Techniques for processing prohibition lists for localized services
By adding independent, non-public networks to the blacklist on user equipment and updating it under specific conditions, the network instability and security risks during user equipment access are resolved, achieving more stable and secure network access management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- MEDIATEK SINGAPORE PTE LTD
- Filing Date
- 2024-09-04
- Publication Date
- 2026-04-17
AI Technical Summary
In the existing technology, user equipment lacks an effective mechanism to manage rejection messages without integrity protection when accessing independent non-public networks, which leads to network access instability and increased security risks.
After receiving a rejection message without integrity protection, the user equipment adds an independent non-public network to the blacklist, starts a timer, and removes the network identity under specific conditions. The blacklist is updated by events such as timer expiration, device shutdown, SIM card removal, or data update.
It improves the stability and security of user equipment access management to independent non-public networks, reduces the risks caused by rejection messages without integrity protection, and enhances the reliability and security of network access.
Smart Images

Figure CN121890131A_ABST
Abstract
Description
[0001] Cross-referencing
[0002] This application declares priority by reference to Indian Patent Application No. 202321063102, entitled “F-LIST Processing Method for Localized Services”, filed on 20 September 2023, the entire contents of which are incorporated herein by reference. Technical Field
[0003] This disclosure generally relates to communication systems, and more specifically, to a technique for managing access to standalone non-public networks (SNPNs) used for localized services by updating a list of prohibited standalone non-public networks (SNPNs) in user equipment (UE) based on specific events and conditions. Background Technology
[0004] The statements in this section provide only background information in relation to this disclosure and may not constitute prior art.
[0005] Wireless communication systems are widely deployed to provide a variety of telecommunications services, such as telephone, video, data, messaging, and broadcasting. Typical wireless communication systems employ multiple access technologies, supporting communication with multiple users by sharing available system resources. Examples of such multiple access technologies include code division multiple access (CDMA) systems, time division multiple access (TDMA) systems, frequency division multiple access (FDMA) systems, orthogonal frequency division multiple access (OFDMA) systems, single-carrier frequency division multiple access (SC-FDMA) systems, and time division synchronous code division multiple access (TD-SCDMA) systems.
[0006] These multiple access technologies have been adopted in various telecommunications standards to provide a common protocol enabling different wireless devices to communicate at the municipal, national, regional, and even global levels. An example of a telecommunications standard is fifth-generation (5G) New Radio (NR). 5G NR is part of the ongoing evolution of mobile broadband driven by the Third Generation Partnership Project (3GPP) to meet new requirements related to latency, reliability, security, scalability (e.g., related to the Internet of Things (IoT),) and other needs. Some aspects of 5G NR may be based on the fourth-generation (4G) Long Term Evolution (LTE) standard. Further improvements to 5G NR technology are still needed. These improvements may also apply to other multiple access technologies and the telecommunications standards that adopt them. Summary of the Invention
[0007] The following is a simplified summary of one or more aspects to provide a basic understanding of them. This content is not a comprehensive overview of all hypothetical aspects, nor is it intended to identify key or essential elements of all aspects, nor to define the scope of any or all aspects. Its sole purpose is to present certain concepts of one or more aspects in a simplified form as a prelude to a more detailed description thereafter.
[0008] In one aspect of this disclosure, a method, a computer-readable medium, and an apparatus are provided. The apparatus may be a user equipment. The user equipment receives a denial message without integrity protection from an independent non-public network. The user equipment adds the identity of the independent non-public network to a prohibited list for accessing localized services. The user equipment starts a timer. The user equipment increments an independent non-public network-specific attempt counter. When the value of the independent non-public network-specific attempt counter is greater than zero and less than a specific maximum value achieved by the user equipment, the user equipment removes the identity of the independent non-public network from the prohibited list. The user equipment performs the removal operation in response to at least one of the following: the timer expires, the user equipment is shut down, a general-purpose integrated circuit card containing a general user identity module is removed, or an entry in the user data list is updated.
[0009] To achieve the foregoing and related objectives, one or more aspects include the features fully described below and specifically pointed out in the claims. The following description and accompanying drawings illustrate certain exemplary features of one or more aspects in detail. However, these features only indicate a portion of the various aspects' principles that may be employed, and this description is intended to encompass all such aspects and their equivalents. Attached Figure Description
[0010] Figure 1 This is a schematic diagram illustrating an example wireless communication system and access network.
[0011] Figure 2 This is a schematic diagram illustrating communication between a base station and user equipment in an access network.
[0012] Figure 3 This example illustrates the logical architecture of a distributed access network.
[0013] Figure 4 This is an example of the physical architecture of a distributed access network.
[0014] Figure 5 This is a schematic diagram illustrating a downlink-centric timeslot.
[0015] Figure 6 This is a schematic diagram centered on the uplink.
[0016] Figure 7 This is a schematic diagram of a wireless communication system.
[0017] Figure 8 This is a sequence diagram showing the operations of user equipment and independent non-public networks (ISNs) for localized services, specifically the list of prohibited ISNs.
[0018] Figure 9 The flowchart illustrates the method (process) for managing access to localized services from independent non-public networks by updating the list of prohibited independent non-public networks based on specific events and conditions. Detailed Implementation
[0019] The detailed description below, taken in conjunction with the accompanying drawings, is intended to describe various configurations and is not intended to represent the only configuration in which the concepts described herein can be implemented. The detailed description includes specific details to provide a thorough understanding of the various concepts. However, those skilled in the art will understand that these concepts can be implemented without these specific details. In some cases, to avoid obscuring these concepts, known structures and components are shown in block diagram form.
[0020] Several aspects of telecommunications systems will now be introduced in conjunction with various apparatuses and methods. These apparatuses and methods will be described in detail below and illustrated with accompanying drawings as various modules, components, circuits, processes, algorithms, etc. (collectively referred to as "elements"). These elements can be implemented by electronic hardware, computer software, or any combination thereof. Whether an element is implemented in hardware or software depends on the specific application and design constraints imposed on the overall system.
[0021] For example, a single element, any part of an element, or any combination of elements can be implemented as a "processing system" comprising one or more processors. Examples of processors include microprocessors, microcontrollers, graphics processing units (GPUs), central processing units (CPUs), application processors, digital signal processors (DSPs), reduced instruction set computing (RISC) processors, systems on a chip (SoC), baseband processors, field-programmable gate arrays (FPGAs), programmable logic devices (PLDs), state machines, gated logic, discrete hardware circuits, and other suitable hardware configured to perform the various functions described in this disclosure. One or more processors in the processing system can execute software. Software should be broadly understood as instructions, instruction sets, code, code segments, program code, programs, subroutines, software components, applications, software applications, software packages, routines, subroutines, objects, executable files, execution threads, procedures, functions, etc., regardless of whether it is called software, firmware, middleware, microcode, hardware description language, or other names.
[0022] Therefore, in one or more example aspects, the functionality can be implemented by hardware, software, or any combination thereof. If implemented by software, these functions can be stored or encoded as one or more instructions or code stored on a computer-readable medium. Computer-readable media include computer storage media. Storage media can be any existing medium accessible to a computer. For example, but not limited to, such computer-readable media can include random-access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), optical disc storage, magnetic disk storage, other magnetic storage devices, combinations of the above types of computer-readable media, or any medium that can be used to store computer-executable code in the form of instructions or data structures and is accessible to a computer.
[0023] Figure 1This illustration shows an example of a wireless communication system and access network 100. The wireless communication system (also known as a wireless wide area network (WWAN)) includes base station 102, user equipment 104, an evolved packet core (EPC) 160, and another core network 190 (e.g., a 5G core (5GC)). Base station 102 may include macro cells (high-power cellular base stations) and / or small cells (low-power cellular base stations). Macro cells include base stations. Small cells include femtocells, picocells, and microcells.
[0024] Base station 102 configured as 4G LTE (collectively referred to as Evolved Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access Network (E-UTRAN)) can interface with EPC 160 via backhaul link 132 (e.g., SI interface). Base station 102 configured as 5G NR (collectively referred to as Next Generation RAN (NG-RAN)) can interface with core network 190 via backhaul link 184. In addition to other functions, base station 102 may perform one or more of the following functions: user data transmission, radio channel encryption and decryption, integrity protection, header compression, mobility control functions (e.g., handover, dual connectivity), inter-cell interference coordination, connection establishment and release, load balancing, non-access stratum (NAS) message distribution, NAS node selection, synchronization, radio access network (RAN) sharing, multimedia broadcast multicast service (MBMS), user and device tracking, RAN information management (RIM), paging, location, and warning message delivery. Base station 102 may communicate with each other directly or indirectly (e.g., via EPC 160 or core network 190) via backhaul link 134 (e.g., X2 interface). Backhaul link 134 may be wired or wireless.
[0025] Base station 102 can wirelessly communicate with user equipment 104. Each base station 102 can provide communication coverage for a corresponding geographic coverage area 110. Overlapping geographic coverage areas 110 may exist. For example, small cell 102' may have geographic coverage area 110' that overlaps with the geographic coverage areas 110 of one or more macro base stations 102. A network containing small cells and macro cells may be referred to as a heterogeneous network. Heterogeneous networks may also include Home Evolved Node Bs (HeNBs) that can provide services to a restricted group called a closed subscriber group (CSG). The communication link 120 between base station 102 and user equipment 104 may include an uplink (UL, also known as a reverse link) transmission from user equipment 104 to base station 102 and / or a downlink (DL, also known as a forward link) transmission from base station 102 to user equipment 104. Communication link 120 may employ multiple-input multiple-output (MIMO) antenna technology, including spatial multiplexing, beamforming, and / or transmit diversity. The communication link may be implemented using one or more carriers. Base station 102 / user equipment 104 may use a spectrum with a bandwidth of up to 7 MHz (e.g., 5, 10, 15, 20, 100, 400 MHz, etc.) per carrier, allocating a total of Yx MHz (x component carriers) for transmission in carrier aggregation in each direction. Carriers may be adjacent or non-adjacent. Carrier allocation may be asymmetrical in the DL and UL directions (e.g., more or fewer carriers allocated to DL than UL). Component carriers may include primary component carriers and one or more secondary component carriers. Primary component carriers may be referred to as primary cells (PCells), and secondary component carriers may be referred to as secondary cells (SCells).
[0026] Some user equipment 104 can communicate with each other via device-to-device (D2D) communication link 158. D2D communication link 158 can use DL / UL wireless wide area network spectrum. D2D communication link 158 can use one or more sidelink channels, such as physical sidelink broadcast channel (PSBCH), physical sidelink discovery channel (PSDCH), physical sidelink shared channel (PSSCH), and physical sidelink control channel (PSCCH). D2D communication can be implemented through various wireless D2D communication systems, such as FlashLinQ, WiMedia, Bluetooth, ZigBee, Wi-Fi based on the IEEE 802.11 standard, LTE, or NR.
[0027] The wireless communication system may also include a Wi-Fi access point (AP) 150 that communicates with Wi-Fi stations (STAs) 152 via a communication link 154 in the 5 GHz unlicensed spectrum. During unlicensed spectrum communication, STAs 152 / AP 150 may perform a clear channel assessment (CCA) before communication to determine channel availability.
[0028] Small cell 102' can operate in licensed and / or unlicensed spectrum. When operating in unlicensed spectrum, small cell 102' can employ NR and use the same 5 GHz unlicensed spectrum as Wi-Fi AP 150. Employing NR in unlicensed spectrum can enhance the coverage and / or increase the capacity of the access network.
[0029] Base station 102, whether a small cell 102' or a large cell (e.g., a macro base station), can include an eNB, gNodeB (gNB), or other types of base stations. Some base stations, such as gNB 180, can communicate with user equipment (UE) 104 in conventional sub-6 GHz bands, millimeter wave (mmW) frequencies, and / or near-millimeter wave frequencies. When gNB 180 operates at millimeter wave or near-millimeter wave frequencies, gNB 180 can be referred to as a millimeter wave base station. Extremely high frequency (EHF) is a radio frequency component of the electromagnetic spectrum. EHF ranges from 30 GHz to 300 GHz, with wavelengths between 1 mm and 10 mm. Radio waves in this band can be referred to as millimeter waves. Near-millimeter waves can extend down to 3 GHz with wavelengths of 100 mm. The super high frequency (SHF) band ranges from 3 GHz to 30 GHz and is also known as centimeter waves. Communication using millimeter-wave / near-millimeter-wave radio frequency bands (e.g., 3 GHz to 300 GHz) suffers from extremely high path loss and short range. Millimeter-wave base station 180 can use beamforming 182 to communicate with UE 104 to compensate for the extremely high path loss and short range.
[0030] Base station 180 can transmit beamforming signals to UE 104 in one or more transmit directions 108a. UE 104 can receive beamforming signals from base station 180 in one or more receive directions 108b. UE 104 can also transmit beamforming signals to base station 180 in one or more transmit directions. Base station 180 can receive beamforming signals from UE 104 in one or more receive directions. Base station 180 / UE 104 can perform beamforming training to determine the optimal receive and transmit directions for each base station 180 / UE 104. The transmit and receive directions of base station 180 can be the same or different. The transmit and receive directions of UE 104 can be the same or different.
[0031] EPC 160 may include a Mobility Management Entity (MME) 162, other MMEs 164, a Serving Gateway 166, a Multimedia Broadcast Multicast Service (MBMS) Gateway 168, a Broadcast Multicast Service Center (BM-SC) 170, and a Packet Data Network (PDN) Gateway 172. MME 162 can communicate with the Home Subscriber Server (HSS) 174. MME 162 is the control node that handles signaling between UE 104 and EPC 160. Generally, MME 162 provides bearer and connection management. All user Internet Protocol (IP) packets are transmitted through Serving Gateway 166, which is itself connected to PDN Gateway 172. PDN Gateway 172 provides UE IP address allocation and other functions. PDN Gateway 172 and BM-SC 170 are connected to IP Service 176. IP service 176 may include the Internet, intranet, IP Multimedia Subsystem (IMS), Packet Switched Streaming Service (PS Streaming Service), and / or other IP services. BM-SC 170 can provide functions for configuring and delivering MBMS user services. BM-SC 170 can serve as an entry point for MBMS transmission by content providers, can be used to authorize and initiate MBMS bearer services in the Public Land Mobile Network (PLMN), and can be used to schedule MBMS transmissions. MBMS Gateway 168 can be used to distribute MBMS traffic to base stations 102 that belong to the Multicast Broadcast Single Frequency Network (MBSFN) area and broadcast specific services, and can be responsible for session management (start / stop) and collecting billing information related to enhanced MBMS (eMBMS).
[0032] The core network 190 may include an Access and Mobility Management Function (AMF) 192, other AMFs 193, a Location Management Function (LMF) 198, a Session Management Function (SMF) 194, and a User Plane Function (UPF) 195. The AMF 192 can communicate with the Unified Data Management (UDM) 196. The AMF 192 is the control node that handles signaling between the UE 104 and the core network 190. Generally, the SMF 194 provides QoS flow and session management. All user Internet Protocol (IP) packets are transmitted through the UPF 195. The UPF 195 provides UE IP address allocation and other functions. The UPF 195 connects to IP services 197. IP services 197 may include the Internet, intranets, IP Multimedia Subsystem (IMS), Packet Switched Streaming Service (PS Streaming Service), and / or other IP services.
[0033] A base station may also be referred to as a gNB, Node B, Evolved Node B (eNB), access point, base transceiver, wireless base station, wireless transceiver, transceiver function, basic service set (BSS), extended service set (ESS), transmit reception point (TRP), or other suitable terms. Base station 102 provides UE 104 with access to EPC 160 or core network 190. Examples of UE 104 include cellular phones, smartphones, session initiation protocol (SIP) phones, laptops, personal digital assistants (PDAs), satellite radios, GPS devices, multimedia devices, video devices, digital audio players (e.g., MP3 players), cameras, game consoles, tablets, smart devices, wearable devices, vehicles, electricity meters, gas pumps, large or small kitchen appliances, medical devices, implants, sensors / actuators, displays, or any other similarly functional devices. Some of these UE 104 devices may be referred to as Internet of Things (IoT) devices (e.g., parking meters, gas pumps, toasters, vehicles, heart monitors, etc.). UE 104 may also be referred to as a station, mobile station, user station, mobile unit, user unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile user station, access terminal, mobile terminal, wireless terminal, remote terminal, handheld device, user agent, mobile client, client, or other suitable terms.
[0034] Although this disclosure may relate to fifth-generation new radio (5G NR), it may also be applied to other similar fields, such as Long Term Evolution (LTE), LTE-Advanced (LTE-A), Code Division Multiple Access (CDMA), Global System for Mobile Communications (GSM) or other radio / RF access technologies.
[0035] Figure 2This is a block diagram illustrating communication between base station 210 and UE 250 in the access network. In the downlink (DL), IP packets from EPC 160 can be provided to controller / processor 275. Controller / processor 275 implements Layer 3 and Layer 2 functions. Layer 3 includes the radio resource control (RRC) layer, and Layer 2 includes the packet data convergence protocol (PDCP) layer, radio link control (RLC) layer, and medium access control (MAC) layer. Controller / processor 275 provides RRC layer functions related to system information (e.g., Master Information Block (MIB), System Information Block (SIB)) broadcasting, RRC connection control (e.g., RRC connection paging, RRC connection establishment, RRC connection modification, and RRC connection release), inter-radio access technology (RAT) mobility, and measurement configuration for UE measurement reports. The controller / processor 275 provides PDCP layer functions related to header compression / decompression, security (encryption, decryption, integrity protection, integrity verification), and handover support. The controller / processor 275 provides RLC layer functions related to upper-layer packet data units (PDUs) transmission, error correction via Automatic Repeat Request (ARQ), concatenation, segmentation, and reassembly of RLC service data units (SDUs), resegmentation of RLC data PDUs, and reordering of RLC data PDUs. The controller / processor 275 provides MAC layer functions related to mapping between logical channels and transport channels, multiplexing of MAC SDUs on transport blocks (TBs), demultiplexing of MAC SDUs from TBs, scheduling information reporting, error correction via Hybrid Automatic Repeat Request (HARQ), priority handling, and logical channel priority.
[0036] The transmit (TX) processor 216 and the receive (RX) processor 270 implement first-layer functions related to various signal processing functions. The first layer (including the physical layer (PHY)) may include error detection of the transport channel, forward error correction (FEC) encoding / decoding of the transport channel, interleaving, rate matching, mapping to the physical channel, modulation / demodulation of the physical channel, and multiple-input multiple-output (MIMO) antenna processing. The TX processor 216 processes the mapping to the signal constellation according to various modulation schemes (e.g., binary phase-shift keying (BPSK), quadrature phase-shift keying (QPSK), M-phase-shift keying (M-PSK), and M-quadrature amplitude modulation (M-QAM)). The encoded and modulated symbols can then be split into parallel streams. Each stream can then be mapped to an Orthogonal Frequency Division Multiplexing (OFDM) subcarrier, multiplexed with a reference signal (e.g., a pilot) in the time and / or frequency domains, and then combined via an Inverse Fast Fourier Transform (IFFT) to produce a physical channel carrying a time-domain OFDM symbol stream. The OFDM streams are spatially precoded to generate multiple spatial streams. Channel estimates from channel estimator 274 are used to determine coding and modulation schemes, as well as spatial processing. The channel estimates can be derived from the reference signal and / or channel state feedback transmitted by user equipment (UE) 250. Each spatial stream can then be provided to different antennas 220 via a separate transmitter (TX) 218. Each transmitter (TX) 218 can modulate a radio frequency (RF) carrier with the corresponding spatial stream for transmission.
[0037] At user equipment 250, each receiver (RX) 254 receives signals through its corresponding antenna 252. Each receiver (RX) 254 recovers the information modulated onto the RF carrier and provides this information to the receiver (RX) processor 256. The TX processor 268 and RX processor 256 implement the first-layer functions associated with various signal processing functions. The RX processor 256 can perform spatial processing on the information to recover any spatial stream facing user equipment 250. If there are multiple spatial streams facing user equipment 250, they can be merged by the RX processor 256 into a single OFDM symbol stream. The RX processor 256 then uses a Fast Fourier Transform (FFT) to transform the OFDM symbol stream from the time domain to the frequency domain. The frequency domain signal includes a separate OFDM symbol stream for each subcarrier of the OFDM signal. The symbols on each subcarrier, along with the reference signal, are recovered and demodulated by determining the most probable signal constellation point transmitted by base station 210. These soft decisions can be based on a channel estimate calculated by channel estimator 258. The soft decision is then decoded and deinterleaved to recover the data and control signals initially transmitted by base station 210 on the physical channel. The data and control signals are then provided to controller / processor 259, which implements Layer 3 and Layer 2 functions.
[0038] Controller / processor 259 may be associated with memory 260, which stores program code and data. Memory 260 may be referred to as computer-readable medium. In the uplink (UL), controller / processor 259 provides demultiplexing, packet reassembly, decryption, header decompression, and control signal processing between transport and logical channels to recover IP packets from EPC 160. Controller / processor 259 is also responsible for error detection using ACK and / or NACK protocols to support Hybrid Automatic Repeat reQuest (HARQ) operation.
[0039] Similar to the description of the downlink (DL) transmission function of base station 210, controller / processor 259 provides RRC layer functions related to system information (e.g., Master Information Block (MIB), System Information Blocks (SIBs)) acquisition, Radio Resource Control (RRC) connectivity, and measurement reporting. Controller / processor 259 provides Packet Data Convergence Protocol (PDCP) layer functions related to header compression / decompression and security (encryption, decryption, integrity protection, integrity verification). Controller / processor 259 provides Radio Link Control (RLC) layer functions related to upper-layer Packet Data Unit (PDU) transmission, error correction via Automatic Repeat Request (ARQ), RLC Service Data Unit (SDU) connectivity, segmentation and reassembly, RLC data PDU resegmentation, and RLC data PDU reordering. The controller / processor 259 provides mapping between logical channels and transport channels, multiplexing of MAC service data units (SDUs) to transport blocks (TBs), demultiplexing of MAC SDUs from TBs, scheduling information reporting, error correction via HARQ, priority handling, and media access control (MAC) layer functions related to logical channel priorities.
[0040] The channel estimate derived by channel estimator 258 based on a reference signal or feedback from base station 210 can be used by TX processor 268 to select appropriate coding and modulation schemes and facilitate spatial processing. The spatial stream generated by TX processor 268 can be provided to different antennas 252 via separate transmitters (TX) 254. Each transmitter (TX) 254 can modulate the radio frequency carrier with the corresponding spatial stream for transmission. Uplink transmission at base station 210 is processed similarly to the description of the user equipment 250 receiving function. Each receiver (RX) 218 receives the signal through its corresponding antenna 220. Each receiver (RX) 218 recovers the information modulated onto the radio frequency carrier and provides this information to RX processor 270.
[0041] Controller / processor 275 may be associated with memory 276, which stores program code and data. Memory 276 may be referred to as computer-readable medium. In the uplink, controller / processor 275 provides demultiplexing, packet reassembly, decryption, header decompression, and control signal processing between transport and logical channels to recover IP packets from user equipment 250. IP packets from controller / processor 275 may be provided to EPC 160. Controller / processor 275 is also responsible for error detection using acknowledgment and / or denial protocols to support hybrid automatic repeat request operation.
[0042] New Radio (NR) can refer to a radio configured to operate under a new air interface (e.g., an air interface other than OFDMA-based air interfaces) or a fixed transport layer (e.g., other than IP). NR can utilize OFDM with a cyclic prefix (CP) in both uplink and downlink, and may include support for half-duplex operation using Time Division Duplexing (TDD). NR may include Enhanced Mobile Broadband (eMBB) services targeting wide bandwidth (e.g., above 80 MHz), millimeter wave (mmW) services targeting high carrier frequencies (e.g., 60 GHz), massive machine-type communications (mMTC) services targeting non-backward-compatible MTC technologies, and / or mission-critical services targeting ultra-reliable low-latency communications (URLLC).
[0043] It supports a single component carrier bandwidth of 100 MHz. In one example, NR resource blocks (RBs) can span 12 subcarriers with a subcarrier bandwidth of 60 kHz for 0.25 milliseconds, or a bandwidth of 30 kHz for 0.5 milliseconds (similarly, a 15 kHz subcarrier spacing (SCS) provides a 50 MHz bandwidth over a 1 millisecond duration). Each radio frame can consist of 10 subframes (10, 20, 40, or 80 NR slots) with a length of 10 milliseconds. Each slot indicates the link direction of data transmission (i.e., downlink or uplink), and the link direction of each slot can be dynamically switched. Each slot can include downlink / uplink data and downlink / uplink control data. See below for information on NR uplink and downlink slots. Figure 5 and Figure 6 A detailed description.
[0044] The Radio Access Network (RAN) may include Central Units (CUs) and Distributed Units (DUs). An NR Base Station (BS, e.g., gNB, 5G Node B, Node B, Transmission Reception Point (TRP), Access Point (AP)) may correspond to one or more base stations. NR cells can be configured as Access Cells (ACells) or Data Only Cells (DCells). For example, the RAN (e.g., CUs or Distributed Units) can configure these cells. DCells can be used for carrier aggregation or dual connectivity and may not be used for initial access, cell selection / reselection, or handover. In some cases, DCells may not transmit synchronization signals (SS); in others, they may transmit synchronization signals. NR base stations can transmit downlink signals to user equipment (UEs) indicating the cell type. Based on the cell type indication, UEs can communicate with the NR base station. For example, user equipment can determine the NR base stations to be considered for cell selection, access, handover, and / or measurement based on the indicated cell type.
[0045] Figure 3 An example logical architecture of a distributed radio access network 300 is illustrated, according to relevant aspects of this disclosure. A 5G access node (5G AN) 306 may include an access node controller (ANC) 302. The ANC may be the central unit (CU) of the distributed radio access network. The backhaul interface to the next-generation core network (NG-CN) 304 may terminate at the ANC. The ANC may include one or more transport access points (TRPs) 308 (also referred to as base stations, NR base stations, Node B, 5G NB, access points, or other terms). As mentioned above, transport access points may be used interchangeably with "cells".
[0046] The transport access point 308 may be a distributed unit (DU). The transport access point may connect to one access node controller (ANC 302) or multiple access node controllers (not shown). For example, for radio access network sharing, radio as a service (RaaS), and service-specific access node controller deployments, the transport access point may connect to multiple access node controllers. The transport access point may include one or more antenna ports. The transport access point may be configured to provide services to user equipment (UE) individually (e.g., dynamically selected) or jointly (e.g., jointly transmitted).
[0047] The local architecture of the distributed radio access network 300 can be used to illustrate the fronthaul definition. This architecture can be defined to support fronthaul solutions for different deployment types. For example, the architecture can be based on transport network capabilities (e.g., bandwidth, latency, and / or jitter). The architecture can share features and / or components with Long Term Evolution (LTE). Depending on the relevant aspects, the next-generation access node (NG-AN) 310 can support dual connectivity with New Radio (NR). The NG-AN can share a common fronthaul for both LTE and NR.
[0048] This architecture enables collaboration between and within the transport access points 308. For example, collaboration can be pre-defined within the transport access points and / or implemented across transport access points via the access node controller 302. Depending on the relevant parties, interfaces between transport access points may be unnecessary or nonexistent.
[0049] According to relevant sources, the architecture of the Distributed Radio Access Network 300 can have a dynamic configuration with logical function segmentation. Packet Data Convergence Protocol (PDCP), Radio Link Control (RLC), and Media Access Control (MAC) protocols can be adaptively placed in the access node controller or the transmission access point.
[0050] Figure 4An example physical architecture of a distributed radio access network 400 is illustrated, according to relevant aspects of this disclosure. A centralized core network unit (C-CU) 402 can host core network functions. The centralized core network unit can be deployed centrally. Functions of the centralized core network unit can be offloaded (e.g., to advanced wireless services (AWS)) to handle peak capacity. A centralized radio access network unit (C-RU) 404 can host one or more access node controller functions. Optionally, the centralized radio access network unit can host core network functions locally. The centralized radio access network unit can be deployed in a distributed manner. The centralized radio access network unit can be located closer to the network edge. A distributed unit (DU) 406 can host one or more transport access points. The distributed unit can be located at the network edge with radio frequency (RF) capabilities.
[0051] Figure 5 Figure 500 illustrates an example of a downlink (DL)-centric timeslot. A downlink-centric timeslot may include a control section 502. The control section 502 may exist in the initial or beginning portion of the downlink-centric timeslot. The control section 502 may include various scheduling and / or control information corresponding to different portions of the downlink-centric timeslot. In some configurations, the control section 502 may be a physical downlink control channel (PDCCH), such as... Figure 5 As shown. The downlink-centric time slot may also include a downlink data portion 504. The downlink data portion 504 may sometimes be referred to as the payload of the downlink-centric time slot. The downlink data portion 504 may include communication resources used for communicating downlink data from a scheduling entity (e.g., a user equipment or base station) to a subordinate entity (e.g., a user equipment). In some configurations, the downlink data portion 504 may be a physical downlink shared channel (PDSCH).
[0052] The downlink-centric time slot may also include a general uplink portion 506. The general uplink portion 506 may sometimes be referred to as an uplink burst, a general uplink burst, and / or other applicable terms. The general uplink portion 506 may include feedback information corresponding to the various portions of the downlink-centric time slot. For example, the general uplink portion 506 may include feedback information corresponding to the control portion 502. Non-limiting examples of feedback information may include acknowledgment (ACK) signals, denial (NACK) signals, hybrid automatic repeat request (HARQ) indicators, and / or other applicable types of information. The general uplink portion 506 may include additional or alternative information, such as information related to random access channel (RACH) procedures, scheduling requests (SRs), and other applicable types of information.
[0053] like Figure 5 As shown, the end of the downlink data portion 504 can be time-separated from the start of the general uplink portion 506. This time separation may sometimes be referred to as a gap, protection period, protection interval, and / or other applicable terms. This separation provides time for the switching from downlink communication (e.g., a receiving operation of a subordinate entity (e.g., a user equipment)) to uplink communication (e.g., a transmitting operation of a subordinate entity (e.g., a user equipment)). Those skilled in the art will understand that the above is merely one example of a downlink-centric timeslot, and alternative structures with similar characteristics may exist without departing from the relevant aspects described herein.
[0054] Figure 6 Figure 600 illustrates an example of an uplink (UL) centered timeslot. An uplink centered timeslot may include a control section 602. The control section 602 may be present in the initial or beginning portion of the uplink centered timeslot. Figure 6 The control section 602 in the above reference can be used as a reference. Figure 5 The control portion 502 is similar. The uplink-centric time slot may also include an uplink data portion 604. The uplink data portion 604 may sometimes be referred to as the payload of the uplink-centric time slot. The uplink data portion 604 may refer to the communication resources used for communicating uplink data from a subordinate entity (e.g., a user equipment) to a scheduling entity (e.g., a user equipment or a base station). In some configurations, the control portion 602 may be the Physical Downlink Control Channel (PDCCH).
[0055] like Figure 6As shown, the end of control section 602 can be time-separated from the start of uplink data section 604. This time separation may sometimes be referred to as a gap, protection period, protection interval, and / or other applicable terms. This separation provides time for the switching from downlink communication (e.g., a receive operation by a scheduling entity) to uplink communication (e.g., a transmit operation by a scheduling entity). Uplink-centric time slots may also include a general uplink section 606. Figure 6 The general uplink section 606 in the reference above can be used as a reference. Figure 5 The general uplink section 506 is similar. The general uplink section 606 may also include or replace channel quality indicators (CQI), sounding reference signals (SRSs), and other applicable types of information. Those skilled in the art will understand that the above is merely an example of an uplink-centric timeslot, and alternative structures with similar characteristics may exist without departing from the relevant aspects described herein.
[0056] In some cases, two or more dependent entities (e.g., user equipment) can communicate using sidechain signals. Practical applications of this type of sidechain communication can include public safety, proximity services, user equipment-to-network relay, vehicle-to-vehicle (V2V) communication, Internet of Everything (IoE) communication, Internet of Things (IoT) communication, mission-critical mesh networks, and / or other applicable applications. Generally, a sidechain signal can refer to a signal used for communication from one dependent entity (e.g., user equipment 1) to another dependent entity (e.g., user equipment 2) without relaying the communication through a scheduling entity (e.g., user equipment or base station), although the scheduling entity may be used for scheduling and / or control purposes. In some examples, sidechain signals can communicate using licensed spectrum (unlike wireless LANs that typically use unlicensed spectrum).
[0057] Figure 7 This is a diagram illustrating a wireless communication system 700. The wireless communication system 700 includes multiple independent non-public networks (SNPNs) and user equipment (UEs) capable of accessing the localized services provided by these independent non-public networks.
[0058] Wireless communication system 700 includes base station 702, which communicates with independent non-public network 710 and provides access to independent non-public network 710. Similarly, base station 712 communicates with independent non-public network 720 and provides access to independent non-public network 720. User equipment 704 can select to connect to the cell of base station 702 or the cell of base station 712 based on various factors, including the availability of localized services and the N1 mode capability status of the user equipment.
[0059] Standalone non-public networks 710 and 720 represent dedicated fifth-generation networks capable of providing localized services to user equipment 704. User equipment 704 supports access to standalone non-public networks providing localized services and operates in automatic standalone non-public network selection mode.
[0060] User equipment 704 supports access to standalone non-public networks that provide localized services associated with selected entries in a "User Data List" and / or selected public terrestrial mobile network subscriptions. This capability allows user equipment 704 to connect to dedicated fifth-generation networks, such as standalone non-public network 710 and standalone non-public network 720, via base stations 702 and 712, respectively.
[0061] The "User Data List" contains entries specifying user credentials and preferences for accessing various independent non-public networks. Each entry in the User Data List may include detailed information such as the independent non-public network identity, credentials, and access parameters. Selecting entries in the User Data List guides User Equipment 704 in determining which independent non-public networks it can access and under what conditions.
[0062] Public terrestrial mobile network subscriptions refer to subscription information stored on a Universal Integrated Circuit Card (UICC), including the Universal Subscriber Identity Module (USIM). This subscription data may also affect the ability of user equipment (UE) 704' to access independent, non-public networks, especially when the UE supports access using credential holder credentials.
[0063] In the wireless communication system 700, user equipment 704 maintains multiple lists and counters to manage its interactions with independent non-public networks (ISNs). These include a "temporarily banned ISN list," a "temporarily banned ISN list for accessing localized services within ISNs," a "permanently banned ISN list," and a "permanently banned ISN list for accessing localized services within ISNs." User equipment 704 also maintains ISN-specific attempt counters for both 3G Partner Program (GLP) access and non-GLP access.
[0064] When user equipment 704 receives a registration rejection message or service rejection message without integrity protection from base station 702 or 712, and the 5G Mobility Management (5GMM) reason value is #74 (temporary unauthorization for this independent non-public network) or #75 (permanent unauthorization for this independent non-public network), a specific procedure will be initiated. User equipment 704 stops the currently running timer (T3510 or T3517) and starts a new timer with a random value within a specified range. .
[0065] If the cause value is #74, User Equipment 704 updates its 5G system (5GS) status to 5U3 ROAMING NOT ALLOWED, removes certain parameters (5G-GUTI, last accessed registered TAI, TAI list, ngKSI, and equivalent independent non-public network list), resets the registration attempt counter, and adds the independent non-public network identity to the corresponding prohibited list based on whether the independent non-public network is a network selected for localized services.
[0066] User equipment 704 also increments a separate non-public network-specific attempt counter for the access type of the received message (3rd Generation Partner Program or non-3rd Generation Partner Program), provided that the counter is below a user equipment-specific maximum value. This allows user equipment 704 to attempt access to the separate non-public network multiple times before being completely blocked. If the rejection message passes integrity verification, the separate non-public network-specific attempt counter is set to its maximum value.
[0067] In the timer Upon expiration, user equipment 704 removes the independent non-public network identity from the banned list under certain conditions. These conditions include an independent non-public network-specific attempt counter value that is greater than zero and less than a user equipment-specific maximum value, and the independent non-public network identity existing in the relevant banned list.
[0068] This mechanism allows user device 704 to efficiently manage access to independent, non-public networks, preventing continuous attempts to access prohibited networks, while also providing user device 704 with an opportunity to retry access after a certain period of time or under specific conditions.
[0069] In this system, user equipment 704 interacts with independent non-public networks 710 and 720 via base stations 702 and 712, respectively. For integrity protection, during the secure mode command flow, the network (e.g., independent non-public network 710 or independent non-public network 720) transmits integrity and encryption algorithms to the user equipment. Subsequent messages exchanged between the network and the user equipment are protected against tampering.
[0070] When the network executes the security mode command procedure, any message received by user equipment 704 is considered to have integrity protection. Conversely, if the procedure is not executed, the message is considered to have no integrity protection. User equipment 704 takes different actions based on the integrity status of the message.
[0071] As described above, if user equipment 704 receives a registration rejection message or service rejection message without integrity protection, especially if the fifth-generation mobility management reason value is #74 (temporary unauthorized access to the independent non-public network) or #75 (permanent unauthorized access to the independent non-public network), a specific action will be triggered. User equipment 704 will stop any running timers, for example... or The timer is started with a random value within a predefined range. .
[0072] In the absence of integrity protection, User Equipment 704 increments a separate non-public network-specific attempt counter for the access type (3rd Generation Partner Program or non-3rd Generation Partner Program) upon receiving a rejection message, provided that the counter is below a specific maximum value for the User Equipment. This mechanism allows User Equipment 704 to attempt to access the separate non-public network a limited number of times before being blocked. However, if the rejection message undergoes integrity verification, the separate non-public network-specific attempt counter is directly set to the maximum value, indicating that further attempts are not permitted.
[0073] A problem arises when user equipment 704, under the first configuration, receives a registration rejection message or service rejection message without integrity protection from base station 702 or 712, with the reason being #74 (temporarily unauthorized for this independent non-public network) or #75 (permanently unauthorized for this independent non-public network). In this scenario, user equipment 704 adds the independent non-public network identity (e.g., independent non-public network 710 or 720) to either the "List of Temporarily Prohibited Independent Non-Public Networks for Accessing Localized Services" or the "List of Permanently Prohibited Independent Non-Public Networks for Accessing Localized Services," depending on the reason value.
[0074] In the first configuration, user equipment 704 starts a timer. It also adds a separate, non-public network-specific attempt counter for third-generation partner program access. However, user equipment 704 has a timer... The handling of these blocked lists upon expiration is undefined. This omission is problematic for localized services because it could unnecessarily prevent user devices from accessing these services with a 704 error, even if the timer expires.
[0075] For example, User Equipment 704 resides on a standalone non-public network (such as standalone non-public network 1) to obtain localized services. If the initial registration is rejected with a fifth-generation mobility management reason value #74 (temporarily unauthorized for the standalone non-public network), and the message lacks integrity protection, then User Equipment 704 adds the standalone non-public network identity to the "List of Standalone Non-Public Networks Temporarily Prohibited for Access to Localized Services." Subsequently, User Equipment 704 starts a timer. And increment the independent, non-public network-specific attempt counter used for third-generation partner program access by 1. Upon expiration, user equipment 704 may or may not remove the independent non-public network identity from the "Temporary List of Prohibited Independent Non-Public Networks for Accessing Localized Services in Independent Non-Public Networks".
[0076] In the second configuration, when the specific attempt counter for independent non-public networks used for access under the 3rd Generation Partner Program (and / or non-3rd Generation Partner Program) is greater than 0 and less than a specific maximum value achieved by the user equipment, user equipment 704 removes each independent non-public network identity from the "Permanently Banned Independent Non-Public Networks List for Access to Localized Services in Independent Non-Public Networks" and / or the "Temporarily Banned Independent Non-Public Networks List for Access to Localized Services in Independent Non-Public Networks" under one or more of the following conditions: 1. Timer The following events may occur: 1. When the license plate expires; 2. When user equipment 704 is shut down; 3. When the general-purpose integrated circuit card containing the general user identity module is removed; 4. When the entries in the "User Data List" are updated. In the second configuration, user equipment 704 may attempt to access a previously prohibited localized service independent non-public network after a specific event or time period. User equipment 704 also considers third-generation partner program and non-third-generation partner program access types, as user equipment 704 may use different access types to connect to independent non-public networks, such as independent non-public network 710 or independent non-public network 720.
[0077] timer Expiration indicates the end of the waiting period for user equipment 704, which was previously restricted from attempting to access certain independent non-public networks due to registration denial (fifth-generation mobility management reason values such as #74 (temporarily unauthorized for this independent non-public network) or #75 (permanently unauthorized for this independent non-public network)). By removing the independent non-public network identity from the blacklist when the timer expires, user equipment 704 can reassess its access rights and may be able to re-attempt to connect to networks such as independent non-public network 710 or independent non-public network 720, which may become accessible due to changes in network conditions or authorization status.
[0078] Therefore, when timer T3247 expires, if the mobile station supports access to a standalone non-public network, an equivalent standalone non-public network, or both using the credential holder's credentials, and is associated with a selected entry in the "User Data List" or a selected public land mobile network subscription, and the value of the corresponding standalone non-public network-specific attempt counter for 3G Partner Program access is greater than zero and less than a specific maximum value achieved by the user equipment, and this standalone non-public network identity is included in the "Permanently Banned Standalone Non-Public Network List" for 3G Partner Program access, the "Temporarily Banned Standalone Non-Public Network List" for 3G Partner Program access, or the "Standalone Non-Public Network List" for accessing localized services, then... User equipment 704 may remove each independent non-public network identity from either the "Permanently Prohibited Independent Non-Public Network List" for access to the 3G Partner Program, the "Temporarily Prohibited Independent Non-Public Network List" for access to the 3G Partner Program, or the "Permanently Prohibited Independent Non-Public Network List" or "Temporarily Prohibited Independent Non-Public Network List" for access to localized services.
[0079] If a mobile site supports access to a standalone non-public network, an equivalent standalone non-public network, or both using the credentials of a credential holder, and is associated with a selected entry in the "User Data List" or a selected public land mobile network subscription, and the value of the specific attempt counter for the corresponding standalone non-public network used for non-3G Partner Program access is greater than zero and less than a specific maximum value achieved by the user equipment, and this standalone non-public network identity is included in the "Permanently Banned Standalone Non-Public Network List" or "Temporarily Banned Standalone Non-Public Network List" for non-3G Partner Program access, or in the "Permanently Banned Standalone Non-Public Network List" for accessing localized services, then this standalone non-public network identity is considered a valid standalone non-public network for accessing localized services. User equipment 704 may also remove each independent non-public network identity from either the "List of Prohibited Independent Non-Public Networks" or the "List of Temporarily Prohibited Independent Non-Public Networks for Access to Localization Services" for non-3rd Generation Partner Program access, or the "List of Permanently Prohibited Independent Non-Public Networks for Access to Localization Services" or the "List of Temporarily Prohibited Independent Non-Public Networks for Access to Localization Services" for access to localization services.
[0080] When User Equipment 704 is powered off, it signifies a significant change in the device's state. The power cycle provides a natural opportunity for User Equipment 704 to reset certain parameters and lists, including the list of prohibited independent non-public networks. Network conditions and authorization status may change during User Equipment 704's shutdown. By clearing these lists upon power-on, User Equipment 704 can restart, potentially allowing access to previously prohibited but now accessible independent non-public networks.
[0081] Similarly, removing a generic integrated circuit card containing a generic user identity module (GMIM) may indicate a change in user subscription or identity. The GMIM contains critical information related to a user's network access permissions and subscriptions. When it is removed, user equipment 704 can no longer authenticate with the network using that specific GMIM. Therefore, previous blacklists may no longer be relevant or applicable.
[0082] Therefore, when User Equipment 704 is shut down or the general integrated circuit card containing the general user identity module is removed, for each independent non-public network specific attempt counter used for 3G Partner Program access, if its value is greater than zero and less than a specific maximum value achieved by the User Equipment, User Equipment 704 may remove the corresponding independent non-public network identity (if any) from the "Permanently Prohibited Independent Non-Public Network List" used for 3G Partner Program access, the "Temporarily Prohibited Independent Non-Public Network List" used for 3G Partner Program access, the "Permanently Prohibited Independent Non-Public Network List for Accessing Localized Services in Independent Non-Public Networks" or the "Temporarily Prohibited Independent Non-Public Network List for Accessing Localized Services in Independent Non-Public Networks" used for accessing localized services.
[0083] When User Equipment 704 is shut down or the general integrated circuit card containing the general user identity module is removed, for each independent non-public network specific attempt counter used for non-3rd Generation Partner Program access, if its value is greater than zero and less than a specific maximum value achieved by the User Equipment, User Equipment 704 may remove the corresponding independent non-public network identity (if any) from the "Permanently Prohibited Independent Non-Public Network List" used for non-3rd Generation Partner Program access, the "Temporarily Prohibited Independent Non-Public Network List" used for non-3rd Generation Partner Program access, the "Permanently Prohibited Independent Non-Public Network List for Accessing Localized Services in Independent Non-Public Networks", or the "Temporarily Prohibited Independent Non-Public Network List for Accessing Localized Services in Independent Non-Public Networks".
[0084] In addition, the "User Data List" contains information about user credentials and preferences for accessing various independent non-public networks (such as independent non-public network 710 and independent non-public network 720). Each entry in the User Data List may contain detailed information such as independent non-public network identity, credentials, and access parameters. When an entry is updated, it may indicate a change in the user's access permissions or the independent non-public networks they are authorized to connect to.
[0085] By removing independent non-public network identities from the prohibited list when updating the "User Data List," user device 704 can reassess its access permissions based on the new subscription information. Therefore, user device 704 will not unnecessarily restrict access to independent non-public networks that the user might now be authorized to access due to changes in user subscriptions or network conditions.
[0086] Therefore, when an entry in the "User Data List" is updated, if user equipment 704 does not support accessing an independent non-public network using the credential holder's credentials and an equivalent independent non-public network, and the value of the independent non-public network-specific attempt counter for third-generation partner program access corresponding to that entry is greater than zero and less than the user equipment's specific maximum value, user equipment 704 may remove the independent non-public network identity (if any) corresponding to that entry from the "Permanently Prohibited Independent Non-Public Network List" or "Temporarily Prohibited Independent Non-Public Network List" for third-generation partner program access, or the "Permanently Prohibited Independent Non-Public Network List for Accessing Localized Services" or "Temporarily Prohibited Independent Non-Public Network List for Accessing Localized Services" for accessing localized services.
[0087] When an entry in the "User Data List" is updated, if user equipment 704 does not support accessing an independent non-public network using the credential holder's credentials and an equivalent independent non-public network, and the value of the independent non-public network-specific attempt counter for accessing an independent non-public network outside the third-generation partner program corresponding to that entry is greater than zero and less than a specific maximum value achieved by the user equipment, user equipment 704 may remove the independent non-public network identity (if any) corresponding to that entry from the "Permanently Prohibited Independent Non-Public Network List" or "Temporarily Prohibited Independent Non-Public Network List" for accessing non-third-generation partner program access, or the "Permanently Prohibited Independent Non-Public Network List for Accessing Localized Services" or "Temporarily Prohibited Independent Non-Public Network List for Accessing Localized Services" for accessing localized services.
[0088] When an entry in the "User Data List" is updated, if the user equipment supports accessing an independent non-public network using the credential holder's credentials, an equivalent independent non-public network, or both, and the independent non-public network associated with that entry for access under the 3G Partner Program has an independent non-public network specific attempt counter value that is greater than zero and less than a specific maximum value achieved by the user equipment in the "Permanently Prohibited Independent Non-Public Network List" or "Temporarily Prohibited Independent Non-Public Network List" for access under the 3G Partner Program, or the "Permanently Prohibited Independent Non-Public Network List" or "Temporarily Prohibited Independent Non-Public Network List" for accessing localized services, the user equipment 704 can remove the independent non-public network identity corresponding to that independent non-public network from the "Permanently Prohibited Independent Non-Public Network List" or "Temporarily Prohibited Independent Non-Public Network List" for access under the 3G Partner Program, or the "Permanently Prohibited Independent Non-Public Network List" or "Temporarily Prohibited Independent Non-Public Network List" for accessing localized services associated with that entry.
[0089] When an entry in the "User Data List" is updated, if User Equipment 704 supports accessing an Independent Non-Public Network (ISN) using the credential holder's credentials, an equivalent Independent Non-Public Network, or both, and the entry is associated with a "Permanently Prohibited Independent Non-Public Network List" or "Temporarily Prohibited Independent Non-Public Network List" for non-3G Partner Program access, or a "Permanently Prohibited Independent Non-Public Network List for Access to Localized Services in Independent Non-Public Networks" or "Temporarily Prohibited Independent Non-Public Network List for Access to Localized Services in Independent Non-Public Networks" for non-3G Partner Program access, its Independent Non-Public Network... If the value of the independent non-public network specific attempt counter is greater than zero and less than the user equipment achieves a specific maximum value, then user equipment 704 can remove the independent non-public network identity corresponding to that independent non-public network from the "Permanently Prohibited Independent Non-Public Network List" or "Temporarily Prohibited Independent Non-Public Network List" associated with that entry for access to non-third-generation partner programs, or the "Permanently Prohibited Independent Non-Public Network List for Accessing Localized Services in Independent Non-Public Networks" or "Temporarily Prohibited Independent Non-Public Network List for Accessing Localized Services in Independent Non-Public Networks" for access to non-third-generation partner programs.
[0090] Figure 8Sequence diagram 800 illustrates the operation of user equipment 704 and standalone non-public network 710 processing the list of standalone non-public networks prohibited from accessing localized services. In operation 802, user equipment 704 initiates a registration request to standalone non-public network 710 via base station 702. This request is typically issued when user equipment 704 attempts to connect to standalone non-public network 710 to access localized services.
[0091] In operation 804, user equipment 704 receives a registration rejection message or service rejection message without integrity protection from standalone non-public network 710 via base station 702. This rejection message contains a fifth-generation mobility management reason value, in this example #74 (temporary unauthorized access to the standalone non-public network) or #75 (permanent unauthorized access to the standalone non-public network). The lack of integrity protection indicates that the network has not yet executed the security mode command procedure.
[0092] Upon receiving the rejection message, in operation 806, user equipment 704 performs several operations. It stops the running timer ( or ), and start the timer with a random value within a specified range. User equipment 704 also updated its fifth-generation system status to 5U3 ROAMING NOT ALLOWED and removed parameters including the 5G Globally Unique Temporary UE Identity (5G-GUTI), the Tracking Area Identity (TAI) of the last access registration, the list of Tracking Area Identity, ngKSI, and the equivalent independent non-public network list.
[0093] In operation 808, user equipment 704 adds the independent non-public network identity to the appropriate prohibited list. If the reason value is #74, the independent non-public network identity is added to the "Temporarily Prohibited Independent Non-Public Networks List for Accessing Localized Services". If the reason value is #75, it is added to the "Permanently Prohibited Independent Non-Public Networks List for Accessing Localized Services".
[0094] In operation 810, user equipment 704 increments a separate, non-public network-specific attempt counter for the access type (3rd Generation Partner Program access or non-3rd Generation Partner Program access) used to receive the rejection message. The counter is incremented only if its current value is below a user equipment-specific maximum value.
[0095] In the first scenario, during operation 812, user equipment 704 is either shut down or the general-purpose integrated circuit card containing the general user identity module is removed. In this case, for each independent non-public network-specific attempt counter (for 3G Partner Program access and non-3G Partner Program access), if its value is greater than zero and less than a specific maximum value achieved by the user equipment, user equipment 704 removes the corresponding independent non-public network identity from all applicable prohibition lists.
[0096] In the second scenario, in operation 814, the entries in the "User Data List" are updated. This update triggers a similar process that removes the independent non-public network identity from the prohibited list based on the value of the independent non-public network-specific attempt counter and whether user equipment 704 supports accessing the independent non-public network using credentials of the credential holder or equivalent independent non-public network.
[0097] In the third scenario, during operation 816, the timer... Upon expiration, User Equipment 704 checks whether the Independent Non-Public Network-Specific Attempt Counter for the relevant access type is greater than zero and less than a specific maximum value implemented by the User Equipment. If this condition is met, and the Independent Non-Public Network Identity exists in any prohibited list, then User Equipment 704 removes the Independent Non-Public Network Identity from those lists.
[0098] These operations enable User Equipment 704 to dynamically manage access to localized services on independent, non-public networks. By removing an independent, non-public network identity from the blacklist under specific conditions, User Equipment 704 can reassess its ability to access these networks, potentially regaining access to localized services that were previously unavailable due to temporary or permanent restrictions.
[0099] Furthermore, in the third configuration, user equipment 704, operating in standalone non-public network access mode, can implement a new standalone non-public network-specific attempt counter for localized services. This configuration meets the need for finer-grained control over localized service access attempts on standalone non-public networks (such as standalone non-public networks 710 and 720).
[0100] In the third configuration, user equipment 704 maintains two new counters for each entry in the "user data list": 1. A localized service stand-alone non-public network-specific attempt counter for third-generation partner program access, applicable to user equipment 704 that supports access to stand-alone non-public networks providing localized services through third-generation partner program access.
[0101] 2. A localized service independent non-public network-specific attempt counter for non-3rd Generation Partner Program access, applicable to user equipment 704 supporting access to localized services via independent non-public networks provided through non-3rd Generation Partner Program access.
[0102] These new counters differ from existing separate, non-public network-specific attempt counters used for general 3G Partner Program access and non-3G Partner Program access. They allow user devices 704 to manage access attempts for localized services separately from other types of access attempts.
[0103] User equipment 704 increments these counters under specific conditions: For the third-generation partner program to access the counter: - User equipment 704 receives a fifth-generation mobility management reason value #74 or #75 in a third-generation partner program access message without integrity protection (such as a registration rejection message or a service rejection message); - Independent non-public networks are selected according to Section 4.9.3.1.1 (a0) of the 3rd Generation Partnership Project Technical Specification 23.122, specifically for independent non-public networks involving localized services; - The current value of the counter is less than the maximum value that the user equipment implements.
[0104] For non-third-generation partner programs to access the counter: - User equipment 704 receives a fifth-generation mobility management reason value #74 or #75 in an integrity protection message when accessing through a non-third-generation partner program access; - The current value of the counter is less than the maximum value that the user equipment implements.
[0105] The third configuration also defines conditions for removing the independent non-public network identity from the "Permanently Banned Independent Non-Public Networks List" and the "Temporarily Banned Independent Non-Public Networks List" when the relevant localization service independent non-public network specific attempt counter (third-generation partner program access or non-third-generation partner program access) value is greater than 0 and less than a specific maximum value achieved by the user equipment. These conditions include one or more of the following: - Timer maturity; - User equipment 704 is shut down; - The general-purpose integrated circuit card containing the general user identity module was removed; - The entries in the "User Data List" have been updated.
[0106] Figure 9Flowchart 900 describes a method (process) by which a user equipment (e.g., user equipment 704) manages access to localized services from independent non-public networks by updating a list of prohibited independent non-public networks based on specific events and conditions. In operation 902, the user equipment receives a rejection message without integrity protection from the independent non-public network. In some configurations, this rejection message is either a registration rejection message or a service rejection message. In some configurations, the rejection message includes a 5G mobility management reason value #74, indicating temporary unauthorization of the independent non-public network, or #75, indicating permanent unauthorization of the independent non-public network.
[0107] In Operation 904, the User Equipment (UE) adds the identity of the Independent Non-Public Network (ISN) to a prohibited list for accessing localized services. In some configurations, this prohibited list is either a "Temporary Prohibited List of ISNs for Accessing Localized Services" or a "Permanent Prohibited List of ISNs for Accessing Localized Services." In Operation 906, the UE starts a timer. In some configurations, this timer is Timer T3247. In Operation 908, the UE increments an ISN-specific attempt counter. In some configurations, this ISN-specific attempt counter is used for 3G Partner Program access. In some configurations, this ISN-specific attempt counter is used for non-3G Partner Program access.
[0108] In operation 910, in response to at least one of the following occurrences: the timer expires, the user equipment is shut down, the universal integrated circuit card (UICC) containing the universal user identity module (USIM) is removed, or the entry in the user data list is updated, the user equipment removes the identity of the independent non-public network (SNPN) from the prohibited list when the value of the SNPN-specific attempt counter is greater than zero and less than the user equipment achieves a specific maximum value.
[0109] In some configurations, the identity of the standalone non-public network is removed from the prohibited list for both 3GPP and non-3GPP access. To remove the identity of the standalone non-public network from the prohibited list, the user equipment removes the identity from either a "permanently prohibited standalone non-public network list for accessing localized services" or a "temporary prohibited standalone non-public network list for accessing localized services."
[0110] In some configurations, when the timer expires, the user equipment removes each individual non-public network identity from a second prohibited list associated with a selected entry in the user data list or a selected public land mobile network (PLMN) subscription.
[0111] In operation 912, after removing the identity of the independent non-public network from the banned list, the user equipment reassesses its access rights to the independent non-public network. In operation 914, after removing the identity of the independent non-public network from the banned list, the user equipment performs an independent non-public network selection.
[0112] It should be understood that the specific order or hierarchy of the blocks in the disclosed process / flowchart is merely exemplary. Depending on design preferences, the specific order or hierarchy of the blocks in the process / flowchart may be rearranged. Furthermore, some blocks may be combined or omitted. The appended method claims present the elements of the blocks in an exemplary order and are not intended to limit the specific order or hierarchy shown.
[0113] The foregoing description is intended to enable those skilled in the art to implement the various aspects described herein. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects. Therefore, the claims are not intended to limit the aspects shown herein, but rather to impose a full scope consistent with the language of the claims, wherein a singular reference to an element does not mean “only one” unless explicitly stated otherwise, but rather “one or more.” The term “exemplary” is used herein to mean “as an example, instance, or illustration.” Any aspect described as “exemplary” is not necessarily to be construed as preferred or superior to other aspects. Unless otherwise explicitly stated, the term “some” means one or more. Combinations such as “at least one A, B, or C,” “one or more A, B, or C,” “at least one A, B, and C,” “one or more A, B, and C,” and “A, B, C, or any combination thereof” include any combination of A, B, and / or C, and may include multiple A, multiple B, or multiple C. Specifically, combinations such as “at least one A, B, or C,” “one or more A, B, or C,” “at least one A, B, and C,” “one or more A, B, and C,” and “A, B, C, or any combination thereof” can be only A, only B, only C, A and B, A and C, B and C, or A, B, and C, wherein any such combination may include one or more members of A, B, or C. All structural and functional equivalents to elements of various aspects of this disclosure that are known or subsequently known to a person skilled in the art are expressly incorporated herein by reference and are intended to be covered by the claims. Furthermore, nothing disclosed herein is intended to be offered to the public, whether or not such disclosure is expressly recited in the claims. The terms “module,” “mechanism,” “element,” “device,” etc., do not necessarily replace the word “means.” Therefore, unless an element expressly uses the phrase “means for…,” no claim element should be construed as means plus function.
Claims
1. A wireless communication method for a user equipment, comprising: Receive a rejection message without integrity protection from an independent, non-public network; Add the identity of this independent, non-public network to a prohibited list for accessing localized services; Start a timer; Add a separate, non-public network-specific attempt counter; and In response to at least one of the following occurrences: the timer expires, the user equipment is shut down, a general integrated circuit card containing a general user identity module is removed, or an entry in a user data list is updated, the identity of the independent non-public network is removed from the banned list when a value of the specific attempt counter for the independent non-public network is greater than zero and less than a specific maximum value achieved by the user equipment.
2. The method of claim 1, wherein the rejection message is one of a registration rejection message or a service rejection message.
3. The method of claim 1, wherein the rejection message includes a fifth-generation mobility management reason value #74 indicating temporary unauthorization of the independent non-public network, or a fifth-generation mobility management reason value #75 indicating permanent unauthorization of the independent non-public network.
4. The method of claim 1, wherein the ban list is one of a temporary ban list of independent non-public networks used for accessing localized services or a permanent ban list of independent non-public networks used for accessing localized services.
5. The method as described in claim 1, wherein the timer is timer T3247.
6. The method of claim 1, wherein the independent non-public network-specific attempt counter is used for third-generation partner program access.
7. The method of claim 1, wherein the independent non-public network-specific attempt counter is used for non-third-generation partner program access.
8. The method of claim 1, further comprising: The identity of this independent, non-public network is removed from the prohibited list for both 3rd Generation Partner Program (GLP) access and non-3rd Generation Partner Program (NVP) access.
9. The method of claim 1, wherein removing the identity of the independent non-public network from the prohibited list comprises removing the identity from one of a permanently prohibited independent non-public network list for accessing localized services or a temporarily prohibited independent non-public network list for accessing localized services.
10. The method of claim 1, further comprising: When the timer expires, each individual non-public network identity is removed from a second prohibited list associated with a selected entry in the user data list or a selected public land mobile network subscription.
11. The method of claim 1, further comprising: After removing the identity of the independent non-public network from the blacklist, the access rights to the independent non-public network will be reassessed.
12. The method of claim 1, further comprising: After the identity of the standalone non-public network is removed from the ban list, a standalone non-public network selection is performed.
13. An apparatus for wireless communication, the apparatus being a user equipment, comprising: A memory; as well as At least one processor, coupled to the memory, is configured as follows: Receive a rejection message without integrity protection from an independent, non-public network; Add the identity of this independent, non-public network to a prohibited list for accessing localized services; Start a timer; Add a separate, non-public network-specific attempt counter; and In response to at least one of the following occurrences: the timer expires, the user equipment is shut down, a general integrated circuit card containing a general user identity module is removed, or an entry in a user data list is updated, the identity of the independent non-public network is removed from the banned list when a value of the specific attempt counter for the independent non-public network is greater than zero and less than a specific maximum value achieved by the user equipment.
14. The apparatus of claim 13, wherein the rejection message is one of a registration rejection message or a service rejection message.
15. The apparatus of claim 13, wherein the denial message includes a fifth-generation mobility management reason value #74 indicating temporary unauthorization of the independent non-public network, or a fifth-generation mobility management reason value #75 indicating permanent unauthorization of the independent non-public network.
16. The apparatus of claim 13, wherein the ban list is one of a temporary ban list of independent non-public networks for accessing localized services or a permanent ban list of independent non-public networks for accessing localized services.
17. The apparatus of claim 13, wherein the timer is timer T3247.
18. The apparatus of claim 13, wherein the independent non-public network-specific attempt counter is used for third-generation partner program access.
19. The apparatus of claim 13, wherein the independent non-public network-specific attempt counter is used for non-Generation 3 Partner Program access.
20. A computer-readable medium for wireless communication of a user equipment, storing computer-executable code, including methods for: Receive a rejection message without integrity protection from an independent, non-public network; Add the identity of this independent, non-public network to a prohibited list for accessing localized services; Start a timer; Add a separate, non-public network-specific attempt counter; and In response to at least one of the following occurrences: the timer expires, the user equipment is shut down, a general integrated circuit card containing a general user identity module is removed, or an entry in a user data list is updated, the identity of the independent non-public network is removed from the banned list when a value of the specific attempt counter for the independent non-public network is greater than zero and less than a specific maximum value achieved by the user equipment.