Detecting impaired wireless and backhaul nodes and releasing their resources

CN122534701APending Publication Date: 2026-08-07NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NOKIA TECHNOLOGIES OY
Filing Date
2026-02-03
Publication Date
2026-08-07

Smart Images

  • Figure CN122534701A_ABST
    Figure CN122534701A_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to detecting a compromised wireless and backhaul node and releasing its resources. An apparatus and method for a communication network are provided. The method can comprise sending, via a wireless and backhaul (WAB) node, a non-access stratum (NAS) message to an access and mobility management function (AMF) of a serving network of a UE; receiving, from the serving network, at least one message comprising an indication that a compromised WAB node is detected; and causing, based on the at least one message, a handover from the WAB node to a wireless network node to be performed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure generally relates to communication networks. More specifically, this disclosure relates to a method, apparatus, system, and computer program for detecting compromised wireless and backhaul (WAB) nodes and releasing resources associated with the compromised WAB nodes. Background Technology universal background

[0002] Mobile telecommunications networks or cell networks (often referred to as communication networks in this document) enable communication between two or more communication devices, provide communication devices with access to data networks, deliver services provided by third-party applications to communication devices, or provide services provided by the communication network to communication devices.

[0003] Communication networks and equipment can operate according to cell technologies (also known as radio access technologies), such as GSM, UTMS, LTE, LTE-A, and NR. Cell technologies are standardized by various standards organizations, such as the 3rd Generation Partnership Project (3GPP) or ETSI (European Telecommunications Standards Institute). 3GPP is currently developing fifth-generation cell technology standards (commonly referred to as 5G or NR standards) and sixth-generation cell technology standards (commonly referred to as 6G standards). Communication networks operating according to 5G or NR standards are generally called 5G networks, while communication networks operating according to 6G standards are generally called 6G networks.

[0004] Communication networks (e.g., 5G or 6G networks) include access networks (e.g., radio access networks), which can wirelessly communicate with one or more communication devices by sharing the available resources (e.g., bandwidth, transmit power, etc.) of the access network. Communication networks can also establish reliable and secure connections between communication devices and the core network of the communication network via the access network. Communication networks (e.g., 5G networks) can provide communication devices with enhanced mobile broadband services (e.g., telephony, video, data, and short message services), ultra-reliable low-latency communication services (e.g., XR services), or massive machine-type communication services.

[0005] Improvements to communication networks are desirable. Summary of the Invention

[0006] This disclosure relates to detecting compromised wireless and backhaul (WAB) nodes and releasing resources associated with compromised WAB nodes.

[0007] According to a first aspect of this disclosure, an apparatus (for a communication network) is provided, the apparatus including at least one processor; and at least one memory storing instructions for an access and mobility management function (AMF), which, when executed by the at least one processor, cause the apparatus to perform operations including: receiving a non-access stratum (NAS) message from a user equipment (UE) via a radio and backhaul (WAB) node; receiving information indicating the operational state of the WAB node; and instructing the WAB node to be powered off based on the information, thereby causing resources allocated to the WAB node to be released.

[0008] In some embodiments, receiving the information indicating the operational status of the WAB node includes receiving the information indicating the operational status of the WAB node from the UE's operation, management and maintenance entity.

[0009] In some embodiments, receiving information indicating the operational status of a WAB node includes receiving information indicating the operational status of a WAB node from an application function entity of the UE.

[0010] In some embodiments, receiving information indicating the operational status of a WAB node includes: sending a query request to the UE's unified data repository, including an identifier associated with the WAB node; and receiving information indicating the operational status of the WAB node from the unified data repository.

[0011] In some embodiments, receiving information indicating the operational status of a WAB node includes: sending a data retrieval request, including an identifier associated with the WAB node, to a wireless network node; and receiving information indicating the operational status of the WAB node from the wireless network node.

[0012] In some embodiments, receiving information indicating the operational status of a WAB node includes: sending a request to the UE's unified data repository to subscribe to information indicating the operational status of a WAB node; and receiving information indicating the operational status of a WAB node from the unified data repository.

[0013] In some embodiments, receiving information indicating the operational status of a WAB node includes: sending a request to the UE's Authentication and Key Management Function (AUSF) including an identifier associated with the WAB node; and receiving an authentication result associated with the operational status of the WAB node from the AUSF.

[0014] In some embodiments, receiving information indicating the operational status of a WAB node includes: sending a request to the UE's Authentication and Key Management Function (AUSF) to subscribe to an authentication result associated with the operational status of the WAB node; and receiving the authentication result of the operational status of the WAB node from the AUSF.

[0015] In some embodiments, instructing the WAB node to be in a shutdown state based on the information to cause the release of resources allocated to the WAB node includes: determining that the WAB node is damaged based on the information indicating that the WAB node is in a shutdown state; and causing the release of resources allocated to the WAB node based on the determination that the WAB node is damaged.

[0016] In some embodiments, instructing the WAB node to be in a powered-off state based on the information to cause the resources allocated to the WAB node to be released includes: instructing the WAB node to be in a powered-off state based on the information to initiate a Protocol Data Unit (PDU) session release for the UE.

[0017] In some embodiments, initiating a PDU session release for the UE based on the information indicating that the WAB node is in a powered-off state includes sending a PDU session release request to the Session Management Function (SMF) serving the UE, the PDU session release request including the UE's identifier and an indication of the damaged WAB node.

[0018] In some embodiments, initiating a PDU session release for the UE based on the information indicating that the WAB node's operating state is powered off includes: sending a deregistration request to the UE based on the information indicating that the WAB node's operating state is powered off, wherein the deregistration request includes an indication that a damaged WAB node has been detected.

[0019] In some embodiments, instructing the WAB node to be in a shutdown state based on the information to cause the resources allocated to the WAB node to be released includes: sending an instruction to the AMF serving the WAB node to instruct the WAB node to be in a shutdown state based on the information to cause damage to the WAB node.

[0020] In some embodiments, instructing the WAB node to be in a powered-off state based on the information to send an indication that the WAB node is damaged to the AMF serving the WAB node includes: instructing the WAB node to be in a powered-off state based on the information to send an indication that the WAB node is damaged to the User Plane Function (UPF) serving the WAB node.

[0021] In some embodiments, instructing the WAB node to be in a shutdown state based on the information to cause the resources allocated to the WAB node to be released includes: instructing the WAB node to be in a shutdown state based on the information to cause at least one connection associated with the WAB node to be released.

[0022] In some embodiments, the NAS message includes a registration request.

[0023] According to a second aspect of this disclosure, an apparatus (for a communication network) is provided, the apparatus including at least one processor; and at least one memory storing instructions of a Session Management Function (SMF), which, when executed by the at least one processor, cause the apparatus to perform operations including: receiving a Protocol Data Unit (PDU) session release request from an Access and Mobility Management Function, the PDU session release request including an identifier of a User Equipment (UE) and an indication that a compromised WAB node has been detected; and initiating a PDU session release for the UE based on the PDU session release request.

[0024] In some embodiments, initiating a PDU session release for a UE based on a PDU session release request includes sending a PDU session release command to the UE, which includes an indication that a compromised WAB node has been detected.

[0025] According to a third aspect of this disclosure, an apparatus (for a communication network) is provided, the apparatus comprising: at least one processor; and at least one memory storing instructions for an Access and Mobility Management Function (AMF), the instructions, when executed by the at least one processor, causing the apparatus to perform operations including: receiving an indication that a Radio and Backhaul (WAB) node served by the AMF is compromised; and, based on the indication, causing resources allocated to the WAB node to be released.

[0026] In some embodiments, receiving an indication that a WAB node served by the AMF is compromised includes receiving an indication that a WAB node served by the AMF is compromised from a wireless network node serving the WAB node.

[0027] In some embodiments, receiving an indication that a WAB node served by an AMF is compromised includes receiving an indication that a WAB node served by an AMF is compromised from a Session Management Function (SMF) serving the WAB node.

[0028] In some embodiments, receiving an indication that a WAB node served by an AMF is damaged includes receiving an indication that a WAB node served by an AMF is damaged from an AMF serving a UE connected to the WAB node.

[0029] In some embodiments, causing the release of resources allocated to the WAB node based on the indication includes at least one of the following: causing the release of at least one Protocol Data Unit (PDU) session associated with the WAB node; causing the cancellation of at least one UE connected to the WAB node; or causing the release of at least one RRC connection between at least one UE connected to the WAB node and the WAB node.

[0030] According to a fourth aspect of this disclosure, a user equipment is provided, the user equipment comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the device to perform operations including: sending a non-access stratum (NAS) message to the access and mobility management function (AMF) of the UE's serving network via a radio and backhaul (WAB) node; receiving from the serving network at least one message including an indication that an compromised WAB node has been detected; and causing at least one connection associated with the WAB node to be released based on the at least one message.

[0031] In some embodiments, receiving at least one message from the serving network that includes an indication that a compromised WAB node has been detected includes: receiving a Protocol Data Unit (PDU) session release command from the session management function (SMF) of the UE's serving network that includes an indication that a compromised WAB node has been detected.

[0032] In some embodiments, causing at least one connection associated with a WAB node to be released based on at least one message includes: releasing a PDU session on the WAB node based on a PDU session release command.

[0033] In some embodiments, receiving at least one message from the service network that includes an indication that a compromised WAB node has been detected includes receiving a deregistration request from the AMF that includes an indication that a compromised WAB node has been detected.

[0034] In some embodiments, causing at least one connection associated with a WAB node to be released based on at least one message includes: deregistering from the service network based on a deregistration request.

[0035] In some embodiments, causing at least one connection associated with a WAB node to be released based on at least one message includes: releasing the radio resource control (RRC) connection with the WAB node based on at least one message.

[0036] In some embodiments, releasing the RRC connection with the WAB node based on at least one message includes: sending an RRC release message to the WAB node including an indication that the WAB node is damaged, based on at least one message; and receiving an RRC release completion message from the WAB node.

[0037] In some embodiments, causing at least one connection associated with a WAB node to be released based on at least one message includes: performing a switch from the WAB node to a wireless network node based on at least one message.

[0038] In some embodiments, the operation further includes: receiving from the AMF a configuration update command for a condition that triggers a switchover, wherein the condition includes receiving at least one message that includes an indication that a compromised WAB node has been detected.

[0039] In some embodiments, performing a handover from a WAB node to a wireless network node includes sending a measurement report of the handover trigger to the WAB node.

[0040] In some embodiments, the operation further includes adding an identifier associated with the WAB node to a blacklist for cell search no earlier than the handover is complete.

[0041] In some embodiments, the UE is in idle mode, wherein receiving at least one message from the serving network including an indication that a compromised WAB node has been detected includes: receiving a configuration update message from the AMF, the configuration update message being associated with updating the cell selection criteria to avoid selecting a WAB node; and wherein causing at least one connection associated with the WAB node to be released based on at least one message includes: updating the cell selection criteria based on the configuration update message.

[0042] In some embodiments, the operation further includes performing at least one of the following based on at least one message: removing the cell ID associated with the WAB node from at least one of the cell selection list or cell search list; avoiding using the WAB node to connect to the serving network; suppressing the execution of measurements for the cells of the WAB node; or suppressing the reporting of cells for the WAB node.

[0043] In some embodiments, the NAS message includes a registration request.

[0044] According to a fifth aspect of this disclosure, a method is provided for use in / performed by / used in an access and mobility management function, the method comprising: receiving a non-access stratum (NAS) message from a user equipment (UE) via a radio and backhaul (WAB) node; receiving information indicating the operational state of the WAB node; and instructing the WAB node to be powered off based on the information to cause resources allocated to the WAB node to be released.

[0045] According to the sixth aspect, a method for a Session Management Function (SMF) / performed by the SMF / used in the SMF is provided, the method comprising: receiving a Protocol Data Unit (PDU) session release request from the Access and Mobility Management Function, the PDU session release request including an identifier of a User Equipment (UE) and an indication that a compromised WAB node has been detected; and initiating a PDU session release for the UE based on the PDU session release request.

[0046] According to a seventh aspect of this disclosure, a method is provided for an Access and Mobility Management Function (AMF) / performed by the AMF / used in the AMF, the method comprising: receiving an indication that a Radio and Backhaul (WAB) node served by the AMF is compromised; and, based on the indication, causing resources allocated to the WAB node to be released.

[0047] According to the eighth aspect of this disclosure, a method is provided for a user equipment (UE) / performed by the UE / used in the UE, the method comprising: sending a non-access stratum (NAS) message to an access and mobility management function (AMF) of a serving network of the UE via a radio and backhaul (WAB) node; receiving from the serving network at least one message including an indication that a compromised WAB node has been detected; and causing at least one connection associated with the WAB node to be released based on the at least one message.

[0048] According to a ninth aspect of this disclosure, an apparatus (for a communication network) is provided, the apparatus comprising: an access and mobility management function (AMF), the AMF including: components for receiving non-access stratum (NAS) messages from a user equipment (UE) via a radio and backhaul (WAB) node; components for receiving information indicating the operational state of the WAB node; and components for instructing the WAB node to be powered off based on the information, thereby causing resources allocated to the WAB node to be released.

[0049] According to a tenth aspect of this disclosure, an apparatus (for a communication network) is provided, the apparatus including a session management function (SMF), the SMF including: components for receiving a protocol data unit (PDU) session release request from an access and mobility management function, the PDU session release request including an identifier of a user equipment (UE) and an indication that a compromised WAB node has been detected; and components for initiating a PDU session release for the UE based on the PDU session release request.

[0050] According to the eleventh aspect of this disclosure, an apparatus (for a communication network) is provided, the apparatus including an Access and Mobility Management Function (AMF), the AMF including: components for receiving an indication that a Radio and Backhaul (WAB) node served by the AMF is compromised; and components for causing resources allocated to the WAB node to be released based on the indication.

[0051] According to a twelfth aspect of this disclosure, a user equipment (UE) is provided, the UE comprising: means for transmitting a non-access stratum (NAS) message to an access and mobility management function (AMF) of a serving network of the UE via a radio and backhaul (WAB) node; means for receiving from the serving network at least one message including an indication that a compromised WAB node has been detected; and means for causing at least one connection associated with the WAB node to be released based on the at least one message.

[0052] According to a thirteenth aspect of this disclosure, a user equipment is provided, the user equipment comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the device to perform operations including: sending a non-access stratum (NAS) message to an access and mobility management function (AMF) of a serving network of a UE via a radio and backhaul (WAB) node; receiving from the serving network at least one message including an indication that an compromised WAB node has been detected; and releasing at least one connection associated with the WAB node based on the at least one message.

[0053] According to a fourteenth aspect of this disclosure, an apparatus is provided, the apparatus including at least one processor; and at least one memory storing instructions for an access and mobility management function (AMF), the instructions, when executed by the at least one processor, causing the apparatus to perform operations including: receiving a non-access stratum (NAS) message from a user equipment (UE) via a radio and backhaul (WAB) node; receiving information indicating an operational state of the WAB node; and instructing the WAB node to be powered off based on the information, thereby causing at least one connection associated with the WAB node to be released.

[0054] In some embodiments, receiving information indicating the operational status of a WAB node includes receiving information indicating the operational status of a WAB node from the UE's operation, management, and maintenance entity.

[0055] In some embodiments, receiving information indicating the operational status of a WAB node includes receiving information indicating the operational status of a WAB node from an application function entity of the UE.

[0056] In some embodiments, receiving information indicating the operational status of a WAB node includes: sending a query request to the UE's unified data repository, including an identifier associated with the WAB node; and receiving information indicating the operational status of the WAB node from the unified data repository.

[0057] In some embodiments, receiving information indicating the operational status of a WAB node includes: sending a data retrieval request, including an identifier associated with the WAB node, to a wireless network node; and receiving information indicating the operational status of the WAB node from the wireless network node.

[0058] In some embodiments, receiving information indicating the operational status of a WAB node includes: sending a request to the UE's unified data repository to subscribe to information indicating the operational status of a WAB node; and receiving information indicating the operational status of a WAB node from the unified data repository.

[0059] In some embodiments, receiving information indicating the operational status of a WAB node includes: sending a request to the UE's Authentication and Key Management Function (AUSF) including an identifier associated with the WAB node; and receiving an authentication result associated with the operational status of the WAB node from the AUSF.

[0060] In some embodiments, receiving information indicating the operational status of a WAB node includes: sending a request to the UE's Authentication and Key Management Function (AUSF) to subscribe to an authentication result associated with the operational status of the WAB node; and receiving the authentication result of the operational status of the WAB node from the AUSF.

[0061] In some embodiments, instructing the WAB node to be in a powered-off state based on the information to cause at least one connection associated with the WAB node to be released includes: determining that the WAB node is damaged based on the information indicating that the WAB node is in a powered-off state; and causing at least one connection associated with the WAB node to be released based on the determination that the WAB node is damaged.

[0062] In some embodiments, instructing the WAB node to be in a powered-off state based on the information to cause at least one connection associated with the WAB node to be released includes: instructing the WAB node to be in a powered-off state based on the information to initiate a Protocol Data Unit (PDU) session release for the UE.

[0063] In some embodiments, initiating a PDU session release for the UE based on the information indicating that the WAB node is in a powered-off state includes sending a PDU session release request to the Session Management Function (SMF) serving the UE, the PDU session release request including the UE's identifier and an indication of the damaged WAB node.

[0064] In some embodiments, initiating a PDU session release for the UE based on the information indicating that the WAB node's operating state is powered off includes: sending a deregistration request to the UE based on the information indicating that the WAB node's operating state is powered off, wherein the deregistration request includes an indication that a damaged WAB node has been detected.

[0065] In some embodiments, the NAS message includes a registration request.

[0066] According to the fifteenth aspect of this disclosure, a method for a user equipment (UE) is provided, the method comprising: sending a non-access stratum (NAS) message to an access and mobility management function (AMF) of a serving network of the UE via a radio and backhaul (WAB) node; receiving from the serving network at least one message including an indication that a compromised WAB node has been detected; and releasing at least one connection associated with the WAB node based on the at least one message.

[0067] According to a sixteenth aspect of this disclosure, a method for an Access and Mobility Management Function (AMF) is provided, the method comprising: receiving a Non-Access Stratum (NAS) message from a User Equipment (UE) via a Radio and Backhaul (WAB) node; receiving information indicating the operational state of the WAB node; and instructing the WAB node to be powered off based on the information to cause at least one connection associated with the WAB node to be released.

[0068] According to the seventeenth aspect of this disclosure, a user equipment (UE) is provided, the UE comprising: means for transmitting a non-access stratum (NAS) message to the access and mobility management function (AMF) of the UE's serving network via a radio and backhaul (WAB) node; means for receiving from the serving network at least one message including an indication that a compromised WAB node has been detected; and means for releasing at least one connection associated with the WAB node based on the at least one message.

[0069] According to the eighteenth aspect of this disclosure, an apparatus (for a communication network) is provided, the apparatus comprising: an access and mobility management function, the access and mobility management function including: components for receiving non-access stratum (NAS) messages from a user equipment (UE) via a radio and backhaul (WAB) node; components for receiving information indicating the operational state of the WAB node; and components for indicatively indicating the operational state of the WAB node as powered off based on the information to cause at least one connection associated with the WAB node to be released.

[0070] According to a nineteenth aspect of this disclosure, a user equipment is provided, the user equipment comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the device to perform operations including: sending a non-access stratum (NAS) message to the access and mobility management function (AMF) of the serving network of the UE via a radio and backhaul (WAB) node; receiving from the serving network at least one message including an indication that an compromised WAB node has been detected; and inducing a handover from the WAB node to a radio network node to be performed based on the at least one message.

[0071] In some embodiments, the operation further includes: receiving from the AMF a configuration update command for a condition that triggers a configuration switch, wherein the condition includes an indication that a compromised WAB node has been detected.

[0072] In some embodiments, performing a handover from a WAB node to a wireless network node includes sending a measurement report of the handover trigger to the WAB node.

[0073] In some embodiments, the operation further includes adding an identifier associated with the WAB node to a blacklist for cell search no earlier than the handover is complete.

[0074] In some embodiments, the UE is in idle mode; and receiving at least one message from the serving network including an indication that a compromised WAB node has been detected includes: receiving a configuration update message from the AMF, the configuration update message being associated with updating the cell selection criteria to avoid selecting a WAB node.

[0075] In some embodiments, inducing a handover from a WAB node to a wireless network node based on at least one message includes at least one of the following: removing the cell ID associated with the WAB node from at least one of the cell selection criteria or cell search criteria based on a configuration update message; or adding the cell ID associated with the WAB node to the blacklist of cell selection or cell search based on a configuration update message; and wherein inducing a handover from a WAB node to a wireless network node based on at least one message further includes at least one of the following: entering a connected mode; or performing a cell search or cell selection.

[0076] In some embodiments, the NAS message includes a registration request.

[0077] According to a twentieth aspect of this disclosure, an apparatus is provided, the apparatus including at least one processor; and at least one memory storing instructions for an access and mobility management function (AMF), the instructions, when executed by the at least one processor, causing the apparatus to perform operations including: receiving a non-access stratum (NAS) message from a user equipment (UE) via a radio and backhaul (WAB) node; receiving information indicating the operational state of the WAB node; and instructing the UE to perform a handover from the WAB node to a radio network node based on the information indicating that the operational state of the WAB node is powered off.

[0078] In some embodiments, receiving information indicating the operational status of a WAB node includes receiving information indicating the operational status of a WAB node from the UE's operation, management, and maintenance entity.

[0079] In some embodiments, receiving information indicating the operational status of a WAB node includes receiving information indicating the operational status of a WAB node from an application function entity of the UE.

[0080] In some embodiments, receiving information indicating the operational status of a WAB node includes: sending a query request to the UE's unified data repository, including an identifier associated with the WAB node; and receiving information indicating the operational status of the WAB node from the unified data repository.

[0081] In some embodiments, receiving information indicating the operational status of a WAB node includes: sending a data retrieval request, including an identifier associated with the WAB node, to a wireless network node; and receiving information indicating the operational status of the WAB node from the wireless network node.

[0082] In some embodiments, receiving information indicating the operational status of a WAB node includes: sending a request to the UE's unified data repository to subscribe to information indicating the operational status of a WAB node; and receiving information indicating the operational status of a WAB node from the unified data repository.

[0083] In some embodiments, receiving information indicating the operational status of a WAB node includes: sending a request to the UE's Authentication and Key Management Function (AUSF) including an identifier associated with the WAB node; and receiving an authentication result associated with the operational status of the WAB node from the AUSF.

[0084] In some embodiments, receiving information indicating the operational status of a WAB node includes: sending a request to the UE's Authentication and Key Management Function (AUSF) to subscribe to an authentication result associated with the operational status of the WAB node; and receiving the authentication result of the operational status of the WAB node from the AUSF.

[0085] In some embodiments, instructing the UE to perform a handover from the WAB node to the wireless network node based on the information to indicate that the WAB node's operating state is powered off includes: causing at least one message, including an indication that a compromised WAB node has been detected, to be sent to the UE.

[0086] In some embodiments, instructing the UE to perform a handover from the WAB node to the wireless network node based on the information to indicate that the WAB node is in a powered-off state includes sending a configuration update command to the UE for configuring conditions for triggering the handover, wherein the conditions include receiving at least one message including an indication that a compromised WAB node has been detected.

[0087] In some embodiments, the UE is in idle mode; and wherein instructing the UE to perform a handover from the WAB node to the radio network node based on the information to indicate that the WAB node's operating state is powered off includes sending a configuration update message to the UE, the configuration update message being associated with updating the cell selection criteria to avoid selecting the WAB node.

[0088] In some embodiments, the NAS message includes a registration request.

[0089] According to a twenty-first aspect of this disclosure, a method for a user equipment (UE) is provided, the method comprising: sending a non-access stratum (NAS) message to an access and mobility management function (AMF) of a serving network of the UE via a radio and backhaul (WAB) node; receiving from the serving network at least one message including an indication that a compromised WAB node has been detected; and inducing a handover from the WAB node to a radio network node to be performed based on the at least one message.

[0090] According to a twenty-second aspect of this disclosure, a method for an Access and Mobility Management Function (AMF) is provided, the method comprising: receiving a Non-Access Stratum (NAS) message from a User Equipment (UE) via a Radio and Backhaul (WAB) node; receiving information indicating the operational state of the WAB node; and instructing the UE to perform a handover from the WAB node to a Radio Network Node based on the information indicating that the operational state of the WAB node is powered off.

[0091] According to a twenty-third aspect of this disclosure, a user equipment (UE) is provided, the UE comprising: means for transmitting a non-access stratum (NAS) message to the access and mobility management function (AMF) of the UE's serving network via a radio and backhaul (WAB) node; means for receiving from the serving network at least one message including an indication that a compromised WAB node has been detected; and means for inducing a handover from the WAB node to the radio network node to be performed based on the at least one message.

[0092] According to a twenty-fourth aspect of this disclosure, an apparatus is provided, comprising: an access and mobility management function (AMF), the AMF including: components for receiving non-access stratum (NAS) messages from a user equipment (UE) via a radio and backhaul (WAB) node; components for receiving information indicating the operational state of the WAB node; and components for inducing the UE to perform a handover from the WAB node to a radio network node based on the information indicating that the operational state of the WAB node is powered off.

[0093] According to the twenty-fifth aspect of this disclosure, a computer program including instructions is provided, wherein execution of the computer program by at least one processor of a (communication network) device causes the device to perform a method according to any one of the fifth, sixth, seventh, eighth, fifteenth, sixteenth, twenty-first, and twenty-second aspects of this disclosure.

[0094] According to the twenty-sixth aspect of this disclosure, a non-transitory computer-readable medium including instructions, which, when executed by at least one processor of the apparatus, cause the apparatus to perform a method according to any one of the fifth, sixth, seventh, eighth, fifteenth, sixteenth, twenty-first, and twenty-second aspects of this disclosure.

[0095] The foregoing description provides a basic understanding of some aspects of this disclosure. This description is not a broad summary of the disclosure, nor is it intended to limit its scope. Other aspects and features of this disclosure will become apparent to those skilled in the art upon reading the following description of exemplary implementations in conjunction with the accompanying drawings. Attached Figure Description

[0096] The accompanying drawings, which illustrate an example implementation of this application, will now be referenced by way of example. In the figures:

[0097] Figure 1 A schematic block diagram illustrating user equipment, communication networks, and data networks, implemented according to an example, is shown.

[0098] Figure 2 A schematic block diagram illustrating user equipment, communication networks, operation and maintenance entities, and data networks, implemented according to an example, is shown.

[0099] Figure 3 The illustration shows an implementation based on an example for... Figure 1 A schematic diagram of the physical and logical components of a communication network device;

[0100] Figure 4 A schematic diagram of the physical and logical components of a user device implemented according to an example is shown;

[0101] Figure 5 A schematic diagram illustrating a wireless and backhaul network architecture implemented according to an example is shown.

[0102] Figure 6 A schematic diagram illustrating a wireless and backhaul network architecture implemented according to an example is shown.

[0103] Figure 7 A schematic diagram of the process implemented according to the example is shown;

[0104] Figures 7A to 7GA schematic diagram of the process implemented according to the example is shown;

[0105] Figure 8 A schematic diagram of the process implemented according to the example is shown;

[0106] Figure 9 A schematic diagram of the process implemented according to the example is shown;

[0107] Figure 10 A schematic diagram of the process implemented according to the example is shown;

[0108] Figure 11 A schematic diagram of the process implemented according to the example is shown;

[0109] Figure 12 A schematic diagram of the process implemented according to the example is shown;

[0110] Figure 13 A schematic diagram of the process implemented according to the example is shown;

[0111] Figure 14 A schematic diagram of the process implemented according to the example is shown;

[0112] Figure 15 A schematic diagram of the process implemented according to the example is shown;

[0113] Figure 16 A schematic diagram of the process implemented according to the example is shown;

[0114] Figure 17 A schematic diagram of the process implemented according to the example is shown;

[0115] Figure 18 A schematic diagram of the process implemented according to the example is shown;

[0116] Figure 19 A flowchart of a method for access and mobility management functions, implemented according to an example, is shown;

[0117] Figure 20 A flowchart of a method for session management functionality, implemented according to an example, is shown;

[0118] Figure 21 A flowchart of a method for access and mobility management functions, implemented according to an example, is shown;

[0119] Figure 22 A flowchart of a method for a user device, implemented according to an example, is shown;

[0120] Figure 23 A flowchart of a method for a user device, implemented according to an example, is shown;

[0121] Figure 24A flowchart of a method for a user device, implemented according to an example, is shown;

[0122] Figure 25 A flowchart illustrating a method for access and mobility management functions implemented according to an example is shown; and

[0123] Figure 26 A flowchart is shown illustrating a method for access and mobility management functions implemented according to an example.

[0124] Similar reference numerals may be used to denote similar components in different drawings. Unless otherwise specified, items depicted in the drawings are not necessarily drawn to scale. Detailed Implementation

[0125] The subject matter is described herein with reference to the accompanying drawings, which illustrate example implementations. However, many different example implementations may be used, and therefore this description should not be construed as limiting it to the embodiments described herein. Rather, these example implementations are provided to make the application thorough and complete. Where possible, the same reference numerals are used in the drawings and the following description to refer to the same elements, and prime numbers are used to indicate similar elements, operations, or steps in alternative example implementations. The separate blocks or separations of logical elements in the illustrated systems and devices do not necessarily require physical separation of such logical elements, as communication between such logical elements can occur through message passing, function calls, shared memory spaces, etc., without any such physical separation. Therefore, logical elements do not need to be implemented in physically or logically separate platforms, although such logical elements are shown separately for ease of explanation. Different devices may have different designs such that while some devices implement some logical elements in hardware, others may implement such logical elements in a programmable processor with code obtained from machine-readable media. Finally, the element referred to by the singular may be plural, and vice versa, unless the context explicitly or inherently indicates otherwise.

[0126] References to “an implementation,” “implementation,” “example implementation,” etc., in this disclosure indicate that the described implementation may include a particular feature, structure, or characteristic, but not every implementation must include that particular feature, structure, or characteristic. Furthermore, these phrases do not necessarily refer to the same implementation. Moreover, when a particular feature, structure, or characteristic is described in conjunction with an implementation, it is understood that a person skilled in the art could implement that feature, structure, or characteristic in conjunction with other implementations, whether explicitly described or not.

[0127] refer to Figure 1An example of a user equipment (UE) 100 configured to communicate with a data network 102 via a communication network 104 is shown. The communication network 104 includes an access network 106 and a core network 108, which includes one or more network functions 110.

[0128] Access network 106 provides radio connectivity (e.g., radio connection) to UE 100 and connects UE 100 to core network 108 via a backhaul network. Access network 106 may include a radio access network (RAN), a non-terrestrial network (e.g., a satellite network), a wireless local area network (WLAN), or any other type of network that provides radio connectivity to UE 100 and connects UE 100 to core network 108. Access network 106 provides radio connectivity (e.g., radio connection) to UE 100 via at least one access node of access network 106. For example, the access node of access network 106 may be a radio access node and may provide radio connectivity to UE 100. Radio access nodes may include gNodeB (gNB), ng-eNodeB (ng-eNB), and eNodeB (eNB). Access nodes of access network 106 may be access points such as wireless local area network (WLAN) access points and may provide radio connectivity to UE 100. In some implementations, the access node of access network 106 may be an access point that provides wired connectivity (typically referred to as fixed access) to UE 100. The backhaul network between access network 106 and core network 108 may include a fixed network, a satellite network, or a combination thereof. Core network 108 connects access network 106 to data network (DN) 102 via its N6 interface (not shown). As described above, the core network includes network functions (NFs) 110 (typically referred to as network functions 110, and collectively as network functions 110). Each corresponding network function 110 may be implemented as software running on dedicated hardware (e.g., one or more physical computing devices, such as servers), a virtualized network function (VNF) instantiated on a physical or virtual machine, or a container provided by the infrastructure of a cloud computing system. Data network 102 may be an external public network, a private data network, or an intranet data network (e.g., for providing IP Multimedia Subsystem (IMS) services). UE 100 (also referred to herein as a mobile terminal) can be configured to access access network 106, register with core network 108, establish one or more data sessions with core network 108, and access services provided by core network 108 and / or application functions hosted on application servers (not shown) on data network 102.

[0129] refer to Figure 2The illustration shows a user equipment (UE) 100 communicating with an application server (not shown) of a third-party application function (not shown) on a managed data network 102 via a communication network 104. The communication network 104 includes a radio access network 106 (e.g., a next-generation radio access network (NG-RAN)) and a core network 108 (e.g., a 5G core network (5GC)), which operate based on fifth-generation radio access technologies, such as those described in the 3rd Generation Partnership Project (3GPP) standard for new radios. The core network 108 includes network functions (generally referred to as network function 110 and collectively as network function 110) that can be connected to a management system 112 configured to manage the communication network 104, as described in further detail below.

[0130] Radio access network 106 includes one or more radio access network (RAN) nodes (also called base stations). RAN nodes can provide one or more cells. For example, a cell can be a macro cell, micro cell, femtocell, or picocell. A cell defines the coverage area or service area of ​​the RAN node. RAN nodes can be, for example, Node Bs (NodeBs or NBs), evolved Node Bs (eNodeBs or eNBs), next-generation Node Bs (gNBs), remote radio units (RRUs), remote radio heads (RRHs), relays, integrated access and backhaul (IAB) nodes, and low-power nodes. RAN nodes can be deployed in non-terrestrial network (NTN) equipment, such as satellites (e.g., low Earth orbit (LEO) or geostationary orbit (GEO) satellites), aircraft, or drones, where such NTN equipment forms a non-terrestrial network, such as a ground station. RAN nodes can also be deployed in groups, in which case the RAN nodes can be referred to as terrestrial network equipment. RANs that include terrestrial network equipment are generally referred to as terrestrial networks.

[0131] RAN nodes can have a split architecture, where the functionality of the RAN node (e.g., eNB or gNB) is distributed among various entities. A RAN node with a split architecture can include Radio Units (RUs) (also known as Remote Radio Headers (RRHs)), Centralized Units (CUs), and one or more Distributed Units (DUs). DUs can be connected to RUs via fronthaul. DUs can be connected to CUs via midrange or F1 interfaces. CUs can be connected to the core network (e.g., Core Network 108) via backhaul. In a RAN node with a split architecture, the operation of the RAN node can be performed by CUs and DUs. One CU can control one or more DUs.

[0132] The RU converts radio signals sent to and from the antenna into digital signals for transmission over a packet network, handles the digital front-end (DFE) and lower PHY layers, and includes digital beamforming capabilities. A DU is a logical entity (e.g., software) hosted on a server near the RU and running on that server. A CU is a logical entity (e.g., software) hosted on a server and running on that server. A CU can be hosted on its own server and running on that server, or it can be hosted on the same server hosting and running the DU and running on that server. A DU includes a subset of the RAN node's capabilities (e.g., eNB or gNB) depending on the functional breakdown, and a CU includes additional RAN node capabilities not included in the DU's subset of capabilities. A DU can include a subset of the layers of the RAN node's protocol stack, and a CU can include additional layers of the protocol stack not included in the DU's subset of layers. For example, in some implementations, the DU may include the Radio Link Control (RLC) layer, Media Access Control (MAC) layer, and Physical (PHY) layer of the protocol stack for the RAN node, while the CU may include layers of the RAN node's protocol stack above the RLC layer, such as the Packet Data Convergence Protocol (PDCP) layer, Radio Resource Control (RRC) layer, and Internet Protocol (IP) layer. The operation of the DU is controlled by the CU.

[0133] Core network 108 has a service-based architecture. The network functions 110 of core network 108 include Access and Mobility Function (AMF), Authentication Server Function (AUSF), Network Exposure Function (NEF), Network Repository Function (NRF), Network Slice Selection Function (NSSF), Policy Control Function (PCF), Session Management Function (SMF), User Plane Function (UPF), Unified Data Repository (UDM), and Network Data Analysis Function (NWDAF). For ease of explanation, Figure 1 Other network functions of core network 108, such as binding support function (BSF) and billing function (CHF), are not shown.

[0134] AMF processes access, authorization, and authentication of user equipment (including UE 100), and manages the mobility of user equipment 100 when it moves between different radio access networks, cells, or locations.

[0135] The SMF is responsible for establishing, maintaining, and terminating Protocol Data Unit sessions in core network 108. The SMF manages user plane resources and interacts with the UPF in core network 108 to ensure that packets are correctly routed and forwarded.

[0136] The UDM performs the authentication process, stores and manages user data, including subscriber profiles, authentication certificates, and authorization policies; implements security mechanisms to protect user data and resources of the communication network (e.g., core network 108) from unauthorized access attacks and vulnerabilities; and interacts with other network functions of core network 108 (such as PCF) to enforce access control policies, Quality of Service (QoS) parameters, and service restrictions based on user profiles and subscription plans. The UDM is also responsible for managing the registration of network functions 110 serving user equipment 100.

[0137] The BSF manages and maintains the binding information between network functions 110. The BSF allows any specific NF110 of the core network 108 to register and remove binding information, and allows the AF or NEF to discover binding information (e.g., address information of a specific network function 110).

[0138] The Network Analysis Data Function (NWAF) is configured to collect or retrieve data about one or more network functions (NFs) in the core network, generate analytics, including energy consumption analysis based on data collected or retrieved by the NWAF about one or more NFs, and provide the generated analytics (including energy consumption analysis) to itself or other NFs that have requested analytics generated by the NWAF. The NWDAF may include an Analysis Logic Function (AnLF) configured to generate analytics based on data collected and / or retrieved by the NWDAF about one or more NFs, including energy consumption analysis (e.g., generating statistics and / or generating predictions). The NWDAF also includes an analytics service exposed by the NWDAF to provide analytics generated by the AnLF. The NWDAF also includes a Model Training Logic Function (NWDAF (MTLF)) configured to train AI / ML models that can be used by the AnLF to generate analytics, including energy consumption analysis based on data collected or retrieved from one or more network functions and / or OAM entities.

[0139] The functions of the other network functions of the core network 108 are well known to those skilled in the art and therefore will not be described in detail.

[0140] Each NF 110 of core network 108 can provide one or more services to other network functions 110 of core network 108 via an application programming interface (API). Each NF 110 can also register itself and its supported services (e.g., services it provides to other network functions) with the NRF of core network 108. The NRF can be used by any network function 110 to discover other network functions 110 (or instances of NF 110) and services supported by other NF 110 (e.g., services provided by other NFs). Any NF 110 can consume (e.g., use) services provided and exposed by another NF 110. An NF 110 that consumes services from another network function is generally referred to as a Network Function Service Consumer (NFc). A network function 110 that provides and exposes one or more of its services is referred to as a Network Function Service Producer (NFp).

[0141] Each NF 110 in core network 108 can also operate in different states. For example, an NF can operate in a sleep state, a semi-sleep state, or a normal state. NFs can transition between different states. An NF can transition from one state to another at a specific time (e.g., at a time configured by the network operator). Alternatively, an NF can be triggered to transition from one state to another, for example, by receiving a trigger message sent by the OAM system. Each NF can provide NF planning information, which includes the time when the NF transitions from one state to another, and the conditions that cause the NF to transition from one state to another. Furthermore, each NF can provide NF capability information, which includes information about the capabilities of the NF when operating in one state (e.g., an NF can only provide some of its NF services when operating in a semi-sleep state, and can only provide all of its services when operating in a normal state).

[0142] Figure 3 The physical and logical components of an exemplary device 300 according to an embodiment of the present disclosure are shown. The device includes one or more network functions 110 of a communication network 104, including at least one of an AMF or an SMF. Although an example implementation of device 300 is shown and discussed below, examples of at least one of the AMFs or SMFs disclosed herein may also be implemented using other devices, which may include [missing information - likely related to network functions 110 and SMFs 110]. Figure 3 The different logical and physical components are shown. Furthermore, although... Figure 3 A single instance of each logical and / or physical component of device 300 is shown, but Figure 3 Each logical or physical component shown can have multiple instances.

[0143] Device 300 includes one or more processors 302, such as a central processing unit (CPU), microprocessor, application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), application-specific logic circuit system, graphics processing unit (GPU), tensor processing unit, neural processing unit, dedicated artificial intelligence processing unit, hardware accelerator, quantum processor, or any combination thereof. One or more processors 302 may generally be referred to as processor 302, and are collectively referred to as processor 302.

[0144] The device 300 also includes one or more memories 304 (generally referred to as memory 304, and collectively referred to herein as "memory 304"), which may include volatile or non-volatile memory (e.g., flash memory, random access memory (RAM), and / or read-only memory (ROM)). Memory 304 may store machine-executable instructions for execution by at least one of the one or more processors 302. For example, machine-executable instructions 306 of at least one of the AMF or SMF described herein are shown stored in memory 304, which may be executed by at least one of the one or more processors 302, causing the device 300 to perform the operations of at least one of the AMF or SMF described herein. Memory 304 may store machine-executable instructions for execution by processor 104, such as those referenced above. Figure 1 Machine-executable instructions for other network functions of the core network 108.

[0145] In addition to machine-executable instructions 306, memory 304 may also store data, information, rules and / or policies.

[0146] In some examples, device 300 may also include one or more electronic storage units (not shown), such as solid-state drives, hard disk drives, disk drives, and / or optical disk drives. In some examples, one or more datasets and / or modules may be provided by external memory (e.g., an external drive that is wired or wirelessly connected to computing system 100), or by transient or non-transitory computer-readable media. Examples of non-transitory computer-readable media include RAM, ROM, erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory, CD-ROM, or other portable storage. Storage units and / or external memory may be used in conjunction with memory 112 to implement data storage, retrieval, and caching functions of device 300.

[0147] For example, the processor and memory 304 of device 300 can communicate with each other via a communication bus. In some implementations, device 300 is a distributed computing system that includes multiple computing devices (e.g., servers) communicating with each other via a data network, and optional one or more additional components. In some implementations, the various operations described herein can be performed by different computing devices (e.g., servers) of the distributed computing system. In some implementations, device 300 is a virtual machine provided by the infrastructure (e.g., hypervisor, processor, and memory) of a cloud computing system.

[0148] The core network functionality described herein can be implemented as a core network entity comprising a combination of hardware processing circuitry and software and / or firmware, the firmware comprising machine-readable instructions, or software comprising machine-readable instructions executable by at least one processor of the hardware processing circuitry of the device. A hardware processing circuitry includes at least one processor and at least one memory storing machine-readable instructions executable by at least one processor of the hardware processing circuitry. The processor includes any one or a combination of an accelerator, a microprocessor, the core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, a digital signal processor, a central processing unit, a graphics processing unit, and a tensor processing unit. The memory includes any one or a combination of volatile or non-volatile memory (e.g., flash memory, cache, random access memory (RAM), and / or read-only memory (ROM)). The memory stores machine-readable instructions of the software and / or firmware for execution by at least one processor of the hardware processing circuitry. The machine-readable instructions can be executed by at least one processor of the hardware processing circuitry to cause the hardware processing circuitry to perform the actions or operations of the methods described herein. For example, the session management function described herein can be implemented as a session management entity, and the session management policy control function described herein can be implemented as a session management policy control entity.

[0149] refer to Figure 4 An example of user equipment 100 is shown. Although Figure 4 A single instance of each physical and / or logical component of user equipment 100 is shown, but user equipment 100 may include... Figure 3 Multiple instances of each physical or logical component are shown.

[0150] User equipment 100 can be any device capable of transmitting and receiving radio signals. Non-limiting examples of user equipment include mobile stations (MS), mobile devices (such as mobile phones or so-called 'smartphones'), computers equipped with wireless interface cards or other wireless interface facilities (such as USB dongles), personal data assistants (PDAs) or tablets equipped with wireless communication capabilities, machine-type communication (MTC) devices, Internet of Things (IoT) type communication devices, or any combination of these devices.

[0151] User equipment 100 also includes one or more processors 401, one or more memories 402 (collectively referred to as memory 402), and other components or circuit systems 403 for software and hardware-assisted execution of operations configured to be performed by user equipment 100, including access to a radio access network (e.g., Figure 1 The processor 401 controls access to and communication with the RAN (as shown). The processor 401 is coupled to the memory 402. One or more processors 401 may include a central processing unit (CPU), a microprocessor, a multi-core processor, a tensor processing unit (TPU), a graphics processing unit (GPU), a neural processing unit (NPU), a dedicated logic circuit, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a dedicated artificial intelligence processing unit, a hardware accelerator, a quantum processor, or any combination thereof. The memory 402 may include volatile or non-volatile memory (e.g., flash memory, random access memory (RAM), and / or read-only memory (ROM)).

[0152] Processor 401 can be configured to execute software code 408 (e.g., the processor can execute the instructions of software code 408). Execution of software code 408 (or execution of instructions of computer code) can, for example, cause user device 100 to perform one or more operations, including those described herein. Figures 22 to 24 The operation described above. Software code 408 can be stored in memory 402.

[0153] User equipment 100 also includes an antenna array 404 and a transceiver 406 for transmitting radio signals (e.g., radio signals) to and / or receiving radio signals from access nodes of the access network (e.g., radio access network nodes of the RAN) via an air interface 407. The radio signals (e.g., radio signals) may carry communications such as voice, email, text messages, multimedia data, and / or machine data. The antenna array 406 may be disposed inside or outside the user equipment 100. The antenna array 406 may include one or more antenna elements. The antenna array 406 may be a multiple-input multiple-output (MIMO) antenna.

[0154] The processor 401, at least one memory 402, transceiver 406, and other components or circuitry 403 of user equipment 100 (e.g., a modem) may be disposed on a circuit board, in a chipset, or in a system-on-a-chip (SOC). The circuit board, chipset, or SOC may be disposed on... Figure 3 The reference numeral 404 indicates the reference numeral 100. User equipment 100 may optionally include a display device 405, such as a touch-sensitive display device. User equipment 100 also includes a battery (not shown). User equipment 100 may also include a speaker (not shown) and a microphone (not shown). User equipment 100 may also include a Universal Subscriber Identity Module (USIM) (not shown) or an Embedded Subscriber Identity Module (eSIM) (not shown).

[0155] In recent years, vehicular repeaters (VMR) have been studied. During this research, a mobile gNB with radio access and backhaul (MWAB) was proposed as an architectural option for implementing VMR functionality. Specifically, the MWAB is configured for backhaul via traditional Protocol Data Unit (PDU) sessions. Figure 5 A schematic diagram of a network architecture with MWAB deployment according to an embodiment of this disclosure is shown. Figure 5 In this context, MWAB nodes include gNB (i.e., Figure 5 The MWAB-gNB (MWAB-gNB) and the MWAB mobile terminal (MWAB-MT) providing radio connectivity for New Radio (NR) backhaul (BH). The BH connection of the MWAB-gNB is established by a PDU session to the serving network for the MWAB-MT (i.e., Figure 5 The MWAB-gNB's NG interface (used for both the control plane and user plane) is transparently forwarded through the serving network. UEs connected to the MWAB node treat the MWAB cell as a normal cell, and the UE can use appropriate signaling procedures to communicate with the NGC (NG core) serving the UE (i.e., Figure 5 The NGC (UE) shown establishes a PDU session. Therefore, the WAB deployment is transparent to the UE. Note that the VMR network serving the actual UE and VMR nodes may be different from the service network serving the donor gNB.

[0156] In this disclosure, WAB-MT is also referred to as WAB-UE, which means that the UE is presented as part of the WAB node. In this disclosure, WAB-MT and WAB-UE can be used interchangeably.

[0157] Specifically, a WAB node consists of two parts:

[0158] - WAB-gNB, which provides services to (multiple) UEs connected to WAB-gNB.

[0159] - WAB-MT, which connects to the BH network so that WAB-gNB can provide services.

[0160] In this disclosure, a mobile gNB with a WAB (MWAB) and a WAB can be used interchangeably, where a MWAB (node) refers to a node / entity installed on a moving object (e.g., a ship, boat, train, bus, tram, car, etc.).

[0161] In some embodiments, the WAB (node) can be mounted on a static object (e.g., in an enterprise location).

[0162] In this disclosure, it is assumed that the WAB (node) comes from the operator and is owned by the end user.

[0163] The VMR architecture can also include AFs (Network Tools). AFs are network-based tools used by the WAB owner to add / modify / remove the MWAB's operational state (e.g., on / off). Connections to such tools are secured using multiple Transport Layer Security (TLS) based connections.

[0164] In this disclosure, the terms "MWAB / WAB owner" and "MWAB / WAB administrator" can be used interchangeably by third parties.

[0165] The following section will discuss example use cases for 5G relay nodes (e.g., WAB nodes).

[0166] Within the existing 5G macro coverage area inside and outside the city, operator A can decide to acquire services provided by the traffic management bureau and utilize some of these vehicle relays, specifically:

[0167] - Advertising vehicles, used to extend challenging macro 5G coverage and capacity for outdoor users in hotspots expected to host city events or high-density gatherings; and

[0168] - Buses and taxis, which are used to provide a better 5G in-vehicle experience for their users (or inbound roamers) and to improve the overall RAN capacity in certain challenging macro areas, such as along highways leading to airports and / or macro cells serving popular bus / taxi locations / routes in cities.

[0169] The service process for this use case includes:

[0170] 1. Operator A enables vehicle relays to operate and interconnect with its 5G macro RAN and network.

[0171] 2. Operator A configures initial relay operation parameters and conditions, such as radio spectrum, vehicle location / trip, time of day, access / parking in the target area, vehicle speed, etc.

[0172] 3. On a day before the event season, operator A activates the relay.

[0173] 4. 5G services begin flowing through all active vehicle relays. Operator A can reconfigure some relay operation parameters (e.g., spectrum, operation time / location) based on observed 5G services and RAN performance.

[0174] 5. In late summer, due to declining demand for 5G services, Operator A decided to discontinue the relay operation (on its network) of advertising vehicles and a few city taxis. City bus and shuttle services to and from the airport continued.

[0175] Note that in some of the operations described above, third-party entities (e.g., vehicle or relay manufacturer / owner, or relay OAM company) may also be involved to allow or assist operator A (to deactivate) and / or configure certain relay settings.

[0176] In this disclosure, the network system (e.g., a 5G system) supports efficient operation of mobile base station relay, such as in a moving vehicle, wirelessly connected to the NG-RAN, and serving nearby 5G NR UEs (inside and / or outside the vehicle).

[0177] Furthermore, network systems (e.g., 5G systems) support means for mobile network operators to configure, provision, and control mobile base station relay operations, including but not limited to:

[0178] - Activate and / or deactivate mobile relay operations;

[0179] - Configure 5G spectrum (licensed or unlicensed) for use by mobile trunks to the UE and RAN via radio links;

[0180] - Configuration of relay operation conditions, such as based on geographic region or location, (multiple) specific time periods, vehicle speed, trip, etc.

[0181] In some embodiments, a WAB node can be powered off by setting its operating state to "off" (e.g., via OAM). However, for various reasons, a WAB node may not be powered off and may continue to operate as a legitimate WAB node. For example, a WAB node may be vulnerable to hacking. Such a WAB node is also known as a compromised WAB node and may pose a potential vulnerability to the network system. Therefore, it is necessary to detect compromised WAB nodes and restrict their access to the network serving UEs near the WAB-gNB.

[0182] In this disclosure, a compromised MWAB can be defined as a MWAB node that violates the configuration or SW changes provided by the OAM and / or remains operational even when the OAM has already configured the MWAB node to be powered off (i.e., the MWAB node's operating state is set to "off / power off"). For example, if the MWAB node is installed on a bus and the bus is not operational at night, the MWAB node can be configured to be powered off at night based on the OAM's configuration. If the MWAB node remains on at night, such a MWAB node is called a compromised MWAB node. A compromised MWAB node may attract nearby UEs and act as an International Mobile Subscriber Identity (IMSI) capturer. IMSI capturers can perform various attacks, such as IMSI split DoS attacks.

[0183] This disclosure provides a method and apparatus for detecting damaged WAB nodes. It also provides a method and apparatus for releasing resources allocated to detected damaged WAB nodes. Further details are discussed using the following embodiments.

[0184] For ease of illustration, the following flowchart assumes that the MWAB's operating state changes from 'on' to 'off'. The following flowchart may disregard other aspects, such as MWAB operating state changes based on time and location constraints.

[0185] Figure 6 A schematic diagram of a MWAB architecture according to an embodiment of the present disclosure is shown. Figure 6 In this configuration, the UE connects to the MWAB node (i.e., MWAB-MT), which includes the MWAB-gNB and MWAB-UE. The MWAB-gNB provides the NR access link to the UE and connects to the (5G) core network (CN) serving the UE, such as the UE-UPF, UE-AMF, UE-SMF, and UE location management function (LMF) in Public Land Mobile Network 2 (PLMN2). Note that UE-UPF refers to the UPF serving the UE, UE-AMF refers to the AMF serving the UE, and so on. The MWAB-UE provides a BH link to the MWAB-gNB via the (5G) core network (i.e., MWAB-UE) serving the MWAB node, such as the NG-RAN, MWAB-UPF, MWAB-AMF, MWAB-SMF, and MWAB-PCF in PLMN1. MWAB-UPF refers to the UPF serving the MWAB-UE, MWAB-AMF refers to the AMF serving the MWAB-UE, and so on. In this disclosure, MWAB-UPF, MWAB-AMF, MWAB-SMF and MWAB-PCF may be referred to as BH-UPF, BH-AMF, BH-SMF and BH-PCF, respectively.

[0186] exist Figure 6 In this configuration, the UDR / UDM at the HPLMN of the MWAB-gNB (i.e., the (multiple) UEs served by the MWAB-gNB) is used for database management. Alternatively or supplementarily, the UDR / UDM of the HPLMN of the MWAB-UE is used for database management. If / when the UDR / UDM of the HPLMN of the MWAB-UE is used for database management, the MWAB operational status will apply to the MWAB node (which includes both the MWAB-gNB and the MWAB-UE), and similarly, time and location restrictions and other configurations will apply to the MWAB-UE, but not directly to the MWAB-gNB.

[0187] Figure 7 A schematic diagram of a process according to an embodiment of the present disclosure is shown. Figure 7 The process shown is used to detect damaged WAB nodes and includes the following steps:

[0188] Step 701: The operator / OAM provides services to the UE via UDR / UDM (i.e., Figure 7 The UE-UDR / UDM shown provides MWAB nodes (e.g., MWAB-gNB) and corresponding parameters, such as the current operating status of the MWAB nodes (e.g., MWAB-gNB).

[0189] Step 702: When OAM sets the operational status of a MWAB node to "Off", MWAB nodes, including MWAB-gNB and MWAB-UE / MT, are expected to be powered off. However, for some reason, the MWAB node may not be powered off and may continue to operate (e.g., as a normal MWAB node).

[0190] Step 703: The MWAB-gNB broadcasts messages such as System Information Block (SIB), Media Access Control (MAC) Control Element (CE), and Downlink Control Information (DCI).

[0191] Step 704: (Multiple) UEs connect to the MWAB node by sending Non-Access Stratum (NAS) messages (e.g., registration request messages). Note that (multiple) UEs may consider the MWAB node to be healthy / good because messages / signals are received from that MWAB node like any other gNB.

[0192] Step 705: The MWAB-gNB transmits / sends the NAS message to the UE-AMF (e.g., sends the initial UE message to the UE-AMF).

[0193] Step 706: The UE-AMF obtains / receives information from the network entity, and the determination of whether the MWAB node is damaged is based on this information.

[0194] Step 707: Based on the information received in step 706, the UE-AMF determines whether the MWAB node is damaged. For example, if the information indicates that the MWAB node is powered off or should not operate, and the UE-AMF is still receiving messages from the MWAB node (e.g., step 705), then the UE-AMF determines that the MWAB node is damaged. If the MWAB node is determined to be undamaged, the NAS procedure (e.g., the registration procedure) continues. If the MWAB node is determined to be damaged, the UE-AMF may release resources and / or connections(s) allocated to or associated with the damaged MWAB node.

[0195] Figures 7A to 7G A schematic diagram of options for supply information according to an embodiment of the present disclosure is shown, on which the determination of whether a MWAB node is damaged is based. Figure 7A and Figure 7G Options A through G in the table show... Figure 7 An embodiment of step 706 in the example.

[0196] Figure 7A (Option A): Configuration via OAM

[0197] Step 706a: The OAM serving the UE configures / provides the AMF with information associated with the MWAB node (e.g., the mwabgNBID of the MWAB node) and the corresponding operational status of the MWAB node.

[0198] Figure 7B (Option B): Configuration via AF / third-party application

[0199] Step 706b: The AF / third-party application configures / provides to the AMF information associated with the MWAB node (e.g., the mwabgNBID of the MWAB node) and the corresponding operational status of the MWAB node. For example, the AF may provide this information via the NEF and / or UDR.

[0200] Figure 7C (Option C): Retrieve data from UDM / UDR

[0201] Step 706c1: When / after receiving the message in step 605, the UE-AMF sends a Nudr_DM_Query request to the UDR, which includes information associated with the mwab-gNB (e.g., mwabgNBID).

[0202] Step 706c2: The UDR sends a response message to the UE-AMF, which includes information associated with the MWAB-gNB (e.g., mwabgNBID) and the operational status of the corresponding MWAB node (MWAB-gNB).

[0203] Figure 7D (Option D): Retrieve data from adjacent gNBs / macro gNBs

[0204] Step 706d1: The neighbor table is configured in the neighboring gNBs by the operator / OAM, or created in the neighboring gNBs by the operator / OAM using the ANR procedure. The UE-AMF sends an Xnap_mwabDataRetrieve request to (multiple) neighboring gNBs, where the Xnap_mwabDataRetrieve request includes information associated with the WAB-gNB (e.g., mwabgNBID).

[0205] Step 706d2: If mwab data associated with WAB-gNB is found in the neighbor table, the neighboring gNB sends the mwab data associated with WAB-gNB to the UE-AMF using an Xnap_mwabDataRetrieve response message that includes information about WAB-gNB (e.g., mwabgNBID) and the operational status of the mwab node.

[0206] Figure 7E (Option E): Subscribe using UDM / UDR

[0207] Step 706e1: The UE-AMF uses the Nudr_DM_Subscribe message to subscribe to changes in the operational state of the MWAB node (e.g., for the MWAB-gNBID, the MWAB node).

[0208] Step 706e2: Based on the Nudr_DM_Subscribe message, if the operational status of the MWAB node (e.g., MWAB-gNB) in the UDR changes, the UDR will notify the UE-AMF.

[0209] Step 706e3: Change the operational state of the MWAB node, and the UDR notifies the UE-AMF of the changed operational state of the MWAB node using the Nudr_DM_Notify message. In this option, the UE-AMF will have the latest operational state of the MWAB node in the UDR / UDM.

[0210] Figure 7F (Option F): AUSF detects damaged WAB nodes

[0211] Step 706f1: The UE-AMF sends a Nausf_OperationStatus_MwabgNB request message to the AUSF, wherein the Nausf_OperationStatus_MwabgNB request message includes information associated with the MWAB node (e.g., wabgNBID).

[0212] Step 706f2: AUSF uses a Nudr_DM_Query request message that includes information associated with the MWAB node (e.g., wabgNBID) to query the UDM / UDR.

[0213] Step 706f3: UDM / UDR sends the operational status of the MWAB node (e.g., mwabgNBID) to AUSF using the Nudr_DM_Query response message.

[0214] Step 706f4: AUSF checks / certifies the operational status of the MWAB-gNB ID.

[0215] Step 706f5: AUSF sends a Nausf_OperationStatus_MwabgNB response message to AMF, which includes an indication of (authentication) success or failure. For example, a successful authentication indication means that the MWAB node (MWAB-gNB) is set to "on", while an authentication failure indication means that the MWAB node (MWAB-gNB) is set to "off".

[0216] Figure 7G (Option G): AUSF uses a subscription and notification method to detect compromised WAB nodes.

[0217] Step 706g1: The UE-AUSF uses the Nudr_DM_Subscribe message to subscribe to the changes in the operational status of the MWAB node of the MWAB-gNBID.

[0218] Step 706g2: Based on the Nudr_DM_Subscribe message, the UDR notifies the UE-AUSF whether / when the operational status of the MWAB node in the UDR has changed.

[0219] Step 706g3: The operational state of the MWAB node (e.g., MWAB-gNB) in the UDR changes, and the UDR uses the Nudr_DM_Notify message to notify the UE-AUSF of the operational state of the MWAB node (e.g., MWAB-gNB). The UE-AUSF then has the latest operational state of the MWAB node (e.g., MWAB-gNB).

[0220] Step 706g4: The UE-AMF sends a Nausf_OperationStatus_MwabgNB request message to the AUSF of the MWAB node by including the wabgNBID of the MWAB node.

[0221] Step 706g5: AUSF checks / certifies the operational status of the MWAB-gNB ID.

[0222] Step 706g6: AUSF sends a Nausf_OperationStatus_MwabgNB response message to AMF, which includes an indication of successful or failed authentication. For example, a successful authentication indication means that the MWAB node (MWAB-gNB) is set to "on", while a failed authentication indication means that the MWAB node (MWAB-gNB) is set to "off".

[0223] In some embodiments, the UE-AMF in options C, D, E, F, or G may perform step 707 periodically. In these embodiments, the UE-AMF may not perform step 707 for each NAS message received from the access network / WAB node / UE and / or for each update information associated with the operational status of the MWAB node.

[0224] Due to the damaged WAB node, resources allocated to (multiple) UEs, MWAB-gNB, and MWAB-MT are released.

[0225] Figure 8 A schematic diagram of a process according to an embodiment of the present disclosure is shown. Figure 8 During the process, the UE-AMF detected a compromised MWAB node and released the resources allocated to the UE. Specifically, Figure 8 The process includes the following steps:

[0226] Step 801: BH-gNB (e.g., Figure 6 NG-RAN in the BH network establishes NG connections (e.g., via BHAMF) with the BH network.

[0227] Step 802: The MWAB-MT of the MWAB node successfully completed the registration process.

[0228] Step 803: Establish a PDU session between MWAB-MT and BH-SMF / BH-UPF.

[0229] Step 804: MWAB-gNB establishes an NG connection with UE-AMF (i.e., UE PLMN network).

[0230] Step 805: The UE-AMF obtains information from the MWAB-UE and, based on... Figure 7 The process shown detects / determines whether the MWAB node is damaged. Figure 8 In the process, UE-AMF determined that the MWAB node / gNB was damaged.

[0231] Step 806: The UE-AMF uses the Nsmf_PDUSession_ReleaseSMContext request / response to release (multiple) UE PDU contexts in the UE-SMF to obtain the UEID of the UE with the 5G Mobility Management (5GMM) reason "WAB Node Damaged".

[0232] Step 807: The UE-SMF initiates the release of the PDU session connected to the UE via the MWAB node. For example, the PDU session release can be based on the 5GSM reason "WAB node damaged".

[0233] Step 808: The UE-SMF uses the PDU session release command to request the termination of (multiple) PDU sessions between the UE-SMF and the UE, the reason being "a compromised WAB node was discovered".

[0234] Step 809: UE-AMF releases the UE's UE context from UE-AMF using a registration release request, with the reason being "damaged WAB node discovered".

[0235] In some embodiments, after releasing the PDU session and / or registering, the UE may perform at least one of the following actions (based on the reason "Disrupted WAB Node Found"):

[0236] 1. Remove (multiple) cell IDs of the MWAB-gNB ID from the cell selection / search criteria.

[0237] 2. Suppress / avoid using MWAB nodes (e.g., MWAB node cell IDs with MWAB-gNB IDs) to connect to the network.

[0238] 3. Stop measuring the MWAB-gNB cell and report it.

[0239] Step 810: The UE releases the RRC connection with the wab-gNB. Alternatively, the UE executes a (conditional) HO to the appropriate neighboring cell / gNB. For example, "Detection of Damaged WAB Node" can be configured for the UE as a conditional trigger for a conditional HO (CHO). Note that "Detection of Damaged WAB Node" is an exemplary indication / cause value that indicates that the MWAB node is (detected as / determined as) damaged. Specifically, if the WAB node is damaged, the UE may or may not obtain the expected response from the damaged WAB node. Regardless of the response from the damaged WAB node, the UE may release the RRC connection, or alternatively, execute a (conditional) HO to the appropriate neighboring cell / gNB.

[0240] In some embodiments, after step 810, the UE can receive an RRC release complete message from the MWAB node.

[0241] In some embodiments, the UE can be based on Figure 9 The process shown releases the RRC link to the damaged WAB node. Figure 9 The process shown is an embodiment of steps 808 to 810, and includes the following steps:

[0242] Step 901: The UE receives a PDU session release command from the UE-SMF. The PDU session release command can indicate the reason (5GSM) "Malfunctioning WAB node detected".

[0243] Step 902: The UE reads the (5GSM) reason "Morbid WAB node detected" and realizes that the WAB node to which the UE is connected is corrupt. In this case, the UE releases the PDU session associated with the MWAB node (e.g., the PDU session on the MWAB node).

[0244] Step 903: After releasing the PDU session, the UE sends a PDU session release complete message to the UE-SMF.

[0245] Step 904: The UE receives a deregistration request from the UE-AMF. The deregistration request includes / indicates (5GMM) the reason "Malfunctioning WAB node detected".

[0246] Step 905: The UE reads the (5GSM) reason "Damaged WAB node detected" and realizes that the WAB node to which the UE is connected is damaged. Therefore, the UE deregisters itself from the network.

[0247] Step 906: The UE sends a cancellation acceptance to the UE-AMF.

[0248] After releasing the PDU session and / or performing a logout, the UE may perform at least one of the following actions:

[0249] 1. Remove the cell ID of the MWAB-gNB ID from the cell selection / search criteria.

[0250] 2. Suppress / avoid using MWAB nodes (e.g., MWAB node cell IDs with MWAB-gNB IDs) to connect to the network.

[0251] 3. Stop measuring the MWAB-gNB cell and report it.

[0252] Step 907: The UE sends an RRC release message to the MWAB node. In some embodiments, the RRC release message includes an information element (IE) "Release Reason" indicating that the MWAB node is compromised.

[0253] Step 908: The UE can receive the RRC release complete message from the MWAB node.

[0254] Figure 10 A schematic diagram of a process according to an embodiment of the present disclosure is shown. Figure 10 In this context, if / when / after confirming / detecting / determining that the MWAB node to which it is connected is damaged, the UE can perform a HO to the appropriate neighboring cell / NG-RAN. Figure 10 The procedure shown can be performed after the UE-AMF detects / determines that the MWAB node is damaged (e.g., step 707 or step 805), and includes the following steps:

[0255] Step 1001: The UE receives a 5GMM status message from the UE-AMF. The 5GMM status message indicates that the MWAB-gNB is damaged, for example, using the (5GMM) reason "WAB node damaged" or IE ngRanList-Status, which indicates that the MWAB-gNB / MWAB node is damaged. For example, IE ngRanList-Status can be expressed as: "wab-gNB ID: damaged", where the wab-gNB ID is the ID of the MWAB-gNB of the MWAB node.

[0256] Step 1002: Based on the 5GMM status message, the UE realizes that the WAB node to which the UE is connected is damaged. This is a configuration trigger for sending a measurement report of HO to the MWAB node.

[0257] Step 1003: The UE sends the HO measurement report to the MWAB node.

[0258] Step 1004: The MWAB node makes a HO decision based on the measurement report and executes the HO mechanism to switch the UE to another NG-RAN ( Figure 10 (Not shown in the image).

[0259] Step 1005: After the HO is successfully completed, the UE adds the MWAB-gNB's wab-gNBID to the cell search blacklist.

[0260] Figure 11 A schematic diagram of a process according to an embodiment of the present disclosure is shown. Based on Figure 11 As shown in the process, the UE can perform a HO to the adjacent NG-RAN based on a notification that the MWAB node to which it is connected is damaged. Figure 11 The procedure shown can be performed after the UE-AMF detects / determines that the MWAB node is damaged (e.g., step 707 or step 805), and includes the following steps:

[0261] Step 1101: The UE-AMF sends a notification to the UE, which includes information / indication that the MWAB node to which the UE is connected is compromised. For example, the notification includes an IE containing information about a list of radio network nodes (e.g., NG-RAN) and a status indication of "compromised".

[0262] Step 1102: The UE becomes aware of the compromised WAB node it is connected to based on this notification, which is a configuration trigger for sending HO measurement reports to the MWAB node.

[0263] Step 1103: The UE sends the HO measurement report to the MWAB node.

[0264] Step 1104: The MWAB node makes a HO decision based on the measurement report and executes the HO mechanism to switch the UE to another NG-RAN ( Figure 11 (Not shown in the image).

[0265] Step 1105: After the HO is successfully completed, the UE adds the MWAB-gNB's wab-gNBID to the cell search blacklist.

[0266] Figure 12 A schematic diagram of a process according to an embodiment of the present disclosure is shown. Based on Figure 12 As shown in the process, the UE can be configured with a CHO whose conditions are associated with acknowledgment / detection / determination that the UE is connected to a damaged MWAB node (e.g., receiving a notification / indication that a "damaged WAB node has been detected" (from the AMF or core network)). Figure 12 The process shown includes the following steps:

[0267] Step 1201: The UE registers with the network via the MWAB node. For example, the UE can register with the network based on Clause 4.2.2.2.2 of 3GPP TS 23.502 V19.2.0.

[0268] Step 1202: During or after registration, the UE-AMF sends a configuration update command to configure a CHO, where the conditions for triggering the CHO are associated with acknowledgment / detection / determination that the MWAB node to which the UE is connected is compromised (e.g., receiving a notification / indication from the UE-AMF that a compromised WAB node has been detected). Note that the UE-AMF can configure such a CHO if the gNB type associated with registration is associated with a WAB node. Furthermore, the configuration of such a CHO may not be possible via the MWAB node because the MWAB node may be compromised.

[0269] Step 1203: The UE receives a notification from the UE-AMF that the MWAB node to which the UE is connected is damaged. In some embodiments, the notification / indication / information that the MWAB node to which the UE is connected is damaged may come from other CN entities.

[0270] Step 1204: Based on the updated configuration, the UE initiates a CHO to another cell / NG-RAN because the conditions are met. In this embodiment, the UE initiates the CHO by sending a measurement report indicating / triggering the HO to the MWAB node.

[0271] Step 1205: The MWAB node makes a HO decision and executes the HO to switch the UE to another cell / NG-RAN. Figure 12 (Not shown in the image).

[0272] Step 1206: After the HO is successfully completed, the UE adds the MWAB-gNB's wab-gNBID to the cell search blacklist.

[0273] Figure 13 A schematic diagram of a process according to an embodiment of the present disclosure is shown. Based on Figure 13 The process shown further updates the cell (re)selection criteria for (multiple) UEs in idle mode to prevent the UE from establishing a connection with the serving network via a compromised MWAB node. Specifically, a UE can enter idle mode after connecting / registering to the serving network via a MWAB node. If it is determined that (multiple) MWAB nodes are compromised, the CN (e.g., UE-AMF) configures / supplies a blacklist of (multiple) compromised MWAB nodes for cell (re)selection to the UE. Therefore, when / if cell (re)selection is performed, such as when / if leaving idle mode and / or entering connected mode, the UE will not select a compromised MWAB node. More specifically, Figure 13 The process shown can be performed after the AMF detects a damaged WAB node (e.g., step 707 or 805) and includes the following steps:

[0274] Step 1301: The UE-AMF uses a configuration update to update the cell (re)selection criteria for UEs in idle mode, where the updated cell (re)selection criteria includes a blacklist of compromised WAB nodes. The configuration update can be performed using Roaming Guidance (SoR) CMCI (e.g., see 3GPP TS 23.122, V19.1.0, C1.1 and 3GPP TS 29.503, V19.1.05.6.2.2.4 clauses) or using UE Parameter Update (UPU).

[0275] Step 1302: Based on the updated (re)selection criteria, the UE performs a cell search / (re)selection (e.g., after leaving idle mode or entering connected mode). Based on the blacklist, the UE will not select a compromised MWAB node.

[0276] Figure 14 A schematic diagram of a process according to an embodiment of the present disclosure is shown. Based on Figure 14 The process illustrated involves releasing the resources / connections associated with a MWAB node after it has been identified / detected as compromised. For example, the detection of a compromised MWAB node could be based on... Figure 7 The process is executed within the framework. Figure 14 The process shown includes the following steps:

[0277] Step 1401: If / when / after detecting / determining that the MWAB node is damaged (e.g., step 707 or 805), the UE-AMF sends a notification / indication / information about the MWAB node being damaged to the BH-AMF (i.e., the AMF serving the MWAB node) to cause the release of resources allocated to the damaged MWAB node and / or the release of connections(s) associated with / on the damaged MWAB node. In this embodiment, the UE-AMF sends such a notification / indication / information to the BH-AMF via the BH-UPF and BH-gNB. Specifically, the UE-AMF sends a Nupf_wabgNBstatusUpdate request to the BH-UPF, which includes the MWAB-UE ID of the MWAB node (i.e., the ID of the MWAB-UE) and the reason "WAB node damaged".

[0278] Step 1402: BH-UPF transmits / sends the Nupf_wabgNBstatusUpdate request to BH-gNB.

[0279] Step 1403: Based on the Nupf_wabgNBstatusUpdate request, BH-gNB stores the operational status of MWAB-UE / MWAB-gNB as damaged.

[0280] Step 1404: Based on the Nupf_wabgNBstatusUpdate request or the MWAB-gNB's operational status being compromised, the BH-gNB sends a wabgNBStatus request to the BH-AMF, where the wabgNBStatus request includes the MWAB-UE ID and the reason "WAB node compromised".

[0281] Step 1405: Based on the wabgNBStatus request, BH-AMF stores the operational status of MWAB-UE as "damaged" and initiates the release of resources allocated to MWAB nodes (i.e., MWAB-UE and MWAB-gNB).

[0282] Step 1406: BH-AMF sends Nsmf_PDUSession_ReleaseSMContext to BH-SMF, which includes the MWAB-UE ID and the (5GMM) reason "WAB node damaged".

[0283] Step 1407: Based on Nsmf_PDUSession_ReleaseSMContext, BH-SMF initiates PDU session release for MWAB UE ID.

[0284] Step 1408: BH-SMF uses a PDU session release command to request termination of (multiple) PDU sessions between BH-SMF and UE, the reason being "damaged WAB node discovered".

[0285] Step 1409: BH-AMF releases the UE context of the UE from BH-AMF using a registration release request, with the reason being "damaged WAB node discovered".

[0286] Step 1410: BH-AMF sends a wabgNBStatus response to BH-gNB.

[0287] Step 1411: The BH-gNB releases the RRC connection between the BH-gNB and the MWAB node because the MWAB node is compromised. Furthermore, after releasing the RRC connection, the BH-gNB can add the MWAB node (e.g., MWAB-UE / MT) to a blacklist to reject further RRC connection requests from the MWAB node.

[0288] Step 1412: After releasing the RRC connection, the BH-gNB sends a wabgNBStatus update response to the UE-AMF via the BH-UPF.

[0289] Figure 15 A schematic diagram of a process according to an embodiment of the present disclosure is shown. Based on Figure 15 The process illustrated involves releasing the NG connections and resources allocated to the MWAB node (e.g., MWAB-gNB) after it has been identified / detected as compromised. For example, the detection of a compromised MWAB node could be based on... Figure 7 The process in. Figure 15The procedure shown can be performed after the UE-AMF determines that the MWAB node (e.g., MWAB-gNB) is damaged (e.g., in step 707 or 805), and includes the following steps:

[0290] Step 1501: The UE AMF (determines) releases the NG connection and, based on the determination that the MWAB-gNB / node is damaged, frees up the resources allocated to the MWAB-gNB.

[0291] Step 1502: The UE AMF initiates an NG release request / response procedure, with the reason indicating that a compromised MWAB node has been detected. For example, the reason can be set to "Compromised MWAB-gNB / node detected" or "Unauthorized WAB node detected".

[0292] Figure 16 A schematic diagram of a process according to an embodiment of the present disclosure is shown. Based on Figure 16 The process illustrated involves sharing information associated with the operational state of the MWAB node with its neighboring gNB(s). Based on this shared information, if the MWAB node is configured to be powered off, the neighboring gNB(s) can avoid handing the UE to the MWAB node(s). Specifically, Figure 16 The process shown includes the following steps:

[0293] Step 1601: In this embodiment, it is assumed that each gNB has a neighbor table configured via OAM or derived via an Automatic Neighbor Resolution (ANR) process. The neighbor table is used for Xn-HO determination.

[0294] Step 1602: The BH-gNB initiates an XnAP MWABgNB configuration update notification message, including information associated with the operational status of the MWAB node, to update the neighbor table in the neighboring gNBs of the MWAB node. In some embodiments, the BH-gNB confirms the operational status of the MWAB node based on information from the UE-AMF (e.g., see...). Figure 14 (Steps 1401 and 1402 in the original text). In some embodiments, for each MWAB node, this information may include the ID of the MWAB-gNB in ​​the MWAB node and information indicating the operational status of the MWAB node / MWAB-gNB. In this embodiment, the MWAB node is configured to be powered off (i.e., operational status: "off").

[0295] Step 1603: Based on the updated neighbor table indicating that the MWAB node is configured to be powered off, the adjacent gNB releases the Xn interface with the MWAB-gNB / node (if any) because a damaged wab node was found.

[0296] Figure 17A schematic diagram of a process according to an embodiment of the present disclosure is shown. Based on Figure 17 The process illustrated involves releasing the resources / connections associated with a MWAB node after it has been identified / detected as compromised. For example, the detection of a compromised MWAB node could be based on... Figure 7 The process is executed within the framework. Figure 17 The process shown can be performed after step 805 and includes the following steps:

[0297] Steps 1701 to 1703: If / when / after detecting / determining that the MWAB node is damaged (e.g., step 707 or 805), the UE-AMF sends a notification / indication / information about the MWAB node being damaged to the BH-AMF (i.e., the AMF serving the MWAB node), causing the resources allocated to the damaged MWAB node and / or the connections(s) associated with / on the damaged MWAB node to be released. In this embodiment, the UE-AMF sends such a notification / indication / information to the BH-AMF via the BH-UPF and BH-SMF. Specifically, the UE-AMF sends a Nupf_wabgNBstatusUpdate request to the BH-UPF, which includes the MWAB-UE ID of the MWAB node (i.e., the ID of the MWAB-UE) and the reason "WAB node damaged". BH-UPF sends a PCFP data forwarding request message to BH-SMF, which includes the MWAB-UE ID and the reason "WAB node damaged" (which may be gNBID), and BHSMF sends a Namf_Communication_N1N2MessageTransfer request message to BH AMF, which includes the WAB-UE ID and the reason "WAB node damaged".

[0298] Step 1704: Based on this information indicating that the MWAB node is damaged (e.g., the WAB-UEID of the MWAB node's WAB-UE / MT and the reason "WAB node damaged"), the BH-AMF stores the operational state of the MWAB node as "damaged" and releases the resources allocated to the MWAB node and / or the connections associated with the MWAB node (e.g., see...). Figure 14 Steps 1405 to 1411 in the process.

[0299] Steps 1705 to 1707: After releasing resources and / or connections, the BH-AMF responds to the BH-SMF using the Namf_Communication_N1N2MessageTransfer message. The BH-SMF responds to the BH-UPF using the PCFP data forwarding message response message, and the BH-UPF responds to the UE-AMF using the Nupf_wabgNBStatusUpdate response message.

[0300] Figure 18 A schematic diagram of a process according to an embodiment of the present disclosure is shown. Based on Figure 18 The process illustrated involves releasing the resources / connections associated with a MWAB node after it has been identified / detected as compromised. For example, the detection of a compromised MWAB node could be based on... Figure 7 The process is executed within the framework. Figure 18 The process shown can be performed after step 707 or 805, and includes the following steps:

[0301] Step 1801: If / when / after detecting / determining that the MWAB node is damaged (e.g., step 707 or 805), the UE-AMF sends a notification / indication / information about the MWAB node being damaged to the BH-AMF (i.e., the AMF serving the MWAB node) to cause the release of resources allocated to the damaged MWAB node and / or the release of connections(s) associated with / on the damaged MWAB node. In this embodiment, the UE-AMF sends such a notification / indication / information directly to the BH-AMF using a Namf_wabgNBStatusUpdate request message. For example, the notification / indication / information may include the WAB-UEID of the MWAB node's WAB-UE / MT and the reason "WAB node damaged".

[0302] Step 1802: Based on this information indicating that the MWAB node is damaged (e.g., the WAB-UEID of the MWAB node's WAB-UE / MT and the reason "WAB node damaged"), the BH-AMF stores the operational state of the MWAB node as "damaged" and releases the resources allocated to the MWAB node and / or the connections associated with the MWAB node (e.g., see...). Figure 14 Steps 1405 to 1411 in the process.

[0303] Step 1803: After releasing resources and / or connections, the BH-AMF responds to the UE-AMF using the Namf_wabgNBStatusUpdate response message.

[0304] In some embodiments, a network function (NF) can refer to a network device / entity that includes an NF, wherein such a network device / entity performs or is configured to perform or is capable of performing at least a portion of the functions of the NF. Note that a network device / entity may include one or more NFs. For example, according to embodiments of this disclosure, a network device / entity including at least one of AMF, SMF, or UPF may be provided.

[0305] Figure 19 A flowchart of a method / process according to an embodiment of the present disclosure is shown. Figure 19 The methods / procedures shown can be used in AMF (e.g., Figures 6 to 18 The UE-AMF shown is used in the AMF / executed by the AMF, and includes the following steps:

[0306] Step 1901: Receive NAS messages from the UE via the WAB node.

[0307] Step 1902: Receive information indicating the operational status of the WAB node.

[0308] Step 1903: Based on this information, instruct the WAB node to be in a shutdown state to cause the resources allocated to the WAB node to be released.

[0309] exist Figure 19 In this process, the AMF receives NAS messages (e.g., registration requests) from the UE via the WAB node. The AMF also receives information indicating the operational status of the WAB node. In some embodiments, this information indicates the operational status of the WAB-gNB within the WAB node. Based on this information, the AMF determines whether the WAB node is compromised / attacked. Based on / if the information indicates that the WAB node's operational status is power off / closed, the AMF determines that the WAB is compromised / attacked, and accordingly causes the resources allocated to the WAB node (e.g., PDU sessions) to be released.

[0310] In some embodiments, the AMF receives information indicating the operational status of the WAB node from the UE's / the OAM (entity) serving the UE.

[0311] In some embodiments, the AMF receives information indicating the operational status of the WAB node from the UE's / the AF serving the UE.

[0312] In some embodiments, the AMF receives information indicating the operational status of the WAB node by sending a query request including an identifier associated with the WAB node to the UDR serving the UE; and by receiving information indicating the operational status of the WAB node from the UDR.

[0313] In some embodiments, the AMF receives information indicating the operational status of the WAB node by sending a data retrieval request, including an identifier associated with the WAB node, to a wireless network node (e.g., a neighboring node); and by receiving information indicating the operational status of the WAB node from the wireless network node.

[0314] In some embodiments, the AMF receives information indicating the operational status of a WAB node by sending a request to the UE's UDR to subscribe to information indicating the operational status of the WAB node. In this case, if / once the information regarding the operational status of the WAB node stored in the UDR changes, the AMF receives that information from the UDR.

[0315] In some embodiments, the AMF receives information indicating the operational status of the WAB node by: sending a request to the UE / AUSF serving the UE, including an identifier associated with the WAB node; and receiving an authentication result associated with the operational status of the WAB node from the ASF. For example, based on / if the authentication result indicates "success," the AMF confirms / determines that the WAB node is not compromised. Based on / if the authentication result indicates "failure," the AMF confirms / determines that the WAB node is compromised.

[0316] In some embodiments, the AMF receives information indicating the operational status of the WAB node by sending a request to the UE's ASF to subscribe to the authentication result associated with the operational status of the WAB node. Therefore, the AMF will receive the authentication result associated with the operational status of the WAB node periodically or whenever the authentication result changes.

[0317] In some embodiments, the ID of the WAB node includes the ID of the WAB-gNB in ​​the WAB node and / or the ID of the WAB-MT / UE in the WAB node.

[0318] In some embodiments, the AMF causes the resources allocated to the WAB node to be released by instructing the WAB node to be in a shutdown state based on the information in the following manner: determining that the WAB node is damaged based on the information indicating that the WAB node is in a shutdown state; and causing the resources allocated to the WAB node and / or at least one connection associated with the WAB node to be released based on the determination that the WAB node is damaged.

[0319] In some embodiments, the AMF causes the resources allocated to the WAB node to be released by instructing the WAB node to be in a shutdown state based on the information by instructing the WAB node to be in a shutdown state based on the information to initiate a PDU session release for the UE.

[0320] In some embodiments, the AMF initiates a PDU session release for the UE by instructing the WAB node to be in a powered-off state based on this information: by sending a PDU session release to the SMF serving the UE (e.g., ...). Figure 6 The UE-SMF sends a PDU session release request, which includes the UE's identifier and an indication that the WAB node is compromised.

[0321] In some embodiments, the AMF initiates a PDU session release for the UE by instructing the WAB node to be in a powered-off state based on the information by sending a deregistration request to the UE, wherein the deregistration request includes an indication that a compromised WAB node has been detected.

[0322] In some embodiments, the AMF causes the resources allocated to the WAB node to be released by instructing the WAB node to be in a shutdown state based on the information in the following manner: an instruction to cause damage to the WAB node based on the information to instruct the WAB node to be in a shutdown state is sent to the AMF serving the WAB node.

[0323] In some embodiments, the AMF sends an indication that the WAB node is compromised to the AMF serving the WAB node in the following manner: to the UPF serving the WAB node (e.g., Figure 6 The MWAB-UPF in the WAB sends an indication that the WAB node is damaged.

[0324] In some embodiments, the AMF directly sends an indication that the WAB node is damaged to the AMF serving the WAB node.

[0325] In some embodiments, releasing resources associated with a WAB node includes releasing at least one connection associated with or on the WAB node.

[0326] Figure 20 A flowchart of a method / process according to an embodiment of the present disclosure is shown. Figure 20 The methods / procedures shown can be used in SMF (e.g., Figure 6 The UE-SMF (in the SMF) is used in the SMF or executed by the SMF, and includes the following steps:

[0327] Step 2001: Receive a PDU session release request from the AMF. The PDU session release request includes the UE's identifier and an indication that a compromised WAB node has been detected.

[0328] Step 2002: Initiate PDU session release for UE based on PDU session release request.

[0329] exist Figure 20 In this context, SMF is derived from AMF (e.g., Figure 6 The UE-AMF (User-Assisted Provider) receives a PDU session release request, which includes the UE's identifier (e.g., UE ID) and an indication that a compromised WAB node has been detected. Based on the PDU session release request, the SMF initiates a PDU session release for the UE.

[0330] In some embodiments, the SMF initiates PDU session release by sending a PDU session release command to the UE, including an indication that a compromised WAB node has been detected.

[0331] Figure 21 A flowchart of a method / process according to an embodiment of the present disclosure is shown. Figure 21 The methods / procedures shown can be used in AMF (e.g., Figure 6 (MWAB-AMF in AMF) / used in AMF / executed by AMF, and includes the following steps:

[0332] Step 2101: Receive an indication that the WAB node served by AMF is damaged.

[0333] Step 2102: Based on this instruction, cause the resources allocated to the WAB node to be released.

[0334] exist Figure 21 In the process, the AMF receives an indication that a WAB node served by the AMF is compromised. This indication may include, for example, the ID associated with the WAB node served by the SMF (e.g., the ID of the WAB-MT / UE within the WAB node) and information indicating that the compromised WAB node (has been detected). Based on this indication, the AMF releases the resources allocated to the WAB node.

[0335] In some embodiments, the AMF receives data from a wireless network node serving the WAB node (e.g., Figure 6 The NG-RAN in the system receives an indication that the WAB node served by the AMF is damaged.

[0336] In some embodiments, the AMF receives data from the SMF serving the WAB node (e.g., Figure 6 The MWAB-SMF in the system receives an indication that the WAB node served by the AMF is damaged.

[0337] In some embodiments, the AMF receives data from the AMF serving the UE connected to the WAB node (e.g., Figure 6 The UE-AMF in the system receives an indication that the WAB node served by the AMF is damaged.

[0338] In some embodiments, the AMF causes the resources allocated to the WAB node to be released based on the indication by at least one of the following:

[0339] - Causes the PDU session associated with the WAB node to be released;

[0340] - Causes at least one UE connected to the WAB node to be deregistered; or

[0341] - Causes at least one RRC connection between at least one UE connected to the WAB node and the WAB node to be released.

[0342] Figure 22 A flowchart of a method / process according to an embodiment of the present disclosure is shown. Figure 22 The methods / procedures shown can be used in UEs (e.g., Figure 6 (UE in the UE) / used in the UE / performed by the UE, and includes the following steps:

[0343] Step 2201: Send a NAS message to the AMF of the serving network serving the UE via the WAB node.

[0344] Step 2202: Receive at least one message from the service network that includes an indication that a compromised WAB node has been detected.

[0345] Step 2203: Based on at least one message, cause at least one connection associated with the WAB node to be released.

[0346] based on Figure 22 The UE communicates with the AMF of its serving network (e.g., via the WAB node) Figure 6 The UE (UE-AMF) sends a NAS message (e.g., a registration request). In this embodiment, the UE receives (multiple) messages including an indication that a compromised WAB node has been detected. Based on the (multiple) messages (e.g., the indication), the UE acknowledges / determines that the WAB node to which it is connected is compromised, and accordingly causes (multiple) connections associated with the WAB node (e.g., RRC connections between the UE and the WAB node and / or PDU sessions from the UE through the WAB node to the serving network) to be released.

[0347] In some embodiments, the messages(s) including an indication that a compromised WAB node has been detected include SMFs (e.g., from the serving network) of the network. Figure 6 The UE releases the PDU session on the WAB node using the UE-SMF (Power Defender-Small Frame).

[0348] In some embodiments, the messages(s) indicating that a compromised WAB node has been detected include a deregistration request from the AMF. Based on the deregistration request, the UE deregisters from the serving network.

[0349] In some embodiments, the UE releases the RRC connection with the WAB node based on an indication (including multiple messages containing such indication) from the damaged WAB node. For example, the UE may release the RRC connection with the WAB node after releasing the PDU session on the WAB node based on a PDU session release command, and after deregistering from the serving network based on a deregistration request. Specifically, the UE may send an RRC release message to the WAB node, including an indication that the WAB node is damaged, based on at least one message (e.g., an indication); and receive an RRC release completion message from the WAB node.

[0350] In some embodiments, to release the connections(s) associated with a WAB node, the UE may initiate a handover from the WAB node to a wireless network node (e.g., a neighboring node / gNB). For example, the handover may be a CHO (Contactless Hitchhiker) event. Specifically, the UE may receive a configuration update command configuring conditions that trigger the handover, wherein the conditions are set to / include an indication that a compromised WAB node has been detected (one or more messages including at least one of the messages containing that indication). If / based on the UE receiving the message(s) including the indication that a compromised WAB node has been detected, the handover is triggered based on the updated conditions (e.g., step 2202).

[0351] In some embodiments, the UE triggers / initiates handover by sending a handover trigger measurement report to the WAB node.

[0352] In some embodiments, the UE adds the ID associated with the WAB node (e.g., the cell ID of the WAB-gNB) to the blacklist for cell search and / or cell selection no earlier than handover completion (i.e., when handover is completed or after handover is completed).

[0353] In some embodiments, the UE transitions to or enters idle mode (e.g., RRC idle). In these embodiments, the UE may receive a configuration update message associated with updating cell (re)selection criteria to avoid selecting a WAB node. For example, a WAB node (the ID associated with the WAB node) may be removed from the cell (re)selection list and / or added to the cell (re)selection blacklist. The UE updates the cell selection criteria based on the configuration update message. As a result, for example, after leaving idle mode and / or transitioning to connected mode, the UE will not establish a connection with the serving network via the WAB node.

[0354] In some embodiments, the UE may perform at least one of the following based on an indication that a compromised WAB node has been detected (including at least one message indicating such an indication):

[0355] - Remove the cell ID associated with the WAB node (e.g., WAB-gNB) from at least one of the cell selection list or cell search list;

[0356] - Avoid using WAB nodes to connect to the service network;

[0357] - Suppress cell measurements targeting WAB nodes; or

[0358] - Suppress cell reporting for WAB nodes.

[0359] Figure 23 A flowchart of a method / process according to an embodiment of the present disclosure is shown. Figure 23 The methods / procedures shown can be used in UEs (e.g., Figure 6 (UE in the UE) / used in the UE / performed by the UE, and includes the following steps:

[0360] Step 2301: Send a NAS message to the AMF of the serving network serving the UE via the WAB node.

[0361] Step 2302: Receive at least one message from the service network that includes an indication that a compromised WAB node has been detected.

[0362] Step 2303: Based on at least one message, release at least one connection associated with the WAB node.

[0363] based on Figure 23 The UE communicates with the AMF of its serving network (e.g., via the WAB node) Figure 6 The UE (UE-AMF) sends a NAS message (e.g., a registration request). In this embodiment, the UE receives (multiple) messages including an indication that a compromised WAB node has been detected. Based on the (multiple) messages (e.g., the indication), the UE confirms / determines that the WAB node to which it is connected is compromised. In this embodiment, based on at least one message (e.g., the indication) and / or the aforementioned determination, the UE releases at least one connection (e.g., a PDU session and / or an RRC connection) associated with the WAB node.

[0364] In some embodiments, the messages(s) including an indication that a compromised WAB node has been detected include SMFs (e.g., from the serving network) of the network. Figure 6 The UE releases the PDU session on the WAB node using the UE-SMF (Power Defender-Small Frame).

[0365] In some embodiments, the messages(s) indicating that a compromised WAB node has been detected include a deregistration request from the AMF. Based on the deregistration request, the UE deregisters from the serving network.

[0366] In some embodiments, the UE releases the RRC connection with the WAB node based on an indication (including multiple messages containing such indication) from the damaged WAB node. For example, the UE may release the RRC connection with the WAB node after releasing the PDU session on the WAB node based on a PDU session release command, and after deregistering from the serving network based on a deregistration request. Specifically, the UE may send an RRC release message to the WAB node, including an indication that the WAB node is damaged, based on at least one message (e.g., an indication); and receive an RRC release completion message from the WAB node.

[0367] In some embodiments, the UE may perform at least one of the following based on an indication that a compromised WAB node has been detected (including at least one message indicating such an indication):

[0368] - Remove the cell ID associated with the WAB node (e.g., WAB-gNB) from at least one of the cell selection list or cell search list;

[0369] - Avoid using WAB nodes to connect to the service network;

[0370] - Suppress cell measurements targeting WAB nodes; or

[0371] - Suppress cell reporting for WAB nodes.

[0372] Figure 24 A flowchart of a method / process according to an embodiment of the present disclosure is shown. Figure 24 The methods / procedures shown can be used in UEs (e.g., Figure 6 (UE in the UE) / used in the UE / performed by the UE, and includes the following steps:

[0373] Step 2401: Send a NAS message to the AMF of the serving network serving the UE via the WAB node.

[0374] Step 2402: Receive at least one message from the service network that includes an indication that a compromised WAB node has been detected.

[0375] Step 2403: A handover from the WAB node to the wireless network node is initiated based on at least one message.

[0376] exist Figure 24 In this process, the UE communicates with the AMF of the UE's serving network (e.g., via the WAB node) Figure 6The UE (UE-AMF) sends a NAS message (e.g., a registration request). In this embodiment, the UE receives (multiple) messages including an indication that a compromised WAB node has been detected. Based on these (multiple) messages (e.g., an indication), the UE confirms / determines that the WAB node to which it is connected is compromised. In this embodiment, the UE performs a handover from the WAB node to the wireless network node based on the aforementioned determination and / or indication (including the (multiple) messages containing the indication).

[0377] For example, the handover could be a CHO. Specifically, the UE can receive a configuration update command that triggers the configuration handover condition, wherein the condition is set to / includes an indication that a compromised WAB node has been detected (one or more messages including at least one of the messages containing the indication). If / based on the UE receiving the message(s) including the indication that a compromised WAB node has been detected, the handover is triggered based on the updated condition (e.g., step 2402).

[0378] In some embodiments, the UE triggers / initiates handover by sending a handover trigger measurement report to the WAB node.

[0379] In some embodiments, the UE adds the ID associated with the WAB node (e.g., the cell ID of the WAB-gNB) to the blacklist for cell search and / or cell selection no earlier than handover completion (i.e., when handover is completed or after handover is completed).

[0380] In some embodiments, the UE transitions to or enters idle mode (e.g., RRC idle). In these embodiments, the UE may receive a configuration update message associated with updating cell (re)selection criteria to avoid selecting a WAB node. For example, a WAB node (the ID associated with the WAB node) may be removed from the cell (re)selection list and / or added to the cell (re)selection blacklist. The UE updates the cell selection criteria based on the configuration update message. As a result, for example, after leaving idle mode and / or transitioning to / entering connected mode, the UE will not establish a connection with the serving network via the WAB node.

[0381] Figure 25 A flowchart of a method / process according to an embodiment of the present disclosure is shown. Figure 25 The methods / procedures shown can be used in AMF (e.g., Figure 6 The UE-AMF (in the AMF) is used in the AMF or executed by the AMF, and includes the following steps:

[0382] Step 2501: Receive NAS messages from the UE via the WAB node.

[0383] Step 2502: Receive information indicating the operation status of the WAB node.

[0384] Step 2503: Based on this information, instruct the WAB node to be in a shutdown state to cause at least one connection associated with the WAB node to be released.

[0385] exist Figure 25 In this process, the AMF receives NAS messages (e.g., registration requests) from the WAB node and information indicating the operational status of the WAB node. Note that this information indicating the operational status of the WAB node can be received before and / or after receiving the NAS message. For example, the AMF may receive such information periodically or subscribe to such information (and its changes). Based on / if this information indicates that the WAB node's operational status is power off, the AMF confirms / determines that the WAB node is compromised. In this case, the AMF causes the release of (multiple) connections associated with the WAB node (e.g., RRC connections between the UE and the WAB node and / or PDU sessions from the UE through the WAB node to the serving network).

[0386] In some embodiments, the AMF receives information indicating the operational status of the WAB node from the UE's / the OAM (entity) serving the UE.

[0387] In some embodiments, the AMF receives information indicating the operational status of the WAB node from the UE's / the AF serving the UE.

[0388] In some embodiments, the AMF receives information indicating the operational status of the WAB node by sending a query request including an identifier associated with the WAB node to the UDR serving the UE; and by receiving information indicating the operational status of the WAB node from the UDR.

[0389] In some embodiments, the AMF receives information indicating the operational status of the WAB node by sending a data retrieval request, including an identifier associated with the WAB node, to a wireless network node (e.g., a neighboring node); and by receiving information indicating the operational status of the WAB node from the wireless network node.

[0390] In some embodiments, the AMF receives information indicating the operational status of a WAB node by sending a request to the UE's UDR to subscribe to information indicating the operational status of the WAB node. In this case, if / once the information regarding the operational status of the WAB node stored in the UDR changes, the AMF receives that information from the UDR.

[0391] In some embodiments, the AMF receives information indicating the operational status of the WAB node by: sending a request to the UE / AUSF serving the UE, including an identifier associated with the WAB node; and receiving an authentication result associated with the operational status of the WAB node from the ASF. For example, based on / if the authentication result indicates "success," the AMF confirms / determines that the WAB node is not compromised. Based on / if the authentication result indicates "failure," the AMF confirms / determines that the WAB node is compromised.

[0392] In some embodiments, the AMF receives information indicating the operational status of the WAB node by sending a request to the UE's ASF to subscribe to the authentication result associated with the operational status of the WAB node. Therefore, the AMF will receive the authentication result associated with the operational status of the WAB node periodically or whenever the authentication result changes.

[0393] In some embodiments, the ID of the WAB node includes the ID of the WAB-gNB in ​​the WAB node and / or the ID of the WAB-MT / UE in the WAB node.

[0394] In some embodiments, the AMF causes the release of multiple connections associated with the WAB node by instructing the WAB node to be in a powered-off state based on this information: by initiating a Protocol Data Unit (PDU) session release for the UE based on the instruction that the WAB node is in a powered-off state. For example, the AMF may send a PDU session release request to the SMF serving the UE, wherein the PDU session release request includes the UE's identifier and an indication of the compromised WAB node.

[0395] In some embodiments, the AMF causes the release of multiple connections associated with the WAB node by instructing the WAB node to be in a powered-off state based on the information by sending a deregistration request to the UE, wherein the deregistration request includes an indication that a compromised WAB node has been detected.

[0396] Figure 26 A flowchart of a method / process according to an embodiment of this disclosure is shown. This method / process can be used in AMF (e.g., Figure 6 The UE-AMF shown is used in the AMF / executed by the AMF, and includes the following steps:

[0397] Step 2601: Receive NAS messages from the UE via the WAB node.

[0398] Step 2602: Receive information indicating the operation status of the WAB node.

[0399] Step 2603: Based on this information, instruct the WAB node to be in a powered-off state to cause the UE to perform a handover from the WAB node to the wireless network node.

[0400] based on Figure 26 The AMF receives NAS messages (e.g., registration requests) from the UE via the WAB node, and also receives information indicating the operational status of the WAB node. Note that this information indicating the operational status of the WAB node can be received before and / or after receiving the NAS message. For example, the AMF can receive such information periodically, or it can subscribe to such information (which changes). Based on / if this information indicates that the WAB node's operational status is power off, the AMF confirms / determines that the WAB node is compromised. In this case, the AMF causes the UE to perform a handover from the WAB node to a wireless network node (e.g., another gNB or a neighboring node).

[0401] In some embodiments, the AMF receives information indicating the operational status of the WAB node from the UE's / the OAM (entity) serving the UE.

[0402] In some embodiments, the AMF receives information indicating the operational status of the WAB node from the UE's / the AF serving the UE.

[0403] In some embodiments, the AMF receives information indicating the operational status of the WAB node by sending a query request including an identifier associated with the WAB node to the UDR serving the UE; and by receiving information indicating the operational status of the WAB node from the UDR.

[0404] In some embodiments, the AMF receives information indicating the operational status of the WAB node by sending a data retrieval request, including an identifier associated with the WAB node, to a wireless network node (e.g., a neighboring node); and by receiving information indicating the operational status of the WAB node from the wireless network node.

[0405] In some embodiments, the AMF receives information indicating the operational status of a WAB node by sending a request to the UE's UDR to subscribe to information indicating the operational status of the WAB node. In this case, if / once the information regarding the operational status of the WAB node stored in the UDR changes, the AMF receives that information from the UDR.

[0406] In some embodiments, the AMF receives information indicating the operational status of the WAB node by: sending a request to the UE / AUSF serving the UE, including an identifier associated with the WAB node; and receiving an authentication result associated with the operational status of the WAB node from the ASF. For example, based on / if the authentication result indicates "success," the AMF confirms / determines that the WAB node is not compromised. Based on / if the authentication result indicates "failure," the AMF confirms / determines that the WAB node is compromised.

[0407] In some embodiments, the AMF receives information indicating the operational status of the WAB node by sending a request to the UE's ASF to subscribe to the authentication result associated with the operational status of the WAB node. Therefore, the AMF will receive the authentication result associated with the operational status of the WAB node periodically or whenever the authentication result changes.

[0408] In some embodiments, the ID of the WAB node includes the ID of the WAB-gNB in ​​the WAB node and / or the ID of the WAB-MT / UE in the WAB node.

[0409] In some embodiments, the AMF induces the UE to perform a handover by sending at least one message to the UE, including an indication that a compromised WAB node has been detected. For example, the AMF may send at least one message to the UE including an indication that a compromised WAB node has been detected.

[0410] In some embodiments, the AMF sends a configuration update command to the UE to configure the conditions for triggering the handover, wherein the conditions include receiving at least one message indicating that a compromised WAB node has been detected. That is, the handover is a conditional handover triggered if / when / based on receiving an indication that a compromised WAB node has been detected (including at least one message containing that indication).

[0411] In some embodiments, the UE is in idle mode (e.g., entering and / or transitioning to idle mode), and the AMF causes the UE to perform a handover from a WAB node to a wireless network node by sending a configuration update message to the UE, which is associated with updating the cell (re)selection criteria to avoid selecting a WAB node. For example, based on the updated cell (re)selection criteria, a WAB node (e.g., the ID associated with the WAB node) can be added to a blacklist for cell search and / or cell (re)selection. Therefore, if the UE enters / transitions to connected mode and / or performs cell (re)selection or cell search / afterwards / whenwards, the UE will not select a compromised WAB node.

[0412] Based on the above description, the disclosed subject matter can be implemented using only hardware, or by using software and the necessary hardware platform, or by a combination of hardware and software. In consideration of this disclosure, the coding of the software used to perform the above methods is within the scope of those skilled in the art. Based on this understanding, the technical solutions of the subject matter disclosed herein can be embodied in the form of a software product. The software product can be stored in a non-volatile or non-transitory storage medium, such as an optical storage medium, flash drive, hard disk, solid-state drive, Universal Serial Bus (USB) drive, etc. The software program or product (also referred to as a computer program or computer product) includes instructions that enable a computing device (e.g., the user equipment or core network device described herein) to execute the methods provided in the implementation of this disclosure.

[0413] The flowcharts in the accompanying drawings and the operations (also referred to as steps) described herein are for illustrative purposes only. These operations or steps can be varied in many ways without departing from the scope of this disclosure. For example, operations may be performed in different orders, or operations may be added, deleted, or modified as needed.

[0414] In this application, the term "circuit system" may refer to one or more of the following: (a) Pure hardware circuit implementation (such as implementations in analog circuit systems, digital circuits and / or quantum circuits); (b) A combination of (multiple) hardware circuits and software, such as: (i) A combination of (multiple) analog, digital, and / or quantum hardware circuits; and (ii) Any or all of the following components: software (including digital signal and / or quantum processors), software, and memory (including multiple memory), which work together to enable a device (such as a mobile phone device, computing device, computing system, or server) to perform various operations; and (c) Any or all parts of (multiple) hardware circuits, such as (multiple) microprocessors, (multiple) processors and / or (multiple) quantum processors, which require software (e.g., firmware) to function, but may be absent when the software is not required to function.

[0415] This definition of circuit system applies to all uses of the term in this application, including in any claim. As another example, as used in this application, the term circuit system also covers implementations of hardware circuitry or processors (or processors) or a portion thereof and their accompanying software and / or firmware. For example, if applicable to a particular claim element, the term circuit also covers baseband integrated circuits or processor integrated circuits for mobile devices, or similar integrated circuits in servers, cell network devices, or other computing or networking devices.

[0416] All values ​​and subranges within the disclosed scope are also disclosed. Furthermore, although the systems, devices, and processes disclosed and illustrated herein may include a particular number of elements, systems, devices, and components may be modified to include more or fewer such elements. While several example implementations are described herein, modifications, adaptations, and other implementations are also possible. For example, elements shown in the accompanying drawings may be replaced, added, or modified, and the example methods described herein may be modified by replacing, reordering, or adding steps to the disclosed methods.

[0417] It is anticipated that features from one or more of the above-described implementations can be selected to create alternative implementations consisting of combinations of features not explicitly described above. Furthermore, features from one or more of the above-described implementations can be selected and combined to create alternative implementations consisting of combinations of features not explicitly described above. After a comprehensive review of this disclosure, the features applicable to such combinations and sub-combinations will be apparent to those skilled in the art.

[0418] Furthermore, numerous specific details are set forth to provide a thorough understanding of the example implementations described herein. However, those skilled in the art will understand that the example implementations described herein can be practiced without these specific details. Moreover, well-known methods, processes, and elements have not been described in detail in order not to obscure the example implementations described herein. The subject matter described herein and in the cited claims is intended to cover and include all appropriate variations of the technology.

[0419] Although the subject matter disclosed herein and some of its advantages (e.g., technical improvements) have been described in detail, other advantages (e.g., other technical improvements) will become apparent from this disclosure. It should be understood that various changes, substitutions, and modifications may be made to the subject matter disclosed herein without departing from the scope of this disclosure as defined by the appended claims.

[0420] The subject matter disclosed herein may be embodied or implemented in other specific forms without departing from the scope of the claims. The exemplary implementations described herein should be considered in all respects as illustrative only, not restrictive. The subject matter disclosed herein is intended to cover and include all suitable variations of the technology. Therefore, the scope of this disclosure is defined by the appended claims rather than by the foregoing description. The scope of the claims should not be limited by the implementations set forth in the examples or implementations described herein, but should be given the broadest interpretation consistent with the description throughout.

Claims

1. A user equipment (UE), comprising: At least one processor; as well as At least one memory stores instructions that, when executed by the at least one processor, cause the device to perform operations, the operations including: Sending non-access stratum NAS messages to the Access and Mobility Management Function (AMF) of the UE's serving network via wireless and backhaul WAB nodes; Receive at least one message from the service network, including an indication that a compromised WAB node has been detected; and A handover from the WAB node to the wireless network node is initiated based on the at least one message.

2. The UE according to claim 1, wherein the operation further comprises: The AMF receives a configuration update command specifying the conditions that trigger the switch, wherein the conditions include the indication that the compromised WAB node has been detected.

3. The UE according to claim 1 or 2, wherein inducing the handover from the WAB node to the radio network node to be performed includes: Send a measurement report that triggers the switch to the WAB node.

4. The UE according to any one of claims 1 to 2, wherein the operation further comprises: No earlier than the handover is completed, the identifier associated with the WAB node is added to the cell search blacklist.

5. The UE according to claim 1, wherein the UE is in idle mode; and Receiving at least one message from the service network that includes the indication that the compromised WAB node has been detected includes: The configuration update message is received from the AMF, which is associated with updating the cell selection criteria to avoid selecting the WAB node.

6. The UE of claim 5, wherein inducing the handover from the WAB node to the radio network node based on the at least one message comprises at least one of the following: Based on the configuration update message, remove the cell ID associated with the WAB node from at least one of the cell selection criteria or cell search criteria; or Based on the configuration update message, the cell ID associated with the WAB node is added to the blacklist for cell selection or cell search; and The handover from the WAB node to the wireless network node being initiated based on the at least one message further includes at least one of the following: Enter connection mode; or Perform the cell search or the cell selection.

7. The UE according to any one of claims 1 to 2, wherein the NAS message includes a registration request.

8. An apparatus for communication, the apparatus comprising: At least one processor; as well as At least one memory stores instructions for an Access and Mobility Management Function (AMF), which, when executed by the at least one processor, cause the device to perform operations including: Receive non-access stratum (NAS) messages from user equipment (UE) via wireless and backhaul WAB nodes; Receive information indicating the operational status of the WAB node; and Based on the information, the WAB node is instructed to be in a powered-off state to cause the UE to perform a handover from the WAB node to the wireless network node.

9. The apparatus of claim 8, wherein receiving the information indicating the operational state of the WAB node comprises: The information indicating the operational status of the WAB node is received from the UE's operation, management, and maintenance entity.

10. The apparatus of claim 8, wherein receiving the information indicating the operational state of the WAB node comprises: The UE receives information indicating the operational status of the WAB node from its application function entity.

11. The apparatus of claim 8, wherein receiving the information indicating the operational status of the WAB-gNB in ​​the WAB node comprises: Send a query request, including the identifier associated with the WAB node, to the UE's unified data repository; as well as Receive the information indicating the operational status of the WAB node from the unified data repository.

12. The apparatus of claim 8, wherein receiving the information indicating the operational state of the WAB node comprises: Send a data retrieval request, including an identifier associated with the WAB node, to the wireless network node; as well as Receive the information indicating the operational status of the WAB node from the wireless network node.

13. The apparatus of claim 8, wherein receiving the information indicating the operational state of the WAB node comprises: Send a request to the unified data repository of the UE for subscription to the information indicating the operational status of the WAB node; as well as Receive the information indicating the operational status of the WAB node from the unified data repository.

14. The apparatus of claim 8, wherein receiving the information indicating the operational state of the WAB node comprises: Send a request to the UE's Authentication and Key Management Function (AUSF) including an identifier associated with the WAB node; as well as Receive the authentication result associated with the operational status of the WAB node from the AUSF.

15. The apparatus of claim 8, wherein receiving the information indicating the operational state of the WAB node comprises: Send a request to the UE's Authentication and Key Management Function (AUSF) to subscribe to the authentication result associated with the operational state of the WAB node; as well as The authentication result of the operation status of the WAB node is received from the AUSF.

16. The apparatus according to any one of claims 8 to 15, wherein instructing the UE to perform the handover from the WAB node to the wireless network node based on the information indicating that the operating state of the WAB node is powered off comprises: At least one message, including an indication that a compromised WAB node has been detected, is sent to the UE.

17. The apparatus of claim 16, wherein instructing the UE to perform the handover from the WAB node to the wireless network node based on the information indicating that the operating state of the WAB node is powered off comprises: Send a configuration update command to the UE to configure the conditions that trigger the handover, wherein the conditions include receiving at least one message including the indication that the damaged WAB node has been detected.

18. The apparatus according to any one of claims 8 to 15, wherein the UE is in an idle mode; Furthermore, instructing the UE to perform the handover from the WAB node to the wireless network node based on the information indicating that the WAB node's operating state is powered off includes: A configuration update message is sent to the UE, which is associated with updating the cell selection criteria to avoid selecting the WAB node.

19. The apparatus according to any one of claims 8 to 15, wherein the NAS message includes a registration request.

20. A method for a user equipment (UE), the method comprising: Sending non-access stratum NAS messages to the Access and Mobility Management Function (AMF) of the UE's serving network via wireless and backhaul WAB nodes; Receive at least one message from the service network, including an indication that a compromised WAB node has been detected; as well as A handover from the WAB node to the wireless network node is initiated based on the at least one message.

21. A method for an Access and Mobility Management Function (AMF), the method comprising: Receive non-access stratum (NAS) messages from user equipment (UE) via wireless and backhaul WAB nodes; Receive information indicating the operational status of the WAB node; as well as Based on the information, the WAB node is instructed to be in a powered-off state to cause the UE to perform a handover from the WAB node to the wireless network node.