System and method for device-triggered re-authentication supporting slice-specific secondary authentication and authorization
By generating and using unauthorized network slice selection assistance information that identifies the failure of SSSA procedures, the user equipment can automatically detect and retry authorize unauthorized network slices, solving the reauthentication problem after the failure of SSSA procedures in the prior art, and achieving efficient network resource utilization and system reliability.
Patent Information
- Application Number
- CN202510170222.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2020-02-14
- Filing Date
- 2020-02-15
- Publication Date
- 2025-05-13
AI Technical Summary
When handling secondary authentication and authorizations that vary according to network slices, the prior art cannot effectively solve the reauthentication problem after the failure of the SSSA procedure, especially when the user authorization problem is not fixed, the user equipment cannot retry registration, resulting in waste of network resources and service interruption.
By generating and using unauthorized network slice selection assistance information for its failed permitted/verified S-NSSAI, the user device allows periodically or upon receiving a trigger to resubmit unauthorized network slices for authorization until the authorization procedure varies by slice are completed.
It is realized that after the SSSA procedure fails, the user equipment can automatically detect and retry authorize unauthorized network slices, avoiding network resource waste and service interruption, and improving system reliability and efficiency.
Smart Images

Figure CN119997016A_ABST
Abstract
Description
[0001] This application is a divisional application of an application with an application date of February 15, 2020, application number 202080013332.7 (international application number PCT / US2020 / 018457), and name “System and method for device-triggered re-authentication supporting slice-specific secondary authentication and authorization”.
[0002] Related Applications
[0003] This application claims the benefit of priority to U.S. Provisional Application No. 62 / 806,575, filed on February 15, 2019, entitled “Systems and Methods of Supporting Device Triggered Re-Authentication of Slice-Specific Secondary Authentication and Authorization,” the entire contents of which are incorporated herein by reference and for all purposes. background
[0005] Cellular and wireless communication technology has seen explosive growth over the past several years. Better communication hardware, larger networks, and more reliable protocols have driven this growth. Wireless service providers are now able to offer their customers an ever-expanding array of features and services, and provide users with unprecedented levels of access to information, resources, and communications. In order to keep up with the pace of these service enhancements, user equipment devices (e.g., cell phones, tablets, laptops, etc.) have become faster and more powerful than ever before, and now typically include multiple processors, systems on chips (SoCs), memories, and other resources (e.g., power rails, etc.) that support high-speed communications and allow device users to execute complex and power-hungry software applications on their user equipment devices.
[0006] Overview
[0007] Various aspects include methods performed by a network server for authorizing access to a network slice associated with a service provided by an external provider for access and use by a user equipment device connected to the network via a network component associated with the service provider. Various aspects may include: generating allowed network slice selection assistance information identifying a network slice authorized by at least one of the service provider or the external provider; generating rejected network slice selection assistance information identifying a network slice that has not been authorized; and sending the allowed network slice selection assistance information and the rejected network slice selection assistance information to the user equipment device.
[0008] In some aspects, generating rejected network slice selection assistance information identifying network slices that have not yet been authorized may include: generating network slice selection assistance information identifying network slices that have not yet been authorized by at least one or more of the service provider or the external provider and including a rejection reason value for each network slice identifying the reason why each network slice has not yet been authorized.
[0009] In some aspects, generating allowed network slice selection assistance information identifying a network slice authorized by at least one of the service provider or the external provider may include generating an allowed network slice selection assistance information element (allowed NSSAI IE) identifying a network slice authorized by at least one of the service provider or the external provider. In some aspects, generating rejected network slice selection assistance information identifying a network slice that has not been authorized may include generating rejected network slice selection assistance information identifying a network slice that has not been authorized by at least one or more of the service provider or the external provider.
[0010] Further aspects may include a network server configured to perform one or more operations of the methods outlined above. Further aspects may include a non-transitory processor-readable storage medium having stored thereon processor-executable instructions configured to cause a processor or server to perform the operations of the methods outlined above. Further aspects include a network server having means for performing the functions of the methods outlined above.
[0011] Further aspects include methods performed by a processor in a user equipment device connected to a network via a network component associated with a service provider for accessing a network slice associated with a service provided by an external provider for access and use by the user equipment device. Such aspects may include receiving from a network server allowed network slice selection assistance information identifying a network slice authorized by at least one of the service provider or the external provider; receiving from the network server rejected network slice selection assistance information identifying a network slice that has not been authorized; adding to a requested network slice selection assistance information information element (requested NSSAI IE) the network slice included in the rejected network slice selection assistance information; and sending, by the processor in the user equipment device to the network server, the requested NSSAI IE.
[0012] In some aspects, receiving allowed network slice selection assistance information identifying a network slice authorized by at least one of the service provider or the external provider may include: receiving an allowed NSSAI IE identifying a network slice authorized by at least one of the service provider or the external provider, and receiving rejected network slice selection assistance information identifying a network slice that has not yet been authorized from a network server may include: receiving rejected network slice selection assistance information identifying a network slice that has not yet been authorized by at least one or more of the service provider or the external provider.
[0013] Some aspects may include adding, to the requested NSSAI IE, the network slices included in the allowed NSSAI for the access type on which the requested NSSAI IE is sent to the network server. Some aspects may include abandoning a re-registration attempt for the network slice included in the rejected network slice selection assistance information until the network slice-specific authorization procedure has been completed. Some aspects may include determining whether the network slice-specific authorization procedure has been completed, and in response to determining that the network slice-specific authorization procedure has been completed, the network slice can now be authorized, or the network slice should be resubmitted for authorization by an external provider, adding to the requested NSSAI IE the network slices included in the rejected NSSAI. Some aspects may include determining whether the network slices included in the rejected NSSAI should be resubmitted for authorization by an external provider.
[0014] A further aspect may include a user equipment device having a processor configured to perform one or more operations of the methods outlined above. A further aspect may include a non-transitory processor-readable storage medium having stored thereon processor-executable instructions configured to cause the processor of the user equipment device to perform the operations of the methods outlined above. A further aspect includes a user equipment device having means for performing the functions of the methods outlined above. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate exemplary aspects of the claims and, together with the general description given above and the detailed description given below, serve to explain features of the claims.
[0017] Figure 1 is a system block diagram conceptually illustrating an example telecommunications system.
[0018] Figure 2 is a component block diagram of a computing system that can be configured to support slice-specific secondary authentication and device-triggered re-authentication for authorization in accordance with various aspects of the present disclosure.
[0019] Figure 3is a call flow diagram illustrating operations and communications between components in a communication system configured to perform registration to support network slicing according to various embodiments.
[0020] Figure 4 A call flow diagram illustrating operations and communications between components in a communication system according to one embodiment that is configured to perform secondary authentication and authorization procedures that vary depending on the network slice.
[0021] Figure 5 A call flow diagram illustrating the operations and communications between components in a communication system configured to perform a network slice-specific secondary re-authentication and re-authorization procedure triggered by an AAA server according to one embodiment.
[0022] Figure 6 A call flow diagram illustrating operations and communications between components in a communication system configured to perform AAA server-triggered, network slice-specific secondary authorization revocation according to one embodiment.
[0023] Figure 7-9 is a process flow diagram illustrating a method of performing secondary authentication and authorization that varies by network slice according to various embodiments.
[0024] Fig.10 is a component block diagram of a user equipment device suitable for triggering re-authentication of secondary authentication and authorization that varies by network slice according to various embodiments.
[0025] Fig.11 is a component block diagram of a network server suitable for use in various embodiments. Detailed Description
[0027] Various aspects will be described in detail with reference to the accompanying drawings. Wherever possible, the same reference numerals will be used throughout the drawings to refer to the same or similar parts. References to specific examples and implementations are for illustrative purposes and are not intended to limit the scope of the claims.
[0028] Various embodiments include methods for efficiently authorizing and / or reauthorizing network slices associated with services provided by an external provider for access and use by a user equipment device connected to a network (e.g., a 5G or new radio network) via a network component associated with a service provider, and computing devices (e.g., user equipment devices, network servers, etc.) configured to implement these methods. A network component (such as a core access and mobility management function (AMF) component) may be configured to generate and send an Allowed Network Slice Selection Assistance Information (Allowed NSSAI) Information Element (IE), a Pending NSSAI IE, and / or an Unauthorized NSSAI IE to a user equipment device. The Allowed NSSAI IE may identify a network slice authorized by at least one or both of the service provider or the external provider. The Unauthorized NSSAI (or Pending NSSAI) IE may identify a network slice authorized by the service provider but not through authorization / validation performed by the external provider.
[0029] The processor in the user equipment device may be configured to determine periodically or based on receiving a trigger whether the network slice included in the pending NSSAI IE should be resubmitted for external provider authorization or verification. In response to determining that the network slice should be resubmitted, the processor may perform a registration procedure including adding the network slice included in the pending NSSAI IE (or in the unauthorized NSSAI IE) to the requested NSSAI (requested NSSAI IE) and sending the requested NSSAI IE to the AMF.
[0030] In order to protect the network from denial of service attacks and excessive network traffic that may be caused by repeated requests for authorization of slices included in unauthorized NSSAI elements by the network, the AMF may be configured to, in response to the AMF determining that the user equipment has repeatedly and unsuccessfully attempted to register a network slice that has repeatedly failed authorization / validation by an external provider, add the network slice to the rejected NSSAI element for the registration area. In order to protect the network from denial of service attacks and excessive network traffic that may be caused by repeated requests for authorization of slices included in unauthorized NSSAI elements by the network, the AMF may be configured to provide a slice-specific backoff timer associated with the slice; upon receipt of such a timer, the user equipment may exclude or not include the S-NSSAI of the slice associated with the backoff timer in the requested NSSAI until the timer expires.
[0031] The terms "user equipment device" and "user equipment" are used interchangeably herein to refer to any or all of the following: a cellular telephone, a smart phone, a portable computing device, a personal or mobile multimedia player, a laptop computer, a tablet computer, a smartbook, an IoT device, a handheld computer, a wireless email receiver, an Internet-enabled multimedia cellular telephone, a connected vehicle, a wireless game controller, and similar electronic devices that include memory, wireless communication components, and a programmable processor.
[0032] The term "system on chip" (SOC) is used herein to refer to a single integrated circuit (IC) chip containing multiple resources and / or processors integrated on a single substrate. A single SOC may include circuit systems for digital, analog, mixed signal and radio frequency functions. A single SOC may also include any number of general and / or special processors (digital signal processors, modem processors, video processors, etc.), memory blocks (e.g., ROM, RAM, flash memory, etc.), and resources (e.g., timers, voltage regulators, oscillators, etc.). Each SoC may also include software for controlling integrated resources and processors, and for controlling peripheral devices. Many user equipment devices include a SOC (herein "SOC-CPU") that operates as the CPU of the device.
[0033] The term "system-in-package" (SIP) is used herein to refer to a single module or package that may contain multiple resources, computing units, cores and / or processors on two or more IC chips, substrates, or SOCs. For example, a SIP may include a single substrate on which multiple IC chips or semiconductor dies are stacked in a vertical configuration. Similarly, a SIP may include one or more multi-chip modules (MCMs) on which multiple ICs or semiconductor dies are packaged into a unified substrate. A SIP may also include multiple independent SOCs coupled together via high-speed communication circuitry and packaged together in close proximity (such as on a single motherboard or in a single mobile communication device). The proximity of the SOCs facilitates high-speed communication and sharing of memory and resources.
[0034] The term "multi-core processor" may be used herein to refer to a single integrated circuit (IC) chip or chip package that includes two or more independent processing cores (e.g., CPU cores, IP cores, GPU cores, etc.) configured to read and execute program instructions. A SOC may include multiple multi-core processors, and each processor in the SOC may be referred to as a core. The term "multiprocessor" may be used herein to refer to a system or device that includes two or more processing units configured to read and execute program instructions.
[0035] In this application, the term "subscriber" may be used for the end consumer of the services provided by the network operator.
[0036] In this application, the term "control plane" may be used to refer to signaling traffic between network components. Control plane data typically does not include payload or actual user data. Examples of control plane data include information related to communication setup, security, authentication, billing, policy rule enforcement, etc.
[0037] In this application, the term "Infrastructure as a Service (IaaS)" may be used to refer to components or systems that provide basic or fundamental computing infrastructure resources (e.g., computing power, memory, network connectivity, disk space, etc.) to consumers via a cloud computing environment or over the Internet. IaaS systems can eliminate the need for network operators and / or equipment manufacturers to purchase and manage proprietary computing resources or facilities. IaaS systems may rely on virtualization and / or provide computing infrastructure as virtual machines or virtualized computing resources.
[0038] In this application, the term "software defined network (SDN)" may be used to refer to components or systems that achieve network programmability through the following operations: utilizing an IaaS system, separating the management and control plane from the data plane, providing programmable interfaces to network equipment, and centrally controlling network equipment without physical access, etc.
[0039] In this application, the term "network function virtualization (NFV)" may be used to refer to components, systems and techniques that utilize virtualization technology to enable existing network infrastructure (both user plane and control plane) to be consolidated (e.g., among elements / functions within each of the user plane and the control plane) and virtualized so that it can operate on commodity hardware or in a virtualized environment within an IaaS system.
[0040] In this application, the term "service provider" may be used to refer to a network, technology, or entity (e.g., a network operator such as AT&T, a vehicle manufacturer such as Ford, etc.) that provides consumers with access to services (e.g., cellular subscription plans, roadside assistance, SiriusXM, etc.) or the Internet. Examples of service provider technologies and networks include 3rd Generation Partnership Project (3GPP), Long Term Evolution (LTE) systems, 3rd Generation wireless mobile communication technology (3G), 4th Generation wireless mobile communication technology (4G), 5th Generation wireless mobile communication technology (5G), Global System for Mobile Communications (GSM), Universal Mobile Telecommunications System (UMTS), High Speed Downlink Packet Access (HSDPA), 3GSM, General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA) systems (e.g., cdmaOne, CDMA2000TM), Enhanced Data Rates for GSM Evolution (EDGE), Advanced Mobile Phone System (AMPS), Digital AMPS (IS-136 / TDMA), Evolution-Data Optimized (EV-DO), Digital Enhanced Cordless Telecommunications (DECT), Worldwide Interoperability for Microwave Access (WiMAX), Wireless Local Area Network (WLAN), Wi-Fi Protected Access I and II (WPA, WPA2), Land Mobile Radio (LMR), and Integrated Digital Enhanced Network (iden). Each of these technologies involves, for example, the transmission and reception of data, signaling, and / or content messages.
[0041] The term “external provider” may be used herein to refer to a third party (e.g., a vehicle manufacturer such as Ford, BMW, etc.) or an external service provider (e.g., a network operator such as VERIZON, etc.) that provides access to services (e.g., roadside assistance, SiriusXM, etc.) to consumers and is a legal entity separate from the service provider that allocates network resources to provide access to Internet or IP services to consumers.
[0042] For ease of reference, the following description of various embodiments includes the acronyms defined in the following table.
[0043]
[0044]
[0045] Network slicing is a virtual network architecture in the same family as software-defined networking (SDN) and network function virtualization (NFV), which allows the creation of multiple virtual networks ("network slices") on a shared physical infrastructure, commodity hardware or IaaS by dividing the network architecture into virtual elements.
[0046] The term "virtualized network function (VNF)" may be used in this application to refer to a component, system, or network element that is configured to implement a network function using virtualization technology. For example, a VNF may be a software implementation of a network function that can be deployed on a virtualized infrastructure (e.g., computing, storage, and network). A VNF may be included and used as part of a network function virtualization (NFV) solution.
[0047] In general, a communication network includes multiple nodes, systems and / or components that are each responsible for providing or implementing specific functionality for the network. For example, a 5G or new radio (NR) network may include a radio access network ((R)AN) component, a core access and mobility management function (AMF) component, a policy control function (PCF) component, a charging system, an implementation component, a session management function (SMF) component, an authentication server function (AUSF) component, a unified data management (UDM) component, a user plane function (UPF) component, an authentication, authorization and accounting (AAA) component, and an application function (AF) component. In various embodiments, any or all of these components may be implemented as a virtualized network function (VNF).
[0048] A network slice may be identified based on Network Slice Selection Assistance Information (NSSAI), which may be included in a control plane or in a signaling message communicated between a user equipment (UE) and a network component. The NSSAI may include a list or set of Single Network Slice Selection Assistance Information (S-NSSAI) elements, each of which identifies a specific instance of a network slice. The S-NSSAI may include a Slice / Service Type (SST) information element that identifies the expected network slice behavior in the form of features and services, a Slice Differentiator (SD) information element that further distinguishes between multiple network slices with the same SST, and a PLMN ID that identifies the network associated with the S-NSSAI that the UE can access. Currently, the 3GPP standard supports the inclusion of up to eight (8) S-NSSAIs within the NSSAI. This allows a single UE to be served by up to eight network slices at a time.
[0049] To access a network slice, the UE typically first performs a registration request procedure in which it provides a requested NSSAI message to a core access and mobility management function (AMF) component in the network. In response, the AMF component performs various authentication operations, which may include performing certain checks based on local policies, the UE's subscriptions, information stored in the UE's SIM card, etc. The authentication operation may also include verifying the network slices that can be provided to the UE (e.g., provided for the UE to access and use).
[0050] If these authentication operations are successful, the AMF component (or other component) may authorize the network slice and generate and send an Allowed NSSAI message to the UE, which informs the UE of the verified network slice that the UE can access and use. In response to receiving the Allowed NSSAI message, the UE may perform various PDU session establishment operations to establish connectivity to the network slice.
[0051] The AMF component may also send a rejected NSSAI message to the UE if authentication (e.g., verification, authorization, etc.) fails (such as when network slicing is not supported, the AMF does not support the registration area in which the UE is currently located, etc.). Due to the way the rejected NSSAI works, a UE that receives a rejected NSSAI message may be blocked from accessing the network slice for an extended or indefinite period of time. That is, in order to prevent hacking and denial of service attacks on the network, the UE cannot retry using the S-NSSAI (i.e., attempt to re-register and add such S-NSSAI to the requested NSSAI). This applies to the registration area (if the S-NSSAI is rejected with the reason indicating "RA") or the PLMN (if the S-NSSAI is rejected with the reason indicating "PLMN", which is a more likely scenario when the S-NSSAI failure is not RA-related).
[0052] There may be some services to which the network operator allocates its network resources, but which are ultimately provided by external service providers. For example, an Internet-connected motor vehicle may include subscription plans or services (roadside assistance, SiriusXM, etc.) that are provided by the manufacturer (e.g., Ford, BMW, etc.) or an external service provider and supported by network resources allocated by the network operator (e.g., AT&T). For these services, the network operator (e.g., AT&T) may or may not have direct access to the accounting, payment, or subscription information required to determine whether a UE can access or use the network slice associated with the service. Instead, such information is typically accessible only to the AAA server (i.e., AAA-S) of the external service provider that is ultimately responsible for the service.
[0053] For such services, in addition to the 'primary' authentication operations performed by the mobile network operator where the AMF ensures that the service and network slice are supported by the network, the AMF may also be required to perform slice-specific secondary authentication (SSSA) operations to ensure that access and use of the requested network slice is permitted by the external service provider or third party.
[0054] Therefore, some of the requested NSSAIs may be subject to slice-specific secondary authentication (SSSA) and may need to be authenticated and / or authorized by the AAA server of the service provider providing the slice-specific service to the UE. Since the SSSA operation may be more time-consuming than the primary authentication operation, the AMF may determine whether SSSA is required for any of the S-NSSAIs and send the UE an allowed NSSAI message only for the verified network slices that do not require SSSA.
[0055] The AMF may initiate an SSSA procedure for a validated network slice determined to require SSSA, and inform the UE that the request is pending secondary authentication (e.g., by sending an N2 message including Registration Accepted and Pending Slice-Specific Secondary Authentication Data fields). When the SSSA procedure is completed, the AMF may send a new Allowed NSSAI message to the UE, which identifies the previously allowed network slice (which does not require SSSA and is authorized by the mobile network operator based on subscription information and AMF local policy) and the newly allowed network slice (which is authorized by the mobile network operator based on subscription information and AMF local policy, and for which the SSSA procedure is successful).
[0056] There is currently no clear standard to address situations where the SSSA procedure fails for an S-NSSAI. Adding an S-NSSAI to a rejected NSSAI when the SSSA procedure fails is problematic because the user may later fix the authorization issue (e.g., pay a bill to the service provider, fix a subscription to the service provider, etc.). This is because, due to security considerations, the UE cannot retry using the S-NSSAI after it has been added to the rejected NSSAI (i.e., attempt to reregister and add such S-NSSAI to the requested NSSAI). This applies to the registration area (if the S-NSSAI is rejected with the reason indicating "RA") or the PLMN (if the S-NSSAI is rejected with the reason indicating "PLMN", which is a more likely scenario when the S-NSSAI failure is not RA-related).
[0057] In addition, the authentication process is always newly initiated by the authenticator (e.g., a network operator associated with the AMF, etc.). When authentication is successful, the system generates and maintains state information that associates the AMF with the external service provider's AAA server (AAA-S). This association can be used to later re-authenticate the previous authentication, revoke the authentication, etc. However, when the SSSA procedure fails (network slice is rejected), the system does not maintain any state information that can be used to identify the association between the AMF and the AAA-S server. If the conditions that caused the SSSA procedure to fail are alleviated (i.e., the user later fixes the authorization issue, pays the bill, etc.), using the existing technology, re-authentication cannot be triggered by AAA-S because there is no valid association between AAA-S and AMF.
[0058] To address these and other issues, various embodiments include components (e.g., UE, AMF, etc.) configured to generate and use an Unauthorized Network Slice Selection Assistance Information (NSSAI) Information Element (IE) that identifies an allowed / validated S-NSSAI for which the SSSA procedure failed. That is, when the components perform a registration operation and generate an Allowed NSSAI IE, the components may also generate and send to the UE an "Unauthorized NSSAI" (or "Pending NSSAI") IE that includes a list of all NSSAIs that are subject to authentication (or further authentication, re-authentication, etc.). That is, the Pending NSSAI IE sent by the AMF may inform the UE about the S-NSSAI(s) for which the authentication and authorization procedures that vary by network slice are pending.
[0059] In some embodiments, when performing SSSA for all S-NSSAIs that require SSSA, the network server (e.g., AMF) may perform a UE configuration update procedure and send to the UE a new allowed NSSAI (adding the S-NSSAI for which SSSA succeeded), an unauthorized NSSAI containing the allowed / verified S-NSSAI for which the SSSA procedure failed, and a rejected NSSAI for the allowed / verified S-NSSAI for which the SSSA procedure failed several times. The AMF may also provide an unauthorized S-NSSAI backoff timer for the allowed / verified S-NSSAI for which the SSSA procedure failed several times.
[0060] The UE processor may be configured to determine whether the S-NSSAI in the unauthorized NSSAI has been authorized periodically or in response to an attempt to use a network slice. In response to determining that the S-NSSAI in the unauthorized NSSAI has been authorized (e.g., the user paid a bill to the provider of the authorized S-NSSAI), the UE may perform a registration procedure and include any of the S-NSSAI in the unauthorized NSSAI in the requested NSSAI. In order to protect the network from continued unauthorized attempts, the network server (e.g., AMF) may be configured to place the S-NSSAI in the rejected NSSAI for the registration area in response to determining that the UE has repeatedly retried to register the S-NSSAI included in the unauthorized NSSAI and the SSSA for the S-NSSAI continues to fail.
[0061] The subscription information may contain one or more S-NSSAIs, i.e., subscribed S-NSSAIs. Based on the operator's policy, one or more subscribed S-NSSAIs may be marked as default S-NSSAIs. If the S-NSSAI is marked as default, the network is expected to serve the UE with the relevant applicable network slice instance when the UE does not send any valid S-NSSAI to the network as part of the requested NSSAI in the Registration Request message.
[0062] The network (e.g., AMF, etc.) may verify the requested NSSAI provided by the UE in the registration request against the subscription information. The subscription information for each S-NSSAI may include a list of subscribed DNNs and a default DNN, as well as an indication of whether the S-NSSAI is subject to secondary authentication and authorization that varies by network slice.
[0063] In roaming scenario, UDM may provide VPLMN with S-NSSAI from the subscribed S-NSSAIs allowed by HPLMN for UEs in VPLMN only. When UDM updates the subscribed S-NSSAI(s) to the serving AMF, based on the configuration in the AMF, AMF itself or NSSF determines the mapping of configured NSSAI and / or allowed NSSAI for the serving PLMN to the subscribed S-NSSAI(s). The serving AMF then updates the UE with the above information.
[0064] The General Public Subscription Identifier (GPSI) may be used to address a 3GPP subscription in different data networks outside the 3GPP system. The 3GPP system stores an association between the GPSI and the corresponding SUPI within the subscription data. The GPSI is a public identifier used within and outside the 3GPP system. The GPSI may be an MSISDN or an external identifier. If the MSISDN is included in the subscription data, it may be possible to support the same MSISDN value in both the 5GS and EPS. The GPSI may be assigned to a UE whose subscription information contains an indication that at least one S-NSSAI is subject to secondary authentication and authorization that varies by network slice.
[0065] It should be noted that there is no implicit 1-to-1 relationship between GPSI and SUPI.
[0066] When a UE registers with a PLMN on an access type, if the UE has a configured NSSAI for the PLMN and the access type has an allowed NSSAI, then in addition to the 5G-S-TMSI (if a 5G-S-TMSI is assigned to the UE), the UE may also provide to the network in the AS layer and the NAS layer the requested NSSAI containing the S-NSSAI(s) corresponding to the slice(s) with which the UE wishes to register. The requested NSSAI can be one of: a configured NSSAI or a subset thereof, as described below (for example, if the UE does not have an allowed NSSAI for the access type for the serving PLMN); an allowed NSSAI or a subset thereof for the access type over which the requested NSSAI is sent; an allowed NSSAI or a subset thereof for the access type over which the requested NSSAI is sent, plus one or more S-NSSAIs from the configured NSSAI that are not already in the allowed NSSAI for the access type, as described below; or an allowed NSSAI or a subset thereof for the access type over which the requested NSSAI is sent, plus one or more S-NSSAIs from the unauthorized NSSAIs.
[0067] If the UE processor is performing operations to register only a subset of S-NSSAI from the configured NSSAI or allowed NSSAI to be able to register with some network slices (e.g., to establish a PDU session for some (certain) application) and the UE has a NSSP in the URSP, the UE processor uses the NSSP in the URSP to ensure that the S-NSSAI included in the requested NSSAI does not conflict with the NSSP in the URSP.
[0068] The subset of S-NSSAIs in the configured NSSAI provided in the requested NSSAI includes one or more S-NSSAIs in the configured NSSAI that are applicable to the PLMN (if any), and for which no corresponding S-NSSAI already exists in the allowed NSSAI for the PLMN for the access type. The UE processor may not include in the requested NSSAI any S-NSSAI that is currently rejected by the network (i.e., rejected in the current registration area or rejected in the PLMN). For registrations to a PLMN for which no configured NSSAI or allowed NSSAI applicable to the PLMN exists, the S-NSSAI provided in the requested NSSAI corresponds to the S-NSSAI(s) in the default configured NSSAI.
[0069] When the UE determines based on the implementation-dependent mechanism that the S-NSSAI is authorizable, the UE processor includes one or more S-NSSAIs from the unauthorized NSSAIs in the requested NSSAI.
[0070] When the UE processor registers with the PLMN on an access type, the UE processor may also indicate in the Registration Request message when the requested NSSAI is based on the default configured NSSAI.
[0071] The UE processor may include the requested NSSAI in the RRC connection establishment and in the establishment of the connection to the N3IWF (if applicable) and in the NAS registration procedure message. However, the UE processor may not indicate any NSSAI in the RRC connection establishment or initial NAS message unless it has a configured NSSAI for the corresponding PLMN, an allowed NSSAI for the corresponding PLMN and access type, or a default configured NSSAI. The (R)AN may route NAS signaling between the UE and the AMF selected using the requested NSSAI obtained during the RRC connection establishment or connection to the N3IWF, respectively. If the (R)AN cannot select an AMF based on the requested NSSAI, the (R)AN routes the NAS signaling to an AMF from the default AMF set. In the NAS signaling, the UE processor provides a mapping of each S-NSSAI in the requested NSSAI to the corresponding HPLMN S-NSSAI.
[0072] When the UE registers with a PLMN, if the UE processor has not included the requested NSSAI or GUAMI when establishing a connection to the (R)AN for that PLMN, the (R)AN may route all NAS signaling from the UE to / from the default AMF to the UE. When the requested NSSAI and 5G-S-TMSI or GUAMI are received from the UE in RRC connection establishment or in connection establishment to the N3IWF, if the 5G-AN can reach the AMF corresponding to the 5G-S-TMSI or GUAMI, the 5G-AN forwards the request to the AMF. Otherwise, the 5G-AN selects a suitable AMF based on the requested NSSAI provided by the UE and forwards the request to the selected AMF. If the 5G-AN cannot select an AMF based on the requested NSSAI, the request is sent to the default AMF.
[0073] When the AMF selected by the AN receives a UE registration request, as part of the registration procedure, the AMF may query the UDM to retrieve the UE subscription information including the subscribed S-NSSAI. The AMF verifies whether the S-NSSAI(s) in the requested NSSAI are permitted based on the subscribed S-NSSAI (to identify the subscribed S-NSSAI that the AMF can use to map the HPLMN S-NSSAI provided by the UE in the NAS message for each S-NSSAI in the requested NSSAI). When the UE context in the AMF does not yet include an allowed NSSAI for the corresponding access type, the AMF queries the NSSF, unless in the case where the AMF is allowed to determine whether it can serve the UE based on the configuration in the AMF. The address of the NSSF is locally configured in the AMF.
[0074] It should be noted that the configuration in AMF may depend on the operator's policy.
[0075] When the UE context in the AMF already includes an allowed NSSAI for the corresponding access type, the AMF may be allowed to determine whether it can serve the UE based on the configuration for that AMF.
[0076] Depending on the implementation configuration as described above, the AMF may be allowed to determine whether it can serve the UE and perform the following operations: the AMF checks whether it can serve all S-NSSAIs from the requested NSSAI that are present in the subscribed S-NSSAI (potentially using the configuration for mapping S-NSSAI values between the HPLMN and the serving PLMN), or in the case where the requested NSSAI is not provided or any S-NSSAI from the requested NSSAI is not present in the subscribed S-NSSAI, all S-NSSAIs in the subscribed S-NSSAI are marked as default. If the AMF can serve the S-NSSAIs in the requested NSSAI, the AMF remains the serving AMF for the UE. The allowed NSSAI then includes a list of S-NSSAI(s) permitted in the requested NSSAI based on the subscribed S-NSSAI, or if the requested NSSAI is not provided, all S-NSSAI(s) marked as default in the subscribed S-NSSAI and also taking into account the availability of network slice instances of the S-NSSAI(s) in the allowed NSSAI in the tracking area that are capable of serving the current UE as described in Section 5.15.8. If the S-NSSAI(s) included in the allowed NSSAI need to be mapped to the subscribed S-NSSAI(s) value, it also determines the mapping. If the requested NSSAI is not provided, or the requested NSSAI includes an S-NSSAI that is invalid in the serving PLMN, or the UE indicates that the requested NSSAI is based on the default configured NSSAI, the AMF may also determine the configured NSSAI for the serving PLMN based on the subscribed S-NSSAI(s) and the operator's configuration, and if applicable, the associated mapping of the configured NSSAI to the HPLMN S-NSSAI, so that these can be configured in the UE. Step (C) is then performed. Otherwise, the AMF queries the NSSF (see (B) below).
[0077] When needed as described above, the AMF needs to query the NSSF and perform the following operations: The AMF queries the NSSF for the requested NSSAI, the default configured NSSAI indication, the mapping of the requested NSSAI to the HPLMN S-NSSAI, the subscribed S-NSSAI (with an indication as to whether it is marked as the default S-NSSAI), any allowed NSSAI that may be for other access types (including its mapping to the HPLMN S-NSSAI), the PLMN ID of the SUPI and the current tracking area of the UE(s).
[0078] It should be noted that when more than one UE's tracking areas are indicated, the UE is using more than one access type.
[0079] Based on this information, local configuration and other locally available information (including RAN capabilities in the current tracking area of the UE or load level information of the network slice instance provided by the NWDAF), the NSSF performs the following operations. The NSSF verifies which S-NSSAI(s) in the requested NSSAI are permitted based on comparing the subscribed S-NSSAI with the S-NSSAI in the mapping of the requested NSSAI to the HPLMN S-NSSAI. In the case where there is no S-NSSAI from the requested NSSAI in the subscribed S-NSSAI, the NSSF considers the S-NSSAI(s) marked as default in the subscribed S-NSSAI. The NSSF selects the network slice instance(s) to serve the UE. When multiple network slice instances in the tracking area of the UE are capable of serving a given S-NSSAI, based on the operator's configuration, the NSSF may select one of them to serve the UE, or the NSSF may postpone the selection of the network slice instance until the NF / service within the network slice instance needs to be selected. The NSSF determines the target AMF Set to be used to serve the UE, or based on the configuration, determines the list of candidate AMF(s) (possibly after querying the NRF).
[0080] It should be noted that if the target AMF(s) returned from the NSSF is a list of candidate AMF(s), the Registration Request message can only be redirected via direct signaling between the initial AMF and the selected target AMF.
[0081] The NSSF determines the allowed NSSAI(s) for the applicable access type(s), which includes a list of S-NSSAI(s) permitted based on the subscribed S-NSSAI in the requested NSSAI, or if the requested NSSAI is not provided, all S-NSSAIs marked as default in the subscribed S-NSSAI and also taking into account the availability of network slice instances of the S-NSSAI(s) in the allowed NSSAI(s) in the tracking area that can serve the current UE. If necessary, the NSSF also determines the mapping of each S-NSSAI in the allowed NSSAI(s) to the subscribed S-NSSAI. Based on the operator configuration, the NSSF can determine the NRF(s) to be used for selecting the NF / service within the selected network slice instance(s).
[0082] Additional processing may be performed to determine the allowed NSSAI(s) in roaming scenarios and the mapping to the subscribed S-NSSAI. If the requested NSSAI is not provided, or the requested NSSAI includes an S-NSSAI that is invalid in the serving PLMN, or a default configured NSSAI indication is received from the AMF, the NSSF may also determine the configured NSSAI for the serving PLMN based on the subscribed S-NSSAI(s) and operator configuration, and if applicable, the associated mapping of the configured NSSAI to the HPLMN S-NSSAI, so these may be configured in the UE. The NSSF returns to the current AMF the allowed NSSAI for the applicable access type, the mapping of each S-NSSAI in the allowed NSSAI to the subscribed S-NSSAI (if determined), and a target AMF set or a list of candidate AMF(s) based on the configuration. The NSSF may return the NRF(s) to be used for selecting the NF / service within the selected network slice instance(s), and the NRF(s) to be used for determining the list of candidate AMF(s) from the AMF set. The NSSF may return the NSI ID(s) to be associated with the network slice instance(s) corresponding to certain S-NSSAIs. The NSSF may return rejected S-NSSAI(s). The NSSF may return the configured NSSAI for the serving PLMN and the associated mapping of the configured NSSAI to the HPLMN S-NSSAI. Depending on the available information and based on the configuration, the AMF may query the appropriate NRF (e.g., locally pre-configured or provided by the NSSF) for the target AMF set. The NRF returns a list of candidate AMFs. If rerouting to the target serving AMF is required, the current AMF reroutes the registration request to the target serving AMF.
[0083] The serving AMF may determine the registration area such that all S-NSSAIs in the allowed NSSAI for that registration area are available in all tracking areas of that registration area (and also taking into account other aspects), and then return this allowed NSSAI and a mapping of allowed NSSAIs to subscribed S-NSSAIs to the UE (if provided). The AMF may return rejected S-NSSAI(s).
[0084] It should be noted that since there is a single distinct registration area for non-3GPP access in the PLMN, the S-NSSAIs in the allowed NSSAIs for that registration area (ie, for non-3GPP access) are homogeneously available in the PLMN.
[0085] The AMF may update the UE slice configuration information for the PLMN when the requested NSSAI is not included, or the mapping of the S-NSSAI in the requested NSSAI to the HPLMN S-NSSAI is incorrect, or the requested NSSAI is considered invalid in the PLMN and so at least one S-NSSAI in the requested NSSAI is rejected as not usable by the UE in the PLMN, or the UE indicates that the requested NSSAI is based on the default configured NSSAI, then the AMF may update the UE slice configuration information for the PLMN.
[0086] If the requested NSSAI includes an S-NSSAI mapped to an S-NSSAI in the HPLMN that is subject to network slice-specific secondary authentication and authorization, the AMF may indicate in the allowed NSSAI only those S-NSSAIs that are not subject to network slice-specific secondary authentication and authorization, and may indicate to the UE that a slice-specific secondary authentication will be performed. Subsequently, the AMF may initiate a network slice-specific secondary authentication and authorization procedure for each S-NSSAI that requires it. At the end of the network slice-specific secondary authentication and authorization step, the UE may obtain a new allowed NSSAI, which also contains the S-NSSAI that is subject to network slice-specific secondary authentication and authorization and for which the authentication and authorization succeeded. If the AMF is required to change, this may be triggered by the AMF using a UE configuration update procedure indicating that the UE is required to re-register. The UE may also obtain an unauthorized NSSAI, which contains an S-NSSAI that is subject to network slice-specific secondary authentication and authorization and for which the network slice-specific secondary authentication and authorization has failed.
[0087] If the requested NSSAI includes only S-NSSAIs mapped to S-NSSAIs in the HPLMN that are subject to network slice-specific secondary authentication and authorization, and the network slice-specific secondary authentication and authorization fails for all S-NSSAIs in the requested NSSAI, the UE does not obtain the allowed NSSAI.
[0088] The serving PLMN may perform network slice-specific secondary authentication and authorization for the S-NSSAI in the HPLMN that is subject to network slice-specific secondary authentication and authorization based on the subscription information.
[0089] To perform network slice specific secondary authentication and authorization for S-NSSAI, AMF invokes EAP based network slice specific secondary authorization procedure for S-NSSAI. This procedure may be invoked by AMF at any time (such as when UE registers with AMF and one of the S-NSSAI in HPLMN mapped to S-NSSAI in requested NSSAI is requiring network slice specific secondary authentication and authorization, or network slice specific AAA server triggers UE re-authentication and authorization for S-NSSAI, or AMF decides to initiate network slice specific secondary authentication and authorization procedure for a previously authorized S-NSSAI based on operator policy or subscription change).
[0090] After a successful or unsuccessful UE network slice specific secondary authentication and authorization, the UE context in the AMF may retain the authentication and authorization status of the UE for the relevant specific S-NSSAI of the HPLMN until the UE remains RM-REGISTERED in the PLMN, so that the AMF does not perform network slice specific secondary authentication and authorization for the UE at every registration procedure with the PLMN.
[0091] The network slice-specific AAA server may revoke authorization or challenge the UE's authentication and authorization at any time. When authorization is revoked for an S-NSSAI in the current allowed NSSAI, the AMF may provide the UE with a new allowed NSSAI and trigger the release of all PDU sessions associated with that S-NSSAI.
[0092] The AMF provides the UE's GPSI to the AAA server to allow the AAA server to initiate secondary authentication and authorization or authorization revocation procedures that vary depending on the network slice, where the current AMF needs to be identified by the system so that the UE authorization status can be questioned or revoked.
[0093] The network slice specific secondary authentication and authorization is performed after a successful registration procedure. The network slice specific secondary authentication and authorization requires that the UE primary authentication and authorization for the SUPI has been successfully completed. If the SUPI authorization is revoked, the network slice specific secondary authorization is also revoked.
[0094] Figure 1 An example wireless network 100, such as a New Radio (NR) or 5G network, is illustrated in which aspects of the present disclosure may be performed. For example, Figure 2 The system-in-package (SIP) 200 illustrated in FIG. 1 may include a 5G modem processor configured to send and receive information via the wireless network 100. As another example, Fig.10 The smartphone illustrated in FIG. 1 can send and receive information via the wireless network 100 .
[0095] exist Figure 1 In the example illustrated in , the wireless network 100 includes several base stations 110 and other network entities. A base station may be a station that communicates with a user equipment device. Each base station 110 may provide communication coverage for a specific geographic area. In 3GPP, the term "cell" may refer to the coverage area of a B node and / or a B node subsystem serving the coverage area, depending on the context in which the term is used. In a new radio (NR) or 5G network system, the term "cell" and eNB, B node, 5GNB, AP, NR base station, NR BS, or transmission reception point (TRP) may be interchangeable. In some examples, a cell may or may not be stationary, and the geographic area of the cell may move according to the location of a mobile base station. In some examples, a base station may be interconnected to each other and / or to one or more other base stations or network nodes (not shown) in the wireless network 100 through various types of backhaul interfaces (such as direct physical connections, virtual networks, or analogs using any suitable transmission networks).
[0096] In general, any number of wireless networks may be deployed in a given geographic area. Each wireless network may support a specific radio access technology (RAT) and may operate on one or more frequencies. RAT may also be referred to as radio technology, air interface, etc. Frequency may also be referred to as carrier, frequency channel, etc. Each frequency may support a single RAT in a given geographic area to avoid interference between wireless networks of different RATs. In some cases, NR or 5G RAT networks may be deployed.
[0097] Base stations may provide communication coverage for macro cells, pico cells, femto cells, and / or other types of cells. A macro cell may cover a relatively large geographic area (e.g., several thousand meters in radius) and may allow unrestricted access by user equipment devices with a service subscription. A pico cell may cover a relatively small geographic area and may allow unrestricted access by user equipment devices with a service subscription. A femto cell may cover a relatively small geographic area (e.g., a residence) and may allow restricted access by user equipment devices associated with the femto cell (e.g., user equipment devices in a closed subscriber group (CSG), user equipment devices of users in a residence, etc.). A base station for a macro cell may be referred to as a macro base station. A base station for a pico cell may be referred to as a pico base station. A base station for a femto cell may be referred to as a femto base station or a home base station. In Figure 1In the example shown in FIG. 1 , base stations 110a, 110b, and 110c may be macro base stations for macro cells 102a, 102b, and 102c, respectively. Base station 110x may be a pico base station for pico cell 102x. Base stations 110y and 110z may be femto base stations for femto cells 102y and 102z, respectively. A base station may support one or more (e.g., three) cells.
[0098] The wireless network 100 may also include a relay station. A relay station is a station that receives transmissions of data and / or other information from an upstream station (e.g., a base station or user equipment device) and sends transmissions of the data and / or other information to a downstream station (e.g., a user equipment device or a base station). A relay station may also be a user equipment device that relays transmissions for other user equipment devices. Figure 1 In the example shown in , a relay station 110r may communicate with a base station 110a and a user equipment device 120r to facilitate communication between the base station 110a and the user equipment device 120r. A relay station may also be referred to as a relay base station, a relay, or the like.
[0099] The wireless network 100 may be a heterogeneous network including different types of base stations (e.g., macro base stations, pico base stations, femto base stations, relays, etc.). These different types of base stations may have different transmit power levels, different coverage areas, and different impacts on interference in the wireless network 100. For example, a macro base station may have a high transmit power level (e.g., 20 Watts), while a pico base station, a femto base station, and a relay may have a lower transmit power level (e.g., 1 Watt).
[0100] Wireless network 100 may support synchronous or asynchronous operation. For synchronous operation, each base station may have similar frame timing, and transmissions from different base stations may be approximately aligned in time. For asynchronous operation, each base station may have different frame timing, and transmissions from different base stations may or may not be aligned in time. The techniques described herein may be used for both synchronous and asynchronous operation.
[0101] A network controller 130 may couple to a set of base stations and provide coordination and control for these base stations. Network controller 130 may communicate with base stations 110 via a backhaul. Base stations 110 may also communicate with each other, directly or indirectly, for example, via a wireless or wired backhaul.
[0102] User equipment (UE) devices 120 (e.g., 120x, 120y, etc.) can be dispersed throughout the wireless network 100, and each user equipment device can be stationary or mobile. Some user equipment devices can be considered to be evolved or machine type communication (MTC) devices or evolved MTC (eMTC) devices. MTC and eMTC user equipment devices include, for example, robots, drones, remote devices, sensors, meters, monitors, location tags, etc., which can communicate with a base station, another device (e.g., a remote device), or some other entity. A wireless node can provide connectivity to or to a network (e.g., a wide area network (such as the Internet) or a cellular network), for example, via a wired or wireless communication link. Some user equipment devices can be considered to be Internet of Things (IoT) devices.
[0103] exist Figure 1 In the figure, a solid line with double arrows may indicate a desired transmission between a user equipment device and a serving base station, which is a base station designated to serve the user equipment device on a downlink and / or uplink. A dashed line with double arrows may indicate an interfering transmission between a user equipment device and a base station.
[0104] A NR base station (e.g., an eNB, a 5G B node, a B node, a transmit receive point (TRP), an access point (AP)) may correspond to one or more base stations. An NR cell may be configured as an access cell (ACell) or a data-only cell (DCell). For example, a RAN (e.g., a central unit or a distributed unit) may configure these cells. A DCell may be a cell used for carrier aggregation or dual connectivity but not for initial access, cell selection / reselection, or switching. The NR base station may transmit a downlink signal indicating the cell type to a user equipment device. Based on the cell type indication, the user equipment device may communicate with the NR base station. For example, the user equipment device may determine the NR base station to be considered for cell selection, access, switching (HO) and / or measurement based on the indicated cell type.
[0105] Various aspects may be implemented on a number of single-processor and multi-processor computer systems, including SOCs or SIPs. Figure 2 The present invention illustrates a method for implementing various aspects in a user equipment or a user equipment device (e.g., Fig.10 An example computing system or SIP 200 architecture used in the smart phone illustrated in FIG.
[0106] exist Figure 1 and Figure 2In the example illustrated in , the SIP 200 includes two SOCs 202, 204, a clock 206, and a voltage regulator 208. In some aspects, the first SOC 202 operates as a central processing unit (CPU) of a user equipment device, which executes instructions of a software application by performing arithmetic, logic, control, and input / output (I / O) operations specified by the instructions. In some aspects, the second SOC 204 can operate as a dedicated processing unit. For example, the second SOC 204 can operate as a dedicated 5G processing unit responsible for managing high-capacity, high-speed (e.g., 5 Gbps, etc.) and / or ultra-high frequency short-wave length (e.g., 28 GHz millimeter wave (mmWave) spectrum, etc.) communications.
[0107] exist Figure 2 In the example illustrated in FIG. 2 , the first SOC 2 includes a digital signal processor (DSP) 210, a modem processor 212, a graphics processor 214, an application processor 216, one or more coprocessors 218 (e.g., vector coprocessors) connected to one or more of these processors, a memory 220, a custom circuit system 222, system components and resources 224, an interconnect / bus module 226, and a thermal management unit 232. The second SOC 204 may include a 5G modem processor 252, a power management unit 254, an interconnect / bus module 264, a plurality of millimeter wave transceivers 256, a memory 258, and various additional processors 260 (such as an application processor, a packet processor, etc.).
[0108] Thermal management unit 232 may be configured to monitor and manage user equipment device surface / skin temperature and / or ongoing power consumption caused by active components that generate heat in the user equipment device. Thermal management unit 232 may intelligently and dynamically determine whether to throttle the execution of active processing components (e.g., CPU, GPU, LCD brightness), the processor that should be throttled, the level to which the frequency of the processor should be throttled, when throttling should occur, etc.
[0109] Each processor 210, 212, 214, 216, 218, 252, 260 may include one or more cores, and each processor / core may perform operations independently of other processors / cores. For example, the first SOC 202 may include a processor that executes a first type of operating system (e.g., FreeBSD, LINUX, OS X, etc.) and a processor that executes a second type of operating system (e.g., MICROSOFT WINDOWS10, etc.). In addition, any or all of the processors 210, 212, 214, 216, 218, 252, 260 may be included as part of a processor cluster architecture (e.g., a synchronous processor cluster architecture, an asynchronous or heterogeneous processor cluster architecture, etc.).
[0110] The first and second SOCs 202, 204 may include various system components, resources, and custom circuitry for managing sensor data, analog-to-digital conversion, wireless data transmission, and for performing other specialized operations (such as decoding data packets and processing encoded audio and video signals for rendering in a web browser). For example, the system components and resources 224 of the first SOC 202 may include power amplifiers, voltage regulators, oscillators, phase-locked loops, peripheral bridges, data controllers, memory controllers, system controllers, access ports, timers, and other similar components used to support processors and software clients running on user equipment devices. The system components and resources 224 and / or custom circuitry 222 may also include circuitry for docking with peripheral devices (such as cameras, electronic displays, wireless communication devices, external memory chips, etc.).
[0111] The first and second SOCs 202, 204 may communicate via an interconnect / bus module 250. The various processors 210, 212, 214, 216, 218 may be interconnected to one or more memory elements 220, system components and resources 224, and custom circuitry 222, and a thermal management unit 232 via an interconnect / bus module 226. Similarly, the processors may be interconnected to a power management unit 256, a millimeter wave transceiver 256, a memory 258, and various additional processors 260 via an interconnect / bus module 264. The interconnect / bus modules 226, 250, 264 may include an array of reconfigurable logic gates and / or implement a bus architecture (e.g., CoreConnect, AMBA, etc.). Communications may be provided by an advanced interconnect, such as a high-performance network on chip (NoC).
[0112] The first and / or second SOC 202, 204 may further include input / output modules (not illustrated) for communicating with resources external to the SOC, such as clock 206 and voltage regulator 208. Resources external to the SOC (e.g., clock 206, voltage regulator 208) may be shared by two or more internal SOC processors / cores.
[0113] In addition to SIP 200 discussed above, various aspects may be implemented in a variety of computing systems that may include a single processor, multiple processors, multi-core processors, or any combination thereof.
[0114] Figure 3 Illustrated are methods for communicating with a communication system (e.g., a communication system) that may be configured to support network slicing according to various embodiments. Figure 1 Method 300 for performing a registration procedure in a wireless network 100 as described in the foregoing. Figure 3In the example illustrated in , method 300 is performed in a communication system including a user equipment (UE) device, a (R)AN component, a new AMF component, an old AMF component, an EIR component, a N3IWF component, a PCF component, an SMF component, an AUSF component, and a UDM component.
[0115] In operation 1, the UE may send an AN message and a UE policy container to the (R)AN component. The AN message may include AN parameters, a registration request (registration type, SUCI or 5G-GUTI or PEI, the last visited TAI (if available), security parameters, requested NSSAI, mapping of requested NSSAI, default configured NSSAI indication, UE radio capability update, UE MM core network capability, PDU session status, list of PDU sessions to be activated, follow-on request, MICO mode preference, requested DRX parameters, (all) LADN DNN and / or indicator requesting LADN information. The UE policy container may include a PSI list, an indication that the UE supports ANDSP, and / or an operating system identifier.
[0116] In the case of NG-RAN, the AN parameters may include, for example, 5G-S-TMSI or GUAMI, the selected PLMN ID and the requested NSSAI, and / or an establishment cause providing the reason for requesting to establish an RRC connection. The registration type may indicate whether the UE wants to perform an initial registration (i.e., the UE is in RM-DEREGISTERED state), a mobility registration update (i.e., the UE is in RM-REGISTERED state and the registration procedure is initiated due to mobility or because the UE needs to update its capabilities or protocol parameters or request a change in the set of network slices it is allowed to use), a periodic registration update (i.e., the UE is in RM-REGISTERED state and the registration procedure is initiated due to the expiration of the periodic registration update timer), or an emergency registration (i.e., the UE is in a restricted service state).
[0117] When the UE is performing an initial registration, the UE may indicate its UE identity in the Registration Request message. If the UE has previously registered in the EPS and has a valid EPS GUTI, the Registration Request message may include a 5G-GUTI, a local 5G-GUTI assigned by the PLMN with which the UE is attempting to register, a local 5G-GUTI assigned by a PLMN equivalent to the PLMN with which the UE is attempting to register, and / or a local 5G-GUTI assigned by any other PLMN (which may also be a 5G-GUTI assigned via another access type). Otherwise, the Registration Request message may include a SUCI in the Registration Request.
[0118] If the UE has a NAS security context, the UE may include in the security parameters an indication that the NAS message is integrity protected and partially encrypted to indicate to the AMF how to handle the encapsulated parameters. If the UE does not have a NAS security context, the Registration Request message may simply contain a plain text IE.
[0119] When the UE is performing an initial registration using a local 5G-GUTI (i.e., the UE is in RM-DEREGISTERED state), the UE may indicate relevant GUAMI information in the AN parameters. When the UE is performing an initial registration using its SUCI, the UE may or may not indicate any GUAMI information in the AN parameters.
[0120] For emergency registration, if the UE does not have a valid 5G-GUTI available, SUCI may be included; when the UE does not have a SUPI and does not have a valid 5G-GUTI, PEI may be included. In other cases, 5G-GUTI may be included and it may indicate the last serving AMF.
[0121] The UE may provide the UE's usage settings based on its configuration. In the case of an initial registration or mobility registration update, the UE may include a mapping of the requested NSSAI (if available) (which is a mapping of each S-NSSAI in the requested NSSAI to the HPLMNS-NSSAI) to ensure that the network can verify whether the S-NSSAI(s) in the requested NSSAI are permitted based on the subscribed S-NSSAI. If the UE is using the default configured NSSAI, the UE may include a default configured NSSAI indication.
[0122] In the case of a mobility registration update, the UE may include in the list of PDU sessions to be activated PDU sessions for which there is pending uplink data. When the UE may include the list of PDU sessions to be activated, the UE may indicate only the PDU sessions associated with the access to which the registration request relates. The UE may include in the list of PDU sessions to be activated always-on PDU sessions accepted by the network, even if there is no pending uplink data for those PDU sessions.
[0123] It should be noted that when the UE is outside the availability area of the LADN, the PDU session corresponding to the LADN is not included in the list of PDU sessions to be activated.
[0124] UE MM core network capabilities may be provided by the UE and handled by the AMF. The UE may include in the UE MM core network capabilities an indication of whether it supports the request type flag "handover" for PDN connectivity requests during the attach procedure.
[0125] The UE may provide LADN DNN(s) or an indication to request LADN information.
[0126] If available, the last visited TAI may be included in order to help the AMF generate a registration area for the UE.
[0127] Security parameters may be used for authentication and integrity protection. The requested NSSAI may indicate network slice selection assistance information. The PDU session status may indicate a previously established PDU session in the UE. When the UE is connected to two AMFs belonging to different PLMNs via 3GPP access and non-3GPP access, the PDU session status may indicate the PDU session established in the UE by the current PLMN.
[0128] A subsequent request may be included when the UE has pending uplink signaling and the UE does not include a list of PDU sessions to be activated, or the registration type may indicate that the UE wants to perform an emergency registration. In initial registration and mobility registration update, the UE may provide UE requested DRX parameters.
[0129] The UE may provide a UE radio capability update indication.
[0130] UE access selection and PDU session selection may identify a list of UE access selection and PDU session selection policy information stored in the UE. They may be used by the PCF to determine whether the UE must be updated with a new PSI or whether some of the stored PSIs are no longer applicable and must be removed.
[0131] In operation 2, the (R)AN may select an AMF component. If the 5G-S-TMSI or GUAMI is not included, or the 5G-S-TMSI or GUAMI does not indicate a valid AMF, the (R)AN selects an AMF based on the (R)AT and the requested NSSAI (if available).
[0132] (R)AN selects AMF. If the UE is in CM-CONNECTED state, the (R)AN may forward the Registration Request message to the AMF based on the UE's N2 connection. If the (R)AN cannot select an appropriate AMF, it may forward the Registration Request to an AMF that has been configured in the (R)AN to perform AMF selection.
[0133] In operation 3, the (R)AN may send an N2 message or a registration request to the new AMF. The N2 message may include N2 parameters, a registration request, and a UE policy container. When using NG-RAN, the N2 parameters may include a selected PLMNID, location information, and a cell identity associated with the cell in which the UE is residing, and a UE context request that may indicate that a UE context including security information needs to be established at the NG-RAN. When using NG-RAN, the N2 parameters also include the establishment cause. A mapping of the requested NSSAI may be provided (if available). If the registration type indicated by the UE is a periodic registration update, operations 4 to 19 may be omitted. When the establishment cause is associated with a priority service (e.g., MPS, MCS), the AMF may include a message priority header to indicate priority information. Other NFs may relay priority information by including a message priority header in a service-based interface.
[0134] In operation 4, the new AMF may send a Namf_Communication_UEContextTransfer message to the old AMF. The Namf_Communication_UEContextTransfer may include a complete registration request. The new AMF may also send a Nudsf_UnstructuredDataManagement_Query() message to the UDSF (if deployed).
[0135] In case of UDSF deployment, if the UE's 5G-GUTI is included in the Registration Request and the serving AMF has changed since the last registration procedure, the new AMF retrieves the stored UE's SUPI and UE context directly from the UDSF using the Nudsf_UnstructuredDataManagement_Query service operation if the new and old AMFs are in the same AMF set and UDSF is deployed, or they may share the stored UE context via implementation-dependent means if UDSF is not deployed. This may include event subscription information for each NF consumer for a given UE. In this case, the new AMF performs and verifies integrity protection using the integrity-protected full Registration Request NAS message.
[0136] In the case of no UDSF deployment, if the UE's 5G-GUTI is included in the Registration Request and the serving AMF has changed since the last registration procedure, the new AMF may invoke the Namf_Communication_UEContextTransfer service operation on the old AMF including a complete Registration Request NAS message that may be integrity protected and the access type to request the UE's SUPI and UE context. In this case, if the context transfer service operation call corresponds to the UE request, the old AMF verifies the integrity protection using the 5G-GUTI and the integrity protected complete Registration Request NAS message, or the SUPI and an indication that the UE is authenticated from the new AMF. The old AMF also transmits event subscription information for the UE by each NF consumer to the new AMF.
[0137] If the old AMF has a PDU Session for another access type (different from the access type indicated in this operation) and if the old AMF determines that it is not possible to relocate the N2 interface to the new AMF, the old AMF returns the UE's SUPI and may indicate that the Registration Request has been validated for integrity protection, but does not include the rest of the UE context.
[0138] It should be noted that in the case where the new AMF has performed a successful UE authentication after a previous integrity check failure in the old AMF, the new AMF sets an indication that the UE is verified according to operation 9a. It should also be noted that after the UE successfully registers with the new AMF, the NF consumer does not need to subscribe to events with the new AMF again.
[0139] If the new AMF has received the UE context from the old AMF during the handover procedure, operations 4, 5 and 10 may be skipped.
[0140] For emergency registration, if the UE identifies itself with a 5G-GUTI that is not known to the AMF, operations 4 and 5 are skipped and the AMF immediately requests a SUPI from the UE. If the UE identifies itself with a PEI, the SUPI request may be skipped. Allowing emergency registration without user identity depends on local regulations.
[0141] In operation 5 (old AMF to new AMF: in response to Namf_Communication_UEContextTransfer(SUPI in AMF, UE context) or UDSF to new AMF: Nudsf_UnstructuredDataManagement_Query()), the old AMF may start an implementation-specific (protection) timer for the UE context.
[0142] If the UDSF is queried in operation 4, the UDSF responds to the new AMF for the Nudsf_UnstructuredDataManagement_Query call with the relevant context including the established PDU session, the old AMF includes the SMF information DNN, (s) S-NSSAI and PDU session ID, the active NGAP UE-TNLA binding to the N3IWF, and the old AMF includes information about the NGAP UE-TNLA binding. If the old AMF is queried in operation 4, the old AMF responds to the new AMF for the Namf_Communication_UEContextTransfer call by including the UE's SUPI and UE context.
[0143] If the old AMF saves information about the established PDU session(s), the old AMF includes SMF information, DNN(s), S-NSSAI(s) and PDU session ID(s).
[0144] If the old AMF holds information about the active NGAP UE-TNLA binding to the N3IWF, the old AMF includes information about the NGAP UE-TNLA binding.
[0145] If the old AMF fails the integrity check of the Registration Request NAS message, the old AMF may indicate an integrity check failure.
[0146] If the old AMF holds information about AM policy association, the old AMF includes information about AM policy association including policy control request trigger and PCF ID. In the case of roaming, V-PCF ID and H-PCF ID are included.
[0147] It should be noted that when the new AMF uses UDSF for context retrieval, the interaction between the old AMF, new AMF and UDSF is an implementation issue due to UE signaling on the old AMF at the same time.
[0148] In operation 6, New AMF to UE: Identity Request (), if the SUCI is not provided by the UE or not retrieved from the old AMF, the Identity Request procedure is initiated by the AMF to send an Identity Request message to the UE requesting the SUCI.
[0149] In operation 7: UE to new AMF: Identity Response(), the UE responds with an Identity Response message including the SUCI. The UE derives the SUCI by using the provided public key of the HPLMN.
[0150] In operation 8, the AMF may decide to initiate UE authentication by invoking the AUSF. In this case, the AMF selects the AUSF based on the SUPI or SUCI. If the AMF is configured to support emergency registration for unauthenticated SUPI and the UE indicated registration type Emergency Registration, the AMF skips the authentication or the AMF accepts that the authentication may fail and continues the registration procedure.
[0151] In operation 9a, if authentication is required, the AMF may request authentication from the AUSF; or if the tracking requirement about the UE is available at the AMF, the AMF provides the tracking requirement in its request to the AUSF. Upon the request from the AMF, the AUSF may perform authentication of the UE. The AUSF selects the UDM and obtains authentication data from the UDM.
[0152] Once the UE has been authenticated, the AUSF provides the relevant security related information to the AMF. In the case where the AMF provides the SUCI to the AUSF, the AUSF may return the SUPI to the AMF only after successful authentication.
[0153] After successful authentication in the new AMF (which was triggered by the integrity check failure in the old AMF in operation 5), the new AMF invokes operation 4 above again and may indicate that the UE is authenticated (i.e. through the cause parameter).
[0154] In operation 9b, if the NAS security context does not exist, NAS security initiation may be performed. If the UE does not have a NAS security context in operation 1, the UE may include a complete registration request message.
[0155] The AMF decides whether the registration request needs to be rerouted, where the initial AMF refers to this AMF.
[0156] In operation 9c, if 5G-AN has requested UE context, AMF initiates NGAP procedure to provide security context to 5G-AN. In addition, if the tracking requirement about UE is available at AMF, AMF provides the tracking requirement to 5G-AN in the NGAP procedure.
[0157] In operation 9d, the 5G-AN stores the security context and acknowledges it to the AMF. The 5G-AN uses the security context to protect messages exchanged with the UE.
[0158] In operation 10 (new AMF to old AMF: Namf_Communication_RegistrationCompleteNotify()), if the AMF has changed, the new AMF notifies the old AMF of the completion of the UE's registration in the new AMF by invoking the Namf_Communication_RegistrationCompleteNotify service operation. If the authentication / security procedures fail, the registration may be rejected and the new AMF invokes the Namf_Communication_RegistrationCompleteNotify service operation with a reject indication cause code towards the old AMF. The old AMF proceeds as if the UE Context Transfer service operation had never been received.
[0159] If one or more of the S-NSSAIs used in the old registration area cannot be served in the target registration area, the new AMF determines which PDU sessions cannot be supported in the new registration area. The new AMF invokes the Namf_Communication_RegistrationCompleteNotify service operation towards the old AMF including the rejected PDU session ID and the rejection reason (e.g., the S-NSSAI becomes no longer available). Subsequently, the new AMF modifies the PDU session state accordingly. The old AMF notifies the corresponding SMF(s) to release the UE's SM context locally by calling the Nsmf_PDUSession_ReleaseSMContext service operation.
[0160] If the new AMF receives information about AM policy association including PCF ID(s) in the UE context transfer in operation 2, and decides based on local policy not to use the PCF(s) identified by the PCF ID(s) for the AM policy association, it will notify the old AMF to no longer use the AM policy association in the UE context, and then perform PCF selection in operation 15.
[0161] In operation 11 (New AMF to UE: Identity Request / Response (PEI)), if the PEI is not provided by the UE or not retrieved from the old AMF, the Identity Request procedure is initiated by the AMF sending an Identity Request message to the UE to retrieve the PEI. The PEI may be transmitted encrypted unless the UE performs an emergency registration and cannot be authenticated. For emergency registration, the UE may have included the PEI in the Registration Request. If so, the PEI retrieval is skipped.
[0162] In operation 12, the new AMF may initiate an ME identity check by calling the N5g-eir_EquipmentIdentityCheck_Get service operation. A PEI check may also be performed. For emergency registration, if PEI is blocked, the operator policy may be used to determine whether the emergency registration procedure continues or stops. If operation 14 is to be performed, the new AMF may select a UDM based on the SUPI, which may then select a UDR instance.
[0163] In operation 13, the AMF may select the UDM.
[0164] In operations 14a-c, if the AMF has changed since the last registration procedure, or if the UE can provide a SUPI that does not involve a valid context in the AMF, or if the UE registers to the same AMF that it has registered to for a non-3GPP access (i.e., the UE is registered on a non-3GPP access and initiates this registration procedure to add a 3GPP access), the new AMF registers with the UDM using Nudm_UECM_Registration for the access to be registered (and subscribes to be notified when the UDM deregisters the AMF). The AMF provides the UDM with an indication of "Homogeneous support for IMS voice over PS sessions". "Homogeneous support for IMS voice over PS sessions" may or may not be included unless the AMF has completed its evaluation of support for "IMS voice over PS sessions".
[0165] It should be noted that at this point, the AMF may or may not have all the information required to determine the settings for the indication of support for IMS voice over PS session for this UE. Therefore, the AMF may send "Homogeneous support for IMS voice over PS session" later in this procedure.
[0166] If the AMF does not have subscription data for the UE, the AMF uses Nudm_SDM_Get to retrieve access and mobility subscription data, SMF selection subscription data and UE context in SMF data. This may require the UDM to retrieve information from the UDR via Nudr_DM_Query. After receiving a successful response, the AMF uses Nudm_SDM_Subscribe to subscribe to be notified when the requested data is modified, and the UDM may subscribe to the UDR via Nudr_DM_Subscribe. If the GPSI is available in the UE subscription data, the GPSI is provided to the AMF in the access and mobility subscription data from the UDM. The UDM may provide indications about updating subscription data for network slicing for the UE. If the UE subscribes to MPS in the serving PLMN, "MPS Priority" may be included in the access and mobility subscription data provided to the AMF. If the UE is subscribed to MCX in the serving PLMN, the "MCX Priority" may be included in the access and mobility subscription data provided to the AMF.
[0167] The new AMF provides the UDM with the access type it serves for the UE, and the access type is set to "3GPP access". The UDM stores the associated access type with the serving AMF and does not remove the AMF identity associated with other access types (if any). The UDM may store the information provided at the time of AMF registration in the UDR via Nudr_DM_Update. If the UE is registered for access in the old AMF and the old AMF and the new AMF are in the same PLMN, then after the relocation of the old AMF is successfully completed, the new AMF may send a separate / independent Nudm_UECM_Registration to update the UDM with the access type set to the access used in the old AMF. The new AMF may create a UE context for the UE after obtaining the access and mobility subscription data from the UDM. The access and mobility subscription data may include whether the UE is allowed to include the NSSAI in plain text in the 3GPP access RRC connection establishment.
[0168] For emergency registrations where the UE is not successfully authenticated, the AMF may or may not register with the UDM. For emergency registrations, the AMF may or may not check access restrictions, regional restrictions or subscription restrictions. For emergency registrations, the AMF may ignore any unsuccessful registration response from the UDM and continue with the registration procedure.
[0169] In operation 14d, when the UDM stores the associated access type (e.g., 3GPP) with the serving AMF as indicated in operation 14a, this operation will cause the UDM to initiate a Nudm_UECM_DeregistrationNotification to the old AMF (if any) corresponding to the same (e.g., 3GPP) access.
[0170] If the timer started in operation 5 is not running, the old AMF may remove the UE context.
[0171] Otherwise, the AMF may remove the UE context when the timer expires. If the service NF removal reason indicated by the UDM is the initial registration, the old AMF calls the Nsmf_PDUSession_ReleaseSMContext(SUPI, PDU session ID) service operation towards all associated SMFs of the UE to notify the UE to deregister from the old AMF. (S)SMFs may release the PDU session upon obtaining this notification. If the old AMF has established a policy association with the PCF and the old AMF has not transmitted (S)PCF IDs to the new AMF (for example, the new AMF is in a different PLMN), the old AMF performs an AMF-initiated policy association termination procedure to delete the association with the PCF. In addition, if the old AMF transmitted (S)PCF IDs in the UE context, but the new AMF notifies in operation 10 that the AM policy association information in the UE context will not be used, the old AMF performs an AMF-initiated policy association termination procedure to delete the association with the PCF. If the old AMF has an N2 connection for the UE (e.g. because the UE was RRC Inactive but has now moved to E-UTRAN or to an area not served by the old AMF), the old AMF may perform an AN Release with a Cause Value indicating that the UE has locally released the RRC Connection to the NG-RAN.
[0172] In operation 14e, the old AMF may use Nudm_SDM_unsubscribe to unsubscribe the subscription data from the UDM.
[0173] In operation 15, if the AMF decides to initiate PCF communication, the AMF operates as follows. If the new AMF decides to contact the (V-)PCF identified by the PCF ID included in the UE context from the old AMF in operation 5, the AMF may contact the (V-)PCF identified by the (V-)PCF ID. If the AMF decides to perform PCF discovery and selection, the AMF selects the (V)-PCF and may select the H-PCF (for roaming scenarios) based on the V-NRF to H-NRF interaction.
[0174] In operation 16, the new AMF may perform an AM policy association modification. For emergency registration, this operation is skipped. If the new AMF contacts the PCF identified by the (V-)PCF ID received during inter-AMF mobility in operation 5, the new AMF may include the PCF ID(s) in the Npcf_AMPolicyControl Create operation. This indication may or may not be included by the AMF during the initial registration procedure.
[0175] If the AMF notifies the PCF of mobility restrictions (e.g., UE location) for adjustment, or if the PCF updates its own mobility restrictions due to some conditions (e.g., applications in use, time and date), the PCF may provide the updated mobility restrictions to the AMF. If the subscription information includes a tracking requirement, the AMF may provide the tracking requirement to the PCF.
[0176] In operation 17, the new AMF may send Nsmf_PDUSession_UpdateSMContext() to the AMF. For emergency registered UEs, this operation may be applied when the registration type is mobility registration update. The AMF may call Nsmf_PDUSession_UpdateSMContext in the following scenario(s): If the list of PDU sessions to be activated may be included in the registration request in operation 1, the AMF may send a Nsmf_PDUSession_UpdateSMContext request to the SMF(s) associated with the PDU session(s) to activate the user plane connection for these PDU sessions. The operations starting from operation 5 may be performed to complete the user plane connection activation without sending RRC inactive assistance information and without sending MM NAS service acceptance from the AMF to the (R)AN as described in operation 12. When the serving AMF has changed, the new serving AMF informs the SMF for each PDU Session that it has taken over the responsibility for the signaling path towards the UE: the new serving AMF calls the Nsmf_PDUSession_UpdateSMContext service operation using the SMF information received from the old AMF at operation 5. It may also indicate whether the PDU Session is to be reactivated. In the case of a PLMN change from V-PLMN to H-PLMN, the new serving AMF only calls the Nsmf_PDUSession_UpdateSMContext service operation for the PDU Session(s) of the home route.
[0177] It should be noted that if the UE moves into the V-PLMN, the AMF in the V-PLMN cannot insert or change the V-SMF(s) even for the PDU sessions of the home route(s), and operation 5 may be performed. In the case where an intermediate UPF insertion, removal or change is performed for the PDU sessions(s) not included in the "PDU sessions(s) to be reactivated", this procedure is performed without N11 and N2 interaction to update the N3 user plane between the (R)AN and the 5GC. The AMF calls the Nsmf_PDUSession_ReleaseSMContext service operation towards the SMF in the following scenario: If any PDU session status may indicate that it is released at the UE, the AMF calls the Nsmf_PDUSession_ReleaseSMContext service operation towards the SMF to release any network resources related to the PDU session. If the serving AMF changes, the new AMF may wait until operation 18 is completed under all SMFs associated with the UE. Otherwise, operations 19 to 22 may continue in parallel with this operation.
[0178] In operation 18 (New AMF to N3IWF: N2 AMF Mobility Request()), if the AMF has changed and the old AMF has indicated an existing NGAP UE association towards the N3IWF, the new AMF creates an NGAP UE association towards the N3IWF to which the UE is connected. This automatically releases the existing NGAP UE association between the old AMF and the N3IWF.
[0179] In operation 19 (N3IWF to new AMF), N2 AMF mobility response () is sent.
[0180] In operation 20a (old AMF to (V-)PCF: AMF initiated UE policy association termination), if the old AMF previously initiated UE policy association to the PCF, and the old AMF did not transmit the PCF ID(s) to the new AMF (for example, the new AMF is in a different PLMN), the old AMF performs the AMF initiated UE policy association termination procedure to delete the association with the PCF. In addition, if the old AMF transmitted the PCF ID(s) in the UE context, but the new AMF notified in operation 10 that the UE policy association information in the UE context will not be used, the old AMF performs the AMF initiated UE policy association termination procedure to delete the association with the PCF.
[0181] In operation 21, the new AMF may generate and send an N2 message including a registration acceptance and a pending slice-specific secondary authentication information element to the UE. The N2 message may also include an allowed NSSAI element that contains only S-NSSAI based on subscription information without requiring slice-specific secondary authentication.
[0182] In some embodiments, the pending slice-specific secondary authentication may be included in the N2 message based on whether the requested NSSAI includes an S-NSSAI mapped to an S-NSSAI in the HPLMN having an indication in the subscription information that it is subject to network slice-specific secondary authentication. In such a case, the AMF may trigger the network slice-specific secondary authentication and authorization in operation 25 (discussed below).
[0183] The Registration Accept may include 5G-GUTI, Registration Area, Mobility Restrictions, PDU Session Status, Allowed NSSAI, Mapping of Allowed NSSAI, Configured NSSAI for Serving PLMN, Mapping of Configured NSSAI, Rejected S-NSSAI, Periodic Registration Update Timer, LADN Information and Accepted MICO Mode, Indication of IMS Voice Support over PS Session, Emergency Services Support Indicator, Accepted DRX Parameters, Network Support for Interworking without N26, Access Stratum Connection Establishment NSSAI Include Mode, Network Slice Subscription Change Indication, Operator Defined Access Class Definition, and / or Pending Slice-Specific Secondary Authentication. The Allowed NSSAI for the Access Type of the UE may be included in the N2 message carrying the Registration Accept message. The Allowed NSSAI contains only S-NSSAI based on subscription information without requiring slice-specific secondary authentication.
[0184] The AMF may send a Registration Accept message to the UE indicating that the registration request has been accepted. If the AMF assigns a new 5G-GUTI, the 5G-GUTI may be included. If the UE is already in the RM-REGISTERED state via another access in the same PLMN, the UE may use the 5G-GUTI received in the Registration Accept for both registrations. If no 5G-GUTI may be included in the Registration Accept, the UE will also use the 5G-GUTI assigned to the existing registration for the new registration. If the AMF assigns a new registration area, it may send the registration area to the UE via a Registration Accept message. If the registration area is not included in the Registration Accept message, the UE may consider the old registration area to be valid. In the case where mobility restrictions apply to the UE and the registration type is not an emergency registration, mobility restrictions may be included. The AMF may indicate the established PDU session to the UE in the PDU session status. The UE locally removes any internal resources associated with the PDU session that is not marked as established in the received PDU session status. If the AMF calls the Nsmf_PDUSession_UpdateSMContext procedure for UP activation of (all) PDU sessions in operation 18 and receives a rejection from the SMF, the AMF may indicate to the UE the reason why the PDU session ID and the user plane resources are not activated. When the UE is connected to two AMFs belonging to different PLMNs via 3GPP access and non-3GPP access, the UE locally removes any internal resources related to the PDU sessions in the current PLMN that are not marked as established in the received PDU session status. If the PDU session status information is in the registration request, the AMF may indicate the PDU session status to the UE. The mapping of allowed NSSAI is the mapping of each S-NSSAI in the allowed NSSAI to the HPLMN S-NSSAI. The mapping of configured NSSAI is the mapping of each S-NSSAI in the configured NSSAI for the serving PLMN to the HPLMN S-NSSAI. The AMF may include in the registration accept message the LADN information of the list of LADNs available within the registration area determined by the AMF for the UE. If the UE includes MICO mode in the request, the AMF responds whether MICO mode should be used. The AMF may include operator-defined access class definitions to let the UE determine the applicable operator-specific access class definitions.
[0185] In case of registration on 3GPP access, the AMF sets the indication of support for IMS voice over PS session. In order to set the indication of support for IMS voice over PS session, the AMF may need to perform the UE capability match request procedure to check the compatibility of UE and NG-RAN radio capabilities related to IMS voice over PS. If the AMF does not receive the Voice Support Match Indicator from the NG-RAN on time, based on the implementation, the AMF may set the indication of support for IMS voice over PS session and update the indication at a later stage.
[0186] In case of registration on non-3GPP access, the AMF sets an indication of support for IMS Voice over PS session.
[0187] The emergency service support indicator informs the UE that emergency services are supported, i.e. the UE is allowed to request a PDU session for emergency services. If the AMF receives "MPS Priority" from the UDM as part of the access and mobility subscription data, then based on the operator policy, the "MPS Priority" may be included in the Registration Accept message to the UE to inform the UE whether the configuration of Access Identity 1 is valid within the selected PLMN. If the AMF receives "MCX Priority" from the UDM as part of the access and mobility subscription data, then based on the operator policy and the UE's subscription to the MCX service, the "MCX Priority" may be included in the Registration Accept message to the UE to inform the UE whether the configuration of Access Identity 2 is valid within the selected PLMN. The AMF sets up interworking without N26 parameters.
[0188] If the UDM is intended to indicate to the UE that a subscription has changed, a network slice subscription change indication may be included. If the AMF includes a network slice subscription change indication, the UE may locally erase all network slice configurations for all PLMNs and, if applicable, update the configuration for the current PLMN based on any received information.
[0189] The Access Stratum Connection Establishment NSSAI Include Mode may be included to instruct the UE what NSSAI (if any) to include in the Access Stratum Connection Establishment. The AMF may set the value to operation modes a, b, c in 3GPP access only if including NSSAI in the allowed RRC connection establishment may indicate that this is allowed.
[0190] If the requested NSSAI includes an S-NSSAI mapped to an S-NSSAI in the HPLMN that has an indication in the subscription information that it is subject to network slice specific secondary authentication, then a pending slice specific secondary authentication may be included. In such a case, the AMF then triggers the network slice specific secondary authentication and authorization at operation 25.
[0191] In operation 21b (new AMF performs UE policy association establishment), the new AMF may send a Npcf_UEPolicyControl creation request to the PCF. The PCF may send a Npcf_UEPolicyControl creation response to the new AMF. The PCF triggers the UE configuration update procedure. This operation may be skipped for emergency registration.
[0192] In operation 22, the UE may send a registration complete message to the AMF. Unlike conventional systems, the rejected NSSAI will not contain any S-NSSAI for which a slice-specific secondary authentication needs to be performed. Instead, the S-NSSAI for which a slice-specific secondary authentication needs to be performed is represented via a pending slice-specific secondary authentication.
[0193] Specifically, when the UE successfully updates itself after receiving any one of the configured NSSAI, the mapping of the configured NSSAI, and the network slice subscription change indication for the serving PLMN in operation 21, the UE may send a registration complete message to the AMF. The UE may send a registration complete message to the AMF to confirm whether the new 5G-GUTI is assigned. If the new 5G-GUTI is assigned, when the lower layer (3GPP access or non-3GPP access) indicates to the RM layer of the UE that the registration complete message has been successfully transmitted across the radio interface, the UE may pass the new 5G-GUTI to the lower layer of its 3GPP access.
[0194] It should be noted that these operations may be required due to the use of RRC Inactive state by NG-RAN and part of the 5G-GUTI is used to calculate the paging frame. It can be assumed that the Registration Complete is reliably delivered to the AMF after the 5G-AN has acknowledged its receipt to the UE.
[0195] When the list of PDU sessions to be activated is not included in the Registration Request and the Registration procedure is not initiated in the CM-CONNECTED state, the AMF releases the signaling connection with the UE. When a subsequent request is included in the Registration Request, the AMF shall not release the signaling connection after the Registration procedure is completed. If the AMF knows that there is some signaling pending in the AMF or between the UE and the 5GC, the AMF shall not release the signaling connection immediately after the Registration procedure is completed.
[0196] The rejected NSSAI does not contain any S-NSSAI for which slice-specific secondary authentication needs to be performed.
[0197] In operation 23, for registration on 3GPP access, if the AMF has not released the signaling connection, the AMF may send RRC inactive assistance information to the NG-RAN. For registration on non-3GPP access, if the UE is still in the CM-CONNECTED state on the 3GPP access, the AMF may send RRC inactive assistance information to the NG-RAN.
[0198] In addition, in operation 23, if the access and mobility subscription data provided by the UDM to the AMF in operation 14b includes roaming steering information with an indication that the UDM requests confirmation of receipt of the information from the UE, the AMF may use Nudm_SDM_Info (Nudm_SDM_Information) to provide the UDM with UE confirmation. The AMF also uses the Nudm_SDM_Info service operation to provide the UDM with confirmation that the UE received the network slice subscription change indication (see operations 21 and 22) and took action on it.
[0199] In operation 24, after operation 14a, and in parallel with any of the preceding operations, the AMF may send a "homomorphic support for IMS voice over PS sessions" indication to the UDM using Nudm_UECM_Update if the AMF has evaluated support for IMS voice over PS sessions, and if the AMF determines that it needs to update homomorphic support for IMS voice over PS sessions.
[0200] In operation 25, if any S-NSSAI of the HPLMN is subject to network slice-specific secondary authentication and authorization, the relevant procedures are performed at this operation. Once the slice-specific secondary authentication is completed for all S-NSSAIs, the AMF may trigger the UE configuration update procedure to deliver new allowed NSSAI and new rejected NSSAI depending on the result of the slice-specific secondary authentication. Mobility-related event notifications towards the NF consumer may be triggered at the end of this procedure for each situation.
[0201] A network slice specific secondary authentication and authorization procedure as described in various embodiments herein may be performed / implemented in operation 25. The procedure may be triggered for a network slice specific secondary authentication and authorization requirement with an AAA server for an S-NSSAI, which may be hosted by the H-PLMN operator or a third party having a business relationship with the H-PLMN. An AAA proxy in the serving PLMN may be involved (e.g., if the AAA server belongs to a third party). Otherwise, the interaction with the AAA server may be undertaken directly by the AUSF.
[0202] In some embodiments, network slice-specific secondary authentication and authorization procedures may be triggered by the AMF during the registration procedure (such as when some network slices require slice-specific secondary authentication, when the AMF determines that slice-specific secondary authentication is required for the S-NSSAI in the current allowed NSSAI (e.g., subscription change), and / or when the AAA server authenticating the network slice triggers re-authentication).
[0203] Figure 4 The operations and message flows 400 involved in performing secondary authentication and authorization procedures that vary by network slice according to various embodiments are illustrated. The operations and message flows 400 may be used as reference Figure 3 The operation 25 described is performed as part of the process.
[0204] In operation block 402, the AMF may trigger the start of a network slice-specific secondary authentication procedure for an S-NSSAI determined to require network slice-specific secondary authentication and authorization based on local policy, a change in subscription information, or a trigger from an AAA server.
[0205] In operation 404, the AMF may request the UE user ID (EAP ID) for EAP authentication for the S-NSSAI in a NAS MM transport message including the S-NSSAI. This may be the S-NSSAI of the H-PLMN instead of the locally mapped S-NSSAI value.
[0206] In operation 406, the UE may send the EAP ID for the S-NSSAI together with the S-NSSAI toward the AMF in a NAS MM transport message.
[0207] In operation 408, the AMF may send the EAP ID to the AUSF in Nausf_Communication_EAPMessage_Transfer(EAP ID Response, AAA-S Address, GIPSI, S-NSSAI).
[0208] In operation 410, if AAA-P exists (eg, because AAA-S belongs to a third party), the AUSF may call the Nausf_Communication_EAPmessageTransfer service to forward the message to the AAA-P. Otherwise, the AUSF forwards the message directly to the AAA-S.
[0209] In operation 412, the AAA-P may associate the AAA-S address with the S-NSSAI and forward the EAP identity message along with the S-NSSAI and the GPSI to the AAA-S addressable by the AAA-S address.
[0210] In operations 414 to 428, EAP messages are exchanged with the UE. One or more iterations of these steps may occur. For example, in operation 414, AAA-S may send an authentication response (EAP message, GPSI, S-NSSAI) to AAA-P.
[0211] In operation 416, the AAA-P may send NAusf_Communication_EAPMessageTransfer(EAP message, GPSI, S-NSSAI) to the AUSF.
[0212] In operation 418, the AUSF may send a Namf_Communication_N1N2MessageTransfer(EAP message, GPSI, S-NSSAI) to the AMF.
[0213] In operation 420, the AMF may send a NAS MM transmission (EAP message, S-NSSAI) to the UE.
[0214] In operation 422, the UE may send a NAS MM transmission (EAP message, S-NSSAI) to the AMF.
[0215] In operation 424, the AMF may send a Nausf_Communication_EAPMessageTransfer request (EAP message, AAA server address, GPSI, S-NSSAI) to the AUSF.
[0216] In operation 426, the AUSF may send a Naaa_Communication_EAPMessageTransfer(EAP message, AAA-S address, GPSI, S-NSSAI) to the AAA-P.
[0217] In operation 428, AAA-P may send an authentication request (EAP message, GPSI, S-NSSAI) to AAA-S.
[0218] In operation 430, EAP authentication is complete and the AAA-S may send an EAP success / failure message along with the GPSI and S-NSSAI to the AAA-P (or directly to the AUSF if the AAA-P does not exist).
[0219] In operation 432, if AAA-P is used, AAA-P may send a Nausf_Communication_EAPmessageTransfer (EAP success / failure, S-NSSAI, GPSI) to the AUSF.
[0220] In operation 434, the AUSF may send a Namf_Communication_N1N2MessageTransfer (EAP success / failure, S-NSSAI, GPSI) to the AMF.
[0221] In operation 436, the AMF may transmit a NAS MM transport message (EAP success / failure, S-NSSAI, V-PLMN mapped S-NSSAI) to the UE. For the S-NSSAI received with the indication of the registration request, the UE may be configured not to request a PDU session establishment until the next registration procedure is completed in operation block 438.
[0222] In operation block 438, if a new allowed NSSAI or unauthorized NSSAI or a new rejected NSSAI needs to be delivered to the UE, or if AMF reallocation is required, the AMF may initiate a UE configuration update procedure.
[0223] Figure 5 The operations and message flows 500 of performing a AAA server-triggered, network slice-specific, secondary re-authentication and re-authorization procedure according to various embodiments are explained.
[0224] In operation 502, the AAA-S (AAA server) may request re-authentication and re-authorization for the UE identified by the GPSI in the re-authentication request message for the network slice specified by the S-NSSAI in the re-authentication request message. The re-authentication request message may be sent to the AAA-P when it is used (e.g., the AAA server belongs to a third party), otherwise it may be sent directly to the AUSF.
[0225] In operation 504, if present, the AAA-P (third party AAA server) may relay the request to the AUSF. In some embodiments, the AAA-P may relay the request via NAusf_ReauthenticationRequest (GPSI, S-NSSAI).
[0226] In operation 506, the AUSF may request the relevant AMF to re-authenticate / re-authorize the S-NSSAI for the UE (the AUSF may need to retrieve the current UE location). In some embodiments, the AAA-P may request the AMF to re-authenticate / re-authorize the S-NSSAI via Namf_ReauthenticationRequest(GPSI, S-NSSAI).
[0227] In operation 508, the AMF may trigger the reference Figure 4 The secondary authentication and authorization procedures that vary by network slice are explained and described.
[0228] Figure 6 Illustrated are the operations and message flow 600 for performing AAA server-triggered, network slice-specific secondary authorization revocation according to one embodiment.
[0229] In operation 602, the AAA-S (AAA server) may request deauthorization for the UE identified by the GPSI in the Deauthentication Request (GPSI, S-NSSAI) message for the network slice identified by the S-NSSAI in the message. The Deauthentication Request message may be sent to the AAA-P when it is used (e.g., the AAA server belongs to a third party), otherwise it may be sent directly to the AUSF.
[0230] In operation 604, if present, the AAA-P (third party AAA server) may relay the request to the AUSF. In some embodiments, the AAA-P may relay the request via NAusf_DeauthenticationRequest (GPSI, S-NSSAI).
[0231] In operation 606, the AUSF may request the relevant AMF to revoke the S-NSSAI authorization for the UE. In some embodiments, the AAA-P may request the AMF to revoke the S-NSSAI authorization via Namf_RevokeAuthorizationRequest(GPSI, S-NSSAI).
[0232] In operation 608, the AMF may initiate a UE configuration update procedure to revoke the NSSAI from the allowed NSSAI. If the AMF needs to be reallocated, the UE configuration update may include a request for registration.
[0233] The UE configuration may be updated by the network at any time using the UE configuration update procedure. The UE configuration may include UE policies provided by the PCF, and access and mobility management related parameters determined and provided by the AMF. This includes the configured NSSAI and its mapping to the subscribed S-NSSAI, the allowed NSSAI and its mapping to the subscribed S-NSSAI, and the unauthorized NSSAI (if the UE configuration update procedure is triggered by the AMF after a slice-specific secondary authentication of the S-NSSAI).
[0234] When AMF needs to change UE configuration for access and mobility management related parameters, AMF initiates the relevant procedure. When PCF needs to change or provide new UE policy in UE, PCF initiates another procedure.
[0235] If the UE configuration update procedure requires the UE to initiate a registration procedure, the AMF explicitly indicates this to the UE.
[0236] When AAA server deauthentication of slice-specific secondary authentication for S-NSSAI is performed, procedures for changing UE configuration for access and mobility management related parameters may also be triggered.
[0237] Figure 7 A method 700 of performing secondary authorization that varies by network slice according to one embodiment is illustrated. The method 700 can be performed by a network server within a network component or serving as a network component, such as a network server serving as an AMF component.
[0238] In box 702, the network server may generate allowed network slice selection assistance information identifying a network slice authorized by at least one or both of the service provider or the external provider, and rejected or unauthorized network slice selection assistance information identifying a network slice that has not yet been authorized. In some embodiments, the network server may generate allowed network slice selection assistance information identifying a network slice authorized by at least one or both of the service provider or the external provider in box 702 by: generating an allowed NSSAI information element (IE) identifying a network slice authorized by at least one or both of the service provider or the external provider. In some embodiments, the network server may generate rejected or unauthorized network slice selection assistance information identifying a network slice that has not yet been authorized in box 702 by: generating rejected or unauthorized network slice selection assistance information identifying a network slice that has not yet been authorized by at least one or more of the service provider or the external provider. The rejected network slice selection assistance information may take the form of an unauthorized NSSAI information element (IE).
[0239] In some embodiments, in box 702, the network server may generate an unauthorized NSSAI information element or rejected or unauthorized network slice selection assistance information identifying a network slice that has not yet been authorized by the following operations: generating network slice selection assistance information that identifies network slices that have not yet been authorized by at least one or more of the service provider or the external provider and includes a rejection cause value for each network slice that identifies the reason why each network slice has not yet been authorized.
[0240] At block 704, the network server may send the allowed NSSAI and the unauthorized NSSAI to the user equipment device. For example, at block 704, the network server may send the allowed network slice selection assistance information generated at block 702 and the rejected or unauthorized network slice selection assistance information to the user equipment device.
[0241] Figure 8A method 800 of performing secondary authorization that varies by network slice according to another embodiment is illustrated. The method 800 can be performed by a network server within a network component or serving as a network component, such as a network server serving as an AMF component.
[0242] In box 802, the network server may generate allowed network slice selection assistance information (e.g., allowed NSSAI IE) that identifies network slices authorized by the service provider (e.g., by the mobile network operator based on subscription information and AMF policy) or previously authorized by the mobile network operator (based on subscription information and AMF policy) and an external provider.
[0243] At block 804, the network server may generate rejected or unauthorized network slice selection assistance information (e.g., Unauthorized NSSAI IE) identifying network slices that are authorized by the mobile network operator but have not passed authorization / verification by an external provider.
[0244] At block 806, the network server may send the allowed network slice selection assistance information and the rejected network slice selection assistance information generated at block 802 to the user equipment device. For example, the network server may send the allowed NSSAI and the unauthorized NSSAI and the rejected NSSAI to the user equipment device.
[0245] Therefore, in some embodiments (e.g., the above reference Figure 7 and Figure 8 In the described embodiments, etc., the network server may be configured to authorize access to network slices associated with services provided by an external provider for access and use by user equipment devices connected to the network via network components associated with the service provider by performing operations, the operations including: generating allowed network slice selection assistance information identifying network slices authorized by at least one or both of the service provider or the external provider; generating rejected network slice selection assistance information identifying network slices that have not yet been authorized; and sending the allowed network slice selection assistance information and the rejected network slice selection assistance information to the user equipment device.
[0246] In some embodiments (for example, the following reference Fig. 9In the described embodiments, etc., a user equipment device connected to a network via a network component associated with a service provider may be configured to access or use a network slice associated with a service provided by an external provider by: receiving allowed network slice selection assistance information identifying network slices authorized by at least one or both of the service provider or the external provider from a network server; receiving rejected network slice selection assistance information identifying network slices that have not yet been authorized from the network server; adding the network slices included in the rejected network slice selection assistance information to a requested network slice selection assistance information (NSSAI) information element (IE); and sending the requested NSSAI IE to the network server.
[0247] Fig. 9 A method 900 of performing network slice-specific secondary authorization according to an embodiment is illustrated. The method 900 may be performed by a processor in a user equipment device.
[0248] In box 901, the user equipment device may receive allowed network slice selection assistance information identifying a network slice authorized by at least one or both of a service provider or an external provider from a network server. In addition, in box 901, the user equipment device may receive rejected network slice selection assistance information identifying a network slice that has not yet been authorized from the network server. For example, in box 901, the user equipment device may receive allowed NSSAI and unauthorized NSSAI from a network server (e.g., an AMF network component). In some embodiments, in box 901, the user equipment device may receive an allowed NSSAI IE identifying a network slice authorized by at least one or both of a service provider or an external provider and rejected network slice selection assistance information identifying a network slice that has not yet been authorized by at least one or more of the service provider or the external provider.
[0249] At block 902, the user equipment device may add to the requested NSSAI the network slices included in the allowed NSSAI for the access type over which the requested NSSAI or a subset thereof is sent. For example, at block 902, the user equipment device may add to the requested NSSAI the network slices included in the allowed NSSAI for the access type over which the requested NSSAI is sent to the network server. In some embodiments, as part of the operation at block 902, the user equipment device may abandon the re-registration attempt for the network slice included in the rejected network slice selection assistance information until the network slice-specific authorization procedure has been completed. In some embodiments, the user equipment device may also determine whether the network slice-specific authorization procedure has been completed, and in response to determining that the network slice-specific authorization procedure has been completed (or in response to determining that the network slice can now be authorized, the network slice should be resubmitted for authorization by an external provider, etc.), add to the requested NSSAI the network slices included in the rejected network slice selection assistance information. In some embodiments, the user equipment device may also determine whether the network slice included in the rejected network slice selection assistance information should be resubmitted for authorization by the external provider.
[0250] return Fig. 9 , at block 904, if the UE determines that the slice can be authorized, the user equipment device may add the network slice included in the unauthorized NSSAI to the requested NSSAI. For example, at block 904, the user equipment device may add the network slice included in the rejected network slice selection assistance information to the requested NSSAI IE. At block 906, the user equipment device may send the requested NSSAI to a network server or component (e.g., an AMF component).
[0251] Various aspects may be implemented on various user equipment devices, examples of which are provided in Fig.10 1000 is illustrated in the form of a smart phone. Smart phone 1000 may include: a first SOC 202 (e.g., SOC-CPU) coupled to a second SOC 204 (e.g., a SOC with 5G capabilities). The first and second SOCs 202, 204 may be coupled to an internal memory 1006, a display 1012, and a speaker 1014. Additionally, the smart phone 1000 may include an antenna 1004 that can be connected to a wireless data link for sending and receiving electromagnetic radiation, and / or a cellular telephone transceiver 1008 coupled to one or more processors in the first and / or second SOCs 202, 204. Smart phone 1000 also typically includes a menu selection button or rocker switch 1020 for receiving user input.
[0252] The typical smart phone 1000 also includes a sound coding / decoding (CODEC) circuit 1010, which digitizes the sound received from the microphone into data packets suitable for wireless transmission, and decodes the received sound data packets to generate analog signals provided to the speaker to produce sound. In addition, one or more of the processors in the first and second SOCs 202, 204, the wireless transceiver 1008, and the CODEC 1010 may include a digital signal processor (DSP) circuit (not shown separately).
[0253] Various embodiments may be implemented in any of a variety of commercially available server devices, such as Fig.11 1100). Such a server 1100 typically includes a processor 1101 coupled to a volatile memory 1102 and a large capacity non-volatile memory (such as a disk drive 1103). The server 1100 may also include a floppy disk drive, a compact disk (CD) or a DVD disk drive 1104 coupled to the processor 1101. The server 1100 may also include a network access port 1106 coupled to the processor 1101, which is used to establish a data connection with a network 1105 (such as a local area network coupled to other carrier network computers and servers).
[0254] The processor may be any programmable microprocessor, microcomputer, or one or more multiprocessor chips that can be configured by software instructions (applications) to perform various functions including the functions of the various aspects described in this application. In some user equipment devices, multiple processors may be provided, such as one processor dedicated to wireless communication functions and one processor dedicated to running other applications. Typically, software applications may be stored in internal memory 1006, which are then accessed and loaded into the processor. The processor may include internal memory sufficient to store application software instructions.
[0255] As used in this application, the terms "component", "module", "system" and similar terms are intended to include computer-related entities, such as but not limited to hardware, firmware, a combination of hardware and software, software, or software in execution that is configured to perform a specific operation or function. For example, a component can be but not limited to a process, a processor, an object, an executable, a thread of execution, a program, and / or a computer running on a processor. As an illustration, both an application running on a user equipment device and a user equipment device can be referred to as a component. One or more components may reside in a process and / or a thread of execution, and a component may be localized on a processor or core and / or distributed between two or more processors or cores. In addition, these components may be executed from various non-transient computer-readable media having various instructions and / or data structures stored thereon. Each component may communicate through local and / or remote processes, function or procedure calls, electronic signals, data packets, memory read / writes, and other known networks, computers, processors, and / or communication methodologies associated with processes.
[0256] Several different cellular and mobile communication services and standards are available and are contemplated in the future, all of which can be implemented and benefit from various aspects. Such services and standards include, for example, the Third Generation Partnership Project (3GPP), Long Term Evolution (LTE) system, third generation wireless mobile communication technology (3G), fourth generation wireless mobile communication technology (4G), fifth generation wireless mobile communication technology (5G), Global System for Mobile Communications (GSM), Universal Mobile Telecommunications System (UMTS), 3GSM, General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA) system (e.g., cdmaOne, CDMA1020TM), Enhanced Data Rates for GSM Evolution (EDGE), Advanced Mobile Phone System (AMPS), Digital AMPS (IS-136 / TDMA), Evolution Data Optimized (EV-DO), Digital Enhanced Cordless Telecommunications (DECT), Worldwide Interoperability for Microwave Access (WiMAX), Wireless Local Area Network (WLAN), Wi-Fi Protected Access I and II (WPA, WPA2), and Integrated Digital Enhanced Network (iden). Each of these technologies involves, for example, the transmission and reception of voice, data, signaling and / or content messages. It should be understood that any reference to terminology and / or technical details related to individual telecommunication standards or technologies is for illustrative purposes only and is not intended to limit the scope of the claims to a particular communication system or technology unless specifically stated in the claim language.
[0257] Various aspects provide improved methods, systems and devices for saving power and improving performance in multi-core processors and systems on chip. The inclusion of multiple independent cores on a single chip and the sharing of memory, resources and power architectures between the cores leads to several power management issues that do not exist in more distributed multi-processing systems. Therefore, when designing power management and voltage / frequency scaling strategies for multi-core processors and systems on chip, a different set of design constraints may be applied than designs for other more distributed multi-processing systems.
[0258] The various aspects illustrated and described are provided merely as examples of various features of the claims. However, the features illustrated and described with respect to any given aspect need not be limited to the associated aspect, and may be used in conjunction or in combination with other aspects illustrated and described. In addition, the claims are not intended to be limited to any one example aspect. For example, one or more operations of a method may replace or be combined with one or more operations of a method.
[0259] The above method descriptions and process flow charts are provided only as illustrative examples and are not intended to require or imply that the operations of the various aspects can be performed in the order given. As will be appreciated by those skilled in the art, the order of operations in the aforementioned various aspects can be performed in any order. Phrases such as "thereafter", "then", "next" are not intended to limit the order of operations; these phrases are used to guide the reader through the description of the method. Further, any reference to a claim element in singular form (e.g., a reference using the article "a", "a", or "the") should not be interpreted as limiting the element to the singular.
[0260] The various illustrative logic blocks, modules, components, circuits, and algorithmic operations described in conjunction with the aspects disclosed herein may be implemented as electronic hardware, computer software, or a combination of the two. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and operations are generally described above in terms of their functionality. Whether such functionality is implemented as hardware or software depends on the specific application and the design constraints imposed on the overall system. A technician may implement the described functionality in different ways for each specific application, but such aspect decisions should not be interpreted as causing a departure from the scope of the claims.
[0261] Hardware for implementing the various illustrative logics, logic blocks, modules, and circuits described in conjunction with the aspects disclosed herein may be implemented or performed using a general purpose processor, digital signal processor (DSP), application specific integrated circuit (ASIC), field programmable gate array (FPGA) or other programmable logic device designed to perform the functions described herein, discrete gate or transistor logic, discrete hardware components, or any combination thereof. A general purpose processor may be a microprocessor, but in an alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of receiver smart objects, for example, a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. Alternatively, some operations or methods may be performed by a circuit system dedicated to a given function.
[0262] In one or more aspects, the functions described may be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, these functions may be stored as one or more instructions or codes on a non-transient computer-readable storage medium or a non-transient processor-readable storage medium. The operation of the method or algorithm disclosed herein may be implemented in a processor-executable software module or a processor-executable instruction, which may reside on a non-transient computer-readable or processor-readable storage medium. A non-transient computer-readable or processor-readable storage medium may be any storage medium that can be accessed by a computer or processor. As an example and not limitation, such non-transient computer-readable or processor-readable storage media may include RAM, ROM, EEPROM, flash memory, CD-ROM or other optical disk storage, disk storage or other magnetic storage smart objects, or any other medium that can be used to store desired program codes in the form of instructions or data structures and can be accessed by a computer. Disk and disc as used herein include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk and Blu-ray disc, wherein disk often reproduces data magnetically and disc reproduces data optically with lasers. Combinations of the above are also included within the scope of non-transitory computer-readable and processor-readable media. Additionally, the operations of a method or algorithm may reside as one or any combination or set of codes and / or instructions on a non-transitory processor-readable storage medium and / or computer-readable storage medium that may be incorporated into a computer program product.
[0263] The previous description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present claims. Various modifications to these aspects will be apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of the claims. Thus, the present disclosure is not intended to be limited to the aspects shown herein, but should be accorded the broadest scope consistent with the appended claims and the principles and novel features disclosed herein.
Claims
1. A method for network slice authentication, comprising: A Network Slice Selection Assistance Information Element (NSSAIIE) is generated by one or more processors of an Access and Mobility Management Function (AMF) that: identifying one or more network slices for which the slice-specific secondary authentication (SSSA) procedure has failed; and including a list of Single Network Slice Selection Assistance Information (S-NSSAI) elements identifying network slices for which authentication has not yet been authorized; as well as The NSSAI IE is transmitted from the AMF to a user equipment (UE).
2. The method of claim 1, further comprising: The AMF updates the network slice authentication status based on the result of the SSSA procedure; as well as Initiate UE configuration update procedure to communicate the updated network slice authentication status.
3. The method of claim 2, wherein updating the network slice authentication state based on the result of the SSSA procedure comprises: adding the S-NSSAI to the allowed NSSAI in response to the SSSA procedure being successful; as well as Retaining or adding the S-NSSAI in the pending NSSAI in response to the SSSA procedure failing.
4. The method of claim 1, further comprising: encrypting the NSSAI IE, and wherein transmitting the NSSAI IE from the AMF to the UE comprises: The encrypted NSSAI IE is sent via a secure channel established between the AMF and the UE.
5. The method of claim 1, further comprising: Monitoring by the AMF of user or service provider actions to authorize previously unauthorized S-NSSAI; as well as When the authorization action is detected, the slice-specific secondary authentication (SSSA) procedure for the authorized S-NSSAI is automatically triggered.
6. The method of claim 1, further comprising: receiving, by the AMF from the UE, a request for access to a network slice, wherein the request comprises a requested NSSAI including one or more S-NSSAIs; The AMF determines whether the S-NSSAI in the requested NSSAI matches the S-NSSAI identified as awaiting authentication in the NSSAI IE; and In response to the S-NSSAI matching the S-NSSAI in the NSSAI IE awaiting authentication, temporary access to the requested network slice is granted based on a policy decision.
7. A device comprising: One or more processors configured with processor-executable instructions to perform the following operations by an access and mobility management function (AMF): Generate a Network Slice Selection Assistance Information Element (NSSAIIE), the NSSAIIE: identifying one or more network slices for which the slice-specific secondary authentication (SSSA) procedure has failed; and including a list of Single Network Slice Selection Assistance Information (S-NSSAI) elements identifying network slices for which authentication has not yet been authorized; as well as The NSSAI IE is transmitted to a user equipment (UE).
8. The apparatus of claim 7, wherein the one or more processors are further configured with processor-executable instructions to: Updating the network slice authentication state based on the result of the SSSA procedure; and Initiate UE configuration update procedure to communicate the updated network slice authentication status.
9. The apparatus of claim 8, wherein the one or more processors are further configured with processor-executable instructions to update the network slice authentication state based on a result of the SSSA procedure by: adding the S-NSSAI to the allowed NSSAI in response to the SSSA procedure being successful; and Retaining or adding the S-NSSAI in the pending NSSAI in response to the SSSA procedure failing.
10. The apparatus of claim 7, wherein the one or more processors are configured with processor-executable instructions to: encrypting the NSSAI IE, and wherein the processor-executable instructions to transmit the NSSAI IE from the AMF to the UE include processor-executable instructions to: The encrypted NSSAI IE is sent via a secure channel established between the AMF and the UE.
11. The apparatus of claim 7, wherein the one or more processors are further configured with processor-executable instructions to: Monitor user or service provider actions that authorize previously unauthorized S-NSSAI; and When the authorization action is detected, the slice-specific secondary authentication (SSSA) procedure for the authorized S-NSSAI is automatically triggered.
12. The apparatus of claim 7, wherein the one or more processors are further configured with processor-executable instructions to: receiving, from the UE, a request for access to a network slice, wherein the request comprises a requested NSSAI including one or more S-NSSAIs; determining whether the S-NSSAI in the requested NSSAI matches the S-NSSAI identified as awaiting authentication in the NSSAI IE; and In response to the S-NSSAI matching the S-NSSAI in the NSSAI IE awaiting authentication, temporary access to the requested network slice is granted based on a policy decision.
13. A method for network slice selection and user equipment (UE) configuration update in a 5G system, comprising: A Network Slice Selection Assistance Information Element (NSSAI IE) is generated by one or more Access and Mobility Management Function (AMF) processors within the network, the NSSAI IE comprising: one or more Single Network Slice Selection Assistance Information (S-NSSAI) elements corresponding to the network slice for which the network slice-specific authentication and authorization procedures are to be initiated; S-NSSAI associated with the network slice that is subject to authentication and authorization procedures; encrypting the NSSAI IE to ensure transmission of the NSSAI IE across the network; The AMF transmits the encrypted NSSAI IE from the AMF to the UE via a secure channel; receiving, by the AMF from the UE, a request for network slice access, the request comprising a requested NSSAI having one or more S-NSSAIs; The AMF determines whether the S-NSSAI in the requested NSSAI matches the S-NSSAI identified as pending authentication or unauthorized in the NSSAI IE; granting, by the AMF, temporary access to the network slice associated with the request for network slice access based on a policy decision, in response to the S-NSSAI in the requested NSSAI matching the S-NSSAI identified as pending authentication in the NSSAI IE; updating, by the AMF, the network slice authentication state based on the result of the network slice-specific authentication and authorization procedure; and The UE configuration update procedure is initiated by the AMF to convey the updated network slice authentication status.