Techniques for preventing downgrade attacks

CN122603495APending Publication Date: 2026-08-18LENOVO (SINGAPORE) PTE LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202580011258.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-01-23
Filing Date
2025-01-22
Publication Date
2026-08-18

AI Technical Summary

Benefits of technology

[0004]本文中描述的方法及设备的一些实施方案可接收UE的网络接入限制强制执行能力的指示,确定网络接入限制信息,向所述UE发射所述网络接入限制信息,及基于所述UE的所述网络接入限制强制执行能力的所述指示及所述经确定网络接入限制信息来应用至少一个网络接入限制。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122603495A_ABST
    Figure CN122603495A_ABST
Patent Text Reader

Abstract

Various aspects of the present disclosure relate to techniques for preventing downgrade attacks. A network entity (NE) is configured to receive an indication of a network access restriction enforcement capability of a user equipment (UE), determine network access restriction information, transmit the network access restriction information to the UE, and apply at least one network access restriction based on the indication of the network access restriction enforcement capability of the UE and the determined network access restriction information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to wireless communications, and more specifically, to techniques for preventing downgrade attacks. Background Technology

[0002] A wireless communication system may include one or more network communication devices, such as base stations, which can support wireless communication with one or more user communication devices (which may also be referred to as user equipment (UE) or other suitable terms). The wireless communication system can support wireless communication with one or more user communication devices by utilizing the resources of the wireless communication system (e.g., time resources (e.g., symbols, time slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers, or the like)). Furthermore, the wireless communication system can support wireless communication across various radio access technologies, including third-generation (3G) radio access technology, fourth-generation (4G) radio access technology, fifth-generation (5G) radio access technology, and other suitable radio access technologies beyond 5G (e.g., sixth-generation (6G)). Summary of the Invention

[0003] The article “a” preceding an element is unrestricted and should be understood to refer to “at least one” or “one or more” of these elements. As used herein, the terms “a,” “at least one,” “one or more,” and “at least one of one or more” are interchangeable. As used herein (including in the claims), the word “or” used in a list of items (e.g., a list of items beginning with phrases such as “at least one of…”, “one or more of…”, or “one or both of…”) indicates an inclusive list, such that (e.g.) a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Furthermore, as used herein, the phrase “based on” should not be construed as referring to a closed set of conditions. For example, without departing from the scope of this disclosure, an exemplary step described as “based on condition A” may be based on both condition A and condition B. In other words, as used herein, the phrase “based on” should be interpreted in the same manner as the phrase “at least partially based on.” Furthermore, as used herein (included in the claims), a “group” may comprise one or more elements.

[0004] Some embodiments of the methods and devices described herein can receive an indication of a UE's network access restriction enforcement capability, determine network access restriction information, transmit the network access restriction information to the UE, and apply at least one network access restriction based on the indication of the UE's network access restriction enforcement capability and the determined network access restriction information.

[0005] Some implementations of the methods and devices described herein can receive an instruction on the network access restriction enforcement capability of a UE, determine the network access restriction information of the UE, configure the network access restriction information of the UE in subscription data associated with the UE, and transmit the network access restriction information.

[0006] Some embodiments of the methods and apparatus described herein may transmit an indication of the UE's network access restriction enforcement capability as part of a Non-Access Layer (NAS) message to a first network, receive network access restriction information of the UE indicating restrictions on the UE's access to a second network, store the network access restriction information, and prevent connection to the second network as indicated in the network access restriction information in response to the first network becoming unavailable. Attached Figure Description

[0007] Figure 1 Examples of wireless communication systems according to aspects of this disclosure are described.

[0008] Figure 2 This document describes an example procedure flow for securely assigning and enforcing Universal Terrestrial Radio Access Network (UTRAN) and GSM EDGE Radio Access Network (GERAN) access restriction information during the registration process, based on aspects of this disclosure.

[0009] Figure 3 This describes an example procedure flow for securely assigning UTRAN and GERAN access restrictions using a UE configuration update procedure, based on aspects of this disclosure.

[0010] Figure 4 This document describes an example procedure flow for securely assigning UTRAN and GERAN access restrictions using a UE parameter update procedure, based on aspects of this disclosure.

[0011] Figure 5A This describes the first part of an example procedure flow for indicating UTRAN and GERAN access restriction information using the Anti-Inter-Architecture Downgrade (ABBA) value for downgrade protection, according to aspects of this disclosure.

[0012] Figure 5B This describes the second part of an example procedure flow for indicating UTRAN and GERAN access restriction information using ABBA values ​​for degradation protection, according to aspects of this disclosure.

[0013] Figure 6 Examples of UEs based on aspects of this disclosure are described.

[0014] Figure 7 Examples of processors according to aspects of this disclosure are described.

[0015] Figure 8 Examples of network equipment (NE) according to aspects of this disclosure are described.

[0016] Figure 9 A flowchart illustrating the method performed by NE according to aspects of this disclosure.

[0017] Figure 10 A flowchart illustrating the method performed by NE according to aspects of this disclosure.

[0018] Figure 11 A flowchart illustrating a method performed by a UE according to aspects of this disclosure. Detailed Implementation

[0019] In wireless communication, 2G / 3G fake base stations (FBS) remain a serious security threat to mobile networks. These networks lack key security features such as mutual authentication, integrity protection, strong security algorithms, and / or similar features. If a UE connects to a 2G / 3G FBS from a 4G or 5G network, it is vulnerable to degradation attacks, such as fraudulent SMS or telephone calls, which can cause significant financial losses to subscribers.

[0020] Several existing procedures exist for UEs connected to 4G / 5G to establish connections with 2G / 3G base stations. For example, when a UE is in a connected state in 4G, it can use a Radio Access Technology (RAT) handover procedure (e.g., as specified in 5.5.2 of TS 23.401, incorporated herein by reference) or a Circuit Switching Back (CSFB) procedure, which includes redirection from 4G to 2G / 3G (e.g., as specified in TS 23.272, incorporated herein by reference) to connect to a 2G / 3G base station. When a UE is in an idle state in 4G, once 4G signaling is unavailable for connection to a 2G / 3G base station, the UE can use a Routing Area Update (RAU) procedure (e.g., as specified in 5.3.3.3 or 5.3.3.6 of TS 23.401, incorporated herein by reference) or cell selection.

[0021] In another instance, when a UE is in a connected state in 5G, it can use a single radio voice call continuity (SRVCC) procedure (as described in TS 23.216, which is incorporated herein by reference) to connect to a 3G base station. When a UE is in an idle or inactive state in 5G, it can use cell selection once 4G and 5G signaling are unavailable for connecting to a 2G / 3G base station.

[0022] It is worth noting that as mobile network systems continue to evolve and improve, operators regularly shift their focus and investment to the latest generation of networks, phasing out older generations, which is currently happening in 2G and 3G networks. In these situations, it is no longer appropriate to allow UEs supporting 2G or 3G networks to continue choosing such networks. In fact, due to the weaker security measures in these older networks, if UEs are tricked into choosing such networks, they will be vulnerable to many known attacks related to 2G and 3G, such as 3GPP SP-231789, which is incorporated herein by reference.

[0023] An existing solution for preventing degradation attacks involves mobility restrictions, such as those described in TS 23.501 (incorporated herein by reference), which may include RAT restrictions, prohibited areas, service area restrictions, core network type restrictions, and closed access group information. However, this solution is limited in that access restrictions are limited to preventing New Radio (NR) or Evolved UTRAN (E-UTRAN) access; it does not consider 2G and 3G access, and therefore does not support access restrictions on UTRAN and / or GERAN.

[0024] Another existing solution involves a security solution for SRVCC from 5G to 3G, as described in TS 33.501 (incorporated herein by reference). However, when a UE switches from 5G to 3G in an SRVCC scenario, it does not prevent further downgrade to 2G. Furthermore, even if the mobile network operator has phased out both 3G and 2G networks, the gNB can initiate an SRVCC-related handover from 5G to 3G to achieve voice continuity, thereby leading to a downgrade attack. Additionally, if the mobile network operator has phased out 3G / 2G networks, and if 5G signaling is unavailable (e.g., 5G signal is blocked by an attacker), then 2G / 3G cell selection can occur, causing the UE to connect to the 2G / 3G network, resulting in a successful downgrade attack.

[0025] Solutions to the aforementioned problems and the limitations of existing solutions are described below with reference to the figures. Aspects of this disclosure are described in the context of wireless communication systems.

[0026] Figure 1This describes an example of a wireless communication system 100 according to aspects of this disclosure. The wireless communication system 100 may include one or more NEs 102, one or more UEs 104, and a core network (CN) 106. The wireless communication system 100 may support various radio access technologies. In some embodiments, the wireless communication system 100 may be a 4G network, such as an LTE network or an LTE-A network. In some other embodiments, the wireless communication system 100 may be an NR network, such as a 5G network, a 5G-A network, or a 5G Ultra Wideband (5G-UWB) network. In other embodiments, the wireless communication system 100 may be a combination of 4G and 5G networks or other suitable radio access technologies, including IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20. The wireless communication system 100 may support radio access technologies beyond 5G, such as 6G. In addition, the wireless communication system 100 can support technologies such as Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), or Code Division Multiple Access (CDMA).

[0027] One or more NEs 102 may be distributed throughout a geographic area to form a wireless communication system 100. One or more of the NEs 102 described herein may be, include, or be referred to as a network node, base station, network element, network function, network entity, wireless access network (RAN), NodeB, eNodeB (eNB), next-generation NodeB (gNB), or other suitable terms. NEs 102 and UEs 104 may communicate via a communication link, which may be wireless or wired. For example, NEs 102 and UEs 104 may perform wireless communication (e.g., receiving signaling, transmitting signaling) via a Uu interface.

[0028] NE 102 can provide a geographic coverage area for which NE 102 can support services for one or more UEs 104 within the geographic coverage area. For example, NE 102 and UE 104 can support wireless communication of signals associated with services (e.g., voice, video, packet data, messaging, broadcasting, etc.) according to one or more radio access technologies. In some embodiments, NE 102 can be mobile, such as a satellite associated with a non-terrestrial network (NTN). In some embodiments, different geographic coverage areas 112 associated with the same or different radio access technologies can overlap, but different geographic coverage areas can be associated with different NEs 102.

[0029] One or more UEs 104 may be distributed throughout the geographic area of ​​the wireless communication system 100. UE 104 may include or be referred to as a remote unit, mobile device, wireless device, remote device, subscriber device, transmitter device, receiver device, or some other suitable term. In some embodiments, UE 104 may be referred to as a unit, station, terminal, or client, and other instances thereof. Alternatively or additionally, UE 104 may be referred to as an Internet of Things (IoT) device, Internet of Everything (IoE) device, or Machine-Type Communication (MTC) device, and other instances thereof.

[0030] UE 104 may be able to support direct wireless communication with other UE 104 via a communication link. For example, UE 104 may support direct wireless communication with another UE 104 via a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular-V2X deployments, the communication link 114 may be referred to as a sidelink. For example, UE 104 may support direct wireless communication with another UE 104 via a PC5 interface.

[0031] NE 102 may support communication with CN 106 or another NE 102, or both. For example, NE 102 may interface with other NE 102 or CN 106 via one or more backhaul links (e.g., S1, N2, N2, or network interfaces). In some implementations, NE 102 may communicate directly with each other. In some other implementations, NE 102 may communicate with each other indirectly (e.g., via CN 106). In some implementations, one or more NE 102 may include sub-components, such as access network entities, which may be instances of Access Node Controllers (ANCs). The ANC may communicate with one or more UE 104s via one or more other access network transmitting entities, which may be referred to as radio headends, smart radio headends, or TRPs.

[0032] CN 106 can support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. CN 106 can be an evolved packet core (EPC) or a 5G core (5GC), which may include control plane entities (e.g., Mobility Management Entity (MME), Access and Mobility Management Function (AMF)) that manage access and mobility, and user plane entities (e.g., Serving Gateway (S-GW), Packet Data Network (PDN) Gateway (P-GW), or User Plane Function (UPF)) that route packets to or interconnect to external networks. In some implementations, the control plane entities may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signaling bearers, etc.) of one or more UEs 104 served by one or more NEs 102 associated with CN 106.

[0033] CN 106 can communicate with the packet data network via one or more backhaul links (e.g., via S1, N2, N2, or another network interface). The packet data network may contain an application server. In some implementations, one or more UEs 104 can communicate with the application server. UE 104 can establish a session (e.g., a Protocol Data Unit (PDU) session or the like) with CN 106 via NE 102. CN 106 can use the established session (e.g., an established PDU session) to route traffic (e.g., control information, data, and the like) between UE 104 and the application server. A PDU session can be an instance of a logical connection between UE 104 and CN 106 (e.g., one or more network functions of CN 106).

[0034] In the wireless communication system 100, NE 102 and UE 104 can use the resources of the wireless communication system 100 (e.g., time resources (e.g., symbols, time slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers)) to perform various operations (e.g., wireless communication). In some embodiments, NE 102 and UE 104 may support different resource structures. For example, NE 102 and UE 104 may support different frame structures. In some embodiments, such as in 4G, NE 102 and UE 104 may support a single frame structure. In some other embodiments, such as in 5G and other suitable radio access technologies, NE 102 and UE 104 may support various frame structures (i.e., multiple frame structures). NE 102 and UE 104 may support various frame structures based on one or more sets of parameters.

[0035] The wireless communication system 100 may support one or more parameter sets, and the parameter sets may include subcarrier spacing and cyclic prefixes. A first parameter set (e.g., μ=0) may be associated with a first subcarrier spacing (e.g., 15 kHz) and a regular cyclic prefix. In some embodiments, the first parameter set (e.g., μ=0) associated with the first subcarrier spacing (e.g., 15 kHz) may utilize one time slot per subframe. A second parameter set (e.g., μ=1) may be associated with a second subcarrier spacing (e.g., 30 kHz) and a regular cyclic prefix. A third parameter set (e.g., μ=2) may be associated with a third subcarrier spacing (e.g., 60 kHz) and a regular cyclic prefix or an extended cyclic prefix. A fourth parameter set (e.g., μ=3) may be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a regular cyclic prefix. A fifth parameter set (e.g., μ=4) may be associated with a fifth subcarrier spacing (e.g., 240 kHz) and a regular cyclic prefix.

[0036] Time intervals for resources (such as communication resources) can be organized according to frames (also known as radio frames). Each frame may have a duration, for example, 10 milliseconds (ms). In some implementations, each frame may contain multiple subframes. For example, each frame may contain 10 subframes, and each subframe may have a duration, for example, 1 ms. In some implementations, each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.

[0037] Alternatively, the time intervals of resources (e.g., communication resources) can be organized according to time slots. For example, a subframe may contain a certain number (e.g., a set of parameters). The number of time slots in each subframe may also depend on one or more parameter sets supported in the wireless communication system 100. For example, the first, second, third, fourth, and fifth parameter sets (i.e., μ=0, μ=1, μ=2, μ=3, μ=4) associated with corresponding subcarrier intervals of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz can respectively utilize one time slot per subframe, two time slots per subframe, four time slots per subframe, eight time slots per subframe, and 16 time slots per subframe. Each time slot may contain a certain number (e.g., a set of parameters) of symbols (e.g., OFDM symbols). In some embodiments, the number (e.g., quantity) of time slots in a subframe may depend on the parameter set. For a conventional cyclic prefix, a time slot may contain 14 symbols. For an extended cyclic prefix (e.g., applicable to a 60 kHz subcarrier spacing), a time slot may contain 12 symbols. The relationship between the number of symbols per time slot, the number of time slots per subframe, and the number of time slots per frame for the regular and extended cyclic prefixes may depend on the parameter set. It should be understood that references to the first parameter set (e.g., μ=0) associated with the first subcarrier spacing (e.g., 15 kHz) can be used interchangeably between subframes and time slots.

[0038] In the wireless communication system 100, the electromagnetic (EM) spectrum can be divided into various categories, frequency bands, channels, etc., based on frequency or wavelength. For example, the wireless communication system 100 may support one or more operating frequency bands, such as frequency ranges represented as FR1 (410 MHz to 7.125 GHz), FR2 (24.25 GHz to 52.6 GHz), FR3 (7.125 GHz to 24.25 GHz), FR4 (52.6 GHz to 114.25 GHz), FR4a or FR4-1 (52.6 GHz to 71 GHz), and FR5 (114.25 GHz to 300 GHz). In some embodiments, NE 102 and UE 104 may perform wireless communication on one or more of the operating frequency bands. In some embodiments, FR1 may be used by NE 102 and UE 104, as well as other equipment or devices, for cellular communication services (e.g., control information, data). In some implementations, FR2 can be used by NE 102 and UE 104, as well as other equipment or devices, for short-range, high data rate capabilities.

[0039] FR1 can be associated with one or more parameter sets (e.g., at least three parameter sets). For example, FR1 can be associated with: a first parameter set (e.g., μ=0) containing a 15 kHz subcarrier spacing; a second parameter set (e.g., μ=1) containing a 30 kHz subcarrier spacing; and a third parameter set (e.g., μ=2) containing a 60 kHz subcarrier spacing. FR2 can be associated with one or more parameter sets (e.g., at least two parameter sets). For example, FR2 can be associated with: a third parameter set (e.g., μ=2) containing a 60 kHz subcarrier spacing; and a fourth parameter set (e.g., μ=3) containing a 120 kHz subcarrier spacing.

[0040] The solutions discussed in this document relate to techniques for preventing degradation attacks. Generally, the subject matter disclosed herein describes features for provisioning UTRAN (3G) and GERAN (2G) access restrictions to network entities (e.g., AMF, gNB, and UE) to avoid handover and for cell selection associated with 2G or 3G access (e.g., GERAN and UTRAN) to prevent degradation attacks. Furthermore, the following embodiments describe various techniques for protecting the provisioning of UTRAN (3G) and GERAN (2G) access restriction information to UEs using NAS security, AS security, and UPU security.

[0041] The first embodiment involves securely assigning UTRAN and GERAN access restriction information to use NAS / AS security to prevent 2G / 3G cell selection or UTRAN / GERAN handover. In this embodiment, the mobile network operator may have phased out 2G / 3G networks, and allowing UE connections in 5G to fall back / switch to 2G / 3G network connections may be undesirable.

[0042] This embodiment describes how UTRAN and / or GERAN access restriction information can be provided to the AMF (if not locally configured) and RAN (e.g., gNB / NR) to avoid inter-RAT handover to UTRAN / GERAN. Furthermore, this embodiment describes assigning UTRAN and / or GERAN access restriction information to the UE to avoid UTRAN / GERAN selection (e.g., 2G / 3G cell selection when 5G signal is unavailable). In one embodiment, the UTRAN and GERAN access restriction information may be sent to the UE in a NAS message after NAS security establishment or in a Radio Resource Control (RRC) message after AS security establishment.

[0043] Figure 2 This document describes an example procedure flow for securely assigning and enforcing UTRAN and GERAN access restriction information during the registration process, according to aspects of this disclosure. It should be noted that in this embodiment, the GERAN and UTRAN access restriction information may be provided to the UE in a NAS message (e.g., a registration acceptance message, NAS transmission, or the like). Alternatively, the GERAN and UTRAN access restriction information may be indicated as part of network access restriction information, which may contain various restriction information, such as UTRAN not allowed, GERAN not allowed, 2G not allowed, 3G not allowed, and / or the like. Furthermore, in another embodiment, existing RAT access restrictions may include UTRAN not allowed / UTRAN, GERAN not allowed / GERAN, and in this case, enhanced RAT restrictions containing information regarding UTRAN and GERAN restrictions may be sent to the UE, RAN, and AMF to apply the 2G and 3G related RAT restrictions.

[0044] In one embodiment, at step 1 (see message 202), UE 201 sends an initial NAS message containing an indication of the UE's ability to support GERAN and UTRAN access restrictions. In another embodiment, UE 201 sends an initial NAS message containing support for network access restriction enforcement capabilities. In this embodiment, the network access restriction enforcement capability information element (IE) contains information indicating support for GERAN and UTRAN access restrictions. In one embodiment, the initial NAS message at step 1 may be an initial registration request message, a mobility registration update request message, a service request message, and / or the like.

[0045] In 2 (see Message Passing 204), in one embodiment, the network may initiate and perform a primary authentication with UE 201 to perform mutual authentication (e.g., using EAP-AKA', 5G AKA, or EAP methods).

[0046] In 3a (see Message Passing 206), in one embodiment, AMF 205 can obtain a request to retrieve subscription data from UDM 209 by sending a Nudm_SubscriberDataManagement (SDM) with the Subscription Permanent Identifier (SUPI) of UE 201 and network access restriction enforcement capability (if received in 1).

[0047] In 3b (see box 208), in one embodiment, based on the operator's local policy (or if the 2G / 3G network has been phased out), the UDM / UDR 209 manages GERAN and UTRAN access restrictions as part of the network access restriction requirements for UE 201 in the subscription data (e.g., as part of the UE access and mobility context). In one implementation, the UDM / UDR 209 manages GERAN and UTRAN access restrictions as part of the mobility or RAT restriction information for UE 201 in the subscription data (e.g., as part of the UE access and mobility context).

[0048] In 4 (see Message Passing 210), in one embodiment, UDM 209 sends a Nudm_SDM_Get response message containing network access restriction information (UTRAN access is restricted, GERAN access is restricted) and other subscription data (as needed).

[0049] In 5 (see box 212), in one embodiment, if AMF 205 receives network access restriction information (UTRAN access restricted, GERAN access restricted) from UDM 209, then AMF 205 stores the network access restriction information and SUPI as part of the UE context. Furthermore, in one embodiment, based on the network access restriction information received from UDM 209 and the network access restriction enforcement capability received from UE 201 in 1, AMF 205 performs one or more access restriction actions, such as not initiating an inter-RAT handover to UTRAN / GERAN, not initiating / forwarding a relocation request related to an SRVCC-specific handover from 5G to 3G or 2G, assigning network access restriction information (UTRAN access restricted, GERAN access restricted) to RAN 203 and UE 201 to enforce UTRAN and GERAN access restrictions and / or similar restrictions on UE 201 at the RAN 203 and UE 201 sides.

[0050] In step 6 (see message 214), in one embodiment, AMF 205 sends a NAS security mode command message to establish NAS security. In this embodiment, AMF 205 may include, for example, a network access restriction enforcement capability (if received in step 1). In one embodiment, AMF 205 may send network access restriction information (UTRAN access restricted, GERAN access restricted) to UE 201 in step 6.

[0051] In 7 (see Message Passing 216), in one embodiment, UE 201 sends a NAS security mode completion message, which may include completion of the initial NAS message and network access restriction enforcement capability (if sent in 1) (if the initial NAS message is not protected in 1, then protection is provided for the initial NAS message).

[0052] In 8 (see Message Passing 218), in one embodiment, AMF 205 sends network access restriction information (UTRAN access restricted, GERAN access restricted) to RAN 203 in an N2 message (e.g., an Initial Context Establishment message).

[0053] In 9 (see box 220), in one embodiment, if RAN 203 receives network access restriction information (UTRAN access restricted, GERAN access restricted) from AMF 205, then RAN 203 stores the network access restriction information as part of the UE context. Furthermore, based on the received network access restriction information, RAN 203 performs one or more access restriction actions, such as not initiating an inter-RAT handover to UTRAN / GERAN, not initiating SRVCC from 5G to 3G or 2G, assigning network access restriction information (UTRAN access restricted, GERAN access restricted) to UE 201, and / or similar actions.

[0054] In 10 (see message 222), in one embodiment, RAN 203 establishes AS security (AS security mode command procedure) with UE 201.

[0055] In 11a (see message passing 224), in one embodiment, RAN 203 sends an RRC message to UE 201, which includes network access restriction information (UTRAN access restricted, GERAN access restricted) received in 8. In one embodiment, if the network access restriction information is not provided to UE 201 by AMF 205 in 7 or 11b, then RAN 203 provides the network access restriction information to UE 201 in 11a.

[0056] In 11b (see Message Passing 226), in one embodiment, after a successful NAS security establishment, AMF 205 sends network access restriction information (UTRAN access restricted, GERAN access restricted) to UE 201 in a NAS message (e.g., a registration accept message or another message on NAS transport).

[0057] In 12 (see box 228), in one embodiment, UE 201 stores network access restriction information (UTRAN access is restricted, GERAN access is restricted), and does not select UTRAN access (3G) or GERAN access (2G) even if 5G or 4G signals are unavailable, and waits until 5G / 4G signals are available to prevent downgrade attacks.

[0058] It should be noted that, Figure 2 In this context, network access restriction information (UTRAN access restricted, GERAN access restricted) can be sent as individual IEs to AMF 205, RAN 203 and UE 201, rather than being sent as part of network access restriction information in 4, 5, 6, 8, 9, 11a and 11b.

[0059] It should be noted that, Figure 2In this context, network access restriction information (UTRAN access restricted, GERAN access restricted) from one AMF 205 can be sent to another AMF along with the UE context (as part of the mobility restriction information or as an individual information element) using the Namf_Communication_UEContextTransfer service operation (request / response message) (e.g., during UE mobility or handover in a 5G system).

[0060] The second embodiment involves securely assigning UTRAN and GERAN access restriction information to prevent 2G / 3G cell selection or UTRAN / GERAN handover using a UE configuration update procedure. In this embodiment, the UTRAN and GERAN access restriction information can be provided to the UE using a UE configuration update procedure, such as... Figure 3 It is displayed in the middle.

[0061] Figure 3 This description illustrates an example procedure flow for securely assigning UTRAN and GERAN access restrictions using a UE configuration update procedure, according to aspects of this disclosure. In one embodiment, the AMF 305 initiates this procedure when it wants to update access and mobility management-related parameters (including network access restriction information, such as UTRAN and GERAN access restriction information) in the UE configuration. The UE configuration update can be sent and applied, depending on the access type (e.g., 3GPP access or non-3GPP access), where applicable.

[0062] In A (prerequisite, see message 302), UE 301 sends an initial NAS message containing an indication of the UE's ability to support GERAN and UTRAN access restrictions. In one embodiment, UE 301 sends an initial NAS message containing support for network access restriction enforcement capabilities in an information element (IE). In one embodiment, the network access restriction enforcement capability IE contains information indicating support for both GERAN and UTRAN access restrictions. It should be noted that the initial NAS message in A may be an initial registration request message, a mobility registration update request message, a service request message, and / or the like.

[0063] In B (Prerequisites, see box 304), due to various reasons, such as changes in UE mobility, NW policies, receipt of subscriber data update notifications from UDM309, changes in network slice configuration (including: due to operator local policies on obsolete 2G / 3G networks and related UE access restrictions on 2G / 3G networks, such as access restrictions on UTRAN and / or GERAN; due to changes in network slice concurrent use group (NSSRG) information in subscription information, for example, as specified in clause 5.15.12 of TS 23.501 (incorporated herein by reference); or due to changes in network slice as group (NSAG) information, for example, as specified in clause 5.15.14 of TS 23.501), or to remove single network slice selection assistance information (S-NSSAI) from allowed NSSAIs due to the expiration of a slice deregistration inactivity timer, or to provide UE 301 with an updated slice usage policy, for example, as specified in TS 23.501), As specified in Clause 5.15.15 of TS 23.501, changes in the UE radio capability ID assigned by the Public Land Mobile Network (PLMN) and enhanced coverage restriction information in the UE context are required to notify the Mobile Base Station Relay (MBSR) (Integrated Access and Backhaul (IAB) - UE) of authorization status changes based on operator configuration and changes related to discontinuous coverage (e.g., out-of-coverage periodic changes). For example, as specified in Clause 5.35A.4 of TS 23.501, UE 301 needs to be notified of reconnection to the network due to NG-RAN timing synchronization status changes (e.g., as specified in Clause 4.15.9.4). AMF 305 determines the necessity of UE configuration updates or that UE 301 needs to perform registration procedures. If UE 201 is in Connection Management (CM) - Idle, AMF 305 may wait until UE 301 is in CM - Connected or a network-triggered service request is triggered (e.g., in Clause 4.2.3.3).

[0064] In one embodiment, if the service area restrictions of UE 301 are updated, then AMF 305 may include a list of mobility restrictions (by including network access restriction information, such as UTRAN and GERAN access restriction information) in the N2 message that delivers the UE configuration update command to UE 301.

[0065] In 1a (see Message Passing 306), in one embodiment, if the AMF 305 receives network access restriction enforcement capability information from the UE 301, as described in A, then the AMF 305 sends a UE configuration update command containing network access restriction information (e.g., UTRAN and GERAN access restriction information) and one or more other UE parameters (e.g., configuration update indication, 5G-GUTI (Globally Unique Temporary Identifier), Tracking Area Identifier (TAI) list, allowed NSSAI, mappings of allowed NSSAI, and / or similar). In one embodiment, the AMF 305 may include a configuration update indication parameter in the UE configuration update command indicating whether the UE acknowledges the command.

[0066] In 1b (see box 308), in one embodiment, UE 301 stores the network access restriction information (UTRAN access is restricted, GERAN access is restricted) received in 1a, and determines that even if 5G or 4G signals are unavailable, it will not select UTRAN access (3G) or GERAN access (2G), and waits until 5G / 4G signals are available to prevent downgrade attacks.

[0067] In 2a (see Message Passing 310), in one embodiment, if the UE configuration update instruction or network access restriction information indicating UTRAN and GERAN access restrictions requires confirmation of the UE configuration update command, then the UE 301 sends a UE configuration update complete message to the AMF 305.

[0068] In 2b (see Message Passing 312), in one embodiment, AMF 305 uses the Nudm_SDM_Info service operation to provide UDM 309 with confirmation that UE 301 has received network access restriction information indicating UTRAN and GERAN access restrictions as part of mobility restrictions, whether the network access restriction information has been provided or updated, and whether actions have been taken accordingly.

[0069] In 2c (see Message Passing 314), in one embodiment, if AMF 305 has configured UE radio capability ID assigned by PLMN and / or network access restriction information indicating UTRAN and GERAN access restrictions to UE 301, then AMF 305 notifies NG-RAN 303 of the UE radio capability ID and / or network access restriction information indicating UTRAN and GERAN access restrictions when it receives confirmation from UE 301 in 2a.

[0070] In 2d (see box 316), in one embodiment, if UE 301 is configured with a new 5G-GUTI in 2a via a non-3GPP access and UE 301 is registered to the same PLMN by both 3GPP and non-3GPP access, then UE 301 will pass the new 5G-GUTI to the lower layer of its 3GPP access.

[0071] In 2e (see box 318), in one embodiment, if RAN 303 receives network access restriction information (UTRAN access restricted, GERAN access restricted) from AMF 305, then this information, as part of the UE context, is stored in RAN 303 along with the 5G-GUTI. Furthermore, in one embodiment, based on the received network access restriction information, RAN 303 does not initiate any inter-RAT handover to UTRAN / GERAN and / or does not initiate SRVCC from 5G to 3G or 2G.

[0072] The third embodiment involves securely assigning UTRAN and GERAN access restriction information to use UE parameter updates to securely prevent 2G / 3G cell selection or UTRAN / GERAN handover. Figure 4 This document describes an example procedure flow for securely assigning UTRAN and GERAN access restrictions using a UE parameter update procedure, based on aspects of this disclosure.

[0073] In 0 (prerequisites, see message passing 402 and 404), in one embodiment, if the UE supports network access restriction enforcement, it sends a message indicating support for the network access restriction enforcement capability to AMF 403, for example, in a NAS / N1 message. In one embodiment, the message includes an IE containing network access restriction enforcement capability information to indicate support for GERAN and UTRAN access restrictions. In one embodiment, AMF 403 may send / forward the received indication of UE support for the network access restriction enforcement capability to UDM 407 in a Nudm service operation message or a Namf service operation message.

[0074] In 1 (see box 406), in one embodiment, when the UE registers with the 5G system, the UDM 407 performs a UE parameter update (UPU) using a control plane procedure. If the end consumer of the updated UE parameters (e.g., updated routing ID data) is a Universal Subscriber Identity Module (USIM), then the UDM uses a security packet mechanism (e.g., as described in 3GPP TS 31.115 (incorporated herein by reference)) to protect these parameters for updating the parameters stored on the USIM. The UDM 407 then prepares UE parameter update data (UPU data) by including the parameters protected by the security packet (if present) and any UE parameters whose end consumer is UE 401 (e.g., as described in TS 24.501 (incorporated herein by reference)). If UDM 407 receives network access restriction enforcement capability information from UE 401 via AMF 403 (e.g., as previously received, such as during UE 401's authentication / registration process / subscriber data management), and if UDM / UDR 407 contains network access restriction information (e.g., as part of subscriber data or UE access and mobility context) indicative of UTRAN and GERAN access restrictions for UE 401 based on the operator's local policy, then UDM 407 provides network access restriction information to UE 401 (e.g., as part of UPU data).

[0075] In 2 (see Message Passing 408), in one embodiment, UDM 407 invokes a Nausf_UPUProtection service operation message to AUSF 405 by including UPU data (e.g., network access restriction information) to obtain UPU-MAC-I. AUSF and Counter UPU UDM 407 can optionally save the latest K from UE 401. AUSF AUSF 405. In one embodiment, if UDM 409 determines that UE 401 will confirm the successful security check of the received UE parameter update data, then UDM 409 includes an ACK indication in the Nausf_UPUProtection service operation message to signal that it still needs the expected UPU-XMAC-I. UE .

[0076] In one embodiment, when calculating UPU-MAC-I AUSF The inclusion of UE parameter update data allows the UE to verify via 401 that it has not been tampered with by any intermediary. Expected UPU-XMAC-I UE UDM 409 is allowed to verify that UE 401 has correctly received UE parameter update data (and network access restriction information).

[0077] In 3 (see Message Passing 410), in one embodiment, AUSF 407 uses a specific home key (K) of UE 401. AUSF The UPU-MAC-I is calculated using UE parameter update data (containing network access restriction information) received from the requester NF (e.g., UDM 409). AUSF And UPU-MAC-I AUSF and Counter UPU Delivered to the requester NF. If the ACK indicates the input exists, then AUSF 407 also calculates UPU-XMAC-I. UE As shown below, and the calculated UPU-XMAC-I is returned in the response. UE .

[0078] For UPU-MAC-I AUSF Generating functions, when from K AUSF Export UPU-MAC-I AUSF At that time, the following parameters are used by AUSF 407 to form the key derivation function (KDF) - FC = 0x7B input S; P0 = UE parameter update data containing network access restriction information, such as the UE parameter update list, as given in Clause 9.11.3.53A of TS 24.501 (starting from octet 23) (incorporated herein by reference); L0 = length of UE parameter update data; P1 = CounterUPU; L1 = length of CounterUPU.

[0079] In one embodiment, the input key Key can be K. AUSF And it detected UPU-MAC-I AUSF It has 128 least significant bits of the output with KDF.

[0080] In one embodiment, for UPU-MAC-I UE / UPU-XMAC-I UE Generating functions, when from K AUSF Export UPU-MAC-I UE / UPU-XMAC-I UE At that time, the following parameters are used by AUSF 407 to form the input S of KDF – FC = 0x7C; P0 = 0x01 (UPU confirmation: UE parameter update data successfully verified); L0 = length of UPU confirmation (i.e., 0x00 0x01); P1 = CounterUPU; L1 = length of CounterUPU.

[0081] In one embodiment, the input key Key can be K.AUSF And recognize UPU-MAC-I UE / UPU-XMAC-I UE It has 128 least significant bits of the output with KDF.

[0082] In 4 (see message 412), in one embodiment, UDM 407 invokes the Nudm_SDM_Notification service operation, which includes the UPU transparent container if AMF 403 supports the UPU transparent container, or includes UE parameter update data (e.g., network access restriction information) and UPU-MAC-I within the access and mobility subscription data. AUSF and Counter UPU Individual IEs. If UDM 407 requests confirmation, then its temporary storage expects UPU-XMAC-I. UE .

[0083] In step 5 (see message passing 414), in one embodiment, upon receiving the Nudm_SDM_Notification message, AMF 403 sends the DL NAS transport message along with network access restriction information as part of the UPU data to the served UE 401. AMF 403 includes a transparent container in the DL NAS transport message (if received from UDM 407 in step 4). Otherwise, if UDM 407 provides an individual IE in step 4, then AMF 403 constructs a UPU transparent container.

[0084] In one embodiment, if AMF 403 receives network access restriction information (UTRAN access restricted, GERAN access restricted) from UDM 407, then this information, as part of the UE context, is stored at AMF 403 along with the SUPI. Furthermore, based on the network access restriction information received from UDM 407 and the network access restriction enforcement capability received from UE 407 (in 1), AMF 403 performs one or more actions, such as not initiating any inter-RAT handover to UTRAN / GERAN, not initiating or forwarding relocation requests related to SRVCC-specific handovers from 5G to 3G or 2G (even if initiated by the RAN), and assigning network access restriction information (UTRAN access restricted, GERAN access restricted) to the RAN in the N2 message to enforce the UTRAN and GERAN access restrictions of UE 401 at the RAN side.

[0085] In 6 (see box 416), in one embodiment, after receiving the DL NAS transmission message, UE 401 updates the data (containing network access restriction information) and Counter based on the received UE parameter update data.UPU Calculate UPU-MAC-I in the same way as AUSF 405. AUSF (like Figure 2 and 3 (as shown in the image), and verify whether it matches the UPU-MAC-I received within the UPU transparent container in the DL NAS transmission message. AUSF Value. If UPU-MAC-I AUSF If authentication is successful and the UPU data contains parameters protected by a security packet (e.g., see 3GPP TS 31.115 (incorporated herein by reference)), UE 401 forwards the security packet to the USIM, for example using the procedure in 3GPP TS 31.111 (incorporated herein by reference). If UPU-MAC-I AUSF If the verification is successful and the UPU data contains parameters that are not protected by security packets (such as network access restriction information), then UE 401 can update its stored parameters using the received parameters in the UDM update data.

[0086] In 7a (see Message Passing 418), in one embodiment, if UDM 407 has requested acknowledgment from UE 401 and (i) UE 401 has successfully verified and updated the UE parameter update data provided by UDM 407, then UE 401 may send a UL NAS transmission message to the serving AMF 403. UE 401 then generates a UPU-MAC-I UE (As specified in 2 and 3, identical to AUSF 405), and the generated UPU-MAC-I is contained within the transparent container in the UL NAS transmission message. UE .

[0087] In 7b (see box 422), in one embodiment, UE 401 stores network access restriction information (UTRAN access is restricted, GERAN access is restricted), and does not select UTRAN access (3G) or GERAN access (2G) even if 5G or 4G signals are unavailable, and UE 401 waits until 5G / 4G signals are available to prevent downgrade attacks.

[0088] In 8 (see Message Passing 420), in one embodiment, if UPU-MAC-I is present... UE If the transparent container is received in the ULNAS transmission message, then AMF 403 sends the Nudm_SDM_Info request message to UDM407 using the transparent container.

[0089] In 9 (see box 424), in one embodiment, if UDM 407 instructs UE 401 to confirm the successful security check of the received UE parameter update data, then UDM 407 will receive the UPU-MAC-I UE With UDM 407 in 4 temporary storage expected UPU-XMAC-I UE Compare them.

[0090] In one embodiment, if UDM 407 supports home-triggered authentication, then UDM 407 can trigger master authentication based on its local policy to refresh the UPU counter based on the value of the counter received in 3.

[0091] Figure 5A and 5B This document describes an example procedure flow for using an ABBA value for degradation protection to indicate UTRAN and GERAN access restriction information, according to aspects of this disclosure. In this embodiment, network access restrictions (e.g., UTRAN and GERAN access restrictions) are enforced using a new ABBA value during primary authentication (e.g., during registration or service access).

[0092] In one embodiment, the new ABBA parameter value can be defined and set by SEAF 505 to indicate any or more of the following: 'UTRAN and GERAN access restricted', 'UTRAN access restricted', 'GERAN access restricted', '5G access only allowed', '5G access only', and 'EPS access allowed'. The ABBA value is provided to UE 501 after successful authentication to prevent degradation attacks related to 3G / 2G redirection, handover, mobility, cell selection, and / or the like. Figure 5A and 5B Describes an enhanced master authentication procedure that sends specific ABBA parameters for network access restrictions to UE 501 and RAN 503.

[0093] In 1a (see Message Passing 502), in one embodiment, UE 501 sends an initial NAS message containing an indication that the UE supports GERAN and UTRAN access restrictions. In one embodiment, the UE sends an initial NAS message containing an IE (Internet Information Processing) indicating support for network access restriction enforcement capabilities. In one embodiment, the network access restriction enforcement capability IE contains information indicating support for GERAN and UTRAN access restrictions.

[0094] In 1b (see Message Passing 504), in one embodiment, SEAF 505 sends a Nausf_UEAuthentication_Authenticate request message to AUSF 507, which contains a Subscription Hidden Identifier (SUCI) / SUPI, the Serving Network (SN) name, and the UE's network access restriction enforcement capability (received in 1a).

[0095] In 1c (see message passing 506), in one embodiment, AUSF 507 sends a Nausf_UEAuthentication_Authenticate request to UDM 509, which contains SUCI / SUPI, SN name, and the UE's network access restriction enforcement capability (received in 1a).

[0096] In 1d (see box 508), in one embodiment, after receiving the Nudm_UEAuthentication_Get request, if a SUCI is received, then UDM 509 invokes the Subscriber Identity De-hiding Function (SIDF). SIDF can de-hide the SUCI to obtain the SUPI before UDM 509 can process the request.

[0097] In 1e (see box 510), in one embodiment, based on the operator’s local policy (or if the 2G / 3G network has been phased out), the UDM / UDR 509 manages GERAN and UTRAN access restrictions as part of the network access restriction requirements for UE 501 in the subscription data that can be configured in the UDM 509 based on the operator’s policy (e.g., as part of the UE access and mobility context).

[0098] In one embodiment, the UDM / UDR 509 manages GERAN and UTRAN access restrictions as part of the mobility restrictions or RAT restrictions information for UE 501 in the subscription data (e.g., as part of the UE access and mobility context).

[0099] In 2 (see Message Passing 512), in one embodiment, UDM 509 sends a Nudm_UEAuthentication_Get response to AUSF 507, which has an authentication vector (AV), SUPI, SN name and network access restriction information indicating UTRAN and GERAN access restrictions for UE 501.

[0100] In 3a (see Message Passing 514), in one embodiment, AUSF 507 sends a Nausf_UEAuthentication_Authenticate response message to SEAF 505 containing an EAP request / AKA' challenge message / 5G SE AV and network access restriction information indicating UTRAN and GERAN access restrictions.

[0101] In 3b (see box 516), in one embodiment, SEAF 505 forwards network access restriction information indicating UTRAN and GERAN access restrictions (if received in 3a) to AMF 505. SEAF 505 uses the network access restriction information indicating UTRAN and GERAN access restrictions and sets the ABBA value. In one embodiment, the ABBA parameter is a variable-length parameter that indicates a value related to 2G / 3G access restrictions or 5G and 4G access restrictions, as shown in Table 1 below:

[0102]

[0103] Table 1: New ABBA values ​​related to network access restrictions.

[0104] In one embodiment, SEAF 505 sets the ABBA parameter to 0x0000. UE 501 can calculate K. AMF Use the ABBA parameters provided by SEAF 505.

[0105] In one embodiment, if the AMF 505 receives network access restriction information (UTRAN access restricted, GERAN access restricted) from the UDM 509, it stores it as part of the UE context along with the SUPI at the AMF 505. Furthermore, based on the network access restriction information received from the UDM 509 and the network access restriction enforcement capability received from the UE 501 (in 1), the AMF 505 performs various actions, including not initiating an inter-RAT handover to UTRAN / GERAN, not initiating or forwarding relocation requests related to SRVCC-specific handovers from 5G to 3G or 2G (even if initiated by RAN 503), and assigning network access restriction information (UTRAN access restricted, GERAN access restricted) to RAN 503 in the N2 message to enforce the UTRAN and GERAN access restrictions on the UE 501 at the RAN 503 side.

[0106] In 4 (see Message Passing 518), in one embodiment, SEAF 505 transparently forwards an EAP Request / AKA' challenge message (if received) and network access restriction information (UTRAN access restricted, GERAN access restricted) to UE 501 in a NAS message authentication request message. The UE forwards the random number (RAND) and the authentication token (AUTN) received in the EAP Request / AKA' challenge message to the USIM. This message may contain ngKSI and ABBA parameters indicating the network access restriction information (UTRAN access restricted, GERAN access restricted).

[0107] In one embodiment, SEAF 505 may include ngKSI and ABBA parameters indicating network access restriction information (UTRAN access restricted, GERAN access restricted) in all EAP authentication request messages. ngKSI may be used by UE 501 and AMF 505 to identify a portion of the native security context created upon successful authentication. SEAF 505 may set the ABBA parameters based on the network access restriction information (UTRAN access restricted, GERAN access restricted). During EAP authentication, in one embodiment, the values ​​of ngKSI and the ABBA parameters indicating the network access restriction information (UTRAN access restricted, GERAN access restricted) sent by SEAF 505 to UE 501 may not be changed. In one embodiment, SEAF 505 needs to understand that the authentication method used is an EAP method that evaluates the authentication method type based on the Nausf_UEAuthentication_Authenticate response message.

[0108] In 5a (see box 520), in one embodiment, upon receiving RAND and AUTN, the USIM verifies the freshness of AV' by checking whether AUTN is acceptable, for example, as described in TS 33.102 (incorporated herein by reference). If so, the USIM calculates the response result (RES). The USIM may return the RES, encryption key (CK), and integrity key (IK) to UE 501. If the USIM calculates Kc (e.g., GPRS Kc) based on CK and IK using the conversion function c3, for example, as described in TS 33.102, and sends it to UE 501, then UE 501 may ignore this GPRS Kc and will not store the GPRS Kc on the USIM or in UE 501.

[0109] refer to Figure 5B In 6 (see Message Passing 524), in one embodiment, UE 501 includes the EAP response / AKA' challenge / RES in the NAS Auth-Resp message. The message was sent to SEAF 505.

[0110] In 7 (see Message Passing 526), ​​in one embodiment, SEAF 505 transparently includes the EAP response / AKA' challenge / RES in the Nausf_UEAuthentication_Authenticate request message. The message was forwarded to AUSF 507.

[0111] In 8 (see box 528), in one embodiment, AUSF 507 verifies the message by comparing the expected result (XRES) with RES, and if AUSF 507 has successfully verified the message, it continues as follows; otherwise, it returns an error to SEAF 505. AUSF 507 notifies UDM 509 of the authentication result.

[0112] In 9 (see Message Passing 530), in one embodiment, AUSF 507 and UE 501 may exchange EAP Request / AKA' notification and EAP Response / AKA' notification messages (if EAP-AKA' is used) via SEAF 505. SEAF 505 may transparently forward these messages.

[0113] In 10 (see box 532), in one embodiment, AUSF 507 derives the Extended Master Session Key (EMSK) from CK' and IK' (if EAP-AKA' is used), as described in RFC 5448. AUSF 507 uses the 256 most significant bits of the EMSK as K. AUSF And then according to K AUSF Calculate K SEAF AUSF 507 sends an EAP success message to SEAF 505 within the Nausf_UEAuthentication_Authenticate response. SEAF 505 can transparently forward the EAP success message along with an ABBA indicating network access restriction information (UTRAN access restricted, GERAN access restricted) to UE 501. In one embodiment, the Nausf_UEAuthentication_Authenticate response message contains K SEAF If AUSF 507 receives a SUCI from SEAF 505 when authentication is initiated, AUSF 507 may also include a SUPI in the Nausf_UEAuthentication_Authenticate response message. AUSF 507 stores the K based on the home network operator's policy. AUSF .

[0114] In 11 (see Message Passing 534), in one embodiment, SEAF 505 sends an EAP success message (if EAP-AKA' is used) or an authentication result as a success message to UE 501 in an N1 message. This message may also include ngKSI and ABBA parameters indicating network access restriction information (UTRAN access is restricted, GERAN access is restricted).

[0115] In 12 (see box 536), in one embodiment, UE 501 derives Kamf based on Kseaf, ABBA indicating network access restriction information (UTRAN access is restricted, GERAN access is restricted) and SUPI.

[0116] In step 13 (see message passing 538), UE 501 sends a NAS safe mode completion message to AMF 505.

[0117] Figure 6 An example of a UE 600 according to aspects of this disclosure is described. UE 600 may include a processor 602, a memory 604, a controller 606, and a transceiver 608. The processor 602, memory 604, controller 606, or transceiver 608, or various combinations thereof, or various components thereof, may be examples of components for performing the aspects of this disclosure described herein. These components may be coupled via one or more interfaces (e.g., operatively, communicatively, functionally, electronically, or electrically).

[0118] Processor 602, memory 604, controller 606, or transceiver 608, or various combinations or components thereof, may be implemented in hardware (e.g., a circuit system). The hardware may include processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), or other programmable logic devices, or any combination thereof configured or otherwise supporting components for performing the functions described in this disclosure.

[0119] Processor 602 may include intelligent hardware devices (e.g., general-purpose processors, DSPs, CPUs, ASICs, FPGAs, or any combination thereof). In some embodiments, processor 602 may be configured to operate memory 604. In some other embodiments, memory 604 may be integrated into processor 602. Processor 602 may be configured to execute computer-readable instructions stored in memory 604 to cause UE 600 to perform various functions of this disclosure.

[0120] Memory 604 may comprise volatile or non-volatile memory. Memory 604 may store computer-readable, computer-executable code containing instructions that, when executed by processor 602, cause UE 600 to perform the various functions described herein. The code may be stored in a non-transitory computer-readable medium, this memory 604, or another type of memory. Computer-readable medium includes both non-transitory computer storage media and communication media, including any media that facilitates the transfer of computer programs from one place to another. Non-transitory storage media may be any available media accessible by a general-purpose or special-purpose computer.

[0121] In some implementations, processor 602 and memory 604 coupled to processor 602 may be configured to cause UE 600 to perform one or more of the functions described herein (e.g., processor 602 executing instructions stored in memory 604). For example, processor 602 may support wireless communication at UE 600 according to the examples disclosed herein.

[0122] UE 600 can be configured to support components for: transmitting an indication of the UE's network access restriction enforcement capability as part of a NAS message with a first network, receiving network access restriction information of the UE indicating restrictions on the UE's access to a second network, storing the network access restriction information, and preventing connection to the second network as indicated in the network access restriction information in response to the unavailability of the first network.

[0123] In one embodiment, the indication of the UE's network access restriction enforcement capability indicates whether the UE supports GERAN access restriction, UTRAN access restriction, or a combination thereof.

[0124] In one embodiment, the second network includes GERAN, UTRAN, or a combination thereof. In one embodiment, the NAS message includes at least one of a registration request message, a security mode completion message, or a combination thereof.

[0125] In one embodiment, UE 600 may be configured to support components for receiving network access restriction information as part of a NAS message, the NAS message including at least one of a NAS security mode command message, a registration accept message, a registration complete message, an authentication request message, an authentication response message, a UE configuration update message, and UPU data.

[0126] In one embodiment, network access restriction information includes ABBA parameter values, which indicate at least one of the following: UTRAN and GERAN access is restricted, UTRAN access is restricted, GERAN access is restricted, 5G access only is allowed, and EPS access is allowed.

[0127] Controller 606 manages the input and output signals of UE 600. Controller 606 can also manage peripheral devices not integrated into UE 600. In some embodiments, controller 606 may utilize an operating system, such as iOS®, Android®, Windows®, or other operating systems. In some embodiments, controller 606 may be implemented as part of processor 602.

[0128] In some embodiments, UE 600 may include at least one transceiver 608. In other embodiments, UE 600 may have more than one transceiver 608. Transceiver 608 may represent a wireless transceiver. Transceiver 608 may include one or more receiver chains 610, one or more transmitter chains 612, or a combination thereof.

[0129] Receiver chain 610 may be configured to receive signals (e.g., control information, data, packets) via wireless media. For example, receiver chain 610 may include one or more antennas for receiving signals over the air or wireless media. Receiver chain 610 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. Receiver chain 610 may include at least one demodulator configured to demodulate the received signal and obtain transmitted data by reversing the modulation technique applied during signal transmission. Receiver chain 610 may include at least one decoder for decoding and processing the demodulated signal to receive the transmitted data.

[0130] Transmitter chain 612 can be configured to generate and transmit signals (e.g., control information, data, packets). Transmitter chain 612 may include at least one modulator for modulating data onto a carrier signal in preparation for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques, such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase shift keying (PSK) or quadrature amplitude modulation (QAM). Transmitter chain 612 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over a wireless medium. Transmitter chain 612 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0131] Figure 7An example of a processor 700 according to aspects of this disclosure is described. Processor 700 may be an example of a processor configured to perform various operations according to the examples described herein. Processor 700 may include a controller 702 configured to perform various operations according to the examples described herein. Processor 700 may optionally include at least one memory 704, which may be, for example, an L1 / L2 / L3 cache. Additionally or alternatively, processor 700 may optionally include one or more arithmetic logic units (ALUs) 706. One or more of these components may be electronically communicated or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses).

[0132] Processor 700 may be a processor chipset and includes a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receive, acquire, retrieve, transmit, output, forward, store, determine, identify, access, write, read) according to the examples described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to the processor chipset (e.g., processor 700) or included in the processor chipset) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase-change memory (PCM), and others).

[0133] Controller 702 can be configured to manage and coordinate various operations of processor 700 (e.g., signaling, receiving, acquiring, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, and reading) to enable processor 700 to support various operations according to the examples described herein. For example, controller 702 can operate as a control unit of processor 700, generating control signals that manage the operation of various components of processor 700. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating operation timing.

[0134] Controller 702 may be configured to fetch (e.g., fetch, retrieve, receive) instructions from memory 704 and determine subsequent instructions to be executed to enable processor 700 to support various operations according to the examples described herein. Controller 702 may be configured to track the memory addresses of instructions associated with memory 704. Controller 702 may be configured to decode instructions to determine the operations to be performed and the operands involved. For example, controller 702 may be configured to interpret instructions and determine control signals to be output to other components of processor 700 to enable processor 700 to support various operations according to the examples described herein. Alternatively or additionally, controller 702 may be configured to manage data flow within processor 700. Controller 702 may be configured to control data transfers between registers, arithmetic logic unit (ALU), and other functional units of processor 700.

[0135] Memory 704 may include one or more caches (e.g., memory local to or included in processor 700) or other memories, such as RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc. In some embodiments, memory 704 may reside within or on the processor chipset (e.g., locally to processor 700). In some other embodiments, memory 704 may reside outside the processor chipset (e.g., remotely from processor 700).

[0136] Memory 704 may store computer-readable, computer-executable code containing instructions that, when executed by processor 700, cause processor 700 to perform the various functions described herein. The code may be stored in a non-transitory computer-readable medium, such as system memory or another type of memory. Controller 702 and / or processor 700 may be configured to execute the computer-readable instructions stored in memory 704 to cause processor 700 to perform various functions. For example, processor 700 and / or controller 702 may be coupled to or coupled to memory 704, and processor 700, controller 702, and memory 704 may be configured to perform the various functions described herein. In some instances, processor 700 may include multiple processors, and memory 704 may include multiple memories. One or more of the multiple processors may be coupled to one or more of the multiple memories, which may be individually or jointly configured to perform the various functions described herein.

[0137] One or more ALU 706s can be configured to support various operations according to the examples described herein. In some embodiments, one or more ALU 706s may reside within or on a processor chipset (e.g., processor 700). In some other embodiments, one or more ALU 706s may reside outside the processor chipset (e.g., processor 700). One or more ALU 706s can perform one or more calculations on data, such as addition, subtraction, multiplication, and division. For example, one or more ALU 706s can receive input operands and opcodes, which determine the operation to be performed. One or more ALU 706s are configured with various logic and arithmetic circuitry, including adders, subtractors, shifters, and logic gates, to process and manipulate data according to the operation. Alternatively, one or more ALU 706s may support logical operations such as AND, OR, XOR, NOR, and NAND, enabling one or more ALU 706s to handle conditional operations, comparisons, and bitwise operations.

[0138] Processor 700 can support wireless communication according to the examples disclosed herein. Processor 700 can be configured or operable to support components for: receiving an indication of a UE's network access restriction enforcement capability, determining network access restriction information, transmitting network access restriction information to the UE, and applying at least one network access restriction based on the indication of the UE's network access restriction enforcement capability and the determined network access restriction information.

[0139] The processor 700 may be configured or operable to support components for: receiving an indication of the UE's network access restriction enforcement capability, determining network access restriction information, configuring the UE's network access restriction information in subscription data associated with the UE, and transmitting network access restriction information.

[0140] The processor 700 may be configured or operable to support components for: transmitting an indication of the UE's network access restriction enforcement capability as part of a NAS message with a first network; receiving network access restriction information of the UE indicating restrictions on the UE's access to a second network; storing the network access restriction information; and preventing connection to the second network as indicated in the network access restriction information in response to the first network being unavailable.

[0141] Figure 8An example of NE 800 according to aspects of this disclosure is described. NE 800 may include a processor 802, a memory 804, a controller 806, and a transceiver 808. The processor 802, memory 804, controller 806, or transceiver 808, or various combinations thereof, or various components thereof, may be examples of components for performing the aspects of this disclosure described herein. These components may be coupled via one or more interfaces (e.g., operatively, communicatively, functionally, electronically, electrically).

[0142] Processor 802, memory 804, controller 806, or transceiver 808, or various combinations or components thereof, may be implemented in hardware (e.g., a circuit system). The hardware may include processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), or other programmable logic devices, or any combination thereof configured or otherwise supporting components for performing the functions described in this disclosure.

[0143] The NE 800 can be configured to support components for: receiving an indication of the UE's network access restriction enforcement capability, determining network access restriction information, transmitting network access restriction information to the UE, and applying at least one network access restriction based on the indication of the UE's network access restriction enforcement capability and the determined network access restriction information.

[0144] In one embodiment, the indication of the UE's network access restriction enforcement capability indicates whether the UE supports GERAN access restriction, UTRAN access restriction, or a combination thereof. In one embodiment, at least one processor is configured to store network access restriction information as part of the UE context.

[0145] In one embodiment, the NE 800 may be configured to support the application of at least one network access restriction by not initiating a handover between RATs to GERAN, UTRAN, or a combination thereof.

[0146] In one embodiment, the NE 800 may be configured to support the application of at least one network access restriction by not initiating or forwarding relocation requests related to SRVCCs for handover to GERAN, UTRAN, or a combination thereof.

[0147] In one embodiment, the NE 800 may be configured to support components for transmitting network access restriction information to the RAN associated with the UE in order to enforce network access restrictions on the UE at the RAN.

[0148] In one embodiment, the NE 800 may be configured to support components for transmitting network access restriction information to the UE in a NAS security message. In one embodiment, the NE 800 may be configured to support components for transmitting network access restriction information to the UE as part of a UE configuration update command.

[0149] In one embodiment, the NE 800 may be configured to support a component for transmitting an acknowledgment to the UDM network function indicating that the UE has received network access restriction information.

[0150] In one embodiment, network access restriction information includes ABBA parameter values, which indicate at least one of the following: UTRAN and GERAN access is restricted, UTRAN access is restricted, GERAN access is restricted, 5G access only is allowed, and EPS access is allowed.

[0151] In one embodiment, the NE 800 may be configured to support components for determining network access restriction information based on the configuration at the NE, the network access restriction information including indications that UTRAN access is restricted / disallowed, GERAN access is restricted / disallowed, or a combination thereof.

[0152] In one embodiment, the NE 800 may be configured to support components for extracting network access restriction information from DM network functions, the network access restriction information including indications that UTRAN access is restricted / disallowed, GERAN access is restricted / disallowed, or a combination thereof.

[0153] In one embodiment, the NE 800 may be configured to support components for: receiving an indication of the UE's network access restriction enforcement capability, determining the UE's network access restriction information, configuring the UE's network access restriction information in subscription data associated with the UE, and transmitting the network access restriction information.

[0154] In one embodiment, the NE 800 may be configured to support components for configuring network access restriction information of the UE in UPU data. In another embodiment, the NE 800 may be configured to support components for configuring network access restriction information of the UE in subscription data associated with the UE based on local policies.

[0155] In one embodiment, the NE 800 may be configured to support components for configuring network access restriction information of a UE in subscription data associated with the UE, based on GERAN, UTRAN, or a combination thereof.

[0156] In one embodiment, the NE 800 may be configured to support components for configuring network access restriction information of the UE as part of the UE’s mobility restrictions, the UE’s RAT restrictions, or a combination thereof in subscription data associated with the UE.

[0157] Processor 802 may include intelligent hardware devices (e.g., general-purpose processors, DSPs, CPUs, ASICs, FPGAs, or any combination thereof). In some embodiments, processor 802 may be configured to operate memory 804. In some other embodiments, memory 804 may be integrated into processor 802. Processor 802 may be configured to execute computer-readable instructions stored in memory 804 to cause NE 800 to perform various functions of this disclosure.

[0158] Memory 804 may comprise volatile or non-volatile memory. Memory 804 may store computer-readable, computer-executable code containing instructions that, when executed by processor 802, cause NE 800 to perform the various functions described herein. The code may be stored in a non-transitory computer-readable medium, this memory 804, or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media, encompassing any media that facilitates the transfer of computer programs from one place to another. Non-transitory storage media may be any available media accessible by a general-purpose or special-purpose computer.

[0159] In some implementations, processor 802 and memory 804 coupled to processor 802 may be configured to cause NE 800 to perform one or more of the functions described herein (e.g., instructions stored in memory 804 are executed by processor 802). For example, processor 802 may support wireless communication at NE 800 according to the examples disclosed herein.

[0160] Controller 806 manages the input and output signals of NE 800. Controller 806 can also manage peripheral devices not integrated into NE 800. In some embodiments, controller 806 may utilize an operating system such as iOS®, Android®, Windows®, or other operating systems. In some embodiments, controller 806 may be implemented as part of processor 802.

[0161] In some embodiments, NE 800 may include at least one transceiver 808. In other embodiments, NE 800 may have more than one transceiver 808. Transceiver 808 may represent a wireless transceiver. Transceiver 808 may include one or more receiver chains 810, one or more transmitter chains 812, or a combination thereof.

[0162] Receiver chain 810 may be configured to receive signals (e.g., control information, data, packets) via wireless media. For example, receiver chain 810 may include one or more antennas for receiving signals over the air or wireless media. Receiver chain 810 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. Receiver chain 810 may include at least one demodulator configured to demodulate the received signal and obtain transmitted data by reversing the modulation technique applied during signal transmission. Receiver chain 810 may include at least one decoder for decoding and processing the demodulated signal to receive the transmitted data.

[0163] Transmitter chain 812 can be configured to generate and transmit signals (e.g., control information, data, or packets). Transmitter chain 812 may include at least one modulator for modulating data onto a carrier signal in preparation for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques, such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase shift keying (PSK) or quadrature amplitude modulation (QAM). Transmitter chain 812 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over a wireless medium. Transmitter chain 812 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0164] Figure 9 A flowchart illustrating a method according to an aspect of this disclosure is provided. The operation of the method may be implemented by the NE, as described herein. In some embodiments, the NE may execute a set of instructions to control the functional elements of the NE to perform the described functions.

[0165] At 902, the method may receive an instruction regarding the UE's network access restriction enforcement capability. The operation of 902 may be performed according to the examples described herein. In some implementations, aspects of the operation of 902 may be referenced... Figure 8 The described NE execution.

[0166] In step 904, the method can determine network access restriction information. The operation of step 904 can be performed according to the examples described herein. In some implementations, aspects of the operation of step 904 may be referenced. Figure 8 The described NE execution.

[0167] In step 906, the method may transmit network access restriction information to the UE. The operation of step 906 can be performed according to the examples described herein. In some implementations, aspects of the operation of step 906 may be described in reference to... Figure 8 The described NE execution.

[0168] In 908, the method may apply at least one network access restriction based on an indication of the UE's network access restriction enforcement capability and determined network access restriction information. The operation of 908 may be performed according to the examples described herein. In some embodiments, aspects of the operation of 908 may be described by reference to... Figure 8 The described NE execution.

[0169] Figure 10 A flowchart illustrating a method according to an aspect of this disclosure is provided. The operation of the method may be implemented by the NE, as described herein. In some embodiments, the NE may execute a set of instructions to control the functional elements of the NE to perform the described functions.

[0170] In step 1002, the method may receive an instruction regarding the UE's network access restriction enforcement capability. The operation of step 1002 may be performed according to the examples described herein. In some implementations, aspects of the operation of step 1002 may be referenced. Figure 8 The described NE execution.

[0171] In step 1004, the method can determine network access restriction information for the UE. The operation of step 1004 can be performed according to the examples described herein. In some implementations, aspects of the operation of step 1004 may be referenced. Figure 8 The described NE execution.

[0172] In step 1006, the method can configure network access restriction information for the UE in subscription data associated with the UE. The operation of step 1006 can be performed according to the examples described herein. In some implementations, aspects of the operation of step 1006 may be derived from references... Figure 8 The described NE execution.

[0173] In 1008, the method may transmit network access restriction information. The operation of 1008 can be performed according to the examples described herein. In some implementations, aspects of the operation of 1008 may be referenced. Figure 8 The described NE execution.

[0174] Figure 11 A flowchart illustrating a method according to an aspect of this disclosure is provided. The operation of the method can be implemented by a UE, as described herein. In some embodiments, the UE can execute a set of instructions to control functional elements of the UE to perform the described functions.

[0175] In 1102, the method may transmit an indication of the UE's network access restriction enforcement capability as part of a NAS message with a first network. The operation of 1102 may be performed according to the examples described herein. In some embodiments, aspects of the operation of 1102 may be described by reference to... Figure 6 The UE execution described.

[0176] At 1104, the method may receive network access restriction information for the UE, indicating restrictions on a second network that the UE can access. The operation of 1104 may be performed according to the examples described herein. In some embodiments, aspects of the operation of 1104 may be described by reference to... Figure 6 The UE execution described.

[0177] In 1106, the method may store network access restriction information. The operation of 1106 can be performed according to the examples described herein. In some implementations, aspects of the operation of 1106 may be referenced. Figure 6 The UE execution described.

[0178] In 1108, the method may prevent connection to a second network as indicated in the network access restriction information in response to the unavailability of the first network. The operation of 1108 may be performed according to the examples described herein. In some embodiments, aspects of the operation of 1108 may be described by reference to... Figure 6 The UE execution described.

[0179] It should be noted that the methods described herein describe possible implementations, and the operations and steps may be rearranged or otherwise modified, and other implementations are possible.

[0180] The description herein is provided to enable those skilled in the art to make or use this disclosure. Various modifications to this disclosure will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other variations without departing from the scope of this disclosure. Therefore, this disclosure is not limited to the examples and designs described herein, but should be given the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A network device NE for wireless communication, comprising: At least one memory; and At least one processor, coupled to the at least one memory and configured to enable the NE: Receive instructions regarding the network access restriction enforcement capability of the user equipment (UE); Determine network access restriction information; The network access restriction information is transmitted to the UE; and At least one network access restriction is applied based on the indication of the UE's network access restriction enforcement capability and the determined network access restriction information.

2. The NE according to claim 1, wherein the indication of the network access restriction enforcement capability of the UE indicates whether the UE supports GSM EDGE radio access network GERAN access restriction, Universal Terrestrial Radio Access Network UTRAN access restriction, or a combination thereof.

3. The NE of claim 1, wherein the at least one processor is configured to store the network access restriction information as part of the UE context.

4. The NE of claim 1, wherein the at least one processor is configured to apply the at least one network access restriction by not initiating a handover between radio access technologies (RATs) to a GSM EDGE radio access network (GERAN), a Universal Terrestrial Radio Access Network (UTRAN), or a combination thereof.

5. The NE of claim 1, wherein the at least one processor is configured to apply the at least one network access restriction by not initiating or forwarding a relocation request related to single radio voice call continuity SRVCC for handover to GSM EDGE radio access network GERAN, Universal Terrestrial Radio Access Network UTRAN, or a combination thereof.

6. The NE of claim 1, wherein the at least one processor is configured to cause the NE to transmit the network access restriction information to a radio access network (RAN) associated with the UE to enforce the network access restriction on the UE at the RAN.

7. The NE of claim 1, wherein the at least one processor is configured to transmit the network access restriction information to the UE in a non-access layer (NAS) security message.

8. The NE of claim 1, wherein the at least one processor is configured to transmit the network access restriction information to the UE as part of a UE configuration update command.

9. The NE of claim 1, wherein the at least one processor is configured to transmit an acknowledgment to the Unified Data Management (UDM) network function indicating that the UE has received the network access restriction information.

10. The NE of claim 1, wherein the network access restriction information includes an anti-inter-architecture degradation ABBA parameter value, which indicates at least one of the following: Universal Terrestrial Radio Access Network (UTRAN) and GSM EDGE Radio Access Network (GERAN) access is restricted, UTRAN access is restricted, GERAN access is restricted, 5G access only is allowed, and Evolved Packet System (EPS) access is allowed.

11. The NE of claim 1, wherein the at least one processor is configured to determine the network access restriction information based on a configuration at the NE, the network access restriction information including an indication that Universal Terrestrial Radio Access Network (UTRAN) access is restricted / disallowed, GSM EDGE Radio Access Network (GERAN) access is restricted / disallowed, or a combination thereof.

12. The NE of claim 1, wherein the at least one processor is configured to cause the NE to extract the network access restriction information from a unified data management UDM network function, the network access restriction information including an indication that Universal Terrestrial Radio Access Network (UTRAN) access is restricted / disallowed, GSM EDGE Radio Access Network (GERAN) access is restricted / disallowed, or a combination thereof.

13. A processor for wireless communication, comprising: At least one controller, coupled to at least one memory and configured to enable the processor to: Receive instructions regarding the network access restriction enforcement capability of the user equipment (UE); Determine network access restriction information; The network access restriction information is transmitted to the UE; and At least one network access restriction is applied based on the indication of the UE's network access restriction enforcement capability and the determined network access restriction information.

14. A method performed by a network equipment (NE), the method comprising: Receive instructions regarding the network access restriction enforcement capability of the user equipment (UE); Determine network access restriction information; The network access restriction information is transmitted to the UE; and At least one network access restriction is applied based on the indication of the UE's network access restriction enforcement capability and the determined network access restriction information.

15. A user equipment (UE) for wireless communication, comprising: At least one memory; and At least one processor, coupled to and configured to enable the UE to: The indication of the UE's network access restriction enforcement capability is transmitted as part of a non-access layer (NAS) message to the first network; Receive network access restriction information for the UE that indicates restrictions on the second network that the UE can access; Store the network access restriction information; and In response to the unavailability of the first network, connection to the second network is prevented as indicated in the network access restriction information.

16. The UE of claim 15, wherein the indication of the network access restriction enforcement capability of the UE indicates whether the UE supports GSM EDGE radio access network GERAN access restriction, Universal Terrestrial Radio Access Network UTRAN access restriction, or a combination thereof.

17. The UE of claim 15, wherein the second network comprises a GSM EDGE radio access network GERAN, a Universal Terrestrial Radio Access Network UTRAN, or a combination thereof.

18. The UE of claim 15, wherein the NAS message includes at least one of a registration request message, a security mode completion message, or a combination thereof.

19. The UE of claim 15, wherein the at least one processor is configured to cause the UE to receive network access restriction information as part of the NAS message, the NAS message including at least one of a NAS security mode command message, a registration request message, a registration completion message, an authentication request message, an authentication response message, a UE configuration update message, and UE parameter update UPU data.

20. The UE of claim 15, wherein the network access restriction information includes an anti-inter-architecture degradation (ABBA) parameter value, which indicates at least one of the following: Universal Terrestrial Radio Access Network (UTRAN) and GSM EDGE Radio Access Network (GERAN) access is restricted; UTRAN access is restricted; GERAN access is restricted; 5G access only is allowed; and Evolved Packet System (EPS) access is allowed.