System and method for handling user equipment parameters in authentication rejection
By removing the network list and resetting the relevant counters after authentication rejection, the challenges of UE parameter management in wireless communication networks are addressed, network selection and service continuity are improved, and the robustness and efficiency of the system are enhanced.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-30
- Publication Date
- 2026-04-07
AI Technical Summary
In wireless communication networks, after authentication rejection, existing technologies struggle to effectively manage user equipment (UE) parameters, impacting subsequent network selection, service continuity, and overall system efficiency.
By deleting the network list and resetting relevant counters, including the registration attempt counter, attach attempt counter, service attempt counter, and tracking area update (TAU) attempt counter, upon receiving an authentication rejection message, the accuracy and up-to-dateness of UE parameters are ensured.
It improved the success rate of subsequent connection attempts for UEs, enhanced network performance and overall system efficiency, and ensured the accuracy and security of network status.
Smart Images

Figure CN121815369A_ABST
Abstract
Description
[0001] Cross-referencing
[0002] The scope of this application claims priority to the following application: Indian Patent Application No. 202421075186, filed on October 4, 2024, the entire contents of which are incorporated herein by reference. [Technical Field]
[0003] This invention provides a system and method for use in wireless communication networks, and more specifically, it provides a system and method for processing user equipment parameters when authentication is rejected. [Background Technology]
[0004] In wireless communication networks, authentication procedures play a crucial role in ensuring the secure and authorized access of user equipment (UE) devices. These procedures typically involve the exchange of authentication information between the UE and the network to verify the identity and credentials of any device attempting to connect.
[0005] The authentication process uses various parameters and identifiers, including temporary and permanent identities, security keys, and location information. Networks may use different types of identities depending on the specific circumstances and security requirements, such as Globally Unique Temporary Identifiers (GUTIs) or Subscription Concealed Identifiers (SUCIs).
[0006] In some cases, the authentication process may fail, resulting in network authentication rejection. This can occur for various reasons, such as invalid credentials, network errors, or security issues. When a UE receives an authentication rejection message, it typically triggers a series of actions to handle the rejection and maintain the integrity of the communication system.
[0007] Handling authentication rejection messages and UE parameters is an area of ongoing development in wireless communication standards. This includes considering the management of stored information such as identity lists, location data, and various counters used for network access attempts. Proper management of these parameters affects subsequent UE behavior, including its ability to select a network, perform cell reselection, and initiate new registration or service requests.
[0008] As wireless networks continue to evolve, transitioning from 4G to 5G and higher versions, the mechanisms for handling authentication rejections and managing UE parameters are also constantly being improved. These developments aim to enhance security, improve user experience, and optimize network performance in the event of authentication challenges.
[0009] Effective handling of UE parameters following authentication rejection can impact network selection, service continuity, and overall system efficiency. This is an area that requires careful consideration to balance security requirements with the need for seamless and reliable wireless connectivity. [Summary of the Invention]
[0010] The specific embodiments disclosed herein are intended to address one or more problems raised in the prior art and provide additional features that will become readily apparent when viewed in conjunction with the accompanying drawings and the following detailed description. According to various embodiments, the present invention discloses numerous specific implementations such as systems, methods, apparatuses, and computer program products. However, it should be understood that these embodiments are presented by way of example only and are not intended to limit the scope of the claims. Those skilled in the art will understand the purpose of the invention upon reading this description, and therefore, various modifications based on the disclosed embodiments will not depart from the scope of the claims declared herein.
[0011] In one specific embodiment, the wireless communication method performed by the wireless communication device includes receiving an authentication rejection message initiated as part of a program from a wireless communication node, and in response to receiving the authentication rejection message, deleting the network list to which the wireless communication node belongs.
[0012] In another embodiment, a device includes a transceiver configured to wirelessly communicate with a network, and a processor coupled to the transceiver and configured to perform operations. The operations include receiving an authentication rejection message initiated as part of a program from the network, and, in response to receiving the authentication rejection message, removing the network from its network list.
[0013] In yet another embodiment, the wireless communication method performed by the wireless communication node includes sending an authentication rejection message initiated as part of a procedure to a wireless communication device, wherein the network list to which the wireless communication node belongs is configured to be removed by the wireless communication device in response to the wireless communication device receiving the authentication rejection message.
[0014] In a further embodiment, a device includes a transceiver configured to wirelessly communicate with a network, and a processor coupled to the transceiver and configured to perform operations. The operations include sending an authentication rejection message initiated as part of a program to the wireless communication device, wherein the list of networks to which the device belongs is configured to be removed by the wireless communication device in response to the wireless communication device receiving the authentication rejection message.
[0015] The foregoing and other aspects, and their implementations, will be described in more detail in the accompanying drawings, description, and claims. [Attached Image Description]
[0016] Various specific embodiments of the present invention are described in detail below with reference to the following figures or drawings. The drawings are for illustrative purposes only, depicting specific embodiments of the invention to aid the reader's understanding. Therefore, the drawings should not be considered as limiting the breadth, scope, or applicability of the invention. It should be noted that these drawings are not necessarily drawn to scale for clarity and ease of explanation.
[0017] Figure 1 This is a schematic diagram of an example cellular communication network implementing one specific embodiment of the present invention.
[0018] Figure 2 This is a schematic diagram of a base station and user equipment according to a specific embodiment of the present invention.
[0019] Figure 3 This is a flowchart of a wireless communication method performed by a wireless communication device according to a specific embodiment of the present invention.
[0020] Figure 4 This is a flowchart of a wireless communication method executed by a wireless communication node, which is a specific embodiment of the present invention.
Detailed Implementation Methods
[0021] Various specific embodiments of the present invention are described below in conjunction with the accompanying drawings to enable those skilled in the art to make and use the invention. As will be apparent to those skilled in the art upon reading this description, various changes or modifications to the examples described herein can be made without departing from the scope of the invention. Therefore, the invention is not limited to the exemplary embodiments and applications described and illustrated herein. Furthermore, the specific order or hierarchy of steps in the methods disclosed herein is merely exemplary. Based on design preferences, the specific order or hierarchy of steps in the disclosed methods or procedures may be rearranged without departing from the scope of the invention. Therefore, those skilled in the art will understand that the methods and techniques disclosed herein present various steps or actions in an exemplary order, and unless explicitly stated otherwise, the invention is not limited to the specific order or hierarchy presented.
[0022] Figure 1 An example wireless communication network, system, or network system 100 according to an embodiment of the present invention is illustrated, which can implement the technology disclosed herein. In the following discussion, wireless communication network 100 can be any wireless network, such as a cellular network or a narrowband Internet of Things (NB-IoT) network, and is referred to herein as "network 100". Such an example network 100 includes a base station 102 (hereinafter referred to as "BS102") and a user equipment 104 (hereinafter referred to as "UE104"), which can communicate with each other via a communication link 110 (e.g., a wireless communication channel), and multiple cells 126, 130, 132, 134, 136, 138, and 140 covering a geographical area 101. Figure 1 In this context, BS102 and UE 104 are located within the corresponding geographical boundaries of cell 126. Each of the other cells 130, 132, 134, 136, 138, and 140 may include at least one base station that operates on its allocated bandwidth to provide sufficient radio coverage to its intended users.
[0023] For example, BS102 can operate on the allocated channel transmission bandwidth to provide sufficient coverage to UE 104. BS102 and UE 104 can communicate via downlink radio frame 118 and uplink radio frame 124, respectively. Each radio frame 118 / 124 can be further divided into subframes 120 / 127, which may include data symbols 122 / 128. In this invention, BS102 and UE 104 are described herein as non-limiting examples of "communication nodes," and the methods disclosed herein can generally be practiced. According to various embodiments of the invention, these communication nodes can perform wireless and / or wired communication.
[0024] Figure 2 A schematic diagram of an example wireless communication system 200 for transmitting and receiving wireless communication signals (e.g., OFDM / OFDMA signals) according to some embodiments of the present invention is shown. System 200 may include components and elements configured to support known or conventional operating characteristics, which do not need to be described in detail herein. In one illustrative embodiment, system 200 may be used for transmitting and receiving wireless communication signals such as… Figure 1 The wireless communication environment 100 is used for communication of data symbols (e.g., transmission and reception).
[0025] System 200 typically includes a base station 202 (hereinafter referred to as "BS202") and a user equipment 204 (hereinafter referred to as "UE204"). BS202 includes a BS (Base Station) transceiver module 210, a BS antenna 212, a BS processor module 214, a BS memory module 216, and a network communication module 218. Each module is coupled and interconnected as needed via a data communication bus 220. UE204 includes a UE (User Equipment) transceiver module 230, a UE antenna 232, a UE memory module 234, and a UE processor module 236. Each module is coupled and interconnected as needed via a data communication bus 240. BS202 communicates with UE204 via a communication channel 250, which can be any wireless channel or other medium suitable for transmitting the data described herein.
[0026] As will be understood by those skilled in the art, system 200 may include, except Figure 2Any number of modules other than those shown. Those skilled in the art will understand that the various illustrative blocks, modules, circuits, and processing logic described in the embodiments disclosed herein can be implemented in hardware, computer-readable software, firmware, or any practical combination thereof. To clearly illustrate this interchangeability and compatibility of hardware, firmware, and software, various illustrative components, blocks, modules, circuits, and steps are generally described according to their functionality. Whether such functionality is implemented as hardware, firmware, or software may depend on the specific application and design constraints imposed on the system as a whole. Those skilled in the art can implement such functionality in a manner suitable for each specific application, but such implementation decisions should not be construed as limiting the scope of the invention.
[0027] According to some embodiments, UE transceiver 230, which may be referred to herein as "uplink" transceiver 230, includes a radio frequency (RF) transmitter and an RF receiver, each including circuitry coupled to antenna 232. A duplex switch (not shown) can selectively couple the uplink transmitter or receiver to the uplink antenna in a time-duplex manner. Similarly, according to some embodiments, BS transceiver 210, which may be referred to herein as "downlink" transceiver 210, includes an RF transmitter and an RF receiver, each including circuitry coupled to antenna 212. A downlink duplex switch can selectively couple the downlink transmitter or receiver to downlink antenna 212 in a time-duplex manner. The operation of the two transceiver modules 210 and 230 can be time-coordinated so that the uplink receiver circuitry is coupled to uplink antenna 232 to receive transmissions on radio link 250, while the downlink transmitter is coupled to downlink antenna 212. In some embodiments, the guard time between duplex direction changes is minimized, achieving tight time synchronization.
[0028] UE transceiver 230 and base transceiver 210 are configured to communicate via wireless data communication link 250 and cooperate with appropriately configured RF antenna devices 212 / 232 to support specific wireless communication protocols and modulation schemes. In some exemplary embodiments, UE transceiver 210 and base transceiver 230 are configured to support industry standards such as Long Term Evolution (LTE) and emerging 5G standards. However, it should be understood that the present invention is not necessarily limited to application to specific standards and related protocols. Rather, UE transceiver 230 and base transceiver 210 can be configured to support alternative or additional wireless data communication protocols, including future standards or variations thereof.
[0029] According to various embodiments, BS202 may be an evolved Node B (eNB), a serving eNB, a target eNB, a micro base station, or a pico base station. For example, in some embodiments, UE 204 may be embodied as various types of user equipment, such as mobile phones, smartphones, personal digital assistants (PDAs), tablets, laptops, wearable computing devices, etc. Processor modules 214 and 236 may be implemented or realized by a general-purpose processor, content-addressable memory, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array, any suitable programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof to perform the functions described herein. In this way, the processor may be implemented as a microprocessor, a controller, a microcontroller, a state machine, or a similar device. The processor may also be implemented as a combination of computing devices, such as a combination of a digital signal processor and a microprocessor, multiple microprocessors, one or more microprocessors combined with a digital signal processor core, or any other such configuration.
[0030] Furthermore, the steps of the methods or algorithms related to the embodiments disclosed herein can be implemented directly in hardware, in firmware, in software modules executed by processor modules 214 and 236 respectively, or in any practical combination thereof. Memory modules 216 and 234 can be implemented as RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art. In this regard, memory modules 216 and 234 can be coupled to processor modules 210 and 230 respectively, such that processor modules 210 and 230 can read information from and write information to memory modules 216 and 234 respectively. Memory modules 216 and 234 can also be integrated into their respective processor modules 210 and 230. In some embodiments, each of memory modules 216 and 234 can include a cache memory for storing temporary variables or other intermediate information during the execution of instructions by processor modules 210 and 230 respectively. Memory modules 216 and 234 may also include non-volatile memory for storing instructions to be executed by processor modules 210 and 230, respectively.
[0031] Network communication module 218 typically represents the hardware, software, firmware, processing logic, and / or other components of base station 202 that enable base transceiver 210 to communicate bidirectionally with other network components and communication nodes configured to communicate with base station 202. For example, network communication module 218 may be configured to support Internet or WiMAX traffic. In a typical deployment, network communication module 218 is unrestricted in that it provides an 802.3 Ethernet interface, enabling base transceiver 210 to communicate with a traditional Ethernet-based computer network. In this way, network communication module 218 may include a physical interface for connecting to a computer network (e.g., a mobile switching center (MSC)). The terms “configured to,” “configured to,” and variations thereof, when used herein in relation to a specified operation or function, refer to a device, component, circuit, structure, machine, signal, etc., that is physically constructed, programmed, formatted, and / or arranged to perform the specified operation or function.
[0032] This invention relates to methods and systems for processing User Equipment (UE) parameters in wireless communication networks, particularly in the event of authentication rejection. In various wireless communication standards, including emerging 6G technologies, managing UE parameters after receiving an authentication rejection message from the network plays a crucial role in maintaining network security and efficiency. This invention addresses challenges related to UE behavior upon receiving an authentication rejection message, including the processing of stored network lists, attempt counters, and other relevant parameters. The techniques described herein can enhance the robustness of wireless communication systems in response to authentication failures by providing improved UE parameter management methods.
[0033] In some cases, a wireless communication device may receive a response to a registration request from a wireless communication node. The wireless communication device can be... Figure 2 The user equipment (UE) 204 shown in the diagram represents the wireless communication node, while the base station (BS) 202 can represent it. A response indicating a registration rejection request can be sent by the BS 202 and received by the UE 204 via communication channel 250.
[0034] Upon receiving a rejection response, the wireless communication device can remove the wireless communication node from the network list. This operation can be performed jointly by the UE processor module 236 and the UE memory module 234. The network list may include a list of Public Land Mobile Networks (PLMNs) or a list of Independent Non-Public Networks (SNPNs), which can be stored in the UE memory module 234.
[0035] In some cases, the wireless communication device may reset various counters after receiving a rejection response. These counters may include registration attempt counters, attach attempt counters, service attempt counters, and tracking area update (TAU) attempt counters. The reset of these counters may be performed by the UE processor module 236, and the updated values may be stored in the UE memory module 234.
[0036] Figure 2 The wireless communication node represented by BS202 can send a response indicating a rejection of the registration request. This transmission can be performed by the BS transceiver module 210 via the BS antenna 212. The BS processor module 214 can generate a rejection response based on authentication failure or other criteria stored in the BS memory module 216.
[0037] In some cases, a wireless communication node can be configured to have its network list removed by the wireless communication device upon receiving a rejection response. This configuration can be implemented in the BS processor module 214 and may involve sending specific information in the rejection response instructing the wireless communication device to remove the network from the network list.
[0038] Wireless communication devices and wireless communication nodes can communicate through a wireless communication channel, which is in Figure 2 The communication channel 250 represents this. This channel can utilize various wireless communication protocols, which can be implemented by the corresponding transceiver modules of the device (UE transceiver module 230 and BS transceiver module 210).
[0039] In some cases, a wireless communication device may receive a response to a registration request from a wireless communication node. The wireless communication device can be a user equipment (UE) device, such as... Figure 2 The UE 204 message shown in the image indicates that the registration request was rejected.
[0040] Upon receiving a rejection response, the wireless communication device can remove the wireless communication node from the network list. The network list may include a Public Land Mobile Network (PLMN) list or a Standalone Non-Public Network (SNPN) list. This removal operation can be performed jointly by the UE processor module 236 and the UE memory module 234.
[0041] In some cases, wireless communication devices may set the update status to a specific value, such as 5U3 ROAMING NOT ALLOWED, after receiving a rejection response. Wireless communication devices can also delete stored parameters, which may include the 5G Globally Unique Temporary Identifier (5G-GUTI), a list of Tracking Area Identifiers (TAIs), the last accessed registration TAI, and the Next Generation Key Set Identifier (ngKSI).
[0042] Wireless communication devices can reset various counters upon receiving a rejection response. These counters may include:
[0043] 1. Register an attempt counter
[0044] 2. Attachment attempt counter
[0045] 3. Service Attempt Counter
[0046] 4. Tracking Region Update (TAU) Attempt Counter
[0047] The reset of these counters can be performed by the UE processor module 236, and the updated values can be stored in the UE memory module 234.
[0048] In some cases, when a denial response is received in the context of the PLMN, the Universal Subscriber Identity Module (USIM) of the wireless communication device may be considered invalid. The USIM may remain in this invalid state until the wireless communication device is turned off or the Universal Integrated Circuit Card (UICC) containing the USIM is removed from the wireless communication device.
[0049] The aforementioned wireless communication methods can enhance the security and efficiency of wireless communication systems by providing a structured approach to handling authentication rejections. By deleting network entries, resetting counters, and managing USIM validity, wireless communication devices can maintain a more accurate and up-to-date state, potentially improving subsequent connection attempts and overall network performance.
[0050] In some cases, a device for wireless communication may be provided. This device may include, for example, a device similar to... Figure 2 The components of user equipment (UE) 204 shown are illustrated. This device may include a transceiver configured to communicate wirelessly with a network and a processor coupled to the transceiver.
[0051] The transceiver of this device can be similar to... Figure 2 The UE transceiver module 230 is shown in the image. The transceiver can be configured to wirelessly communicate with a network via a communication channel, which can be similar to... Figure 2 Communication channel 250 is depicted in the image.
[0052] The device's processor can be similar to Figure 2 The UE processor module 236 is shown in the image. The processor can be coupled to the transceiver and configured to perform various operations.
[0053] In some cases, the processor can be configured to receive a response to a registration request from the network. The response may indicate a rejection of the registration request. This operation can be performed in conjunction with a transceiver that receives the response via a wireless communication channel.
[0054] Upon receiving a response indicating rejection, the processor can be configured to remove the network to which the network belongs from the network list. The network list can include a list of Public Land Mobile Networks (PLMNs) or a list of Independent Non-Public Networks (SNPNs). The network list can be stored in the device's memory module, which can be similar to... Figure 2 The UE memory module 234 is shown in the image.
[0055] In some cases, the processor can be configured to reset various counters upon receiving a rejection response. These counters may include:
[0056] 1. Register an attempt counter
[0057] 2. Attachment attempt counter
[0058] 3. Service Attempt Counter
[0059] 4. Tracking Region Update (TAU) Attempt Counter
[0060] The processor can reset these counters by setting their values to a predetermined initial value (e.g., zero). The updated counter values can be stored in the device's storage module. Resetting the registration attempt counter can be particularly useful in the event of multiple failed registration attempts. By resetting this counter, the device can initiate a new series of registration attempts without being limited by previous failures. Resetting the attach attempt counter can be beneficial when the device is unable to attach to the network. This reset may allow the device to make new attach attempts, possibly with different parameters or on a different network. The service attempt counter can be reset to allow the device to initiate new service requests without being limited by previous unsuccessful attempts. This can be particularly useful when switching between different types of services or attempting to access a service after a period of inactivity. Resetting the Tracking Area Update (TAU) attempt counter can enable the device to perform a new TAU procedure, which is important for maintaining the device's location information within the network. By configuring the processor to perform these operations, the device can maintain a more accurate and up-to-date state, potentially improving subsequent connection attempts and overall network performance. The device may be able to adapt more effectively to changing network conditions and recover more quickly from authentication failures or other issues that could lead to registration request rejections. In some cases, wireless communication methods can be performed by wireless communication nodes, such as... Figure 2The base station (BS) 202 is shown in the diagram. The method may include the BS 202 sending a response to a registration request to a wireless communication device. This response may indicate that the registration request has been rejected. The BS 202 may send the response via the BS antenna 212 using the BS transceiver module 210. The BS processor module 214 may generate a rejection response based on authentication failure or other criteria stored in the BS storage module 216. The response may be transmitted to the wireless communication device via communication channel 250. In some cases, the network list to which the BS 202 belongs may be configured to be deleted by the wireless communication device upon receiving a rejection response. This configuration may be implemented in the BS processor module 214 and may involve sending specific information in the rejection response instructing the wireless communication device to delete the network list. The network list may include a Public Land Mobile Network (PLMN) list or a Standalone Non-Public Network (SNPN) list. Deleting this list by the wireless communication device helps ensure that outdated or invalid network information is not retained after authentication rejection. In some cases, the wireless communication device may be configured to reset various counters upon receiving a rejection response from the BS 202. These counters may include a registration attempt counter, an attachment attempt counter, a service attempt counter, and a Tracking Area Update (TAU) attempt counter. Resetting these counters allows wireless communication devices to attempt new registrations, attachments, service requests, and tracking area updates without being limited by previous failures. The BS202 can initiate different procedures based on the identity type used by the wireless communication device in the initial NAS message. If a 5G-GUTI (5G Globally Unique Temporary Identifier) is used, the BS202 can initiate an identification procedure to retrieve a SUCI (Subscription Hidden Identifier) from the wireless communication device. After retrieving the SUCI, the BS202 can use the received SUCI to restart the primary authentication and key negotiation procedure based on 5G AKA (Authentication and Key Negotiation). If the SUCI was used for identification in the initial NAS message or in the restarted primary authentication and key negotiation procedure based on 5G AKA, the BS202 can send an authentication rejection message to the wireless communication device. The BS202 can also send this message if the network decides not to initiate the identification procedure after the primary authentication and key negotiation procedure based on 5G AKA fails. When sending the authentication rejection message, the BS202 can maintain the wireless communication device's 5GMM (5G Mobility Management Context) and 5GNAS (Non-Access Stratum) security context unchanged. This preservation of context allows for potential future recovery or analysis of authentication failures. The methods implemented by BS202 can enhance the security and efficiency of wireless communication systems by providing a structured approach to handling authentication denials. By instructing wireless communication devices to remove devices from the network list and reset counters, BS202 can help maintain a more accurate and up-to-date state of devices in the network, potentially improving subsequent connection attempts and overall network performance.In some cases, devices for wireless communication may be provided. These devices may include, for example, those used for wireless communication. Figure 2 The components of the base station (BS) 202 shown are illustrated. The device may include a transceiver configured to wirelessly communicate with a network and a processor coupled to the transceiver. The transceiver of the device may be similar to... Figure 2 The BS transceiver module 210 shown is configured to communicate wirelessly with a network via a communication channel, which can be similar to... Figure 2 The communication channel 250 is shown. The device's processor can be similar to... Figure 2 The BS processor module 214 shown is illustrated. The processor can be coupled to a transceiver and configured to perform various operations. In some cases, the processor can be configured to send a response to a registration request to a wireless communication device. This response can indicate that the registration request has been rejected. This operation can be performed in conjunction with a transceiver that can send the response via a wireless communication channel. The device can be configured to have its network list removed by the wireless communication device when the wireless communication device receives a rejection response. This configuration can be implemented in the processor and may involve sending specific information in the rejection response instructing the wireless communication device to remove the network list. The network list can include a list of Public Land Mobile Networks (PLMNs) or a list of Independent Non-Public Networks (SNPNs). Removing this list by the wireless communication device helps ensure that outdated or invalid network information is not retained after authentication rejection.
[0061] In some cases, wireless communication devices may be configured to reset various counters upon receiving a rejection response from the device. These counters may include registration attempt counters, attach attempt counters, service attempt counters, and tracking area update (TAU) attempt counters. Resetting these counters may allow the wireless communication device to make new attempts at registration, attach, service request, and TAU without being limited by previous failures.
[0062] The device may initiate different procedures depending on the identity type used by the wireless communication device in the initial NAS message. If a 5G-GUTI (5G Globally Unique Temporary Identifier) is used, the device may initiate an identification procedure to retrieve a SUCI (Subscription Concealed Identifier) from the wireless communication device. After retrieving the SUCI, the device may use the received SUCI to restart the primary authentication and key negotiation procedure based on 5G AKA (Authentication and Key Agreement).
[0063] If SUCI was used for identification in the initial NAS message or in a restarted 5G AKA-based primary authentication and key negotiation procedure, the device may send an authentication rejection message to the wireless communication device. The device may also send this message if the network decides not to initiate the identification procedure after an unsuccessful 5G AKA-based primary authentication and key negotiation procedure.
[0064] When sending an authentication rejection message, the device may preserve the 5G MM (5G Mobility Management) context and 5G NAS (Non-Access Stratum) security context of the wireless communication device. This preservation of context may allow for potential future recovery or analysis of authentication failures.
[0065] Devices can enhance the security and efficiency of wireless communication systems by providing a structured approach to handling authentication denials. By instructing wireless communication devices to remove devices from the network list and reset counters, devices can help maintain a more accurate and up-to-date state of devices within the network, potentially improving subsequent connection attempts and overall network performance.
[0066] In some cases, User Equipment (UE) 204 may perform actions such as Figure 3 The wireless communication method 300 is shown. Method 300 may begin at step 302, where UE 204 receives an authentication rejection message initiated as part of a procedure. This authentication rejection message may be sent by a wireless communication node (e.g., base station 202) and received by UE transceiver module 230 via communication channel 250. This procedure may be a registration procedure, an attachment procedure, or a Tracking Area Update (TAU) procedure.
[0067] Upon receiving an authentication rejection message, method 300 may proceed to decision 304, whereby the UE processor module 236 may determine or identify whether the received message is an authentication rejection message. This determination may involve analyzing the content of the received message to identify a specific authentication rejection indicator or code.
[0068] If the message is determined to be an authentication rejection message (the Yes branch of decision 304), method 300 may proceed to step 306. In step 306, UE processor module 236 may remove the network list to which the wireless communication node belongs. This network list may be stored in UE memory module 234 and may include a list of Public Land Mobile Networks (PLMNs) or an equivalent list of Independent Non-Public Networks (SNPNs). Removing this list may help ensure that UE 204 does not retain outdated or invalid network information after authentication rejection.
[0069] After deleting the network from the list, method 300 may continue to perform multiple counter reset operations, such as... Figure 3 Steps 308A, 308B, 308C, and 308D are shown in the diagram. In step 308A, UE processor module 236 may reset the registration attempt counter. This reset may allow UE 204 to initiate a new series of registration attempts without being limited by previous failures. In step 308B, UE processor module 236 may reset the attach attempt counter. This reset may enable UE 204 to make new attach attempts, possibly using different parameters or on a different network. Step 308C may involve UE processor module 236 resetting the service attempt counter. This reset may allow UE 204 to make new service requests without being limited by previous unsuccessful attempts. In step 308D, UE processor module 236 may reset the Tracking Area Update (TAU) attempt counter. This reset may enable UE 204 to execute a new TAU procedure, which may be important for maintaining the UE's location information in the network.
[0070] The UE processor module 236 may reset these counters by setting their values to a predetermined initial value (e.g., zero). The updated counter values may be stored in the UE memory module 234. After performing the counter reset operation, method 300 may end at step 310. The UE processor module 236 may then configure the UE transceiver module 230 to attempt new connections based on the reset counters and the updated network list status.
[0071] If the received message is determined not to be an authentication rejection message (the No branch of decision 304), method 300 may proceed directly to step 310, bypassing the network list deletion and counter reset operations. Then, UE processor module 236 may instruct UE transceiver module 230 to continue normal operation based on the type of the received message.
[0072] By implementing method 300, UE 204 may maintain a more accurate and up-to-date state, potentially improving subsequent connection attempts and overall network performance. UE 204 may be able to adapt more effectively to changing network conditions and recover more quickly from authentication failures or other issues that could lead to registration request rejection.
[0073] In some cases, base station (BS) 202 may perform actions such as Figure 4 The wireless communication method 400 is shown. Method 400 may begin at step 402, where BS 202 sends an authentication rejection message to the wireless communication device as part of a procedure. This authentication rejection message may be generated by BS processor module 214 and sent by BS transceiver module 210 via communication channel 250. This procedure may be a registration procedure, an attachment procedure, or a Tracking Area Update (TAU) procedure.
[0074] The base station processor module 214 can generate an authentication rejection message based on various factors, such as authentication attempt failure, security issues, or network policies. The processor module can also determine the specific content of the rejection message, including any instructions or code that may trigger action on the receiving wireless communication device. Once the authentication rejection message is generated, the base station processor module 214 can instruct the base station transceiver module 210 to send the message. The base station transceiver module 210 can then encode the message, modulate it onto a carrier signal, and transmit it through the communication channel 250 via the base station antenna 212.
[0075] After sending the authentication rejection message, method 400 may end at step 404. At this time, the base station processor module 214 may update the internal records or context related to the authentication attempt and prepare for subsequent communication attempts from the same or other wireless communication devices.
[0076] In some implementations, the base station processor module 214 may be configured to include specific information in the authentication rejection message, instructing the receiving wireless communication device to remove the network list to which the base station 202 belongs. This network list may include a list of Public Land Mobile Networks (PLMNs) or an equivalent list of Independent Non-Public Networks (SNPNs).
[0077] The base station processor module 214 can also be configured to include information in the authentication rejection message prompting the receiving wireless communication device to reset various counters. These counters may include a registration attempt counter, an attach attempt counter, a service attempt counter, and a tracking area update (TAU) attempt counter.
[0078] In some cases, the wireless communication method performed by the wireless communication node may include the additional aspects described in claims 15-17: the procedure may be a registration procedure, an attachment procedure, or a Tracking Area Update (TAU) procedure. This makes the method applicable to a variety of scenarios requiring authentication. The network list to which the wireless communication node belongs may include a list of Public Land Mobile Networks (PLMNs) or an equivalent list of Independent Non-Public Networks (SNPNs). This specification of the network list type ensures the clarity of the information that the wireless communication device is expected to remove upon receiving an authentication rejection message.
[0079] In response to receiving an authentication rejection message, the wireless communication device can be configured to reset at least one of the following: registration attempt counter, attach attempt counter, service attempt counter, or tracking area update (TAU) attempt counter. Resetting these counters allows the wireless communication device to make new attempts in various procedures without being limited by previous failures.
[0080] By implementing these aspects, the wireless communication method performed by base station 202 can help maintain accurate and up-to-date network information on wireless communication devices, potentially improving the efficiency and reliability of the entire wireless communication system.
[0081] In some implementations, the rejection response transmitted in step 404 may contain specific information or code instructing the wireless communication device to perform additional operations. These operations may include resetting various counters, such as registration attempt counters, attach attempt counters, service attempt counters, or tracking area update (TAU) attempt counters. By prompting the reset of these counters, base station 202 enables the wireless communication device to make new attempts during registration, attach, service request, and tracking area update, without being limited by previous failures.
[0082] Method 400 can end at step 402, marking the end of the procedure. After the transmission rejection response, base station 202 can prepare to handle subsequent communication attempts from the same or other wireless communication devices. Base station processor module 214 can update the relevant context or parameters to reflect the completed rejection procedure.
[0083] By implementing method 400, base station 202 can enhance the efficiency and security of the wireless communication system. A structured approach to handling registration rejections and managing the network list on the wireless communication device helps maintain a more accurate representation of the network state. This can lead to improved subsequent connection attempts and overall network performance.
[0084] Method 400 can be adapted to various network configurations and protocols. In some cases, the specific action triggered by the rejection response can be customized based on the type of wireless communication device, the nature of the authentication failure, or the current network conditions. This flexibility allows base station 202 to optimize its response strategy to adapt to different scenarios, further enhancing the robustness of the wireless communication system.
[0085] While various embodiments of the invention have been described above, it should be understood that they are presented by way of example only and not by way of limitation. Similarly, various diagrams may depict an exemplary architecture or configuration provided to those skilled in the art to understand exemplary features and functions of the invention. However, those skilled in the art will understand that the invention is not limited to the exemplary architecture or configuration shown, but can be implemented using various alternative architectures and configurations. Furthermore, as will be understood by those skilled in the art, one or more features of one embodiment may be combined with one or more features of another embodiment described herein. Therefore, the breadth and scope of the invention should not be limited to the exemplary embodiments described above.
[0086] It should also be understood that the use of designations such as "first," "second," etc., to refer to elements in this document generally does not restrict the number or order of these elements. Rather, these designations can be used as a convenient means of distinguishing two or more elements or instances of elements in this document. Therefore, referring to the first and second elements does not mean that only two elements can be used, or that the first element must precede the second element in some way.
[0087] Furthermore, anyone with basic technical skills would understand that information and signals can be represented using a variety of different techniques and methods. For example, data, instructions, commands, information, signals, bits, and symbols can be represented, for instance, by voltage, current, electromagnetic waves, magnetic fields or particles, light fields or particles, or any combination thereof.
[0088] Those skilled in the art will also understand that any of the various exemplary logic blocks, modules, processors, devices, circuits, methods, and functions related to the various aspects disclosed herein can be implemented by electronic hardware (e.g., digital implementation, analog implementation, or a combination of both), firmware, various forms of program or design code containing instructions (which may be referred to herein as "software" or "software module"), or any combination of these technologies. To clearly illustrate this interchangeability of hardware, firmware, and software, the various exemplary components, blocks, modules, circuits, and steps described above are generally described in terms of their functionality. Whether such functionality is implemented as hardware, firmware, or software, or a combination of these technologies, depends on the specific application and design constraints imposed on the system as a whole. Those skilled in the art can implement the described functionality in various ways for each specific application, but such implementation decisions will not lead to a departure from the scope of the invention.
[0089] Furthermore, those skilled in the art will understand that the various exemplary logic blocks, modules, devices, components, and circuits described herein can be implemented in or executed by integrated circuits (ICs), which may include general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, or any combination thereof. Logic blocks, modules, and circuits may also include antennas and / or transceivers for communicating with various components within a network or device. A general-purpose processor may be a microprocessor, but alternatively, the processor may be any conventional processor, controller, or state machine. The processor may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors combined with a DSP core, or any other configuration suitable for performing the functions described herein.
[0090] If implemented in software, functionality can be stored as one or more instructions or code on a computer-readable medium. Therefore, the steps of the methods or algorithms disclosed herein can be implemented as software stored on a computer-readable medium. Computer-readable media include computer storage media and communication media, encompassing any medium capable of enabling the transfer of computer programs or code from one place to another. Storage media can be any available medium accessible to a computer. By way of example and not limitation, such computer-readable media can include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired program code in the form of instructions or data structures and is accessible to a computer.
[0091] In this document, the term "module" refers to software, firmware, hardware, and any combination of these elements used to perform the relevant functions described herein. Furthermore, for the purposes of discussion, various modules are described as discrete modules; however, as will be apparent to those skilled in the art, two or more modules can be combined to form a single module to perform the relevant functions according to embodiments of the invention.
[0092] Furthermore, memory or other storage, as well as communication components, may be used in embodiments of the invention. It will be understood that, for clarity, embodiments of the invention have been described above with reference to different functional units and processors. However, it will be apparent that any suitable allocation of functionality among different functional units, processing logic elements, or domains may be used without affecting the invention. For example, a function shown to be performed by a separate processing logic element or controller may be performed by the same processing logic element or controller. Therefore, references to specific functional units are merely references to suitable means of providing said functionality and not strict indications of logical or physical structure or organization.
[0093] Various modifications to the implementations described herein will be apparent to those skilled in the art, and the general principles defined herein can be applied to other implementations without departing from the scope of the invention. Therefore, the invention is not intended to be limited to the implementations shown herein, but rather to be interpreted in the broadest possible sense, consistent with the novel features and principles disclosed herein, as set forth in the following claims.
Claims
1. A wireless communication method, comprising: An authentication rejection message initiated as part of a procedure is received by a wireless communication device from a wireless communication node. as well as In response to receiving the authentication rejection message, the wireless communication device removes the wireless communication node from the network list to which it belongs.
2. The wireless communication method of claim 1, wherein the procedure is a registration procedure, an attachment procedure, or a tracking area update (TAU) procedure.
3. The wireless communication method of claim 1, wherein the network list includes a list of Public Land Mobile Networks (PLMNs) or an equivalent list of Independent Non-Public Networks (SNPNs).
4. The wireless communication method of claim 1, further comprising, in response to receiving the authentication rejection message: The wireless communication device resets a registration attempt counter.
5. The wireless communication method of claim 1, further comprising, in response to receiving the authentication rejection message: The wireless communication device resets an attach attempt counter.
6. The wireless communication method of claim 1, further comprising, in response to receiving the authentication rejection message: The wireless communication device resets a service attempt counter.
7. The wireless communication method of claim 1, further comprising, in response to receiving the authentication rejection message: The wireless communication device resets a Tracking Area Update (TAU) attempt counter.
8. An apparatus comprising: A transceiver configured to communicate wirelessly with a network; as well as A processor coupled to the transceiver is configured to perform the following operations: Receive an authentication rejection message initiated as part of a procedure from the network; as well as In response to receiving the authentication denial message, the network to which the network belongs is removed from the network list.
9. The device of claim 8, wherein the procedure is a registration procedure, an attachment procedure, or a tracking area update (TAU) procedure.
10. The device of claim 8, wherein the network list includes a list of Public Land Mobile Networks (PLMNs) or an equivalent list of Independent Non-Public Networks (SNPNs).
11. The device of claim 8, wherein the operation further comprises: Reset the registration attempt counter.
12. The device of claim 8, wherein the operation further comprises: Reset the attachment attempt counter.
13. The apparatus of claim 8, wherein the operation further comprises: Reset a service attempt counter.
14. The apparatus of claim 8, wherein the operation further comprises: Reset the Tracking Area Update (TAU) attempt counter.
15. A wireless communication method, comprising: An authentication rejection message is sent by a wireless communication node to a wireless communication device as part of a procedure. The network list to which the wireless communication node belongs is configured to be removed by the wireless communication device in response to the wireless communication device receiving the authentication rejection message.
16. The wireless communication method of claim 15, wherein the procedure is a registration procedure, an attachment procedure, or a tracking area update (TAU) procedure.
17. The wireless communication method of claim 15, wherein the network list includes a list of Public Land Mobile Networks (PLMNs) or an equivalent list of Independent Non-Public Networks (SNPNs).
18. The wireless communication method as described in claim 15, wherein, In response to receiving the authentication rejection message, the wireless communication device is configured to reset at least one of the following: registration attempt counter, attachment attempt counter, service attempt counter, or tracking area update (TAU) attempt counter.
19. An apparatus comprising: A transceiver configured to communicate wirelessly with a network; as well as A processor coupled to the transceiver is configured to perform the following operations: An authentication rejection message is sent to the wireless communication device as part of the procedure, wherein a network list to which the device belongs is configured to be removed by the wireless communication device in response to the wireless communication device receiving the authentication rejection message.
20. The device of claim 19, wherein the network list includes a list of Public Land Mobile Networks (PLMNs) or an equivalent list of Standalone Non-Public Networks (SNPNs).
21. The apparatus of claim 19, wherein the program is a registration program, an attachment program, or a Tracking Area Update (TAU) program.