Method for handling non-integrity protected reject message and user equipment thereof
By utilizing multiple access technology and a rejection counter mechanism in 5G systems, the UE can retry other access networks after receiving a non-integrity protection rejection message. This solves the problem of UEs being vulnerable to fraudulent network attacks in 5G systems and achieves effective processing and service protection of non-integrity protection rejection messages.
Patent Information
- Application Number
- CN202310490278.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2018-04-23
- Filing Date
- 2019-04-23
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2039-04-23
AI Technical Summary
The lack of an effective mechanism for handling non-integrity protection rejection messages in 5G systems makes UEs vulnerable to denial-of-service attacks by fraudulent networks.
After receiving a non-integrity protection rejection message, the UE retryes other access networks, including 3GPP and non-3GPP access networks, using multiple access technology. It selects a suitable access network for retrying using a rejection counter and priority rules until successful registration.
It enables effective handling of non-integrity protection denial messages, protects UEs from denial-of-service attacks by fraudulent networks, and improves the robustness and reliability of the system.
Smart Images

Figure CN116582852B_ABST
Abstract
Description
[0001] Cross-references
[0002] The present invention claims the benefit of priority under 35 U.S.C. §119 to U.S. Provisional Patent Application No. 62 / 661,221, filed April 23, 2018, and entitled “Improvement to handling of non-integrity protected reject messages in 5G,” the entire contents of which are incorporated herein by reference. Technical Field
[0003] Embodiments of the present invention generally relate to a wireless communication system, and more particularly, to a method for processing a non-integrity protection reject message in a fifth generation communication system. Background Art
[0004] In recent years, wireless communication networks have grown at an exponential rate. Long-Term Evolution (LTE) systems offer high peak data rates, low latency, improved system capacity, and lower operating costs due to their simplified network architecture. LTE systems, also known as 4G systems, provide seamless integration with older wireless systems such as GSM, CDMA, and the Universal Mobile Telecommunications System (UMTS). Third Generation Partnership Project (3GPP) networks typically include a convergence of 2G / 3G / 4G systems. With the development and deployment of the 5G system (5GS), 5GS allows for multiple access points to the network, including both 3GPP and non-3GPP access. With the optimization of network design, numerous improvements have been made based on the evolution of various standards. With the development of 5GS, base stations (gNBs) will support reduced UE bandwidth capabilities within wideband carriers and reduce UE power consumption through bandwidth adaptation.
[0005] The main function of Session Management (SM) for 2G / 3G systems or Evolved Packet System (EPS) SM (EPS SM, ESM) for 4G systems is to support Packet Data Protocol (PDP) context or EPS bearer processing for user terminals. Upon receiving a registration request message, the network may reject the request using a reason code. For different reason codes, the network may provide a retry mechanism for the user, and resend the SM / ESM request if certain conditions are met. However, for some specific reason codes, the UE is not allowed to apply the retry mechanism and resend another SM / ESM request unless the UE is turned off or the USIM is removed. Therefore, these reason codes may result in a permanent rejection of data services provided to the user. Traditional systems such as EPS specify protection mechanisms to protect UEs from service denial attacks against mobile terminals from fraudulent networks. With the development of 5GS, UEs can access the 5GS core network (CN) via 3GPP access and non-3GPP access. 5GS does not have a protection mechanism against denial of service attacks against mobile terminals from rogue networks, and the multiple access characteristics of 5GS need to be considered. Summary of the Invention
[0006] A method and apparatus for processing a non-integrity rejection message in a 5G system are provided. In one novel aspect, in attempting a 5G mobility management (5GMM) process to a core network (CN), once a UE receives a rejection message via one access without integrity protection, the UE retries one or more other accesses before processing the rejection fact. In one embodiment, if the UE determines that an alternative access to the CN is provided via the same cell / tracking area (TA), the UE attempts the same 5GMM process on another access in the same cell / TA. Alternative accesses include other types of 3GPP access and non-3GPP access, such as WiFi access. Second, the UE may search for services from another cell / TA, and third, the UE may search for another public land mobile network (PLMN). In one embodiment, if a UE attempting a 5GMM process to the CN receives a rejection cause that invalidates the UE using one access without integrity protection, the UE attempts the system several times before processing the rejection fact by tracking an invalid counter, the invalid counter being incremented by one each time a rejection with a cause value that invalidates the UE is received.
[0007] In one embodiment, the UE updates one or more corresponding reject counters based on the first access network and the first PLMN, wherein each reject counter counts corresponding registration rejects received without integrity protection and attempts for new registration requests based on registration rules. In one embodiment, the registration rule allows the new registration request involving the selected access network and the selected PLMN upon determining that one or more registration conditions are satisfied based on predefined registration selection criteria, wherein the selection criteria allow selection of a non-3GPP network. In one embodiment, the registration rule selects eligible access networks in descending priority, including: selecting an available access network in the same cell or same TA as the first access network; selecting an available access network in the same PLMN as the first access network but in a different TA; and selecting an available access network in a different PLMN. In another embodiment, the registration rule selects eligible access networks for the new registration request from the 5GS or EPS in descending priority, including the following networks: same access network, different 3GPP access network, and non-3GPP access network. In yet another embodiment, the second access network is eligible if the updated reject counter for the second access network is less than a preconfigured registration maximum for the second access network.
[0008] In one embodiment, the one or more reject counters include a retry counter that increases by one for each registration request sent by the UE. In another embodiment, the registration condition includes the retry counter being less than a preconfigured maximum value of the UE's retry counter. In one embodiment, the 5GS supports EPS, and wherein the one or more reject counters include an invalidation counter that is updated for each registration reject with a cause value, wherein the cause value indicates a non-integrity protection reject that invalidates the UE. In another embodiment, the UE does not consider a rejection valid until the invalidation counter is greater than or equal to a preconfigured maximum value of the invalidation counter. In one embodiment, the UE resets the one or more reject counters upon receiving a registration accept message from the 5GS or EPS.
[0009] In another embodiment, a UE configured to process a non-integrity protection reject message includes one or more radio frequency transceiver modules configured to transmit and receive radio signals in one or more corresponding radio networks in a 5GS. The UE also includes registration request circuitry configured to transmit a registration request on a first access network connected to a first public land mobile network, wherein the UE is capable of accessing a core network in the 5GS via multiple access networks, wherein the multiple access networks include one or more 3GPP networks and at least one non-3GPP network. The UE also includes registration response circuitry configured to receive a registration reject from the 5GS with a cause value indicating a non-integrity protection reject that invalidates the UE. The UE further includes counter circuitry configured to update one or more corresponding reject counters based on the first access network and the first public land mobile network, wherein each reject counter counts corresponding registration rejects received without integrity protection. The UE further includes retry circuitry configured to attempt a new registration request based on registration rules, wherein the registration rules allow the new registration request involving a selected access network and a selected public land mobile network upon a determination based on predefined registration selection criteria that one or more registration conditions are satisfied, and wherein the selection criteria allow selection of a non-3GPP network.
[0010] The present invention proposes a method for processing non-integrity protection rejection messages and a user device thereof, and utilizes the 5G multiple access feature to achieve the beneficial effect of a protection mechanism against service denial attacks on mobile terminals from fraudulent networks.
[0011] Other embodiments and advantages are described in the detailed description below. This summary is not intended to define the invention. The invention is defined by the claims. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] The accompanying drawings are used to describe embodiments of the present invention, wherein like numerals indicate like components.
[0013] Figure 1 An exemplary 5G system 100 with 3GPP access and non-3GPP access is shown according to one novel aspect.
[0014] Figure 2 A simplified block diagram of a user equipment and a base station is shown according to an embodiment of the present invention.
[0015] Figure 3 According to an embodiment of the present invention, a schematic diagram of a 5G system with multiple access and a UE accessing the network through different access networks is shown.
[0016] Figure 4 According to an embodiment of the present invention, a schematic diagram of a retry process for processing a non-integrity protection rejection message received by a UE in a 5GS is shown.
[0017] Figure 5 According to an embodiment of the present invention, a schematic flow chart of a UE retry process performed upon receiving a non-integrity protection reject message before the UE is considered invalid is shown.
[0018] Figure 6 According to an embodiment of the present invention, a schematic flow chart is shown of a UE retry process and successful registration upon receiving a non-integrity protection reject message.
[0019] Figure 7 According to an embodiment of the present invention, a schematic flow chart of a UE processing a non-integrity protection rejection message in a 5G system is shown. DETAILED DESCRIPTION
[0020] Reference will now be made in detail to some embodiments of the present invention, examples of which are illustrated in the accompanying drawings.
[0021] Figure 1An exemplary 5G system 100 with 3GPP access and non-3GPP access is shown according to one novel aspect. The 5G system 100 is a PLMN or equivalent public land mobile network (EPLMN) that supports one or more radio access technology (RAT) networks, which one or more RAT networks include 3GPP networks, such as 5G, 4G / LTE systems, 3G systems, and possibly 2G systems (not shown). Each 3GPP system has fixed infrastructure units (e.g., 3GPP base stations 102) to form a wireless network distributed over a geographic area. The infrastructure unit may also be referred to as a next generation NodeB (gNB), an access point, an access terminal, a base station, a NodeB, an evolved NodeB, or other terms used in the art. The 3GPP wireless base station is connected to an access and mobility management function (AMF) unit 121 for control plane operations. The 3GPP base station 102 is connected to the system architecture evolution (SAE) gateway 111 via the S1 interface, wherein the SAE gateway 111 includes a serving gateway (S-GW) and a packet data network (PDN) gateway (P-GW). The 3GPP base station 102 may also include a radio network controller (RNC). The RNC of the 3G system is connected to a serving GPRS support node (SGSN) connected to the SAE gateway 111. The 5G system 100 may also have a non-3GPP base station 103. Each of the 3GPP base station 102 and the non-3GPP base station 103 serves a geographical area. The non-3GPP base station may be a WiFi access point (AP). The UE 101 is connected to the non-3GPP base station 103 via a non-3GPP radio link protocol (e.g., WiFi). The non-3GPP base station 103 is connected to a non-3GPP interworking function (IWF) unit 122 for control plane communication. The non-3GPP base station 103 is connected to a non-3GPP access gateway 112 for data plane communication with the network. In the 5G system 100, the PLMN / EPLMN 110 may include 3GPP network entities and non-3GPP network entities.The 3GPP network in the PLMN may also include different system protocols.
[0022] Figure 2 A simplified block diagram of a UE 201 and a base station (BS) 202 is shown according to an embodiment of the present invention. BS 202 has an antenna 226 for transmitting and receiving radio signals. An RF transceiver module 223, coupled to antenna 226, receives RF signals from antenna 226, converts the RF signals into baseband signals, and transmits them to a processor 222. RF transceiver module 223 also converts baseband signals received from processor 222, converts the baseband signals into RF signals, and transmits them to antenna 226. Processor 222 processes the received baseband signals and invokes various functional modules to execute features within base station 202. Memory 221 stores program instructions and data 224 to control the operation of base station 202. Base station 202 also includes a set of control circuits, such as a registration controller 225, which performs the functional tasks of handling non-integrity protection rejection messages in 5G. These functions can be implemented in software, firmware, or hardware. Base station 202 is connected to an AMF unit 250 for control plane operations, which includes a UE registration controller 251.
[0023] Similarly, UE 201 has an antenna 235 that transmits and receives radio signals. An RF transceiver module 234 is coupled to antenna 235, receives RF signals from antenna 235, converts them to baseband signals, and transmits the baseband signals to processor 232. RF transceiver module 234 also converts baseband signals received from processor 232, converts them to RF signals, and transmits them to antenna 235. Processor 232 processes the received baseband signals and invokes various functional modules and circuits to implement features within UE 201. Memory 231 stores program instructions and data 236 to control the operation of UE 201.
[0024] UE 201 also includes a set of control modules or circuits that perform functional tasks. These functions can be implemented in software, firmware, or hardware. Controller 290 supports the processing of non-integrity protection reject messages in 5G. Registration request circuitry 291 sends a registration request on a first access network connected to a first PLMN, where the UE is capable of accessing a 5GS CN via multiple access networks, including one or more 3GPP networks and at least one non-3GPP network. Registration response circuitry 292 receives a registration reject from the 5GS with a cause value indicating a non-integrity protection reject that invalidates the UE. Counter circuitry 293 updates one or more corresponding reject counters based on the first access network and the first PLMN, each reject counter counting corresponding registration rejects received without integrity protection. Retry circuitry 294 attempts a new registration request based on registration rules. The registration rules allow a new registration request involving a selected access network and a selected PLMN upon determining that one or more registration conditions are met based on predefined registration selection criteria, wherein the selection criteria also allow for selection of a non-3GPP network.
[0025] like Figure 1 As shown, the 5G system can use multiple access technologies to connect to the network, including 3GPP access (e.g., E-UTRA and NR) and non-3GPP access (e.g., WiFi). The UE can connect to the network through different access networks. In one novel aspect, when the UE receives a non-integrity protection reject message, the UE will retry other access technologies.
[0026] Figure 3According to an embodiment of the present invention, a schematic diagram of a 5G system with a multiple access network and a UE accessing the network through different access networks is shown. UE 301 is configured to access the 5G system through multiple access networks, including 3GPP networks (e.g., E-UTRA and NR) and non-3GPP networks (e.g., wireless local area networks (WLAN)). The example 5G system is configured to have multiple cells, each cell having one or more base stations serving each cell. The base station may be a 3GPP base station, for example, base stations 311-314, 321-322, 331-334, and 341-342, or a non-3GPP base station / AP, for example, non-3GPP base stations / APs 315, 316, 323, 335, and 343. Multiple base stations serving a geographic area may also overlap. One or more serving cells form a tracking area. For example, tracking area 310 includes cells served by 3GPP base stations 311, 312, 313, and 314, and non-3GPP base stations / APs 315 and 316. Similarly, tracking area 320 includes cells served by 3GPP base stations 321 and 322, and non-3GPP base station / AP 323. Tracking area 330 includes cells served by 3GPP base stations 331, 332, and 334, and non-3GPP base station / AP 335. Tracking area 340 includes cells served by 3GPP base stations 341 and 342, and non-3GPP base station / AP 343. A PLMN may be served by one or more tracking areas or one or more cells. For example, PLMN-1 351 includes tracking areas 310 and 320. PLMN-2 352 includes tracking areas 330 and 340. As an example, UE 301 may be served by 3GPP base stations 311 and 312 in tracking area 310, 3GPP base station 321 in tracking area 320, and 3GPP base station 331 in tracking area 330. UE 301 may also be served by non-3GPP base station / AP 315 in tracking area 310, non-3GPP base station / AP 323 in tracking area 320, and non-3GPP base station / AP 335 in tracking area 330.
[0027] like Figure 3As shown, since UEs in 5GS can access the core network on multiple accesses (e.g., E-UTRA, NR, and non-3GPP), the handling of non-integrity protection reject messages requires new considerations. Once the UE receives some fatal cause values, which require the UE to consider the USIM invalid and thus result in a complete denial of service for the UE, the UE needs to consider other access options first. The handling process of non-integrity protection reject messages needs to be modified for 5GMM purposes. Existing EPS solutions designed for malicious cell operation on E-UTRA need to be improved for 5GS that allows multiple accesses (e.g., E-UTRA / NR and non-3GPP).
[0028] Figure 4 According to an embodiment of the present invention, a schematic diagram of a retry process for processing a non-integrity protection rejection message received by a UE in a 5GS is shown. In one novel aspect, upon receiving a non-integrity protection rejection message, the UE retries other accesses to the 5GS. In one embodiment, if the UE attempts a 5GMM process to the CN and receives rejection reasons #3, #6, #7, #8 (or another reason that invalidates the UE) via one access without integrity protection, then if the UE supports and the network provides alternative access to the CN, the UE is allowed to try another access several times before processing the rejection fact. This means that in the first stage, if the UE determines that alternative access to the CN can be provided via the same cell / TA, the UE can try the same 5GMM process on another access in the same cell / TA. In the second stage, the UE can search for services in another cell / TA, and in the third stage, the UE can search for another PLMN. In another embodiment, when the UE operates in a 5GS that can support EPS, the retry is performed through other accesses. If the UE attempts a 5GMM procedure to the CN and receives a rejection cause #3, #6, #7, #8 (or another reason that invalidates the UE) via an access without integrity protection, then if the UE supports and the network provides access to a different system (EPS or GERAN / UTRAN), the UE is allowed to try that system several times before processing the rejection fact. In the 5G system, the reception of cause values #3, #6 (i.e. illegal UE / ME) in a 5GMM reject message requires the UE to consider the USIM invalid, which means a complete rejection of the service received from the network. The reception of cause value #8 in a 5GMM reject message means that the UE cannot access the 5GS (N1 mode must be disabled) and the UE must search for other systems / accesses for service. If the UE does not support other systems than 5GS, it also means a complete rejection of the service. Other cause values in 5GMM that lead to service rejection also require a retry procedure to protect the UE.
[0029] A retry process is configured for the UE based on the received non-integrity protected rejection message. The retry process can be configured using priority rules for the target cell / base station for retry. Such priority rules can be predefined or preconfigured. The priority rules can also be updated dynamically. The UE applies the priority rules based on the UE's existing access to the network. First, in step 401, the UE determines that the UE supports multiple access and 5GMM supports multiple access. Multiple access supports multiple access methods, including E-UTRA, NR and non-3GPP access. Upon detecting a registration rejection message from the network, the UE determines whether it is a non-integrity protected rejection message with a preconfigured cause value (for example, cause values #3, #6, #7 and #8). Other cause values can also trigger the retry process. The trigger value of the retry process can be preconfigured or predefined by the network or operator. The trigger value of the retry process can also be updated dynamically. Upon detecting a non-integrity protected rejection message with a preconfigured cause value, the UE applies the priority rules to select a retry target. In step 411, the UE first retries a base station with the same access and in the same cell or tracking area (TA). If step 411 fails to successfully register, the UE moves to step 421. In step 421, the UE retries a different access in the same cell or TA. For example, if the UE is currently using 3GPP access to access the network, the UE first retries the base station using the same 3GPP access in the same cell or TA. If registration fails, the UE retries the base station using a different 3GPP access (if available); otherwise, the UE retries a non-3GPP access. If step 421 fails, in step 431, the UE retries accessing a base station in a different cell or TA connected to the same PLMN. If step 431 fails, in step 441, the UE retries accessing a base station in a different PLMN. When selecting a base station in a different cell, TA, or PLMN, the UE prioritizes the same access as the original access over a different access.
[0030] The retry process for handling non-integrity protection reject messages for UEs in 5GS protects UEs from denial of service attacks. In one embodiment, one or more reject counters are configured for the retry process. During the retry process, the UE updates the one or more reject counters each time a non-integrity protection reject message is received. Upon successful registration, the UE resets the one or more reject counters.
[0031] Figure 5According to an embodiment of the present invention, an exemplary flow chart illustrates a UE retry process when a non-integrity-protected Reject message is received before the UE is deemed invalid. A UE 501 in a 5GS is configured to access the CN via multiple access. The 5GS is configured with multiple access, including 3GPP access and non-3GPP access. UE 501 can access the 5GS CN via an AMF 502 in a NR-connected PLMN, an AMF 503 in a non-3GPP-connected PLMN, an AMF 504 in a EUTRAN-connected PLMN, or an AMF 505 in an LTE-connected PLMN. In step 511, UE 501 sends a Registration Request to the NR-connected AMF 502. In step 512, UE 501 receives a Registration Reject from the NR-connected AMF 502. The Registration Reject message is non-integrity-protected, and the cause value is one selected from a predefined set of cause values. The cause value set for 5GMM includes cause values #3, #6, #7, and #8. The cause value set may also include other cause values. In one embodiment, the cause value set may be dynamically updated. Once a registration rejection is received in step 512, the UE leaves the current access NR and increases the rejection counter by one in step 513. In one embodiment, the rejection counter is a counter that tracks all registration rejection messages before registration acceptance. In another embodiment, a separate rejection counter may also be configured for each type of access or each cell / TA / PLMN. In step 513, the UE determines whether the maximum value of one or more rejection counters has been reached. If not, in step 521, the UE sends a registration request to the AMF 504 connected to the EUTRAN. The AMF 504 connected to the EUTRAN is selected according to the priority rule for selection, wherein the priority rule is Figure 4Detailed description and illustration are given in step 522. The UE receives a non-integrity-protected Registration Reject message. In step 523, UE 501 leaves EUTRAN access and increments a reject counter. If each reject counter is less than the preconfigured maximum value of each corresponding reject counter, the UE selects another access for retry. In step 531, the UE sends a Registration Request to the non-3GPP-connected AMF 503. In step 532, the UE receives a non-integrity-protected Registration Reject message. In step 533, the UE leaves the non-3GPP access and increments one or more corresponding reject counters. If each reject counter is less than the corresponding maximum value of each reject counter, the UE selects a new access for retry. In step 541, the UE sends an Attach Request or Tracking Area Update Request to the LTE-connected AMF 505. In step 542, the UE receives a non-integrity-protected Attach Reject message or Tracking Area Update Reject message. In step 551, the UE increments one or more reject counters and detects that at least one reject counter is greater than the maximum value of the reject counter. Subsequently, in step 560, the UE considers the USIM invalid. In one embodiment, an invalidation counter is configured for the UE. The UE does not consider a rejection valid until the invalidation counter is greater than or equal to a preconfigured maximum value for the invalidation counter. The invalidation counter is updated / incremented by one for each registration rejection with a cause value, such as cause values #3, #6, #7, or #8 in 5GMM indicating a non-integrity protection rejection that invalidates the UE. In another embodiment, the one or more rejection counters include a retry counter that is incremented by one for each registration request sent by the UE.
[0032] Figure 6According to an embodiment of the present invention, an exemplary flow chart illustrates the UE retry process when a non-integrity-protected Reject message is received and registration is successful. A UE 601 in a 5GS is configured to access the CN via multiple access points. The 5GS is configured with multiple access points, including 3GPP access and non-3GPP access. UE 601 can access the 5GS CN via an AMF 602 in a NR-connected PLMN, an AMF 603 in a non-3GPP-connected PLMN, an AMF 604 in a EUTRAN-connected PLMN, or an AMF 605 in an LTE-connected PLMN. In step 611, the UE sends a Registration Request to the NR-connected AMF 602. In step 612, UE 601 receives a Registration Reject from the NR-connected AMF 602. The Registration Reject message is non-integrity-protected, and the cause value is one selected from a predefined set of cause values. The cause value set for 5GMM includes cause values #3, #6, #7, and #8. The cause value set may also include other cause values. In one embodiment, the cause value set may be dynamically updated. Once a Registration Reject is received in step 612, the UE leaves the current access NR and increases the Reject counter by one in step 613. In one embodiment, the Reject counter is a counter that tracks all Registration Reject messages before the Registration Accept. In another embodiment, a separate Reject counter may be configured for each type of access or each cell / TA / PLMN. In step 613, the UE determines whether the maximum value of one or more Reject counters has been reached. If not, the UE sends a Registration Request to the EUTRAN-connected AMF 604 in step 621. The EUTRAN-connected AMF 604 is selected based on the priority rule for selection, wherein the priority rule is Figure 4Detailed description and illustration are given in step 622. In step 623, UE 501 leaves EUTRAN access and increments a rejection counter. If each rejection counter is less than the preconfigured maximum value of each corresponding rejection counter, the UE selects another access for retry. In step 631, the UE sends a Registration Request to the non-3GPP connected AMF 603. In step 632, the UE receives a Registration Reject message with non-integrity protection. In step 633, the UE leaves the non-3GPP access and increments one or more corresponding rejection counters. If each rejection counter is less than the corresponding maximum value of each rejection counter, the UE selects a new access for retry. In step 641, the UE sends an Attach Request or Tracking Area Update Request to the LTE connected AMF 605. In step 642, the UE receives an Attach Accept message or Tracking Area Update Accept message. The UE successfully registers with 5GS via the LTE connected AMF 605. In step 651, the UE resets all rejection counters. In step 660, the USIM is deemed valid.
[0033] Figure 7 According to an embodiment of the present invention, an exemplary flow chart of a UE processing a non-integrity protection reject message in a 5G system is shown. In step 701, a UE in a 5GS sends a registration request on a first access network connected to a first PLMN, wherein the UE is capable of accessing a 5GS CN through multiple access networks, wherein the multiple core networks include one or more 3GPP networks and at least one non-3GPP network. In step 702, the UE receives a registration reject with a cause value from the 5GS, wherein the cause value indicates a non-integrity protection reject that invalidates the UE. In step 703, the UE updates one or more corresponding reject counters based on the first access network and the first PLMN, wherein each reject counter counts corresponding registration rejects received without integrity protection. In step 704, the UE attempts a new registration request based on a registration rule, wherein once one or more registration conditions are determined to be met based on a predefined registration selection criterion, the registration rule allows a new registration request involving a selected access network and a selected PLMN, wherein the selection criterion also allows the selection of a non-3GPP network.
[0034] Although the present invention has been described in conjunction with certain specific embodiments for illustrative purposes, the present invention is not limited thereto. Therefore, various modifications, adaptations and combinations of the various features of the described embodiments may be made without departing from the scope of the invention as described in the claims.
Claims
1. A method for processing a non-integrity protection rejection message, comprising: The user equipment sends a registration request to the fifth generation system through the first access network; receiving a registration reject with a cause value indicating a non-integrity protection reject that disables the user equipment from the fifth generation system; updating a value of a reject counter in response to receipt of the registration reject; as well as If the value of the rejection counter is less than a preconfigured maximum value, attempting a new registration request through the second access network, The first access network and the second access network are selected from a third generation partnership project access network type and a non-third generation partnership project access network type, and the second access network is different from the first access network.
2. The method for processing a non-integrity protection rejection message according to claim 1, wherein: The user equipment is capable of accessing a system other than the fifth generation system.
3. The method for processing a non-integrity protection rejection message according to claim 2, wherein: The systems other than the fifth generation system include an Evolved Packet System.
4. The method for processing a non-integrity protection rejection message according to claim 1, wherein: The cause value is one of the 5G mobility management reject causes #3, #6, #7 or #8.
5. The method for processing a non-integrity protection rejection message according to claim 1, wherein: The second access network and the first access network are in the same cell, the same tracking area, or the same public land mobile network.
6. The method for processing a non-integrity protection rejection message according to claim 1, wherein: The method further includes: if the value of the rejection counter is greater than or equal to the pre-configured maximum value, considering that the USIM of the user equipment is invalid.
7. The method for processing a non-integrity protection rejection message according to claim 1, wherein: Further comprising resetting the value of the rejection counter in response to receiving a registration acceptance.
8. The method for processing a non-integrity protection rejection message according to claim 1, wherein: The 3GPP access network type access type includes 5G New Radio, Evolved Universal Terrestrial Radio Access and other 3GPP access access types, and the non-3GPP access network type access type includes WiFi and other non-3GPP access types.
9. A user equipment for processing a non-integrity protection rejection message, comprising: one or more radio frequency transceiver modules for transmitting and receiving radio signals in one or more corresponding radio networks in the fifth generation system; a registration request circuit, configured to send a registration request to the fifth generation system via the first access network; a registration response circuit for receiving, from the fifth generation system, a registration reject with a cause value indicating a non-integrity protection reject that disables the user equipment; a counter circuit for updating a value of a rejection counter in response to receipt of the registration rejection; as well as retry circuit, if the value of the rejection counter is less than a preconfigured maximum value, attempting a new registration request through the second access network, The first access network and the second access network are selected from a third generation partnership project access network type and a non-third generation partnership project access network type, and the second access network is different from the first access network.
10. The user equipment for processing a non-integrity protection rejection message according to claim 9, characterized in that: The user equipment is capable of accessing a system other than the fifth generation system.
11. The user equipment for processing a non-integrity protection rejection message according to claim 10, characterized in that: The systems other than the fifth generation system include an Evolved Packet System.
12. The user equipment for processing a non-integrity protection rejection message according to claim 9, characterized in that: The cause value is one of the 5G mobility management reject causes #3, #6, #7 or #8.
13. The user equipment for non-integrity protection reject message processing according to claim 9, wherein the second access network and the first access network are in the same cell, the same tracking area or the same public land mobile network.
14. The user equipment for processing a non-integrity protection rejection message according to claim 9, characterized in that: If the value of the rejection counter is greater than or equal to the pre-configured maximum value, the USIM of the user equipment is considered invalid.
15. The user equipment for processing a non-integrity protection rejection message according to claim 9, characterized in that: The retry circuit resets the value of the reject counter in response to receiving a registration accept.
16. The user equipment for processing a non-integrity protection rejection message according to claim 9, characterized in that: The 3GPP access network type access type includes 5G New Radio, Evolved Universal Terrestrial Radio Access and other 3GPP access access types, and the non-3GPP access network type access type includes WiFi and other non-3GPP access types.
Citation Information
Patent Citations
Method for reporting denied connection in wireless communication system and apparatus supporting same
CN104737615A
Mobile communication method, mobile communication system, program, exchange, and specific radio base station
US20110117913A1