Non-access stratum (NAS) based user equipment location verification in non-terrestrial networks

By using NAS security context encryption of UE location information in wireless communication systems, the problem of UE location verification in non-terrestrial networks is solved, enabling accurate UE location verification and resource control in NTN systems, and improving system security and resource management efficiency.

CN122460115APending Publication Date: 2026-07-24QUALCOMM INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
QUALCOMM INC
Filing Date
2024-12-03
Publication Date
2026-07-24

Smart Images

  • Figure CN122460115A_ABST
    Figure CN122460115A_ABST
Patent Text Reader

Abstract

Techniques for non-access stratum (NAS)-based user equipment (UE) location verification in non-terrestrial networks (NTNs) are disclosed. In an aspect, a UE can encrypt location information of the UE using a portion of a NAS security context to create encrypted UE location information, transmit a connection request to a NTN base station (BS), the connection request including a first uplink (UL) NAS count value, the encrypted UE location information, and a NAS message including a UE identifier, a NAS message authentication code, and a second UL NAS count value, and receive a connection response from the NTN BS.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] All aspects of this disclosure relate to wireless technology. Background Technology

[0002] Related technical descriptions

[0003] Wireless communication systems have evolved through many generations, including first-generation analog radiotelephone service (1G), second-generation (2G) digital radiotelephone service (including transitional 2.5G and 2.75G networks), third-generation (3G) high-speed data, wireless services with internet capabilities, and fourth-generation (4G) services (e.g., Long Term Evolution (LTE) or WiMax). Currently, many different types of wireless communication systems are in use, including cellular systems and Personal Communication Services (PCS) systems. Known examples of cellular systems include cellular analog Advanced Mobile Phone Systems (AMPS), as well as digital cellular systems based on Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Global System for Mobile Communications (GSM), and others.

[0004] The fifth-generation (5G) wireless standard, known as New Radio (NR), delivers higher data transfer speeds, more connections, better coverage, and other improvements. According to the Next Generation Mobile Networks Alliance (NGC), the 5G standard is designed to provide higher data rates, more accurate positioning (e.g., based on Positioning Reference Signals (RS-P), such as downlink, uplink, or sidelink Positioning Reference Signals (PRS)), and other technological enhancements compared to previous standards. These enhancements, along with the use of higher frequency bands, advancements in the PRS process and technology, and the high-density deployment of 5G, enable high-accuracy positioning based on 5G. Summary of the Invention

[0005] The following is a simplified summary of the invention relating to one or more aspects disclosed herein. Therefore, this summary should not be considered an exhaustive overview relating to all conceived aspects, nor should it be considered to identify key or decisive elements relating to all conceived aspects or to depict the scope associated with any particular aspect. Thus, the sole purpose of this summary is to present, in a simplified form, certain concepts relating to one or more aspects involving the mechanisms disclosed herein, prior to the detailed description presented below.

[0006] In one aspect, a method of wireless communication performed by a user equipment (UE) includes: encrypting the location information of the UE using a portion of a non-access stratum (NAS) security context to create encrypted UE location information; transmitting a connection request to a non-terrestrial network (NTN) base station (BS) including a first uplink (UL) NAS count value, the encrypted UE location information, and a NAS message including a UE identifier, a NAS message authentication code, and a second UL NAS count value; and receiving a connection response from the NTN BS.

[0007] In one aspect, a wireless communication method performed by an NTN BS includes: receiving a connection request from a UE, the connection request including a first UL NAS count value, encrypted UE location information, and a NAS message including a UE identifier, a NAS message authentication code, and a second UL NAS count value; transmitting the UE identifier, the first UL NAS count value, and the encrypted UE location information to a core network (CN) node; receiving decrypted UE location information from the CN node; determining whether the UE is allowed or not allowed to access based at least on the UE location information; and transmitting a connection response to the UE indicating whether the UE is allowed or not allowed to access.

[0008] In one aspect, a method for wireless communication performed by a CN node includes: receiving a UE identifier, a ULNAS count value, and encrypted UE location information from an NTN BS; determining decrypted UE location information from the encrypted UE location information; and transmitting the decrypted UE location information to the NTN BS.

[0009] In one aspect, a UE includes: one or more memories; one or more transceivers; and one or more processors communicatively coupled to the one or more memories and the one or more transceivers, the one or more processors being individually or in combination configured to: encrypt UE location information using a portion of a NAS security context to create encrypted UE location information; transmit a connection request to an NTN BS via the one or more transceivers, the connection request including a first UL NAS count value, the encrypted UE location information, and a NAS message including a UE identifier, a NAS message authentication code, and a second UL NAS count value; and receive a connection response from the NTN BS via the one or more transceivers.

[0010] In one aspect, an NTN BS includes: one or more memories; one or more transceivers; and one or more processors communicatively coupled to the one or more memories and the one or more transceivers, the one or more processors being individually or in combination configured to: receive a connection request from a UE via the one or more transceivers, the connection request including a first UL NAS count value, encrypted UE location information, and a NAS message including a UE identifier, a NAS message authentication code, and a second UL NAS count value; transmit the UE identifier, the first UL NAS count value, and the encrypted UE location information to a CN node via the one or more transceivers; receive decrypted UE location information from the CN node via the one or more transceivers; determine whether the UE is allowed or not allowed access based at least on the UE location information; and transmit a connection response to the UE via the one or more transceivers indicating whether the UE is allowed or not allowed access.

[0011] In one aspect, a CN node includes: one or more memories; one or more transceivers; and one or more processors communicatively coupled to the one or more memories and the one or more transceivers, the one or more processors being individually or in combination configured to: receive a UE identifier, a UL NAS count value, and encrypted UE location information from an NTN BS via the one or more transceivers; determine decrypted UE location information from the encrypted UE location information; and transmit the decrypted UE location information to the NTN BS via the one or more transceivers.

[0012] Based on the accompanying drawings and detailed description, other objects and advantages associated with the aspects disclosed herein will be apparent to those skilled in the art. Attached Figure Description

[0013] The accompanying drawings are provided to help describe various aspects of this disclosure, and are provided for illustrative purposes only and not to limit the aspects.

[0014] Figure 1 Example wireless communication systems according to various aspects of this disclosure are illustrated.

[0015] Figure 2A , Figure 2B and Figure 2C Example wireless network architectures based on various aspects of this disclosure are illustrated.

[0016] Figure 3A , Figure 3B and Figure 3C It is a simplified block diagram of several examples of components that can be used in user equipment (UE), base stations and network entities and configured to support communications as taught herein.

[0017] Figure 4 This is a signaling and event diagram illustrating the existing mechanism used by the Long Term Evolution (LTE) UE 402 to recover from Radio Link Failure (RLF) conditions.

[0018] Figure 5 This is a signaling and event diagram illustrating the process according to various aspects of this disclosure, through which the UE can connect to a non-terrestrial network (NTN).

[0019] Figure 6 This is a signaling and event diagram illustrating the processes according to various aspects of this disclosure, through which the UE can connect to the NTN and also change the Mobility Management Entity (MME).

[0020] Figures 7 to 9 This is a flowchart of an example process associated with UE location verification based on the Non-Access Stratum (NAS) in NTN, according to various aspects of this disclosure. Detailed Implementation

[0021] Various aspects of this disclosure are provided below in the description of various examples provided for illustrative purposes and in the accompanying drawings. Alternative aspects may be devised without departing from the scope of this disclosure. Additionally, well-known elements of this disclosure will not be described in detail or will be omitted so as not to obscure the relevant details of this disclosure.

[0022] The various aspects collectively involve the authentication of User Equipment (UE) location to a non-terrestrial network (NTN) using Non-Access Stratum (NAS) security mechanisms. Some aspects are more specifically related to Control Plane (CP) UEs that do not support the creation of Access Stratum (AS) security contexts. In one aspect, the UE can use a portion of the NAS security context to encrypt its location information to create encrypted UE location information; transmit a connection request to the NTN base station (BS) including a first uplink (UL) NAS count value, the encrypted UE location information, and a NAS message including the UE identifier, NAS message authentication code, and a second UL NAS count value; and receive a connection response from the NTN BS.

[0023] Specific aspects of the subject matter described in this disclosure can be implemented to achieve one or more of the following potential advantages. In some examples, only the CP UE can use the techniques described herein to provide the UE's location information, which may be a regulatory requirement for obtaining access to the NTN, without establishing AS security or without the existence of AS security and without changing the existing NAS protocol. Other techniques disclosed herein allow the NTN base station (BS) to request the core network (CN) node to use NAS security mechanisms to protect the Radio Resource Control (RRC) configuration instructions that the NTN BS wants to transmit to UEs that are permitted or will be permitted to access the NTN.

[0024] The terms “exemplary” and / or “example” are used herein to mean “serving as an example, instance, or illustration.” Any aspect described herein as “exemplary” and / or “example” is not necessarily to be construed as superior to or better than other aspects. Similarly, the term “aspects of this disclosure” does not require that all aspects of this disclosure include the features, advantages, or modes of operation discussed.

[0025] Those skilled in the art will understand that any of a variety of different techniques and methods can be used to represent the information and signals described below. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be mentioned throughout the following description can be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, light fields or optical particles, or any combination thereof, depending in part on the specific application, in part on the desired design, in part on the corresponding technology, and so on.

[0026] Furthermore, many aspects are described according to a sequence of actions to be performed by elements of, for example, a computing device. It will be appreciated that the various actions described herein can be performed by specific circuitry (e.g., an application-specific integrated circuit (ASIC)), by program instructions executed by one or more processors, or by a combination of both. Additionally, the sequence of actions described herein can be considered to be entirely embodied in any form of non-transitory computer-readable storage medium storing a corresponding set of computer instructions that, when executed, will cause or command the associated processor of the device to perform the functionality described herein. Therefore, various aspects of this disclosure can be embodied in a variety of different forms, all of which are contemplated within the scope of the claimed subject matter. Furthermore, for each aspect described herein, any corresponding form of any such aspect may be described herein as, for example, "logic configured to perform the described actions."

[0027] As used herein, unless otherwise stated, the terms “User Equipment” (UE) and “Base Station” are not intended to be specific or otherwise limited to any particular Radio Access Technology (RAT). Generally, a UE can be any wireless communication device used by a user to communicate over a wireless communication network (e.g., mobile phone, router, tablet computer, laptop computer, consumer asset positioning device, wearable device (e.g., smartwatch, glasses, augmented reality (AR) / virtual reality (VR) headset, etc.), vehicle (e.g., car, motorcycle, bicycle, etc.), Internet of Things (IoT) device, etc.). A UE can be mobile or can (e.g., at certain times) be stationary and can communicate with a Radio Access Network (RAN). As used herein, the term “UE” can be interchangeably referred to as “Access Terminal” or “AT,” “Client Equipment,” “Wireless Equipment,” “Subscriber Equipment,” “Subscriber Terminal,” “Subscriber Station,” “User Terminal” or “UT,” “Mobile Equipment,” “Mobile Terminal,” “Mobile Station,” or variations thereof. Generally, a UE can communicate with a core network via the RAN, and through the core network, a UE can connect to external networks such as the Internet and to other UEs. Of course, other mechanisms for connecting to the core network and / or the Internet are also possible for the UE, such as through wired access networks, wireless local area network (WLAN) networks (e.g., based on the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard, etc.).

[0028] A base station may operate according to one of several RATs to communicate with the UE, depending on the network in which it is deployed, and may alternatively be referred to as an Access Point (AP), Network Node, Node B, Evolved Node B (eNB), Next Generation eNB (ng-eNB), New Radio (NR) Node B (also referred to as gNB or gNodeB), etc. The base station may primarily be used to support the UE's radio access, including supporting data, voice, and / or signaling connections for the supported UE. In some systems, the base station may only provide edge node signaling functions, while in others, it may provide additional control and / or network management functions. The communication link through which the UE can transmit signals to the base station is called an uplink (UL) channel (e.g., reverse traffic channel, reverse control channel, access channel, etc.). The communication link through which the base station can transmit signals to the UE is called a downlink (DL) or forward link channel (e.g., paging channel, control channel, broadcast channel, forward traffic channel, etc.). As used herein, the term "traffic channel (TCH)" may refer to an uplink / reverse traffic channel or a downlink / forward traffic channel.

[0029] The term "base station" can refer to a single physical transmit / receive point (TRP) or multiple physical TRPs that may or may not be co-located. For example, when the term "base station" refers to a single physical TRP, the physical TRP can be the antenna of a base station corresponding to a cell (or several cell sectors) of the base station. When the term "base station" refers to multiple co-located physical TRPs, the physical TRP can be the antenna array of the base station (e.g., as in a multiple-input multiple-output (MIMO) system or where the base station employs beamforming). When the term "base station" refers to multiple non-co-located physical TRPs, the physical TRP can be a distributed antenna system (DAS) (a network of spatially separated antennas connected via a transmission medium to a common source) or a remote radio headend (RRH) (a remote base station connected to a serving base station). Alternatively, a non-co-located physical TRP can be the serving base station from which the UE receives measurement reports and a neighboring base station where the UE is measuring its reference radio frequency (RF) signal. Because, as used herein, a TRP is the point by which a base station transmits and receives radio signals, references to transmitting from or receiving at a base station should be understood to refer to a specific TRP of the base station.

[0030] In some specific implementations supporting UE positioning, the base station may not support the UE's radio access (e.g., it may not support data, voice, and / or signaling connections for the UE), but may instead transmit reference signals to the UE for measurement and / or receive and measure signals transmitted by the UE. Such a base station may be referred to as a positioning beacon (e.g., in the case of transmitting signals to the UE) and / or as a location measurement unit (e.g., in the case of receiving and measuring signals from the UE).

[0031] An “RF signal” refers to an electromagnetic wave of a given frequency that transmits information across the space between a transmitter and a receiver. As used herein, a transmitter may send a single “RF signal” or multiple “RF signals” to a receiver. However, due to the propagation characteristics of RF signals through multipath channels, a receiver may receive multiple “RF signals” corresponding to each transmitted RF signal. The same transmitted RF signal on different paths between the transmitter and receiver may be referred to as a “multipath” RF signal. As used herein, an RF signal may also be referred to as a “wireless signal” or simply a “signal” where the context clearly indicates that the term “signal” refers to a wireless signal or an RF signal.

[0032] Figure 1An example wireless communication system 100 according to various aspects of this disclosure is illustrated. The wireless communication system 100 (which may also be referred to as a wireless wide area network (WWAN)) may include various base stations 102 (labeled "BS") and various UEs 104. Base station 102 may include macro cell base stations (high-power cellular base stations) and / or small cell base stations (low-power cellular base stations). In one aspect, the macro cell base station may include an eNB and / or an ng-eNB (wherein the wireless communication system 100 corresponds to an LTE network), or a gNB (wherein the wireless communication system 100 corresponds to an NR network), or a combination of both, and the small cell base station may include femtocells, picocells, microcells, etc.

[0033] Base station 102 can collectively form a RAN and interface with core network 170 (e.g., evolved packet core (EPC) or 5G core (5GC)) via backhaul link 122, and interface with one or more location servers 172 (e.g., location management function (LMF) or secure user plane location (SUPL) location platform (SLP)) via core network 170. Location server 172 can be part of core network 170 or can be external to core network 170. Location server 172 can be integrated with base station 102. UE 104 can communicate with location server 172 directly or indirectly. For example, UE 104 can communicate with location server 172 via base station 102 currently serving UE 104. UE 104 can also communicate with location server 172 via another path, such as via application server (not shown), via another network, such as via wireless local area network (WLAN) access point (AP) (e.g., AP 150 described below), etc. For signaling purposes, communication between UE 104 and location server 172 can be represented as an indirect connection (e.g., via core network 170, etc.) or a direct connection (e.g., as shown via direct connection 128), wherein intermediate nodes (if present) are omitted from the signaling diagram for clarity.

[0034] In addition to other functions, base station 102 may perform functions associated with one or more of the following: transmitting user data, radio channel encryption and decryption, integrity protection, header compression, mobility control functions (e.g., handover, dual connectivity), inter-cell interference coordination, connection establishment and release, load balancing, distribution of Non-Access Stratum (NAS) messages, NAS node selection, synchronization, RAN sharing, Multimedia Broadcast Multicast Service (MBMS), subscriber and equipment tracking, RAN Information Management (RIM), paging, location, and delivery of warning messages. Base stations 102 may communicate with each other directly or indirectly (e.g., via EPC / 5GC) on backhaul link 134, which may be wired or wireless.

[0035] Base station 102 can wirelessly communicate with UE 104. Each base station in base station 102 can provide communication coverage for a corresponding geographic coverage area 110. In one aspect, one or more cells can be supported by base station 102 in each geographic coverage area 110. A “cell” is a logical communication entity used to communicate with a base station (e.g., via a frequency resource, which is referred to as a carrier frequency, component carrier, carrier, frequency band, etc.) and can be associated with an identifier (e.g., Physical Cell Identifier (PCI), Enhanced Cell Identifier (ECI), Virtual Cell Identifier (VCI), Cell Global Identifier (CGI), etc.) used to distinguish cells operating via the same or different carrier frequencies. In some cases, different cells can be configured according to different protocol types that can provide access for different types of UEs (e.g., Machine Type Communication (MTC), Narrowband IoT (NB-IoT), Enhanced Mobile Broadband (eMBB), or other protocol types). Because a cell is supported by a specific base station, the term “cell” can refer to either or both of the logical communication entity and the base station supporting the logical communication entity, depending on the context. Furthermore, since the TRP is typically the physical transmission point of a cell, the terms "cell" and "TRP" can be used interchangeably. In some cases, the term "cell" can also refer to the geographical coverage area of ​​a base station (e.g., a sector), as long as the carrier frequency can be detected and used for communication within a portion of the geographical coverage area 110.

[0036] While the geographic coverage areas 110 of adjacent macro cell base stations 102 may partially overlap (e.g., in handover areas), some areas within geographic coverage areas 110 may substantially overlap with larger geographic coverage areas 110. For example, a small cell base station 102' (labeled "SC" for "small cell") may have a geographic coverage area 110' that substantially overlaps with the geographic coverage areas 110 of one or more macro cell base stations 102. A network that includes both small cell base stations and macro cell base stations can be referred to as a heterogeneous network. A heterogeneous network may also include a home eNB (HeNB) that can provide service to a restricted group referred to as a Closed Subscriber Group (CSG).

[0037] The communication link 120 between base station 102 and UE 104 may include uplink (also known as reverse link) transmission from UE 104 to base station 102 and / or downlink (DL) (also known as forward link) transmission from base station 102 to UE 104. The communication link 120 may use MIMO antenna techniques, including spatial multiplexing, beamforming, and / or transmit diversity. The communication link 120 may use one or more carrier frequencies. Carrier allocation may be asymmetric for the downlink and uplink (e.g., more or fewer carriers may be allocated to the downlink compared to the uplink).

[0038] The wireless communication system 100 may also include a WLAN access point (AP) 150 that communicates with a wireless local area network (WLAN) station (STA) 152 via a communication link 154 in unlicensed spectrum (e.g., 5 GHz). When communicating in unlicensed spectrum, the WLAN STA 152 and / or WLAN AP 150 may perform a free channel assessment (CCA) or listen-before-talk (LBT) process before communication to determine whether the channel is available.

[0039] Small cell base station 102' can operate in licensed and / or unlicensed spectrum. When operating in unlicensed spectrum, small cell base station 102' can employ LTE or NR technology and use the same 5GHz unlicensed spectrum as WLAN AP 150. Small cell base station 102' employing LTE / 5G in unlicensed spectrum can improve the coverage and / or increase the capacity of the access network. NR in unlicensed spectrum may be referred to as NR-U. LTE in unlicensed spectrum may be referred to as LTE-U, Licensed Assisted Access (LAA), or MULTEFIRE. ® .

[0040] The wireless communication system 100 may also include a millimeter-wave (mmW) base station 180, which can operate at mmW and / or near-mmW frequencies to communicate with the UE 182. Extremely high frequency (EHF) is a portion of the electromagnetic spectrum that contains radio frequency (RF). EHF has a range of 30 GHz to 300 GHz, with wavelengths between 1 mm and 10 mm. Radio waves in this band are referred to as millimeter waves. Near-mmW extends down to frequencies of 3 GHz with wavelengths of 100 mm. Ultra-high frequency (SHF) bands extend between 3 GHz and 30 GHz, and are also referred to as centimeter waves. Communication using mmW / near-mmW radio bands has high path loss and relatively short range. The mmW base station 180 and the UE 182 can utilize beamforming (transmit and / or receive) on the mmW communication link 184 to compensate for the extremely high path loss and short range. Furthermore, it should be understood that, in alternative configurations, one or more base stations 102 may also use mmW or near-mmW and beamforming for transmission. Therefore, it should be understood that the foregoing examples are merely illustrative and should not be construed as limiting the various aspects disclosed herein.

[0041] Transmit beamforming is a technique used to focus RF signals in a specific direction. Traditionally, when a network node (e.g., a base station) broadcasts an RF signal, it broadcasts the signal in all directions (omnidirectionally). Using transmit beamforming, the network node determines where a given target device (e.g., a UE) is located (relative to the transmitting network node) and projects a stronger downlink RF signal in that specific direction, thus providing the receiving device with a faster and stronger RF signal (in terms of data rate). To change the directivity of the RF signal during transmission, the network node can control the phase and relative amplitude of the RF signal at each of one or more transmitters broadcasting the RF signal. For example, the network node can use an array of antennas (called a "phased array" or "antenna array") that forms an RF beam that can be "manipulated" to be pointed in different directions without actually moving the antennas. Specifically, RF currents from the transmitters are fed to individual antennas with the correct phase relationship, such that radio waves from the individual antennas add up in the desired direction to increase radiation, while canceling out in the undesired direction to suppress radiation.

[0042] Transmit beams can be quasi-co-located, meaning they appear to the receiver (e.g., the UE) as having the same parameters regardless of whether the network node's own transmit antennas are physically co-located. In NR, there are four types of quasi-co-located (QCL) relationships. Specifically, a given type of QCL relationship means that certain parameters of a second reference RF signal on a second beam can be derived based on information about the source reference RF signal on the source beam. Therefore, if the source reference RF signal is QCL type A, the receiver can use the source reference RF signal to estimate the Doppler shift, Doppler spread, average delay, and delay spread of the second reference RF signal transmitted on the same channel. If the source reference RF signal is QCL type B, the receiver can use the source reference RF signal to estimate the Doppler shift and Doppler spread of the second reference RF signal transmitted on the same channel. If the source reference RF signal is QCL type C, the receiver can use the source reference RF signal to estimate the Doppler shift and average delay of the second reference RF signal transmitted on the same channel. If the source reference RF signal is of type QCL D, the receiver can use the source reference RF signal to estimate the spatial reception parameters of a second reference RF signal transmitted on the same channel.

[0043] In receive beamforming, a receiver uses a receive beam to amplify an RF signal detected on a given channel. For example, the receiver may increase the gain setting of an antenna array in a particular direction and / or adjust the phase setting of the antenna array in a particular direction to amplify the RF signal received from that direction (e.g., increase its gain level). Therefore, when a receiver is described as performing beamforming in a certain direction, it means that the beam gain in that direction is high relative to the beam gain along other directions, or that the beam gain in that direction is the highest compared to the beam gain of all other receive beams available to the receiver in that direction. This results in a stronger received signal strength (e.g., reference signal received power (RSRP), reference signal received quality (RSRQ), signal-to-interference-plus-noise ratio (SINR), etc.) of the RF signal received from that direction.

[0044] The transmit and receive beams can be spatially correlated. Spatial correlation means that parameters for a second beam (e.g., transmit or receive beam) for a second reference signal can be derived based on information about a first beam (e.g., receive or transmit beam) for a first reference signal. For example, a UE can use a specific receive beam to receive a reference downlink reference signal (e.g., a synchronization signal block (SSB)) from a base station. The UE can then form a transmit beam for transmitting an uplink reference signal (e.g., a sounding reference signal (SRS)) to that base station based on the parameters of the receive beam.

[0045] It is important to note that, depending on the entity forming the "downlink" beam, the beam can be either a transmit beam or a receive beam. For example, if the base station is forming a downlink beam to transmit a reference signal to the UE, the downlink beam is a transmit beam. However, if the UE is forming a downlink beam, the downlink beam is a receive beam for receiving the downlink reference signal. Similarly, depending on the entity forming the "uplink" beam, the beam can be either a transmit beam or a receive beam. For example, if the base station is forming an uplink beam, the uplink beam is an uplink receive beam, while if the UE is forming an uplink beam, the uplink beam is an uplink transmit beam.

[0046] The electromagnetic spectrum is typically subdivided into various categories, bands, channels, etc., based on frequency / wavelength. In 5G NR, two initial operating bands have been designated as frequency ranges FR1 (410MHz to 7.125GHz) and FR2 (24.25GHz to 52.6GHz). It should be understood that although a portion of FR1 is greater than 6GHz, in various documents and articles, FR1 is often (interchangeably) referred to as the "sub-6GHz" band. A similar naming issue sometimes occurs with FR2, which is often (interchangeably) referred to as the "millimeter wave" band in documents and articles, although this differs from the designation used by the International Telecommunication Union.® Extremely high frequency (EHF) bands (30 GHz to 300 GHz) are designated as “millimeter wave” bands.

[0047] The frequencies between FR1 and FR2 are generally referred to as mid-band frequencies. Recent 5G NR studies have identified the operating bands used for these mid-band frequencies as the frequency range designation FR3 (7.125 GHz to 24.25 GHz). Bands falling within FR3 can inherit FR1 and / or FR2 characteristics, thus effectively extending the features of FR1 and / or FR2 to mid-band frequencies. Furthermore, higher frequency bands are currently being explored to extend 5G NR operation beyond 52.6 GHz. For example, three higher operating frequency bands have been identified as the frequency range designations FR4a or FR4-1 (52.6 GHz to 71 GHz), FR4 (52.6 GHz to 114.25 GHz), and FR5 (114.25 GHz to 300 GHz). Each of these higher frequency bands falls within the EHF band.

[0048] In light of the foregoing, unless otherwise specifically stated, it should be understood that, as used herein, the term "below 6 GHz" and the like can broadly refer to frequencies less than 6 GHz, within FR1, or including intermediate frequency band frequencies. Furthermore, unless otherwise specifically stated, it should be understood that, as used herein, the term "millimeter wave" and the like can broadly refer to frequencies that can include intermediate frequency band frequencies, within FR2, FR4, FR4-a or FR4-1 and / or FR5, or within the EHF band.

[0049] In multi-carrier systems such as 5G, one of the carrier frequencies is referred to as the "primary carrier," "anchor carrier," "primary serving cell," or "PCell," and the remaining carrier frequencies are referred to as "secondary carriers," "secondary serving cells," or "SCell." In carrier aggregation, the anchor carrier is the carrier operating on the primary frequency (e.g., FR1) used by UE 104 / 182 and the cell, where UE 104 / 182 performs an initial Radio Resource Control (RRC) connection establishment procedure or initiates an RRC connection re-establishment procedure. The primary carrier carries all common and UE-specific control channels and can be a carrier on a licensed frequency (however, this is not always the case). The secondary carrier is a carrier operating on a second frequency (e.g., FR2) that can be configured and used to provide additional radio resources once an RRC connection is established between UE 104 and the anchor carrier. In some cases, the secondary carrier can be a carrier on an unlicensed frequency. Secondary carriers may contain only the necessary signaling information and signals. For example, since the primary uplink and primary downlink carriers are typically UE-specific, the UE-specific signaling information and signals may not be present in the secondary carrier. This means that different UEs 104 / 182 within a cell can have different downlink primary carriers. The same applies to the uplink primary carrier. The network can change the primary carrier of any UE 104 / 182 at any time. This is done, for example, to balance the load on different carriers. Since a "serving cell" (whether PCell or SCell) corresponds to the carrier frequency / component carrier through which a base station communicates, the terms "cell," "serving cell," "component carrier," and "carrier frequency" can be used interchangeably.

[0050] For example, still refer to Figure 1 One of the frequencies used by macro cell base station 102 can be an anchor carrier (or "PCell"), and the other frequencies used by macro cell base station 102 and / or mmW base station 180 can be secondary carriers ("SCell"). Simultaneous transmission and / or reception on multiple carriers allows UE 104 / 182 to significantly increase its data transmission and / or reception rates. For example, compared to the data rate obtained by a single 20MHz carrier, two aggregated 20MHz carriers in a multi-carrier system would theoretically result in a doubling of the data rate (i.e., 40MHz).

[0051] The wireless communication system 100 may also include a UE 164, which can communicate with the macro cell base station 102 via communication link 120 and / or with the mmW base station 180 via mmW communication link 184. For example, the macro cell base station 102 may support PCells and one or more SCells for the UE 164, and the mmW base station 180 may support one or more SCells for the UE 164.

[0052] In some cases, UE 164 and UE 182 may be able to communicate via sidelink. A sidelink-capable UE (SL-UE) can communicate with base station 102 via communication link 120 using the Uu interface (i.e., the air interface between the UE and the base station). SL-UEs (e.g., UE 164, UE 182) can also communicate directly with each other via radio sidelink 160 using the PC5 interface (i.e., the air interface between sidelink-capable UEs). Radio sidelink (or simply "sidelink") is an adaptation of core cellular network (e.g., LTE, NR) standards that allows direct communication between two or more UEs without the need for communication through a base station. Sidelink communication can be unicast or multicast and can be used for device-to-device (D2D) media sharing, vehicle-to-vehicle (V2V) communication, vehicle-to-everything (V2X) communication (e.g., cellular V2X (cV2X) communication, enhanced V2X (eV2X) communication, emergency rescue applications, etc. One or more SL-UEs in a group of SL-UEs utilizing sidelink communication may be located within the geographical coverage area 110 of base station 102. Other SL-UEs in this group may be outside the geographical coverage area 110 of base station 102, or may be unable to receive transmissions from base station 102 for other reasons. In some cases, the groups of SL-UEs communicating via sidelink communication may utilize a one-to-many (1:M) system, where each SL-UE transmits to every other SL-UE in the group. In some cases, base station 102 facilitates the scheduling of resources used for sidelink communication. In other cases, sidelink communication is performed between the individual SL-UEs without involving base station 102.

[0053] On one hand, the sidelink 160 can operate via a wireless communication medium of interest that can be shared with other vehicles and / or infrastructure access points and other RATs for wireless communication. "Medium" can include one or more time, frequency, and / or space communication resources (e.g., covering one or more channels across one or more carriers) associated with wireless communication between one or more transmitter / receiver pairs. On another hand, the medium of interest may correspond to at least a portion of unlicensed frequency bands shared among various RATs. While different licensed frequency bands have been reserved for certain communication systems (e.g., by government entities such as the U.S. Federal Communications Commission (FCC), these systems (particularly those employing small cell access points) have recently extended their operation to unlicensed National Information Infrastructure (U-NII) bands used by Wireless Local Area Network (WLAN) technologies (most notably the IEEE 802.11x WLAN technology commonly referred to as "Wi-Fi"). Example systems of this type include various variants of CDMA, TDMA, FDMA, Orthogonal FDMA (OFDMA), Single-Carrier FDMA (SC-FDMA), and so on.

[0054] It should be noted that, although Figure 1 Only two of these UEs are exemplified as SL-UEs (i.e., UE 164 and UE 182), but any UE exemplified can be an SL-UE. Furthermore, although only UE 182 is described as capable of beamforming, any UE exemplified (including UE 164) can be capable of beamforming. When SL-UEs are capable of beamforming, they can beamform towards each other (i.e., towards other SL-UEs), towards other UEs (e.g., UE 104), towards base stations (e.g., base station 102, base station 180, small cell 102', access point 150), etc. Therefore, in some cases, UE 164 and UE 182 can utilize beamforming via sidelink 160.

[0055] exist Figure 1 In the example, the UE shown (for simplicity, in) Figure 1Any UE (shown as a single UE 104) can receive signal 124 from one or more Earth-orbiting spacecraft (SV) 112 (e.g., satellites). In one aspect, SV 112 may be part of a satellite positioning system that allows UE 104 to use as an independent source of location information. Satellite positioning systems typically include a system of transmitters (e.g., SV 112) positioned such that a receiver (e.g., UE 104) can determine its location on or above the Earth based at least in part on positioning signals (e.g., signal 124) received from the transmitters. Such transmitters typically transmit signals marked with a set number of repeating pseudo-random noise (PN) codes. While typically located in SV 112, transmitters may sometimes be located at ground-based control stations, base stations 102, and / or other UEs 104. UE 104 may include one or more dedicated receivers specifically designed to receive signal 124 in order to derive geographic location information from SV 112.

[0056] In a satellite positioning system, the use of signal 124 can be enhanced by various satellite-based augmentation systems (SBAS), which may be associated with or otherwise made capable of being used with one or more global and / or regional navigation satellite systems. For example, SBAS may include augmentation systems that provide integrity information, differential correction, etc., such as Wide Area Augmentation System (WAAS), European Geosynchronous Navigation Coverage Service (EGNOS), Multifunctional Satellite Augmentation System (MSAS), GPS-assisted geographic augmentation navigation, or GPS and Geographic Augmentation Navigation System (GAGAN). Therefore, as used herein, a satellite positioning system may include any combination of one or more global and / or regional navigation satellites associated with such one or more satellite positioning systems.

[0057] On one hand, SV 112 may additionally or alternatively be part of one or more non-terrestrial networks (NTNs). In an NTN, SV 112 connects to an earth station (also referred to as a ground station, NTN gateway, or gateway), which in turn connects to elements in the 5G network, such as the modified base station 102 (without a ground antenna) or network nodes in a 5GC. This element, in turn, provides access to other elements in the 5G network and ultimately to entities outside the 5G network, such as internet web servers and other user equipment. Thus, as a replacement or supplement to communication signals from the ground base station 102, UE 104 can receive communication signals (e.g., signal 124) from SV 112.

[0058] The wireless communication system 100 may also include one or more UEs, such as UE 190, which are indirectly connected to one or more communication networks via one or more device-to-device (D2D) peer-to-peer (P2P) links (referred to as "side links"). Figure 1 In one example, UE 190 has a D2D P2P link 192 with one of UEs 104 connected to one of the base stations 102 (e.g., UE 190 can indirectly obtain cellular connectivity through this D2D P2P link), and has a D2D P2P link 194 with a WLAN STA 152 connected to a WLAN AP 150 (UE 190 can indirectly obtain WLAN-based Internet connectivity through this D2D P2P link). In one example, D2D P2P links 192 and 194 can utilize any known D2D RAT (such as LTE Direct (LTE-D), Wi-Fi Direct). ® ,Bluetooth ® (etc.) to support.

[0059] Figure 2A An example wireless network architecture 200 is illustrated. For instance, the 5GC 210 (also referred to as the Next Generation Core (NGC)) can be functionally viewed as control plane (C-plane) functions 214 (e.g., UE registration, authentication, network access, gateway selection, etc.) and user plane (U-plane) functions 212 (e.g., UE gateway functions, access to data networks, IP routing, etc.), which work together to form the core network. The user plane interface (NG-U) 213 and the control plane interface (NG-C) 215 connect the gNB 222 to the 5GC 210, specifically to user plane functions 212 and control plane functions 214, respectively. In an additional configuration, the ng-eNB 224 can also connect to the 5GC 210 via the NG-C 215 to the control plane function 214 and the NG-U 213 to the user plane function 212. Furthermore, the ng-eNB 224 can communicate directly with the gNB 222 via a backhaul connection 223. In some configurations, the next-generation RAN (NG-RAN) 220 may have one or more gNBs 222, while other configurations include one or more of both ng-eNBs 224 and gNBs 222. Either or both of the gNBs 222 or ng-eNBs 224 can communicate with one or more UEs 204 (e.g., any of the UEs described herein).

[0060] Another optional aspect may include a location server 230, which can communicate with the 5GC 210 to provide location assistance to the UE 204. The location server 230 may be implemented as multiple separate servers (e.g., physically separate servers, different software modules on a single server, different software modules distributed across multiple physical servers, etc.), or alternatively, each may correspond to a single server. The location server 230 may be configured to support one or more location services for the UE 204, which may be connected to the location server 230 via the core network, the 5GC 210, and / or via the Internet (not illustrated). Furthermore, the location server 230 may be integrated into a component of the core network, or alternatively, may be located outside the core network (e.g., a third-party server, such as an original equipment manufacturer (OEM) server or a service server).

[0061] Figure 2B Another example wireless network architecture 240.5GC 260 is illustrated (which can be used with...). Figure 2AThe 5GC 210 (corresponding to 5GC 210) can be functionally considered as a control plane function provided by the Access and Mobility Management Function (AMF) 264 and a user plane function provided by the User Plane Function (UPF) 262, which work together to form the core network (i.e., 5GC 260). The functions of AMF 264 include: registration management, connection management, reachability management, mobility management, lawful interception, transmission of session management (SM) messages between one or more UEs 204 (e.g., any of the UEs described herein) and the Session Management Function (SMF) 266, a transparent proxy service for routing SM messages, access authentication and access authorization, transmission of short message service (SMS) messages between UE 204 and the Short Message Service Function (SMSF) (not shown), and Secure Anchoring Functionality (SEAF). AMF 264 also interacts with the Authentication Server Function (AUSF) (not shown) and UE 204 and receives an intermediate key established as a result of the UE 204's authentication process. In the case of UMTS (Universal Mobile Telecommunications System) Subscriber Identity Module (USIM) authentication, AMF 264 retrieves security material from the AMF. AMF 264 also includes Security Context Management (SCM). The SCM receives a key from the SEAF and uses this key to derive an access network-specific key. AMF 264 functionality also includes location service management for regulatory services, transmission of location service messages between UE 204 and Location Management Function (LMF) 270 (which acts as location server 230), transmission of location service messages between NG-RAN 220 and LMF 270, Evolved Packet System (EPS) bearer identifier allocation for EPS interoperability, and UE 204 mobility event notification. Furthermore, AMF 264 also supports non-3GPP... ® (Third Generation Partner Program) Access network functionality.

[0062] The functions of UPF 262 include: acting as an anchor point for intra-RAT / inter-RAT mobility (where applicable), acting as an external Protocol Data Unit (PDU) session point interconnecting to a data network (not shown), providing packet routing and forwarding, packet inspection, user plane policy rule enforcement (e.g., strobing, redirection, traffic steering), lawful eavesdropping (user plane collection), traffic usage reporting, quality of service (QoS) processing for the user plane (e.g., uplink / downlink rate enforcement, reflective QoS marking in the downlink), uplink traffic verification (Service Data Flow (SDF) to QoS flow mapping), transport-level packet marking in the uplink and downlink, downlink packet buffering and downlink data notification triggering, and delivering and forwarding one or more "end markers" to the source RAN node. UPF 262 can also support the delivery of location service messages between UE 204 and location servers (such as SLP 272) on the user plane.

[0063] The functions of SMF 266 include session management, UE Internet Protocol (IP) address allocation and management, selection and control of user plane functions, service orientation configuration at UPF 262 for routing services to the correct destination, partial control of policy enforcement and QoS, and downlink data notification. The interface through which SMF 266 communicates with AMF 264 is called the N11 interface.

[0064] Another optional aspect may include an LMF 270, which can communicate with the 5GC 260 to provide location assistance to the UE 204. The LMF 270 can be implemented as multiple separate servers (e.g., physically separate servers, different software modules on a single server, different software modules distributed across multiple physical servers, etc.), or alternatively, each can correspond to a single server. The LMF 270 can be configured to support one or more location services for the UE 204, which can connect to the LMF 270 via the core network, the 5GC 260, and / or via the Internet (not illustrated). SLP 272 can support similar functions to LMF 270, but while LMF 270 can communicate with AMF 264, NG-RAN 220, and UE 204 on the control plane (e.g., using interfaces and protocols designed to deliver signaling messages rather than voice or data), SLP 272 can communicate with UE 204 and external clients (e.g., third-party server 274) on the user plane (e.g., using protocols designed to carry voice and / or data, such as Transmit Control Protocol (TCP) and / or IP).

[0065] Another optional aspect may include a third-party server 274, which can communicate with LMF 270, SLP 272, 5GC 260 (e.g., via AMF 264 and / or UPF 262), NG-RAN 220, and / or UE 204 to obtain location information (e.g., location estimation) of UE 204. Therefore, in some cases, the third-party server 274 may be referred to as a Location Services (LCS) client or an external client. The third-party server 274 may be implemented as multiple separate servers (e.g., physically separate servers, different software modules on a single server, different software modules distributed across multiple physical servers, etc.), or alternatively, each may correspond to a single server.

[0066] User plane interface 263 and control plane interface 265 connect 5GC 260, and specifically connect UPF 262 and AMF 264 to one or more gNB 222 and / or ng-eNB 224 in NG-RAN 220. The interface between gNB 222 and / or ng-eNB 224 and AMF 264 is referred to as the "N2" interface, while the interface between gNB 222 and / or ng-eNB 224 and UPF 262 is referred to as the "N3" interface. The gNB 222 and / or ng-eNB 224 of NG-RAN 220 can communicate directly with each other via backhaul connection 223, referred to as the "Xn-C" interface. One or more of gNB 222 and / or ng-eNB 224 can communicate with one or more UEs 204 via a radio interface referred to as the "Uu" interface.

[0067] The functionality of the gNB 222 is divided among the gNB Central Unit (gNB-CU) 226, one or more gNB Distributed Units (gNB-DU) 228, and one or more gNB Radio Units (gNB-RU) 229. The gNB-CU 226 is a logical node that includes base station functions other than those specifically allocated to the gNB-DU 228, including user data delivery, mobility control, radio access network sharing, location, session management, etc. More specifically, the gNB-CU 226 typically hosts the Radio Resource Control (RRC), Serving Data Adaptation Protocol (SDAP), and Packet Data Convergence Protocol (PDCP) protocols of the gNB 222. The gNB-DU 228 is a logical node that typically hosts the Radio Link Control (RLC) and Media Access Control (MAC) layers of the gNB 222. Its operation is controlled by the gNB-CU 226. One gNB-DU 228 can support one or more cells, and a cell is supported by only one gNB-DU 228. The interface 232 between gNB-CU 226 and one or more gNB-DU 228 is referred to as the "F1" interface. The physical (PHY) layer functionality of gNB 222 is typically managed by one or more independent gNB-RU 229s, which perform functions such as power amplification and signal transmission / reception. The interface between gNB-DU 228 and gNB-RU 229 is referred to as the "Fx" interface. Therefore, UE 204 communicates with gNB-CU 226 via the RRC, SDAP, and PDCP layers, with gNB-DU 228 via the RLC and MAC layers, and with gNB-RU 229 via the PHY layer.

[0068] The deployment of communication systems such as 5G NR systems can be arranged in a variety of ways using various components or parts. In a 5G NR system or network, network nodes, network entities, network mobility elements, RAN nodes, core network nodes, network elements, or network equipment (such as base stations or one or more units (or components) performing base station functions) can be implemented in aggregated or decomposed architectures. For example, base stations (such as Node B (NB), evolved NB (eNB), NR base stations, 5GNB, AP, TRP, cells, etc.) can be implemented as aggregated base stations (also known as standalone base stations or monolithic base stations) or decomposed base stations.

[0069] Aggregated base stations can be configured to utilize a radio protocol stack that is physically or logically integrated within a single RAN node. Decentralized base stations can be configured to utilize a protocol stack that is physically or logically distributed across two or more units, such as one or more central or centralized units (CUs), one or more distributed units (DUs), or one or more radio units (RUs). In some aspects, the CU can be implemented within a RAN node, and one or more DUs can be co-located with the CU, or alternatively, can be geographically or virtually distributed across one or more other RAN nodes. DUs can be implemented to communicate with one or more RUs. Each of the CU, DU, and RU can also be implemented as a virtual unit, namely a virtual central unit (VCU), a virtual distributed unit (VDU), or a virtual radio unit (VRU).

[0070] Base station type operation or network design can take into account the aggregation characteristics of base station functionality. For example, decomposed base stations can be used in Integrated Access Backhaul (IAB) networks, Open Radio Access Networks (O-RAN) (such as those developed by the O-RAN Alliance), and other similar networks. ® This can be used in proposed network configurations or virtualized radio access networks (vRAN, also known as cloud radio access networks (C-RAN)). Decomposition can include distributing functionality across two or more units in various physical locations, as well as virtually distributing the functionality of at least one unit, which allows for flexibility in network design. Various units in a decomposed base station or decomposed RAN architecture can be configured to communicate wirelessly with at least one other unit.

[0071] Figure 2C An example disaggregated base station architecture 250 according to various aspects of this disclosure is illustrated. The disaggregated base station architecture 250 may include one or more central units (CUs) 280 (e.g., gNB-CU 226) that can communicate directly with the core network 267 (e.g., 5GC 210, 5GC 260) via a backhaul link, or indirectly with the core network 267 via one or more disaggregated base station units (such as a near real-time (near-RT) RAN intelligent controller (RIC) 259 via an E2 link or a non-real-time (non-RT) RIC 257 associated with a Service Management and Orchestration (SMO) framework 255, or both). CUs 280 may communicate with one or more duplex units (DUs) 285 (e.g., gNB-DU 228) via a corresponding midhaul link (e.g., an F1 interface). DUs 285 may communicate with one or more radio units (RUs) 287 (e.g., gNB-RU 229) via a corresponding fronthaul link. RU 287 can communicate with the corresponding UE 204 via one or more radio frequency (RF) access links. In some implementations, UE 204 can be served by multiple RU 287s simultaneously.

[0072] Each of these units (i.e., CU 280, DU 285, RU 287, and near-RT RIC 259, non-RT RIC 257, and SMO frame 255) may include or be coupled to one or more interfaces configured to receive or transmit signals, data, or information (collectively, signals) via wired or wireless transmission media. Each of the units, or an associated processor or controller providing instructions to the communication interfaces of these units, may be configured to communicate with one or more other units via transmission media. For example, these units may include wired interfaces configured to receive signals or transmit signals to one or more other units via wired transmission media. Additionally, these units may include wireless interfaces that may include receivers, transmitters, or transceivers (such as RF transceivers) configured to receive signals or transmit signals to one or more other units, or both, via wireless transmission media.

[0073] In some aspects, the CU 280 can host one or more higher-level control functions. Such control functions may include RRC, PDCP, Serving Data Adaptation Protocol (SDAP), etc. Each control function can be implemented using an interface configured to communicate signaling with other control functions hosted by the CU 280. The CU 280 can be configured to handle user plane functionality (i.e., Central Unit-User Plane (CU-UP)), control plane functionality (i.e., Central Unit-Control Plane (CU-CP)), or a combination thereof. In some implementations, the CU 280 can be logically split into one or more CU-UP units and one or more CU-CP units. When implemented in an O-RAN configuration, the CU-UP units can communicate bidirectionally with the CU-CP units via an interface such as an E1 interface. The CU 280 can be implemented to communicate with the DU 285 for network control and signaling, as needed.

[0074] DU 285 may correspond to a logic unit that includes one or more base station functions for controlling the operation of one or more RU 287s. In some aspects, DU 285 may be at least partially based on functional partitioning (such as that provided by the 3rd Generation Partnership Project (3GPP)). ®The DU285 is configured to host one or more of the following functional partitions: the RLC layer, the MAC layer, and one or more high-PHY layers (such as modules for forward error correction (FEC) encoding and decoding, scrambling, modulation, and demodulation). In some respects, the DU285 may also host one or more low-PHY layers. Each layer (or module) may be implemented using an interface configured to communicate with other layers (and modules) hosted by the DU285 or with control functions hosted by the CU280.

[0075] Lower-layer functionality can be implemented by one or more RU 287s. In some deployments, an RU287 controlled by a DU 285 may correspond to a logical node that hosts RF processing functions or low-PHY layer functions (such as performing Fast Fourier Transform (FFT), Inverse FFT (iFFT), digital beamforming, Physical Random Access Channel (PRACH) extraction and filtering, or both, based at least in part on functional decomposition (such as lower-layer functional decomposition). In such architectures, the RU 287 may be implemented to handle over-the-air (OTA) communications with one or more UE 204s. In some specific implementations, the real-time and non-real-time aspects of communication with the control plane and user plane of the RU 287 may be controlled by the corresponding DU 285. In some scenarios, this configuration enables the implementation of the DU 285 and CU 280 in cloud-based RAN architectures such as vRAN architectures.

[0076] SMO framework 255 can be configured to support RAN deployment and provisioning of both non-virtualized and virtualized network elements. For non-virtualized network elements, SMO framework 255 can be configured to support the deployment of dedicated physical resources for RAN coverage requirements, which can be managed via operation and maintenance interfaces such as the O1 interface. For virtualized network elements, SMO framework 255 can be configured to interact with cloud computing platforms such as Open Cloud (O-Cloud) 269 to perform network element lifecycle management (such as instantiating virtualized network elements) via cloud computing platform interfaces such as the O2 interface. Such virtualized network elements may include, but are not limited to, CU 280, DU 285, RU 287, and near-RT RIC 259. In some implementations, SMO framework 255 can communicate with the hardware aspects of the 4G RAN (such as Open eNB (O-eNB) 261) via the O1 interface. Additionally, in some implementations, SMO framework 255 can communicate directly with one or more RU 287s via the O1 interface. SMO framework 255 may also include a non-RT RIC 257 configured to support the functionality of SMO framework 255.

[0077] The non-RT RIC 257 can be configured to include logical functions enabling non-real-time control and optimization of RAN elements and resources, including artificial intelligence / machine learning (AI / ML) workflows for model training and updates, or policy-based guidance for applications / features in the near-RT RIC 259. The non-RT RIC 257 can be coupled to or communicate with the near-RT RIC 259 (e.g., via an A1 interface). The near-RT RIC 259 can be configured to include logical functions enabling near real-time control and optimization of RAN elements and resources via data collection and actions through an interface (e.g., via an E2 interface) that connects one or more CU 280s, one or more DU 285s, or both, and O-eNBs to the near-RT RIC 259.

[0078] In some implementations, to generate AI / ML models to be deployed in the near-RT RIC 259, the non-RT RIC 257 may receive parameters or external enrichment information from an external server. This information can be utilized by the near-RT RIC 259 and can be received from non-network data sources or network functions at the SMO framework 255 or the non-RT RIC 257. In some examples, the non-RT RIC 257 or the near-RT RIC 259 may be configured to tune RAN behavior or performance. For example, the non-RT RIC 257 may monitor long-term trends and patterns in performance and employ AI / ML models to perform corrective actions via the SMO framework 255 (such as reconfiguration via O1) or by creating RAN management policies (such as A1 policies).

[0079] Figure 3A , Figure 3B and Figure 3C Examples are shown that can be incorporated into UE 302 (which may correspond to any UE described herein), base station 304 (which may correspond to any base station described herein), and network entity 306 (which may correspond to or embody any network function described herein, including location server 230 and LMF 270, or alternatively may be independent of...). Figure 2A and Figure 2BSeveral example components (represented by corresponding boxes) of the NG-RAN 220 and / or 5GC 210 / 260 infrastructure (such as private networks) depicted herein support the operation as described herein. It should be understood that these components may be implemented in different specific implementations in different types of devices (e.g., in ASICs, in System-on-Chip (SoCs), etc.). The illustrated components may also be incorporated into other devices in a communication system. For example, other devices in the system may include components similar to those described as providing similar functionality. Furthermore, a given device may contain one or more of these components. For example, a device may include multiple transceiver components that enable the device to operate on multiple carriers and / or communicate via different technologies.

[0080] UE 302 and base station 304 each include one or more Wireless Wide Area Network (WWAN) transceivers 310 and 350, which provide components (e.g., components for transmitting, components for receiving, components for measuring, components for tuning, components for blocking transmission, etc.) for communication via one or more wireless communication networks (not shown), such as NR networks, LTE networks, GSM networks, etc. WWAN transceivers 310 and 350 may each be connected to one or more antennas 316 and 356 for communication with other network nodes (such as other UEs, access points, base stations (e.g., eNB, gNB), etc.) via at least one designated RAT (e.g., NR, LTE, GSM, etc.) through a wireless communication medium of interest (e.g., a time / frequency resource set in a specific spectrum). WWAN transceivers 310 and 350 can be configured in various ways, according to a specified RAT, to transmit and encode signals 318 and 358 (e.g., messages, indications, information, etc.), and conversely, to receive and decode signals 318 and 358 (e.g., messages, indications, information, pilots, etc.). Specifically, WWAN transceivers 310 and 350 each include: one or more transmitters 314 and 354 for transmitting and encoding signals 318 and 358, respectively; and one or more receivers 312 and 352 for receiving and decoding signals 318 and 358, respectively.

[0081] In at least some cases, UE 302 and base station 304 each further include one or more short-range wireless transceivers 320 and 360, respectively. Short-range wireless transceivers 320 and 360 can be connected to one or more antennas 326 and 366, respectively, and provide access over a wireless communication medium of interest via at least one designated RAT (e.g., Wi-Fi, LTE Direct, Bluetooth). ® ZIGBEE ® Z-WAVE ® Components for communicating with other network nodes (such as other UEs, access points, base stations, etc.) including PC5, Dedicated Short-Range Communication (DSRC), Wireless Access for Vehicle Environments (WAVE), Near Field Communication (NFC), Ultra-Wideband (UWB), etc. These components include (e.g., components for transmitting, components for receiving, components for measuring, components for tuning, components for blocking transmission, etc.). Short-range transceivers 320 and 360 can be configured in various ways according to a specified RAT to transmit and encode signals 328 and 368 (e.g., messages, indications, information, etc.), and conversely, to receive and decode signals 328 and 368 (e.g., messages, indications, information, pilots, etc.). Specifically, the short-range wireless transceiver 320 and short-range wireless transceiver 360 each include: one or more transmitters 324 and 364 respectively for transmitting and encoding signals 328 and 368, and one or more receivers 322 and 362 respectively for receiving and decoding signals 328 and 368. As a specific example, the short-range wireless transceiver 320 and short-range wireless transceiver 360 can be Wi-Fi transceivers, Bluetooth transceivers, etc. ® Transceiver, Zigbee ® and / or Z-WAVE ® Transceivers, NFC transceivers, UWB transceivers, or vehicle-to-vehicle (V2V) and / or vehicle-to-everything (V2X) transceivers.

[0082] In at least some cases, UE 302 and base station 304 also include satellite signal interfaces 330 and 370, each satellite signal interface including one or more satellite signal receivers 332 and 372, and optionally including one or more satellite signal transmitters 334 and 374, respectively. In some cases, base station 304 may be a terrestrial base station that can communicate with a spacecraft (e.g., spacecraft 112) via satellite signal interface 370. In other cases, base station 304 may be a spacecraft (or other non-terrestrial entity) that uses satellite signal interface 370 to communicate with terrestrial networks and / or other spacecraft.

[0083] Satellite signal receivers 332 and 372 can be connected to one or more antennas 336 and 376, respectively, and can provide components for receiving and / or measuring satellite positioning / communication signals 338 and 378, respectively. When satellite signal receivers 332 and 372 are satellite positioning system receivers, satellite positioning / communication signals 338 and 378 can be Global Positioning System (GPS) signals, Global Navigation Satellite System (GLONASS) signals, Galileo signals, BeiDou signals, Indian Regional Navigation Satellite System (NAVIC), Quasi-Zenith Satellite System (QZSS) signals, etc. When satellite signal receivers 332 and 372 are non-terrestrial network (NTN) receivers, satellite positioning / communication signals 338 and 378 can be communication signals originating from a 5G network (e.g., carrying control and / or user data). Satellite signal receivers 332 and 372 can include any suitable hardware and / or software for receiving and processing satellite positioning / communication signals 338 and 378, respectively. Satellite signal receivers 332 and 372 may request appropriate information and operations from other systems, and in at least some cases, use measurements obtained by any suitable satellite positioning system algorithm to perform calculations to determine the locations of UE 302 and base station 304, respectively.

[0084] Optional satellite signal transmitters 334 and 374 (when present) can be connected to one or more antennas 336 and 376, respectively, and can be provided with components for transmitting satellite positioning / communication signals 338 and 378, respectively. When satellite signal transmitter 374 is a satellite positioning system transmitter, the satellite positioning / communication signal 378 can be a GPS signal, GLONASS signal, etc. ® Signals include Galileo signals, BeiDou signals, NAVIC signals, and QZSS signals. When satellite signal transmitters 334 and 374 are NTN transmitters, satellite positioning / communication signals 338 and 378 can be communication signals originating from a 5G network (e.g., carrying control and / or user data). Satellite signal transmitters 334 and 374 can include any suitable hardware and / or software for transmitting satellite positioning / communication signals 338 and 378, respectively. Satellite signal transmitters 334 and 374 can request appropriate information and operations from other systems.

[0085] Base station 304 and network entity 306 each include one or more network transceivers 380 and 390, which provide components (e.g., transmitting components, receiving components, etc.) for communicating with other network entities (e.g., other base stations 304, other network entities 306). For example, base station 304 may use one or more network transceivers 380 to communicate with other base stations 304 or network entities 306 via one or more wired or wireless backhaul links. Similarly, network entity 306 may use one or more network transceivers 390 to communicate with one or more base stations 304 via one or more wired or wireless backhaul links, or to communicate with other network entities 306 via one or more wired or wireless core network interfaces.

[0086] Transceivers can be configured to communicate via wired or wireless links. A transceiver (whether wired or wireless) includes transmitter circuitry (e.g., transmitters 314, 324, 354, 364) and receiver circuitry (e.g., receivers 312, 322, 352, 362). In some embodiments, the transceiver may be an integrated device (e.g., implementing transmitter and receiver circuitry in a single device), in some embodiments it may include separate transmitter and receiver circuitry, or in other embodiments it may be implemented in a different manner. The transmitter and receiver circuitry of a wired transceiver (e.g., network transceiver 380 and network transceiver 390 in some embodiments) may be coupled to one or more wired network interface ports. Wireless transmitter circuitry (e.g., transmitters 314, 324, 354, 364) may include or be coupled to multiple antennas (e.g., antennas 316, 326, 356, 366), such as an antenna array, which allows the corresponding device (e.g., UE 302, base station 304) to perform transmit beamforming, as described herein. Similarly, wireless receiver circuitry (e.g., receivers 312, 322, 352, 362) may include or be coupled to multiple antennas (e.g., antennas 316, 326, 356, 366), such as an antenna array, which allows the corresponding device (e.g., UE 302, base station 304) to perform receive beamforming, as described herein. In one aspect, the transmitter and receiver circuitry may share the same multiple antennas (e.g., antennas 316, 326, 356, 366), such that the corresponding device may perform only receive or only transmit at a given time, rather than both receive and transmit simultaneously. Wireless transceivers (e.g., WWAN transceivers 310 and 350, short-range wireless transceivers 320 and 360) may also include network listening modules (NLMs) for performing various measurements.

[0087] As used herein, various wireless transceivers (e.g., transceivers 310, 320, 350, and 360 in some specific embodiments, and network transceivers 380 and 390) and wired transceivers (e.g., network transceivers 380 and 390 in some specific embodiments) may generally be described as "transceiver," "at least one transceiver," or "one or more transceivers." Therefore, whether a particular transceiver is a wired or wireless transceiver can be inferred from the type of communication performed. For example, backhaul communication between network devices or servers typically involves signaling via a wired transceiver, while wireless communication between a UE (e.g., UE 302) and a base station (e.g., base station 304) will typically involve signaling via a wireless transceiver.

[0088] UE 302, base station 304, and network entity 306 also include other components that can be used in conjunction with the operation disclosed herein. UE 302, base station 304, and network entity 306 each include one or more processors 342, 384, and 394 for providing functionality related to, for example, wireless communication, and for providing other processing functionality. Thus, processors 342, 384, and 394 may provide components for processing, such as components for determining, components for calculating, components for receiving, components for transmitting, components for indicating, etc. In one aspect, processors 342, 384, and 394 may include, for example, one or more general-purpose processors, multi-core processors, central processing units (CPUs), ASICs, digital signal processors (DSPs), field-programmable gate arrays (FPGAs), other programmable logic devices or processing circuits, or various combinations thereof.

[0089] UE 302, base station 304, and network entity 306 each include memory circuitry implementing memories 340, 386, and 396 (e.g., each including a memory device) for maintaining information (e.g., information indicating reserved resources, thresholds, parameters, etc.). Therefore, memories 340, 386, and 396 can provide components for storage, retrieval, maintenance, etc. In some cases, UE 302, base station 304, and network entity 306 may each include NAS modules 348, 388, and 398. NAS modules 348, 388, and 398 may be hardware circuitry that is part of or coupled to processors 342, 384, and 394, respectively, which, when executed, enable UE 302, base station 304, and network entity 306 to perform the functionality described herein. In other aspects, NAS modules 348, 388, and 398 may be external to processors 342, 384, and 394 (e.g., part of a modem processing system, integrated with another processing system, etc.). Alternatively, NAS modules 348, 388 and 398 may be memory modules stored in memories 340, 386 and 396 respectively, which enable UE 302, base station 304 and network entity 306 to perform the functionality described herein when executed by processors 342, 384 and 394 (or modem processing system, another processing system, etc.). Figure 3A The possible locations of the NAS module 348 are illustrated. The NAS module may be part of, for example, one or more WWAN transceivers 310, memory 340, one or more processors 342 or any combination thereof, or it may be a standalone component. Figure 3B The possible locations of NAS module 388 are illustrated. The NAS module may be part of, for example, one or more WWAN transceivers 350, memory 386, one or more processors 384 or any combination thereof, or it may be a standalone component. Figure 3C The possible locations of NAS module 398 are illustrated. The NAS module may be part of, for example, one or more network transceivers 390, memory 396, one or more processors 394 or any combination thereof, or it may be a standalone component.

[0090] UE 302 may include one or more sensors 344 coupled to one or more processors 342 to provide components for sensing or detecting motion and / or orientation information independent of motion data derived from signals received by one or more WWAN transceivers 310, one or more short-range wireless transceivers 320, and / or satellite signal interfaces 330. By way of example, sensor 344 may include accelerometers (e.g., microelectromechanical systems (MEMS) devices), gyroscopes, geomagnetic sensors (e.g., compasses), altimeters (e.g., barometric altimeters), and / or any other type of motion detection sensor. Furthermore, sensor 344 may include multiple different types of devices and combine their outputs to provide motion information. For example, sensor 344 may use a combination of multi-axis accelerometers and orientation sensors to provide the ability to calculate positioning in two-dimensional (2D) and / or three-dimensional (3D) coordinate systems.

[0091] In addition, UE 302 includes a user interface 346 that provides components for providing instructions to a user (e.g., audible and / or visual instructions) and / or for receiving user input (e.g., when the user actuates a sensing device such as a keypad, touchscreen, microphone, etc.). Although not shown, base station 304 and network entity 306 may also include user interfaces.

[0092] Referring more specifically to one or more processors 384, in the downlink, IP packets from network entity 306 can be provided to processor 384. One or more processors 384 can implement functionality for the RRC layer, Packet Data Convergence Protocol (PDCP) layer, RLC layer, and MAC layer. One or more processors 384 may provide: RRC layer functionality associated with broadcasting system information (e.g., Master Information Block (MIB), System Information Block (SIB)), RRC connection control (e.g., RRC connection paging, RRC connection establishment, RRC connection modification, and RRC connection release), inter-RAT mobility, and measurement configuration for UE measurement reporting; PDCP layer functionality associated with header compression / decompression, security (encryption, decryption, integrity protection, integrity verification), and handover support functions; RLC layer functionality associated with the delivery of upper-layer PDUs, error correction via Automatic Repeat Request (ARQ), concatenation, segmentation, and reassembly of RLC Service Data Units (SDUs), resegmentation of RLC data PDUs, and reordering of RLC data PDUs; and MAC layer functionality associated with mapping between logical channels and transport channels, scheduling information reporting, error correction, priority processing, and logical channel priority ordering.

[0093] Transmitter 354 and receiver 352 implement Layer 1 (L1) functionality associated with various signal processing functions. Layer 1, including the physical (PHY) layer, may include: error detection on the transport channel, forward error correction (FEC) decoding / decoding of the transport channel, interleaving, rate matching, mapping to the physical channel, modulation / demodulation of the physical channel, and MIMO antenna processing. Transmitter 354 processes the mapping to the signal constellation based on various modulation schemes (e.g., binary phase shift keying (BPSK), quadrature phase shift keying (QPSK), M-phase shift keying (M-PSK), M-quadrature amplitude modulation (M-QAM)). The decoded and modulated symbols can then be split into parallel streams. Each stream can then be mapped to orthogonal frequency division multiplexing (OFDM) subcarriers, multiplexed with a reference signal (e.g., pilot) in the time and / or frequency domains, and then combined using inverse fast Fourier transform (IFFT) to produce a physical channel carrying a stream of time-domain OFDM symbols. The OFDM symbol stream is spatially pre-decoded to generate multiple spatial streams. Channel estimates from a channel estimator can be used to determine the decoding and modulation scheme, as well as for spatial processing. These channel estimates can be derived from a reference signal transmitted by UE 302 and / or channel condition feedback. Each spatial stream can then be provided to one or more different antennas 356. Transmitter 354 can use the corresponding spatial stream to modulate an RF carrier for transmission.

[0094] At UE 302, receiver 312 receives signals via its corresponding antenna 316. Receiver 312 recovers the information modulated onto the RF carrier and provides this information to one or more processors 342. Transmitter 314 and receiver 312 implement Layer 1 functionality associated with various signal processing functions. Receiver 312 can perform spatial processing on the information to recover any spatial stream destined for UE 302. If multiple spatial streams are destined for UE 302, they can be combined by receiver 312 into a single OFDM symbol stream. Receiver 312 then uses a Fast Fourier Transform (FFT) to transform the OFDM symbol stream from the time domain to the frequency domain. The frequency domain signal includes a separate OFDM symbol stream for each subcarrier of the OFDM signal. The symbols on each subcarrier, along with the reference signal, are recovered and demodulated by determining the most probable signal constellation points transmitted by base station 304. These soft decisions can be based on channel estimates calculated by a channel estimator. The soft decisions are then decoded and deinterleaved to recover the data and control signals originally transmitted by base station 304 on the physical channel. Then, data and control signals are provided to one or more processors 342, which implement layer 3 (L3) and layer 2 (L2) functionality.

[0095] In the downlink, one or more processors 342 provide demultiplexing, packet reassembly, decryption, header decompression, and control signal processing between the transport and logical channels to recover IP packets from the core network. One or more processors 342 are also responsible for error detection.

[0096] Similar to the functionality described in conjunction with downlink transmissions performed by base station 304, one or more processors 342 provide: RRC layer functionality associated with system information (e.g., MIB, SIB) acquisition, RRC connectivity, and measurement reporting; PDCP layer functionality associated with header compression / decompression and security (encryption, decryption, integrity protection, integrity verification); RLC layer functionality associated with the delivery of upper-layer PDUs, error correction via ARQ, concatenation, segmentation, and reassembly of RLC SDUs, resegmentation of RLC data PDUs, and reordering of RLC data PDUs; and MAC layer functionality associated with mapping between logical channels and transport channels, multiplexing of MAC SDUs onto transport blocks (TBs), demultiplexing of MAC SDUs from TBs, scheduling information reporting, error correction via Hybrid Automatic Repeat Request (HARQ), priority processing, and logical channel priority ordering.

[0097] The channel estimate derived by the channel estimator from the reference signal or feedback transmitted by the base station 304 can be used by the transmitter 314 to select an appropriate decoding and modulation scheme and facilitate spatial processing. The spatial stream generated by the transmitter 314 can be provided to different antennas 316. The transmitter 314 can use the corresponding spatial stream to modulate the RF carrier for transmission.

[0098] Uplink transmissions are processed at base station 304 in a manner similar to that described in conjunction with the receiver function at UE 302. Receiver 352 receives signals via its corresponding antenna 356. Receiver 352 recovers the information modulated onto the RF carrier and provides this information to one or more processors 384.

[0099] In the uplink, one or more processors 384 provide demultiplexing, packet reassembly, decryption, header decompression, and control signal processing between the transport channel and the logical channel to recover IP packets from UE 302. IP packets from one or more processors 384 can be provided to the core network. One or more processors 384 are also responsible for error detection.

[0100] For convenience, UE 302, base station 304 and / or network entity 306 are in Figure 3A , Figure 3B and Figure 3CThe document is shown as including various components that can be configured according to the various examples described herein. However, it should be understood that the illustrated components may have different functionalities in different designs. In particular, Figures 3A to 3C Various components are optional in alternative configurations, and various aspects include configurations that can vary due to design choices, cost, equipment usage, or other considerations. For example, in Figure 3A In certain cases, specific implementations of UE 302 may omit WWAN transceiver 310 (e.g., wearable devices, tablets, personal computers (PCs), or laptops may have Wi-Fi and / or Bluetooth). ® (Without cellular capability), or the short-range wireless transceiver 320 can be omitted (e.g., cellular only), or the satellite signal interface 330 can be omitted, or the sensor 344 can be omitted, etc. In another example, in Figure 3B In certain cases, specific implementations of base station 304 may omit WWAN transceiver 350 (e.g., a Wi-Fi "hotspot" access point without cellular capabilities), or short-range wireless transceiver 360 (e.g., cellular only), or satellite signal interface 370, etc. For the sake of brevity, examples of various alternative configurations are not provided herein, but will be readily understood by those skilled in the art.

[0101] Various components of UE 302, base station 304, and network entity 306 can be communicatively coupled to each other via data buses 308, 382, ​​and 392, respectively. In one aspect, data buses 308, 382, ​​and 392 can form or be part of the communication interfaces of UE 302, base station 304, and network entity 306, respectively. For example, in cases where different logical entities are embodied in the same device (e.g., gNB and location server functionality integrated into the same base station 304), data buses 308, 382, ​​and 392 can provide communication between these logical entities.

[0102] Figure 3A , Figure 3B and Figure 3C The components can be implemented in various ways. In some specific implementations, Figure 3A , Figure 3B and Figure 3CThe components can be implemented in one or more circuits, such as, for example, one or more processors and / or one or more ASICs (which may include one or more processors). Here, each circuit may use and / or combine at least one memory component for storing information or executable code used by the circuit to provide that functionality. For example, some or all of the functionalities represented by blocks 310 to 346 may be implemented by the processor and memory components of UE 302 (e.g., by executing appropriate code and / or by appropriate configuration of the processor components). Similarly, some or all of the functionalities represented by blocks 350 to 388 may be implemented by the processor and memory components of base station 304 (e.g., by executing appropriate code and / or by appropriate configuration of the processor components). Moreover, some or all of the functionalities represented by blocks 390 to 398 may be implemented by the processor and memory components of network entity 306 (e.g., by executing appropriate code and / or by appropriate configuration of the processor components). For simplicity, various operations, actions, and / or functions are described herein as being performed "by the UE," "by the base station," "by the network entity," etc. However, it should be understood that such operations, actions and / or functions can actually be performed by specific components or combinations of components of the UE 302, base station 304, network entity 306, etc. (such as processors 342, 384, 394, transceivers 310, 320, 350 and 360, memory 340, 386 and 396, NAS modules 348, 388 and 398, etc.).

[0103] In some designs, network entity 306 may be implemented as a core network component. In other designs, network entity 306 may operate differently from the network operator or cellular network infrastructure (e.g., NG RAN 220 and / or 5GC 210 / 260). For example, network entity 306 may be a component of a private network that can be configured to communicate with UE 302 via base station 304 or independently of base station 304 (e.g., via a non-cellular communication link such as Wi-Fi).

[0104] Non-terrestrial networks (NTNs) involve communication with satellite vehicles (SVs), drones, manned or unmanned aerial vehicles, balloons, or other non-terrestrial transceivers, all of which may be referred to herein as NTN base stations (BSs). In densely populated areas globally, both terrestrial networks (TNs) and NTNs may be available for UEs. In some areas surrounding the globe (such as oceans), TN infrastructure is absent, in which case the NTN may be the only network available for the UE. Regardless of TN availability, NTN BS transceivers typically cover a much larger geographical area than TN base station transceivers, and current NTN regulations require, for example, verification of the UE's location before allowing UE access to the NTN. Location information requires confidentiality protection for privacy (e.g., preventing eavesdroppers from determining the UE's location), integrity protection for tamper resistance (e.g., preventing attackers from spoofing the UE's location to the core network), and replay protection (e.g., preventing attackers from participating in replay attacks).

[0105] However, some Control Plane (CP)-only Cellular Internet of Things (CIoT) UEs do not support Access Layer (AS) security protocols, and therefore the NTN Radio Access Network (RAN) lacks secure means to verify the location of those types of UEs, thus preventing CPUEs from connecting to the NTN. Therefore, it is desirable to provide a mechanism through which UEs can confidentially and securely provide their location information to the NTN RAN.

[0106] Therefore, this paper proposes techniques for UE location verification in NTN. In some aspects, existing Non-Access Stratum (NAS) mechanisms are utilized to control UE access to the NTN network without using AS security mechanisms and without requiring changes to existing NAS protocols. In other aspects, NAS mechanisms can also be employed to protect Radio Resource Control (RRC) messages that the NTN BS may want to transmit to UEs that are permitted or will be permitted to access the NTN.

[0107] Figure 4 This is a signaling and event diagram 400 illustrating the existing mechanism used by the Long Term Evolution (LTE) UE 402 to recover from a Radio Link Failure (RLF) condition (e.g., by selecting a new cell from the same or a different eNB). Figure 4 The example illustrates the interaction between UE 402, RAN source eNB 404, RAN target eNB 406, and core network (CN) nodes (such as Mobility Management Entity (MME) 408). Generally, the UE and MME communicate with each other using NAS messages, and the eNB and MME communicate with each other using the S1 Application Protocol (S1-AP), which can be used to transmit NAS messages or other types of messages.

[0108] exist Figure 4 In the example shown, at box 410, UE 402 is authenticated to the network and NAS security is established. For example, UE 402 and MME 408 can use protected NAS messages to establish a NAS security context based on the Evolved Packet System (EPS) Authentication and Key Agreement (AKA) process. Data can also be transmitted via NAS. Figure 4 In the example shown, UE 402 and MME 408 communicate with each other via source eNB 404.

[0109] At box 412, UE 402 detects a failure in the radio link between itself and the source eNB 404 and selects a new eNB. When an RLF occurs, UE 402 can authenticate itself to a new target (e.g., target eNB 406) via the MME.

[0110] As shown in box 414, the Access Layer (AS) portion of UE 402 triggers the NAS portion of UE 402 to create a two-part NAS Message Authentication Code (NAS-MAC) using the NAS security context stored within UE 402: the first 16 bits include an uplink MAC value (UL_NAS_MAC), which is used by the UE to authenticate itself to the target eNB 406, and the last 16 bits include an expected downlink MAC value (XDL_NAS_MAC), which is used by the target eNB 406 to authenticate itself to UE 402. In some respects, UE 402 can compute UL_NAS_MAC and XDL_NAS_MAC using the following inputs with the currently used NAS integrity algorithm: K as the key. NASint The UE 402's AS portion calculates the NAS-MAC by taking the uplink NAS COUNT (used for the next uplink NAS message), the DIRECTION bit (set to 0), and the target cell ID (as part of the message to be protected). The UE 402's AS portion then sends the UL_NAS_MAC value along with the UE identifier (such as the UE's Serving Temporary Mobile Subscriber Identity (S-TMSI)) to the target eNB 406, for example, signal 416. Figure 4 The example shown is an RRC connection re-establishment request message. The target eNB 406 can use S-TMSI to determine the MME with which the target eNB 406 should communicate, for example... Figure 4 MME 408 in the middle.

[0111] exist Figure 4In the example shown, the target eNB 406 forwards the S-TMSI and UL_NAS_MAC values ​​to the MME 408, for example, signal 418. At box 420, the MME 408 uses the NAS security context stored on the MME 408 (which should match the NAS security context stored on the UE 402) to calculate the NAS-MAC and verifies that the UL_NAS_MAC value is correct for the UE 402. If verification is successful, as in this example, the MME 408 transmits the XDL_NAS_MAC value to the target eNB 406, for example, signal 422, which is an indication that the UE 402 has been verified to the target eNB 406. From this point onward, the target eNB 406 will allow the UE 402 to access. If verification in box 420 fails, the MME 408 instructs the target eNB 406 to release the connection to the UE 402.

[0112] The target eNB 406 forwards the XDL_NAS_MAC value to the UE 402, for example, signal 424, which is Figure 4 The example shown is an RRC connection re-establishment response message. At box 426, UE 402 verifies that the XDL_NAS_MAC value it received from the target eNB 406 is correct. In this way, UE 402 and the target eNB 406 can mutually authenticate each other, and UE 402 is granted access to the RAN via the target eNB 406.

[0113] Figure 5 The signaling and event diagram 500 illustrates a process according to various aspects of this disclosure, through which the UE 502 can connect to the NTN and optionally receive protected RRC information. Figure 5 The interaction between UE 502, TN RAN source eNB 504, NTN RAN target eNB 506 and core network nodes (such as MME 508 for 4G or Access and Mobility Management Function (AMF) for 5G) is illustrated.

[0114] exist Figure 5 In the example shown, at box 510, UE 502 is authenticated to the terrestrial network and NAS security is established. For example, UE 502 and MME 508 can use protected NAS messages based on the EPS AKA procedure to establish a NAS security context. Data can also be transmitted via NAS.

[0115] exist Figure 5In the example shown, at box 512, UE 502 selects an NTN node, such as the target eNB 506. This could be because UE 502 has lost connectivity with a TN node and / or cannot find a suitable TN node, and therefore decides to connect to, for example, an available NTN. Figure 5 In the example shown, UE 502 is subject to regulatory requirements prohibiting UEs from joining the NTN unless their geographic location can be verified. Therefore, at box 514, UE 502 uses at least a portion of its existing NAS security context (such as a UL NAS count value, a NAS encryption key, a NAS security key, or a combination thereof) to encrypt its location information (which may be coarse location information at this time). It should be understood that UE 502 may provide its geographic location for any reason, regardless of whether such information is required by regulations or otherwise.

[0116] The NAS security context protects UE location information in several ways. For example, an uplink NAS count is consumed for protection and incremented, preventing replay attacks; the UE location information is encrypted, not sent in plaintext; and the selected NAS security algorithm provides integrity protection for the UE location information, preventing some attacks by detecting breaches of message modifications during transit. For instance, if the MME 508 has identified that the uplink NAS count used for encryption is not greater than the latest uplink NAS count stored as part of the UE's NAS security context, the MME may refuse to decrypt the encrypted location information.

[0117] exist Figure 5 In the example shown, UE 502 sends a Radio Resource Control (RRC) Connection Request message, e.g., signal 516, to target eNB 506. Figure 5 In the example shown, in addition to the NAS message, the RRC connection request message also includes a ULNAS count and encrypted UE location information. The NAS message may include a Tracking Area Update (TAU) message, data on the NAS message, or other types of NAS messages. The NAS message includes a UE identifier (e.g., the S-TMSI value assigned to UE 502) along with UL_NAS_MAC and UL NAS count values. The MME uses at least a portion of the UE identifier (e.g., the MME code (MMEC) portion of the S-TMSI) to identify UE 502 and retrieve its security context.

[0118] However, it should be noted that the UL NAS count embedded within the NAS message differs from the UL NAS count included in the RRC connection request message outside the NAS message. Specifically, the step of encrypting the UE location information using the NAS security context consumes the UL NAS count; for example, assuming the UL NAS count is X when the UE location information is encrypted, the UL NAS count will be incremented to X+1 when it is used to protect the NAS message later included in the RRC connection request message. Therefore, the RRC connection request message will include a UL NAS count field indicating the value X, and the NAS message will contain a UL NAS count field indicating the value X+1, as shown below. Figure 5 As shown, signal 516.

[0119] exist Figure 5 In the example shown, the target eNB 506 transmits the UE identifier S-TMSI, the UL NAS count value used to encrypt the UE location information, and the encrypted UE location information, such as signal 518, which is an S1-AP message, to the MME 508. However, the target eNB 506 does not forward the NAS message until the UE's location has been verified.

[0120] In some respects, the target eNB 506 may also want to provide RRC information to the UE 502, for example, to provide configuration information to the UE 502, and the target eNB 506 may further want to protect (via encryption, integrity protection, or both) this configuration information. In this case, the target eNB 506 may optionally request the MME 508 to protect the DL RRC information using the NAS security context. In this case, the target eNB 506 may optionally include the RRC information for the MME 508 to encrypt and protect using the security context of the UE 502 within signal 518, for example, as a DL RRC information protection request transmitted to the MME 508 along with encrypted UE location information.

[0121] At block 520, MME 508 verifies and decrypts the encrypted UE location information. If verification is successful, MME 508 updates the uplink NAS count in the UE's NAS security context using the received uplink NAS count value, and then transmits the decrypted UE location information to the target eNB 506, for example, signal 522. In some aspects, if the RRC target eNB 506 has requested DL RRC information protection, MME 508 may optionally use the current DL NAS count value to protect the RRC information at block 520, and include the DL NAS count value along with the protected RRC information in signal 522. MME 508 then increments the DL NAS count and stores the DL NAS count as the current DL NAS count as part of the UE NAS security context.

[0122] At box 524, the target eNB 506 determines, at least in part, whether UE 502 is allowed access to the NTN RAN based on UE location information. If UE 502 is allowed access, the target eNB 506 forwards the NAS message to the MME 508, e.g., signal 526, and the MME 508 processes the NAS message and performs the remainder of the process, e.g., calculating the NAS-MAC, etc. Figure 4 Elements 420, 422, 424, and 426 exemplify a mechanism that enables UE 502 and MME 508 to mutually authenticate each other, and UE 502 is granted access to the RAN via target eNB 506. In some aspects, if MME 508 encrypts the RRC information at block 520 and provides the encrypted RRC information and DL NAS count to target eNB 506 in signal 522, target eNB 506 can, for example, forward the encrypted RRC information and DL NAS count to UE 502 in optional signal 528. UE 502 can then use the DL NAS count value received in optional signal 528 to authenticate and decrypt the received RRC information.

[0123] It should be noted that the same process can be used for 5G, but with AMF instead of MME.

[0124] Figure 6 The signaling and event diagram 600 illustrates the process according to various aspects of this disclosure, through which the UE 602 can connect to the NTN and also change the MME. Figure 6 The interaction between UE 602, NTN RAN target eNB 604 and two core network nodes (target MME 606 and source MME 608) is illustrated.

[0125] exist Figure 6In the example shown, at box 610, UE 602 is authenticated to the terrestrial network and NAS security is established. For example, UE 602 and the source MME 608 can use protected NAS messages based on the EPS AKA procedure to establish a NAS security context. Data can also be transmitted over the NAS.

[0126] exist Figure 6 In the example shown, at box 612, UE 602 selects an NTN node, such as target eNB 604, and at box 614, UE 602 uses its existing NAS security context to encrypt the location information (which may be coarse location information at this time).

[0127] exist Figure 6 In the example shown, UE 602 sends an RRC connection request message to target eNB 604, for example, signal 616. Figure 6 In the example shown, in addition to the NAS message, the RRC connection request message also includes a UL NAS count and encrypted UE location information. In some aspects, the NAS message may include a TAU message, data on the NAS message, or other types of NAS messages. Although Figure 6 It is not shown in the diagram, but the NAS message includes the UE identifier (e.g., the S-TMSI value assigned to UE 602) along with the UL_NAS_MAC and UL NAS count values.

[0128] exist Figure 6 In the example shown, NTN access is associated with an MME change. The target eNB 604 transmits the UE identifier S-TMSI, a UL NAS count value used to encrypt the UE location information, and encrypted UE location information, such as signal 618, which is an S1-AP message, to the target MME 606. However, the target eNB 604 does not forward the NAS message until the UE's location has been verified.

[0129] Because the target MME 606 does not yet have the security context of UE 602, the target MME 606 cannot decrypt the UE location information it received in the RRC connection request message (i.e., signal 516). Therefore, in Figure 6 In the example shown, the target MME 606 obtains assistance from the source MME 608, and the target MME 606 can identify this assistance using at least a portion of the UE ID (such as the MME code (MMEC) portion of the S-TMSI). Figure 6 In the example shown, the target MME 606 forwards the S-TMSI, UL NAS count, and encrypted UE location information to the source MME 608, for example, signal 620.

[0130] At box 622, the source MME 608 verifies and decrypts the encrypted UE location information. If verification is successful, the source MME 608 updates the uplink NAS count value in the UE's NAS security context using the received uplink NAS count value. The source MME 608 then transmits the decrypted UE location information to the target MME 606, for example, signal 624.

[0131] In some respects, such as when the source MME 608 can determine, based on the decrypted location information, that UE 602 will be allowed access to the NTN, the source MME 608 may optionally pass the security context of UE 602 to the target MME 606, for example, by including the security context in signal 624. If the source MME 608 is not yet able to make that determination, the source MME 608 may choose not to pass the security context of UE 602 at this time.

[0132] exist Figure 6 In the example shown, the target MME 606 forwards the decrypted UE location information to the target eNB 604, for example, signal 626. At box 628, the target eNB 604 determines, at least in part, that UE 602 is allowed access based on the UE location information and releases the NAS message (e.g., signal 626) to the target MME 606, and the rest of the process continues as normal.

[0133] It should be understood that Figure 5 The optional steps shown, related to the target eNB requesting that the MME protect the RRC information, the MME protecting the RRC information and transmitting it to the target eNB, and the target eNB forwarding the protected RRC information, can also be optionally implemented as follows: Figure 6 This is performed as part of the illustrated procedure. Optional RRC information protection may be performed by the source MME (when the RRC information is provided in signal 620), or by the target MME after it retrieves the UE security context from the source MME.

[0134] Figure 7 This is a flowchart of an example process 700 associated with NAS-based UE location verification in an NTN, based on various aspects of this disclosure. In some specific implementations, Figure 7 One or more process frames can be executed by the UE (e.g., UE 104). In some specific implementations, Figure 7 One or more process frames may be executed by another device or a group of devices, separate from or including the UE. Additionally or alternatively, Figure 7One or more process blocks may be executed by one or more components of UE 302 (such as processor 332, memory 340, WWAN transceiver 310, short-range wireless transceiver 320, satellite signal receiver 330, sensor 344, user interface 346, and NAS module 348), any or all of these components may be parts for performing the operation of process 700.

[0135] like Figure 7 As shown, process 700 may include encrypting the UE's location information using a portion of the NAS security context at block 710 to create encrypted UE location information. Components used to perform the operation of block 710 may include the UE 302's processor 332, memory 340, or WWAN transceiver 310. For example, the UE 302 may use the processor 332 and memory 340 to encrypt the UE's location information.

[0136] like Figure 7 As shown, process 700 may further include transmitting a connection request to the NTN BS at block 720. This connection request includes a first UL NAS count value, encrypted UE location information, and a NAS message including a UE identifier, a NAS message authentication code, and a second UL NAS count value. Components used to perform the operation of block 720 may include the processor 332, memory 340, or WWAN transceiver 310 of the UE 302. For example, the UE 302 may use transmitter 314 to transmit the connection request.

[0137] like Figure 7 As shown, process 700 may also include receiving a connection response from the NTN BS at block 730. Components used to perform the operation of block 730 may include the processor 332, memory 340, or WWAN transceiver 310 of UE 302. For example, UE 302 uses receiver 312 to receive the connection response.

[0138] In some respects, this part of the NAS security context includes the first UL NAS count value, the NAS encryption key, the NAS security key, or a combination thereof.

[0139] In some respects, connection requests include RRC connection request messages.

[0140] In some respects, the connection response indicates that the UE is allowed to access the NTN BS.

[0141] In some aspects, process 700 also includes: receiving DL NAS counts and encrypted RRC configuration information from NTN BS; using the DL NAS counts to decrypt the encrypted RRC configuration information to obtain the decrypted RRC configuration information; and configuring the UE based on the decrypted RRC configuration information.

[0142] Process 700 may include additional embodiments, such as those described below and / or any single embodiment or any combination of embodiments described in conjunction with one or more other processes described elsewhere herein. Although Figure 7 An example block for process 700 is shown, but in some specific implementations, it differs from... Figure 7 Compared to the boxes depicted, process 700 may include additional boxes, fewer boxes, different boxes, or boxes arranged in a different manner. Additionally or alternatively, two or more boxes in process 700 may be executed in parallel.

[0143] Figure 8 This is a flowchart of an example process 800 associated with NAS-based UE location verification in an NTN, based on various aspects of this disclosure. In some specific implementations, Figure 8 One or more process frames can be executed by a non-terrestrial network base station (e.g., non-terrestrial network base station 102). In some specific implementations, Figure 8 One or more process frames may be executed by another device or a group of devices, separate from or including the non-terrestrial network base station. Additionally or alternatively, Figure 8 One or more process frames may be executed by one or more components of BS 304 (such as processor 384, memory 386, WWAN transceiver 350, short-range wireless transceiver 360, satellite signal receiver 370, network transceiver 380, and NAS module 388), any or all of these components may be parts for performing the operations of process 800.

[0144] like Figure 8 As shown, process 800 may include receiving a connection request from the UE at block 810. This connection request includes a first ULNAS count value, encrypted UE location information, and a NAS message including a UE identifier, a NAS message authentication code, and a second UL NAS count value. Components for performing the operation of block 810 may include the processor 384, memory 386, or WWAN transceiver 350 of the BS 304. For example, a non-terrestrial network base station 304 may use a receiver 352 to receive the connection request.

[0145] like Figure 8 As further shown, process 800 may include transmitting a UE identifier, a first UL NAS count value, and encrypted UE location information to the CN node at block 820. Components for performing the operation of block 820 may include a processor 384, a memory 386, or a WWAN transceiver 350 of the BS 304. For example, a non-terrestrial network base station 304 may use a transmitter 354 to transmit the UE identifier, the first UL NAS count value, and encrypted UE location information.

[0146] like Figure 8 As further shown, process 800 may include receiving decrypted UE location information from the CN node at block 830. Components used to perform the operation of block 830 may include the processor 384, memory 386, or WWAN transceiver 350 of the BS 304. For example, the non-terrestrial network base station 304 may use receiver 352 to receive the decrypted UE location information.

[0147] like Figure 8 As further shown, process 800 may include determining, at block 840, whether the UE is allowed or not allowed access based at least on the UE location information. Components for performing the operation of block 840 may include the processor 384, memory 386, or WWAN transceiver 350 of the BS 304. For example, the non-terrestrial network base station 304 may use the processor 384 to determine whether the UE is allowed or not allowed access.

[0148] like Figure 8 As further shown, process 800 may include transmitting a connection response to the UE at block 850, the connection response indicating whether the UE is allowed or denied access. Components for performing the operation of block 850 may include the processor 384, memory 386, or WWAN transceiver 350 of the BS 304. For example, a non-terrestrial network base station 304 may use transmitter 354 to transmit the connection response.

[0149] In some respects, process 800 includes forwarding the NAS message to the CN node when it is determined that the UE is allowed access.

[0150] In some aspects, process 800 includes transmitting RRC configuration information to the CN node and receiving DL NAS counting and encrypted RRC configuration information from the CN node.

[0151] In some respects, process 800 includes forwarding DL NAS counts and encrypted RRC configuration information to the UE when it is determined that the UE is allowed access.

[0152] Process 800 may include additional embodiments, such as those described below and / or any single embodiment or any combination of embodiments described in conjunction with one or more other processes described elsewhere herein. Although Figure 8 An example box for process 800 is shown, but in some specific implementations, it differs from... Figure 8 Compared to the boxes depicted, process 800 may include additional boxes, fewer boxes, different boxes, or boxes arranged in a different manner. Additionally or alternatively, two or more boxes in the process 800 may be executed in parallel.

[0153] Figure 9This is a flowchart of an example process 900 associated with NAS-based UE location verification in an NTN, based on various aspects of this disclosure. In some specific implementations, Figure 9 One or more process frames can be executed by a network entity 306, which may be a CN node (e.g., MME 508, target MME 606, source MME 608). In some specific implementations, Figure 9 One or more process frames may be executed by another device or a group of devices, either separate from or including the CN node. Additionally or alternatively, Figure 9 One or more process frames may be executed by one or more components of the device (such as a processor, memory, or transceiver), and any or all of these components may be parts for performing the operations of process 900.

[0154] like Figure 9 As shown, process 900 may include receiving a UE identifier, a UL NAS count value, and encrypted UE location information from an NTN BS at block 910. Components used to perform the operation of block 910 may include a processor, memory, or transceiver of any of the devices described herein. For example, a CN node may use network transceiver 390 to receive the UE identifier, UL NAS count value, and encrypted UE location information.

[0155] like Figure 9 As further shown, process 900 may include determining decrypted UE location information from encrypted UE location information at block 920. Components used to perform the operation of block 920 may include a processor, memory, or transceiver of any of the devices described herein. For example, a CN node may use processor 394 to determine decrypted UE location information from encrypted UE location information.

[0156] like Figure 9 As further shown, process 900 may include transmitting decrypted UE location information to the NTN BS at block 930. Components used to perform the operation of block 930 may include a processor, memory, or transceiver of any of the devices described herein. For example, a CN node may use network transceiver 390 to transmit the decrypted UE location information.

[0157] In some respects, CN nodes include MME or AMF.

[0158] In some respects, determining the decrypted UE location information from the encrypted UE location information includes: decrypting the encrypted UE location information based at least on the ULNAS count value.

[0159] In some aspects, process 900 includes: identifying the UE's NAS security context based on the UE identifier, and updating the UL NAS count value within the NAS security context using the UL NAS count value received from the NTN BS.

[0160] In some aspects, determining the decrypted UE location information from the encrypted UE location information includes: determining a second CN node that maintains the NAS security context of the UE based on the UE identifier, transmitting the UE identifier, UL NAS count value and encrypted UE location information to the second CN node, and receiving the decrypted UE location information from the second CN node.

[0161] In some respects, process 900 includes: receiving the UE's NAS security context from the second CN node, and storing the NAS security context.

[0162] In some respects, the second CN node includes MME or AMF.

[0163] In some aspects, process 900 includes: receiving RRC configuration information directly or indirectly from NTN BS, encrypting the RRC configuration information to create encrypted RRC configuration information, and transmitting the encrypted RRC configuration information directly or indirectly to NTN BS.

[0164] Process 900 may include additional embodiments, such as those described below and / or any single embodiment or any combination of embodiments described in conjunction with one or more other processes described elsewhere herein. Although Figure 9 An example block for process 900 is shown, but in some specific implementations, it differs from... Figure 9 Compared to the boxes depicted, process 900 may include additional boxes, fewer boxes, different boxes, or boxes arranged in a different manner. Additionally or alternatively, two or more boxes in process 900 may be executed in parallel.

[0165] As can be seen in the detailed description above, different features are grouped together in the examples. This manner of disclosure should not be construed as an intention to have more features than those explicitly mentioned in each clause. Rather, the various aspects of this disclosure may include fewer features than those in the individual example clauses disclosed. Therefore, the following clauses should be regarded accordingly as incorporated into the description, where each clause may serve as a separate example. Although each dependent clause may refer in the clause to a specific combination with one of the other clauses, the aspect of that dependent clause is not limited to that specific combination. It should be understood that other example clauses may also include combinations of aspects of a dependent clause with the subject matter of any other dependent or independent clause, or combinations of any feature with other dependent and independent clauses. The various aspects disclosed herein explicitly include these combinations unless explicitly stated or readily inferred that a particular combination is not intended for use (e.g., contradictory aspects, such as defining an element as both an electrical insulator and an electrical conductor). Furthermore, it is contemplated that aspects of a clause may be included in any other independent clause, even if that clause does not directly depend on the independent clause.

[0166] Specific implementation examples are described in the following numbered clauses:

[0167] Clause 1. A method of wireless communication performed by a user equipment (UE), the method comprising: encrypting location information of the UE using a portion of a non-access stratum (NAS) security context to create encrypted UE location information; transmitting a connection request to a non-terrestrial network (NTN) base station (BS), the connection request including a first uplink (UL) NAS count value, the encrypted UE location information, and a NAS message including a UE identifier, a NAS message authentication code, and a second UL NAS count value; and receiving a connection response from the NTN BS.

[0168] Clause 2. The method according to Clause 1, wherein the portion of the NAS security context includes the first UL NAS count value, the NAS encryption key, the NAS integrity key, or a combination thereof.

[0169] Clause 3. The method according to any one of Clauses 1 to 2, wherein the connection request includes a Radio Resource Control (RRC) connection request message.

[0170] Clause 4. The method according to any one of Clauses 1 to 3, wherein the connection response indicates that the UE is permitted to access the NTN BS.

[0171] Clause 5. The method according to any one of Clauses 1 to 4, the method further comprising: receiving downlink (DL) NAS counts and encrypted RRC configuration information from the NTN BS; using the DL NAS counts to decrypt the encrypted RRC configuration information to obtain decrypted RRC configuration information; and configuring the UE according to the decrypted RRC configuration information.

[0172] Clause 6. A method of wireless communication performed by a non-terrestrial network (NTN) base station (BS), the method comprising: receiving a connection request from a user equipment (UE), the connection request including a first uplink (UL) NAS count value, encrypted UE location information, and a NAS message including a UE identifier, a NAS message authentication code, and a second UL NAS count value; transmitting the UE identifier, the first UL NAS count value, and the encrypted UE location information to a core network (CN) node; receiving decrypted UE location information from the CN node; determining, at least based on the UE location information, whether the UE is allowed or not allowed to access; and transmitting a connection response to the UE indicating whether the UE is allowed or not allowed to access.

[0173] Clause 7. The method according to Clause 6, the method further comprising: forwarding the NAS message to the CN node when it is determined that the UE is allowed access.

[0174] Clause 8. The method according to any one of Clauses 6 to 7, the method further comprising: transmitting Radio Resource Control (RRC) configuration information to the CN node; and receiving downlink (DL) NAS counting and encrypted RRC configuration information from the CN node.

[0175] Clause 9. The method according to Clause 8, the method further comprising: forwarding the DL NAS count and the encrypted RRC configuration information to the UE when it is determined that the UE is allowed access.

[0176] Clause 10. A method of wireless communication performed by a core network (CN) node, the method comprising: receiving a UE identifier, an uplink (UL) non-access stratum (NAS) count value, and encrypted UE location information from a non-terrestrial network (NTN) base station (BS); determining decrypted UE location information from the encrypted UE location information; and transmitting the decrypted UE location information to the NTN BS.

[0177] Clause 11. The method according to Clause 10, wherein the CN node includes a Mobility Management Entity (MME) or an Access and Mobility Management Function (AMF).

[0178] Clause 12. The method according to any one of Clauses 10 to 11, wherein determining the decrypted UE location information from the encrypted UE location information comprises: decrypting the encrypted UE location information based at least on the UL NAS count value, the NAS encryption key, the NAS security key, or a combination thereof.

[0179] Clause 13. The method according to Clause 12, the method further comprising: identifying a NAS security context of a UE based on the UE identifier; and updating the UL NAS count value within the NAS security context using the UL NAS count value received from the NTN BS.

[0180] Clause 14. The method according to any one of Clauses 10 to 13, wherein determining the decrypted UE location information from the encrypted UE location information comprises: determining a second CN node that maintains the NAS security context of the UE based on the UE identifier; transmitting the UE identifier, the UL NAS count value, and the encrypted UE location information to the second CN node; and receiving the decrypted UE location information from the second CN node.

[0181] Clause 15. The method according to Clause 14, the method further comprising: receiving the NAS security context of the UE from the second CN node; and storing the NAS security context.

[0182] Clause 16. The method according to any one of Clauses 14 to 15, wherein the second CN node includes a Mobility Management Entity (MME) or an Access and Mobility Management Function (AMF).

[0183] Clause 17. The method according to any one of Clauses 10 to 16, the method further comprising: receiving radio resource control (RRC) configuration information directly or indirectly from the NTN BS; encrypting the RRC configuration information to create encrypted RRC configuration information; and transmitting the encrypted RRC configuration information directly or indirectly to the NTN BS.

[0184] Clause 18. A user equipment (UE) comprising: one or more memories; one or more transceivers; and one or more processors communicatively coupled to the one or more memories and the one or more transceivers, the one or more processors being individually or in combination configured to: encrypt location information of the UE using a portion of a Non-Access Stratum (NAS) security context to create encrypted UE location information; transmit a connection request via the one or more transceivers to a non-terrestrial network (NTN) base station (BS), the connection request including a first uplink (UL) NAS count value, the encrypted UE location information, and a NAS message including a UE identifier, a NAS message authentication code, and a second UL NAS count value; and receive a connection response from the NTN BS via the one or more transceivers.

[0185] Clause 19. The UE as described in Clause 18, wherein the portion of the NAS security context includes the first UL NAS count value, the NAS encryption key, the NAS security key, or a combination thereof.

[0186] Clause 20. The UE pursuant to any one of Clauses 18 to 19, wherein the connection request includes a Radio Resource Control (RRC) connection request message.

[0187] Clause 21. A UE pursuant to any one of Clauses 18 to 20, wherein the connection response indicates that the UE is permitted to access the NTN BS.

[0188] Clause 22. The UE according to any one of Clauses 18 to 21, wherein the one or more processors are further configured individually or in combination to: receive downlink (DL) NAS counts and encrypted RRC configuration information from the NTN BS via the one or more transceivers; decrypt the encrypted RRC configuration information using the DL NAS counts to obtain decrypted RRC configuration information; and configure the UE according to the decrypted RRC configuration information.

[0189] Clause 23. The UE pursuant to any one of Clauses 18 to 22, wherein the UE includes CP-only cellular Internet of Things (CIoT) devices.

[0190] Clause 24. A non-terrestrial network base station (NTN BS) comprising: one or more memories; one or more transceivers; and one or more processors communicatively coupled to the one or more memories and the one or more transceivers, the one or more processors being individually or in combination configured to: receive a connection request from a user equipment (UE) via the one or more transceivers, the connection request including a first uplink (UL) NAS count value, encrypted UE location information, and a NAS message including a UE identifier, a NAS message authentication code, and a second UL NAS count value; transmit the UE identifier, the first UL NAS count value, and the encrypted UE location information to a core network (CN) node via the one or more transceivers; receive decrypted UE location information from the CN node via the one or more transceivers; determine, at least based on the UE location information, whether the UE is allowed or not allowed to access; and transmit a connection response to the UE via the one or more transceivers indicating whether the UE is allowed or not allowed to access.

[0191] Clause 25. The NTN BS as described in Clause 24, wherein the one or more processors are further configured individually or in combination to forward the NAS message to the CN node when it is determined that the UE is allowed access.

[0192] Clause 26. The NTN BS according to any one of Clauses 24 to 25, wherein the one or more processors are further configured individually or in combination to: transmit Radio Resource Control (RRC) configuration information to the CN node via the one or more transceivers; and receive downlink (DL) NAS counting and encrypted RRC configuration information from the CN node via the one or more transceivers.

[0193] Clause 27. The CN node as described in Clause 26, wherein the one or more processors are further configured individually or in combination to forward the DL NAS count and the encrypted RRC configuration information to the UE when it is determined that the UE is allowed access.

[0194] Clause 28. A core network (CN) node comprising: one or more memories; one or more transceivers; and one or more processors communicatively coupled to the one or more memories and the one or more transceivers, the one or more processors being individually or in combination configured to: receive a UE identifier, an uplink (UL) non-access stratum (NAS) count value, and encrypted UE location information from a non-terrestrial network (NTN) base station (BS) via the one or more transceivers; determine decrypted UE location information from the encrypted UE location information; and transmit the decrypted UE location information to the NTN BS via the one or more transceivers.

[0195] Clause 29. The CN node as described in Clause 28, wherein the CN node includes a Mobility Management Entity (MME) or an Access and Mobility Management Function (AMF).

[0196] Clause 30. A CN node according to any one of Clauses 28 to 29, wherein, in order to determine the decrypted UE location information from the encrypted UE location information, the one or more processors are individually or in combination configured to: decrypt the encrypted UE location information based at least on the UL NAS count value, the NAS encryption key, the NAS security key, or a combination thereof.

[0197] Clause 31. The CN node according to Clause 30, wherein the one or more processors are further configured individually or in combination to: identify the NAS security context of the UE based on the UE identifier; and update the UL NAS count value within the NAS security context using the UL NAS count value received from the NTNBS.

[0198] Clause 32. A CN node according to any one of Clauses 28 to 31, wherein, in order to determine the decrypted UE location information from the encrypted UE location information, the one or more processors are individually or in combination configured to: determine a second CN node maintaining the NAS security context of the UE based on the UE identifier; transmit the UE identifier, the UL NAS count value, and the encrypted UE location information to the second CN node via the one or more transceivers; and receive the decrypted UE location information from the second CN node via the one or more transceivers.

[0199] Clause 33. The CN node according to Clause 32, wherein the one or more processors are further configured individually or in combination to: receive the NAS security context of the UE from the second CN node via the one or more transceivers; and store the NAS security context.

[0200] Clause 34. A CN node pursuant to any one of Clauses 32 to 33, wherein the second CN node comprises a Mobility Management Entity (MME) or an Access and Mobility Management Function (AMF).

[0201] Clause 35. A CN node according to any one of Clauses 28 to 34, wherein the one or more processors are further configured individually or in combination to: receive Radio Resource Control (RRC) configuration information from the NTN BS via the one or more transceivers; encrypt the RRC configuration information to create encrypted RRC configuration information; and transmit the encrypted RRC configuration information to the NTN BS via the one or more transceivers.

[0202] Those skilled in the art will understand that information and signals can be represented using any of a variety of different techniques and arts. For example, data, instructions, commands, information, signals, bits, symbols, and chips that may be mentioned throughout the above description can be represented by voltage, current, electromagnetic waves, magnetic fields or magnetic particles, light fields or optical particles, or any combination thereof.

[0203] Furthermore, those skilled in the art will understand that the various exemplary logic blocks, modules, circuits, and algorithm steps described in connection with the aspects disclosed herein can be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability between hardware and software, various exemplary components, blocks, modules, circuits, and steps have been described above in general terms of their functionality. Whether such functionality is implemented as hardware or software depends on the specific application and the design constraints imposed on the overall system. Those skilled in the art may implement the described functionality in different ways for each specific application, but such specific implementation decisions should not be construed as departing from the scope of this disclosure.

[0204] The various exemplary logic blocks, modules, and circuits described in conjunction with the aspects disclosed herein may be implemented or performed using a general-purpose processor, a digital signal processor (DSP), an ASIC, a field-programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic components, discrete hardware components, or any combination thereof designed to perform the functions described herein. The general-purpose processor may be a microprocessor, but in alternative embodiments, the processor may be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors combined with a DSP core, or any other such configuration.

[0205] The methods, sequences, and / or algorithms described in conjunction with the aspects disclosed herein may be embodied directly in hardware, in a software module executed by a processor, or a combination of both. The software module may reside in random access memory (RAM), flash memory, read-only memory (ROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), registers, hard disks, removable disks, CD-ROMs, or any other form of storage medium known in the art. Example storage media are coupled to a processor such that the processor can read information from and write information to the storage medium. Alternatively, the storage medium may be integral with the processor. The processor and storage medium may reside in an ASIC. The ASIC may reside in a user terminal (e.g., a UE). Alternatively, the processor and storage medium may reside as discrete components in the user terminal.

[0206] In one or more examples, the described functionality may be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functionality may be stored as one or more instructions or code on or transmitted via a computer-readable medium. A computer-readable medium includes both computer storage media and communication media, which includes any medium that facilitates the transfer of a computer program from one place to another. A storage medium may be any available medium accessible to a computer. By way of example and not limitation, such computer-readable media may include RAM, ROM, EEPROM, CD-ROM or other optical disc storage, disk storage or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and is accessible to a computer. Furthermore, any connection is appropriately referred to as a computer-readable medium. For example, if the software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included within the definition of a medium. As used herein, disks and optical discs include: compact optical discs (CDs), laser discs, optical discs, digital versatile discs (DVDs), floppy disks, and Blu-ray discs. Disks typically reproduce data magnetically, while optical discs reproduce data optically using lasers. Combinations of these should also be included within the scope of computer-readable media.

[0207] While the foregoing disclosure illustrates exemplary aspects of this disclosure, it should be noted that various changes and modifications may be made herein without departing from the scope of this disclosure as defined by the appended claims. For example, the functions, steps, and / or actions of the method claims according to aspects of this disclosure described herein need not be performed in any particular order. Furthermore, no component, function, action, or instruction described or claimed herein should be construed as critical or essential unless explicitly stated otherwise. Additionally, as used herein, the terms “set,” “group,” etc., are intended to include one or more of the stated elements. Furthermore, as used herein, the terms “having,” “comprising,” “including,” etc., do not exclude the presence of one or more additional elements (e.g., element “having” A may also have B). Furthermore, the phrase “based on” is intended to mean “at least partially based on” unless otherwise explicitly stated. Furthermore, as used herein, the term “or” is intended to be open-ended when used in a series and is interchangeable with “and / or” unless otherwise explicitly stated (e.g., if used in conjunction with “any” or “only one”), or these alternatives are mutually exclusive (e.g., “one or more” should not be interpreted as “one and more”). Additionally, although components, functions, actions, and instructions may be described or claimed in the singular, plural forms may also be considered unless explicitly stated to be limited to the singular. Therefore, as used herein, the articles “a,” “an,” “the,” and “described” are intended to include one or more of the stated elements. Additionally, as used herein, the terms “at least one” and “one or more” include “one” component, function, action, or instruction that performs or is capable of performing the described or claimed functionality, and also include “two or more” components, functions, actions, or instructions that perform or are capable of performing the described or claimed functionality in combination.

Claims

1. A method for wireless communication performed by a user equipment (UE), the method comprising: The location information of the UE is encrypted using a portion of the Non-Access Layer (NAS) security context to create encrypted UE location information; A connection request is transmitted to a non-terrestrial network (NTN) base station (BS), the connection request including a first uplink (UL) NAS count value, encrypted UE location information, and a NAS message including a UE identifier, a NAS message authentication code, and a second UL NAS count value; as well as Receive a connection response from the NTN BS.

2. The method of claim 1, wherein the portion of the NAS security context includes the first ULNAS count value, the NAS encryption key, the NAS integrity key, or a combination thereof.

3. The method of claim 1, wherein the connection request includes a Radio Resource Control (RRC) connection request message.

4. The method of claim 1, wherein the connection response indicates that the UE is permitted to access the NTN BS.

5. The method according to claim 1, further comprising: Receive downlink (DL) NAS count and encrypted RRC configuration information from the NTN BS; The encrypted RRC configuration information is decrypted using the DL NAS count to obtain the decrypted RRC configuration information; as well as Configure the UE based on the decrypted RRC configuration information.

6. A method for wireless communication performed by a non-terrestrial network (NTN) base station (BS), the method comprising: A connection request is received from the user equipment (UE), the connection request including a first uplink (UL) NAS count value, encrypted UE location information, and a NAS message including a UE identifier, a NAS message authentication code, and a second UL NAS count value; The UE identifier, the first UL NAS count value, and the encrypted UE location information are transmitted to the core network (CN) node. Receive decrypted UE location information from the CN node; At least based on the UE location information, it is determined whether the UE is allowed or not to access the network; as well as A connection response indicating whether the UE is allowed or not allowed to access is transmitted to the UE.

7. The method according to claim 6, further comprising: When it is determined that the UE is allowed to access, the NAS message is forwarded to the CN node.

8. The method according to claim 6, further comprising: Transmit Radio Resource Control (RRC) configuration information to the CN node; as well as Receive downlink (DL) NAS counts and encrypted RRC configuration information from the CN node.

9. The method according to claim 8, further comprising: When it is determined that the UE is allowed access, the DLNAS count and the encrypted RRC configuration information are forwarded to the UE.

10. A method for wireless communication performed by a core network (CN) node, the method comprising: Receive UE identifier, uplink (UL) non-access stratum (NAS) count value and encrypted UE location information from non-terrestrial network (NTN) base station (BS); Determine the decrypted UE location information from the encrypted UE location information; as well as The decrypted UE location information is transmitted to the NTN BS.

11. The method of claim 10, wherein the CN node comprises a Mobility Management Entity (MME) or an Access and Mobility Management Function (AMF).

12. The method of claim 10, wherein determining the decrypted UE location information from the encrypted UE location information comprises: The encrypted UE location information is decrypted based at least on the UL NAS count value, the NAS encryption key, the NAS security key, or a combination thereof.

13. The method according to claim 12, further comprising: The UE's NAS security context is identified based on the UE identifier; And update the UL NAS count value within the NAS security context using the UL NAS count value received from the NTN BS.

14. The method of claim 10, wherein determining the decrypted UE location information from the encrypted UE location information comprises: The second CN node that maintains the NAS security context of the UE is determined based on the UE identifier; The UE identifier, the UL NAS count value, and the encrypted UE location information are transmitted to the second CN node; as well as Receive the decrypted UE location information from the second CN node.

15. The method according to claim 14, further comprising: Receive the NAS security context of the UE from the second CN node; as well as Store the NAS security context.

16. The method of claim 14, wherein the second CN node comprises a Mobility Management Entity (MME) or an Access and Mobility Management Function (AMF).

17. The method according to claim 10, further comprising: Receive Radio Resource Control (RRC) configuration information directly or indirectly from the NTN BS; The RRC configuration information is encrypted to create encrypted RRC configuration information; as well as The encrypted RRC configuration information is transmitted directly or indirectly to the NTN BS.

18. A user equipment (UE), the user equipment (UE) comprising: One or more memory units; One or more transceivers; and One or more processors, communicatively coupled to one or more memories and one or more transceivers, wherein the one or more processors are configured individually or in combination to: The location information of the UE is encrypted using a portion of the Non-Access Layer (NAS) security context to create encrypted UE location information; A connection request is transmitted to a non-terrestrial network (NTN) base station (BS) via the one or more transceivers. The connection request includes a first uplink (UL) NAS count value, encrypted UE location information, and a NAS message including a UE identifier, a NAS message authentication code, and a second UL NAS count value. as well as Receive connection response from the NTN BS via the one or more transceivers.

19. The UE of claim 18, wherein the portion of the NAS security context includes the first ULNAS count value, the NAS encryption key, the NAS integrity key, or a combination thereof.

20. The UE of claim 18, wherein the connection request includes a Radio Resource Control (RRC) connection request message.

21. The UE of claim 18, wherein the connection response indicates that the UE is permitted to access the NTN BS.

22. The UE of claim 18, wherein the one or more processors are further configured individually or in combination to: Receive downlink (DL) NAS counts and encrypted RRC configuration information from the NTN BS via the one or more transceivers; The encrypted RRC configuration information is decrypted using the DL NAS count to obtain the decrypted RRC configuration information; and Configure the UE based on the decrypted RRC configuration information.

23. The UE of claim 18, wherein the UE includes a control plane only (CP) cellular Internet of Things (CIoT) device.

24. A non-terrestrial network base station (NTN BS), the non-terrestrial network base station (NTN BS) comprising: One or more memory units; One or more transceivers; and One or more processors, communicatively coupled to one or more memories and one or more transceivers, wherein the one or more processors are configured individually or in combination to: A connection request is received from a user equipment (UE) via the one or more transceivers. The connection request includes a first uplink (UL) NAS count value, encrypted UE location information, and a NAS message including a UE identifier, a NAS message authentication code, and a second UL NAS count value. The UE identifier, the first UL NAS count value, and the encrypted UE location information are transmitted to the core network (CN) node via the one or more transceivers. Receive decrypted UE location information from the CN node via the one or more transceivers; At least based on the UE location information, it is determined whether the UE is allowed or not to access the network; as well as A connection response indicating whether the UE is allowed or not allowed to access is transmitted to the UE via the one or more transceivers.

25. The NTN BS of claim 24, wherein the one or more processors are further configured individually or in combination to forward the NAS message to the CN node when it is determined that the UE is allowed access.

26. The NTN BS of claim 24, wherein the one or more processors are further configured individually or in combination to: Transmit Radio Resource Control (RRC) configuration information to the CN node via the one or more transceivers; and Receive downlink (DL) NAS counts and encrypted RRC configuration information from the CN node via the one or more transceivers.

27. The NTN BS of claim 26, wherein the one or more processors are further configured individually or in combination to forward the DL NAS count and the encrypted RRC configuration information to the UE when it is determined that the UE is allowed access.

28. A core network (CN) node, the core network (CN) node comprising: One or more memory units; One or more transceivers; and One or more processors, communicatively coupled to one or more memories and one or more transceivers, wherein the one or more processors are configured individually or in combination to: Receive UE identifier, uplink (UL) non-access stratum (NAS) count value and encrypted UE location information from non-terrestrial network (NTN) base station (BS) via the one or more transceivers; Determine the decrypted UE location information from the encrypted UE location information; as well as The decrypted UE location information is transmitted to the NTN BS via the one or more transceivers.

29. The CN node of claim 28, wherein the CN node comprises a Mobility Management Entity (MME) or an Access and Mobility Management Function (AMF).

30. The CN node of claim 28, wherein, in order to determine the decrypted UE location information from the encrypted UE location information, the one or more processors are individually or in combination configured to: decrypt the encrypted UE location information based at least on the UL NAS count value, the NAS encryption key, the NAS integrity key, or a combination thereof.

31. The CN node of claim 30, wherein the one or more processors are further configured individually or in combination to: identify the NAS security context of the UE based on the UE identifier; and update the UL NAS count value within the NAS security context using the UL NAS count value received from the NTN BS.

32. The CN node of claim 28, wherein, in order to determine the decrypted UE location information from the encrypted UE location information, the one or more processors are configured individually or in combination to: The second CN node that maintains the NAS security context of the UE is determined based on the UE identifier; The UE identifier, the UL NAS count value, and the encrypted UE location information are transmitted to the second CN node via the one or more transceivers. as well as The decrypted UE location information is received from the second CN node via the one or more transceivers.

33. The CN node of claim 32, wherein the one or more processors are further configured individually or in combination to: Receive the NAS security context of the UE from the second CN node via the one or more transceivers; and Store the NAS security context.

34. The CN node of claim 32, wherein the second CN node comprises a Mobility Management Entity (MME) or an Access and Mobility Management Function (AMF).

35. The CN node of claim 28, wherein the one or more processors are further configured individually or in combination to: Receive Radio Resource Control (RRC) configuration information from the NTN BS via the one or more transceivers; The RRC configuration information is encrypted to create encrypted RRC configuration information; and The encrypted RRC configuration information is transmitted to the NTN BS via the one or more transceivers.