Power saving method for multi-subscriber identity module device

By coordinating multi-SIM state management in wireless communication devices, the problems of signal conflict and increased power demand are resolved, resulting in power savings and improved communication quality.

CN121753370APending Publication Date: 2026-03-27APPLE INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-08-14
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

In wireless communication devices, when multiple subscriber identity modules (SIMs) are active at the same time, it may lead to signal conflicts and increased power demand, affecting user experience and battery life.

Method used

By coordinating communication, wireless devices are allowed to operate in Multi Subscriber Identity Module (MSIM) mode, and based on received attachment or registration rejection messages, the SIM state can be changed, radio components can be disabled, and the device can switch to single SIM mode or limited service residency state to reduce power consumption.

Benefits of technology

It effectively reduces the power requirements of wireless devices while maintaining good transmission and reception capabilities, improving communication quality and battery life.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121753370A_ABST
    Figure CN121753370A_ABST
Patent Text Reader

Abstract

A wireless device may send a first attach request to a network node using a first SIM associated with a first radio, and send a second attach request to the network node using a second SIM associated with a second radio. In addition, the wireless device may operate in a multi-subscriber identity module (MSIM) mode, receiving an attach rejection message from the network node including an attach rejection cause code. The wireless device may transition the second SIM to a restricted service residence state based at least in part on receiving the attachment rejection message; disabling one of the first radio component or the second radio component; transitioning to a single SIM mode; and communicating with the network node via the first SIM.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to wireless devices, and more specifically to apparatus, systems, and methods for coordinating communications and providing power-saving techniques for multi-subscriber identity module devices in wireless communication systems. Background Technology

[0002] The use of wireless communication systems is growing rapidly. In recent years, wireless devices, such as smartphones and tablets, have become increasingly sophisticated. In addition to supporting telephone calls, many mobile devices (i.e., user equipment or UE) now offer access to the internet, email, text messaging, and navigation using the Global Positioning System (GPS), and are capable of operating complex applications that utilize these functionalities. Furthermore, many different wireless communication technologies and standards exist. Some examples of wireless communication standards include GSM, UMTS (e.g., associated with WCDMA or TD-SCDMA air interfaces), LTE, LTE-A (LTE-Advanced), HSPA, 3GPP2 CDMA2000 (e.g., 1xRTT, 1xEV-DO, HRPD, eHRPD), IEEE 802.11 (WLAN or Wi-Fi), and Bluetooth. ™ wait.

[0003] The increasing number of features and functionalities introduced into wireless communication devices has created a continuous demand for improvements in both wireless communication and the devices themselves. Ensuring the accuracy of signals transmitted and received by User Equipment (UE) devices—such as wireless devices like cellular phones, base stations, and relay stations used in wireless cellular communications—is of paramount importance. For example, some UEs may include multiple Subscriber Identity Modules (SIMs) that can be active simultaneously. In some cases, conflicts may occur between transmissions of such UEs associated with different SIMs. Such conflicts can negatively impact the user experience and performance of the UE. Furthermore, increasing the functionality of UE devices can put significant strain on their battery life. For example, certain paging schedules for different SIMs may require increased power consumption. Therefore, it is equally important to reduce the power requirements in UE device design while allowing the UE to maintain good transmit and receive capabilities to improve communication.

[0004] To increase coverage and better serve the growing demand and scope for the intended uses of wireless communication, in addition to the aforementioned communication standards, new wireless communication technologies are under development, including fifth-generation (5G) New Radio (NR) communication. Therefore, there is a need to improve the areas supporting this development and design. Summary of the Invention

[0005] Various implementations relate to apparatus, systems, and methods for coordinating communications and providing power-saving techniques for multi-subscriber identity module devices in wireless communication systems.

[0006] According to some embodiments, a wireless device can send a first attachment request to a network node using a first SIM associated with a first radio component, and send a second attachment request to the network node using a second SIM associated with a second radio component. Additionally, the wireless device can operate in a multi-subscriber identity module (MSIM) mode, receiving an attachment rejection message from the network node including an attachment rejection reason code. Based at least in part on receiving the attachment rejection message, the wireless device can switch the second SIM to a restricted service state; disable either the first or second radio component; switch to single-SIM mode; and communicate with the network node via the first SIM.

[0007] In some implementations, the attachment rejection reason code may be attachment rejection reason #6 associated with an unauthorized mobile device (ME). Additionally or alternatively, the attachment rejection message may be non-integrity (non-IP) protected. In some implementations, a restricted service camp state may provide emergency service to the wireless device. According to another implementation, at least one processor may be further configured to cause the wireless device to transition the second SIM out of the restricted service camp state upon completion of a power cycle.

[0008] In some cases, at least one processor may be further configured to cause the wireless device to: receive an attachment acceptance message from a network node on the first SIM; and transition to a registration idle state at least in part based on the successful registration process. Additionally, at least one processor may be further configured to cause the wireless device to: receive an authentication request from a network node on the second SIM; and send an authentication response to the network node on the second SIM. Furthermore, at least one processor may be further configured to cause the wireless device to receive an authentication rejection message from a network node on the second SIM, wherein the second SIM is transitioned to a restricted service residency state at least in part based on the receipt of the authentication rejection message. Additionally or alternatively, the first SIM may provide emergency and normal services at least in part based on being in a registration idle state.

[0009] According to another embodiment, a method performed by the UE may include: operating in MSIM mode; and sending a first registration request to a network node using a first radio component associated with a first SIM. The method may further include: transitioning the first SIM to a registration idle state, at least in part based on performing a successful registration process associated with a first cell of the network node; and sending a second registration request to the network node using a second radio component associated with a second SIM. The method may further include receiving a registration rejection message from the network node using the second radio component. In some embodiments, the registration rejection message may include a registration rejection reason code associated with a second cell of the network node. The method may further include: blocking the second cell; and performing a cell selection process, wherein the second cell is blocked during the cell selection process. According to some embodiments, the registration rejection message may be a non-IP registration rejection message.

[0010] Additionally, the method may include: upon receiving a registration rejection message, starting one or more timers. In some embodiments, the one or more timers may include a T3245 timer, and the method may further include marking the second SIM as invalid for the duration of the T3245 timer. Additionally or alternatively, the one or more timers may include a T3247 timer, and the method may further include: incrementing a counter of the timer; marking the tracking area (TA) associated with the second cell as prohibited; and searching for TAs other than the prohibited TA. In some embodiments, the registration rejection reason code may be registration rejection reason #6 associated with unauthorized mobile equipment (ME).

[0011] According to other embodiments, an apparatus may include at least one processor of a UE operating in MSIM mode, and the at least one processor may be configured to cause the UE to send a first registration request associated with a first Tracking Area Identifier (TAI) to a Public Land Mobile Network (PLMN) using a first radio component associated with a first SIM. The at least one processor may be further configured to cause the UE to receive a registration rejection message from a network node using the first radio component, wherein the registration rejection message may include a registration rejection reason code. The at least one processor may be further configured to cause the UE to: start one or more timers; mark the first TAI as prohibited; and search for a second TAI that excludes the first TAI.

[0012] In some embodiments, the at least one processor may be further configured to cause the UE to: send a second registration request associated with a second TAI to the PLMN using a second radio component; and receive a registration acceptance message from the PLMN using a second SIM. According to some embodiments, the at least one processor is further configured to cause the UE to: send a third registration request associated with a second TAI to the PLMN using a first radio component associated with a first SIM; and receive a second registration acceptance message from the PLMN using the first radio component associated with the first SIM. Additionally or alternatively, one or more timers may include a T3247 timer, and the at least one processor may be further configured to cause the UE to: increment the counter of the T3247 timer upon receiving a registration rejection message from the PLMN. According to some embodiments, the registration rejection message may be a non-IP non-access stratum (NAS) rejection message.

[0013] In some implementations, as the counter of the T3247 timer is incremented, the at least one processor may be further configured to cause the UE to: update the prohibited TAI list to include the corresponding prohibited TAI associated with the corresponding registration request message upon receiving a corresponding registration rejection message. Additionally or alternatively, when the counter of the T3247 timer reaches its maximum value, the at least one processor may be further configured to cause the UE to perform a cell search procedure in different TAIs.

[0014] The technologies described herein can be implemented in and / or used with a variety of different types of devices, including but not limited to any one of cellular phones, tablets, wearable computing devices, portable media players and various other computing devices.

[0015] The present invention is intended to provide a brief overview of some of the subjects described in this document. Therefore, it should be understood that the above features are merely illustrative and should not be construed as narrowing the scope or substance of the subjects described herein in any way. Other features, aspects, and advantages of the subjects described herein will become apparent from the following detailed description, drawings, and claims. Attached Figure Description

[0016] A better understanding of the subject matter can be obtained by considering the following detailed description of various embodiments in conjunction with the accompanying drawings, in which:

[0017] Figure 1 Example wireless communication systems according to some implementation schemes are illustrated;

[0018] Figure 2 Examples of base stations (BS) communicating with user equipment (UE) devices according to some implementation schemes are shown.

[0019] Figure 3 Example block diagrams of a UE according to some implementation schemes are shown;

[0020] Figure 4 Example block diagrams of a BS according to some implementation schemes are shown;

[0021] Figure 5 Example block diagrams of cellular communication circuits according to some implementation schemes are shown;

[0022] Figure 6 and Figure 7 Examples of 5G NR base stations (gNBs) according to some implementation schemes are illustrated; and

[0023] Figure 8 This is a communication flowchart illustrating an example aspect of the operation of an MSIM device according to some implementation schemes, where multiple SIMs are in a limited service residency state;

[0024] Figure 9 This is a communication flowchart illustrating an example aspect of MSIM device power-saving techniques for avoiding both SIMs being in a limited service residency state, according to some implementation schemes;

[0025] Figure 10 This is a communication flowchart illustrating an example aspect of the operation of an MSIM device according to some implementation schemes, where one SIM is able to successfully register and another SIM receives an authentication rejection;

[0026] Figure 11 This is a communication flowchart illustrating an example method of MSIM power-saving technology according to some implementation schemes, where one SIM is operating in a normal registration state and another SIM is in a limited service residency state;

[0027] Figure 12 This is a communication flowchart illustrating an example aspect of the operation of an MSIM device according to some implementation schemes, where one SIM operates in a normal registration state and another SIM receives a registration rejection message with non-integrity protection;

[0028] Figure 13 This is a communication flowchart illustrating an example method for power saving in a scenario where one SIM is operating in a normal registration state and another SIM has received a non-integrity protection registration rejection message, according to some implementation schemes.

[0029] Figure 14This is a communication flowchart illustrating an alternative method for power saving in a scenario where one SIM is operating in a normal registration state and another SIM has received a non-integrity protection registration rejection message, according to some implementation schemes.

[0030] Figure 15 This is a communication flowchart illustrating an example aspect of the operation of an MSIM device according to some implementation schemes, wherein two SIMs from the same PLMN follow a cyclic process after receiving a non-integrity-protected registration rejection message; and

[0031] Figure 16 This is a communication flowchart illustrating an example method for power saving in a scenario where a SIM receives a non-integrity protection registration rejection message and attempts to reside in a second tracking area, according to some implementation schemes.

[0032] While the features described herein may be readily modified and alternatively adapted, specific embodiments thereof are shown by way of example in the accompanying drawings and described in detail herein. However, it should be understood that the drawings and their detailed description are not intended to limit one to the specific forms disclosed, but rather to cover all modifications, equivalents, and alternatives falling within the substance and scope of the subject matter as defined by the appended claims. Detailed Implementation

[0033] acronym

[0034] Various acronyms are used throughout this disclosure. Definitions of the most frequently used acronyms that may appear throughout this disclosure are provided below:

[0035] • 3GPP: Third Generation Partnership Project

[0036] •TS: Technical Specifications

[0037] •RAN: Radio Access Network

[0038] •RAT: Radio Access Technology

[0039] •UE: User Equipment

[0040] •RF: Radio Frequency

[0041] •BS: Base Station

[0042] •DL: Downlink

[0043] •UL: Uplink

[0044] •LTE: Long Term Evolution

[0045] •NR: New Radio

[0046] •5GS: 5G system

[0047] • 5GMM: 5GS Mobility Management

[0048] •5GC: 5G Core Network

[0049] •IE: Information Elements

[0050] •TX: Send

[0051] •RX: Receive

[0052] •WLAN: Wireless LAN

[0053] •EPC: Evolution Group Core

[0054] •IEEE: Institute of Electrical and Electronics Engineers

[0055] • Wi-Fi: Wireless Local Area Network (WLAN) RAT based on the IEEE 802.11 standard

[0056] • MUSIM / MSIM: Multi-Subscriber Identity Module

[0057] •USIM: Universal Subscriber Identity Module

[0058] •SIM: Subscriber Identity Module

[0059] •DDS: Default Data SIM

[0060] • nDDS: Non-default data SIM

[0061] •EN-DC: Enhanced Dual Connectivity

[0062] •MME: Mobility Management Entity

[0063] •GSMA: Global System for Mobile Communications Association

[0064] •IMEI: International Mobile Equipment Identity

[0065] •ME: Mobile Equipment

[0066] •NAS: Non-Access Layer

[0067] •DoS: Denial of Service

[0068] •NG-RAN: Next Generation Radio Access Network

[0069] •gNB: Next-generation node B

[0070] •UICC: Universal Integrated Circuit Card

[0071] •MS: Mobile Station

[0072] •TA: Tracking Area

[0073] •TAI: Tracking Area Identifier

[0074] •PLMN: Public Land Mobile Network

[0075] •GPRS: General Packet Radio Service

[0076] •NW: Network

[0077] the term

[0078] The following is a glossary of terms used in this disclosure:

[0079] Memory media—any of various types of nontransitory memory devices or storage devices. The term "memory media" is intended to include mounting media, such as CD-ROMs, floppy disks, or magnetic tape devices; computer system memory or random access memory, such as DRAM, DDR RAM, SRAM, EDO RAM, Rambus RAM, etc.; non-volatile memory, such as flash memory; magnetic media, such as hard disk drives or optical storage devices; registers or other similar types of memory elements, etc. Memory media may also include other types of nontransitory memory or combinations thereof. Furthermore, memory media may reside in a first computer system executing a program, or may reside in a different second computer system connected to the first computer system via a network such as the Internet. In the latter example, the second computer system may provide program instructions to the first computer for execution. The term "memory media" may include two or more memory media residing in different locations in different computer systems connected via, for example, a network. Memory media may store program instructions (e.g., embodied in a computer program) that can be executed by one or more processors.

[0080] Carrier medium—such as memory media as described above, and physical transmission medium, such as buses, networks, and / or other physical transmission media for transmitting signals (such as electrical signals, electromagnetic signals, or digital signals).

[0081] Programmable hardware elements encompass a variety of hardware devices that include multiple programmable functional blocks connected via programmable interconnects. Examples include FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), FPOAs (Field-Programmable Object Arrays), and CPLDs (Complex PLDs). Programmable functional blocks can range from fine-grained (combinational logic or lookup tables) to coarse-grained (arithmetic logic units or processor cores). Programmable hardware elements can also be referred to as "configurable logic."

[0082] Computer system—any of all types of computing or processing systems, including personal computer systems (PCs), mainframe computer systems, workstations, networked appliances, internet-connected appliances, personal digital assistants (PDAs), television systems, grid computing systems, or other devices or combinations of devices. In general, the term "computer system" can be broadly defined to encompass any device (or combination of devices) having at least one processor that executes instructions from a memory medium.

[0083] User equipment (UE) (or “UE device”) — any of various types of computer systems or devices that are mobile or portable and perform wireless communication. Examples of UE devices include mobile phones or smartphones (e.g., iPhone). ™ Based on Android ™ Telephones), portable gaming devices (e.g., Nintendo DS) ™ PlayStation Portable ™ Gameboy Advance ™ iPhone ™ Laptops, wearable devices (e.g., smartwatches, smart glasses), PDAs, portable internet devices, music players, data storage devices, or other handheld devices, etc. Generally speaking, the term "UE" or "UE device" can be broadly defined to encompass any electronic device, computing device, and / or telecommunications device (or combination of devices) that is easily transmitted and capable of wireless communication by a user.

[0084] A wireless device is any of various types of computer systems or devices that perform wireless communication. A wireless device can be portable (or mobile), or it can be stationary or fixed in a location. A UE is an example of a wireless device.

[0085] A communication device is any of various types of computer systems or devices that perform communication, which may be wired or wireless. A communication device may be portable (or mobile), or it may be stationary or fixed in a location. A wireless device is one example of a communication device. A UE is another example of a communication device.

[0086] Base station—The term “base station” has the full range of its common meaning and includes at least a wireless communication station that is installed in a fixed location and is used for communication as part of a wireless telephone system or radio system.

[0087] A processing element (or processor) – refers to a variety of elements or combinations of elements capable of performing the functions of a device, such as user equipment or cellular network equipment. A processing element may include, for example: a processor and associated memory, a portion or circuitry of a single processor core, an entire processor core, a single processor, a processor array, circuitry such as an application-specific integrated circuit (ASIC), programmable hardware elements such as a field-programmable gate array (FPGA), and any combination thereof.

[0088] A channel is a medium used to transmit information from a transmitter to a receiver. It should be noted that because the characteristics of the term "channel" can vary depending on the wireless protocol, the term "channel" as used herein can be considered to be used in a standard manner consistent with the type of device to which the term is referenced. In some standards, channel width can be variable (e.g., depending on device capabilities, band conditions, etc.). For example, LTE can support scalable channel bandwidths from 1.4 MHz to 20 MHz. In contrast, WLAN channels can be 22 MHz wide, while Bluetooth channels can be 1 MHz wide. Other protocols and standards may include different definitions of channels. Furthermore, some standards may define and use multiple types of channels, for example, different channels for uplink or downlink and / or different channels for different purposes such as data, control information, etc.

[0089] Frequency band—The term “frequency band” has the full range of its general meaning and includes at least a segment of spectrum (e.g., radio frequency spectrum) in which a channel is used or reserved for the same purpose.

[0090] Automatically—means that an action or operation is performed by a computer system (e.g., software executed by the computer system) or device (e.g., circuits, programmable hardware elements, ASICs, etc.) without requiring direct user input to specify or perform that action or operation. Therefore, the term "automatic" contrasts with an action performed or specified manually by the user, where the user provides input to perform that action directly. An automatic process can be initiated by user-provided input, but the subsequent actions performed "automatically" are not specified by the user; that is, they are not performed "manually," where the user specifies each action to be performed. For example, a user filling out a form by selecting each field and providing input to specify information (e.g., by typing information, selecting a checkbox, radio selection, etc.) is considered manually filling out the form, even though the computer system must update the form in response to the user's actions. The form can be automatically filled out by a computer system (e.g., software executed on the computer system) which analyzes the fields of the form and fills it out without any user input specifying answers for the fields. As indicated above, the user can invoke the automatic filling of the form but does not participate in the actual filling of the form (e.g., the user does not manually specify answers for the fields, but they are completed automatically). This manual provides various examples of operations that can be performed automatically in response to actions taken by the user.

[0091] Approximately—means a value close to the correct or precise value. For example, approximately could mean a value within 1% to 10% of the precise (or expected) value. However, it should be noted that the actual threshold (or tolerance) can be application-dependent. For example, in some implementations, “approximately” could mean within 0.1% of some specified or expected value, while in various other implementations, the threshold could be, for example, 2%, 3%, 5%, etc., depending on the expectations or requirements of a particular application.

[0092] Concurrency refers to the parallel execution or implementation of tasks, processes, or programs in a manner that at least partially overlaps. For example, concurrency can be achieved using “strong” or strict parallelism, where tasks are executed in parallel (at least partially) on corresponding computing elements; or using “weak parallelism,” where tasks are executed in an interleaved manner (e.g., by time multiplexing of execution threads).

[0093] "Configured as" – Various components can be described as being "configured to" perform one or more tasks. In this context, "configured as" is a broad expression generally meaning "having a structure" that performs one or more tasks during operation. Therefore, a component can be configured to perform a task even when it is not currently performing one (e.g., a set of electrical conductors can be configured to electrically connect one module to another, even when the two modules are not connected). In some contexts, "configured as" can be a broad expression generally meaning "having a circuit" that performs one or more tasks during operation. Therefore, a component can be configured to perform a task even when it is not currently powered on. Generally, the circuit forming the structure corresponding to "configured as" can include hardware circuitry.

[0094] For ease of description, various components may be described as performing one or more tasks. Such descriptions should be interpreted as including the phrase "configured to". Statements describing a component as configured to perform one or more tasks are explicitly intended not to invoke the interpretation of 35 USC § 112(f) for that component.

[0095] Figure 1 and Figure 2 —Communication System

[0096] Figure 1 A simplified example wireless communication system according to some implementation schemes is illustrated. Note that... Figure 1 The system described herein is merely one example of a possible system, and the features of this disclosure can be implemented in any of the various systems as needed.

[0097] As shown in the figure, the example wireless communication system includes a base station 102A, which communicates with one or more user equipments 106A, 106B, etc., to user equipment 106N via a transmission medium. Each user equipment may be referred to herein as a "user equipment" (UE). Therefore, user equipment 106 is referred to as a UE or UE device.

[0098] Base station (BS) 102A may be a transceiver base station (BTS) or a cell site (“cellular base station”), and may include hardware for implementing wireless communication with UE 106A to UE 106N.

[0099] The communication area (or coverage area) of a base station may be referred to as a "cell". Base station 102A and UE 106 can be configured to communicate via a transmission medium using any of a variety of Radio Access Technologies (RATs), also known as wireless communication technologies or telecommunications standards, such as GSM, UMTS (associated with air interfaces such as WCDMA or TD-SCDMA), LTE, LTE-Advanced (LTE-A), 5G New Radio (5G NR), HSPA, 3GPP2 CDMA2000 (e.g., 1xRTT, 1xEV-DO, HRPD, eHRPD), etc. Note that if base station 102A is implemented in an LTE environment, its alternative location may be referred to as an "eNodeB" or "eNB". Note that if base station 102A is implemented in a 5G NR environment, its alternative location may be referred to as a "gNodeB" or "gNB".

[0100] As shown in the figure, base station 102A can also be configured to communicate with network 100 (e.g., in various possibilities, the core network of a cellular service provider, telecommunications networks such as the Public Switched Telephone Network (PSTN), and / or the Internet). Therefore, base station 102A facilitates communication between user equipments and / or between user equipments and network 100. Specifically, cellular base station 102A can provide UE 106 with various telecommunications capabilities, such as voice, SMS, and / or data services.

[0101] Base station 102A and other similar base stations (such as base stations 102B, ..., 102N) operating according to the same or different cellular communication standards can therefore be provided as a network of cells that can provide continuous or nearly continuous overlapping services to UE 106A-N and similar devices over a geographical area via one or more cellular communication standards.

[0102] Therefore, although base station 102A can act as such Figure 1 The illustrated "serving cells" are UEs 106A to 106N, but each UE 106 may also be able to receive signals (and possibly within its communication range) from one or more other cells (which may be provided by base stations 102B to 102N and / or any other base stations), which may be referred to as "neighboring cells." Such cells may also facilitate communication between user equipments and / or between user equipments and network 100. These cells may include "macro" cells, "micro" cells, "pecimen" cells, and / or any other cells of various other granularities providing service area size. For example, Figure 1 The illustrated base stations 102A-102B may be macro cells, while base station 102N may be a micro cell. Other configurations are also possible.

[0103] In some implementations, base station 102A may be a next-generation base station, such as a 5G New Radio (5G NR) base station or a “gNB”. In some implementations, the gNB may be connected to a legacy evolved packet core (EPC) network and / or to an NR core (NRC) network. Furthermore, the gNB cell may include one or more transition and receive points (TRPs). Additionally, a UE capable of operating under 5G NR may be connected to one or more TRPs within one or more gNBs. For example, base station 102A and one or more other base stations 102 may support joint transmission, enabling UE 106 to receive transmissions from multiple base stations (and / or multiple TRPs provided by the same base station).

[0104] It should be noted that UE 106 may be able to communicate using multiple wireless communication standards. For example, UE 106 may be configured to communicate using wireless networking (e.g., Wi-Fi) and / or peer-to-peer wireless communication protocols (e.g., Bluetooth, Wi-Fi peer-to-peer, etc.) other than at least one cellular communication protocol (e.g., GSM, UMTS (associated with, for example, WCDMA or TD-SCDMA air interfaces), LTE, LTE-A, 5G NR, HSPA, 3GPP2 CDMA2000 (e.g., 1xRTT, 1xEV-DO, HRPD, eHRPD, etc.)). If desired, UE 106 may also or alternatively be configured to communicate using one or more Global Navigation Satellite Systems (GNSS, e.g., GPS or GLONASS), one or more mobile television broadcasting standards (e.g., ATSC-M / H), and / or any other wireless communication protocol. Other combinations of wireless communication standards (including more than two wireless communication standards) are also possible.

[0105] Figure 2 The illustration shows a user equipment 106 (e.g., one of devices 106A to 106N) communicating with base station 102 according to some embodiments. UE 106 can be a cellular communication-capable device, such as a mobile phone, handheld device, computer, laptop, tablet, smartwatch, or other wearable device, or virtually any type of wireless device.

[0106] UE 106 may include a processor (processing element) configured to execute program instructions stored in memory. UE 106 may execute any method implementation of the method embodiments described herein by executing such stored instructions. Alternatively or additionally, UE 106 may include programmable hardware elements, such as field-programmable gate arrays (FPGAs), integrated circuits, and / or any of various other possible hardware components configured to (e.g., individually or in combination) execute any method implementation of the method embodiments described herein or any portion thereof.

[0107] UE 106 may include one or more antennas for communicating using one or more wireless communication protocols or technologies. In some embodiments, UE 106 may be configured to communicate using, for example, NR or LTE using at least some shared radio components. As an additional possibility, UE 106 may be configured to communicate using CDMA2000 (1xRTT / 1xEV-DO / HRPD / eHRPD) or LTE using a single shared radio component and / or GSM or LTE using a single shared radio component. The shared radio component may be coupled to a single antenna or may be coupled to multiple antennas (e.g., for MIMO) for performing wireless communication. Generally, the radio component may include any combination of baseband processors, analog RF signal processing circuitry (e.g., including filters, mixers, oscillators, amplifiers, etc.) or digital processing circuitry (e.g., for digital modulation and other digital processing). Similarly, the radio component may use the aforementioned hardware to implement one or more receive chains and transmit chains. For example, UE 106 may share one or more portions of the receive chain and / or transmit chain among multiple wireless communication technologies (such as those discussed above).

[0108] In some implementations, UE 106 may include independent transmit and / or receive chains (e.g., including independent antennas and other radio components) for each wireless communication protocol configured to communicate therewith. As another possibility, UE 106 may include one or more radio components shared among multiple wireless communication protocols, as well as one or more radio components used uniquely by a single wireless communication protocol. For example, UE 106 may include shared radio components for communicating using either LTE or 5G NR (or either LTE or 1xRTT, or either LTE or GSM, and various other possibilities), and separate radio components for communicating using each of Wi-Fi and Bluetooth. Other configurations are also possible.

[0109] Figure 3 —UE block diagram

[0110] Figure 3 A simplified block diagram of a communication device 106 according to some implementation schemes is shown. Note that... Figure 3 The block diagram of the communication device is merely one example of possible communication devices. According to the implementation, among other devices, the communication device 106 may be a user equipment (UE) device, a mobile device or mobile station, a wireless device or wireless station, a desktop computer or computing device, a mobile computing device (e.g., a laptop, notebook, or portable computing device), a tablet computer, and / or a combination of devices. As shown, the communication device 106 may include a set of components 300 configured to perform core functions. For example, this set of components may be implemented as a system-on-a-chip (SOC), which may include portions for various purposes. Alternatively, the set of components 300 may be implemented as separate components or groups of components for various purposes. The set of components 300 may be (e.g., communicatively; directly or indirectly) coupled to various other circuitry of the communication device 106.

[0111] For example, communication device 106 may include various types of memory (e.g., including NAND flash memory 310), input / output interfaces such as connector I / F 320 (e.g., for connection to a computer system; docking station; charging station; input devices such as microphone, camera, keyboard; output devices such as speaker; etc.), a display 360 that may be integrated with or external to communication device 106, and wireless communication circuitry 330 (e.g., for LTE, LTE-A, NR, UMTS, GSM, CDMA2000, Bluetooth, Wi-Fi, NFC, GPS, etc.). In some embodiments, communication device 106 may include wired communication circuitry (not shown), such as a network interface card for Ethernet, for example.

[0112] The wireless communication circuit 330 may be coupled (e.g., communicatively; directly or indirectly) to one or more antennas, such as antenna 335 as shown in the figure. The wireless communication circuit 330 may include cellular communication circuitry and / or medium-to-short-range wireless communication circuitry, and may include multiple receive chains and / or multiple transmit chains for receiving and / or transmitting multiple spatial streams, such as in a multiple-input multiple-output (MIMO) configuration.

[0113] In some embodiments, as further described below, the cellular communication circuit 330 may include one or more receive chains (including and / or coupled to (e.g., communicatively; directly or indirectly) dedicated processors and / or radio components) for multiple RATs (e.g., a first receive chain for LTE and a second receive chain for 5G NR). Furthermore, in some embodiments, the cellular communication circuit 330 may include a single transmit chain that can be switched between radio components dedicated to a particular RAT. For example, a first radio component may be dedicated to a first RAT (e.g., LTE) and can communicate with a dedicated receive chain and a transmit chain shared with a second radio component. A second radio component may be dedicated to a second RAT (e.g., 5G NR) and can communicate with a dedicated receive chain and a shared transmit chain.

[0114] The communication device 106 may also include one or more user interface elements and / or be configured to be used with one or more user interface elements. The user interface elements may include any of a variety of elements, such as a display 360 (which may be a touch screen display), a keyboard (which may be a separate keyboard or may be implemented as part of the touch screen display), a mouse, a microphone and / or a speaker, one or more cameras, one or more buttons, and / or any of a variety of other elements capable of providing information to the user and / or receiving or interpreting user input.

[0115] The communication device 106 may also include one or more smart cards 345 with SIM (subscriber identity module) functionality, such as one or more UICC (universal integrated circuit card) cards 345.

[0116] As shown in the figure, the SOC 300 may include a processor 302 and a display circuit 304. The processor executes program instructions of the communication device 106, and the display circuit performs graphics processing and provides display signals to the display 360. One or more processors 302 may also be coupled to a memory management unit (MMU) 340 (which may be configured to receive addresses from the processor 302 and translate those addresses into locations in memory (e.g., memory 306, read-only memory (ROM) 350, NAND flash memory 310)) and / or coupled to other circuitry or devices (such as the display circuit 304, wireless communication circuitry 330, connector I / F 320, and / or display 360). The MMU 340 may be configured to perform memory protection and page table translation or setup. In some embodiments, the MMU 340 may be included as part of the processor 302.

[0117] As noted above, communication device 106 may be configured to communicate using wireless and / or wired communication circuitry. As described herein, communication device 106 may include hardware and software components for implementing any of the various features and techniques described herein. For example, by executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable memory medium), processor 302 of communication device 106 may be configured to implement some or all of the features described herein. Alternatively (or further), processor 302 may be configured as a programmable hardware element (such as an FPGA (Field-Programmable Gate Array)) or as an ASIC (Application-Specific Integrated Circuit). Alternatively (or further), in conjunction with one or more of other components 300, 304, 306, 310, 320, 330, 340, 345, 350, 360, processor 302 of communication device 106 may be configured to implement some or all of the features described herein.

[0118] Furthermore, as described herein, processor 302 may include one or more processing elements. Therefore, processor 302 may include one or more integrated circuits (ICs) configured to perform the functions of processor 302. Additionally, each integrated circuit may include circuitry (e.g., a first circuit, a second circuit, etc.) configured to perform the functions of processor 302.

[0119] Furthermore, as described herein, the wireless communication circuit 330 may include one or more processing elements. In other words, one or more processing elements may be included in the wireless communication circuit 330. Therefore, the wireless communication circuit 330 may include one or more integrated circuits (ICs) configured to perform the functions of the wireless communication circuit 330. Additionally, each integrated circuit may include circuitry (e.g., a first circuit, a second circuit, etc.) configured to perform the functions of the wireless communication circuit 330.

[0120] Figure 4 —Block diagram of a base station

[0121] Figure 4 Example block diagrams of base station 102 according to some implementation schemes are shown. It should be noted that... Figure 4 The base station shown is merely one example of a possible base station. As illustrated, base station 102 may include processor 404, which executes program instructions for base station 102. Processor 404 may also be coupled to memory management unit (MMU) 440, which may be configured to receive addresses from processor 404 and translate those addresses into locations in memory (e.g., memory 460 and read-only memory (ROM) 450) or into other circuitry or devices.

[0122] Base station 102 may include at least one network port 470. Network port 470 may be configured to couple to a telephone network and provide access to multiple devices, such as UE device 106, as described above. Figure 1 and Figure 2 Access to the telephone network described in the text.

[0123] Network port 470 (or an additional network port) may also be configured, or alternatively configured, to couple to a cellular network, such as the core network of a cellular service provider. The core network may provide mobility-related services and / or other services to multiple devices, such as UE device 106. In some cases, network port 470 may be coupled to a telephone network via the core network, and / or the core network may provide a telephone network (e.g., in other UE devices served by a cellular service provider).

[0124] In some implementations, base station 102 may be a next-generation base station, such as a 5G New Radio (5G NR) base station, or a “gNB”. In such implementations, base station 102 may be connected to a legacy evolved packet core (EPC) network and / or to an NR core (NRC) network. Furthermore, base station 102 may be considered a 5G NR cell and may include one or more transition and receive points (TRPs). Additionally, UEs capable of operating according to 5G NR may be connected to one or more TRPs within one or more gNBs.

[0125] Base station 102 may include at least one antenna 434, and may include multiple antennas. At least one antenna 434 may be configured to operate as a wireless transceiver and may be further configured to communicate with UE device 106 via radio component 430. Antenna 434 communicates with radio component 430 via communication link 432. Communication link 432 may be a receive link, a transmit link, or both. Radio component 430 may be configured to communicate via various wireless communication standards, including but not limited to 5G NR, LTE, LTE-A, GSM, UMTS, CDMA2000, Wi-Fi, etc.

[0126] Base station 102 can be configured to perform wireless communication using multiple wireless communication standards. In some cases, base station 102 may include multiple radio components that enable base station 102 to communicate according to multiple wireless communication technologies. For example, as one possibility, base station 102 may include an LTE radio component for performing communication according to LTE and a 5G NR radio component for performing communication according to 5G NR. In this case, base station 102 may be able to operate as both an LTE base station and a 5G NR base station. As another possibility, base station 102 may include a multimode radio component capable of performing communication according to any of multiple wireless communication technologies (e.g., 5G NR and LTE, 5G NR and Wi-Fi, LTE and Wi-Fi, LTE and UMTS, LTE and CDMA2000, UMTS and GSM, etc.).

[0127] As further described herein, BS 102 may include hardware and software components for implementing or supporting specific implementations of the features described herein. The processor 404 of base station 102 may be configured, for example, to implement or support some or all of the methods described herein by executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable memory medium). Alternatively, processor 404 may be configured as a programmable hardware element such as a FPGA (Field-Programmable Gate Array), or as an ASIC (Application-Specific Integrated Circuit), or a combination thereof. Alternatively (or further), in conjunction with one or more of other components 430, 432, 434, 440, 450, 460, 470, the processor 404 of BS 102 may be configured to implement or support some or all of the features described herein.

[0128] Furthermore, as described herein, processor 404 may include one or more processing elements. Therefore, processor 404 may include one or more integrated circuits (ICs) configured to perform the functions of processor 404. Additionally, each integrated circuit may include circuitry (e.g., a first circuit, a second circuit, etc.) configured to perform the functions of processor 404.

[0129] Furthermore, as described herein, radio component 430 may include one or more processing elements. Therefore, radio component 430 may include one or more integrated circuits (ICs) configured to perform the functions of radio component 430. Additionally, each integrated circuit may include circuitry (e.g., a first circuit, a second circuit, etc.) configured to perform the functions of radio component 430.

[0130] Figure 5 —Block diagram of cellular communication circuit

[0131] Figure 5Simplified block diagrams of cellular communication circuits according to some implementation schemes are shown. Note that... Figure 5 The block diagram of the cellular communication circuit is only one example of possible cellular communication circuits; other circuits, such as those including or coupled to sufficient antennas for different RATs to perform uplink activities using independent antennas, or those including or coupled to fewer antennas, such as those that can be shared among multiple RATs, are also possible. According to some embodiments, the cellular communication circuit 330 may be included in a communication device (such as the communication device 106 described above). As noted above, among other devices, the communication device 106 may be a user equipment (UE) device, a mobile device or mobile station, a wireless device or wireless station, a desktop computer or computing device, a mobile computing device (e.g., a laptop computer, notebook computer, or portable computing device), a tablet computer, and / or a combination of these devices.

[0132] Cellular communication circuitry 330 may be coupled (e.g., communicatively; directly or indirectly) to one or more antennas, such as antennas 335a to 335b and 336 as shown in the figure. In some embodiments, cellular communication circuitry 330 may include dedicated receive chains for multiple RATs (including and / or coupled to (e.g., communicatively; directly or indirectly) dedicated processors and / or radio components) (e.g., a first receive chain for LTE and a second receive chain for 5G NR). For example, as Figure 5 As shown, the cellular communication circuit 330 may include a first modem 510 and a second modem 520. The first modem 510 may be configured for communication according to a first RAT (e.g., such as LTE or LTE-A), and the second modem 520 may be configured for communication according to a second RAT (e.g., such as 5G NR).

[0133] As shown, the first modem 510 may include one or more processors 512 and a memory 516 communicating with the processors 512. The modem 510 may communicate with a radio frequency (RF) front-end 530. The RF front-end 530 may include circuitry for transmitting and receiving radio signals. For example, the RF front-end 530 may include a receiver circuitry (RX) 532 and a transmitter circuitry (TX) 534. In some embodiments, the receiver circuitry 532 may communicate with a downlink (DL) front-end 550, which may include circuitry for receiving radio signals via an antenna 335a.

[0134] Similarly, the second modem 520 may include one or more processors 522 and a memory 526 communicating with the processors 522. The modem 520 may communicate with an RF front-end 540. The RF front-end 540 may include circuitry for transmitting and receiving radio signals. For example, the RF front-end 540 may include receiving circuitry 542 and transmitting circuitry 544. In some embodiments, the receiving circuitry 542 may communicate with a DL front-end 560, which may include circuitry for receiving radio signals via an antenna 335b.

[0135] In some implementations, switch 570 may couple transmitting circuitry 534 to uplink (UL) front-end 572. Additionally, switch 570 may couple transmitting circuitry 544 to UL front-end 572. UL front-end 572 may include circuitry for transmitting radio signals via antenna 336. Therefore, when cellular communication circuitry 330 receives an instruction to transmit according to a first RAT (e.g., supported by a first modem 510), switch 570 may be switched to a first state allowing the first modem 510 to transmit signals according to the first RAT (e.g., via a transmission chain including transmitting circuitry 534 and UL front-end 572). Similarly, when cellular communication circuitry 330 receives an instruction to transmit according to a second RAT (e.g., supported by a second modem 520), switch 570 may be switched to a second state allowing the second modem 520 to transmit signals according to the second RAT (e.g., via a transmission chain including transmitting circuitry 544 and UL front-end 572).

[0136] As described herein, the first modem 510 and / or the second modem 520 may include hardware and software components for implementing any of the various features and techniques described herein. For example, processors 512, 522 may be configured to implement some or all of the features described herein by executing program instructions stored on a memory medium (e.g., a non-transitory computer-readable storage medium). Alternatively (or further), processors 512, 522 may be configured as programmable hardware elements (such as FPGAs (Field-Programmable Gate Arrays)) or as ASICs (Application-Specific Integrated Circuits). Alternatively (or further), processors 512, 522 may be configured to implement some or all of the features described herein in conjunction with one or more of other components 530, 532, 534, 540, 542, 544, 550, 570, 572, 335, and 336.

[0137] Furthermore, as described herein, processors 512 and 522 may include one or more processing elements. Therefore, processors 512 and 522 may include one or more integrated circuits (ICs) configured to perform the functions of processors 512 and 522. Additionally, each integrated circuit may include circuitry (e.g., a first circuit, a second circuit, etc.) configured to perform the functions of processors 512 and 522.

[0138] In some embodiments, the cellular communication circuit 330 may include only one transmit / receive chain. For example, the cellular communication circuit 330 may not include modem 520, RF front-end 540, DL front-end 560, and / or antenna 335b. As another example, the cellular communication circuit 330 may not include modem 510, RF front-end 530, DL front-end 550, and / or antenna 335a. In some embodiments, the cellular communication circuit 330 may also not include switch 570, and RF front-end 530 or RF front-end 540 may communicate with UL front-end 572 (e.g., direct communication).

[0139] Figures 6 to 7 —5G NR architecture

[0140] In some specific implementations, fifth-generation (5G) wireless communication will initially be deployed in parallel with other wireless communication standards, such as LTE. For example, Figure 6 This illustrates a possible standalone (SA) implementation of the next-generation core (NGC) network 606 and 5G NR base stations (e.g., gNB 604), dual connectivity between LTE and 5G new radio (5G NR or NR), such as according to Figure 7 The non-standalone (NSA) architecture shown has been designated as part of the initial NR deployment. Therefore, as Figure 7 As shown, the Evolved Packet Core (EPC) network 600 can continue to communicate with the current LTE base station (e.g., eNB 602). Furthermore, eNB 602 can communicate with the 5G NR base station (e.g., gNB 604) and can transfer data between the EPC network 600 and gNB 604. In some cases, gNB 604 may also have at least a user plane reference point with the EPC network 600. Therefore, the EPC network 600 can be used (or reused), and gNB 604 can serve as additional capacity for user equipment, for example, to provide increased downlink throughput for the UE. In other words, LTE can be used for control plane signaling, and NR can be used for user plane signaling. Therefore, LTE can be used to establish connections to the network, and NR can be used for data services. It should be understood that many other non-independent architecture variations are possible.

[0141] Power-saving methods for multi-subscriber identity module devices

[0142] In some implementations, UE 106 may include multiple subscriber identity modules (SIMs, sometimes referred to as SIM cards). In other words, UE 106 may be a multi-SIM (MUSIM) device, such as a dual-SIM device. Any of the various SIMs may be a physical SIM (e.g., a SIM card) or an embedded (e.g., a virtual) SIM. Any combination of physical and / or virtual SIMs may be included. Each SIM may provide various services to the user (e.g., packet-switched service and / or circuit-switched service). In some implementations, UE 106 may share a common receive (Rx) chain and / or transmit (Tx) chain for multiple SIMs (e.g., UE 106 may have a dual-SIM dual-standby (DSDS) architecture). Other architectures are possible. For example, UE 106 may be a dual-SIM dual-active (DSDA) architecture, may include separate Tx chains and / or Rx chains for various SIMs, may include more than two SIMs, etc.

[0143] Different identities (e.g., different SIMs) can have different identifiers, such as different UE identities (UE IDs). For example, an International Mobile Subscriber Identity (IMSI) can be an identity associated with a SIM (e.g., in a MUSIM device, each SIM can have its own IMSI). An IMSI can be unique. Similarly, each SIM can have its own unique International Mobile Equipment Identity (IMEI). Therefore, IMSI and / or IMEI can be examples of possible UE IDs; however, other identifiers can be used as UE IDs.

[0144] Different identities can have the same or different relationships with various Public Land Mobile Networks (PLMNs). For example, a first identity may have a first home PLMN, while a second identity may have a different home PLMN. In such cases, one identity may be pre-occupied on the home network (e.g., on a cell provided by BS 102), while another identity may be roaming (e.g., simultaneously pre-occupied on the same cell provided by BS 102 or pre-occupied on different cells provided by the same or different BS 102). In other cases, multiple identities may be home to simultaneously (e.g., on the same or different cells in the same or different networks) or may roam simultaneously (e.g., on the same or different cells in the same or different networks). It should be understood that multiple combinations are possible. For example, two SIM subscriptions on a MUSIM device may belong to the same equivalence / carrier (e.g., AT&T / AT&T or CMCC / CMCC). As another possibility, SIM-A may be roaming into the network of SIM-B (SIM-A CMCC user roaming to AT&T, and SIM-B is also AT&T).

[0145] Furthermore, for UEs with MUSIM configurations in a DSDS architecture (e.g., SIM1 and SIM2), Tx / Rx can be suspended for SIM1 when the UE performs RF (radio frequency) retuning from SIM1 to SIM2. However, for UEs supporting 5G NR millimeter wave frequencies, dedicated FR2 Tx / Rx RF capabilities can be included as hardware in the UE, and some current MUSIM designs may not fully utilize this capability. For example, a UE with a MUSIM configuration including SIM1 supporting LTE and FR2 (millimeter wave) with active packet switching can be considered a data-preferred or data-default SIM (DDS). Additionally, in some examples, certain high-range FR1 frequencies can also use dedicated Tx / Rx. UEs can also include non-data or non-data-default SIMs (e.g., SIM2) that support LTE but do not support FR2 (mmWave). Therefore, there may be a scenario where a UE operates in Enhanced Dual Connectivity (EN-DC) mode while SIM1 is active, and SIM1 may stop service due to Tx / Rx suspension on SIM1 when SIM2 receives or makes a voice call. For UEs with MUSIM configuration in the DSDA architecture, Tx / Rx capabilities on SIM1 and SIM2 may not be suspended.

[0146] Network denial handling for MSIM devices

[0147] In cases where a UE or ME receives "Network Denial Reason #6" on any of its MSIM instances, the GSMA has provided input for the aforementioned scenarios involving multi-SIM devices. More specifically, the GSMA has provided directives to networks and UEs to ensure the proper functioning of regulatory-mandated (or voluntary) processes to prevent the use of stolen devices on mobile networks. However, while the directives provide measures to enhance security, some power-saving techniques used in conjunction with these security-related directives may be beneficial in extending battery life in the UE. Therefore, it may be beneficial to provide power-saving methods for various scenarios involving an MSIM device receiving reason code Denial #6 "Illegal ME" on one or more of its SIMs.

[0148] For example, in some security-related instances, it might be necessary to block service access for one IMEI from a device's IMEI, which could further lead to the entire device being blocked. More specifically, if a device receives a rejection #6 "Illegal ME" via a 3GPP / connection, it might be necessary to block operation on all 3GPP / 3GPP2 connections. Similarly, if a "Lock Until Power Cycle Command" is received via a 3GPP2 connection, the device can block operation on all 3GPP / 3GPP2 connections. For example, if a device (e.g., User Equipment (UE)) and / or the IMEI associated with the device has been marked as an illegal mobile equipment (ME), the network can determine to block service access for that IMEI. According to some instances, marking an ME as "illegal" can be associated with a user reporting that the ME has been stolen.

[0149] Furthermore, there may be scenarios where NW rejection handling can be optimized for MSIM UEs. For example, a power-saving method could involve shutting down the radio components used by the first MSIM instance when transitioning to a restricted service state (until a power cycle is performed) while another MSIM instance is already in a normal or restricted service state. This disabling of the first radio components can help improve the UE's battery life.

[0150] Additionally, scenarios involving MSIM devices (e.g., MSIM UEs) receiving non-integrity-protected NW rejection messages to invalidate the SIM can benefit from enhanced Denial-of-Service (DoS) handling mechanisms or methods. These enhancements can help reduce unnecessary signaling load and identify fraudulent networks more quickly. Therefore, user experience can be improved from these enhancements.

[0151] Figure 8 MSIM operations under restricted service status

[0152] Figure 8 This is a communication flowchart illustrating an example aspect of MSIM device operation according to some implementation schemes, where multiple SIMs are in a restricted service camp state. For example, if the User Equipment (UE) (e.g., the radio device) conforms to the aforementioned MSIM device GSMA directives, and if the MSIM UE receives a Reject #6 “Illegal ME” reason code for one of its IMEIs (e.g., the first SIM), the radio device should similarly treat the other IMEI (e.g., the second SIM). In other words, according to some implementation schemes, the UE should prevent the SIM that received the Reject #6 reason code, as well as the other SIM (e.g., other IMEIs), from receiving appropriate 3GPP services.

[0153] In this scenario, the UE can access only restricted services, and the first SIM can be marked as invalid. For example, after receiving attachment denial reason code #6, which could indicate that the first SIM is associated with a stolen wireless device, the UE can move both the first and second SIMs to a restricted service camp state. In other words, according to some implementations, multiple MSIM instances in the UE can be in a restricted service camp state simultaneously. Furthermore, according to some implementations, the restricted service camp state can be associated with an MSIM instance that only provides emergency services to the user. For example, in the restricted service camp state, the MSIM instance can still access emergency services (e.g., the ability to make emergency calls, such as 9-1-1 in the US).

[0154] Therefore, if the rejection reason code #6 is received as an integrity protection message and the UE is not configured to use timer T3245, the UE can remain in a limited service dwell state on multiple MSIM instances until a power cycle is performed. Thus, in this scenario, it may be beneficial for the UE to disable one MSIM instance to avoid draining its battery and / or provide power savings while maintaining emergency service on another MSIM instance.

[0155] Figure 8 An example communication flowchart between a network and a first SIM (MSIM_Instance_1) and a second SIM (e.g., MSIM_Instance_2) according to some implementations is illustrated. More specifically, in 802, the UE can power on in MSIM mode supporting the use of both MSIM_Instance_1 and MSIM_Instance_2. According to some implementations, in 804, MSIM_Instance_1 can be used to send an attachment request to the network, and in 806, the network can enable security protection for MSIM_Instance_1. For example, enabling security protection for MSIM_Instance_1 allows secure exchange of Non-Access Stratum (NAS) messages.

[0156] Additionally, in step 808, the network can send an attachment denial reason #6 code to MSIM_Instance_1, which can indicate that the UE is an unauthorized ME (e.g., the ME or UE may have been reported as stolen). Therefore, in step 810, in response to receiving the attachment denial reason code #6 and according to the aforementioned GSMA directive, MSIM_Instance_1 can transition to a restricted service camp state. Furthermore, in step 812, MSIM_Instance_2 can also transition to a restricted service camp state. Therefore, according to some implementations, as shown in step 814, since both MSIM_Instance_1 and MSIM_Instance_2 are in a restricted service camp state, emergency service can be provided only to the UE.

[0157] In Figure 8 In some related implementations, the first SIM can instead be MSIM_Instance_2, and the second SIM can be MSIM_Instance_1, such that their roles are reversed with respect to the methods performed in 802-814.

[0158] Figure 9 - Power-saving technology for MSIM operations involving restricted service residency states

[0159] Figure 9 This is a communication flowchart illustrating an example aspect of MSIM device power-saving techniques for avoiding both SIMs being in a limited service residency state, according to some implementation schemes. More specifically and with Figure 8 In this scenario, the UE may only access emergency services because both the first and second SIMs have transitioned to a restricted service residency mode / state. Therefore, while the GSMA directives can provide security enhancements, it may not be necessary to enable two MSIM instances, as emergency services can be provided via one of the MSIM instances.

[0160] For example, in 902, the UE can power on in MSIM mode, which supports the use of both a first SIM (e.g., MSIM_Instance_1) and a second SIM (e.g., MSIM_Instance_2). In 904, MSIM_Instance_1 can be used to send an attachment request to the network, and in 906, MSIM_Instance_2 can also be used to send an attachment request to the network. In response, according to some implementations, the network can enable security protection for MSIM_Instance_1 in 908.

[0161] Furthermore, in 910, the network can send an attachment rejection reason #6 code to MSIM_Instance_1, which indicates that the UE is an illegal ME. Therefore, in 912, in response to receiving the attachment rejection reason code #6 and according to the aforementioned GSMA directive, MSIM_Instance_1 can transition to a restricted service camp state. In 914, MSIM_Instance_2 can further transition to a restricted service camp state in response to a similar transition of MSIM_Instance_1. Therefore, according to some implementations, as shown in 916, since both MSIM_Instance_1 and MSIM_Instance_2 are in a restricted service camp state, emergency service can be provided to the UE only.

[0162] Therefore, in 918, the UE can disable or turn off the radio component associated with MSIM_Instance_1, while the different radio components associated with MSIM_Instance_2 remain enabled to provide emergency services to the UE. Therefore, in 920, since the radio component used for MSIM_Instance_1 is disabled, the UE can switch or transition to single-SIM mode. This disabling of the radio component can provide power-saving measures to extend the UE's battery life due to the reduced transmission associated with it.

[0163] In other words, in a scenario where MSIM_Instance_1 (e.g., the first SIM) has transitioned to a restricted service dwell state (until a power cycle is executed) due to a rejection reason code from the network (e.g., reason code #6), it may be beneficial to disable the radio components used for the first SIM. The UE can then be associated with a single-SIM mode in restricted service. Therefore, disabling the radio components used for MSIM_Instance_1 can help save or conserve the UE's battery power.

[0164] For example, according to Figure 9 In some related implementations, a wireless device may send a first attachment request to a network node using a first SIM associated with a first radio component, and send a second attachment request to the network node using a second SIM associated with a second radio component. Additionally, the wireless device may operate in a multi-subscriber identity module (MSIM) mode, receiving an attachment rejection message from the network node including an attachment rejection reason code. Based at least in part on receiving the attachment rejection message, the wireless device may switch the second SIM to a restricted service state; disable either the first or second radio component; switch to single-SIM mode; and communicate with the network node via the first SIM.

[0165] In some implementations, the attachment rejection reason code may be attachment rejection reason #6 associated with an unauthorized mobile device (ME). Additionally or alternatively, the attachment rejection message may be non-integrity (non-IP) protected. In some implementations, a restricted service camp state may provide emergency service to the wireless device. According to another implementation, at least one processor may be further configured to cause the wireless device to transition the second SIM out of the restricted service camp state upon completion of a power cycle.

[0166] In Figure 9 In some related implementations, the first SIM can instead be MSIM_Instance_2, and the second SIM can be MSIM_Instance_1, such that their roles are reversed with respect to the methods performed in 902-920.

[0167] Figure 10 -MSIM operations involving normal registration and restricted service residency status

[0168] Figure 10 This is a communication flowchart illustrating an example aspect of the operation of an MSIM device according to some implementation schemes, where one SIM is able to successfully register and another SIM receives an authentication rejection.

[0169] In some implementations, if the UE is operating in MSIM mode and SIM_Instance_1 (e.g., the first SIM) is able to register normally, while SIM_Instance_2 (e.g., the second SIM) marks the Universal SIM (USIM) as invalid, the UE can receive an integrity-protected authentication rejection. More specifically, the UE can receive an integrity-protected attachment rejection reason #7, indicating that EPS service is not allowed for that particular IMEI (e.g., the second SIM associated with MSIM_Instance_2). Therefore, the second SIM (e.g., MSIM_Instance_2) can move to a restricted service-resident mode until it performs a power cycle. In other words, because the UE is operating in MSIM mode and another SIM instance (e.g., the first SIM) may be operating in normal registration service, it may be pointless for the UE to put the second SIM in restricted service-resident mode until it performs a power cycle.

[0170] For example, Figure 10The example illustrates that in 1002, the UE can power on in MSIM mode. In 1004, the first SIM (e.g., MSIM_Instance_1) can then attach to the network and further move to the registration idle state. In 1006, the second SIM (e.g., MSIM_Instance_2) can also transmit an attachment request to the network and receive an authentication request in 1008. Therefore, the UE can respond to the request in 1008 by sending an authentication response to the network via MSIM_Instance_2 in 1010.

[0171] According to some implementations, at 1012, the network may not accept the authentication provided by MSIM_Instance_2 in 1010. Therefore, the network can send an authentication rejection message in 1014, and MSIM_Instance_2 can move to a restricted service camp state in 1016 until a power cycle is performed. Therefore, according to some implementations, at 1018, the UE can operate in MSIM mode, where MSIM_Instance_1 is in a normal registration idle state, while MSIM_Instance_2 is in a restricted service camp state. However, keeping an MSIM instance in a restricted service camp state may be unnecessary, as a SIM can provide the UE with both emergency services and normal registration services (e.g., data communications and / or voice calls). Therefore, in this scenario, it may be beneficial for the UE to disable the MSIM instance in restricted service to avoid draining its battery and / or to provide power-saving measures.

[0172] In Figure 10 In some related implementations, the first SIM can instead be MSIM_Instance_2, and the second SIM can be MSIM_Instance_1, such that their roles are reversed with respect to the methods performed in 1002-1018.

[0173] Figure 11 - Power-saving technology for MSIM operations involving normal registration status and restricted service residency status

[0174] Figure 11 This is a communication flowchart illustrating an example method of MSIM power-saving technology according to some implementation schemes, where one SIM is operating in a normal registration state and another SIM is in a limited service residency state.

[0175] According to Figure 10In some implementation schemes related to this scenario, the UE can access normal registered services via MSIM_Instance_1 (e.g., the first SIM) and access restricted services (e.g., emergency services only) via MSIM_Instance_2 in restricted service camp mode. More specifically, after receiving an authentication rejection or attachment rejection reason code (e.g., reason code #7) indicating that integrity protection of EPS services is not allowed for MSIM_Instance_2 (e.g., the second SIM), the UE can follow an appropriate procedure (e.g., a GSMA procedure or instruction) to prevent the second SIM from receiving appropriate 3GPP services by transitioning the second SIM to a restricted service camp state until a power cycle is performed.

[0176] For example, in step 1102, the UE can power on and operate in MSIM mode. Therefore, in steps 1104 and 1106, MSIM_Instance_1 and MSIM_Instance_2 can transmit attachment requests to the network. According to some implementations, in step 1108, the network can send an attachment acceptance message to MSIM_Instance_1, and in step 1110, MSIM_Instance_1 can transition to a registered idle state.

[0177] According to some implementations, in step 1112, the network may send an authentication request. Therefore, the UE may respond to the request in step 1112 by sending an authentication response to the network via MSIM_Instance_2 in step 1114. According to some implementations, in step 1116, the network may not accept the authentication provided by MSIM_Instance_2 in step 1114 and send an authentication rejection message in step 1118. Alternatively, the network may send an attachment rejection, which may include a rejection reason code indicating that EPS service is not permitted for MSIM_Instance_2, such as reason code #7.

[0178] Therefore, at 1120, MSIM_Instance_2 can transition to a restricted service camp state until a power cycle is executed. In other words, according to some implementations, MSIM_Instance_2 can receive an authentication rejection or an attachment rejection with integrity protection and reason code #7, and each of these rejection messages can transition MSIM_Instance_2 to a restricted service camp state until a power cycle is executed. Therefore, according to some implementations, at 1122, the UE can operate in MSIM mode, where MSIM_Instance_1 is in a normal registration idle state, while MSIM_Instance_2 is in a restricted service camp state. However, it may be unnecessary for one of the MSIM instances to be in a restricted service camp state, as another normally registered SIM (e.g., MSIM_Instance_1) can provide the UE with emergency services as well as normal registration services (e.g., data communications and / or voice calls).

[0179] Therefore, in scenarios where MSIM_Instance_2 has transitioned to a restricted service dwell state (until a power cycle is executed) due to an authentication or attachment rejection reason code from the network (e.g., reason code #7), disabling the radio component for MSIM_Instance_2 may be beneficial. At 1124, the UE can disable or turn off the radio component associated with MSIM_Instance_2, and then the UE can be associated with a single-SIM mode in normal service. Thus, by disabling the radio component for MSIM_Instance_1, this can help save or conserve the UE's battery power by reducing transmissions made via MSIM_Instance_2.

[0180] For example, in relation to Figure 11 In some related examples, the wireless device can receive an attachment acceptance message from a network node on the first SIM and transition to a registration idle state, at least in part, based on the successful registration process. Additionally, the wireless device can receive an authentication request from a network node on the second SIM and send an authentication response to the network node from the second SIM. Furthermore, the wireless device can receive an authentication rejection message from a network node on the second SIM, transitioning the second SIM to a limited service residency state, at least in part, based on the receipt of the authentication rejection message. Alternatively or additionally, the first SIM can provide emergency and normal services, at least in part, based on being in a registration idle state.

[0181] In Figure 11In some related implementations, the first SIM can instead be MSIM_Instance_2, and the second SIM can be MSIM_Instance_1, such that their roles are reversed with respect to the methods performed in 1102-1126.

[0182] Figure 12 - MSIM operation during normal registration status involving registration rejection messages related to incomplete integrity protection

[0183] Recently, the 3GPP specification has provided instructions for UEs to handle 5GS Mobility Management (5GMM) rejection messages. These 5GS Mobility Management (5GMM) rejection messages are received without integrity protection before the network has established a secure exchange of NAS messages. More specifically, when a malicious network transmits unsolicited NAS rejection messages without security protection, it can lead to a denial-of-service (DoS) attack on the victim UE. For example, according to some implementations, normal processing of unprotected registration rejection messages triggered by fake or spoofed Next Generation Radio Access Networks / Next Generation Node Bs (NG-RAN / gNB) that include fatal rejection reasons (such as values ​​or reason codes #6 "illegal ME") may cause the UE to treat or mark the Universal Subscriber Identity Module (USIM) as invalid for 5GS service until it is shut down (e.g., performing a power cycle) or until the Universal Integrated Circuit Card (UICC) containing the USIM is removed.

[0184] However, older implementations or operations of the network may still transmit non-integrity protection rejection messages. Therefore, non-integrity protection messages should not be ignored or discarded entirely, and thus the methods or mechanisms used to process these messages can provide enhanced benefits to the UE.

[0185] Figure 12 This is a communication flowchart illustrating an example aspect of the operation of an MSIM device according to some implementation schemes, where one SIM operates in a normal registration state and another SIM receives a registration rejection message with non-integrity protection.

[0186] For example, such as Figure 12As shown, at 1202, the UE can power on in MSIM mode, and the first SIM (e.g., MSIM_Instance_1) can then attach to the network and move to a registration idle state in 1204. In 1206, the second SIM (e.g., MSIM_Instance_2) can send a registration request to the network and receive a non-integrity-protected (non-IP) registration rejection message in 1208. More specifically, according to some embodiments, at 1208, the network can send a non-IP registration rejection message associated with or including reason code #6, which can indicate that MSIM_Instance_2 corresponds to an illegal ME.

[0187] Therefore, in 1210, MSIM_Instance_2 can start a T3245 timer and mark the USIM as invalid for the duration of the T3245 timer. In other words, MSIM_Instance_2 can be considered invalid for network registration until the T3245 timer expires. Alternatively, if MSIM_Instance_2 does not configure a T3245 timer, MSIM_Instance_2 can start a T3247 timer. Furthermore, MSIM_Instance_2 can increment the counter of the T3247 timer and mark the corresponding Tracking Area (TA) associated with the network registration attempt as prohibited. In some implementations, MSIM_Instance_2 can then search for another TA while excluding prohibited TAs.

[0188] In other words, according to some implementations, a mechanism for DoS attack prevention when the UE receives a non-IP denial reason #6 may involve the UE starting a timer T3245 using a random value uniformly drawn from a range between 12h and 24h (as an example range), and marking the USIM as invalid for that duration. Alternatively, if the UE is not configured to use the T3245 timer, the UE may instead start a timer T3247 using a random value uniformly drawn from a range between 30 minutes and 60 minutes (as an example range), and maintain a counter for the "SIM / USIM deemed invalid for GPRS service" event, incrementing the counter until it reaches a maximum value defined by the UE. The UE can then continue searching for cells in different TAs. Furthermore, according to some implementations, such a mechanism for MSIM devices can be extended to all 3GPPRATs.

[0189] For example, when an MSIM UE receives a non-integrity protection rejection reason #6 (illegal ME) on one MSIM instance, another MSIM instance might still be able to register normally with security enabled. A 3GPP approach might involve multiple attempts from the device and could result in additional signaling load on the network side. Furthermore, according to some implementations, in the event of a fraudulent network transmission of the non-integrity protection rejection reason #6, the UE could be denied any service until timers T3245 or T3247 have reached their duration.

[0190] Therefore, while previous 3GPP approaches to address rejection reason messages for non-integrity protection may have overlooked the additional information and flexibility that MSIM devices may possess, the aforementioned mechanism can help UEs identify fraudulent networks in less time and take responsive actions to mitigate latency and / or provide power savings.

[0191] In Figure 12 In some related implementations, the first SIM can instead be MSIM_Instance_2, and the second SIM can be MSIM_Instance_1, such that their roles are reversed with respect to the methods performed in 1202-1210.

[0192] Figure 13 and Figure 14 - Power-saving method for MSIM operations involving registration rejection messages related to non-integrity protection

[0193] Figure 13 This is a communication flowchart illustrating an example method for power saving in a scenario where one SIM is operating in a normal registration state and another SIM has received a non-integrity protection registration rejection message, according to some implementation schemes.

[0194] For example, in step 1302, the UE can power on in MSIM mode, and the first SIM (e.g., MSIM_Instance_1) can send an attachment request to the network. Therefore, in step 1304, MSIM_Instance_1 can attach and move to the registered idle state. Similarly, the second SIM (e.g., MSIM_Instance_2) can send a registration request to the network in step 1306, but in step 1308 receives a non-IP registration rejection reason #6, illegal ME message from the network. However, in step 1310, according to some implementations, since MSIM_Instance_1 has already transitioned to the registered state, MSIM_Instance_2 can ignore the non-IP rejection and continue with cell selection and disable the current cell.

[0195] In other words, in the case of an MSIM device, the UE may have additional information about the registration status of another MSIM instance. When the UE receives a non-IP rejection reason #6 on the current instance (e.g., SIM), it can use this additional information to determine its action. For example, if an MSIM UE first receives a non-IP rejection reason #6 illegal ME on one MSIM instance, the other MSIM instance may be able to successfully complete registration. Furthermore, according to some implementations, because the UE can register normally on MSIM_Instance_2, the UE can use this information on MSIM_Instance_1 to stop the T3245 / T3247 timer initiated for DoS and immediately continue cell selection. Therefore, according to some implementations, this can provide power savings by bypassing or actively stopping the T3245 / T3247 timer, which could lead to registration delays if the T3245 / T3247 timer is not stopped.

[0196] For example, according to Figure 13 In a related alternative implementation, a method performed by the UE may include: operating in MSIM mode; and sending a first registration request to a network node using a first radio component associated with a first SIM. The method may further include: transitioning the first SIM to a registration idle state, at least in part based on performing a successful registration process associated with a first cell of the network node; and sending a second registration request to the network node using a second radio component associated with a second SIM. The method may further include receiving a registration rejection message from the network node using the second radio component. In some implementations, the registration rejection message may include a registration rejection reason code associated with a second cell of the network node. The method may further include: blocking the second cell; and performing a cell selection process, wherein the second cell is blocked during the cell selection process. According to some implementations, the registration rejection message may be a non-IP registration rejection message.

[0197] In Figure 13 In some related implementations, the first SIM can instead be MSIM_Instance_2, and the second SIM can be MSIM_Instance_1, such that their roles are reversed with respect to the methods performed in 1302-1310.

[0198] Figure 14 This is a communication flowchart illustrating an alternative method for power saving in a scenario where one SIM is operating in a normal registration state and another SIM has received a non-integrity protection registration rejection message, according to some implementation schemes.

[0199] For example, in 1402, the UE can power on in MSIM mode, and the second SIM (e.g., MSIM_Instance_2) can transmit a registration request to the network in 1404. Additionally, in 1406, MSIM_Instance_2 can receive a non-IP registration rejection reason #6, illegal ME message from the network. However, in 1408, according to some embodiments, if MSIM_Instance_2 has configured a T3245 timer, it can start the T3245 timer and mark the USIM as invalid for the duration of the timer (e.g., until expiration). Alternatively, according to some embodiments, if MSIM_Instance_2 has not configured a T3245 timer, it can start a T3247 timer, increment the counter, mark the TA as disabled, and search for another TA.

[0200] Additionally, in step 1410, MSIM_Instance_1 can attach and move to the registration idle state. Therefore, once the UE knows that MSIM_Instance_1 has successfully registered, in step 1412, MSIM_Instance_2 can stop timer T3245 or timer T3247 and immediately begin cell selection and disable the current serving cell. In other words, according to some implementations, if the MSIM UE receives a non-integrity-protected rejection reason #6 "illegal ME" on one MSIM instance, and another MSIM instance successfully registers, the UE can simply ignore the non-IP rejection message received on the current MSIM instance and continue the cell selection process, during which the current serving cell is disabled.

[0201] For example, with Figure 14 Related methods may include: starting one or more timers upon receiving a registration rejection message. In some embodiments, the one or more timers may include a T3245 timer, and the method may further include marking the second SIM as invalid for the duration of the T3245 timer. Additionally or alternatively, the one or more timers may include a T3247 timer, and the method may further include: incrementing a counter of the timer; marking the tracking area (TA) associated with the second cell as prohibited; and searching for TAs other than the prohibited TA. In some embodiments, the registration rejection reason code may be registration rejection reason #6 associated with unauthorized mobile equipment (ME).

[0202] In Figure 14In some related implementations, the first SIM can instead be MSIM_Instance_2, and the second SIM can be MSIM_Instance_1, such that their roles are reversed with respect to the methods performed in 1402-1412.

[0203] Figure 15 - MSIM loop operation involving registration rejection messages for non-integrity protection

[0204] Figure 15 This is a communication flowchart illustrating an example aspect of the operation of an MSIM device according to some implementation schemes, where two SIMs from the same PLMN follow a loop process after receiving a non-integrity-protected registration rejection message.

[0205] For example, in 1502, the UE can execute a cyclical process (e.g., a cyclical mechanism or method) until a maximum counter value is reached. In other words, the counter can be incremented until the maximum value is reached each time a cycle involving 1504, 1506, 1508, and 1510 is completed. According to some implementations, the cyclical process can be stopped when the maximum value is reached. More specifically, the cyclical process may include 1504, in which the UE can power on in MSIM mode, and the first SIM (e.g., MSIM_Instance_1) can transmit a registration request to the PLMN in 1506. Additionally, in 1508, MSIM_Instance_1 can receive a non-IP registration rejection reason #6, illegal ME message from the PLMN. Therefore, according to some implementations, if MSIM_Instance_1 is not configured with timer T3245, MSIM_Instance_2 can start timer T3247, increment the counter, mark the TA as disabled, and search for another TA. Furthermore, according to some implementations, if the maximum value of the counter has not yet been reached, the UE can continue to return to the appropriate start of the 1502 cycle process (e.g., 1504 or 1506).

[0206] Additionally, in step 1512, the UE can execute a second loop procedure associated with MSIM_Instance_2, and the counter can be incremented until it reaches a maximum value each time loops involving steps 1514, 1516, and 1588 are completed. According to some implementations, the 1512 loop procedure can be stopped when the maximum value is reached.

[0207] More specifically, the 1512 cycle may include 1514, in which MSIM_Instance_2 may transmit a registration request to the same PLMN. Additionally, in 1516, MSIM_Instance_2 may receive a non-IP registration rejection reason #6, illegal ME message from the PLMN. Therefore, according to some implementations, if MSIM_Instance_2 is not configured with timer T3245, it may start timer T3247, increment the counter, mark the TA as disabled, and search for another TA. Furthermore, according to some implementations, if the maximum value of the counter has not been reached, the UE may continue to the appropriate start of the 1502 cycle (e.g., 1504 or 1506). In at least some cases, these 1502 and 1512 cycle processes of the SIM may result in a greater number of signaling attempts from the MSIM device, and thus increase the signaling load on the network.

[0208] In other words, when an MSIM UE receives a non-IP rejection reason code #6 "Illegal ME" on two MSIM instances from the same PLMN and the UE is not configured to use the T3245 timer, each MSIM instance (e.g., the first SIM and the second SIM, i.e., MSIM_Instance_1 and MSIM_Instance_2) can independently maintain a counter for the "SIM / USIM deemed invalid for GPRS service" event. Furthermore, the first and second SIMs can increment the counters for each rejection from the network until they reach their maximum values. Therefore, the two SIMs can then continue searching for another cell in different TAs.

[0209] Therefore, while an MSIM device can run separate DoS-specific counters and timers on two MSIM instances as if they were two single-SIM devices, this can lead to reduced efficiency and power savings for both the MSIM device and the network. Therefore, according to some implementations, it may be beneficial to treat the two MSIM instances as a single device with a single counter for both SIMs in this scenario.

[0210] In Figure 15 In some related implementations, the first SIM can instead be MSIM_Instance_2, and the second SIM can be MSIM_Instance_1, such that their roles are reversed with respect to the methods performed in 1502-1518.

[0211] Figure 16 - Power-saving method for MSIM operation involving registration rejection messages related to non-integrity protection in the tracking area

[0212] Figure 16 This is a communication flowchart illustrating an example method for power saving in a scenario where a SIM receives a non-integrity protection registration rejection message and attempts to reside in a second tracking area, according to some implementation schemes.

[0213] For example, in 1602, the UE can power on in MSIM mode, and the first SIM (e.g., MSIM_Instance_2) can transmit a registration request associated with the first tracking area identifier (TAI_1) to the PLMN in 1604. Additionally, in 1606, MSIM_Instance_2 can receive a registration rejection reason #6, illegal ME message from the PLMN. Therefore, according to some embodiments, in 1608, if MSIM_Instance_2 is not configured with timer T3245, MSIM_Instance_2 can start a common timer T3247 (e.g., common for the second SIM (e.g., MSIM_Instance_1) and MSIM_Instance_2), incrementing the counter, marking TAI_1 ​​as disabled, and searching for another TA. Furthermore, according to some embodiments, since the UE may now know that TAI_1 ​​is disabled, MSIM_Instance_1 may not attempt to register on TAI_1.

[0214] Conversely, at 1610, MSIM_Instance_1 can attempt to camp on the second TAI (e.g., TAI_2), and at 1612, it sends a registration request associated with TAI_2 to the PLMN. Furthermore, at 1614, security protection can be enabled, and the PLMN can send a registration acceptance message to MSIM_Instance_1 at 1616. Therefore, at 1618, the UE (e.g., and thus its associated MSIM instance) knows that MSIM_Instance_1 can successfully register with the PLMN on TAI_2, and therefore MSIM_Instance_2 can begin cell selection on TAI_2. Therefore, at 1620, MSIM_Instance_2 can send a registration request associated with TAI_2 to the PLMN. Furthermore, at 1622, security protection can be enabled, and the PLMN can send a registration acceptance message to MSIM_Instance_2 at 1624.

[0215] In other words, two MSIM instances can be associated with a single UE, and both instances can have the same carrier SIM. This allows one MSIM instance to perform an action in response to the actions of the other MSIM instance. Therefore, a single timer can be used to maintain a common counter for the "SIM / USIM deemed invalid for GPRS service" event and a shared "5GS no-tracking zones for roaming" list for NAS rejection messages for non-integrity protection.

[0216] For example, and with Figure 16 Relatedly, if one MSIM instance successfully registers, another MSIM instance can trigger registration on the same TAI. However, if either instance fails to register due to non-integrity protection rejection reason code #6 "Illegal ME", the UE can restart the common T3247 timer and update the common counter for the "SIM / USIM deemed invalid for GPRS service" event. Additionally, the UE can update the TAI in the shared "5GS No Tracking Areas for Roaming" list for NAS rejection messages used for non-integrity protection. In this scenario, setting a maximum number of attempts per device (e.g., 10 attempts as an example) may be beneficial. Therefore, if each instance is associated with the maximum number of 10 attempts, this would potentially result in 20 attempts per device, which would be substantially redundant since both MSIM instances have the same carrier SIM. Thus, the common timer can be used for both MSIM instances to reduce the number of registration attempts per device, and further as a potential power-saving method with reduced redundancy. In other words, it may be beneficial for the UE to use a single timer to maintain a common counter for the "SIM / USIM deemed invalid for GPRS service" event and a shared "5GS no-tracking areas for roaming" list for NAS rejection messages for non-integrity protection. Therefore, by maintaining a common timer and counter, as well as a shared list of no-tracking areas, the UE's MSIM instance can be able to connect to the network more efficiently and further save power through reduced communication.

[0217] In addition, according to Figure 16In a related implementation, an apparatus may include at least one processor of a UE operating in MSIM mode, and the at least one processor may be configured to cause the UE to send a first registration request associated with a first Tracking Area Identifier (TAI) to a Public Land Mobile Network (PLMN) using a first radio component associated with a first SIM. The at least one processor may be further configured to cause the UE to receive a registration rejection message from a network node using the first radio component, wherein the registration rejection message may include a registration rejection reason code. The at least one processor may be further configured to cause the UE to: initiate one or more timers; mark the first TAI as prohibited; and search for a second TAI that excludes the first TAI.

[0218] In some embodiments, the at least one processor may be further configured to cause the UE to: send a second registration request associated with a second TAI to the PLMN using a second radio component; and receive a registration acceptance message from the PLMN using a second SIM. According to some embodiments, the at least one processor is further configured to cause the UE to: send a third registration request associated with a second TAI to the PLMN using a first radio component associated with a first SIM; and receive a second registration acceptance message from the PLMN using the first radio component associated with the first SIM. Additionally or alternatively, one or more timers may include a T3247 timer, and the at least one processor may be further configured to cause the UE to: increment the counter of the T3247 timer upon receiving a registration rejection message from the PLMN. According to some embodiments, the registration rejection message may be a non-IP non-access stratum (NAS) rejection message.

[0219] In some implementations, as the counter of the T3247 timer is incremented, the at least one processor may be further configured to cause the UE to: update the prohibited TAI list to include the corresponding prohibited TAI associated with the corresponding registration request message upon receiving a corresponding registration rejection message. Additionally or alternatively, when the counter of the T3247 timer reaches its maximum value, the at least one processor may be further configured to cause the UE to perform a cell search procedure in different TAIs.

[0220] In Figure 16 In some related implementations, the first SIM can instead be MSIM_Instance_1, and the second SIM can be MSIM_Instance_2, such that their roles are reversed with respect to the methods performed in 1602-1624.

[0221] Example Implementation Plan

[0222] Another example implementation may include a device comprising: an antenna; a radio component coupled to the antenna; and a processing element operatively coupled to the radio component, wherein the device is configured to implement any or all of the foregoing examples.

[0223] Another example implementation may include a method comprising: by a device: performing any or all of the foregoing examples.

[0224] Another implementation may include a non-transitory computer-accessible memory medium that, when executed at the device, causes the device to perform any or all of the instructions of any of the foregoing examples.

[0225] Another example implementation may include a computer program that includes instructions for performing any or all of the portions of any of the examples above.

[0226] Another example implementation may include an apparatus that includes means for performing any or all of the elements of any of the foregoing examples.

[0227] Another example implementation may include an apparatus comprising a processing element configured to cause a wireless device to perform any or all of the elements of any of the foregoing examples.

[0228] As is widely recognized, the use of personally identifiable information should comply with privacy policies and measures that are generally accepted to meet or exceed industry or governmental requirements for protecting user privacy. Specifically, personally identifiable information data should be managed and processed to minimize the risk of unintentional or unauthorized access or use, and the nature of authorized use should be clearly explained to users.

[0229] Embodiments of this disclosure may be implemented in any of a variety of forms. For example, some embodiments may be implemented as computer-implemented methods, computer-readable storage media, or computer systems. Other embodiments may be implemented using one or more custom-designed hardware devices such as ASICs. Other embodiments may be implemented using one or more programmable hardware elements such as FPGAs.

[0230] In some embodiments, a non-transitory computer-readable storage medium may be configured to store program instructions and / or data, wherein, if executed by a computer system, the program instructions cause the computer system to perform a method, such as any method embodiment of the method embodiments described herein, or any combination of method embodiments described herein, or any subset or combination of any such subset of any method embodiments described herein.

[0231] In some implementations, the device (e.g., UE 106 or BS 102) may be configured to include a processor (or a set of processors) and a memory medium, wherein the memory medium stores program instructions, and wherein the processor is configured to read from the memory medium and execute the program instructions, wherein the program instructions are executable to implement any of the various method implementations described herein (or any combination of the method implementations described herein, or any subset or combination of any subset of the method implementations described herein). The device may be implemented in any of the various forms.

[0232] Although the above embodiments have been described in considerable detail, many variations and modifications will become apparent to those skilled in the art once the above disclosure is fully understood. It is intended that the following claims be construed as encompassing all such variations and modifications.

Claims

1. A wireless device, the wireless device comprising: First radio component and second radio component; At least one processor, coupled to the first radio component and the second radio component and configured to enable the wireless device to: Send a first attachment request to the network node using the first SIM associated with the first radio component; A second attachment request is sent to the network node using a second SIM associated with the second radio component; Operating in Multi-Subscriber Identity Module (MSIM) mode, receiving an attachment rejection message from the network node, wherein the attachment rejection message includes an attachment rejection reason code; The second SIM is switched to a restricted service residency state, at least in part based on the receipt of the attachment rejection message; Disable the second radio component; Switch to single SIM mode; and Communicating with the network node, wherein the communication is associated with the first SIM.

2. The wireless device of claim 1, wherein the attachment denial reason code is attachment denial reason #6 associated with unauthorized mobile equipment (ME).

3. The wireless device according to claim 1, wherein the restricted service dwell state provides emergency services to the wireless device.

4. The wireless device of claim 1, wherein the at least one processor is further configured to cause the wireless device to transition the second SIM out of the restricted service dwell state upon completion of a power cycle.

5. The wireless device of claim 1, wherein the attachment rejection message is non-integrity protected.

6. The wireless device of claim 1, wherein the at least one processor is further configured to cause the wireless device to: Receive an attach accept message from the network node on the first SIM; At least in part, the process transitions to a registration idle state based on the successful execution of the registration process; Receive an authentication request from the network node on the second SIM; Send an authentication response to the network node on the second SIM; and Receive an authentication rejection message from the network node on the second SIM; The second SIM is switched to the restricted service residency state based at least in part on receiving the authentication rejection message.

7. The wireless device of claim 6, wherein the first SIM provides emergency and normal services at least in part based on being in the registered idle state.

8. A method, the method comprising: User equipment (UE) operating in Multi-Subscriber Identity Module (MSIM) mode: The first registration request is sent to the network node using a first radio component associated with the first subscriber identity module (SIM); The first SIM is transitioned to a registration idle state, at least in part, based on the successful registration process associated with the first cell of the network node. A second registration request is sent to the network node using a second radio component associated with the second SIM; The second radio component is used to receive a registration rejection message from the network node, wherein the registration rejection message includes a registration rejection reason code associated with a second cell of the network node; The second cell is prohibited; and Perform a cell selection process, wherein the selection of the second cell is prohibited during the cell selection process.

9. The method of claim 8, wherein the registration rejection message is a non-integrity protected registration rejection message.

10. The method according to claim 8, further comprising: Upon receiving the registration rejection message, start one or more timers.

11. The method of claim 10, wherein the one or more timers include a T3245 timer, and the method further comprises: The second SIM is marked as invalid during the duration of the T3245 timer.

12. The method of claim 10, wherein the one or more timers include a T3247 timer, and the method further comprises: Increment the counter of the timer; Mark the tracking area (TA) associated with the second cell as prohibited; as well as Search for users other than those who are banned.

13. The method of claim 8, wherein the registration rejection reason code is registration rejection reason #6 associated with illegal mobile equipment (ME).

14. An apparatus comprising: At least one processor of a user equipment (UE) operating in a multi-subscriber identity module (MSIM) mode, wherein the at least one processor is configured to cause the UE to: The first radio component associated with the first subscriber identity module (SIM) sends a first registration request associated with the first tracking area identifier (TAI) to the public land mobile network (PLMN); The first radio component is used to receive a registration rejection message from the network node, wherein the registration rejection message includes a registration rejection reason code; Start one or more timers; Mark the first TAI as prohibited; and The search excludes the second TAI from the first TAI.

15. The apparatus of claim 14, wherein the at least one processor is further configured to cause the UE to: The second radio component associated with the second SIM is used to send a second registration request associated with the second TAI to the PLMN; and The second radio component is used to receive the registration acceptance message from the PLMN.

16. The apparatus of claim 15, wherein the at least one processor is further configured to cause the UE to: The first radio component associated with the first SIM is used to send a third registration request associated with the second TAI to the PLMN; and The first radio component associated with the first SIM is used to receive a second registration acceptance message from the PLMN.

17. The apparatus of claim 14, wherein the one or more timers include a T3247 timer, and wherein the at least one processor is further configured to cause the UE to: When a registration rejection message is received from the PLMN, the counter of the T3247 timer is incremented.

18. The apparatus of claim 17, wherein when the counter of the T3247 timer is incremented, the at least one processor is further configured to cause the UE to: Upon receiving a registration rejection message, update the blocked TAI list to include the corresponding blocked TAI associated with the registration request message.

19. The apparatus of claim 17, wherein when the counter of the T3247 timer reaches its maximum value, the at least one processor is further configured to cause the UE to: Perform the cell search process in different TAIs.

20. The apparatus of claim 14, wherein the registration rejection message is a non-integrity protected non-access stratum (NAS) rejection message.