Network slice specific authentication and authorization
By introducing the Network Slice Specific Authentication and Authorization (NSSAA) mechanism, AMF can efficiently handle UE access and mobility management in a multi-network slicing environment, solving the problem of inefficient network slicing management in existing systems, and achieving a more efficient network slicing authentication and authorization process.
Patent Information
- Application Number
- CN202180036800.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-05-20
- Filing Date
- 2021-05-20
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2041-05-20
AI Technical Summary
In the existing 4G/5G systems, the management and authentication and authorization mechanism of network slices have problems such as inefficiency and insufficient flexibility. Especially in a multi-network slice environment, the access and mobility management function (AMF) of UEs is difficult to efficiently handle network slice-specific authentication and authorization requests.
The network slice-specific authentication and authorization (NSSAA) mechanism is introduced, and NAS request messages from wireless devices are received through AMF, and network slice-specific authentication and authorization processes are determined and executed, supporting efficient management in a multi-network slice environment.
It improves the efficiency and flexibility of network slicing management, ensures efficient access and mobility management of UE in a multi-slicing environment, and improves the overall performance and user experience of the system.
Smart Images

Figure CN115735371B_ABST
Abstract
Description
[0001] Cross - Reference to Related Applications
[0002] This application claims the benefit of U.S. Provisional Application No. 63 / 027,571, filed on May 20, 2020, the entire content of which is incorporated herein by reference. BRIEF DESCRIPTION OF THE DRAWINGS
[0003] Examples of several embodiments of the present invention are described herein with reference to the figures.
[0004] Figure 1 FIG. is a diagram of an exemplary 5G system architecture for aspects of an embodiment according to the present disclosure.
[0005] Figure 2 FIG. is a diagram of an example 5G system architecture for aspects of an embodiment according to the present disclosure.
[0006] Figure 3 FIG. is a system diagram of an example wireless device and network node in a 5G system for aspects of an embodiment according to the present disclosure.
[0007] Figure 4 FIG. is a system diagram of an example wireless device for aspects of an embodiment according to the present disclosure.
[0008] Figure 5A and Figure 5B depicts two registration management state models in UE 100 and AMF 155 for aspects of an embodiment according to the present disclosure.
[0009] Figure 6A and Figure 6B depicts two connection management state models in UE 100 and AMF 155 for aspects of an embodiment according to the present disclosure.
[0010] Figure 7 FIG. is a schema for classifying and tagging traffic for aspects of an embodiment according to the present disclosure.
[0011] Figure 8 FIG. is an exemplary call flow for aspects of an embodiment according to the present disclosure.
[0012] Figure 9 FIG. is an exemplary call flow for aspects of an embodiment according to the present disclosure.
[0013] Figure 10 FIG. is an exemplary call flow for aspects of an embodiment according to the present disclosure.
[0014] Figure 11 FIG. is an exemplary call flow for aspects of an embodiment according to the present disclosure.
[0015] Figure 12An exemplary call flow according to an aspect of an embodiment of the present disclosure.
[0016] Figure 13 An exemplary call flow according to an aspect of an embodiment of the present disclosure.
[0017] Figure 14 An exemplary radio resource control (RRC) state transition aspect according to an aspect of an embodiment of the present disclosure.
[0018] Figure 15 Shows a service - based architecture of a 5G network regarding the interaction between the control plane (CP) and the user plane (UP).
[0019] Figure 16 Shows an exemplary embodiment of the present disclosure.
[0020] Figure 17 Shows an exemplary embodiment of the present disclosure.
[0021] Figure 18 Shows an exemplary embodiment of the present disclosure.
[0022] Figure 19 Shows an exemplary embodiment of the present disclosure.
[0023] Figure 20 Shows an exemplary embodiment of the present disclosure.
[0024] Figure 21 Shows an exemplary embodiment of the present disclosure.
[0025] Figure 22 Shows an exemplary flowchart of the present disclosure.
[0026] Figure 23 Shows an exemplary flowchart of the present disclosure. Detailed Description
[0027] Exemplary embodiments of the present invention enable enhanced features and functions to be implemented in 4G / 5G systems. Embodiments of the techniques disclosed herein can be used in the technical fields of 4G / 5G systems and network slicing for communication systems. More specifically, embodiments of the techniques disclosed herein can relate to 5G core networks and 5G systems for network slicing in communication systems. Throughout this disclosure, UE, wireless device, and mobile device may be used interchangeably.
[0028] The following abbreviations are used throughout this disclosure:
[0029] 5G Fifth - generation mobile network
[0030] 5GC 5G core network
[0031] 5GS 5G System
[0032] 5G-AN 5G Access Network
[0033] 5QI 5G QoS Indicator
[0034] ACK Acknowledgment
[0035] AF Application Function
[0036] AMF Access and Mobility Management Function
[0037] AN Access Network
[0038] CDR Charging Data Record
[0039] CCNF Common Control Network Function
[0040] CIoT Cellular IoT
[0041] CN Core Network
[0042] CP Control Plane
[0043] DDN Downlink Data Notification
[0044] DL Downlink
[0045] DN Data Network
[0046] DNN Data Network Name
[0047] DRX Discontinuous Reception
[0048] F-TEID Fully Qualified TEID
[0049] gNB Next Generation Node B
[0050] GPSI Generic Public Subscription Identifier
[0051] GTP GPRS Tunneling Protocol
[0052] GUTI Global Unique Temporary Identifier
[0053] HPLMN Home Public Land Mobile Network
[0054] IMSI International Mobile Subscriber Identity
[0055] LADN Local Area Data Network
[0056] LI Lawful Interception
[0057] MEI Mobile Equipment Identifier
[0058] MICO Mobile-Initiated Only Connection
[0059] MME Mobility Management Entity
[0060] MO Mobile Originated
[0061] MSISDN Mobile Subscriber ISDN
[0062] MT Mobile Terminated
[0063] N3IWF Non-3GPP Interworking Function
[0064] NAI Network Access Identifier
[0065] NAS Non-Access Stratum
[0066] NAS-MM Non-Access Stratum Mobility Management
[0067] NAS-SM Non-Access Stratum Session Management
[0068] NB-IoT NarrowBand IoT
[0069] NEF Network Exposure Function
[0070] NF Network Function
[0071] NGAP Next Generation Application Protocol
[0072] NR New Radio
[0073] NRF Network Repository Function
[0074] NSI Network Slice Instance
[0075] NSSAI Network Slice Selection Assistance Information
[0076] NSSF Network Slice Selection Function
[0077] OCS Online Charging System
[0078] OFCS Offline Charging System
[0079] PCF Policy Control Function
[0080] PDU Packet / Protocol Data Unit
[0081] PEI Permanent Equipment Identifier
[0082] PLMN Public Land Mobile Network
[0083] PRACH Physical Random Access Channel
[0084] PLMN Public Land Mobile Network
[0085] PSA PDU Session Anchor
[0086] RAN Radio Access Network
[0087] QFI QoS Flow Identifier
[0088] RM Registration Management
[0089] S1-AP S1 Application Protocol
[0090] SBA Service-Based Architecture
[0091] SEA Security Anchor Function
[0092] SCM Security Context Management
[0093] SI System Information
[0094] SIB System Information Block
[0095] SMF Session Management Function
[0096] SMSF SMS Function
[0097] S-NSSAI Single Network Slice Selection Assistance Information
[0098] SSC Session and Service Continuity
[0099] SUCI Service User Correlation ID
[0100] SUPI Subscriber Permanent Identifier
[0101] TEID Tunnel Endpoint Identifier
[0102] UDM Unified Data Management
[0103] UER Unified Data Repository
[0104] UDR User Data Repository
[0105] UE User Equipment
[0106] UL Uplink
[0107] UL CL Uplink Classifier
[0108] UPF User Plane Function
[0109] PLMN Public Land Mobile Network
[0110] Example Figure 1 And Figure 2depicts a 5G system including an access network and a 5G core network. An example 5G access network may include an access network connected to the 5G core network. The access network may include an NG-RAN 105 and / or a non-3GPP AN 165. An example 5G core network may be connected to one or more 5G access networks 5G-AN and / or NG-RAN. The 5G core network may include functional elements or network functions as in example Figure 1 and example Figure 2 where interfaces may be used for communication between the functional elements and / or network elements.
[0111] In an example, a network function may be a processing function in a network, which may have functional behavior and / or interfaces. A network function may be implemented as a network element on dedicated hardware and / or as a network node depicted in Figure 3 and Figure 4 or implemented as a software instance running on dedicated hardware and / or shared hardware, or implemented as a virtual function instantiated on a suitable platform.
[0112] In an example, the Access and Mobility Management Function AMF 155 may include the following functions (some of the functions of AMF 155 may be supported in a single instance of AMF 155): termination of the RAN 105 CP interface (N2), termination of the NAS (N1), NAS encryption and integrity protection, registration management, connection management, reachability management, mobility management, lawful interception (for AMF155 events and the interface with the LI system), providing transport for session management, SM messages between the UE 100 and the SMF 160, transparent proxy for routing SM messages, access authentication, access authorization, providing transport for SMS messages between the UE 100 and the SMSF, security anchor function, SEA, interaction with the AUSF 150 and the UE 100, receiving the intermediate key established as a result of the UE 100 authentication process, security context management SCM for receiving the key for deriving the access network specific key from the SEA, and so on.
[0113] In an example, the AMF 155 may support non-3GPP access networks via the N2 interface with the N3IWF 170, support NAS signaling with the UE 100 via the N3IWF 170, support authentication of the UE connected via the N3IWF 170, mobility management, authentication, and separate security context states for the UE 100 connected via non-3GPP access 165 or simultaneously connected via 3GPP access 105 and non-3GPP access 165, support coordinated RM context valid for both 3GPP access 105 and non-3GPP access 165, support CM management context for the UE 100 for connectivity via non-3GPP access, and so on.
[0114] In an example, the AMF 155 area may include one or more AMF 155 sets. An AMF 155 set may include some AMF 155s serving a given area and / or network slice. In an example, multiple AMF 155 sets may be for each AMF 155 area and / or network slice. An application identifier may be an identifier that can be mapped to a specific application traffic detection rule. The configured NSSAI may be the NSSAI that can be provided in the UE 100. For a DNN, the DN 115 access identifier (DNAI) may be an identifier for the user plane to access the DN 115. The initial registration may be related to the registration of the UE 100 in the RM-DEREGISTERED (RM-deregistered) states 500, 520. The N2AP UE 100 association may be a logical association between the 5G AN node and the AMF 155 according to the UE 100. The N2AP UE-TNLA combination may be a combination between the N2AP UE 100 association and the TNL association of a specific transport network layer for a given UE 100.
[0115] In an example, the session management function SMF 160 may include one or more of the following functions (one or more of the SMF 160 functions may be supported in a single instance of the SMF 160): session management (e.g., session establishment, modification, and release, including tunnel maintenance between the UPF 110 and the AN 105 node), UE 100 IP address allocation and management (including optional authorization), selection and control of the UP function, configuration of traffic steering at the UPF 110 to route traffic to an appropriate destination, termination of the interface for the policy control function, control of part of the policy enforcement and QoS, lawful interception (for SM events and the interface with the LI system), termination of the SM part of the NAS message, downlink data notification, initiation of AN-specific SM information, sent to the (R)AN 105 via the AMF 155 through N2, determination of the SSC mode of the session, roaming function, handling of local enforcement to apply the QoS SLA (VPLMN), charging data collection and charging interface (VPLMN), lawful interception (in the VPLMN, for SM events and the interface with the LI system), support for interaction with the external DN 115 to transmit signaling for PDU session authorization / authentication by the external DN 115, and so on.
[0116] In an example, the User Plane Function (UPF) 110 may include one or more of the following functions (some of the UPF 110 functions may be supported in a single instance of the UPF 110): an anchor point for RAT-in / RAT-out mobility (if applicable), an external PDU session point interconnected to the DN 115, packet routing and forwarding, packet inspection and the user plane part of policy rule enforcement, lawful interception (UP collection), traffic usage reporting, an uplink classifier that supports routing traffic flows for a data network, a branching point that supports multi-homed PDU sessions, QoS handling for the user plane, uplink traffic verification (SDF to QoS flow mapping), transport-level packet marking in the uplink and downlink, downlink packet buffering, downlink data notification triggering, and so on.
[0117] In an example, the UE 100 IP address management may include the allocation and release of the UE 100 IP address and / or the update of the allocated IP address. The UE 100 may set the requested PDU type during the PDU session establishment procedure based on its IP stack capabilities and / or configuration. In an example, the SMF 160 may select the PDU type of the PDU session. In an example, if the SMF 160 receives a request with the PDU type set to IP, the SMF 160 may select the PDU type as IPv4 or IPv6 based on the DNN configuration and / or operator policy. In an example, the SMF 160 may provide a cause value to the UE 100 to indicate whether other IP versions are supported on the DNN. In an example, if the SMF 160 receives a request with the PDU type as IPv4 or IPv6 and the requested IP version is supported by the DNN, the SMF 160 may select the requested PDU type.
[0118] In an exemplary implementation, the 5GC elements and the UE 100 may support the following mechanisms: During the PDU session establishment procedure, the SMF 160 may send the IP address to the UE 100 via SM NAS signaling. Once the PDU session can be established, IPv4 address allocation and / or IPv4 parameter configuration via DHCPv4 may be used. If IPv6 is supported, IPv6 prefix allocation may be supported via IPv6 stateless autoconfiguration. In an example, the 5GC network elements may support IPv6 parameter configuration via stateless DHCPv6.
[0119] The 5GC may support the allocation of static IPv4 addresses and / or static IPv6 prefixes based on the subscription information in the UDM 140 and / or based on the configuration on a per-subscriber, per-DNN basis.
[0120] The User Plane Function (UPF 110) can handle the user plane path of a PDU session. The UPF 110 that provides an interface to the data network can support the function of the PDU session anchor.
[0121] In the example, the Policy Control Function PCF 135 can support a unified policy framework to control network behavior, provide policy rules for control plane functions to enforce policy rules, implement a front end to access subscription information related to policy decisions in the User Data Repository (UDR), and so on.
[0122] The Network Exposure Function NEF 125 can provide a means to securely expose the services and capabilities provided by 3GPP network functions, translate between the information exchanged with the AF 145 and the information exchanged with internal network functions, receive information from other network functions, and so on.
[0123] In the example, the Network Repository Function NRF 130 can support a service discovery function that can receive NF discovery requests from NF instances, provide information about the discovered NF instances (to be discovered) to NF instances, and maintain information about available NF instances and the services they support, and so on.
[0124] In the example, the NSSF 120 can select a set of network slice instances serving the UE 100 and can determine the allowed NSSAI. In the example, the NSSF 120 can determine the set of AMF 155 to be used to serve the UE 100, and / or based on the configuration, determine a list of candidate AMF 155 by querying the NRF 130.
[0125] In the example, the data stored in the UDR can include at least user subscription data, including at least subscription identifiers, security credentials, access and mobility related subscription data, session related subscription data, policy data, and so on.
[0126] In the example, the AUSF 150 can support the Authentication Server Function (AUSF 150).
[0127] In the example, the Application Function (AF) AF 145 can interact with the 3GPP core network to provide services. In the example, based on the operator deployment, the application function can be trusted by the operator to directly interact with relevant network functions. The application function that the operator does not allow to directly access network functions can use an external exposure framework (e.g., via the NEF 125) to interact with relevant network functions.
[0128] In an example, the control plane interface between the (R)AN 105 and the 5G Core can support connecting multiple different types of ANs (e.g., 3GPP RAN 105, N3IWF 170 for untrusted access 165) to the 5GC via a control plane protocol. In an example, the N2 AP protocol can be used for both 3GPP access 105 and non-3GPP access 165. In an example, the control plane interface between the (R)AN 105 and the 5G Core can support decoupling between the AMF 155 and other functions (such as the SMF 160) that may need to control services supported by the AN (e.g., control of UP resources in the AN 105 for a PDU session).
[0129] In an example, the 5GC can provide policy information from the PCF 135 to the UE 100. In an example, the policy information can include: access network discovery and selection policy, UE 100 routing selection policy (URSP), SSC mode selection policy (SSCMSP), network slice selection policy (NSSP), DNN selection policy, non-seamless offloading policy, etc.
[0130] In an example, as depicted in Figure 5A and Figure 5B the Registration Management RM can be used to register or deregister the UE / user 100 in the network and establish a user context in the network. Connection Management can be used to establish and release a signaling connection between the UE 100 and the AMF 155.
[0131] In an example, the UE 100 can register on the network to receive services for which registration is requested. In an example, the UE 100 can update its registration on the network periodically to maintain reachability (periodic registration update), or update when moving (e.g., mobile registration update), or update its capabilities or renegotiate protocol parameters.
[0132] In an example, as depicted in example Figure 8 and Figure 9 the initial registration procedure may involve performing network access control functions (e.g., user authentication and access authorization based on the subscription profile in the UDM 140). Example Figure 9 is Figure 8 a continuation of the initial registration procedure depicted in. Due to the initial registration procedure, the identity of the service AMF 155 can be registered in the UDM 140.
[0133] In an example, the Registration Management RM procedure can be applied on both 3GPP access 105 and non-3GPP access 165.
[0134] Example Figure 5AIt can depict the RM state of the UE 100 as observed by the UE 100 and the AMF 155. In an exemplary embodiment, two RM states that can reflect the registration state of the UE 100 in the selected PLMN can be adopted in the UE 100 and the AMF 155: RM-DEREGISTERED 500 and RM-REGISTERED (RM-Registration) 510. In the example, in the RM-DEREGISTERED state 500, the UE 100 may not be registered in the network. The UE 100 context in the AMF 155 may not maintain the valid location or routing information of the UE 100, so the UE 100 may not be reachable through the AMF 155. In the example, the UE 100 context can be stored in the UE 100 and the AMF 155. In the example, in the RM REGISTERED state 510, the UE 100 can be registered on the network. In the RM-REGISTERED 510 state, the UE 100 can receive services that may require registration on the network.
[0135] In an exemplary embodiment, two RM states that can reflect the registration state of the UE 100 in the selected PLMN can be adopted in the AMF 155 for the UE 100: RM-DEREGISTERED 520 and RM-REGISTERED 530.
[0136] As shown in the example Figure 6A and Figure 6B depicted, the connection management CM can include establishing and releasing a signaling connection between the UE 100 and the AMF 155 through the N1 interface. The signaling connection can be used to implement NAS signaling exchange between the UE 100 and the core network. The signaling connection between the UE 100 and the AMF 155 can include both an AN signaling connection between the UE 100 and the (R)AN 105 (e.g., an RRC connection through 3GPP access) and the N2 connection of the UE 100 between the AN and the AMF 155. In the example, the signaling connection can be an N1 signaling connection. In the example, the signaling connection can be an N1 NAS signaling connection.
[0137] As shown in the example Figure 6A and Figure 6BAs depicted, for the NAS signaling connection between UE 100 and AMF 155, two CM states can be adopted, namely CM-IDLE (CM-Idle) 600, 620 and CM-CONNECTED (CM-Connected) 610, 630. The UE 100 in the CM-IDLE 600 state can be in the RM-REGISTERED 510 state and may not have a NAS signaling connection established with the AMF 155 via N1. The UE 100 in the CM-IDLE 600 state can be in the RRC idle state. The UE 100 can perform cell selection, cell reselection, PLMN selection, and so on. The UE 100 in the CM-CONNECTED 610 state can have a NAS signaling connection with the AMF 155 via N1. In the example, the UE 100 in the CM-CONNTED 610 state can be in the RRC connected state. The UE 100 in the CM-CONNTECTED 610 state can be in the RRC inactive state. In the example, the CM state in the AMF and the CM state in the UE can be different. This may be the case when a local state change occurs without a clear signaling procedure (e.g., UE context release procedure) between the UE and the AMF. In the example, the RRC state in the UE (e.g., wireless device) and the RRC state in the base station (e.g., gNB, eNB) can be different. This may be the case when a local state change occurs without a clear signaling procedure (e.g., RRC release procedure) between the UE and the base station.
[0138] In an exemplary implementation, for the UE 100 at the AMF 155, two CM states can be adopted, namely CM-IDLE 620 and CM-CONNECTED 630.
[0139] In the example, the RRC inactive state can be applied to the NG-RAN (e.g., it can be applied to NR and E-UTRA connected to the 5G CN). Based on the network configuration, the AMF 155 can provide auxiliary information to the NG RAN 105 to assist the NG RAN 105 in making a decision on whether the UE 100 can be sent to the RRC inactive state. When the UE 100 is in the CM-CONNECTED 610 in the RRC inactive state, the UE 100 can continue the RRC connection as a response to the paging by the RAN 105 due to uplink data pending, mobility-initiated signaling procedures, to notify the network that it has left the RAN 105 notification area, and so on.
[0140] In an example, NAS signaling connection management may include establishing and releasing NAS signaling connections. The NAS signaling connection establishment function may be provided by UE 100 and AMF 155 to establish a NAS signaling connection for UE 100 in the CM-IDLE 600 state. The procedure for releasing the NAS signaling connection may be initiated by the 5G(R)AN 105 node or AMF 155.
[0141] In an example, reachability management of UE 100 may detect whether UE 100 is reachable and may provide the UE 100 location (e.g., access node) to the network to reach UE 100. Reachability management may be accomplished by paging based on UE 100 and UE 100 location tracking. UE 100 location tracking may include both UE 100 registration area tracking and UE 100 reachability tracking. During the registration and registration update procedures, UE 100 and AMF 155 may negotiate UE100 reachability characteristics in the CM-IDLE 600, 620 states.
[0142] In an example, for the CM-IDLE 600, 620 states, two UE100 reachability classes may be negotiated between UE 100 and AMF 155. 1) When UE 100 is in the CM-IDLE 600 mode, UE 100 reachability allows the mobile device to terminate data. 2) The mobile-initiated connection (MICO) mode. 5GC may support PDU connection services that provide PDU exchange between UE100 and a data network identified by a DNN. The PDU connection service may be supported via a PDU session established according to the request of UE 100.
[0143] In an example, a PDU session may support one or more PDU session types. A PDU session may be established (e.g., according to a UE 100 request), modified (e.g., according to UE 100 and 5GC requests), and / or released (e.g., according to UE 100 and 5GC requests) using NAS SM signaling exchanged via N1 between UE 100 and SMF160. 5GC is capable of triggering a specific application in UE 100 according to a request from an application server. When receiving the trigger, UE 100 may send it to the identified application in UE 100. The identified application in UE 100 may establish a PDU session for a specific DNN.
[0144] In an example, the 5G QoS model may support as in the example Figure 7The QoS flow-based framework depicted in. The 5G QoS model can support both QoS flows that require guaranteed flow bitrates and QoS flows that do not require guaranteed flow bitrates. In an example, the 5G QoS model can support reflective QoS. The QoS model can include flow mapping or packet marking at the UPF 110(CN_UP)110, AN 105, and / or UE 100. In an example, packets can arrive at and / or be destined for the application / service layer 730 from the UE 100, UPF 110(CN_UP)110, and / or AF 145.
[0145] In an example, a QoS flow can be the granularity of QoS differentiation within a PDU session. The QoS flow ID, QFI can be used to identify QoS flows in the 5G system. In an example, user plane traffic with the same QFI within a PDU session can receive the same traffic forwarding treatment. The QFI can be carried in the encapsulation header on N3 and / or N9 (e.g., without changing the end-to-end packet header). In an example, the QFI can be applied to PDUs with different types of payloads. The QFI can be unique within a PDU session.
[0146] In an example, when a PDU session is established, a QoS flow is established, or when the user plane is activated each time using NG-RAN, the QoS parameters of the QoS flow can be provided to the (R)AN 105 as a QoS profile via N2. In an example, each PDU session may require a default QoS rule. The SMF 160 can allocate a QFI for the QoS flow and can derive the QoS parameters from the information provided by the PCF 135. In an example, the SMF 160 can provide the QFI and a QoS profile containing the QoS parameters of the QoS flow to the (R)AN 105.
[0147] In an example, a 5G QoS flow can be the granularity for QoS forwarding processing in the 5G system. Traffic mapped to the same 5G QoS flow can receive the same forwarding treatment (e.g., scheduling policy, queue management policy, rate-making policy, RLC configuration, etc.). In an example, providing different QoS forwarding treatments may require separate 5G QoS flows.
[0148] In an example, the 5G QoS indicator can be a scalar that can be used as a reference for a specific QoS forwarding behavior (e.g., packet loss rate, packet delay budget) to be provided to a 5G QoS flow. In an example, the 5G QoS indicator can be implemented in the access network by 5QI reference node-specific parameters (e.g., scheduling weight, admission threshold, queue management threshold, link layer protocol configuration, etc.) that can control the QoS forwarding processing.
[0149] In an example, edge computing can provide computing and storage resources with sufficient connectivity near the device generating traffic.
[0150] In an example, the 5GC can support edge computing and enable operators and third-party services to be hosted near the attachment access point of the UE. The 5G core network can select a UPF 110 close to the UE 100 and perform traffic steering from the UPF 110 to the local data network via the N6 interface. In an example, the selection and traffic steering can be based on the subscription data of the UE 100, the location of the UE 100, information from the application function AF 145, policies, other relevant traffic rules, and so on. In an example, the 5G core network can expose network information and capabilities to the edge computing application function. The functional support for edge computing can include: local routing, where the 5G core network can select a UPF 110 to route user traffic to the local data network; traffic steering, where the 5G core network can select the traffic to be routed to an application in the local data network; session and service continuity to enable UE100 and application mobility; user plane selection and reselection, for example, based on an input from the application function; network capability openness, where the 5G core network and the application function can provide information to each other via the NEf 125; QoS and charging, where the PCF 135 can provide QoS control and charging rules for the traffic routed to the local data network; support for the local area data network, where the 5G core network can provide support for connecting to the LADN in a specific area where the application is deployed; and so on.
[0151] An example 5G system can be a 3GPP system including a 5G access network 105, a 5G core network, and the UE 100, etc. The allowed NSSAI can be the NSSAI provided by the serving PLMN during, for example, the registration procedure, indicating the network-allowed NSSAI of the UE 100 in the serving PLMN of the current registration area.
[0152] In an example, the PDU connection service can provide the exchange of PDUs between the UE 100 and the data network. A PDU session can be an association between the UE 100 and the data network DN 115 that can provide the PDU connection service. The type of the association can be IP, Ethernet, and / or unstructured.
[0153] Establishing a user plane connection to the data network via a network slice instance can include the following: performing an RM procedure to select an AMF 155 that supports the required network slice, and establishing the number of one or more PDU sessions to the required data network via the network slice instance.
[0154] In an example, the network slice set of the UE 100 can change at any time when the UE 100 can register on the network, and can be initiated by the network or the UE 100.
[0155] In an example, the periodic registration update can be that the UE 100 re-registers when the periodic registration timer expires. The requested NSSAI can be the NSSAI that the UE 100 can provide to the network.
[0156] In an example, the service-based interface can represent the way in which a set of services can be provided / exposed by a given NF.
[0157] In an example, service continuity can be an uninterrupted user experience of a service, including cases where the IP address and / or the anchor point can change. In an example, session continuity can refer to the continuity of a PDU session. For an IP type of PDU session, session continuity can imply that the IP address is reserved during the lifetime of the PDU session. The uplink classifier can be a UPF 110 function that is designed to direct uplink traffic to the data network DN 115 based on filter rules provided by the SMF 160.
[0158] In an example, the 5G system architecture can support data connections and services such that the deployment can use technologies such as network function virtualization and / or software-defined networking. The 5G system architecture can utilize service-based interactions between the identified control plane (CP) network functions. In the 5G system architecture, it can be considered to separate the user plane (UP) functions from the control plane functions. If needed, the 5G system can enable network functions to directly interact with other NFs.
[0159] In an example, the 5G system can reduce the dependency between the access network (AN) and the core network (CN). The architecture can include an aggregated access agnostic core network having a common AN-CN interface, which can integrate different 3GPP and non-3GPP access types.
[0160] In an example, the 5G system can support a unified authentication framework, stateless NFs with separation of computing resources and storage resources, capability openness, and simultaneous access to local services and centralized services. To support low-latency services and access to local data networks, the UP functions can be deployed close to the access network.
[0161] In an example, the 5G system can support roaming by utilizing home routed traffic and / or local breakout traffic in the visited PLMN. An example 5G architecture can be service-based, and the interactions between network functions can be represented in two ways. (1) As a service-based representation (in the exemplary Figure 1depicted in Figure [x], where the network functions in the control plane can enable other authorized network functions to access their services. When necessary, this representation may also include point-to-point reference points. (2) As a reference point representation, it shows the interaction between NF services in network functions described by point-to-point reference points (e.g., N11) between any two network functions.
[0162] In an example, a network slice may include a core network control plane and user plane network functions, a 5G radio access network; the functions of the N3IWF for non-3GPP access networks, etc. The network slices can be different for supported features and network function implementations. An operator may deploy multiple network slice instances that carry the same features but are used for different groups of UEs, e.g., when they carry different promised services and / or because they can be dedicated to customers. The NSSF 120 may store mapping information between the slice instance ID and the NF ID (or NF address).
[0163] In an example, the UE 100 may be served by one or more network slice instances via the 5G-AN simultaneously. In an example, the UE 100 may be served by k network slices at a time (e.g., k = 8, 16, etc.). Logically, the AMF 155 instance serving the UE 100 may belong to the network slice instance serving the UE 100.
[0164] In an example, for each PLMN, a PDU session may belong to a specific network slice instance. In an example, different network slice instances may not share a PDU session. Different slices may have slice-specific PDU sessions using the same DNN.
[0165] The S-NSSAI (Single Network Slice Selection Assistance Information) may identify a network slice. The S-NSSAI may include: a slice / service type (SST), which may refer to the expected behavior of the network slice in terms of features and services; and / or a slice differentiator (SD). The slice differentiator may be optional information that may supplement the slice / service type to allow further differentiation to select a network slice instance from potentially multiple network slice instances that conform to the indicated slice / service type. In an example, the same network slice instance with different S-NSSAIs may be selected. The CN part of the network slice instance serving the UE 100 may be selected by the CN.
[0166] In an example, the subscription data may include the S-NSSAI of the network slices subscribed by the UE 100. One or more S-NSSAIs may be marked as the default S-NSSAI. In an example, k S-NSSAIs may be marked as the default S-NSSAI (e.g., k = 8, 16, etc.). In an example, the UE 100 may subscribe to more than 8 S-NSSAIs.
[0167] In the example, the UE 100 can be configured by the HPLMN, and each PLMN is configured with an NSSAI. After successfully completing the UE registration procedure, the UE 100 can obtain the Allowed NSSAI of this PLMN from the AMF 155, which can include one or more S-NSSAIs.
[0168] In the example, the Allowed NSSAI of the PLMN can take precedence over the configured NSSAI. The UE 100 can use the S-NSSAI corresponding to the network slice for subsequent network slice selection related procedures in the serving PLMN in the Allowed NSSAI.
[0169] In the example, establishing a user plane connection to the data network via a network slice instance can include: performing an RM procedure to select the AMF 155 that can support the required network slice, establishing the number of one or more PDU sessions to the required data network via the network slice instance, and so on.
[0170] In the example, when the UE 100 registers with the PLMN, if the UE 100 has a configured NSSAI or an Allowed NSSAI for the PLMN, the UE 100 can provide the requested NSSAI (the requested NSSAI includes the S-NSSAI corresponding to the slice that the UE 100 attempts to register for), a temporary user ID (if a temporary user ID is assigned to the UE), and so on, to the network and NAS layers in the RRC. The requested NSSAI can be the configured NSSAI, the Allowed NSSAI, and so on.
[0171] In the example, when the UE 100 registers with the PLMN, if the UE 100 does not have a configured NSSAI or an Allowed NSSAI for the PLMN, the RAN 105 can route the NAS signaling from the UE 100 to the default AMF 155 / route the NAS signaling from the default AMF to the UE.
[0172] In the example, based on local policies, subscription changes, and / or UE 100 mobility, the network can change the set of permitted network slices that the UE 100 is registered to. In the example, the network can perform the change during the registration procedure, or use an RM procedure (which can trigger the registration procedure) to trigger a notification of the change of the supported network slices to the UE 100. The network can provide the UE 100 with a new Allowed NSSAI and a tracking area list.
[0173] In the example, during the registration procedure in a PLMN, if the network decides, based on network slice aspects, that the UE 100 should be served by a different AMF 155, the AMF 155 that first receives the registration request may redirect the registration request to another AMF 155 via the RAN 105 or via direct signaling between the initial AMF 155 and the target AMF 155.
[0174] In the example, the network operator may provide the UE 100 with a Network Slice Selection Policy (NSSP). The NSSP may include one or more NSSP rules.
[0175] In the example, if the UE 100 has one or more PDU sessions established corresponding to a specific S-NSSAI, the UE 100 may route the user data of the application in one PDU session, unless other conditions in the UE 100 prohibit the use of the PDU session. If the application provides a DNN, the UE 100 may consider the DNN to determine which PDU session to use. In the example, if the UE 100 does not have a PDU session established with a specific S-NSSAI, the UE 100 may request a new PDU session corresponding to the S-NSSAI and having a DNN that may be provided by the application. In the example, in order for the RAN 105 to select appropriate resources for supporting the network slice in the RAN 105, the RAN 105 may know the network slice used by the UE 100.
[0176] In the example, when the UE 100 triggers the establishment of a PDU session, the AMF 155 may select the SMF 160 in the network slice instance based on the S-NSSAI, DNN, and / or other information (such as UE 100 subscription and local operator policies, etc.). The selected SMF 160 may establish the PDU session based on the S-NSSAI and DNN.
[0177] In the example, to support network control privacy of the slice information of the slices that the UE 100 can access, when the UE 100 realizes or is configured such that privacy considerations are applicable to the NSSAI, the UE 100 may not include the NSSAI in the NAS signaling, unless the UE 100 has a NAS security context, and the UE 100 may not include the NSSAI in the unprotected RRC signaling.
[0178] In the example, for a roaming scenario, during the establishment of a PDU connection, network slice-specific network functions can be selected in the VPLMN and HPLMN based on the S-NSSAI provided by the UE 100. If a standardized S-NSSAI is used, the selection of slice-specific NF instances can be performed by each PLMN based on the provided S-NSSAI. In the example, the VPLMN can map the S-NSSAI of the HPLMN to the S-NSSAI of the VPLMN based on a roaming protocol (e.g., including mapping to the default S-NSSAI of the VPLMN). In the example, the selection of slice-specific NF instances can be performed in the VPLMN based on the S-NSSAI of the VPLMN. In the example, any slice-specific NF instance in the HPLMN can be selected based on the S-NSSAI of the HPLMN.
[0179] As depicted in the example Figure 8 and Figure 9 the UE 100 can execute a registration procedure to obtain authorization for receiving services, to enable mobile tracking, to achieve reachability, etc.
[0180] In an example, the UE 100 may send a message 805 to the (R)AN 105 (including AN parameters, RM-NAS registration request (registration type, SUCI or SUPI or 5G-GUTI, last visited TAI (if available), security parameters, requested NSSAI, mapping of the requested NSSAI, UE 100 5GC capabilities, PDU session state, PDU sessions to be reactivated, subsequent requests, MICO mode preference, etc.) etc.). In an example, in the case of the NG-RAN, the AN parameters may include, for example, SUCI or SUPI or 5G-GUTI, the selected PLMN ID, and the requested NSSAI, etc. In an example, the AN parameters may include a cause for establishment. The cause for establishment may provide the reason for requesting the establishment of an RRC connection. In an example, the registration type may indicate whether the UE 100 is to perform an initial registration (i.e., the UE 100 is in the RM-DEREGISTERED state), a mobility registration update (e.g., the UE 100 is in the RM-REGISTERED state and initiates a registration procedure due to mobility), a periodic registration update (e.g., the UE 100 is in the RM-REGISTERED state and may start a registration procedure due to the expiration of a periodic registration update timer), or an emergency registration (e.g., the UE 100 is in a limited service state). In an example, if the UE 100 performs an initial registration with a PLMN for which the UE 100 does not yet have a 5G-GUTI (i.e., the UE 100 is in the RM-DEREGISTERED state), the UE 100 may include its SUCI or SUPI in the registration request. If the home network has provided a public key to protect the SUPI in the UE, the SUCI may be included. If the UE 100 receives a UE 100 configuration update command indicating that the UE 100 needs to re-register and the 5G-GUTI is invalid, the UE 100 may perform an initial registration and may include the SUPI in the registration request message. For an emergency registration, if the UE 100 does not have an available valid 5G-GUTI, the SUPI may be included; when the UE 100 does not have a SUPI and does not have a valid 5G-GUTI, the PEI may be included. In other cases, the 5G-GUTI may be included, and it may indicate the last serving AMF 155. If the UE 100 has registered via non-3GPP access in a PLMN that is different from the 3GPP access in a new PLMN (e.g., not the registered PLMN or an equivalent PLMN of the registered PLMN), during the registration procedure via non-3GPP access, the UE 100 may not provide the 5G-GUTI assigned by the AMF 155 via 3GPP access.If the UE 100 has registered in a PLMN (e.g., a registered PLMN) that is different from the non-3GPP access in a new PLMN (e.g., not the registered PLMN or an equivalent PLMN of the registered PLMN) via 3GPP access, during the registration procedure via 3GPP access, the UE 100 may not provide the 5G-GUTI assigned by the AMF 155 via non-3GPP access. The UE 100 may provide the usage settings of the UE based on its configuration. In the case of initial registration or mobile registration update, the UE 100 may include a mapping of the requested NSSAI, which may be a mapping of each S-NSSAI in the requested NSSAI of the HPLMN to the S-NSSAI in the configured NSSAI, to ensure that the network can verify whether the S-NSSAI in the requested NSSAI is allowed based on the subscribed S-NSSAI. If available, the last visited TAI may be included to assist the AMF 155 in generating the registration area of the UE. In the example, security parameters may be used for authentication and integrity protection. The requested NSSAI may indicate network slice selection assistance information. The PDU session state may indicate the previously established PDU sessions in the UE. When the UE 100 is connected to two AMF 155s belonging to different PLMNs via 3GPP access and non-3GPP access, the PDU session state may indicate the PDU sessions established in the UE for the current PLMN. The PDU sessions to be reactivated may be included to indicate the PDU sessions for which the UE 100 may intend to activate the UP connection. When the UE 100 is outside the available area of the LADN, the PDU session corresponding to the LADN may not be included in the PDU sessions to be reactivated. When the UE 100 may have outstanding uplink signaling and the UE 100 may not include the PDU sessions to be reactivated, subsequent requests may be included, or the registration type may indicate that the UE 100 may need to perform an emergency registration.
[0181] In the example, if including the SUPI or 5G-GUTI does not indicate a valid AMF 155, based on the (R)AT and the requested NSSAI (if available), the (R)AN 105 may select an AMF 155. If the UE 100 is in the CM-CONNECTED state, the (R)AN 105 may forward the registration request message to the AMF 155 based on the N2 connection of the UE. If the (R)AN 105 cannot select an appropriate AMF 155, it may forward the registration request to the AMF 155 that has been configured in the (R)AN 105 to perform AMF 155 selection.
[0182] In the example, (R)AN 105 may send an N2 message 810 (including: N2 parameters, RM-NAS registration request (registration type, SUPI or 5G-GUTI, last visited TAI (if available), security parameters, requested NSSAI, mapping of the requested NSSAI, UE 100 5GC capabilities, PDU session status, PDU sessions to be reactivated, subsequent requests, and MICO mode preference), etc.) to the new AMF 155. In the example, when using NG-RAN, the N2 parameters may include the selected PLMN ID, location information, cell identity, and the RAT type related to the cell where the UE 100 is located. In the example, when using NG-RAN, the N2 parameters may include the establishment cause.
[0183] In the example, the new AMF 155 may send a Namf_Communication_UEContextTransfer (complete registration request) 815 to the old AMF 155. In the example, if the 5G-GUTI of the UE is included in the registration request and the serving AMF 155 has changed since the last registration procedure, the new AMF 155 may invoke the Namf_Communication_UEContextTransfer service operation 815 (including the complete registration request IE that may be integrity protected) on the old AMF 155 to request the SUPI and MM context of the UE. The old AMF 155 may use the integrity protected complete registration request IE to verify whether the context transfer service operation invocation corresponds to the requested UE 100. In the example, the old AMF 155 may transfer the event subscription information of each NF consumer for the UE to the new AMF 155. In the example, if the UE 100 identifies itself with the PEI, the SUPI request may be skipped.
[0184] In an example, the old AMF 155 may send a response 815 (SUPI, MM context, SMF 160 information, PCF ID) of Namf_Communication_UEContextTransfer to the new AMF 155. In an example, the old AMF 155 may respond to the new AMF 155 that invokes Namf_Communication_UEContextTransfer by including the SUPI and MM context of the UE. In an example, if the old AMF 155 maintains information about the established PDU session, the old AMF 155 may include SMF 160 information, including S-NSSAI, SMF 160 identity, and PDU session ID. In an example, if the old AMF 155 maintains information about the active NGAP UE-TNLA to the N3IWF, the old AMF 155 may include information about the NGAP UE-TNLA binding.
[0185] In an example, if the SUPI is not provided by the UE 100 or retrieved from the old AMF 155, the identity request procedure 820 may be initiated by the AMF 155 sending an identity request message to the UE 100 that requests the SUCI.
[0186] In an example, the UE 100 may respond with an identity response message 820 that includes the SUCI. The UE 100 may derive the SUCI by using the public key of the provided HPLMN.
[0187] In an example, the AMF 155 may decide to initiate UE 100 authentication 825 by invoking the AUSF 150. The AMF 155 may select the AUSF 150 based on the SUPI or SUCI. In an example, if the AMF 155 is configured to support emergency registration with an unauthenticated SUPI and the registration type indicated by the UE 100 is emergency registration, the AMF 155 may skip authentication and security settings, or the AMF 155 may accept that the authentication may fail and may continue the registration procedure.
[0188] In the example, the authentication 830 can be performed by the Nudm_UEAuthenticate_Get operation. The AUSF 150 can discover the UDM 140. If the AMF 155 provides the SUCI to the AUSF 150, the AUSF 150 can return the SUPI to the AMF 155 after successful authentication. In the example, if a network slice is used, the AMF 155 can decide whether to reroute the registration request in the case where the initial AMF 155 refers to the AMF 155. In the example, the AMF 155 can initiate the NAS security function. In the example, when the NAS security function setup is completed, the AMF 155 can start the NGAP procedure so that the 5G-AN can use it to protect the procedure with the UE. In the example, the 5G-AN can store the security context and can confirm it to the AMF 155. The 5G-AN can use the security context to protect the messages exchanged with the UE.
[0189] In the example, the new AMF 155 can send a Namf_Communication_RegistrationCompleteNotify 835 to the old AMF 155. If the AMF 155 has changed, the new AMF 155 can notify the old AMF155 that the registration of the UE100 in the new AMF 155 can be completed by invoking the Namf_Communication_RegistrationCompleteNotify service operation. If the authentication / security procedure fails, the registration can be rejected, and the new AMF 155 can invoke the Namf_Communication_RegistrationCompleteNotify service operation, where the rejection indication reason code is directed towards the old AMF 155. The old AMF 155 can continue as if it had never received the UE 100 context transfer service operation. If one or more of the S-NSSAIs used in the old registration area cannot be served in the target registration area, the new AMF 155 can determine which PDU sessions may not be supported in the new registration area. The new AMF 155 can invoke the Namf_Communication_RegistrationCompleteNotify service operation to the old AMF 155, including the rejected PDU session ID and the rejection reason (e.g., the S-NSSAI has become unavailable). The new AMF 155 can modify the PDU session state accordingly. The old AMF155 can notify the corresponding SMF 160 to locally release the SM context of the UE by invoking the Nsmf_PDUSession_ReleaseSMContext service operation.
[0190] In the example, the new AMF 155 may send an identity request / response 840 (e.g., PEI) to the UE 100. If the PEI is not provided by the UE 100 or retrieved from the old AMF 155, the identity request procedure may be initiated by the AMF 155 sending an identity request message to the UE 100 to retrieve the PEI. Unless the UE 100 performs an emergency registration, the PEI may be transmitted encrypted and may not be authenticated. For an emergency registration, the UE 100 may have included the PEI in the registration request.
[0191] In the example, the new AMF 155 may initiate an ME identity check 845 by invoking the N5g-eir_EquipmentIdentityCheck_Get service operation 845.
[0192] In the example, based on the SUPI, the new AMF 155 may select 905 the UDM 140. The UDM 140 may select a UDR instance. In the example, the AMF 155 may select the UDM 140.
[0193] In the example, if the AMF 155 has changed since the last registration procedure, or if the UE 100 provides a SUPI that may not reference a valid context in the AMF 155, or if the UE 100 is registered to the same AMF 155 and it has registered to a non-3GPP access (e.g., the UE 100 is registered via non-3GPP access and may initiate a registration procedure to add 3GPP access), the new AMF 155 may register with the UDM 140 using Nudm_UECM_Registration 910 and may subscribe to be notified by the UDM 140 when the UDM 140 may cancel the AMF 155 registration. The UDM 140 may store the AMF 155 identifier associated with the access type and may not delete the AMF 155 identifier associated with another access type. The UDM 140 may store the information provided when registering in the UDR by Nudr_UDM_Update. In the example, the AMF 155 may retrieve the access and mobility subscription data and the SMF 160 selection subscription data using Nudm_SDM_Get 915. The UDM 140 may retrieve this information (access and mobility subscription data) from the UDR via Nudr_UDM_Query. After receiving a successful response, the AMF 155 may subscribe to be notified using Nudm_SDM_Subscribe 920 when the requested data may be modified. The UDM 140 may subscribe to the UDR via Nudr_UDM_Subscribe. If the GPSI is available in the UE 100 subscription data, the GPSI may be provided from the UDM 140 to the AMF 155 in the subscription data. In the example, the new AMF 155 may provide the access type for which it serves the UE100 to the UDM 140, and the access type may be set to 3GPP access. The UDM 140 may store the associated access type together with the serving AMF 155 in the UDR via Nudr_UDM_Update. The new AMF 155 may create an MM context for the UE 100 after obtaining the mobile subscription data from the UDM 140. In the example, when the UDM 140 stores the associated access type together with the serving AMF 155, the UDM140 may initiate Nudm_UECM_DeregistrationNotification921 to the old AMF 155 corresponding to the 3GPP access. The old AMF 155 may remove the MM context of the UE. If the service NF deletion reason indicated by the UDM 140 is initial registration, the old AMF 155 may call the Namf_EventExposure_Notify service operation to all the associated SMF 160s of the UE 100 to notify the UE 100 to deregister from the old AMF 155. The SMF 160 may release the PDU session when obtaining this notification.In the example, the old AMF 155 can use Nudm_SDM_unsubscribe 922 to unsubscribe from the UDM 140 for subscription data.
[0194] In the example, if the AMF 155 decides to initiate PCF 135 communication, for example, if the AMF 155 has not obtained the access and mobility policy of the UE 100, or if the access and mobility policy in the AMF 155 is no longer valid, the AMF 155 can select 925 the PCF 135. If the new AMF 155 receives the PCF ID from the old AMF 155 and successfully contacts the PCF 135 identified by the PCF ID, the AMF 155 can select the (V-)PCF identified by the PCF ID. If the PCF 135 identified by the PCF ID may not be in use (for example, no response from the PCF 135), or if no PCF ID is received from the old AMF 155, the AMF 155 can select 925 the PCF 135.
[0195] In the example, the new AMF 155 can perform policy association establishment 930 during the registration procedure. If the new AMF 155 contacts the PCF 135 identified by the (V-)PCF ID received during the movement between AMFs, the new AMF 155 can include the PCF-ID in the Npcf_AMPolicyControl Get operation. If the AMF 155 notifies the PCF 135 of mobility restrictions (e.g., UE 100 location) for adjustment, or if the PCF 135 updates its own mobility restrictions due to certain conditions (e.g., applications in use, time, and date), the PCF 135 can provide the updated mobility restrictions to the AMF 155.
[0196] In the example, the PCF 135 can invoke the Namf_EventExposure_Subscribe service operation 935 for UE 100 event subscription.
[0197] In the example, the AMF 155 may send Nsmf_PDUSession_UpdateSMContext 936 to the SMF 160. In the example, if the PDU session to be reactivated is included in the registration request, the AMF 155 may invoke Nsmf_PDUSession_UpdateSMContext. The AMF 155 may send the Nsmf_PDUSession_UpdateSMContext request to the SMF 160 associated with the PDU session to activate the user plane connection of the PDU session. The SMF 160 may decide to trigger, for example, the insertion, removal, or change of the PSA by the intermediate UPF 110. In the case of performing the insertion, removal, or relocation of the intermediate UPF 110 for a PDU session not included in the PDU session to be reactivated, the procedure to update the N3 user plane between the (R)AN 105 and the 5GC may be performed without N11 and N2 interactions. The AMF 155 may invoke the Nsmf_PDUSession_ReleaseSMContext service operation to the SMF 160 when it indicates the release at the UE 100 in any PDU session state. The AMF 155 may invoke the Nsmf_PDUSession_ReleaseSMContext service operation to the SMF 160 to release any network resources related to the PDU session.
[0198] In the example, the new AMF 155 may send an N2 AMF 155 mobility request 940 to the N3IWF. If the AMF 155 has changed, the new AMF 155 may create an NGAP UE 100 association for the N3IWF connecting the UE 100. In the example, the N3IWF may respond to the new AMF 155 with an N2 AMF 155 mobility response 940.
[0199] In an example, the new AMF 155 may send a registration acceptance 955 to the UE 100 (including: 5G-GUTI, registration area, mobility restrictions, PDU session status, permitted NSSAI, [mapping of permitted NSSAI], periodic registration update timer, LADN information, and accepted MICO mode, indication of support for IMS voice via a PS session, emergency service support indicator, etc.). In an example, the AMF 155 may send a registration acceptance message indicating that the registration request has been accepted to the UE 100. If the AMF 155 allocates a new 5G-GUTI, the 5G-GUTI may be included. If the AMF 155 allocates a new registration area, it may send the registration area to the UE 100 via the registration acceptance message 955. If the registration area is not included in the registration acceptance message, the UE 100 may consider the old registration area valid. In an example, mobility restrictions may be included in cases where mobility restrictions are applicable to the UE 100 and the registration type may not be an emergency registration. The AMF 155 may indicate the established PDU sessions to the UE 100 in the PDU session status. The UE 100 may locally remove any internal resources related to PDU sessions not marked as established in the received PDU session status. In an example, when the UE 100 is connected to two AMF 155s belonging to different PLMNs via 3GPP access and non-3GPP access, the UE 100 may locally remove any internal resources related to the PDU sessions of the current PLMN that are not marked as established in the received PDU session status. If the PDU session status information is in the registration request, the AMF 155 may indicate the PDU session status to the UE. The mapping of the permitted NSSAI may be the mapping of each S-NSSAI in the permitted NSSAI of the HPLMN to the S-NSSAI in the configured NSSAI. The AMF 155 may include the LADN information of the LADN in the registration acceptance message 955, where the LADN is available within the registration area determined by the AMF 155 for the UE. If the UE100 includes the MICO mode in the request, the AMF 155 may respond as to whether the MICO mode can be used. The AMF 155 may set an indication of support for IMS voice via a PS session. In an example, to set an indication of support for IMS voice via a PS session, the AMF 155 may execute a UE / RAN radio information and compatibility request procedure to check the compatibility of the UE 100 and RAN radio capabilities related to IMS voice via a PS. In an example, the emergency service support indicator may notify the UE 100 of support for emergency services. For example, the UE 100 may request a PDU session for emergency services. In an example, the handover restriction list and UE-AMBR may be provided by the AMF 155 to the NG-RAN.
[0200] In an example, the UE 100 may send a registration complete 960 message to the new AMF 155. In an example, the UE 100 may send a registration complete message 960 to the AMF 155 to confirm that a new 5G-GUTI can be allocated. In an example, when information about a PDU session to be reactivated is not included in the registration request, the AMF 155 may release the signaling connection with the UE 100. In an example, when a follow-up request is included in the registration request, the AMF 155 may not release the signaling connection after the registration procedure is completed. In an example, if the AMF 155 realizes that some signaling is pending in the AMF 155 or between the UE 100 and the 5GC, the AMF 155 may not release the signaling connection after completing the registration procedure.
[0201] As depicted in the exemplary Figure 10 and Figure 11 As depicted, a service request procedure (e.g., a service request procedure triggered by the UE 100) may be used by the UE 100 in the CM-IDLE state to request the establishment of a secure connection to the AMF 155. Figure 11 is a continuation of the Figure 10 depicting the service request procedure. The service request procedure may be used to activate a user plane connection for an established PDU session. The service request procedure may be triggered by the UE 100 or the 5GC and may be used when the UE 100 is in CM-IDLE and / or CM-CONNECTED, and may allow for the selective activation of user plane connections for some established PDU sessions.
[0202] In an example, the UE 100 in the CM IDLE state may initiate a service request procedure to send uplink signaling messages, user data, etc., in response to a network paging request, etc. In an example, after receiving a service request message, the AMF 155 may perform authentication. In an example, after establishing a signaling connection to the AMF 155, the UE 100 or the network may send signaling messages such as PDU session establishment from the UE 100 to the SMF 160 via the AMF 155.
[0203] In an example, for any service request, the AMF 155 may respond with a service acceptance message to synchronize the PDU session state between the UE 100 and the network. If the service request may not be accepted by the network, the AMF 155 may respond to the UE 100 with a service rejection message. The service rejection message may include an indication or a cause code requesting the UE 100 to perform a registration update procedure. In an example, for a service request due to user data, if the activation of the user plane connection may not be successful, the network may take further actions. In an example Figure 10 andFigure 11 There may be more than one UPF involved, for example, the old UPF 110-2 and the PDU session anchor PSA UPF 110-3.
[0204] In the example, the UE 100 may send a message to the (R)AN 105, and the AN message includes AN parameters, mobility management, MM NAS service request 1005 (for example, a list of PDU sessions to be activated, a list of allowed PDU sessions, security parameters, PDU session status, etc.), and so on. In the example, when the UE 100 can reactivate a PDU session, the UE 100 may provide a list of PDU sessions to be activated. When the service request can be a response to paging or NAS notification, the list of allowed PDU sessions may be provided by the UE 100 and may identify the PDU sessions that can be transmitted to the access on which the service request can be sent or associated with the access. In the example, for the case of NG-RAN, the AN parameters may include the selected PLMN ID and the establishment cause. The establishment cause may provide the reason for requesting to establish an RRC connection. The UE 100 may send a NAS service request message for the AMF 155 encapsulated in the RRC message to the RAN 105.
[0205] In the example, if the service request can be triggered for user data, the UE 100 may use the list of PDU sessions to be activated to identify the PDU session for which the UP connection will be activated in the NAS service request message. If the service request can be triggered for signaling, the UE 100 may not be able to identify any PDU sessions. If this procedure can be triggered for a paging response, and / or the UE 100 may have user data to be transmitted simultaneously, the UE 100 may identify the PDU session for which the UP connection can be activated in the MM NAS service request message through the list of PDU sessions to be activated.
[0206] In the example, if the service request through 3GPP access can be triggered in response to paging indicating non-3GPP access, the NAS service request message may identify, in the list of allowed PDU sessions, the list of PDU sessions associated with the non-3GPP access that can be reactivated through 3GPP. In the example, the PDU session status may indicate the available PDU sessions in the UE 100. In the example, when the UE 100 may be outside the availability area of the LADN, the UE 100 may not trigger the service request procedure for the PDU session corresponding to the LADN. If the service request can be triggered for other reasons, the UE 100 may not be able to identify such PDU sessions in the list of PDU sessions to be activated.
[0207] In an example, (R)AN 105 may send an N2 message 1010 (e.g., a service request) including N2 parameters, an MM NAS service request, etc. to AMF 155. If AMF 155 may not be able to handle the service request, the N2 message may be rejected. In an example, if NG-RAN can be used, the N2 parameters may include 5G-GUTI, selected PLMN ID, location information, RAT type, establishment cause, etc. In an example, 5G-GUTI may be obtained in the RRC procedure, and (R)AN 105 may select AMF 155 based on the 5G-GUTI. In an example, the location information and RAT type may relate to the cell where UE 100 may camp. In an example, based on the PDU session state, AMF 155 may initiate a PDU session release procedure in the network for a PDU session whose PDU session ID may be indicated by UE 100 as unavailable.
[0208] In an example, if the service request is not sent with integrity protection or the integrity protection verification fails, AMF155 may initiate a NAS authentication / security procedure 1015.
[0209] In an example, if UE 100 triggers a service request to establish a signaling connection, after the signaling connection is successfully established, UE 100 and the network may exchange NAS signaling.
[0210] In an example, AMF 155 may send a PDU session update context request 1020 to SMF 160, e.g., an Nsmf_PDUSession_UpdateSMContext request including a PDU session ID, a cause, UE 100 location information, an access type, etc.
[0211] In an example, if UE 100 can identify the PDU session to be activated in the NAS service request message, the Nsmf_PDUSession_UpdateSMContext request may be invoked by AMF 155. In an example, the Nsmf_PDUSession_UpdateSMContext request may be triggered by SMF 160, where the PDU session identified by UE 100 may be associated with a PDU session ID other than the one that triggered this procedure. In an example, the Nsmf_PDUSession_UpdateSMContext request may be triggered by SMF 160, where during a network-triggered service request procedure, the current UE 100 location may be outside the valid area of the N2 information provided by SMF160. AMF 155 may not send the N2 information provided by SMF 160 during a network-triggered service request procedure.
[0212] In the example, the AMF 155 may determine the PDU session to be activated and may send an Nsmf_PDUSession_UpdateSMContext request to the SMF 160 associated with the PDU session, where the cause is set to indicate the establishment of the user plane resources of the PDU session.
[0213] In the example, if the procedure can be triggered in response to a paging indicating non-3GPP access and the list of permitted PDU sessions provided by the UE 100 may not include the PDU session for which the UE 100 has been paged, the AMF 155 may notify the SMF 160 that the user plane of the PDU session may not be reactivated. The service request procedure may succeed without reactivating the user plane of any PDU session, and the AMF 155 may notify the UE 100.
[0214] In the example, if the PDU session ID may correspond to the LADN and the SMF 160 may determine, based on the UE 100 location reported from the AMF 155, that the UE 100 may be outside the availability area of the LADN, the SMF 160 may decide (based on local policy) to keep the PDU session, may reject the activation of the user plane connection of the PDU session, and may notify the AMF 155. In the example, if the procedure can be triggered by a network-triggered service request, then the SMF 160 may notify the UPF 110 that initiated the data notification to discard the downlink data of the PDU session and / or not to provide additional data notification messages. The SMF 160 may respond to the AMF 155 with an appropriate rejection reason and may stop the user plane activation of the PDU session.
[0215] In the example, if the PDU session ID may correspond to the LADN and the SMF 160 may determine, based on the UE 100 location reported from the AMF 155, that the UE 100 may be outside the availability area of the LADN, the SMF 160 may decide (based on local policy) to release the PDU session. The SMF 160 may locally release the PDU session and may notify the AMF 155 that the PDU session may be released. The SMF 160 may respond to the AMF 155 with an appropriate rejection reason and may stop the user plane activation of the PDU session.
[0216] In an example, if the SMF 160 can accept the UP activation of the PDU session, based on the location information received from the AMF 155, the SMF 160 can check the UPF 110 selection 1025 criteria (e.g., slice isolation requirements, slice coexistence requirements, dynamic load of the UPF110, relative static capacity of the UPF110 among the UPFs supporting the same DNN, location of the UPF110 available at the SMF 160, UE 100 location information, capabilities of the UPF 110, and functions required for a specific UE 100 session. In the example, an appropriate UPF 110 can be selected by matching the functions and features required by the UE 100, DNN, PDU session type (e.g., IPv4, IPv6, Ethernet type, or unstructured type), and (if applicable) static IP address / prefix, SSC mode selected for the PDU session, UE 100 subscription profile in the UDM 140, DNAI included in the PCC rule, local operator policy, S-NSSAI, access technology used by the UE 100, UPF 110 logical topology, etc.), and can determine to perform one or more of the following: continue to use the current UPF; if the UE 100 has moved out of the service area of the UPF 110 previously connected to the (R)AN 105 while maintaining the UPF acting as the PDU session anchor, a new intermediate UPF 110 can be selected (or intermediate UPF110 can be added / removed); a re - establishment of the PDU session can be triggered to perform re - location / re - assignment of the UPF 110 acting as the PDU session anchor, e.g., the UE 100 has moved out of the service area of the anchor UPF 110 connected to the RAN 105.
[0217] In an example, the SMF 160 can send an N4 session establishment request 1030 to the UPF 110 (e.g., a new intermediate UPF 110). In the example, if the SMF 160 can select a new UPF 110 to act as the intermediate UPF 110 - 2 for the PDU session, or if the SMF 160 can select to insert an intermediate UPF 110 for a PDU session that may not have an intermediate UPF 110 - 2, an N4 session establishment request 1030 message can be sent to the new UPF 110, thereby providing packet detection, data forwarding, execution, and reporting rules to be installed on the new intermediate UPF. The PDU session anchor addressing information (on N9) for this PDU session can be provided to the intermediate UPF110 - 2.
[0218] In an example, if the SMF 160 selects a new UPF 110 to replace the old (intermediate) UPF 110 - 2, the SMF 160 can include a data forwarding indication. The data forwarding indication can indicate to the UPF 110 that a second tunnel endpoint can be reserved for buffered DL data from the old I - UPF.
[0219] In the example, the new UPF 110 (in the middle) can send an N4 session establishment response message 1030 to the SMF 160. In the case where the UPF 110 can allocate CN tunnel information, the UPF 110 can provide the SMF 160 with the DL CN tunnel information and the UL CN tunnel information (e.g., CN N3 tunnel information) of the UPF 110 that serves as the PDU session anchor. If a data forwarding indication can be received, the new (middle) UPF 110 serving as the N3 termination point can send the DL CN tunnel information of the old (middle) UPF 110-2 to the SMF 160. The SMF 160 can start a timer to release the resources in the old middle UPF 110-2.
[0220] In the example, if the SMF 160 can select a new middle UPF 110 for the PDU session or can remove the old I-UPF 110-2, the SMF 160 can send an N4 session modification request message 1035 to the PDU session anchor PSA UPF 110-3, thereby providing a data forwarding indication and DL tunnel information from the new middle UPF 110.
[0221] In the example, if a new middle UPF 110 can be added for the PDU session, the (PSA) UPF 110-3 can start sending DL data to the new I-UPF 110 as indicated by the DL tunnel information.
[0222] In the example, if a service request can be triggered by the network, and the SMF 160 can remove the old I-UPF 110-2 and can not replace the old I-UPF 110-2 with the new I-UPF 110, then the SMF 160 can include a data forwarding indication in the request. The data forwarding indication can indicate to the (PSA) UPF 110-3 that a second tunnel endpoint can be reserved for the buffered DL data from the old I-UPF 110-2. In this case, the PSA UPF 110-3 can start buffering the DL data that it may receive from the N6 interface simultaneously.
[0223] In the example, the PSA UPF 110-3 (PSA) can send an N4 session modification response 1035 to the SMF 160. In the example, if a data forwarding indication can be received, the PSA UPF 110-3 can become the N3 termination point and can send the CN DL tunnel information of the old (middle) UPF 110-2 to the SMF 160. The SMF 160 can start a timer to release the resources in the old middle UPF 110-2 (if any).
[0224] In an example, the SMF 160 may send an N4 session modification request 1045 to the old UPF 110-2 (e.g., may include the new UPF 110 address, the new UPF 110 DL tunnel ID, etc.). In an example, if the service request can be triggered by the network, and / or the SMF 160 can remove the old (intermediate) UPF 110-2, then the SMF 160 may send an N4 session modification request message to the old (intermediate) UPF 110-2 and may provide DL tunnel information for buffering DL data. If the SMF 160 can allocate a new I-UPF 110, the DL tunnel information is from the new (intermediate) UPF 110 that can be used as the N3 termination point. If the SMF 160 cannot allocate a new I-UPF 110, the DL tunnel information may be from the new UPF 110 (PSA) 110-3 that is used as the N3 termination point. The SMF 160 may start a timer to monitor the forwarding tunnel. In an example, the old (intermediate) UPF 110-2 may send an N4 session modification response message to the SMF 160.
[0225] In an example, if the I-UPF 110-2 can be relocated and a forwarding tunnel is established to the new I-UPF 110, the old (intermediate) UPF 110-2 may forward its buffered data to the new (intermediate) UPF 110 that is used as the N3 termination point. In an example, if the old I-UPF 110-2 may be removed, and the new I-UPF 110 may not be allocated for the PDU session, and a forwarding tunnel may be established to the UPF 110 (PSA) 110-3, the old (intermediate) UPF 110-2 may forward its buffered data to the UPF 110 (PSA) 110-3 that is used as the N3 termination point.
[0226] In the example, when the SMF 160 receives an Nsmf_PDUSession_UpdateSMContext request with a cause (including, for example, the establishment of user plane resources), it can send an N11 message 1060 to the AMF 155, such as an Nsmf_PDUSession_UpdateSMContext response (including an N1 SM container (PDU session ID, PDU session re - establishment indication), N2 SM information (PDU session ID, QoS profile, CN N3 tunnel information, S - NSSAI), cause). The SMF 160 can determine whether UPF 110 re - allocation can be performed based on the UE 100 location information, the UPF 110 service area, and operator policies. In the example, for a PDU session that can be determined to be served by the current UPF 110 (e.g., PDU session anchor or intermediate UPF) by the SMF 160, the SMF 160 can generate N2 SM information and can send an Nsmf_PDUSession_UpdateSMContext response 1060 to the AMF 155 to establish the user plane. The N2 SM information can contain information that the AMF 155 can provide to the RAN 105. In the example, for a PDU session for which the SMF 160 determines that the UPF 110 needs to be re - positioned as the PDU session anchor UPF, the SMF 160 can reject the activation of the PDU session's UP by sending an Nsmf_PDUSession_UpdateSMContext response that can contain an N1 SM container to the UE 100 via the AMF 155. The N1 SM container can include the corresponding PDU session ID and the PDU session re - establishment indication.
[0227] When receiving a Namf_EventExposure_Notify from the AMF 155 to the SMF 160 with an indication that the UE 100 is reachable, if the SMF 160 may have pending DL data, the SMF 160 can call the Namf_Communication_N1N2MessageTransfer service operation to the AMF155 to establish the user plane of the PDU session. In the example, in the case of DL data, the SMF 160 can continue to send DL data notifications to the AMF 155.
[0228] In the example, if the PDU session can correspond to LADN and UE 100 may be outside the availability area of LADN, or if AMF 155 can notify SMF 160 that UE 100 may be reachable for regulatory prioritized services and the PDU session to be activated may not be used for regulatory prioritized services; or if SMF 160 may decide to perform PSA UPF 110-3 relocation for the requested PDU session, then SMF 160 can send a message to AMF 155 to reject the UP for activating the PDU session by including a cause in the Nsmf_PDUSession_UpdateSMContext response.
[0229] In the example, AMF 155 can send an N2 request message 1065 to (R)AN 105 (e.g., N2 SM information received from SMF 160, security context, AMF 155 signaling connection ID, handover restriction list, MM NAS service acceptance, list of recommended cells / TA / NG-RAN node identifiers). In the example, RAN 105 can store the security context, AMF 155 signaling connection Id, QoS information of QoS flows of the PDU session that can be activated, and the N3 tunnel ID in the UE 100 RAN 105 context. In the example, the MM NAS service acceptance can include the PDU session state in AMF 155. If SMF 160 may reject the UP for activating the PDU session, the MM NAS service acceptance can include the PDU session ID and the reason why the user plane resources may not be activated (e.g., LADN is unavailable). The local PDU session release during the session request procedure can be indicated to UE 100 via the session state.
[0230] In the example, if there is a number of PDU sessions that may involve multiple SMF 160s, AMF 155 may not wait for responses from all SMF 160s before it can send N2 SM information to UE 100. AMF 155 may wait for all responses from SMF 160s before it can send the MM NAS service acceptance message to UE 100.
[0231] In an example, if the procedure can be triggered for PDU session user plane activation, the AMF 155 may include at least one N2 SM information from the SMF 160. The AMF 155 may send additional N2 SM information from the SMF 160 in a separate N2 message (e.g., N2 tunnel setup request) if it exists. Alternatively, if multiple SMFs 160 may be involved, the AMF 155 may send an N2 request message to the (R)AN 105 after receiving all Nsmf_PDUSession_UpdateSMContext response service operations from all SMFs 160 associated with the UE 100. In this case, the N2 request message may include the N2 SM information and the PDU session ID received in each Nsmf_PDUSession_UpdateSMContext response, enabling the AMF 155 to associate the response with the relevant SMF 160.
[0232] In an example, if the RAN 105 (e.g., NG RAN) node can provide a list of recommended cells / TA / NG-RAN node identifiers during the AN release procedure, the AMF 155 may include the information from the list in the N2 request. When the RAN 105 may decide to enable the RRC inactive state of the UE 100, the RAN 105 may use this information to allocate the RAN 105 notification area.
[0233] If the AMF 155 can receive an indication from the SMF 160 during the PDU session establishment procedure that the UE 100 may be using a PDU session related to delay-sensitive services for any PDU session established for the UE 100, and the AMF 155 has received an indication from the UE 100 that it can support CM-CONNECTED in the RRC inactive state, the AMF 155 may include the RRC inactive assistance information of the UE. In an example, the AMF 155 based on the network configuration may include the RRC inactive assistance information of the UE.
[0234] In an example, the (R)AN 105 may send a message to the UE 100 to perform an RRC connection reconfiguration 1070 with the UE 100, depending on the QoS information of all QoS flows of the PDU session for which the UP connection can be activated and the data radio bearer. In an example, user plane security may be established.
[0235] In an example, if the N2 request may include an MM NAS service accept message, the RAN 105 may forward the MM NAS service accept to the UE 100. The UE 100 may locally delete the context of the PDU session that may not be available in the 5GC.
[0236] In the example, if the N1 SM information can be transmitted to the UE 100 and can indicate that some PDU sessions can be re - established, then the UE 100 can initiate a PDU session re - establishment for the PDU sessions that can be re - established after the service request procedure may complete.
[0237] In the example, after the user - plane radio resources can be set up, the uplink data from the UE 100 can be forwarded to the RAN 105. The RAN 105 (e.g., NG - RAN) can send the uplink data to the provided UPF 110 address and tunnel ID.
[0238] In the example, the (R)AN 105 can send an N2 request confirmation 1105 (e.g., N2 SM information (including: AN tunnel information, list of accepted QoS flows of the PDU sessions for which the UP connection is activated, list of rejected QoS flows of the PDU sessions for which the UP connection is activated)) to the AMF 155. In the example, the N2 request message may include N2 SM information, e.g., AN tunnel information. The RAN 105 can respond to the N2 SM information with a separate N2 message (e.g., N2 tunnel setup response). In the example, if multiple N2 SM information are included in the N2 request message, the N2 request confirmation can include multiple N2 SM information and information enabling the AMF 155 to associate the response with the relevant SMF 160.
[0239] In the example, the AMF 155 can send a per - PDU - session Nsmf_PDUSession_UpdateSMContext request 1110 (N2 SM information (AN tunnel information), RAT type) to the SMF 160. If the AMF 155 can receive N2 SM information (one or more) from the RAN105, the AMF 155 can forward the N2 SM information to the relevant SMF 160. If the UE 100 time zone may have changed compared to the last reported UE 100 time zone, the AMF 155 can include the UE 100 time zone IE in the Nsmf_PDUSession_UpdateSMContext request message.
[0240] In the example, if dynamic PCC is deployed, then the SMF 160 can initiate a notification about the new location information (if subscribed) to the PCF 135 by invoking an event exposure notification operation (e.g., Nsmf_EventExposure_Notify service operation). The PCF 135 can provide updated policies by invoking a policy control update notification message 1115 (e.g., Npcf_SMPolicyControl_UpdateNotify operation).
[0241] In an example, if the SMF 160 can select a new UPF 110 to act as the intermediate UPF 110 for a PDU session, then the SMF 160 can initiate an N4 session modification procedure 1120 to the new I-UPF 110 and can provide AN tunnel information. Downlink data from the new I-UPF 110 can be forwarded to the RAN 105 and the UE 100. In an example, the UPF 110 can send an N4 session modification response 1120 to the SMF 160. In an example, the SMF 160 can send an Nsmf_PDUSession_UpdateSMContext response 1140 to the AMF 155.
[0242] In an example, if a forwarding tunnel to the new I-UPF 110 can be established and if a timer set by the SMF 160 for the forwarding tunnel may expire, then the SMF 160 can send an N4 session modification request 1145 to the new (intermediate) UPF 110 acting as the N3 termination point to release the forwarding tunnel. In an example, the new (intermediate) UPF 110 can send an N4 session modification response 1145 to the SMF 160. In an example, the SMF 160 can send an N4 session modification request 1150 or an N4 session release request to the PSA UPF 110-3. In an example, if the SMF 160 can continue to use the old UPF 110-2, then the SMF 160 can send an N4 session modification request 1155, thereby providing AN tunnel information. In an example, if the SMF 160 can select the new UPF 110 as the intermediate UPF 110 and the old UPF 110-2 may not be the PSA UPF 110-3, then the SMF 160 can initiate resource release by sending an N4 session release request (release reason) to the old intermediate UPF 110-2 after the timer expires.
[0243] In the example, the old intermediate UPF 110-2 can send an N4 session modification response or an N4 session release response 1155 to the SMF 160. The old UPF 110-2 can confirm with an N4 session modification response or an N4 session release response message to confirm the modification or release of resources. The AMF 155 can invoke the Namf_EventExposure_Notify service operation to notify NF that may have subscribed to the event of mobility-related events after this procedure may be completed. In the example, if the SMF 160 has subscribed to the UE100 moving into or out of the area of interest and if the current location of the UE can indicate that it may be moving into or out of the subscribed area of interest, or if the SMF 160 has subscribed to the LADN DNN and if the UE 100 may be moving into or out of the area where the LADN is available, or if the UE 100 may be in the MICO mode and the AMF 155 has notified that the SMF 160 of the UE 100 is unreachable and the SMF 160 may not send a DL data notification to the AMF 155, and the AMF 155 can notify the SMF 160 that the UE 100 is reachable, then the AMF155 can invoke Namf_EventExposure_Notify on the SMF 160, or if the SMF 160 has subscribed to the reachability status of the UE 100, then the AMF 155 can notify the reachability of the UE 100.
[0244] In Figure 12 and Figure 13An example PDU session establishment procedure is depicted. In one exemplary implementation, when the PDU session establishment procedure can be employed, the UE 100 may send a NAS message 1205 (or an SM NAS message) to the AMF 155, which NAS message includes the NSSAI, S-NSSAI (e.g., requested S-NSSAI, permitted S-NSSAI, subscribed S-NSSAI, etc.), DNN, PDU session ID, request type, old PDU session ID, N1 SM container (PDU session establishment request), etc. In the example, the UE 100 may generate a new PDU session ID for establishing a new PDU session. In the example, when emergency services may be required and an emergency PDU session may not have been established yet, the UE 100 may initiate the PDU session establishment procedure requested by the UE 100, where the request type indicates an emergency request. In the example, the UE 100 may initiate the PDU session establishment procedure requested by the UE 100 by transmitting a NAS message containing the PDU session establishment request within the N1 SM container. The PDU session establishment request may include the PDU type, SSC mode, protocol configuration options, etc. In the example, if the PDU session establishment is a request to establish a new PDU session, the request type may indicate an initial request, and if the request pertains to an existing PDU session between 3GPP access and non-3GPP access or to an existing PDN connection in the EPC, the request type may indicate an existing PDU session. In the example, if the PDU session establishment can be a request to establish a PDU session for emergency services, the request type may indicate an emergency request. If the request pertains to an existing PDU session for emergency services between 3GPP access and non-3GPP access, the request type may indicate an existing emergency PDU session. In the example, the NAS message sent by the UE 100 may be encapsulated by the AN in an N2 message sent to the AMF 155 that may include user location information and access technology type information. In the example, the PDU session establishment request message may contain an SM PDU DN request container that contains information on external DN authorization for the PDU session. In the example, if the procedure can be triggered for SSC mode 3 operation, then the UE 100 may include the old PDU session ID in the NAS message, which old PDU session ID may indicate the PDU session ID of the ongoing PDU session to be released. The old PDU session ID may be an optional parameter that can be included in this case. In the example, the AMF 155 may receive the NAS message (e.g., NAS SM message) and user location information (e.g., cell ID in the case of the RAN 105) from the AN. In the example, when the UE 100 is outside the availability area of the LADN, the UE 100 may not trigger the PDU session establishment for the PDU session corresponding to the LADN.
[0245] In the example, the AMF 155 can determine that the NAS message or the SM NAS message corresponds to a request for a new PDU session based on the request type indicating an initial request and that the PDU session ID may not be used for any existing PDU session of the UE 100. If the NAS message does not contain an S-NSSAI, the AMF 155 can determine the default S-NSSAI of the requested PDU session according to the UE 100 subscription (if it can only contain one default S-NSSAI), or based on the operator policy. In the example, the AMF 155 can perform the SMF 160 selection 1210 and select the SMF 160. If the request type can indicate an initial request or the request can be attributed to a handover from EPS, the AMF 155 can store the association of the S-NSSAI, the PDU session ID, and the SMF 160 ID. In the example, if the request type is an initial request and if the old PDU session ID indicating an existing PDU session can be included in the message, the AMF 155 can select the SMF 160 and can store the association of the new PDU session ID and the selected SMF 160 ID.
[0246] In the example, the AMF 155 can send an N11 message 1215 to the SMF 160, for example, an Nsmf_PDUSession_CreateSMContext request (including: SUPI or PEI, DNN, S-NSSAI, PDU session ID, AMF 155 ID, request type, N1 SM container (PDU session establishment request), user location information, access type, PEI, GPSI), or an Nsmf_PDUSession_UpdateSMContext request (SUPI, DNN, S-NSSAI, PDU session ID, AMF 155 ID, request type, N1 SM container (PDU session establishment request), user location information, access type, RAT type, PEI). In the example, if the AMF 155 may not be associated with the SMF 160 of the PDU session ID provided by the UE 100 (for example, when the request type indicates an initial request), the AMF 155 can invoke the Nsmf_PDUSession_CreateSMContext request. However, if the AMF 155 is already associated with the SMF 160 of the PDU session ID provided by the UE 100 (for example, when the request type indicates an existing PDU session), the AMF 155 can invoke the Nsmf_PDUSession_UpdateSMContext request. In the example, the AMF 155 ID can be the GUAMI of the UE, which uniquely identifies the AMF 155 serving the UE 100. The AMF 155 can forward the PDU session ID and the N1 SM container containing the PDU session establishment request received from the UE 100. When the UE 100 registers for an emergency service without providing the SUPI, the AMF 155 can provide the PEI instead of the SUPI. If the UE 100 registers for an emergency service but has not been authenticated, the AMF 155 can indicate that the SUPI has not been authenticated.
[0247] In an example, if the request type does not indicate an emergency request nor an existing emergency PDU session, and if the SMF 160 has not been registered and the subscription data may not be available, the SMF 160 may register with the UDM 140 and may retrieve the subscription data 1225 and the subscription be notified when the subscription data can be modified. In an example, if the request type can indicate an existing PDU session or an existing emergency PDU session, the SMF 160 may determine that the request is attributable to a handover between 3GPP access and non-3GPP access, or attributable to a handover from EPS. The SMF 160 may identify the existing PDU session based on the PDU session ID. Instead of creating a new SM context, the SMF 160 may update the existing SM context and may provide a representation of the updated SM context to the AMF 155 in the response. If the request type can be an initial request, and if the old PDU session ID can be included in the Nsmf_PDUSession_CreateSMContext request, the SMF 160 may identify the existing PDU session to be released based on the old PDU session ID.
[0248] In an example, the SMF 160 may send an N11 message response 1220 to the AMF 155, for example, a PDU session create / update response, an Nsmf_PDUSession_CreateSMContext response 1220 (cause, SM context ID or N1 SM container (PDU session reject (cause))) or an Nsmf_PDUSession_UpdateSMContext response.
[0249] In an example, if the SMF 160 can perform secondary authorization / authentication 1230 during the establishment of a PDU session by the DN-AAA server, the SMF 160 may select a UPF 110 and may trigger PDU session establishment authentication / authorization.
[0250] In an example, if the request type can indicate an initial request, the SMF 160 may select an SSC mode for the PDU session. The SMF 160 may select one or more UPFs as needed. In the case where the PDU type is IPv4 or IPv6, the SMF 160 may allocate an IP address / prefix for the PDU session. In the case where the PDU type is IPv6, the SMF 160 may allocate an interface identifier for the UE 100 so that the UE 100 can construct its link-local address. For an unstructured PDU type, the SMF 160 may allocate an IPv6 prefix for the PDU session and the N6 point-to-point tunnel (based on UDP / IPv6).
[0251] In the example, if dynamic PCC is deployed, the SMF 160 may perform PCF 135 selection 1235. If the request type indicates an existing PDU session or an existing emergency PDU session, the SMF 160 may use the PCF 135 that has been selected for the PDU session. If dynamic PCC is not deployed, the SMF 160 may apply local policies.
[0252] In the example, the SMF 160 may execute the session management policy establishment procedure 1240 to establish a PDU session with the PCF 135 and may obtain the default PCC rules for the PDU session. If available at the SMF 160, the GPSI may be included. If the request type in 1215 indicates an existing PDU session, then the SMF 160 may notify the events previously subscribed by the PCF 135 through the session management policy modification procedure, and the PCF 135 may update the policy information in the SMF 160. The PCF 135 may provide the authorized session-AMBR and the authorized 5QI and ARP to the SMF 160. The PCF 135 may subscribe to the IP allocation / release event (and may subscribe to other events) in the SMF 160.
[0253] In the example, the PCF 135 may set the ARP of the PCC rule to a value that can be reserved for emergency services based on the emergency DNN.
[0254] In the example, if the request type in 1215 indicates an initial request, the SMF 160 may select the SSC mode for the PDU session. The SMF 160 may select one or more UPFs 1245 as needed. In the case where the PDU type is IPv4 or IPv6, the SMF 160 may allocate an IP address / prefix for the PDU session. In the case where the PDU type is IPv6, the SMF 160 may allocate an interface identifier for the UE 100 so that the UE 100 can construct its link-local address. For the unstructured PDU type, the SMF 160 may allocate an IPv6 prefix for the PDU session and the N6 point-to-point tunnel (e.g., based on UDP / IPv6). In the example, for a PDU session of the Ethernet PDU type, the SMF 160 may neither allocate a MAC nor an IP address to the UE 100 for this PDU session.
[0255] In the example, if the request type in 1215 is an existing PDU session, the SMF 160 may maintain the same IP address / prefix that can be allocated to the UE 100 in the source network.
[0256] In an example, if the request type in 1215 indicates an existing PDU session involving an existing PDU session that moves between 3GPP access and non-3GPP access, the SMF 160 may maintain the SSC mode of the PDU session, for example, the current PDU session anchor and IP address. In an example, the SMF 160 may trigger, for example, the insertion of a new intermediate UPF 110 or the allocation of a new UPF 110. In an example, if the request type indicates an emergency request, then the SMF 160 may select the 1245 UPF 110 and may select SSC mode 1.
[0257] In an example, the SMF 160 may execute the session management policy modification 1250 procedure to report some events to the previously subscribed PCF 135. If the request type is an initial request, dynamic PCC is deployed, and the PDU type is IPv4 or IPv6, then the SMF 160 may notify the (previously subscribed) PCF 135 of the allocated UE 100 IP address / prefix.
[0258] In an example, the PCF 135 may provide updated policies to the SMF 160. The PCF 135 may provide the authorized session-AMBR, the authorized 5QI, and the ARP to the SMF 160.
[0259] In an example, if the request type indicates an initial request, then the SMF 160 may initiate the N4 session establishment procedure 1255 with the selected UPF 110. The SMF 160 may initiate the N4 session modification procedure with the selected UPF 110. In an example, the SMF 160 may send an N4 session establishment / modification request 1255 to the UPF 110 and may provide packet detection, enforcement, reporting rules, etc. to be installed on the UPF 110 for this PDU session. If the CN tunnel information is allocated by the SMF 160, the CN tunnel information may be provided to the UPF 110. If this PDU session requires selective user plane deactivation, then the SMF 160 may determine the inactivity timer and provide it to the UPF 110. In an example, the UPF 110 may confirm by sending an N4 session establishment / modification response 1255. If the CN tunnel information is allocated by the UPF, the CN tunnel information may be provided to the SMF 160. In an example, if multiple UPFs are selected for a PDU session, then the SMF 160 may initiate the N4 session establishment / modification procedure 1255 with each UPF 110 of the PDU session.
[0260] In an example, the SMF 160 may send a Namf_Communication_N1N2MessageTransfer1305 message to the AMF 155 (including a PDU session ID, an access type, N2 SM information (PDU session ID, QFI, QoS profile, CN tunnel information, S-NSSAI, session-AMBR, PDU session type, etc.), an N1 SM container (PDU session establishment acceptance (QoS rules, selected SSC mode, S-NSSAI, assigned IPv4 address, interface identifier, session-AMBR, selected PDU session type, etc.))). In the case where multiple UPFs are used for a PDU session, the CN tunnel information may include tunnel information related to the UPF 110 terminating N3. In an example, the N2 SM information may carry information that the AMF 155 may forward to the (R)AN 105 (e.g., CN tunnel information corresponding to the core network address of the N3 tunnel corresponding to the PDU session, one or more QoS profiles and corresponding QFIs may be provided to the (R)AN 105, the PDU session ID may indicate the association between the AN resources and the PDU session for the UE 100 to the UE 100 through AN signaling with the UE 100, etc.). In an example, the PDU session may be associated with an S-NSSAI and a DNN. In an example, the N1 SM container may contain the PDU session establishment acceptance that the AMF 155 may provide to the UE 100. In an example, multiple QoS rules and QoS profiles may be included in the PDU session establishment acceptance within the N1 SM and the N2 SM information. In an example, the Namf_Communication_N1N2MessageTransfer 1305 may also include a PDU session ID and information that allows the AMF 155 to know which access is used for the UE 100.
[0261] In an example, the AMF 155 may send an N2 PDU session request 1310 to the (R)AN105 (including N2 SM information, a NAS message (PDU session ID, an N1 SM container (PDU session establishment acceptance, etc.))). In an example, the AMF 155 may send a NAS message 1310 to the (R)AN 105, and the NAS message may include a PDU session ID and the PDU session establishment acceptance for the UE 100, as well as the N2 SM information received from the SMF 160 within the N2 PDU session request 1310.
[0262] In an example, the (R)AN 105 can exchange an AN-specific signaling 1315 with the UE 100, and the AN-specific signaling exchange can be related to the information received from the SMF 160. In the example, in the case of the 3GPP RAN 105, an RRC connection reconfiguration procedure can be performed with the UE 100 to establish the necessary RAN 105 resources related to the QoS rules of the PDU session request 1310. In the example, the (R)AN 105 can allocate (R)AN 105 N3 tunnel information for the PDU session. In the case of dual connectivity, the primary RAN 105 node can allocate some (zero or more) QFIs to be set to the primary RAN 105 node and allocate other QFIs to the secondary RAN 105 node. The AN tunnel information can include the tunnel endpoints of each involved RAN 105 node and the QFI allocated to each tunnel endpoint. The QFI can be allocated to the primary RAN 105 node or the secondary RAN 105 node. In the example, the (R)AN 105 can forward the NAS message 1310 (PDU session ID, N1 SM container (PDU session establishment acceptance)) to the UE 100. If the necessary RAN 105 resources are established and the (R)AN 105 tunnel information is successfully allocated, the (R)AN 105 can provide the NAS message to the UE 100.
[0263] In an example, the N2 PDU session response 1320 can include a PDU session ID, a cause, N2 SM information (PDU session ID, AN tunnel information, a list of accepted / rejected QFIs), and so on. In the example, the AN tunnel information can correspond to the access network address of the N3 tunnel corresponding to the PDU session.
[0264] In an example, the AMF 155 can forward the N2 SM information received from the (R)AN 105 to the SMF 160 via the Nsmf_PDUSession_UpdateSMContext request 1330 (including: N2 SM information, request type, etc.). In the example, if the list of rejected QFIs is included in the N2 SM information, the SMF 160 can release the QoS profile associated with the rejected QFI.
[0265] In an example, the SMF 160 can initiate an N4 session modification procedure 1335 with the UPF 110. The SMF 160 can provide the AN tunnel information and the corresponding forwarding rules to the UPF 110. In the example, the UPF 110 can provide an N4 session modification response 1335 to the SMF 160160.
[0266] In the example, the SMF 160 may send an Nsmf_PDUSession_UpdateSMContext response 1340 (cause) to the AMF 155. In the example, after this step, the SMF 160 may subscribe to UE 100 mobility event notifications (e.g., location reports, UE 100 moving into or out of an area of interest) from the AMF 155 by invoking the Namf_EventExposure_Subscribe service operation. For LADN, the SMF 160 may subscribe to UE 100 moving into or out of the LADN service area event notification by providing the LADN DNN as an indicator of the area of interest. The AMF 155 may forward the relevant events subscribed by the SMF 160.
[0267] In the example, the SMF 160 may send an Nsmf_PDUSession_SMContextStatusNotify (release) 1345 to the AMF 155. In the example, if during this procedure, at any time the PDU session establishment is unsuccessful, the SMF 160 may notify the AMF 155 by invoking the Nsmf_PDUSession_SMContextStatusNotify (release) 1345. The SMF 160 may release any N4 sessions created, any PDU session addresses (if allocated) (e.g., IP addresses), and may release the association with the PCF 135.
[0268] In the example, in the case where the PDU type is IPv6, the SMF 160 may generate an IPv6 router advertisement 1350 and send it to the UE 100 via N4 and the UPF 110.
[0269] In the example, if the PDU session may not be established, when the SMF 160 no longer processes the PDU session for the UE 100 for this (DNN, S-NSSAI), the SMF 160 may use Nudm_SDM_Unsubscribe (SUPI, DNN, S-NSSAI) to unsubscribe 1360 from modifications to the session management subscription data for the corresponding (SUPI, DNN, S-NSSAI). In the example, if the PDU session may not be established, the SMF 160 may use Nudm_UECM_Deregistration (SUPI, DNN, PDU session ID) to deregister 1360 for a given PDU session.
[0270] Figure 15Shows the service-based architecture of a 5G network regarding the control plane (CP) and user plane (UP) interactions. This diagram can depict the logical connections between nodes and functions, and the connections shown therein cannot be interpreted as direct physical connections. A wireless device can form a radio access network connection with a base station, which is connected to a User Plane (UP) Function (UPF) through a network interface that provides a defined interface, such as the N3 interface. The UPF can provide a logical connection to a Data Network (DN) through a network interface such as the N6 interface. The radio access network connection between the wireless device and the base station can be referred to as a Data Radio Bearer (DRB).
[0271] The DN can be a data network for providing carrier services, third-party services such as the Internet, IP Multimedia Subsystem (IMS), Augmented Reality (AR), Virtual Reality (VR). In some embodiments, the DN can represent an edge computing network or resource, such as a Mobile Edge Computing (MEC) network.
[0272] The wireless device is also connected to the AMF through a logical N1 connection. The AMF can be responsible for the authentication and authorization of access requests, as well as mobility management functions. The AMF can perform other roles and functions. From a service-based perspective, the AMF can communicate with other core network control plane functions through a service-based interface represented as Namf.
[0273] The SMF is a network function that can be responsible for allocating and managing the IP addresses assigned to wireless devices, as well as selecting the UPF for the traffic associated with a specific session of a wireless device. There will typically be multiple SMFs in the network, where each SMF can be associated with a corresponding group of wireless devices, base stations, or UPFs. From a service-based perspective, the SMF can communicate with other core network functions through a service-based interface represented as Nsmf. The SMF can also be connected to the UPF through a logical interface such as the network interface N4.
[0274] The Authentication Server Function (AUSF) can provide authentication services to other network functions through a service-based Nausf interface. A Network Exposure Function (NEF) can be deployed in the network to allow servers, functions, and other entities (such as entities outside the trust domain (operator network)) to be exposed to the services and capabilities within the network. In one such example, the NEF can act as a proxy between an external Application Server (AS) outside the shown network and network functions such as PCF, SMF, UDM, and AMF. The external AS can provide information that can be used in the parameter settings associated with a data session. The NEF can communicate with other network functions through a service-based Nnef network interface. The NEF can have an interface to non-3GPP functions.
[0275] The Network Repository Function (NRF) can provide network service discovery functionality. The NRF may be specific to the Public Land Mobile Network (PLMN) or network operator with which it is associated. The service discovery functionality can allow network functions and wireless devices connected to the network to determine where and how to access existing network functions.
[0276] The PCF can communicate with other network functions via the service-based Npcf interface and can be used to provide policies and rules to other network functions, including those within the control plane. The execution and application of policies and rules may not be the responsibility of the PCF. The responsibility for the function to which the PCF transmits policies can be the responsibility of the AMF or the SMF. In one such example, the PCF can transmit session management-associated policies to the SMF. This can be used to allow a unified policy framework, by means of which network behavior can be managed.
[0277] The UDM can provide a service-based Nudm interface to communicate with other network functions. The UDM can provide a data storage facility to other network functions. Unified data storage can allow a unified view of network information, which can be used to ensure that the most relevant information can be provided to different network functions from a single resource. This can allow other network functions to be implemented more easily, as they may not need to determine where specific types of data are stored in the network. The UDM can employ an interface such as Nudr to connect to the UDR. The PCF can be associated with the UDM.
[0278] The PCF can have a direct interface to the UDR or can use the Nudr interface to connect to the UDR. The UDM can receive requests to retrieve content stored in the UDR or requests to store content in the UDR. The UDM can be responsible for functions such as credential handling, location management, and subscription management. The UDR can also support authentication credential handling, user identity handling, access authorization, registration / mobility management, subscription management, and Short Message Service (SMS) management. The UDR can be responsible for storing data provided by the UDM. The stored data is associated with policy profile information (which can be provided by the PCF) that manages access rights to the stored data. In some embodiments, the UDR can store policy data as well as user subscription data, which can include any or all of subscription identifiers, security credentials, access and mobility-related subscription data, and session-related data.
[0279] The Application Function (AF) can represent the non-data plane (also known as the non-user plane) function of an application deployed within the network operator's domain and within a 3GPP-compliant network. The AF can be in an internal Application Server (AS). The AF can interact with other core network functions via the service-based Naf interface, and can access network capability exposure information, as well as provide application information for use in decisions such as traffic routing. The AF can also interact with functions such as the PCF to provide application-specific input to policy and policy enforcement decisions. In many cases, the AF may not provide network services to other network functions. The AF can generally be regarded as a consumer or user of services provided by other network functions. Applications (application servers) outside the trust domain (operator network) can perform many of the same functions as the AF by using the NEF.
[0280] The radio device can communicate with network functions in the core network control plane (CN-UP) and the core network user plane (CN-CP). The UPF and the Data Network (DN) are part of the CN-UP. The DN may be outside the core network domain (cellular network domain). In the illustration ( Figure 15 ), the base station is on the CP-UP side. The base station can provide connections for both the CN-CP and the CN-UP. The AMF, SMF, AUSF, NEF, NRF, PCF, and UDM can be functions residing within the CN-CP and are generally referred to as control plane functions. If the AF resides within the trust domain, the AF can communicate directly with other functions within the CN-CP via the service-based Naf interface. If the AF resides outside the trust domain, the AM can communicate indirectly with other functions within the CN-CP via the NEF.
[0281] When establishing a PDU session towards a data network (DN), it may be necessary to authenticate and / or authorize the PDU session against an authentication, authorization, and accounting (AAA) server in the data network. This may be the case if the DN corresponds to a corporate network or is provided by a third party in some other way. During the establishment of a PDU session using the Extensible Authentication Protocol (EAP), the 5G system can support this via a secondary authentication / authorization with the DN-AAA server. This secondary authentication and / or authorization can be performed in addition to the primary 5G system access authentication handled by the AMF during the registration procedure. In an example, the DN-AAA server can be part of a mobile operator. The DN-AAA server can be part of a data network provider (e.g., a private company). The secondary authentication can allow a third party to control the identification and authorization of service users of the third party. The load on the 5G system can be reduced and the flexibility and modularity of the 5G system can be increased. During the secondary authentication / authorization, the DN-AAA server can provide or update a QoS policy or authorization level for the PDU session of the wireless device. The SMF can perform the role of the EAP authenticator. When the SMF receives a PDU session establishment request from the wireless device, the SMF can be configured to request secondary authentication / authorization by the DN-AAA server. In response to this configuration, the SMF can initiate an EAP authentication by requesting the wireless device to provide its DN-specific identity. This DN-specific identity can be specific to the DN and independent of the SIM-based identity.
[0282] Figure 16 A general procedure for registration and network slice-specific authentication and authorization (NSSAA) involving a wireless device, a base station, an AMF, a UDM, an AUSF, and an AAA server (AAA server) is shown.
[0283] In addition to secondary authentication / authorization, the 5G system can also support NSSAA after the registration procedure is completed. NSSAA can be per-slice granular authentication and authorization and can be performed by the AMF before the establishment of a PDU session. NSSAA can avoid the need to perform secondary authentication / authorization when establishing a PDU session. If the wireless device realizes that the authentication of the slice (indicated by a rejected S-NSSAI) has failed, the wireless device can refrain from performing the PDU session establishment for the slice.
[0284] The AAA server (AAA-S) can trigger the NSSAA procedure for the S-NSSAI that requires NSSAA. The AAA-S can be hosted by the H-PLMN operator or by a third party having a business relationship with the H-PLMN using the EAP framework. If the AAA server belongs to a third party, an AAA proxy (AAA-P) in the HPLMN may be involved. The AMF can perform the role of the EAP authenticator and communicate with the AAA-S via the AUSF. The AUSF can assume any AAA protocol interoperable with the AAA protocol supported by the AAA-S.
[0285] As Figure 16 shown, the wireless device can send a registration request message to the AMF via the base station to register with the AMF. The registration request message can include the NSSAA capability of the wireless device, the wireless device identity, the requested NSSAI (e.g., network slice identifier), etc. The NSSAA capability can indicate whether the wireless device supports NSSAA. The requested NSSAI can include at least one requested S-NSSAI that the wireless device expects to receive services from. In an example, the requested S-NSSAI can indicate eMBB, URLLC, MIoT, V2X, etc. In response to receiving the registration request message, the AMF can check the subscription information of the wireless device with the UDM. The subscription information can include information on whether NSSAA is required for the specific S-NSSAI (e.g., slice) requested by the wireless device.
[0286] In an example, the wireless device may not support NSSAA. If the wireless device does not support NSSAA, the wireless device can indicate in the registration request message that the wireless device does not support NSSAA. For example, the wireless device can indicate that the wireless device does not support NSSAA in the registration request message by not including the NSSAA capability in the registration request message. Based on the subscription information, the AMF can determine that at least one S-NSSAI in the requested NSSAI is subject to NSSAA. If the wireless device does not support NSSAA, the AMF will not trigger the NSSAA procedure for the wireless device. The AMF can consider any S-NSSAI subject to NSSAA as a rejected NSSAI. In response to the registration request message, the AMF can send a registration acceptance message to the wireless device via the base station. The registration acceptance message can include the allowed NSSAI and / or the rejected NSSAI. If all S-NSSAIs of the wireless device are subject to NSSAA and the wireless device does not support NSSAA, the AMF can deregister the wireless device by sending a deregistration request message including the rejected NSSAI to the wireless device.
[0287] In an example, a wireless device may support NSSAA. Based on subscription information, the AMF may determine that at least one S-NSSAI in the requested NSSAI is subject to NSSAA. In this case, the AMF may consider any S-NSSAI subject to NSSAA as a pending NSSAI. The AMF may indicate the pending NSSAI including the pending S-NSSAI to the wireless device by sending a registration acceptance message including the pending NSSAI. The registration acceptance message may also include the allowed NSSAI. The allowed NSSAI may include at least one S-NSSAI that is allowed for the wireless device to perform a PDU session. In response to sending the registration acceptance message to the wireless device, the AMF may perform the NSSAA procedure for the pending NSSAI with the wireless device, the AUSF, the AAA-S, and the AAA-P. As will be discussed in more detail below, Figure 17 shows the details of an exemplary NSSAA procedure.
[0288] After completing the NSSAA procedure, the AMF may determine the allowed NSSAI and the rejected NSSAI. If the NSSAA fails for the S-NSSAI of the pending NSSAI, the S-NSSAI changes to the rejected NSSAI. If the NSSAA succeeds for the S-NSSAI of the pending NSSAI, the S-NSSAI changes to the allowed NSSAI. After the NSSAA procedure, the AMF may indicate the updated allowed NSSAI and the rejected NSSAI to the wireless device by sending a configuration update message including the allowed NSSAI and the rejected NSSAI. If all S-NSSAIs are subject to NSSAA and the NSSAA for all S-NSSAIs fails for the wireless device, the AMF may deregister the wireless device by sending a deregistration request message including the rejected NSSAI.
[0289] Figure 17 shows an exemplary NSSAA procedure, such as the NSSAA procedure mentioned above with respect to Figure 16 For an S-NSSAI that requires NSSAA, based on a change in subscription information, part of the registration procedure (or triggered by the AAA-S), the AMF may trigger the start of the NSSAA procedure. The AMF may send an Extensible Authentication Protocol (EAP) identity request for the S-NSSAI to the wireless device in a NAS MM transport message including the S-NSSAI. This is the S-NSSAI of the H-PLMN, rather than the locally mapped S-NSSAI value. The wireless device may provide an EAP identity response for the S-NSSAI along with the S-NSSAI in a NAS MM transport message for the AMF.
[0290] The AMF may send an EAP identity response (including the EAP identity response, AAA-S address, GPSI, S-NSSAI) to the AUSF in the Nausf_NSSAA_Authenticate request. If there is an AAA-P as shown in Figure 17 (e.g., because the AAA-S belongs to a third party and the operator deploys an agent to the third party), the AUSF forwards the EAP ID response message to the AAA-P. Otherwise, the AUSF forwards the message directly to the AAA-S. The AUSF may use an AAA protocol message of the same protocol supported by the AAA-S to the AAA-P or the AAA-S. The AAA-P may forward the EAP identity message together with the S-NSSAI and the GPSI to the AAA-S addressable by the AAA-S.
[0291] The AAA-S may store the GPSI to create an association with the EAP identity in the EAP ID response message, so that the AAA-S can later use the GPSI to revoke authorization or trigger re-authentication. The EAP message may be exchanged with the wireless device. One or more iterations of these steps may be performed. If the EAP authentication is completed, the AAA-S may store the S-NSSAI for which the authorization has been granted, so that the AAA-S can decide to trigger re-authentication and re-authorization based on its local policy. The AAA-S may use the GPSI and the S-NSSAI to deliver an EAP success / failure message to the AAA-P (or directly to the AUSF if the AAA-P does not exist). If the AAA-P is used, the AAA-P may send an AAA protocol message including (EAP success / failure, S-NSSAI, GPSI) to the AUSF. The AUSF may send a Nausf_NSSAA_Authenticate response (EAP success / failure, S-NSSAI, GPSI) to the AMF. The AMF may transmit a NAS MM transfer message (EAP success / failure) to the wireless device. The AMF may store the EAP result for each S-NSSAI for which it performs the NSSAA procedure.
[0292] In the prior art, a wireless device may request one or more network slices. A network (e.g., an access and mobility management function) may allow or deny each of the requested network slices and may indicate to the wireless device which of the requested slices are allowed and which are denied. If the network indicates allowed slices, the wireless device may establish sessions to obtain network services. Session establishment may require allocation of radio resources and a large amount of control signaling. Some slices may require authentication and / or authorization (e.g., network slice specific authentication and authorization, or NSSAA) before being allowed. Authentication and / or authorization may require additional signaling within the network, which may result in latency. In such cases, the network may wait until authentication and / or authorization is completed before signaling permission, but the latency may inconvenience the user. Additionally, while waiting for a slice to be permitted, the wireless device may take actions that it would not take if the slice were permitted (e.g., mobility-related actions, inactivity-related actions, etc.). By the time the wireless device receives notification that the requested slice is permitted, the wireless device may no longer be in a position to enjoy the benefits of the permitted slice.
[0293] Exemplary embodiments support indication of a pending network slice. In cases where authentication and / or authorization is required, the network may support indication of a pending network slice. For example, some network slices may require network slice specific authentication and authorization (NSSAA). If a wireless device requests such a slice, the network slice may not be able to clearly indicate whether the slice is allowed or denied. The status of the slice may depend on the result of the authentication and / or authorization procedure. This procedure may require additional signaling and latency. In such cases, the network may indicate that the network slice is pending, thereby enabling the wireless device and / or one or more other network elements (e.g., a base station) to anticipate the likelihood that the slice will be allowed.
[0294] Figure 18 An example of a wireless device served by a base station, an AMF, and a UDM is shown. The wireless device may initiate a registration procedure with the AMF by sending a registration request message to the AMF via the base station. The registration request message may be a non-access stratum (NAS) message. The NAS message may be encapsulated into a radio resource control (RRC) message and sent by the wireless device to the base station. If the base station receives an RRC message including the NAS message, the base station may send the NAS message encapsulated into an N2 message from the base station to the AMF. In the example, the N2 message may be a RAN message. As Figure 16 shown, the registration request message may include a requested NSSAI, NSSAA capabilities, etc. The requested NSSAI may include at least one requested S-NSSAI. The NSSAA capability may be an indicator indicating whether the wireless device supports NSSAA.
[0295] In an example, during the registration procedure, the AMF may receive a registration request message from a wireless device via a base station. The registration request message may indicate one or more network slices to obtain one or more services associated with the one or more network slices. The one or more network slices may be a requested NSSAI including at least one requested S-NSSAI. In response to receiving the registration request message, as part of the registration procedure, the AMF may query the subscription information of the wireless device with the UDM. The subscription information may include mapping information between the S-NSSAI and the NSSAA request. The AMF may determine whether NSSAA is required for each S-NSSAI based on the subscription information and the NSSAA capabilities. The AMF may determine the pending NSSAI based on the requested NSSAI, the subscription information, the NSSAA capabilities of the wireless device, etc. The pending NSSAI includes at least one pending S-NSSAI. The pending NSSAI or the pending S-NSSAI is the network slice for which the NSSAA procedure will be performed. In the example, the requested NSSAI includes S-NSSAI 1, S-NSSAI 2, and S-NSSAI-1 is subject to NSSAA based on the subscription information. The AMF may determine that for the wireless device, S-NSSAI 1 is the pending S-NSSAI and S-NSSAI 2 is the allowed S-NSSAI. In the example, the wireless device does not support the NSSAA capability. If the wireless device does not support the NSSAA capability, the AMF may determine the S-NSSAI subject to NSSAA as the rejected S-NSSAI. If the wireless device does not support the NSSAA capability, the AMF may not provide the pending NSSAI to the base station.
[0296] The AMF may indicate the pending NSSAI to the wireless device by sending a registration acceptance message. The registration acceptance message may be a NAS response message. The registration acceptance message may include the pending NSSAI. The AMF may send an N2 setup message to the base station to indicate the pending NSSAI to the base station. The N2 setup message may be a radio access network (RAN) setup message, a RAN message, etc. The N2 message may be a next generation (NG) message. The base station may receive an N2 message from the AMF including the pending NSSAI for NSSAA.
[0297] In response to receiving an N2 message including a pending NSSAI, a base station may determine radio resource control (RRC) parameters for a wireless device based on the pending NSSAI. The RRC parameters may facilitate efficient decisions regarding the mobility of the wireless device. For example, the RRC parameters may include frequency / band priorities for the idle mode mobility of the wireless device, frequency / band priorities for the connected mode mobility of the wireless device, measurement report configuration parameters of the wireless device, and the like. The base station may send an RRC message including the RRC parameters to the wireless device. The wireless device may select a cell associated with the pending NSSAI based on the RRC parameters. The wireless device may prioritize frequencies associated with the pending NSSAI. For example, in a homogeneous deployment scenario where all base stations from different vendors support RAN slicing, this exemplary implementation may be beneficial.
[0298] In the prior art, a wireless device may request a slice, and there may be a delay when the wireless device waits for an indication that the requested slice is allowed or denied. For example, the delay may be caused by authentication and / or authorization procedures associated with the slice. While waiting for the indication, the wireless device may make mobility decisions based on the RRC parameters provided by the base station. This may lead to the mobility of the wireless device to a cell that does not support the requested slice. Later, if an indication that the slice is allowed arrives, the wireless device may have moved to a non-supporting cell, resulting in inconvenience and / or additional delay. For example, the wireless device may be forced to select a new cell in order to obtain service via the allowed slice, or alternatively, forego the benefits of the allowed slice. In contrast, as Figure 18 shown, an indication that the slice is pending supports the expectations of the wireless device when making mobility decisions. For example, if the slice is pending, the base station may provide different RRC parameters, and / or the wireless device may make different mobility decisions. For example, if the slice is pending, the wireless device may not move to a cell that does not support the pending slice.
[0299] In an example embodiment, the base station may indicate to the AMF of the wireless device whether the base station supports the RAN slicing function (e.g., RAN slicing). The base station may send a parameter including a RAN slicing indicator to the AMF. In an example, the RAN slicing indicator may be a request for a pending NSSAI. The base station may include the parameter in an initial user equipment (UE) message, a UE context modification message, a handover requirement message to the AMF. In response to receiving the RAN slicing indicator from the base station, the AMF may indicate the pending NSSAI. In addition to the RAN slicing indicator, the base station may also indicate to the AMF the number of pending S-NSSAIs. The AMF may determine the number of pending S-NSSAIs to indicate to the base station based on the number of pending S-NSSAIs. In an example, the number of pending NSSAIs of the wireless device is three, including S-NSSAI 1, S-NSSAI 2, and S-NSSAI 3, and the number of pending NSSAIs indicated by the base station is two. The AMF may indicate two of the three S-NSSAIs to the base station and exclude one S-NSSAI. The AMF determines the two S-NSSAIs based on the local policy of the S-NSSAI and / or the configured priority information. This exemplary embodiment may be beneficial for heterogeneous deployment scenarios where some base stations may not support RAN slicing or RAN slicing of pending NSSAIs.
[0300] In an example, the AMF may determine at least one second network slice, and the at least one second network slice may be allowed to be used by the wireless device to establish a Packet Data Unit (PDU) session. The at least one second network slice may be an allowed NSSAI. The N2 message also includes the allowed NSSAI. The AMF may send an N2 message including a pending NSSAI and an allowed NSSAI. The base station may receive an N2 message including a pending NSSAI and an allowed NSSAI. The base station may prioritize the frequency / band / cell associated with the allowed NSSAI over the frequency / band / cell associated with the pending NSSAI. The pending NSSAI may be a potentially allowed NSSAI. In an example, if the NSSAA is successful, the pending NSSAI may become an allowed NSSAI. If the wireless device has valid credentials for the pending S-NSSAI, the pending NSSAI will be an allowed NSSAI. In an example, if the NSSAA fails, the pending NSSAI may be changed to a rejected NSSAI. The AAA server may revoke the authentication / authorization of the wireless device for a specific S-NSSAI after the credentials are provided to the wireless device. If the AAA service revokes the authentication / authorization of the wireless device, the credentials of the wireless device may be invalid, and the NSSAA may fail. In an example, the pending NSSAI becomes a rejected NSSAI, which depends on the credential validity. For the case where the NSSAA fails for the wireless device, it may be beneficial to prioritize the allowed NSSAI over the pending NSSAI for RRC parameter configuration.
[0301] In an example, the N2 message (e.g., RAN message, NG message) may be an initial context setup message. The N2 message may be a handover request message. The N2 message may be a path switch request confirmation message.
[0302] Figure 19 An exemplary embodiment is shown, where the base station may determine the handover of the wireless device based on the pending network slice. A registration procedure may be performed between the wireless device, the first base station, and the AMF, as Figure 16 explained. After the registration procedure, the AMF may provide the pending NSSAI to the first base station, as Figure 17 explained.
[0303] In an example, the second base station may be an adjacent base station of the first base station. The second base station may send a support list of one or more S-NSSAIs during a base station setup (e.g., Xn setup procedure, NG-RAN node configuration update) procedure. The first base station may know the support list of one or more S-NSSAIs (e.g., network slices) of the second base station. The first base station may receive an N2 setup message (e.g., N2 message) including a pending NSSAI from the AMF.
[0304] In an example, the first base station may not support one or more of the pending S-NSSAIs in the pending NSSAI. The first base station may experience a shortage of resources for one or more of the pending S-NSSAIs. The second base station may support one or more of the pending S-NSSAIs in the pending NSSAI, and the resource situation (e.g., congestion) may be better than that of the first base station.
[0305] The first base station may receive one or more measurement reports from the wireless device, and the measurement reports include one or more cells / frequencies of the second base station suitable for residence. In an example, the signal quality / level of one or more cells / frequencies of the second base station may be higher than the handover threshold. The first base station may determine a handover to a cell (e.g., target cell) of the second base station based on the pending NSSAI. The first base station may determine a handover to a cell of the second base station based on the pending NSSAI, a support list of one or more S-NSSAIs of the second base station, the resource situations of the first base station and the second base station, the measurement reports from the wireless device, etc.
[0306] The first base station may send a handover request message to the second base station. The handover request message may include the pending NSSAI. The handover request message may further include the allowed NSSAI, the target cell ID (e.g., the identity of the cell), information for security key derivation, the RAN identity of the wireless device in the first base station, the radio resource management (RRM) configuration including the wireless device inactivity time, the basic access stratum (AS) configuration including antenna information and downlink carrier frequency, the current QoS flow to data radio bearer (DRB) mapping rule applied to the wireless device, the SIB1 (e.g., broadcast system information) of the first base station (e.g., source gNB), the wireless device capabilities, PDU session related information, and may include UE-reported measurement information, including beam-related information (if available).
[0307] The second base station may receive the handover request message from the first base station. The second base station may determine whether to accept the handover request based on the pending NSSAI, the allowed NSSAI, etc. The second base station may perform slice-aware admission control based on the pending NSSAI. If the second base station accepts the handover request from the first base station, the second base station may send a handover request confirmation message to the first base station. The second base station may send a handover request confirmation message to the first base station based on the determination. The first base station may also perform the handover procedure of the wireless device to the second base station. In response to the handover decision, the first base station may send an RRC reconfiguration message to the wireless device, and the RRC reconfiguration message may include the information required to access the cell of the second base station.
[0308] In the prior art, a wireless device may request a slice, and there may be a delay when the wireless device waits for an indication that the requested slice is permitted or denied. For example, the delay may be caused by authentication and / or authorization procedures associated with the slice. While waiting for this indication, a base station associated with the wireless device may make a handover decision associated with the wireless device. This may result in the mobility of the wireless device to a cell that does not support the requested slice. Later, if an indication that the slice is permitted arrives, the wireless device may have already handed over to a non-supporting cell, resulting in inconvenience and / or additional delay. For example, the wireless device may be forced to select a new cell in order to obtain service via the permitted slice, or alternatively, forgo the benefits of the permitted slice. In contrast, as Figure 19 shown, an indication that the slice is pending supports the expectations of the base station and / or the wireless device when making handover decisions. For example, if the slice is pending, the base station can avoid handover, select a different handover target, etc.
[0309] Figure 20 shows an exemplary embodiment in which the RRC connection of the wireless device is maintained based on the AMF indicating to the base station that the network slice is pending. For example, the AMF can indicate to the base station that NSSAA will be performed for the wireless device. Figure 20 shows how the AMF indicates the NSSAA to be performed for the wireless device between the wireless device, the base station, and the AMF. In the example, the registration procedure can be performed as explained in Figure 16 . Based on the registration procedure, the AMF determines that at least one S-NSSAI is pending for NSSAA. The AMF can send an N2 setup message that includes an indicator indicating the existence of a pending NSSAA. The indicator can indicate that the NSSAA is pending and will be performed for the wireless device. In the example, if no PDU session is established for the wireless device and no data radio bearer (DRB) is allocated for the wireless device, the AMF can provide the indicator.
[0310] In the example, all S-NSSAIs of the requested NSSAI or the configured NSSAI of the wireless device may be subject to NSSAA based on the subscription information. In the example, all available S-NSSAIs of the wireless device may be subject to NSSAA based on the subscription information. In the example, the AMF can determine that there is no permitted S-NSSAI for the wireless device or that the permitted NSSAI is empty. If there is no permitted NSSAI, the wireless device may not request PDU session establishment from the wireless device. In the example, the AMF can provide the permitted NSSAI and the pending NSSAI by sending a NAS message that includes the permitted NSSAI and the pending NSSAI. The wireless device may not need any services associated with the permitted NSSAI for a certain period of time, so the wireless device may not request any PDU sessions with the SMF.
[0311] The base station may receive an indicator indicating that the NSSAA is pending or will be executed. In the prior art, if the base station detects the inactivity of a wireless device (e.g., no uplink / downlink data is transmitted within a specific time period), the base station may request a connection release with the wireless device from the AMF. If the base station receives the indicator, the base station may maintain (e.g., extend) the connection with the wireless device. If the base station receives the indicator, the base station may delay / postpone the connection release with the wireless device. When detecting the inactivity of the wireless device based on an indicator indicating that the NSSAA will be executed (e.g., there is a pending NSSAI), the base station may not send a release request to the AMF. The base station may extend the inactivity timer of the wireless device based on the indicator. When maintaining the RRC connection for the wireless device, the NSSAA procedure may be completed. If the NSSAA is completed, the AMF may provide the allowed NSSAI for the wireless device that sends a NAS message including the allowed NSSAI. The AMF may send a second N2 message including the allowed NSSAI and indicate it to the base station. In response to receiving the allowed NSSAI, the wireless device may send a PDU session establishment request message to the SMF via the AMF. This exemplary embodiment may reduce connection transactions (e.g., connection mode to idle mode, idle mode to connection mode) by enabling the base station to maintain the RRC connection based on the existence of the pending NSSAI.
[0312] In the example, the AMF may indicate to the base station that the connection should be maintained within a specific time period. The AMF may indicate to the base station that the connection should be maintained so that the base station can wait for the completion of the NSSAA. This exemplary embodiment may be beneficial when maintaining the connection is not only for the pending NSSAI situation but also for general use between the base station and the AMF.
[0313] In the prior art, the wireless device may request a slice, and there may be a delay when the wireless device waits for an indication that the requested slice is allowed or denied. For example, the delay may be caused by the authentication and / or authorization procedure associated with the slice. When waiting for the indication, the wireless device and / or the base station may release the connection of the wireless device. The release may be based on, for example, the inactivity of the wireless device. For example, when waiting for the authentication and / or authorization of the slice, the inactivity mechanism may cause the wireless device to lose the RRC connection. Later, if an indication that the slice is allowed arrives, the wireless device may have to establish an RRC connection before obtaining service via the slice, resulting in inconvenience and / or additional delay. In contrast, as Figure 20As shown, a slice being pending indicates the expectations of the wireless device and the base station when managing the connection of the wireless device. For example, if the slice is pending, the wireless device and / or the base station may maintain the RRC connection, avoid releasing the RRC connection, etc. For example, if the slice is pending, the wireless device and / or the base station may prevent the inactivity timer from expiring (pausing, extending, restarting, etc.).
[0314] Figure 21 Shows the format of an N2 message (e.g., RAN message, NG message) as an exemplary embodiment. The N2 message may be an NGAP message. As Figures 18 to 20 part of the embodiment, the AMF may send an N2 message to the base station. The N2 message may include an AMF UE NGAP ID, a RAN UE NGAP ID, a permitted NSSAI, an indicator indicating the NSSAA to be performed, a pending NSSAI, a mobility restriction list, etc. The AMF UE NGAP ID may uniquely identify the UE association on the NG interface (e.g., N2 interface) within the AMF side. The RAN UE NGAP ID may uniquely identify the UE association on the NG interface within the NG-RAN side. The AMF UE NGAP ID and the RAN UE NGAP may be mandatory information elements (IEs) of this N2 message. The permitted NSSAI may include at least one S-NSSAI that is permitted for the PDU session establishment of the wireless device. The permitted NSSAI may be a conditional IE. In an example, all S-NSSAIs may be pending for the NSSAA, and there may be no permitted NSSAI. If there is no permitted NSSAI for the wireless device, the AMF may not conditionally provide the permitted NSSAI. If at least one S-NSSAI is permitted for the wireless device, the AMF may provide a permitted NSSAI including at least one S-NSSAI. The indicator indicating the NSSAA to be performed may be an optional IE. If all NSSAIs are pending for the NSSAA and no S-NSSAI is permitted for the wireless device, the AMF sets the indicator in this N2 message. If there is a pending NSSAI for the wireless device, the pending NSSAI may be optional and provided by the AMF. Providing the pending NSSAI message from the AMF to the base station in the N2 message may be based on the RAN slice indicator from the base station or the local policy from the AMF. The mobility restriction list may be optional for the wireless device.
[0315] Figure 22 、 Figure 23 is an exemplary flowchart as part of an exemplary embodiment.
[0316] In Figure 22Among them, the AMF can receive a non-access stratum (NAS) request message indicating the requested NSSAI from the wireless device. In an example, the NAS message can be a registration request message. The requested NSSAI can include at least one requested S-NSSAI. The requested S-NSSAI can be a network slice where the wireless device can request service requests. The AMF can determine at least one first network slice of the pending network slice specific authentication and authorization (NSSAA). This determination can be based on the requested NSSAI and the subscription information about the network slice. In an example, if the requested S-NSSAI in the requested NSSAI complies with NSSAA based on the subscription information, the AMF determines that the requested S-NSSAI is at least one first network slice of the pending NSSAA. In an example, in addition to the requested NSSAI, the AMF can determine at least one first network slice of the pending NSSAA. The AMF can select an appropriate S-NSSAI not from the requested S-NSSAI but from the subscribed S-NSSAI. The appropriate S-NSSAI can comply with NSSAA based on the subscription information. The appropriate S-NSSAI can be at least one network slice of the pending NSSAA. The UDM can provide subscription information to the AMF during the registration procedure. The AMF can indicate at least one first network slice of the pending NSSAA by sending a RAN message including at least one first network slice of the pending NSSAA.
[0317] In Figure 23Among them, the base station can receive RAN messages of the wireless device from the AMF. The RAN message includes the pending NSSAI of NSSAA. The pending NSSAI may include at least one first network slice of the pending NSSAA. The base station can indicate to the AMF to provide the pending NSSAI. The base station can indicate to the AMF the RAN slice information required by the wireless device. The base station can indicate to the AMF that the base station supports RAN slices. In response to the indication from the base station, the AMF may provide the pending NSSAI. In response to receiving the pending NSSAI, the base station can determine the radio resource control (RRC) parameters of the wireless device based on the pending NSSAI. The RAN message may also include the permitted NSSAI of the wireless device. The base station can determine the RRC parameters of the wireless device based on the permitted NSSAI and the pending NSSAI. The base station can prioritize the permitted NSSAI over the pending NSSAI. In an example, the RRC parameters may include a list of frequencies / frequency bands for idle mode mobility. The base station can allocate the frequencies / frequency bands associated with the permitted NSSAI with a higher priority than the frequencies / frequency bands associated with the pending NSSAI. For idle mode mobility (e.g., cell reselection) / connected mode mobility or measurement reporting, the base station can prioritize the frequencies / frequency bands associated with the pending NSSAI over the frequencies / frequency bands not associated with the pending NSSAI. The base station can send an RRC message including the RRC parameters to the wireless device based on the determination. The RRC message can be an RRC reconfiguration message. The RRC parameters may include idle mode mobility parameters, connected mode mobility parameters, and measurement reporting related parameters.
[0318] In an example, the access and mobility management function (AMF) can receive a non-access stratum (NAS) request message from the wireless device indicating one or more network slices. The AMF can determine at least one first network slice among one or more network slices of the pending network slice specific authentication and authorization (NSSAA). The AMF can be a radio access network (RAN) message that indicates at least one first network slice of the pending NSSAA to the base station.
[0319] In an example, the AMF can send a NAS response message to the wireless device via the base station. The NAS response message includes at least one first network slice of the pending NSSAA.
[0320] In an example, the AMF can receive parameters from the base station indicating the RAN slice support required by the wireless device. In response to receiving the parameters from the base station, the AMF can send a RAN message indicating at least one first network slice of the pending NSSAA to the base station. These parameters can further indicate the number of network slices supported by the RAN slice. The AMF can determine the number of at least one first network slice including the RAN message based on the number of network slices supported by the RAN slice.
[0321] In an example, the AMF may further determine at least one second network slice, and the at least one second network slice is allowed to be used by the wireless device to establish a Packet Data Unit (PDU) session. The RAN message may further indicate the at least one second network slice.
[0322] In an example, the RAN message may further indicate the NSSAA to be performed for the wireless device. The AMF may indicate that the NSSAA is to be performed based on: no network slice is allowed for the wireless device to establish a Packet Data Unit (PDU) session; and the pending NSSAI of the NSSAA.
[0323] The NAS request message may further include an indication of the wireless device's capabilities for the NSSAA. Determining the pending NSSAI may be based on the capabilities indication.
[0324] The AMF may receive a Non-Access Stratum (NAS) request message from the wireless device that includes a requested Network Slice Selection Assistance Information (NSSAI). The AMF may determine the pending NSSAI of the Network Slice Specific Authentication and Authorization (NSSAA) based on the requested NSSAI. The AMF may send a Radio Access Network (RAN) message including the pending NSSAI to the base station.
[0325] In an example, the base station may receive a Radio Access Network (RAN) message from the Access and Mobility Management Function (AMF), the message including the pending Network Slice Selection Assistance Information (NSSAI) of the Network Slice Specific Authentication and Authorization (NSSAA). The base station may determine the Radio Resource Control (RRC) parameters of the wireless device based on the pending NSSAI. The base station may send an RRC message including the RRC parameters to the wireless device. The RRC parameters include at least one of the frequency / band priority of the idle mode mobility of the wireless device, the frequency / band priority of the connected mode mobility of the wireless device, the measurement report configuration of the wireless device, etc.
[0326] The base station may send parameters indicating RAN slice support to the AMF. Receiving the pending NSSAI may be based on RAN slice support.
[0327] The pending NSSAI may include at least one single NSSAI (S-NSSAI) for which the NSSAA is to be performed. The RAN message may further include the allowed NSSAI of the wireless device. The allowed NSSAI may include at least one single NSSAI that is allowed by the wireless device to establish a Packet Data Unit (PDU) session. For determining the RRC parameters, the base station may prioritize the allowed NSSAI over the pending NSSAI.
[0328] The RAN message can be an initial context setup message. The RAN message can be a handover request message. The RAN message can be a path switch request confirmation message. The base station can maintain the connection setup with the wireless device based on the pending NSSAI.
[0329] The base station can receive a radio access network (RAN) message from the access and mobility management function (AMF), the message including the pending network slice selection assistance information (NSSAI) of network slice specific authentication and authorization (NSSAA). The base station can determine to hand over the wireless device to a second base station based on the pending NSSAI. In response to this determination, the base station can send an RRC message indicating the handover to the second base station to the wireless device.
[0330] The access and mobility management function (AMF) can receive a non-access stratum (NAS) request message from the wireless device indicating one or more network slices. The AMF can determine that at least one first network slice in the one or more network slices has pending network slice specific authentication and authorization (NSSAA). The AMF can send a radio access network (RAN) message indicating the NSSAA to be performed for the wireless device to the base station based on this determination. The AMF can receive parameters indicating the RAN slice support of the wireless device from the base station. Sending the RAN message including the pending NSSAI can be based on these parameters.
[0331] In an example, the base station can receive a radio access network (RAN) message from the access and mobility management function (AMF), the message indicating the network slice specific authentication and authorization (NSSAA) to be performed for the wireless device. The base station can detect data transmission and reception inactivity with the wireless device. In response to detecting the inactivity, the base station can maintain the radio resource control (RRC) connection with the wireless device based on the RAN message indicating the NSSAA to be performed.
[0332] The base station can receive the allowed network slice selection assistance information (NSSAI) of the wireless device from the AMF. The AMF can receive a second RAN message that requests a packet data unit (PDU) session establishment request for the allowed NSSAI.
[0333] In this specification, "a", "an", and similar phrases will be interpreted as "at least one" and "one or more". In this specification, the term "may" is interpreted as, for example, "can". In other words, the term "may" indicates that the phrase following the term "may" is an example of one of the various suitable possibilities that may or may not be used in one or more of the various embodiments. If A and B are sets and every element of A is also an element of B, then A is called a subset of B. In this specification, only non-empty sets and subsets are considered. For example, the possible subsets of B = {cell1, cell2} are: {cell1}, {cell2}, and {cell1, cell2}.
[0334] In this specification, a parameter (information element: IE) may include one or more objects, and each of those objects may include one or more other objects. For example, if parameter (IE) N includes parameter (IE) M, and parameter (IE) M includes parameter (IE) K, and parameter (IE) K includes parameter (information element) J, then, for example, N includes K and N includes J. In an exemplary embodiment, when one or more messages include multiple parameters, this means that the parameters among the multiple parameters are in at least one of the one or more messages, but not necessarily in each of the one or more messages.
[0335] Many of the elements described in the disclosed embodiments can be implemented as modules. A module is herein defined as a separable element that performs a defined function and has a defined interface to other elements. The modules described in this disclosure can be implemented in hardware, software in combination with hardware, firmware, wetware (i.e., hardware with biological elements), or a combination thereof, all of which can be behaviorally equivalent. For example, a module can be implemented as a software routine written in a computer language configured to be executed by a hardware machine (such as C, C++, Fortran, Java, Basic, Matlab, etc.) or a modeling / simulation program (e.g., Simulink, Stateflow, GNU Octave, or LabVIEW MathScript). Additionally, it is possible to implement a module using physical hardware incorporating discrete or programmable analog, digital, and / or quantum hardware. Examples of programmable hardware include: computers; microcontrollers; microprocessors; application-specific integrated circuits (ASICs); field-programmable gate arrays (FPGAs); and complex programmable logic devices (CPLDs). Computers, microcontrollers, and microprocessors are programmed using languages such as assembly, C, C++. FPGAs, ASICs, and CPLDs are often programmed using hardware description languages (HDLs), such as VHSIC hardware description language (VHDL) or Verilog, which configure the connections between less-functional internal hardware modules on the programmable device. Finally, it should be emphasized that the above techniques are often used in combination to achieve the results of functional modules.
[0336] Exemplary embodiments of the present invention can be implemented using a variety of physical and / or virtual network elements, software-defined networks, virtual network functions.
[0337] The disclosure of this patent document incorporates copyrighted material. The copyright owner does not object to anyone making a facsimile reproduction of the patent document or the patent disclosure as it appears in the patent and trademark office patent file or records for the limited purposes as required by law, but reserves all copyright rights in all other respects.
[0338] Although the various embodiments have been described above, it should be understood that they have been presented by way of example and not limitation. It will be apparent to those skilled in the relevant art that various changes may be made in form and detail without departing from the spirit and scope of the present disclosure. In fact, after reading the above description, it will be apparent to those skilled in the relevant art how to implement alternative embodiments. Accordingly, the current embodiments should not be limited by any of the above exemplary embodiments. In particular, it should be noted that, for purposes of illustration, the above explanations have focused on examples using 5G AN. However, those skilled in the art will recognize that embodiments of the present invention may also be implemented in systems including one or more legacy systems or LTE. The disclosed methods and systems may be implemented in wireless or wired systems. The features of the various embodiments presented in the present invention may be combined. One or more features (methods or systems) of one embodiment may be implemented in other embodiments. A limited number of example combinations are shown to indicate to those skilled in the art the possibilities of features that may be combined in various embodiments to create enhanced transmission and reception systems and methods.
[0339] In addition, it should be understood that any figures highlighting features and advantages are presented for purposes of illustration only. The disclosed architecture is flexible and configurable enough such that it may be utilized in ways different from those shown. For example, the actions listed in any flowchart may be reordered or optionally used in certain embodiments.
[0340] Furthermore, the purpose of the abstract of the present disclosure is to generally enable the United States Patent and Trademark Office and the public, especially scientists, engineers, and practitioners in the field who are not familiar with patent or legal terms or phrases, to quickly determine the nature and substance of the technical disclosure of the present application by a cursory review. The abstract of the present disclosure is not intended to limit the scope in any way.
[0341] Finally, the applicant's intention is that only claims that include the recitation language "means for..." or "step for..." are to be construed under 35 U.S.C. 112. Claims that do not expressly include the phrase "means for..." or "step for..." should not be construed under 35 U.S.C. 112.
Claims
1. A communication method, comprising: receiving, by an access and mobility management function (AMF) from a base station, a non-access stratum (NAS) request message of a wireless device, the NAS request message including single network slice selection assistance information (S-NSSAI) corresponding to one or more network slices; determining, by the AMF, to perform network slice specific authentication and authorization (NSSAA) for a first network slice among the one or more network slices; and sending, by the AMF to the base station based on the determination, an N2 setup message, the N2 setup message including an indication that the first network slice is pending.
2. The method according to claim 1, wherein the NAS request message is a registration request message of the wireless device.
3. The method according to claim 1, further comprising sending, by the AMF via the base station to the wireless device, a NAS response message based on determining to perform the NSSAA, the NAS response message including the indication that the first network slice is pending.
4. The method according to claim 1, wherein the indication that the first network slice is pending includes the S-NSSAI of the first network slice.
5. The method according to claim 1, wherein the indication that the first network slice is pending indicates one or more of the following: performing or about to perform NSSAA for the first network slice; and the NSSAA of the first network slice is not completed.
6. The method according to claim 1, wherein the indication that the first network slice is pending is included in a radio access network (RAN) message.
7. The method according to claim 6, wherein the RAN message is one or more of the following: an N2 message; an initial context setup message; a handover request message; and a path switch request acknowledgement message.
8. The method according to claim 1, further comprising: sending, by the AMF to an authentication and / or authorization function, an authentication and / or authorization request for the first network slice based on the first network slice that requires NSSAA; and receiving, by the AMF from the authentication and / or authorization function, an indication that the first network slice is authenticated and / or authorized.
9. The method according to claim 8, further comprising one or more of the following: sending, by the AMF to the base station, an indication that the first network slice is allowed based on the indication that the first network slice is authenticated and / or authorized; and sending, by the AMF to the wireless device, a NAS message indicating that the first network slice is allowed based on the indication that the first network slice is authenticated and / or authorized.
10. The method according to claim 9, further comprising receiving, by the AMF via the base station from the wireless device, a session establishment request associated with the first network slice.
11. An access and mobility management function (AMF), the access and mobility management function comprising one or more processors and a memory storing instructions, the instructions when executed by the one or more processors cause the access and mobility management function to perform operations, the operations including: The AMF receives a non-access stratum (NAS) request message of a wireless device from a base station, the NAS request message including single network slice selection assistance information (S-NSSAI) corresponding to one or more network slices; The AMF determines to perform network slice specific authentication and authorization (NSSAA) on a first network slice among the one or more network slices; and Based on the determination, the AMF sends an N2 setup message to the base station, the N2 setup message including an indication that the first network slice is pending.
12. The AMF according to claim 11, further comprising, based on determining to perform the NSSAA, the AMF sending a NAS response message to the wireless device via the base station, the NAS response message including the indication that the first network slice is pending.
13. The AMF according to claim 11, wherein the indication that the first network slice is pending includes the S-NSSAI of the first network slice.
14. The AMF according to claim 11, wherein the indication that the first network slice is pending indicates one or more of the following: NSSAA is being performed or will be performed for the first network slice; and The NSSAA of the first network slice is not completed.
15. The AMF according to claim 11, wherein the indication that the first network slice is pending is included in a radio access network (RAN) message.
16. The AMF according to claim 15, wherein the RAN message is one or more of the following: N2 message; Initial context setup message; Handover request message; and Path switch request acknowledgment message.
17. The AMF according to claim 11, further comprising: Based on the first network slice that requires NSSAA, the AMF sends an authentication and / or authorization request for the first network slice to an authentication and / or authorization function; and The AMF receives an indication that the first network slice is authenticated and / or authorized from the authentication and / or authorization function.
18. The AMF according to claim 17, further comprising one or more of the following: Based on the indication that the first network slice is authenticated and / or authorized, the AMF sends an indication that the first network slice is permitted to the base station; and Based on the indication that the first network slice is authenticated and / or authorized, the AMF sends a NAS message indicating that the first network slice is permitted to the wireless device.
19. The AMF according to claim 18, further comprising the AMF receiving a session establishment request associated with the first network slice from the wireless device via the base station.
20. A communication system, comprising: An access and mobility management function (AMF), the access and mobility management function including one or more first processors and a first memory storing first instructions, the first instructions, when executed by the one or more first processors, cause the AMF to: Receive a non-access stratum (NAS) request message of a wireless device from a base station, the NAS request message including single network slice selection assistance information (S-NSSAI) corresponding to one or more network slices; Determine to perform network slice specific authentication and authorization (NSSAA) for a first network slice among the one or more network slices; And Send an N2 setup message to the base station based on the determination, the N2 setup message including an indication that the first network slice is pending; And A base station, the base station including: one or more second processors and a second memory storing second instructions, the second instructions causing the base station, when executed by the one or more second processors: Send the NAS request message to the AMF; And Receive the N2 setup message from the AMF, the N2 setup message including an indication that a first network slice among the one or more network slices is pending.