 in the RM-REGISTERED state. The UE context includes the allowed NSSAI and the pending NSSAI. As mentioned before, the UE context can also include the rejected NSSAI.
[0107] As described in the first embodiment, the UE context can include status information indicating the permission status of NSSAA for each S-NSSAI included in one or more of the allowed NSSAI, the rejected NSSAI, and the pending NSSAI. The status information for an S-NSSAI can indicate whether the current NSSAA permission for each S-NSSAI is still available (allowed to use or permitted) or not available (not allowed to use or not permitted) during reauthentication and reauthorization.
[0108] In some implementations, the AMF 2 can manage the status information with respect to S-NSSAIs included in the allowed NSSAI. In other words, the status information can be associated with the allowed NSSAI. In other implementations, the AMF 2 can manage the current permission status of each S-NSSAI subject to NSSAA independently of the allowed NSSAI, the rejected NSSAI, and the pending NSSAI.
[0109] In some implementations, to indicate that the current permission of NSSAA for a particular S-NSSAI is still available during reauthentication and reauthorization, the status information can indicate that the particular S-NSSAI is activated (in an activated state), in a valid state, or previously authorized. On the other hand, to indicate that the current permission of NSSAA for a particular S-NSSAI is not available due to ongoing reauthentication and reauthorization, the status information can indicate that the particular S-NSSAI is deactivated (in a deactivated state), in an invalid state, subject to ongoing (re)authorization (in (re)authorization), or (yet) not authorized.
[0110] That is, if the status information of a particular currently allowed S-NSSAI indicates that (re)authorization is ongoing, this can mean in some implementations that the current authorization for the particular S-NSSAI is still “valid” during reauthentication and reauthorization, or can mean in other implementations that the current authorization for the particular S-NSSAI is “invalid” during reauthentication and reauthorization.
[0111] The available status can include multiple statuses (sub-statuses), such as “authorized” and “in reauthentication and reauthorization.” Likewise, the unavailable status can include multiple statuses (sub-statuses), such as “not authorized” and “in reauthentication and reauthorization.”
[0112] The status information indicating whether the current permission of NSSAA for a particular S-NSSAI is previously authorized, in (re)authorization, or (yet) not authorized can be included in data for operations managing NSSAA with respect to S-NSSAI. This data can be referred to as “S-NSSAI subject to network slice specific authentication and authorization.”
[0113] To indicate that the current grant of NSSAA for a specific S-NSSAI is in (re)authorization, the status information can indicate that, as a precaution, re- authentication of the granted S-NSSAI is to be performed.
[0114] To indicate that the current grant of NSSAA for a specific S-NSSAI is not authorized, the status information can indicate that, due to suspicion, re-authentication and re- authorization (additional authentication and authorization) of the granted S-NSSAI is to be performed.
[0115] In step 702, when the AMF 2 triggers a re-authentication and re-authorization procedure (renewed or additional NSSAA) for a specific S-NSSAI currently allowed for the UE 1, the AMF 2 continues to store the specific S-NSSAI in the allowed NSSAI. More specifically, the AMF 2 keeps the specific S-NSSAI in the allowed NSSAI at least until the result of the re-authentication and re-authorization procedure is obtained.
[0116] As mentioned above, the UE context of the UE 1 can comprise status information indicating the status of the grant of NSSAA for S-NSSAIs. The status information for a S-NSSAI can indicate whether the current grant of NSSAA for the respective S-NSSAI is still available (allowed to use or granted) or not available (not allowed to use or not granted) during re-authentication and re-authorization. In this case, in step 702, the AMF 2 can change (or associate) the status of the specific S-NSSAI to the available state. Alternatively, the AMF 2 can maintain the status of the specific S-NSSAI in the available state. In other words, the AMF 2 can recognize that the status of the specific S-NSSAI is in the available state. As mentioned before, the available state can indicate that the specific S-NSSAI or the grant of NSSAA for the specific S-NSSAI is activated (in the activated state), in the valid state, previously authorized, or subject to an ongoing (re)authorization (in (re)authorization).
[0117] Alternatively, in step 702, the AMF 2 can change (or associate) the status of the specific S-NSSAI to the unavailable state while keeping the specific S-NSSAI stored in the allowed NSSAI. In other words, the AMF 2 can recognize that the status of the specific S-NSSAI is in the unavailable state. As mentioned before, the unavailable state can indicate that the specific S-NSSAI or the grant of NSSAA for the specific S-NSSAI is deactivated (in the deactivated state), in the invalid state, subject to an ongoing (re)authorization (in (re)authorization), or not yet authorized.
[0118] If the re-authentication and re-authorization procedure for the specific S-NSSAI is successful, the AMF 2 can change the status of the specific S-NSSAI from the unavailable state to the available state. In other words, if the re-authentication and re-authorization procedure for the specific S-NSSAI is successful, the AMF 2 can recognize that the status of the specific S-NSSAI is in the available state. In some implementations, the AMF 2 can remove information (e.g., a flag) indicating the unavailable state from the status information of the specific S-NSSAI.
[0119] On the other hand, if the re-authentication and re-authorization procedure for the specific S-NSSAI fails, the AMF 2 removes the specific S-NSSAI from the allowed NSSAI and stores it in the rejected NSSAI. The AMF 2 sends a message to the UE 1 indicating that the specific S-NSSAI is to be removed from the allowed NSSAI and included in the rejected NSSAI. The message can be a message sent from the AMF 2 to the UE 1 to update the UE NSSAI configuration or any other UE configuration. The message can be a NAS message, or more specifically, a UE Configuration Update Command message.
[0120] Figure 7 The procedures in FIG. 7 can, for example, help improve service continuity. For example, if the AMF 2 receives a request from the UE 1 to establish a new PDU session associated with a specific S-NSSAI during the performance of the re-authentication and re-authorization procedure for the specific S-NSSAI, the AMF 2 can proceed with the PDU session establishment procedure based on the reason why the specific S-NSSAI is included in the allowed NSSAI.
[0121] For example, the AMF 2 can determine whether to proceed with a PDU session establishment procedure associated with a specific S-NSSAI based on information indicating the status related to the current grant of NSSAA for the specific S-NSSAI. For example, if the AMF 2 receives a request from the UE 1 to establish a new PDU session associated with the specific S-NSSAI, the AMF 2 can proceed with the PDU session establishment procedure based on the fact that the status of the specific S-NSSAI is in the available state.
[0122] On the other hand, if the AMF 2 receives a request from the UE 1 to establish a new PDU session associated with a specific S-NSSAI, the AMF 2 can not proceed with the PDU session establishment procedure based on the reason why the status of the specific S-NSSAI is in the unavailable state (e.g., not authorized).
[0123] In some implementations, the AAA-S 9 can perform the procedures in FIG. 8 in conjunction with the procedures in FIG. 7. Figure 7The same operations as in the first embodiment are performed. In particular, as in step 701, the AAA-S can store the allowed NSSAI and the pending NSSAI for UE 1, and can also store the rejected NSSAI for UE 1. As in step 702, when the AAA-S 9 triggers a re-authentication and re-authorization procedure (renewed or additional NSSAA) for a specific S-NSSAI currently allowed for UE 1, the AAA-S 9 can keep the specific S-NSSAI stored in the allowed NSSAI. In addition, as described for the AMF 2, the AAA-S can manage information indicating the status related to the current permission of the NSSAA for each S-NSSAI.
[0124] By enabling the AAA-S 9 to manage the authorization status of the S-NSSAI by the NSSAA, it is possible to reduce unnecessary signaling. For example, during the execution of the re-authentication and re-authorization procedure for a specific S-NSSAI, the AAA-S 9 can avoid sending the signaling of the re-authentication and re-authorization request for the specific S-NSSAI.
[0125] Figure 8 An example of a re-authentication and re-authorization procedure initiated (or triggered) by the AAA-S is shown. Figure 8 Steps 801-804 in Figure 3 are the same as steps 301-304 in In step 805, the AMF 2 maintains S-NSSAI#1 stored in the allowed NSSAI#1 within the UE context of UE 1. At this time, the AMF 2 can change (or associate) the status of S-NSSAI#1 to the unavailable state during the maintenance of S-NSSAI#1 stored in the allowed NSSAI. In other words, the AMF 2 can recognize that the status of S-NSSAI#1 is in the unavailable state. Step 806 is the same as step 306 in Figure 3 .
[0126] Sixth embodiment
[0127] This embodiment provides a variant of the first and fifth embodiments. The structure example of the cellular network according to this embodiment can be the same as the example shown in Figure 1 .
[0128] Figure 9 is a flowchart showing an example of the operation of the AMF 2. Step 901 is the same as step 201 in Figure 2 and step 701 in Figure 7 . In particular, in step 901, the AMF 2 manages the UE context of UE 1 in the RM-REGISTERED state. The UE context includes the allowed NSSAI and the pending NSSAI. As previously described, the UE context can also include the rejected NSSAI.
[0129] In step 902, when the re-authentication and re-authorization procedure (NSSAA again or additional) for the specific S-NSSAI currently allowed for UE 1 is triggered, AMF 2 judges whether to remove the specific S-NSSAI from the allowed NSSAI. In other words, AMF 2 judges whether the specific S-NSSAI needs to be removed from the allowed NSSAI. If the specific S-NSSAI needs to be removed from the allowed NSSAI, AMF 2 operates in the same way as in step 202 of Figure 2 , to remove the specific S-NSSAI from the allowed NSSAI and store it in the pending NSSAI. Otherwise, AMF 2 operates as in step 702 of Figure 7 , to keep the specific S-NSSAI stored in the allowed NSSAI.
[0130] As described in the first embodiment and the fifth embodiment, the UE context can include status information indicating the NSSAA permission status for each S-NSSAI included in one or more than one of the allowed NSSAI, the rejected NSSAI, and the pending NSSAI. The status information of the S-NSSAI can indicate whether the current NSSAA permission for each S-NSSAI is still available (allowed to use or permitted) or not available (not allowed to use or not permitted) during the re-authentication and re-authorization. When the specific S-NSSAI is removed from the allowed NSSAI in step 902, AMF 2 can move the specific S-NSSAI from the allowed NSSAI to the pending NSSAI, and also change the status of the specific S-NSSAI from the available state to the unavailable state. Alternatively, AMF 2 can move the specific S-NSSAI from the allowed NSSAI to the pending NSSAI, but maintain the status of the specific S-NSSAI in the available state. In another aspect, when the specific S-NSSAI is maintained to be stored in the allowed NSSAI, AMF 2 can change (or associate) the status of the specific S-NSSAI to the available state. Alternatively, AMF 2 can change (or associate) the status of the specific S-NSSAI to the unavailable state while continuing to store the specific S-NSSAI in the allowed NSSAI.
[0131] In some implementations, AMF 2 can make the judgment of step 902 in units of network slices (in units of S-NSSAI). Alternatively, AMF 2 can make the judgment of step 902 in units of UE.
[0132] In some implementations, AMF 2 may make the determination of step 902 based on the subscription information of UE 1. For example, the subscription information of UE 1 may indicate the handling of the allowed S-NSSAI during network slice reauthentication and reauthorization (e.g., whether the allowed S-NSSAI needs to be maintained within the allowed NSSAI (or not)).
[0133] In some implementations, AMF 2 may make the determination in step 902 based on an indication (or explicit parameter) from AAA-S that a specific S-NSSAI has been approved. For example, when requesting AMF 2 to reauthenticate a network slice associated with a specific S-NSSAI via AUSF 4, AAA-S may send a reauthentication request message including the explicit parameter.
[0134] In some implementations, AMF 2 may make the determination in step 902 based on a local configuration of AMF 2. For example, a network operator may locally configure AMF 2 with respect to the handling of allowed S-NSSAI during network slice reauthentication and reauthorization (e.g., whether it is required (or not required) to maintain the allowed S-NSSAI within the allowed NSSAI).
[0135] In some implementations, AMF 2 may make the determination of step 902 based on the type of network slice associated with a specific S-NSSAI. For example, AMF 2 may recognize the type of network slice based on a slice / service type (SST) or a slice distinguisher (SD) or both included in a specific S-NSSAI. For example, if a specific S-NSSAI indicates a slice type requiring service continuity (e.g., URLLC), AMF 2 may determine the type of network slice as in Figure 7 Otherwise, AMF 2 may operate as in step 702 of Figure 2 The method operates as in step 202 to remove the specific S-NSSAI from the allowed NSSAI and store it in the pending NSSAI.
[0136] Figure 9 The operations shown enable AMF 2 to change whether to keep the Allowed S-NSSAI within the Allowed NSSAI when performing network slice reauthentication and reauthorization.
[0137] Seventh embodiment
[0138] This embodiment provides a variation of the fifth embodiment. The structural example of the cellular network according to this embodiment can be Figure 1 The example shown is the same. The UE context of UE 1 in this embodiment includes information indicating the status of S-NSSAI.
[0139] Figure 10 is a flowchart illustrating an example of the operation of the AMF 2. Figure 10 The operations described in the Figure 7 occur after step 702 of the method 700. In step 1001, the AMF 2 receives from the UE 1 a request for establishing a new PDU session associated with a particular S-NSSAI. In step 1002, the AMF 2 refers to the UE context of the UE 1. Then, in case the particular S-NSSAI is stored in the allowed NSSAI but the permission status information related to this particular S-NSSAI indicates an unavailable status, the AMF 2 rejects the received establishment request. As mentioned before, the unavailable status can be referred to as unpermitted status, unallowable status, deactivated status or invalid status. As mentioned before, the unavailable status can be referred to as unpermitted status, deactivated status or invalid status. The unavailable status can comprise several (sub-) statuses, e.g. “unauthorized” and “in re- authentication and re-authorization”.
[0140] Figure 10 The illustrated operations enable the AMF 2 to prevent the establishment of a new PDU session associated with a network slice for which a re-authentication and re-authorization procedure is ongoing.
[0141] Eighth embodiment
[0142] This embodiment provides a variant of the fifth embodiment. The structure example of the cellular network according to this embodiment can be the same as the one illustrated in Figure 1 The UE context of the UE 1 in this embodiment contains information indicating the status of the S-NSSAI.
[0143] Figure 11 is a flowchart illustrating an example of the operation of the AMF 2. Figure 11 The operations described in the Figure 7 occur after step 702 of the method 700. In step 1001, the AMF 2 receives from the UE 1 a request for establishing a new PDU session associated with a particular S-NSSAI. In step 1002, the AMF 2 refers to the UE context of the UE 1. Then, in case the particular S-NSSAI is stored in the allowed NSSAI but the permission status information related to this particular S-NSSAI indicates an unavailable status, the AMF 2 rejects the received establishment request. As mentioned before, the unavailable status can be referred to as unpermitted status, unallowable status, deactivated status or invalid status. As mentioned before, the unavailable status can be referred to as unpermitted status, deactivated status or invalid status. The unavailable status can comprise several (sub-) statuses, e.g. “unauthorized” and “in re- authentication and re-authorization”.
[0144] Figure 11The operations shown enable the AMF 2 to prevent the establishment of new PDU sessions associated with a network slice that is undergoing a reauthentication and reauthorization procedure, at least until the result of the NSSAA procedure is obtained.
[0145] The following provides a structural example of UE 1 and AMF 2 according to the above embodiment. Figure 12 1 is a block diagram illustrating an example structure of UE 1. Radio frequency (RF) transceiver 1201 performs analog RF signal processing for communication with an NG-RAN node. RF transceiver 1201 may include multiple transceivers. The analog RF signal processing performed by RF transceiver 1201 includes upconversion, downconversion, and amplification. RF transceiver 1201 is coupled to antenna array 1202 and baseband processor 1203. RF transceiver 1201 receives modulation symbol data (or OFDM symbol data) from baseband processor 1203, generates a transmit RF signal, and supplies the transmit RF signal to antenna array 1202. Furthermore, RF transceiver 1201 generates a baseband receive signal based on the receive RF signal received by antenna array 1202, and supplies the baseband receive signal to baseband processor 1203. RF transceiver 1201 may include an analog beamformer circuit for beamforming. For example, the analog beamformer circuit includes multiple phase shifters and multiple power amplifiers.
[0146] The baseband processor 1203 performs digital baseband signal processing (i.e., data plane processing) and control plane processing for radio communications. Digital baseband signal processing includes (a) data compression / decompression, (b) data isolation / concatenation, (c) synthesis / decomposition of transmission formats (i.e., transmission frames), (d) channel coding / decoding, (e) modulation (i.e., symbol mapping) / demodulation, and (f) generation of OFDM symbol data (i.e., baseband OFDM signals) using an inverse fast Fourier transform (IFFT). On the other hand, control plane processing includes communication management for Layer 1 (e.g., transmit power control), Layer 2 (e.g., radio resource management and hybrid automatic repeat request (HARQ) processing), and Layer 3 (e.g., signaling related to attachment, mobility, and call management).
[0147] The digital baseband signal processing of the baseband processor 1203 may include, for example, signal processing of the Service Data Adaptation Protocol (SDAP) layer, the Packet Data Convergence Protocol (PDCP) layer, the Radio Link Control (RLC) layer, the Medium Access Control (MAC) layer, and the Physical (PHY) layer. In addition, the control plane processing performed by the baseband processor 1203 may include processing of the Non-Access Stratum (NAS) protocol, the Radio Resource Control (RRC) protocol, and the MAC Control Element (CE).
[0148] The baseband processor 1203 can perform multiple-input multiple-output (MIMO) encoding and precoding for beamforming.
[0149] The baseband processor 1203 can include a modem processor (e.g., a digital signal processor (DSP)) for performing digital baseband signal processing and a protocol stack processor (e.g., a central processing unit (CPU) or a micro processing unit (MPU)) for performing control plane processing. In this case, the protocol stack processor for performing control plane processing can be integrated with the application processor 1204 described later.
[0150] The application processor 1204 is also called a CPU, MPU, microprocessor, or processor core. The application processor 1204 can include a plurality of processors (or processor cores). The application processor 1204 loads a system software program (an operating system (OS)) and various application programs (e.g., a call application, a WEB browser, a mail program, a camera operation application, and a music player application) from the memory 1206 or from other memory (not shown) and executes the programs, thereby providing various functions of the UE 1.
[0151] In some implementations, as shown by the dashed line (1205) in Figure 12 In other words, the baseband processor 1203 and the application processor 1204 can be implemented in a single system on chip (SoC) device 1205. The SoC device can be referred to as a large scale integration (LSI) or a chipset.
[0152] The memory 1206 is a volatile memory, a non-volatile memory, or a combination thereof. The memory 1206 can include a plurality of memory devices physically independent of each other. The volatile memory is, for example, a static random access memory (SRAM), a dynamic RAM (DRAM), or a combination thereof. The non-volatile memory is, for example, a mask read only memory (MROM), an electrically-erasable programmable ROM (EEPROM), a flash memory, a hard drive, or any combination thereof. The memory 1206 can include, for example, an external memory device accessible from the baseband processor 1203, the application processor 1204, and the SoC 1205. The memory 1206 can include an internal memory device integrated in the baseband processor 1203, the application processor 1204, or the SoC 1205. Furthermore, the memory 1206 can include a memory in a universal integrated circuit card (UICC).
[0153] The memory 1206 can store one or more software modules (computer programs) 1207 including instructions and data for performing the processing of the UE 1 described in the above embodiments. In some implementations, the baseband processor 1203 or the application processor 1204 can load the software modules 1207 from the memory 1206 and execute the loaded software modules, in order to perform the processing of the UE 1 described in the above embodiments with reference to the attached drawings.
[0154] The control plane processing and operations performed by the UE 1 described in the above embodiments can be implemented by elements other than the RF transceiver 1201 and the antenna array 1202, i.e., by the memory 1206 for storing the software modules 1207 and one or both of the baseband processor 1203 and the application processor 1204.
[0155] Figure 13 A structure example of the AMF 2 is shown. Referring to Figure 13 , the AMF 2 includes a network interface 1301, a processor 1302, and a memory 1303. The network interface 1301 is used for communication with, for example, RAN nodes and with other network functions (NFs) or nodes in the 5GC. The other NFs or nodes in the 5GC include, for example, a UDM, an AUSF, an SMF, and a PCF. The network interface 1301 can include, for example, a network interface card (NIC) compliant with the IEEE 802.3 family of standards.
[0156] The processor 1302 can be, for example, a microprocessor, a micro processing unit (MPU), or a central processing unit (CPU). The processor 1302 can include a plurality of processors.
[0157] The memory 1303 is constituted by a volatile memory and a non-volatile memory. The volatile memory is, for example, a static random access memory (SRAM), a dynamic RAM (DRAM), or a combination thereof. The non-volatile memory is, for example, a mask read only memory (MROM), an electrically erasable programmable ROM (EEPROM), a flash memory, a hard disk drive, or any combination thereof. The memory 1303 can include a memory located remotely from the processor 1302. In this case, the processor 1302 can access the memory 1303 via the network interface 1301 or an I / O interface (not shown).
[0158] The memory 1303 can store one or more software modules (computer programs) 1304 including instructions and data for performing the processing of the AMF 2 described in the above embodiments. In some implementations, the processor 1302 can be configured to load one or more software modules 1304 from the memory 1303 and execute the loaded software modules, in order to perform the processing of the AMF 2 described in the above embodiments.
[0159] As described above with reference to Figure 12 and 13 The processors included in the UE 1 and the AMF 2 according to the above-described embodiments each execute one or more programs including instructions for causing a computer to perform the algorithms described with reference to the accompanying drawings. The programs can be stored and provided to the computer using any type of non-transitory computer readable media. The non-transitory computer readable media include any type of tangible storage media. Examples of the non-transitory computer readable media include a magnetic storage media (such as a floppy diskette, a magnetic tape, a hard disk drive, etc.), an opto-magnetic storage media (e.g., a compact disk read only memory (CD-ROM), a CD-R, a CD-R / W, and the like), and a semiconductor storage media (such as a mask ROM, a programmable ROM (PROM), an erasable PROM (EPROM), a flash ROM, a random access memory (RAM), and the like). The programs can be provided to the computer using any type of transitory computer readable media. Examples of the transitory computer readable media include an electrical signal, an optical signal, and an electromagnetic wave. The transitory computer readable media can provide the programs to the computer via a wired communication line (e.g., an electrical wire and an optical fiber) or a wireless communication line.
[0160] The user equipment (UE) in the present application is an entity connected to a network via a wireless interface. It should be noted that the radio terminal (UE) in the present application is not limited to a dedicated communication device, and the UE can be any device having the communication functions described herein.
[0161] The terms "user equipment (UE)" (as a term used by 3GPP), "mobile station", "mobile terminal", "mobile device", and "radio terminal (wireless device)" are generally intended to be synonymous with one another. The UE can include a standalone mobile station such as a terminal, a cellular phone, a smartphone, a tablet, a cellular IoT (Internet of Things) terminal, and an IoT device, etc. It should be understood that the terms "UE" and "radio terminal" also encompass devices that remain stationary for a long period of time.
[0162] The UE can for example be a device and / or energy-related machinery for production or manufacturing (e.g. a device or machinery such as a boiler, an engine, a turbine, a solar panel, a wind turbine, a hydroelectric generator, a thermal power generator, a nuclear power generator, a battery, a nuclear system and / or related devices, a heavy electric machine, a pump including a vacuum pump, a compressor, a fan, a blower, an oil hydraulic device, a pneumatic device, a metalworking machine, a robot and / or application system thereof, a tool, an extrusion die or a die-casting die, a reel, a conveying device, a lifting device, a material handling device, a textile machine, a sewing machine, a printing and / or related machinery, a papermaking machinery, a chemical machinery, a mining and / or construction machinery and / or related devices, an agricultural, forestry and / or fishery machinery and / or appliance, a safety and / or environmental protection device, a tractor, a bearing, a precision bearing, a chain, a gear, a power transmission device, a lubricator, a valve, a pipe, and / or an application system of any of the aforementioned devices or machinery, etc.).
[0163] The UE can for example be a transportation device (e.g. a transportation device such as a locomotive vehicle, a motor vehicle, a motorcycle, a bicycle, a train, a bus, a cart, a rickshaw, a ship and other watercraft, an airplane, a rocket, a satellite, a drone, a balloon, etc.).
[0164] The UE can for example be an information and communication device (e.g. an information and communication device such as an electronic computer and related devices, a communication and related devices, an electronic component, etc.).
[0165] The UE can for example be a refrigeration device, a refrigeration application product and device, a trade and / or service industry device, a vending machine, a service machine, an office machine or device, a consumer electric and electronic appliance (e.g. a consumer electronic appliance such as an audio device, a speaker, a radio, a video device, a television, a stove, a rice cooker, a coffee maker, a dishwasher, a washing machine, a dryer, a fan, an exhaust fan and related products, a vacuum cleaner, etc.).
[0166] The UE can for example be an electric application system or device (e.g. an electric application system or device such as an x-ray system, a particle accelerator, a radioisotope device, an acoustic wave device, an electromagnetic application device, a power application device, etc.).
[0167] The UE can for example be an electronic lamp, a luminaire, a measuring instrument, an analyzer, a tester, or a measuring or sensing instrument (e.g. a measuring or sensing instrument such as a smoke alarm, a human alarm sensor, a motion sensor, a wireless tag, etc.), a watch or clock, a laboratory instrument, an optical device, a medical device and / or system, a weapon, a tableware or hand tool, etc.
[0168] For example, a UE may be a wirelessly equipped personal digital assistant or related equipment (such as a wireless card or module designed to be attached to or inserted into other electronic devices (eg, personal computers, electrical measuring machines, etc.)).
[0169] A UE may be a device or part of a system that provides the applications, services, and solutions described below for the "Internet of Things (IoT)" using various wired and / or wireless communication technologies. IoT devices (or "things") may be equipped with appropriate electronics, software, sensors, and / or network connectivity, etc., which enable these devices to collect data and exchange data with each other and other communication devices. IoT devices may include automated devices that follow software instructions stored in internal memory. IoT devices can operate without the need for human supervision or interaction. IoT devices may also remain stationary and / or inactive for extended periods of time. IoT devices may be implemented as part of (typically) stationary devices. IoT devices may also be embedded in non-stationary devices (e.g., vehicles) or attached to animals or people to be monitored / tracked. It should be understood that IoT technology can be implemented on any communication device capable of connecting to a communication network for sending / receiving data, regardless of whether such communication device is controlled by human input or by software instructions stored in memory. It should be understood that IoT devices are sometimes also referred to as machine-type communication (MTC) devices, machine-to-machine (M2M) communication devices, or narrowband-IoT (NB-1) UEs.
[0170] It should be understood that a UE may support one or more than one IoT or MTC application.
[0171] Some examples of MTC applications are listed in 3GPP TS 22.368 V13.2.0 (2017-01-13) Annex B (the contents of which are incorporated herein by reference). This list is not exhaustive and is intended to indicate some examples of MTC applications. In this list, service areas for MTC applications include security, tracking and tracing, payment, health, remote maintenance / control, metering, and consumer devices.
[0172] Examples of safety-related MTC applications include surveillance systems, fixed-line backup, control of physical access (eg, to buildings), and car / driver safety.
[0173] Examples of MTC applications related to track and trace include queue management, order management, telematics insurance: pay-as-you-go (PAYD), asset tracking, navigation, traffic information, road pricing, and road traffic optimization / diversion.
[0174] Examples of payment-related MTC applications include point of sale (POS), vending machines, and gaming machines.
[0175] Examples of MTC applications related to health include monitoring vital signs, supporting the elderly or disabled, web access to remote medical points, and remote diagnosis.
[0176] Examples of MTC applications related to remote maintenance / control include sensors, lighting, pumps, valves, elevator control, vending machine control, and vehicle diagnosis.
[0177] Examples of MTC applications related to metering include power, gas, water, heating, grid control, and industrial metering.
[0178] Examples of MTC applications related to consumer devices include digital photo frames, digital cameras, and electronic books (eBooks).
[0179] The application, service, and solution can be a mobile virtual network operator (MVNO) service / system, an emergency radio communication service / system, a private branch exchange (PBX) service / system, a PHS / digital cordless telecommunication service / system, a point of sale (POS) service / system, an advertisement call service / system, a multimedia broadcast and multicast service (MBMS) service / system, a vehicle-to-everything (V2X) service / system, a train radio service / system, a location-related service / system, a disaster / emergency wireless communication service / system, an Internet of Things (IoT) service / system, a community service / system, a video streaming service / system, a femtocell application service / system, a voice over LTE (VoLTE) service / system, a radio tag service / system, a billing service / system, a radio on-demand service / system, a roaming service / system, an activity monitoring service / system, a telecommunication operator / communication NW selection service / system, a function restriction service / system, a proof of concept (PoC) service / system, a personal information management service / system, a display video service / system, a non-communication service / system, a self-organizing network / delay tolerant network (DTN) service / system, and the like.
[0180] The above-described UE categories are merely examples of application of the technical ideas and embodiments described in the present application. The UE described in the present application is not limited to these examples, and various modifications can be made thereto by those skilled in the art.
[0181] The above-described embodiments are merely examples of application of the technical ideas obtained by the present inventors. The technical ideas are not limited to the above-described embodiments, and various modifications can be made thereto.
[0182] All or a part of the above-described embodiments can be described as, but are not limited to, the following supplementary notes.
[0183] (Supplementary note 1)
[0184] An access and mobility management function, AMF, node, comprising:
[0185] at least one memory; and
[0186] at least one processor coupled to the at least one memory,
[0187] wherein the at least one processor is configured to manage a user equipment, UE, context related to a UE,
[0188] wherein the UE context comprises:
[0189] a) a set of allowed network slice identifiers indicating one or more network slice identifiers currently allowed for the UE, and
[0190] b) a set of pending network slice identifiers indicating one or more network slice identifiers pending a network slice specific authentication and authorization, NSSAA, procedure, and
[0191] wherein the at least one processor is configured to, in case the at least one processor triggers initiation of a re-authentication and re-authorization procedure for a first network slice identifier currently allowed for the UE, remove the first network slice identifier from the set of allowed network slice identifiers and store the first network slice identifier in the set of pending network slice identifiers.
[0192] (Supplementary note 2)
[0193] The AMF node of supplementary note 1, wherein the at least one processor is configured to, in response to receiving a request from the UE for establishing a new session associated with the first network slice identifier during the first network slice identifier is stored in the set of pending network slice identifiers, reject the request.
[0194] (Supplementary note 3)
[0195] The AMF node of supplementary note 1, wherein the at least one processor is configured to, in response to receiving a request from the UE for establishing a new session associated with the first network slice identifier during the first network slice identifier is stored in the set of pending network slice identifiers, suspend a session establishment procedure triggered by the request at least until a result of the re-authentication and re-authorization is obtained.
[0196] (Supplementary note 4)
[0197] The AMF node of any of Supplementary Notes 1 to 3, wherein the at least one processor is configured to, in response to removing the first network slice identifier from the allowed set of network slice identifiers and storing the first network slice identifier in the pending set of network slice identifiers, send, to the UE, a non-access stratum (NAS) message indicating an update to UE configuration, and
[0198] wherein the NAS message indicates that the first network slice identifier is to be removed from the allowed set of network slice identifiers and is to be included in the pending set of network slice identifiers.
[0199] (Supplementary Note 5)
[0200] The AMF node of any of Supplementary Notes 1 to 4, wherein the at least one processor is configured to:
[0201] determine, at a triggering of an initiation of a re-authentication and re- authorization procedure for the first network slice identifier, whether the first network slice identifier needs to be removed from the allowed set of network slice identifiers; and
[0202] in a case that the at least one processor determines that the first network slice identifier does not need to be removed from the allowed set of network slice identifiers, continue to store the first network slice identifier in the allowed set of network slice identifiers.
[0203] (Supplementary Note 6)
[0204] The AMF node of Supplementary Note 5, wherein the at least one processor is configured to determine, at the triggering of the initiation of the re-authentication and re- authorization procedure for the first network slice identifier, whether the first network slice identifier needs to be removed from the allowed set of network slice identifiers based on subscription information of the UE.
[0205] (Supplementary Note 7)
[0206] The AMF node of Supplementary Note 5, wherein the at least one processor is configured to determine, at the triggering of the initiation of the re-authentication and re- authorization procedure for the first network slice identifier, whether the first network slice identifier needs to be removed from the allowed set of network slice identifiers based on an indication from an authentication, authorization, and accounting (AAA) server that allowed the first network slice identifier.
[0207] (Supplementary Note 8)
[0208] The AMF node of Supplementary Note 5, wherein the at least one processor is configured to determine whether the first network slice identifier needs to be removed from the allowed network slice identifier set based on a type of network slice associated with the first network slice identifier when triggering initiation of the re-authentication and re-authorization procedure for the first network slice identifier.
[0209] (Supplementary Note 9)
[0210] The AMF node of any of Supplementary Notes 1 to 8, wherein the at least one processor is configured to trigger initiation of the re-authentication and re-authorization procedure for the first network slice identifier in a case that a) an authentication, authorization, and accounting server, AAA server, request for re-authentication of the first network slice identifier, or b) the AMF node determines that re-authentication is needed for the first network slice identifier based on an operator policy or based on a change in subscription information of the UE.
[0211] (Supplementary Note 10)
[0212] The AMF node of any of Supplementary Notes 1 to 9, wherein,
[0213] the first network slice identifier is a single network slice selection assistance information, S-NSSAI,
[0214] the allowed network slice identifier set is an allowed network slice selection assistance information, allowed NSSAI, indicating one or more S-NSSAIs currently allowed for the UE, and
[0215] the pending network slice identifier set is a pending network slice selection assistance information, pending NSSAI, indicating one or more S-NSSAIs pending for the NSSAA.
[0216] (Supplementary Note 11)
[0217] A method in an access and mobility management function, AMF, node, the method comprising:
[0218] managing a user equipment, UE, context related to a UE,
[0219] wherein the UE context comprises:
[0220] a) an allowed network slice identifier set indicating at least one network slice identifier currently allowed for the UE, and
[0221] b) a pending network slice identifier set indicating at least one network slice identifier pending for a network slice specific authentication and authorization procedure, NSSAA procedure; and
[0222] remove the first network slice identifier from the allowed network slice identifier set and store the first network slice identifier in the pending network slice identifier set in case the AMF node triggers initiation of re-authentication and re-authorization procedures for the first network slice identifier currently allowed for the UE.
[0223] (Supplementary note 12)
[0224] A program for causing a computer to perform a method in an access and mobility management function, AMF, node, the method comprising:
[0225] managing a UE context related to a user equipment, UE,
[0226] wherein the UE context comprises:
[0227] a) an allowed network slice identifier set indicating at least one network slice identifier currently allowed for the UE, and
[0228] b) a pending network slice identifier set indicating at least one network slice identifier pending a network slice specific authentication and authorization, NSSAA, procedure; and
[0229] remove the first network slice identifier from the allowed network slice identifier set and store the first network slice identifier in the pending network slice identifier set in case the AMF node triggers initiation of re-authentication and re-authorization procedures for the first network slice identifier currently allowed for the UE.
[0230] (Supplementary note 13)
[0231] An access and mobility management function, AMF, node, comprising:
[0232] at least one memory; and
[0233] at least one processor coupled to the at least one memory,
[0234] wherein the at least one processor is configured to manage a UE context related to a user equipment, UE,
[0235] wherein the UE context comprises:
[0236] a) an allowed network slice identifier set indicating one or more network slice identifiers currently allowed for the UE, and
[0237] b) a set of network slice identifiers to be processed, which indicates one or more network slice identifiers for which a network slice specific authentication and authorization procedure, NSSAA procedure, is to be processed, and
[0238] wherein the at least one processor is configured to continue storing the first network slice identifier in the allowed network slice identifier set in case the at least one processor triggers initiation of a re-authentication and re-authorization procedure for the first network slice identifier currently allowed for the UE.
[0239] (Supplementary note 14)
[0240] The AMF node of supplementary note 13, wherein the at least one processor is configured to, in case of continuing storing the first network slice identifier in the allowed network slice identifier set, set a status of the first network slice identifier to a first state indicating that a permission for the first network slice identifier is currently being invalidated.
[0241] (Supplementary note 15)
[0242] The AMF node of supplementary note 14, wherein the at least one processor is configured to, in response to receiving a request from the UE for establishing a new session associated with the first network slice identifier during the status of the first network slice identifier being in the first state, reject the request.
[0243] (Supplementary note 16)
[0244] The AMF node of supplementary note 14, wherein the at least one processor is configured to, in response to receiving a request from the UE for establishing a new session associated with the first network slice identifier during the status of the first network slice identifier being in the first state, suspend a session establishment procedure triggered by the request at least until a result of re-authentication and re-authorization is obtained.
[0245] (Supplementary note 17)
[0246] The AMF node of any of supplementary notes 13 to 16, wherein the at least one processor is configured to, in response to a failure of the re-authentication and re-authorization procedure for the first network slice identifier, remove the first network slice identifier from the allowed network slice identifier set.
[0247] (Supplementary note 18)
[0248] The AMF node of any of supplementary notes 13 to 17, wherein the at least one processor is configured to:
[0249] determine whether the first network slice identifier needs to be removed from the allowed network slice identifier set upon triggering initiation of the re-authentication and re-authorization procedure for the first network slice identifier; and
[0250] remove the first network slice identifier from the allowed network slice identifier set and store the first network slice identifier in the pending network slice identifier set in a case that the at least one processor determines that the first network slice identifier needs to be removed from the allowed network slice identifier set.
[0251] (Supplementary note 19)
[0252] The AMF node of Supplementary Note 18, wherein the at least one processor is configured to determine whether the first network slice identifier needs to be removed from the allowed network slice identifier set upon triggering initiation of the re-authentication and re-authorization procedure for the first network slice identifier based on subscription information of the UE.
[0253] (Supplementary note 20)
[0254] The AMF node of Supplementary Note 18, wherein the at least one processor is configured to determine whether the first network slice identifier needs to be removed from the allowed network slice identifier set upon triggering initiation of the re-authentication and re-authorization procedure for the first network slice identifier based on an indication from an authentication, authorization and accounting server (AAA server) that allows the first network slice identifier.
[0255] (Supplementary note 21)
[0256] The AMF node of Supplementary Note 18, wherein the at least one processor is configured to determine whether the first network slice identifier needs to be removed from the allowed network slice identifier set upon triggering initiation of the re-authentication and re-authorization procedure for the first network slice identifier based on a type of network slice associated with the first network slice identifier.
[0257] (Supplementary note 22)
[0258] The AMF node of any of Supplementary Notes 13 to 21, wherein the at least one processor is configured to trigger initiation of the re-authentication and re-authorization procedure for the first network slice identifier in a case that a) an authentication, authorization and accounting server (AAA server) that allows the first network slice identifier requests re-authentication, or b) the AMF node determines that re-authentication is needed for the first network slice identifier based on an operator policy or based on a change in subscription information of the UE.
[0259] (Supplementary note 23)
[0260] The AMF node according to any one of Supplementary notes 13 to 22, wherein
[0261] The first network slice identifier is a single Network Slice Selection Assistance Information, S-NSSAI,
[0262] The allowed network slice identifier set is an Allowed Network Slice Selection Assistance Information, Allowed NSSAI, indicating one or more S-NSSAIs currently allowed for the UE, and
[0263] The pending network slice identifier set is a Pending NSSAI indicating one or more S-NSSAIs pending for the NSSAA.
[0264] (Supplementary note 24)
[0265] A method in an Access and Mobility Management Function, AMF, node, the method comprising:
[0266] managing a UE context related to a User Equipment, UE,
[0267] wherein the UE context comprises:
[0268] a) an allowed network slice identifier set indicating at least one network slice identifier currently allowed for the UE, and
[0269] b) a pending network slice identifier set indicating at least one network slice identifier pending for a Network Slice Specific Authentication and Authorization, NSSAA, procedure; and
[0270] in case the AMF node triggers initiation of a re-authentication and re-authorization procedure for a first network slice identifier currently allowed for the UE, continue storing the first network slice identifier in the allowed network slice identifier set.
[0271] (Supplementary note 25)
[0272] A program for causing a computer to perform a method in an Access and Mobility Management Function, AMF, node, the method comprising:
[0273] managing a UE context related to a User Equipment, UE,
[0274] wherein the UE context comprises:
[0275] a) an allowed network slice identifier set indicating at least one network slice identifier currently allowed for the UE, and
[0276] b) a set of network slice identifiers to be processed, which indicates at least one network slice identifier for which a network slice specific authentication and authorization procedure, NSSAA procedure, is to be processed; and
[0277] In a case where the AMF node triggers initiation of a re-authentication and re-authorization procedure for a first network slice identifier currently allowed for the UE, the first network slice identifier is continued to be stored in the allowed network slice identifier set.
[0278] This application is based on and claims priority to Japanese Patent Application 2019-237390, filed on December 26, 2019, the disclosure of which is incorporated by reference herein in its entirety.
[0279] List of reference signs
[0280] 1 UE
[0281] 2 AMF
[0282] 3 SMF
[0283] 4 AUSF
[0284] 5 AN
[0285] 6 UPF
[0286] 7 DN
[0287] 8 UDM
[0288] 9 AAA-S
[0289] 1203 baseband processor
[0290] 1204 application processor
[0291] 1206 memory
[0292] 1207 module
[0293] 1302 processor
[0294] 1303 memory
[0295] 1304 module
Claims
1. An access and mobility management function node, namely an AMF node, comprising: Memory; as well as at least one processor coupled to the memory, The at least one processor is configured to manage a UE context related to a user equipment (UE), The UE context includes: a) allowed network slice selection assistance information, i.e., allowed NSSAI, comprising an allowed network slice identifier set, wherein the allowed network slice identifier set indicates at least one network slice identifier currently allowed for the UE, b) a pending NSSAI, which includes a pending network slice identifier set, the pending network slice identifier set indicating at least one network slice identifier to be processed by a network slice specific authentication and authorization procedure, i.e., an NSSAA procedure, and c) status information indicating whether the NSSAA procedure is ongoing for one or more network slice identifiers, and The at least one processor is configured to set the status information to indicate that the NSSAA process for the first network slice identifier included in the allowed NSSAI is currently in progress when the at least one processor triggers the NSSAA process in the reauthentication and reauthorization process for the first network slice identifier included in the allowed NSSAI.
2. The AMF node of claim 1, wherein, The at least one processor is configured to, in response to receiving from the UE a request to establish a new session associated with the first network slice identifier while the status information is set to indicate that an NSSAA procedure for the first network slice identifier is currently ongoing, reject the request.
3. The AMF node of claim 1, wherein, The at least one processor is configured to, in response to receiving a request from the UE to establish a new session associated with the first network slice identifier during the period when the status information is set to indicate that the NSSAA procedure for the first network slice identifier is currently in progress, suspend the session establishment procedure triggered by the request, at least until a result of reauthentication and reauthorization is obtained.
4. The AMF node of claim 1, wherein, The at least one processor is configured to, in response to receiving a request from the UE to establish a new session associated with the first network slice identifier while the status information is set to indicate that the NSSAA procedure for the first network slice identifier is currently in progress, continue the session establishment procedure triggered by the request.
5. The AMF node of any one of claims 1 to 4, wherein, The at least one processor is configured to remove the first network slice identifier from the allowed NSSAI in response to a failure of the NSSAA procedure for the first network slice identifier.
6. The AMF node of claim 5, wherein, The at least one processor is configured to: storing the first network slice identifier from the allowed NSSAI in a rejected NSSAI comprising a set of rejected network identifiers; and Send information to the UE indicating rejection of the first network slice identifier.
7. The AMF node of any one of claims 1 to 4, wherein, The at least one processor is configured to, in response to a success of the NSSAA procedure for the first network slice identifier, change the status information to indicate that the first network slice identifier is allowed for the UE.
8. The AMF node of claim 7, wherein, The at least one processor is configured to continue a session establishment procedure triggered by a request to establish a new session associated with the first network slice identifier in response to the status information being set to indicate that the first network slice identifier is allowed for the UE during reception of the request from the UE.
9. The AMF node of any one of claims 1 to 4, wherein, The at least one processor is configured to trigger initiation of a NSSAA procedure for the first network slice identifier in case of an authentication, authorization and accounting server, AAA server, request for re-authentication of the first network slice identifier being allowed, or the AMF node determining that re-authentication for the first network slice identifier is needed based on an operator policy or based on a change of subscription information of the UE.
10. A method in an access and mobility management function, AMF, node, the method comprising: managing a user equipment, UE, context related to the UE, wherein the UE context comprises: a) allowed network slice selection assistance information, allowed NSSAI, comprising a set of allowed network slice identifiers indicating at least one network slice identifier currently allowed for the UE, b) pending NSSAI comprising a set of pending network slice identifiers indicating at least one network slice identifier for which a network slice specific authentication and authorization procedure, NSSAA procedure, is pending, and c) status information indicating for one or more network slice identifiers whether a NSSAA procedure is ongoing, and setting the status information to indicate that a NSSAA procedure for a first network slice identifier comprised in the allowed NSSAI is currently ongoing in case the AMF node triggers a NSSAA procedure in a re-authentication and re-authorization procedure for the first network slice identifier.
Citation Information
Patent Citations
Creating network slice selection policy rule
CN110506439A
User Plane Function Selection For Isolated Network Slice
US20190182875A1