Network slice-specific authentication and authorization
By storing the suspended NSSAI of the equivalent PLMN in the UE and stopping the backoff timer, the problem of the UE being unable to access services and experiencing signaling failures in the equivalent PLMN is solved, thereby improving the flexibility and system efficiency of providing location services during NSSAI.
Patent Information
- Application Number
- CN202180037264.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-05-05
- Filing Date
- 2021-05-24
- Publication Date
- 2026-01-23
- Estimated Expiration
- 2041-05-24
AI Technical Summary
In the prior art, when the UE's registration area contains the TAI of the equivalent PLMN, it only stores the suspended NSSAI of the registered PLMN, resulting in the inability to access the services of the equivalent PLMN; the backoff timer is not properly stopped during the 5GSM secondary authentication process, resulting in signaling failure; and when the NSSAI is not allowed, services unrelated to slicing, such as location services, cannot be provided.
The UE stores the suspended NSSAI for each equivalent PLMN and stops the backoff timer upon receiving a PDU session authentication command; it allows other services, such as location services, to be provided during NSSAI and controls service availability via AMF.
It solves the problem of UEs being unable to access services in the equivalent PLMN, avoids signaling failures, and allows slice-independent services to be provided during NSAA, improving the system's flexibility and efficiency.
Smart Images

Figure CN115699889B_ABST
Abstract
Description
Technical Field
[0001] Specific examples of this disclosure provide methods, apparatus, and systems for performing authentication and authorization in a network. For example, specific examples of this disclosure provide methods, apparatus, and systems for performing NSSAA in 3GPP 5G. Background Technology
[0002] Specific examples of this disclosure provide methods, apparatus, and systems for performing authentication and authorization in a network. For example, specific examples of this disclosure provide methods, apparatus, and systems for performing NSSAA in 3GPP 5G.
[0003] The various acronyms, abbreviations, and definitions used in this disclosure are defined at the end of this description.
[0004] In 3GPP 5GS (e.g., in 3GPP standard specifications), the following are defined: A Network Slice (NS) is defined as a logical network that provides specific network capabilities and characteristics. A Network Slice Instance (NSI) is defined as a set of network function instances and the resources (e.g., compute, storage, and network resources) required to constitute a deployed NS. A Network Function (NF) is defined as a processing function in the network adopted or defined by 3GPP, having defined functional behavior and an interface defined by 3GPP. NSs can be identified by Single Network Slice Selection Auxiliary Information (S-NSSAI).
[0005] Overview of equivalent PLMN and registration regions applied to slices
[0006] As described in the 3GPP standard specification, the AMF assigns a registration area to the UE during the registration process. This consists of a list of Tracking Area Identifiers (TAIs) that can provide services to the UE in that registration area, and each of these tracking areas consists of one or more cells covering a geographic area.
[0007] A PLMN that has equivalent service functions to other PLMNs is called an equivalent PLMN. For PLMN selection and cell selection / reselection, the UE considers these PLMNs to be equivalent to each other. When the AMF returns a list of TAIs to the UE during the registration process, this list can consist of the TAIs of PLMNs equivalent to the registered PLMN, as well as the TAIs of the registered PLMN.
[0008] When a UE requests to register to a set of slices, the network provides the UE with an allowed NSSAI and a set of tracking areas that can provide services to all slices in the allowed NSSAI of a specific registration area. If there is a PLMN equivalent to the registered PLMN, the tracking area identifier of the equivalent PLMN that can provide services to all slices in the allowed NSSAI is also sent back to the UE.Figure 1a and 1b An example is provided for assigning TAIs to a registered region based on a set of S-NSSAIs allowed for use by the UE, wherein the TAI set consists of TAIs from the registered PLMN and the equivalent PLMN.
[0009] exist Figure 1a and 1b In the example, when the network returns allowed NSSAIs of {S-NSSAI-1, S-NSSAI-2, S-NSSAI-3}, the returned TAI list is TA#3 (registered PLMN), TA#6 (EPLMN1), and TA#9 (EPLMN2). Furthermore, when the UE registers within an RPLMN and receives allowed NSSAIs, these allowed NSSAIs are stored for the RPLMN and separately for each EPLMN. Therefore, in the example above, allowed NSSAIs are stored for the RPLMN and separately for EPLMN1 and EPLMN2.
[0010] This is described in the 3GPP standard specification, as shown in Table 1.
[0011] Table 1
[0012]
[0013] The above description implies that a UE can directly use an authorized NSSAI in an equivalent PLMN (ePLMN) without explicit request. This can occur when a UE in 5GMM-CONNECTED mode with an RRC inactivity indication reselects to enter an ePLMN in which the TAI is already in the UE's registered area. Since the TAI has already been authorized, the UE does not need to register and can therefore directly switch to connected mode via a service request procedure, followed by a PDU session request for the slice in the UE's authorized NSSAI (which applies to that ePLMN).
[0014] Overview of Network Slice-Specific Authentication and Authorization (NSSAA)
[0015] NSSAA was introduced as part of 3GPP Rel-16. This function enables the network to perform slice-specific authentication and authorization for a set of S-NSSAIs to ensure that users are allowed access to those slices. This process is performed after the 5GMM authentication process and after the registration process. A high-level description of this function can be found in the 3GPP standard specification, while further details can be found in the 3GPP standard specification. The specific functions of the NSSAA process are summarized below.
[0016] The NSSAA process is access-independent. That is, if a slice is successfully authorized, the NSSAA process is considered authorization for both access types (i.e., 3GPP and non-3GPP access types). The term "authorization" can be interpreted as meaning that slice-specific authentication / authorization has been successful for a particular S-NSSAI. However, this does not mean that S-NSSAI is permitted for use in the UE's current Tracking Area (TA) on 3GPP access.
[0017] When a UE registers with the network, it may include a request for NSSAI in its registration request message (if the UE is available). The network behavior specified in the 3GPP standard is described below, as shown in Table 2.
[0018] Table 2
[0019]
[0020]
[0021] When a UE does not have an authorized NSSAI, it is not allowed to obtain service due to an ongoing NSSAA, with a few exceptions. For example, this is described in the 3GPP standard specification as shown in Table 3.
[0022] Table 3
[0023]
[0024] As shown in Table 4, NSSAA can be re-initiated at any time specified in the 3GPP standard specification.
[0025] Table 4
[0026]
[0027]
[0028] As can be seen from the above, the suspended NSSAI defined in the 3GPP standard specification is provided by the service PLMN during the registration process, which indicates the suspended S-NSSAI for the network slice-specific authentication and authorization process.
[0029] The total number of S-NSSAI in the following projects:
[0030] The number of NSSAIs allowed (A-NSSAI) and the number of NSSAIs denied cannot exceed 8, and
[0031] The number of suspended NSSAI (P-NSSAI) and configured NSSAI (C-NSSAI) cannot exceed 16.
[0032] Overview of 5GSM Secondary Authentication
[0033] The 5GSM secondary authentication process is defined in the 3GPP standard specification. It enables the data network (DN) to (re)authenticate and (re)authorize the upper layers of the UE when the UE establishes a PDU session. This process can be performed during or after the PDU session process requested by the UE to establish a non-urgent PDU session. The process is initiated by the SMF and involves the network authenticating the UE using the Extensible Authentication Protocol (EAP) as specified in IETF RFC 3748. The 3GPP standard specification provides a detailed overview of the exchange of EAP messages involved in 5GSM secondary authentication. The exchange of EAP messages occurs between the UE acting as an EAP client and the DN-AA server acting as an EAP server.
[0034] The above information is presented as background information only to aid in understanding this disclosure. No determination or assertion is made regarding whether any of the above content can be considered prior art. Summary of the Invention
[0035] Technical issues
[0036] The purpose of specific examples of this disclosure is to at least partially address, resolve, and / or mitigate at least one problem and / or disadvantage associated with related technologies, such as at least one problem and / or disadvantage described herein. The purpose of specific examples of this disclosure is to provide at least one advantage relative to related technologies, such as at least one advantage described herein.
[0037] The independent claims define this disclosure. The dependent claims define the advantageous features.
[0038] The embodiments or examples disclosed in the specification and / or drawings that do not fall within the scope of the claims should be understood as examples that help to understand this disclosure.
[0039] Various aspects, advantages, and prominent features will become apparent to those skilled in the art from the following detailed description, taken in conjunction with the accompanying drawings illustrating the examples disclosed herein.
[0040] Before proceeding with the following detailed description, it may be advantageous to list the definitions of specific words and phrases used throughout this patent document: the terms “comprising” and “including” and their derivatives mean including but not limited to; the term “or” is inclusive, meaning and / or; the phrases “associated with” and “as associated with” and their derivatives can mean including, being included in, interconnected with, containing, contained in, connected with, coupled with, able to communicate with, cooperate with, interleaved, juxtaposed, proximate, combined with, having, having its properties, etc.; and the term “controller” means any device, system, or part thereof that controls at least one operation, such device may be implemented in hardware, firmware, or software, or some combination of at least two of them. It should be noted that the functionality associated with any particular controller can be centralized or distributed, whether local or remote.
[0041] Furthermore, the various functions described below can be implemented or supported by one or more computer programs, each of which is formed by computer-readable program code and contained in a computer-readable medium. The terms "application" and "program" refer to one or more computer programs, software components, instruction sets, procedures, functions, objects, classes, instances, associated data, or portions thereof suitable for implementation in appropriate computer-readable program code. The phrase "computer-readable program code" includes any type of computer code, including source code, object code, and executable code. The phrase "computer-readable medium" includes any type of medium that can be accessed by a computer, such as read-only memory (ROM), random access memory (RAM), hard disk drive, optical disc (CD), digital video disc (DVD), or any other type of storage. "Non-transitory" computer-readable media does not include wired, wireless, optical, or other communication links that transmit transient electrical or other signals. Non-transitory computer-readable media includes media that permanently store data, as well as media that store data and can subsequently be overwritten, such as rewritable optical discs or erasable memory devices.
[0042] This patent document provides comprehensive definitions of specific words and phrases, and those skilled in the art will understand that in many (if not most) cases, these definitions apply to the prior and future use of the words and phrases defined herein.
[0043] Solution to the problem
[0044] A method for a user equipment (UE) in a wireless communication system, wherein the UE is assigned to a registration area comprising two or more tracking areas (TAs), including at least a first set of TAs belonging to a first public land mobile network (PLMN) to which the UE is registered, the method comprising: receiving a pending network slice selection assistance information (NSSAI) including one or more single NSSAIs (S-NSSAIs) in response to performing a network slice-specific authentication and authorization (NSSAA) procedure; and, if the two or more TAs include at least a second set of TAs belonging to at least one second PLMN equivalent to the first PLMN, applying the received pending NSSAI to at least one second PLMN in the registration area.
[0045] A method for a user equipment (UE) in a wireless communication system, the method comprising: in response to receiving a first message (e.g., a 5GSM message), starting a backoff timer (e.g., T3396, T3584, T3585); when establishing or participating in a data session (e.g., a PDU session), receiving a second message (e.g., a PDU SESSION AUTHENTICATION COMMAND message) for use in the UE authentication process; in response to the second message, stopping the backoff timer; and in response to the second message, sending a third message (e.g., a PDU SESSION AUTHENICATION COMPLETE message).
[0046] A method for a user equipment (UE) in a network, the method comprising: determining that the UE has not allowed NSSAI; and, if a condition is met, initiating or executing a procedure, wherein the condition includes: the procedure being related to the transmission of a predefined type of service, a predefined type of data transmission, and / or a NAS message.
[0047] A method according to claim 28, 29, or 30, wherein the condition further includes: (e.g., receiving an indication to support a procedure from an AMF entity) (e.g., the 5G-LCS bit of the 5GS Network Function Support IE is set to "Support Location Services via 5GC"), allowing a predefined default behavior to initiate or execute the procedure when the UE does not allow NSSAI, optionally receiving an indication to allow a procedure from an AMF entity when the UE does not allow NSSAI (e.g., a predefined bit of the 5GS Network Function Support IE is set to a first predefined value), and / or optionally not receiving an indication to disallow a procedure when the UE does not allow NSSAI (e.g., a predefined bit of the 5GS Network Function Support IE is set to a second predefined value). Attached Figure Description
[0048] To gain a more complete understanding of this disclosure and its advantages, please now refer to the following description taken in conjunction with the accompanying drawings, wherein similar reference numerals denote similar parts:
[0049] Figure 1a This is a table showing an example of how NSSAI can assign TAs to registered regions;
[0050] Figure 1b This shows the relationship between the TAI in the registration area and the NSSAI allowed;
[0051] Figure 2 This is a flowchart illustrating problems and solutions related to backtracking timers according to specific examples of this disclosure; and
[0052] Figure 3 This is a block diagram of an exemplary network entity that can be used in a particular example of this disclosure. Detailed Implementation
[0053] The following discussion Figures 1a to 3 The various embodiments described in this patent document to illustrate the principles of this disclosure are for illustrative purposes only and should not be construed as limiting the scope of this disclosure in any way. Those skilled in the art will understand that the principles of this disclosure can be implemented in any suitably arranged system or device.
[0054] The following description of examples of this disclosure with reference to the accompanying drawings is intended to aid in a full understanding of the disclosure as defined by the claims. Various specific details are included to aid understanding, but these details should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the examples described herein without departing from the scope of this disclosure.
[0055] The same or similar components may be designated with the same or similar reference numerals, although they may be shown in different figures.
[0056] For clarity and brevity, and to avoid obscuring the subject matter of this disclosure, detailed descriptions of techniques, structures, constructions, functions, or processes known in the art may be omitted.
[0057] The terms and words used herein are not limited to their book or standard meanings, but are used only to enable a clear and consistent understanding of this disclosure.
[0058] In this document, the words “including,” “having,” and “containing,” as well as variations of these words (e.g., “including having” and “containing”), mean “including but not limited to” and do not mean (nor) exclude other features, elements, components, integers, steps, processes, operations, functions, characteristics, attributes, and / or combinations thereof.
[0059] In this document, singular forms (e.g., “a,” “one,” and “the”) include plural forms unless the context requires otherwise. For example, a reference to “an object” includes a reference to one or more such objects.
[0060] In this document, the language of general form “X for Y” (where Y is some action, process, operation, function, activity or step, and X is some means that perform the action, process, operation, function, activity or step) includes X that is specifically used for, but not necessarily and exclusively used for Y, in an adjusted, configured or arranged manner.
[0061] Features, elements, components, integers, steps, processes, operations, functions, characteristics, attributes, and / or combinations thereof described or disclosed in connection with a particular aspect, embodiment, example, or claim of this disclosure should be understood to be applicable to any other aspect, embodiment, example, or claim described herein, unless incompatible therewith.
[0062] Specific examples of this disclosure provide methods, apparatus, and systems for performing authentication and authorization in a network. The following examples are applicable and use terminology associated with 3GPP 5G. For example, specific examples of this disclosure provide methods, apparatus, and systems for performing NSAA in 3GPP 5G. However, those skilled in the art will understand that the techniques disclosed herein are not limited to these examples or 3GPP 5G and can be applied to any suitable system or standard, such as one or more existing and / or future generation wireless communication systems or standards.
[0063] For example, the functionality of the various network entities and other features disclosed herein can be applied to corresponding or equivalent entities or functions in other communication systems or standards. Corresponding or equivalent entities or functions can be considered as entities or functions performing the same or similar roles, functions, operations, or purposes in the network. For example, the functionality of the AMF in the following example can be applied to any other suitable type of entity performing access and mobility management functions, and the functionality of the SMF in the following example can be applied to any other suitable type of entity performing session management functions.
[0064] Those skilled in the art will understand that this disclosure is not limited to the specific examples disclosed herein. For example:
[0065] The technologies disclosed in this article are not limited to 3GPP 5G;
[0066] One or more entities in the examples disclosed herein can be replaced by one or more alternative entities that perform equivalent or corresponding functions, procedures or operations;
[0067] One or more messages in the examples disclosed herein may be replaced by one or more alternative messages, signals or other types of information carriers that transmit equivalent or corresponding information.
[0068] In the examples disclosed in this article, one or more additional elements, entities, and / or messages may be added;
[0069] One or more non-essential elements, entities, and / or messages may be omitted in a particular example;
[0070] The functionality, process, or operation of a specific entity in one example can be divided into two or more separate entities in a replacement example;
[0071] The functionality, process, or operation of two or more separate entities in one example can be performed by a single entity in a replacement example;
[0072] The information carried by a particular message in one example can be carried by two or more separate messages in the alternative example;
[0073] The information carried by two or more separate messages in one example can be carried by a single message in the replacement example;
[0074] The order in which operations are performed can be modified in the replacement example (if possible); and
[0075] Information transmission between network entities is not limited to the specific form, type, and / or order of messages described in conjunction with the examples disclosed herein.
[0076] Specific examples of this disclosure may be provided in the form of means / devices / network entities configured to perform one or more defined network functions and / or methods thereof. Specific examples of this disclosure may be provided in the form of systems (e.g., networks) that include one or more such means / devices / network entities and / or methods thereof. For example, in the following examples, a network may include a UE, an AMF, and an SMF.
[0077] Given the relevant technology, at least the following problems exist:
[0078] 1. Handling suspended NSSAI and allowed NSSAI
[0079] As described above, if the registered area contains TAIs belonging to different PLMNs that are equivalent PLMNs, the UE stores the received allowed NSSAIs separately for the registered PLMN and for each equivalent PLMN. However, when the network performs an NSSAA during registration and sends a pending NSSAI back to the UE, the UE may only store the pending NSSAI for the registered PLMN.
[0080] Observation 1: The UE may have a suspended NSSAI for RPLMN storage only, but may not have a suspended NSSAI for any EPLMN storage.
[0081] If NSSAI is allowed to consist of S-NSSAI-1, and the UE performs mobility and periodic registration updates in the RPLMN that triggers the NSSAA on S-NSSAI-1, the AMF sends back a suspended NSSAI containing S-NSSAI-1 to the UE, and the UE stores the suspended NSSAI.
[0082] Observation 2: For disallowed RPLMN, the UE can store S-NSSAI-1 simultaneously in both suspended NSSAI and allowed NSSAI.
[0083] Furthermore, if the TAI list of the registered area contains a PLMN equivalent to the registered PLMN, then since the RPLMN only stores the suspended NSSAI, but stores the allowed NSSAI of both the RPLMN and EPLMN, the UE (with RRC-inactive indication in 5GMM-CONNECTED mode) can perform cell reselection to the EPLMN and access the S-NSSAI-1 service that is currently performing NSSAA.
[0084] Observation 3: When S-NSSAI in EPLMN is performing NSSAA in RPLMN, the UE can obtain access to the services of that S-NSSAI.
[0085] 2. Stop the 5GSM backoff timer due to 5GSM secondary authentication.
[0086] The 3GPP standard specification defines 5GSM congestion control, describing three types of congestion control backoff timers. For DNN-based congestion control, the SMF can request the UE to start backoff timer T3396. For S-NSSAI-based congestion control, the SMF can request the UE to start backoff timer T3585. For S-NSSAI and DNN-based congestion control, the SMF can request the UE to start backoff timer T3584. Whenever the network sends a downlink NAS message and the backoff timer is running, the UE should stop the backoff timer and process the network-initiated message.
[0087] One issue is that the 3GPP standard specification does not mention stopping the backoff timer when the UE receives the PDU SESSIONAUTHENTICATION COMMAND.
[0088] Figure 2The top two-thirds of the diagram illustrates an issue related to the Backoff (BO) timer. In step 1, the UE sends a message to the SMF (e.g., a PDU session modification request). In step 2, the SMF encounters congestion. In step 3, the SMF sends a message to the UE with one or more BO timer indications (e.g., a PDU session modification rejection). In step 4, the UE starts one or more corresponding BO timers. As shown in step 5, the UE cannot send messages while the BO timers are running. In step 6, the SMF is no longer congested. In step 7, the SMF sends a PDU session authentication command message to the UE. As shown in step 8, the UE cannot send a response to the PDU session authentication command message because the BO timers are running. Therefore, in step 9, the SMF retransmits the message from step 7. This leads to the problem shown in step 10, where steps 7 through 9 may be repeated multiple times, resulting in unnecessary signaling and related process failures.
[0089] 3. The current NSAAA process may block location services.
[0090] When the network does not grant NSSAI permission to the UE in the registration acceptance message, the UE should not initiate a request (e.g., a service request) to obtain the service, unless the service is related to an emergency service or the UE is a high-priority UE, etc. This behavior is expected because the restriction on obtaining the service is directly related to accessing the slice via SMF.
[0091] However, there are specific services that the UE can access regardless of the slice, such as location services. Therefore, the UE might be allowed to access such services when NSSAI is not permitted. Currently, this behavior is lacking, thus preventing the UE from accessing location services unrelated to NSSAI.
[0092] In view of the above problems, specific examples in this disclosure provide one or more solutions as follows.
[0093] 1. Handling suspended NSSAI and allowed NSSAI
[0094] A specific example of this disclosure stores the suspended NSSAI for each equivalent PLMN, wherein the registration region includes TAI from these equivalent PLMNs.
[0095] In a specific example of this disclosure, when the UE stores a suspended NSSAI, the UE removes any S-NSSAI from the allowed NSSAIs.
[0096] In a specific example of this disclosure, for a PLMN equivalent to a registered PLMN, the UE removes the S-NSSAI from the stored allowed NSSAIs.
[0097] In a specific example, when the UE's registered area contains the TAI of the equivalent PLMN, the UE will also suspend the NSSAI applied to the equivalent PLMN.
[0098] In a specific example, if the registered region contains TAIs belonging to different PLMNs that are equivalent PLMNs, then for each equivalent PLMN, the UE can replace any stored suspended NSSAI with the suspended NSSAI received in the registered PLMN.
[0099] In a specific example, if a registration acceptance with a suspended NSSAI is received and the registration area contains an equivalent PLMN, the UE may also store the suspended NSSAI of the equivalent PLMN.
[0100] Therefore, in a specific example, when the UE receives a suspended NSSAI from the network and stores the suspended NSSAI of the registered PLMN (RPLMN), if the registered area contains TAIs belonging to different PLMNs that are equivalent PLMNs, the UE additionally stores the received suspended NSSAIs for each equivalent PLMN. If the UE does not store the suspended NSSAIs of the equivalent PLMNs (but stores the allowed NSSAIs of the EPLMNs), then (e.g., in 5GMM-CONNECTED mode with RRC-inactive indication) the UE can perform cell reselection to the EPLMN and is able to access the service of the S-NSSAI for the ongoing NSSAA.
[0101] 2. Stop the 5GSM backoff timer due to 5GSM secondary authentication.
[0102] The specific examples of this disclosure operate according to the new specification conditions of TS 24.501 to stop the backoff timers T3396, T3584 and T3485 running in the UE when the UE receives the PDUSESSION AUTHENTICATION COMMAND.
[0103] In a specific example, for the 5GSM secondary authentication process, when the UE receives the PDU SESSIONAUTHENTICATION COMMAND, if the backoff timer is running, the UE stops the backoff timer.
[0104] Figure 2 The next third shows a solution based on a specific example of this disclosure. Figure 2 Replace the next third of steps 6 to 9 Figure 2The middle third of the process consists of steps 6 to 10. In step 6, the SMF is no longer congested. In step 7, the SMF sends a message to the UE (e.g., a PDU session authentication command message). In step 8, the UE stops one or more BO timers. Therefore, in step 9, the UE can send a message to the SMF (e.g., a PDU session authentication complete message) to execute / complete the relevant procedures.
[0105] 3. Allow other services during NSSAA when NSSAI is not permitted.
[0106] The specific examples disclosed herein allow other services (such as transporting location service messages or other types of containers) during NSSAA, even if NSSAI is not available.
[0107] Specific examples in this disclosure allow the AMF to control whether or not these services can be used when NSSAI is not permitted. If NSSAI is not permitted, the AMF can initially instruct that a particular service cannot be used during NSSAI. When NSSAI is permitted, the AMF can trigger a registration process from the UE, causing the AMF to instruct that these services can now be used.
[0108] Those skilled in the art will understand that, for the purposes of all the techniques disclosed herein, the situation where NSSAI is not allowed can be understood to include the situation where a suspended NSSAI is sent to the UE (optionally, NSSAI is not allowed).
[0109] A specific example of this disclosure provides a method for a user equipment (UE) in a wireless communication system, wherein the UE is assigned to a registration area comprising two or more tracking areas (TAs), including at least a first set of TAs belonging to a first public land mobile network (PLMN) to which the UE is registered, the method comprising: receiving, in response to a network slice-specific authentication and authorization (NSSAA) procedure, a pending network slice selection assistance information (NSSAI) including one or more single NSSAIs (S-NSSAIs); and, if the two or more TAs include at least a second set of TAs belonging to at least one second PLMN equivalent to the first PLMN, the received pending NSSAI is applicable to at least one second PLMN in the registration area.
[0110] In a specific example, the received suspended NSSAI can be applied to the TA of at least one second PLMN that can serve one or more S-NSSAIs in the received suspended NSSAI.
[0111] In a particular example, the method may further include: storing the received suspended NSSAI for each of at least one second PLMN.
[0112] In a particular example, storing the suspended NSSAI of at least one of the second PLMNs may include replacing the previously stored suspended NSSAI with the received suspended NSSAI of at least one of the second PLMNs.
[0113] In a specific example, the suspended NSSAI can be received in a NAS message (e.g., a REGISTRATION ACCEPT message).
[0114] In a specific example, the received suspended NSSAI may be applied to the first PLMN (e.g., also including the received suspended NSSAI stored in the first PLMN).
[0115] In a particular example, the method may further include: receiving an allowed NSSAI that includes one or more S-NSSAIs; and, if two or more TAs include at least one second group of TAs belonging to at least one second PLMN equivalent to the first PLMN, the received allowed NSSAI applies to each of the first PLMN and at least one second PLMN in the registration region.
[0116] In a particular example, the method may further include: storing the received NSSAI for each of the first PLMN and at least one second PLMN.
[0117] In a specific example, the method may also include: receiving a set of TAs that can serve all S-NSSAIs allowed in S-NSSAI.
[0118] In a particular example, the received set of TAs may include one or more TAs of a first PLMN and one or more TAs of at least one second PLMN. A particular example of this disclosure provides a method for a user equipment (UE) in a wireless communication system, the method comprising: in response to receiving a first message (e.g., a 5GSM message), initiating a backoff timer (e.g., T3396, T3584, T3585); when establishing or participating in a data session (e.g., a PDU session), receiving a second message (e.g., a PDUSESSION AUTHENICATION COMMAND message) for use in the UE authentication process; in response to the second message, stopping the backoff timer; and in response to the second message, sending a third message (e.g., a PDU SESSIONAUTHENICATION COMPLETE message).
[0119] In a specific example, stopping the backoff timer may include: if the UE provides Single Network Slice Selection Assistance Information (S-NSSAI) and Data Network Name (DNN) during PDU session establishment, then if the timer (e.g., T3584) runs for the same combination of [S-NSSAI, DNN] provided by the UE, then stop the timer.
[0120] In a specific example, stopping the backoff timer may include: if the UE does not provide S-NSSAI during PDU session setup, then if the timer (e.g., T3584) runs for the same [no S-SSAI, DNN] combination provided by the UE, then stop the timer.
[0121] In a specific example, stopping the backoff timer may include stopping the timer if the timer (e.g., T3584) runs for the same [S-NSSAI, no DNN] combination provided by the UE during PDU session setup.
[0122] In a specific example, stopping the backoff timer may include: if the UE does not provide either S-NSSAI or DNN during PDU session setup, then if the timer (e.g., T3584) runs for the same [no S-SSAI, no DNN] combination provided by the UE, then stop the timer.
[0123] In a specific example, stopping the backoff timer may include stopping the timer if the UE provides a data network name (DNN) during PDU session establishment, and if the timer (e.g., T3396) is to run for the DNN provided by the UE.
[0124] In a specific example, stopping the backoff timer may include stopping the timer if the UE does not provide a DNN during PDU session setup and if no timer associated with the DNN (e.g., T3396) is running.
[0125] In a specific example, stopping the backoff timer may include: if the UE provides S-NSSAI during PDU session setup, then if the timer (e.g., T3585) is running for S-NSSAI provided by the UE, then stop the timer.
[0126] In a specific example, stopping the backoff timer may include stopping the timer if the UE does not provide S-NSSAI during PDU session setup and if no timer (e.g., T3585) associated with an un-S-NSSAI is running.
[0127] In a specific example, stopping the backoff timer may include stopping the timer if the UE does not provide a DNN, and if the timer corresponding to the DNN that the UE believes is associated with the PDU session (e.g., T3396) is running.
[0128] In a specific example, the UE may consider the association between the DNN and the PDU session based on the value (e.g., the DNN value) returned by a network entity (e.g., an SMF entity) in a message (e.g., a PDU session establishment accept message or a PDU session modification accept message).
[0129] In a specific example, stopping the backoff timer may include: if the UE does not provide the [S-NSSAI,DNN] combination, then if the timer corresponding to the [S-NSSAI,DNN] combination that the UE believes is associated with the PDU session (e.g., T3584) is running, stop the timer.
[0130] In a specific example, the UE may consider the association of the [S-NSSAI,DNN] combination with the PDU session based on the value (e.g., the [S-NSSAI,DNN] combination value) returned by a network entity (e.g., an SMF entity) in a message (e.g., a PDU session establishment accept message or a PDU session modification accept message).
[0131] In a specific example, stopping the backoff timer may include stopping the timer if the UE does not provide S-NSSAI and if the timer corresponding to the S-NSSAI that the UE believes is associated with the PDU session (e.g., T3585) is running.
[0132] In a specific example, the UE may consider the association of S-NSSAI with the PDU session based on the value (e.g., S-NSSAI value) returned by a network entity (e.g., SMF entity) in a message (e.g., PDU session establishment accept message or PDU session modification accept message), or based on the value (e.g., S-NSSAI value) that is considered to be associated with the PDU session after moving to the target 5GS system of the VPLMN.
[0133] In a specific example, the UE authentication process may include 5GSM secondary authentication.
[0134] In a specific example, the stopping of the backoff timer is not transparent to the UE's 5GSM layer.
[0135] A specific example of this disclosure provides a method for a user equipment (UE) in a network, the method comprising: determining that the UE has not allowed NSSAI; and, if a condition is met, initiating or executing a procedure, wherein the condition includes: the procedure being related to the transmission of a predefined type of service, a predefined type of data transmission, and / or a NAS message.
[0136] In a particular example, the method may also include: receiving a message (e.g., a NAS message) from a network entity (e.g., an AMF entity), wherein one or more of the following occur: the message is received during an NSSAA procedure; the message is a registration acceptance message; the message indicates that an NSSAA should be performed; the message does not include allowing NSSAI; and the message includes suspending NSSAI.
[0137] In a specific example, initiating or executing a process may include: (e.g., sending a service request message, a control plane service request message, or a NAS message (e.g., a UL NAS TRANSPORT message) to an AMF entity.
[0138] In a specific example, the condition also includes: (e.g., receiving an indication to support the procedure from an AMF entity, e.g., the 5G-LCS bit of the 5GS Network Function Support IE is set to "Support Location Services via 5GC"), a predefined default behavior to allow the procedure to be initiated or executed when the UE does not allow NSSAI, optionally receiving an indication to allow the procedure from an AMF entity when the UE does not allow NSSAI, e.g., the predefined bit of the 5GS Network Function Support IE is set to a first predefined value, and / or optionally not receiving an indication to disallow the procedure when the UE does not allow NSSAI, e.g., the predefined bit of the 5GS Network Function Support IE is set to a second predefined value.
[0139] In a specific example, a service of a predefined type may be a service not associated with a PDU session, and / or data of a predefined type may be data not associated with a PDU session.
[0140] In a specific example, a predefined type of service may include a location service.
[0141] In a specific example, data of a predefined type may include one or more of the following: SMS; LPP message; SOR transparent container; container of a predefined type; or UE parameter update transparent container.
[0142] In a specific example, the condition may also include receiving a message (e.g., a DL NAS TRANSPORT message) related to a process (e.g., sending a UL NAS TRANSPORT message).
[0143] In a specific example, the method may further include: receiving permission for NSSAI from a network entity (e.g., an AMF entity); receiving one or more messages from a network entity (e.g., an AMF entity); and, in response to receiving at least a first message (e.g., a configuration update command) from an AMF entity, performing a registration process for initiating or executing the process.
[0144] In a specific example, the first message may include an instruction to request registration.
[0145] In a particular example, one or more messages may include a second message (e.g., a registration acceptance message).
[0146] In a particular example, at least one message (e.g., a first message or a second message) may include indications that the process is permitted, available, and / or supported.
[0147] In a specific example, NSSAI can be received in at least one message (e.g., the first message or the second message).
[0148] A specific example of this disclosure provides a method for entities in a network including network entities (e.g., AMF entities) and user equipment (UEs), the method comprising: determining that the UE has not allowed NSSAI; and, when the UE has not allowed NSSAI, sending to the UE a first message indicating whether a specific procedure is allowed, available, or supported, wherein the procedure is related to the transmission of a predefined type of service, the transmission of a predefined type of data, and / or the transmission of NAS messages.
[0149] In a specific example, when the UE does not allow NSSAI, the first message may indicate that the procedure is not allowed, unavailable, and / or not supported.
[0150] In a particular example, the method may further include: determining that the UE has NSSAI enabled; and sending one or more messages to the UE including a second message indicating that the procedure is enabled, available, and / or supported.
[0151] In a specific example, one or more messages may include messages used to trigger the UE to perform a registration procedure for initiating or executing a process (e.g., a configuration update command message).
[0152] In a specific example, the method may also include sending an NSSAI permission to the UE.
[0153] In a specific example, NSSAI can be sent to the UE in a second message.
[0154] Specific examples of this disclosure provide a first network entity (e.g., UE, AMF entity, and / or SMF entity) configured to operate according to any example, embodiment, aspect, and / or claim disclosed herein.
[0155] Specific examples of this disclosure provide a second network entity (e.g., UE, AMF entity, and / or SMF entity) configured to cooperate with a first network entity according to any example, embodiment, aspect, and / or claim disclosed herein.
[0156] Specific examples of this disclosure provide a network (or wireless communication system) including a UE and one or more additional network entities according to any example, embodiment, aspect and / or claim disclosed herein.
[0157] Specific examples of this disclosure provide computer programs including instructions that, when executed by a computer or processor, cause the computer or processor to perform methods according to any example, embodiment, aspect, and / or claim disclosed herein.
[0158] Specific examples of this disclosure provide a computer- or processor-readable data carrier on which a computer program according to the foregoing examples is stored.
[0159] Specific examples of this disclosure will now be described in more detail.
[0160] 1. Handling suspended NSSAI and allowed NSSAI
[0161] To address the problem described in Observation 1 above, a specific example of this disclosure may store the suspended NSSAI for each equivalent PLMN, wherein the registered area consists of TAIs from these equivalent PLMNs. To address the problem described in Observation 3 above, in a specific example of this disclosure, for a PLMN equivalent to the registered PLMN, the UE (also) removes the S-NSSAI from the stored allowed NSSAIs. In this case, when the UE receives a REGISTRATIONACCEPT in the current PLMN containing the suspended NSSAI, for each equivalent PLMN, the UE can replace any stored suspended NSSAI with the suspended NSSAI received in the registered PLMN, and for each access type, remove the S-NSSAI (if any) included in the suspended NSSAI from the stored allowed NSSAIs.
[0162] For example:
[0163] For observation 1, a specific example of this disclosure can be operated according to the following normative statement 1) added to the 3GPP standard specification: and
[0164] For observation 3, specific examples of this disclosure can be operated according to normative statement 2) added to the 3GPP standard specification as shown in Table 5.
[0165] Table 5
[0166]
[0167]
[0168] To address the problem described in Observation 2 above, in a specific example of this disclosure, when the UE stores a suspended NSSAI, the UE removes any S-NSSAI from the allowed NSSAIs. For example, this specific example of the disclosure can operate according to normative statement 2) added to the 3GPP standard specification as shown in Table 6 below.
[0169] Table 6
[0170]
[0171]
[0172] The specific examples disclosed herein can be operated according to the modified sub-clauses shown above.
[0173] In the above, those skilled in the art will understand that when an NSSAI (e.g., suspending an NSSAI or allowing an NSSAI) applies to a PLMN in a registered region, this can be considered equivalent to: applying a suspended NSSAI to a PLMN in a registered region; or assuming that a suspended NSSAI applies to a PLMN in a registered region. When an NSSAI (e.g., suspending an NSSAI or allowing an NSSAI) applies to a PLMN or at least two PLMNs, the NSSAI of the PLMN or each PLMN can be stored.
[0174] Technical personnel will understand that suspended NSSAI can be received in any suitable message type. For example, suspended NSSAI can be received in any NAS message, not limited to the REGISTRATION ACCEPT message.
[0175] 2. Stop the 5GSM backoff timer due to 5GSM secondary authentication.
[0176] To address the issue discussed above where the UE stops the backoff timer upon receiving the PDU SESSION AUTHENTICATION COMMAND, specific examples of this disclosure can be implemented according to the normative statements of the 3GPP standard specifications as shown in Table 7 below.
[0177] Table 7
[0178]
[0179]
[0180]
[0181] The specific examples disclosed herein can be operated according to the modified sub-clauses shown above.
[0182] 3. Allow other services, such as location services, during NSAA.
[0183] In a specific example of this disclosure, during any NSSAA procedure, if the UE receives any NAS message, such as a registration acceptance message (optionally, the "To perform NSSAA" indicator is set to "To perform network slice-specific authentication and authorization", optionally, NSSAA is not allowed, and optionally, NSSAA is suspended), if the "5G-LCS" bit of the 5GS network function support IE is set to "Support location services via 5GC", the UE can determine that the UE can initiate the relevant NAS procedure to send a location service message.
[0184] Therefore, in a specific example of this disclosure, during NSSAA, if the UE does not allow NSSAI, the UE may be allowed to initiate a UE-initiated NAS transfer procedure (i.e., sending a UL NAS TRANSPORT message may be permitted) to send location service messages. Similarly, in a specific example of this disclosure, the UE may be allowed to initiate a service request procedure (i.e., sending a service request message or a control plane service request message may be permitted) to send location service messages.
[0185] The above techniques can also be applied to other types of data that the UE can send using UL NAS TRANSPORT messages, such as, but not limited to, SMS, LPP messages, SOR transparent containers, UE parameter update transparent containers, or any other suitable type of container.
[0186] More generally, in specific examples of this disclosure, for any service or data not bound to a PDU session, even if the UE does not allow NSSAI, the UE may initiate a service request procedure to send the relevant data or container (e.g., as listed above) by sending a service request message or a control plane service request message. Similarly, in specific examples of this disclosure, even if the UE does not allow NSSAI, the UE may initiate a UE-initiated NAS transport procedure to send the relevant data or container (e.g., as listed above) by sending a UL NAS TRANSPORT message.
[0187] It is possible that, when NSSAI is not permitted for use by the UE, the AMF may not want the UE to use any other services based on network policy, even if those services are unrelated to the slice. For this purpose, specific examples of this disclosure may apply one or more of the following techniques. The service can be SMS, location services, etc., or any combination of these services.
[0188] For services for which there is no means of negotiating capability exchange or support between the UE and the network, the default behavior may be to allow these services. Alternatively, the default behavior may be to disallow these services. Alternatively, these services may be allowed to the UE only if the UE receives the relevant service (or message) in a DL NAS TRANSPORT message, and if it allows the UE to respond to the service by sending relevant data in a UL NAS TRANSPORT message.
[0189] For example, if the UE receives a DL NAS TRANSPORT message containing a UE parameter update transparent container, then the UE parameter update transparent container, etc., can be allowed to be sent by the UE in the DL NAS TRANSPORT message.
[0190] Those skilled in the art will understand that the UE parameter update transparent container is used only as an example, and the techniques disclosed herein can be applied to other types of services or containers sent using the NAS transport procedure.
[0191] For services that require negotiation of capability or support indication between the UE and the network (e.g., SMS, location services), the UE can determine whether these services can be sent (even if NSSAI permission is not received) based on the content of the network's indication for the corresponding service (or location of the bit) in the 5GS Registration Result IE and / or 5GS Network Function Support IE.
[0192] In a specific example of this disclosure, if the AMF's policy is that the UE cannot use the service when NSSAI is not allowed, the AMF can instruct the corresponding bit in the appropriate IE in the registration acceptance message to disallow or not support the service. For example, if the AMF does not want the UE to use location services when NSSAI is not allowed due to NSSAI, the AMF can set the 5G-LCS bit of the 5GS network function support IE to "Location services via 5GC not supported". The same behavior and techniques can also be applied to other services (such as SMS), and it should be noted that different bits in the corresponding IE (i.e., the 5GS registration result IE) (i.e., the "SMS allowed" bit) need to be set to appropriate values (e.g., "SMS not allowed on NAS").
[0193] When NSSAI is allowed to be used by the UE, the AMF can use the configuration update command message to trigger the registration process from the UE in 5GMM-CONNECTED mode (referred to as connected mode), so that the corresponding service can be allowed because NSSAI is allowed to be used.
[0194] The AMF can also optionally indicate "Request Registration" in the "RED" bit of the Configuration Update Indication IE. The AMF can indicate that the registration process can be performed by the UE using an existing NAS signaling connection, i.e., without releasing (or waiting for the network to release) the NAS signaling connection. For example, the AMF can use the Signaling Connection Hold Request (SCMR) bit, setting the SCMR bit to 1 to indicate "No need to release the N1NAS signaling connection". Based on this, the UE can perform the registration process in connected mode, i.e., using the current NAS signaling connection (and without releasing the NAS signaling connection or waiting for the network to release the NAS signaling connection). When sending the registration request, the UE can request all services it needs, such as SMS, location services, etc., by setting appropriate bits in the 5GMM Capability IE (e.g., the "5G-LCS" bit can be set to indicate "Support LCS Notification Mechanism") and / or in the 5GS Update Type IE (e.g., requesting the use of SMS by setting "Request SMS" accordingly).
[0195] For example, if the AMF disallows SMS when NSSAI is unavailable, and assuming the AMF now wants to allow the UE to use SMS when NSSAI is available, the AMF can send a configuration update command message, including an SMS indication IE where the SMS availability indication is set to "SMS available on NAS". Optionally, the AMF takes the above action when sending the permission to allow NSSAI to the UE in the configuration update command message. The AMF can also optionally indicate "Request registration" in the "RED" bit of the configuration update indication IE.
[0196] If the AMF does not allow another service (such as the transmission or delivery of location service messages) when NSSAI is unavailable, and the AMF now wants to allow the UE to use the service, the AMF can send a configuration update command message to the UE with one or more of the following:
[0197] 1. This message can indicate "Request Registration" in the "RED" bit of the configuration update indicator for IE;
[0198] 2. This message can instruct another IE, which will also be used to trigger the registration process from connected mode, without releasing the NAS signaling connection. For this purpose, an existing IE or a new IE with the relevant information or bits can be used.
[0199] 3. Optionally, the above actions can be taken by the AMF when sending the new NSSAI permission in the configuration update command message (i.e., the above actions or indications can be performed in the same message carrying the new NSSAI permission); and
[0200] 4. Optionally, the AMF may use bits to indicate whether there is an update regarding network use of a specific service (or data type), for example, where the update might mean, for example, that a specific service (or data type) is allowed or not allowed, etc. New bits can be defined for each service (e.g., location service messages, LPP, UE policy containers, etc.), where the new bits can be defined in a new IE or an existing IE. The AMF can set corresponding bits to indicate whether the network's permission for service use has changed (e.g., from disallowed to allowed, or vice versa). Based on this indication via at least one bit (wherein, optionally, the bit is used for a specific service or data type as described above), the UE can perform a registration procedure (i.e., send a registration request message) to request the specific service represented by the bits in discussion for the UE. The UE may optionally send the registration request due to a NAS message indicating a (re)registration request, whereby the (re)registration is optionally completed by the UE using an existing NAS connection, i.e., the UE does not release the connection for the purpose of the UE (re)registration.
[0201] Alternatively, the AMF can achieve the above objective by providing a new NSSAI permission without using a configuration update command message. The AMF can use any of the above actions to first trigger the registration process from the UE in connected mode, and then provide the new NSSAI permission in the registration acceptance message. In the registration acceptance message, assuming NSSAI permission is available, the AMF can also indicate which services the UE is now allowed to use. Therefore, relevant bits in the relevant IE can be set accordingly to indicate, for example, that SMS or location service messages are now available.
[0202] Technicians will understand that the above techniques can be used in any appropriate combination.
[0203] Figure 3 This is a block diagram of exemplary network entities that can be used in this disclosure. For example, UE, AMF, SMF, and / or any other suitable network entity can be used. Figure 3 It is provided in the form of network entities as shown. Technical personnel will understand that... Figure 3 The network entity shown can be implemented as, for example, a network unit on dedicated hardware, a software instance running on dedicated hardware, or a virtualization function instantiated on a suitable platform (e.g., on cloud infrastructure).
[0204] Entity 300 includes a processor (or controller) 301, a transmitter 303, and a receiver 305. Receiver 305 is configured to receive one or more messages or signals from one or more other network entities. Transmitter 303 is configured to send one or more messages or signals to one or more other network entities. Processor 301 is configured to perform one or more operations and / or functions as described above. For example, processor 301 may be configured to perform operations of the UE, AMF, and / or SMF.
[0205] The techniques described herein can be implemented using any suitably configured apparatus and / or system. Such apparatus and / or system can be configured to perform methods according to any aspect, embodiment, example, or claim disclosed herein. Such apparatus may include one or more elements (e.g., receiver, transmitter, transceiver, processor, controller, module, unit, etc.), each element configured to perform one or more corresponding process, operational, and / or method steps for implementing the techniques described herein. For example, operation / function of X can be performed by a module (or X module) configured to perform X. One or more elements can be implemented in hardware, software, or any combination of hardware and software.
[0206] It is understood that the examples of this disclosure may be implemented in the form of hardware, software, or any combination of hardware and software. Any such software may be stored in the form of volatile or non-volatile storage (e.g., storage devices like ROM, whether erasable or rewritable), or in the form of memory (e.g., RAM, memory chips, devices, or integrated circuits) or stored on optical or magnetically readable media (such as, for example, CDs, DVDs, disks, or magnetic tapes).
[0207] It is understood that storage devices and storage media are embodiments of machine-readable storage suitable for storing one or more programs including instructions that, when executed, implement specific examples of this disclosure. Therefore, specific examples provide programs including code for implementing methods, apparatus, or systems according to any example, embodiment, aspect, and / or claim disclosed herein, and / or machine-readable storage for storing such programs. Furthermore, such programs can be communicated electronically via any medium (e.g., communication signals transmitted over wired or wireless connections).
[0208] Although this disclosure has been described with reference to various embodiments, various changes and modifications will be apparent to those skilled in the art. The aim is to include such changes and modifications that fall within the scope of the appended claims.
Claims
1. A method for communication by a user equipment (UE) in a wireless communication system, comprising: Send a registration request message associated with the registration process to the Access and Mobility Management Function (AMF); as well as Receive a registration acceptance message from AMF, which includes Suspend Network Slice Selection Assistance Information (NSSAI). If the registration area assigned by the AMF during the registration process contains a Tracking Area Identifier (TAI) belonging to a different PLMN that is an equivalent Public Land Mobile Network (PLMN), then the suspended NSSAI applies to the equivalent PLMN in the registration area.
2. The method according to claim 1, wherein, A suspended NSSAI consists of one or more single NSSAIs (S-NSSAIs).
3. The method according to claim 2, wherein, Suspend NSSAI applies to the tracking area (TA) of at least one PLMN serving one or more S-NSSAIs in Suspend NSSAI.
4. The method according to claim 1, further comprising: If the registered region contains TAIs belonging to different PLMNs that are equivalent PLMNs, then the suspended NSSAI of each of the equivalent PLMNs is stored.
5. The method according to claim 4, wherein, The suspended NSSAI for each of the storage equivalent PLMNs includes: replacing any storage's suspended NSSAI with the suspended NSSAI received in the registration accept message.
6. The method according to claim 1, further comprising: Store the received suspended NSSAI of the first PLMN, wherein the received suspended NSSAI applies to the first PLMN.
7. A user equipment (UE) in a wireless communication system, comprising: transceiver; and A processor, coupled to a transceiver, wherein the processor is configured as follows: Send a registration request message associated with the registration process to the Access and Mobility Management Function (AMF); and Receive a registration acceptance message from AMF, which includes Suspend Network Slice Selection Assistance Information (NSSAI). If the registration area assigned by the AMF during the registration process contains a Tracking Area Identifier (TAI) belonging to a different PLMN that is an equivalent Public Land Mobile Network (PLMN), then the suspended NSSAI applies to the equivalent PLMN in the registration area.
8. The UE according to claim 7, wherein, A suspended NSSAI consists of one or more single NSSAIs (S-NSSAIs).
9. The UE according to claim 8, wherein, Suspend NSSAI applies to the tracking area (TA) of at least one PLMN serving one or more S-NSSAIs in Suspend NSSAI.
10. The UE according to claim 7, wherein, The processor is also configured as follows: If the registered region contains TAIs belonging to different PLMNs that are equivalent PLMNs, then the suspended NSSAI of each of the equivalent PLMNs is stored.
11. The UE according to claim 10, wherein, In order to store the suspended NSSAI for each of the equivalent PLMNs, the processor is configured as follows: Replace any stored suspended NSSAI with the suspended NSSAI received in the registration accept message.
12. The UE according to claim 7, wherein, The processor is also configured as follows: Store the received suspended NSSAI of the first PLMN, wherein the received suspended NSSAI applies to the first PLMN.