Radio communication access capabilities of a wireless device
Patent Information
- Application Number
- ES2024198315T
- Authority / Receiving Office
- ES · ES
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-01-10
- Filing Date
- 2020-01-10
- Publication Date
- 2026-09-14
- Estimated Expiration
- 2040-01-10
Smart Images

Figure 00000042_0000 
Figure 00000043_0000 
Figure 00000044_0000
Abstract
Description
Radio communication access capabilities of a wireless device Technical field This application relates, in general, to wireless communications, and more specifically to the radiocommunication access capabilities of a wireless device. Background Wireless devices inform wireless communication networks about their capabilities when joining the network and / or at other times, so that the device and the network can communicate using parameters within the device's capabilities. Device capabilities can be classified into two categories depending on which layer of the protocol hierarchy they relate to. Access stratum (AS) capabilities are portions of the capability information that depend on the access technology, such as the device's power class and supported frequency bands. AS capabilities are used by the radio access network. Therefore, AS capabilities can also be appropriately referred to as radio access capabilities.Non-access stratum (NAS) capabilities are those that are not related to access, such as supported security algorithms. NAS capabilities are used by the core network. Until now, wireless devices have unconditionally provided their radio access capabilities to the radio access network when the radio access network requests them. While this approach allows for early optimization of service / connectivity based on radio access capabilities, it can carry security and / or privacy risks. The draft 3rd generation partnership project (3GPP) S3-160559 discloses 4G network manipulation attacks and discusses some possible solutions to such attacks. Compendium The invention is defined by the independent claims. Preferred embodiments are stated in dependent claims. Some of the implementations described herein ensure the integrity and / or confidentiality of radio access capability information that a wireless communication network receives, stores, and / or uses. Therefore, these and other implementations can safeguard the network against security attacks (e.g., man-in-the-middle attacks) on radio access capability information and / or protect users from being tracked using such information. According to one or more embodiments, for example, a wireless device transmits and / or a radio network node requests (at least part of) radio access capability information only upon or after the activation of access layer (AS) security. In this case, the radio access capability information is then proactively transmitted with integrity protection. In some embodiments, the radio access capability information transmitted upon or after AS security activation constitutes all the radio access capability information that the wireless device is required to transmit.However, in other embodiments, the radio access capability information transmitted at or after the AS security activation constitutes only a part of the radio access capability information that the wireless device must transmit, with another (e.g., less sensitive) part of the information being transmitted before the AS security activation. Alternatively or additionally, the wireless device and / or the radio network node in one or more embodiments retroactively check whether the radio access capability information was received by the network with its data integrity intact. For example, the network may transmit a derivative (e.g., a hash value) of the received information back to the wireless device so that the device can verify the integrity of the information received by the network and perhaps report integrity issues to the network as needed.Therefore, this and other implementations for retroactive integrity checking can ensure that the network does not store and / or otherwise use radio access capability information that was not received with its integrity intact, while at the same time, in some implementations, there is no requirement that the transmission of the information be delayed until the AS security activation. Still other implementations effectively label, flag, contaminate, or otherwise mark radio access capability information as having been received by the wireless communication network before the AS security activation, as having had its integrity verified, and / or as having been transmitted wirelessly without confidentiality protection. Therefore, such a label, flag, contamination, or mark serves as a warning to any network node that the information is subject to the possibility of improper manipulation and / or leakage. In this way, network nodes can handle the radio access capability information accordingly.For example, in some implementations, the network may allow the storage and / or use of information for a limited time if the information is tagged, contaminated, or marked as described above, but may effectively delete the information after certain events and / or time periods have elapsed, so that the information (in case it has been improperly manipulated or leaked) does not propagate and / or have a long-term impact. In another example, some network nodes may trigger the reacquisition of radio access capability information from the device if it was tagged, contaminated, or marked. Therefore, in general terms, some embodiments of this document include a method carried out by a network node in a wireless communication network. The method includes acquiring radio access capability information from a wireless device, where the radio access capability information of the wireless device indicates the device's radio access capabilities. The method may also include determining whether the wireless communication network received the radio access capability information from the wireless device before access layer security was activated for the wireless device.The method may also include, if the wireless communication network received the wireless device's radio access capabilities information before the access layer security for the wireless device was activated according to that determination, reacquiring the wireless device's radio access capabilities information after the access layer security for the wireless device is activated. In some embodiments, the method further comprises determining whether or not to reacquire the radio access capability information of the wireless device after the access layer security for the wireless device is activated, depending respectively on whether or not the wireless communication network received the radio access capability information of the wireless device before the access layer security for the wireless device was activated.Alternatively or additionally, the method may further comprise determining whether or not to store the wireless device's radio access capability information at the network node, depending respectively on whether the wireless communication network received the wireless device's radio access capability information after or before the access layer security was activated for the wireless device. Alternatively or additionally, the method may also comprise determining whether or not to forward the wireless device's radio access capability information from the network node to another network node, depending respectively on whether the wireless communication network received the wireless device's radio access capability information after or before the access layer security was activated for the wireless device. In some embodiments, the method further comprises, if the wireless communication network received the radio access capability information from the wireless device before the access layer security was activated for the wireless device, refraining from storing the radio access capability information on the network node and / or refraining from forwarding the radio access capability information from the network node to another network node.In some embodiments, reacquiring the wireless device's radio access capability information after access layer security is activated for the wireless device comprises, after access layer security is activated for the wireless device: (i) transmitting to the wireless device a capability query requesting the wireless device's radio access capability information; and (ii) receiving the wireless device's radio access capability information in response to the capability query. In some embodiments, reacquiring the wireless device's radio access capability information comprises receiving the wireless device's radio access capability information through a control plane connection after access layer security is activated to secure the control plane connection. In one such embodiment, the control plane connection is a Radio Resource Control (RRC) connection. In some embodiments, reacquiring the wireless device's radio access capability information after access stratum security is activated for the wireless device comprises retrieving the wireless device's radio access capability information using a User Equipment (UE) capability transfer procedure by Radio Resource Control (RRC) after a Security Mode Order (SMC) procedure of the Access Stratum is successfully performed. In some embodiments, the method also includes including, along with the radio access capability information, an indication of whether the radio access capability information was received before the access layer security was activated. In some embodiments, the method also includes transmitting, to another network node, control signaling that indicates whether the radio access capability information was received before the access layer security was activated, its integrity has not been verified and / or it was received from the wireless device without confidentiality protection. In some embodiments, radio access capabilities information comprises: one of multiple Radio Resource Control (RRC) segments indicating the radio access capabilities of the wireless device; or an identifier mapped to the radio access capabilities of the wireless device. In some implementations, the network node is a New Radiocommunications Node B, gNB, a Next Generation Evolved Node B, ng-eNB, or an Evolved Node B, eNB. Other embodiments of this document include a method carried out by a network node in a wireless communication network. The method comprises receiving radio access capability information indicating the radio access capabilities of a wireless device. The method may also comprise creating a derivative of the received radio access capability information. The method may further comprise receiving a derivative of radio access capability information transmitted by the wireless device. The method may then comprise verifying whether the created derivative matches the received derivative.In some embodiments, the method comprises receiving the received derivative within a message that is integrity-protected and / or confidentiality-protected, and receiving radio access capability information from the wireless device via a control plane connection before access layer security is activated on the control plane connection. In some embodiments, the created derivative is a hash value of the received radio access capability information. In some embodiments, the method further comprises triggering a radio resource control (RRC) connection reset or a recovery from the no-access layer in response to verification that the created derivative does not match the received derivative. In some embodiments, radio access capabilities information comprises: one of multiple Radio Resource Control (RRC) segments indicating the radio access capabilities of the wireless device; or an identifier mapped to the radio access capabilities of the wireless device. The embodiments described herein also include a method implemented by a wireless device. The method comprises transmitting radio access capability information to a wireless communication network, indicating the wireless device's radio access capabilities. The method further comprises creating a derivative of the transmitted radio access capability information and transmitting the created derivative to the wireless communication network. In some embodiments, the method comprises transmitting the created derivative within a message that is protected with respect to integrity and / or protected with respect to confidentiality, and transmitting radio access capability information through a control plane connection before access layer security is activated on the control plane connection. In some implementations, the created derivative is a hash value of the transmitted radio access capability information. In some embodiments, radio access capabilities information comprises: one of multiple Radio Resource Control (RRC) segments indicating the radio access capabilities of the wireless device; or an identifier mapped to the radio access capabilities of the wireless device. Other aspects relate to a device network node, a radio communications network node, a wireless device, software products, or a computer-readable storage medium corresponding to the methods summarized above and their corresponding functional implementations. For example, embodiments of this document include a network node configured for use in a wireless communication network. The network node is configured (for example, by means of communication circuitry and processing circuitry) to acquire radio access capability information from a wireless device, where the radio access capability information of the wireless device indicates the wireless device's radio access capabilities.The network node can be configured to determine whether the wireless communication network received radio access capability information from the wireless device before access layer security was activated for the wireless device. The network node can also be configured to reacquire the wireless device's radio access capability information after access layer security is activated if the wireless communication network received the wireless device's radio access capability information before access layer security was activated for the wireless device, based on this determination. The embodiments also include a network node configured for use in a wireless communication network. The network node is configured (for example, by means of communication and processing circuitry) to receive radio access capability information indicating the radio access capabilities of a wireless device. The network node may also be configured to create a derivative of the received radio access capability information. The network node may further be configured to receive a derivative of radio access capability information transmitted by the wireless device. The network node may then be configured to verify whether the created derivative matches the received derivative. The embodiments also include a wireless device. The wireless device is configured (for example, by means of communication circuitry and processing circuitry) to transmit radio access capability information to a wireless communication network, indicating the wireless device's radio access capabilities. The wireless device is further configured to create a derivative of the transmitted radio access capability information and transmit the created derivative to the wireless communication network. Brief description of the drawings Figure 1 is a block diagram of a wireless communication network according to some implementations. Figure 2 is a logic flow diagram of a method carried out by a wireless device according to particular implementations. Figure 3 is a logical flow diagram of a method carried out by a network node according to particular realizations. Figure 4 is a logical flow diagram of a method carried out by a wireless device according to other embodiments. Figure 5 is a logical flow diagram of a method carried out by a network node according to other realizations. Figure 6 is a block diagram of a wireless communication network according to other embodiments. Figure 7 is a logical flow diagram of a method carried out by a network node according to still other embodiments. Figure 8 is a logical flow diagram of a method carried out by a network node according to still other realizations. Figure 9 is a logical flow diagram of a method carried out by a network node according to other realizations. Figure 10 is a block diagram of a wireless device according to particular embodiments. Figure 11 is a block diagram of a wireless device according to other embodiments. Figure 12 is a block diagram of a wireless device according to other embodiments. Figure 13 is a block diagram of a network node according to particular realizations. Figure 14 is a block diagram of a network node according to other realizations. Figure 15 is a block diagram of a network node according to still other realizations. Figure 16 is a block diagram of a network node according to other realizations. Figure 17 is a block diagram of a network node according to other realizations. Figure 18 is a block diagram of a wireless communication system according to some implementations. Figure 19 is a signaling diagram for recovering UE capabilities in an initial onboarding to a network. Figure 20 is a signaling diagram for sending UE capabilities after access layer (AS) security activation according to some embodiments. Figure 21 is a signaling diagram for recovering UE capabilities in establishing a connection. Figure 22 is a signaling diagram for using a hash value of UE capabilities sent after access layer (AS) security activation according to some implementations. Figure 23 is a signaling diagram for sending only a minimal portion of UE capabilities before AS safety activation according to some implementations. Figure 24 is a signaling diagram for an Nx-based handover in New Radiocommunications (NR), according to some realizations. Figure 25 is a block diagram of a wireless communication network according to some implementations. Figure 26 is a block diagram of a user device according to some implementations. Figure 27 is a block diagram of a virtualization environment according to some implementations. Figure 28 is a block diagram of a communication network with a host computer according to some implementations. Figure 29 is a block diagram of a host computer according to some implementations. Figure 30 is a flowchart illustrating a method implemented in a communication system, according to one embodiment. Figure 31 is a flowchart illustrating a method implemented in a communication system, according to one embodiment. Figure 32 is a flowchart illustrating a method implemented in a communication system, according to one embodiment. Figure 33 is a flowchart illustrating a method implemented in a communication system, according to one embodiment. Detailed description Figure 1 shows a wireless communication network 10 (e.g., a 5G network) according to some embodiments. The network 10 includes a core network (CN) 10A and a radio access network (RAN) 10B. The RAN 10B includes one or more radio network nodes 12 (e.g., one or more base stations) to provide radio access to wireless communication devices 14 (also referred to simply as wireless devices), one of which is shown. Through this radio access, a wireless device 14 connects to CN 10A, which in turn can provide the wireless device 14 with access to one or more external networks, such as the Internet. CN 10A, for example, can include different CN nodes, such as a node 16 that can, for example, implement an access and mobility function, AMF. From a protocol structure perspective, Network 10 is divided into an access layer (AS) and a non-access layer (NAS). The AS contains protocols that handle activities between wireless device 14 and RAN 10B, for example, to transport data over a radio link and manage radio resources. The NAS contains protocols that handle activities between wireless device 14 and CN 10A, for example, to establish communication sessions and maintain continuous communication as wireless device 14 moves. Network 10 is also divided into a user plane (UP) and a control plane (CP). The control plane contains protocols responsible for managing transport carriers, while the user plane contains protocols responsible for transporting user traffic. Figure 1 shows that wireless device 14 establishes a control plane connection 18 (for example, in the form of a radio resource control, or RRC, connection) between wireless device 14 and radio network node 12. Wireless device 14 transmits so-called radio access capabilities information 20 to radio network node 12 through this control plane connection 18, for example, by means of one or more wirelessly transmitted RRC messages. Radio access capabilities information 20 is any type of information that indicates the radio access capabilities of wireless device 14. The information 20 can, for example, indicate those capabilities explicitly using explicit parameter values, using multiple capability information segments, or using a (manufacturer-specific) identifier (for example,(Capacity ID) that encodes or maps to a set of capabilities, using compressed information, or similar. Regardless of the particular form in which the capabilities are indicated, the wireless device 14 radio access capabilities as used herein refer to the wireless device's ability to communicate via radio access with RAN 10B. These radio access capabilities may also be referred to as AS capabilities. Therefore, radio access capabilities are distinct from the wireless device 14's capabilities with respect to communication with CN 10A and / or via the NAS. In any case, the radio access capabilities indicated by the radio access capabilities information 20 may include, for example,frequency bands supported by the wireless device, discontinuous receive cycle lengths supported by the wireless device, feature group indicator information indicating support for different types of measurement reports, etc. Alternatively or additionally, radio access capabilities may include one or more of: support for delay balance reports, support for RRC_inactive status, support for UL transmission either via the Master Cell Group (MCG) or Secondary Cell Group (SCG) path for a split Signaling Radio Carrier (SRB), support for uplink (UL) transmission via either the MCG or SCG path for a split Data Radio Carrier (DRB), support for direct SRB between the Service Network (SN) and a UE,Support for EUTRA Vehicle-to-Everything (V2X) communications, support for IMS voice PDCP over NR for an MCG carrier in the NRs, support for various PDCP parameters / features (e.g., PDCP duplication, out-of-order delivery, maximum number of header compression context sessions), support for RLC parameters / features (e.g., supported length(s) of RLC sequence number), MAC parameters / features (e.g., support for large discontinuous receive cycle lengths, support for cell group-configured lease configurations, support for skipping uplink transmission for an uplink lease), and physical layer parameters / features (e.g., supported frequency bands, supported band combinations, support for beam mapping, support for extended cyclic prefix (CP),Support for SRS antenna port switching, supported frequency separation class, supported PDCCH search space monitoring occasions, supported PDSCH mapping types, supported PDCCH blind decoding capabilities, supported PUCCH formats). Regardless, some implementations in this document ensure the integrity and / or confidentiality of the radio access capability information that Network 10 receives, stores, and / or uses. Therefore, these and other implementations can safeguard Network 10 from man-in-the-middle attacks on the radio access capability information and / or protect users from being tracked using that information. According to one or more embodiments, for example, wireless device 14 and radio network node 12 activate AS security 24 to secure control plane connection 18. This may involve the use of security keys to activate or apply integrity protection and / or confidentiality protection on control plane connection 18. After activating AS security 24, wireless device 14, as shown in Figure 1, transmits radio access capability information 20 to the radio network node via control plane connection 18. In some embodiments, therefore, wireless device 14 transmits and / or radio network node 12 receives radio access capability information 20 only upon or after activation of access layer (AS) security 24.In this case, then, the information 20 of radiocommunication access capabilities is proactively transmitted and received with integrity and / or confidentiality protection. In some embodiments, the wireless device 14 transmits the radio access capabilities information 20 to the radio network node 12 in response to receiving a capability query 22 from the radio network node 12 requesting the information 20. In one or more embodiments, the wireless device 14 effectively enforces a policy that it will not transmit the radio access capability information 20 until after the AS security is activated, for example, by delaying such transmission as necessary to first activate AS security 24. Even if the wireless device 14 receives the capability query 22 before the AS security 24 is activated, for example, the wireless device 14 in some embodiments refrains from responding to the query 22 with the information 20 until after the AS security is activated. Then, in one or more embodiments, in response to receiving the capability query 22, the wireless device 14 can check or verify whether the access layer security 24 is or has been activated to secure the control plane connection 18.If access layer security 24 is or has been activated to secure control plane connection 18 according to that check, wireless device 14 will transmit radio access capability information 20 in response to capability request 22. On the other hand, if access layer security 24 is or has not been activated to secure control plane connection 18 according to that check, wireless device 14, in some implementations, may transmit a radio access capability rejection message (not shown), rejecting the radio access capability request. Alternatively or in addition to rejecting the request, wireless device 14 may trigger non-access layer (NAS) recovery. In other embodiments, however, the radio network node 12 imposes, either alternatively or additionally, the policy that the radio access capacity information 20 will not be transmitted wirelessly until after the AS security 24 has been activated. In such a case, the radio network node 12 may refrain from transmitting the capacity query 22 until after the AS security 24 has been activated. Correspondingly, the wireless device 14 may receive the capacity query 22 only upon or after the AS security 24 has been activated. In some embodiments, the radio access capability information 20 transmitted upon or after the activation of AS security constitutes all the radio access capability information that wireless device 14 is required to transmit. Therefore, in this case, wireless device 14 can wait to transmit any radio access capability information (i.e., any type or amount of such information) until after the activation of AS security 24. However, in other embodiments, the radio access capability information 20 transmitted upon or after the activation of AS security 24 constitutes only a portion of the radio access capability information that the wireless device 14 must transmit, with another (e.g., less sensitive) portion 19 being transmitted before the activation of AS security 24. In this case, in some embodiments, the wireless device 14 transmits a first portion 19 of radio access capability information to the radio network node 12 via the control plane connection 18 before activating AS security 24.In some embodiments, this first part 19 of radio access capabilities information includes information considered less sensitive and / or information considered to have a greater impact on early optimization. In one or more embodiments, the first part 19 of information includes frequency bands supported by the wireless device 14, discontinuous receive cycle lengths supported by the wireless device 14, and / or feature group information indicating support for different types of measurement reports. Regardless, upon or after the activation of AS security 24, the wireless device 14 in such embodiments then transmits the radio access capabilities information 20 in the form of a second part of radio access capabilities information.Note that, in embodiments that transmit radiocommunication access capability in the form of RRC segments, the first and second parts may each comprise one or more of these RRC segments. In some implementations that communicate radio access capacity information in parts, radio network node 12 requests these respective parts separately before and after AS security 24 is activated. For example, in some implementations, radio network node 12 transmits a first capacity query requesting the first part 19 before AS security 24 is activated, and transmits a second capacity query (shown as query 22 in Figure 1) requesting the second part after AS security 24 is activated. Therefore, in general, Figure 2 represents a method carried out by a wireless device 14 according to particular embodiments. The method includes establishing a control plane connection 18 between the wireless device 14 and a radio network node 12 (block 200) and activating access layer security to secure the control plane connection 18 (block 210). The method also includes, after the access layer security is activated to secure the control plane connection 18, transmitting, to the radio network node 12 via the control plane connection 18, radio access capabilities information 20 indicating the radio access capabilities of the wireless device 14 (block 220). In some embodiments, the method may also include receiving, from the radio network node 12, a capacity query 22 requesting radio access capabilities from the wireless device 12 (Block 230). In this case, the radio access capability information 20 may be transmitted in response to the capacity query 22. That said, in some embodiments, the method may include, in response to receiving capability query 22, checking whether access layer security is enabled to secure control plane connection 18 (Block 240). The method in this case may include transmitting radio access capability information 20 only if access layer security is enabled to secure control plane connection 18, as determined by this check. Therefore, in some embodiments, the method may further include, in response to determining, based on this check, that access layer security is not enabled to secure control plane connection 18, transmitting a radio access capability rejection message that either rejects the radio access capability request or triggers a recovery from the non-access layer. Therefore, in some embodiments, the capacity query 22 may be received before access stratum security has been activated; that is, Block 230 may occur before Block 210. In one or more embodiments, when this occurs, the method may further include delaying the transmission of the access stratum capacity information 20 over radio communications until access stratum security has been activated. Such a delay may involve, for example, rejecting the query 22 and transmitting the capacity information only in response to a subsequent query received after security activation. Alternatively, the delay may involve waiting to transmit the capacity information 20, without necessarily rejecting the query, until after activation has occurred. In other embodiments shown in Figure 2, capacity query 22 can be received at or after the activation of the access layer security; i.e., Block 230 can take place at or after Block 210. Regardless of whether the capabilities information 20 is transmitted in response to a query, in some embodiments, the method may involve waiting to transmit any radio access capabilities information until after the access layer security has been activated. That is, the wireless device 14 refrains from transmitting any type or amount of radio access capabilities information until after activation, for example, to safeguard all types or parts of that information. In other embodiments, the method may include transmitting, to radio network node 12 via control plane connection 18, a first piece of radio access capability information before access layer security is activated, such that the radio access capability information 20 transmitted (in Block 220) via control plane connection 18 after access layer security is activated is a second piece of radio access capability information. The first piece of radio access capability information may indicate, for example, one or more of: frequency bands supported by the wireless device; discontinuous receive cycle lengths supported by the wireless device 12; or feature group information indicating support for different types of measurement reports.The first and second parts can be a first and second radiocommunication resource control (RRC) segment. In some implementations, this activation includes activating integrity protection and / or confidentiality protection on the control plane connection. In some embodiments, control plane connection 18 is an RRC connection, and radio access capabilities information 20 is transmitted in one or more RRC messages. In some embodiments, the radio access capabilities information 20 comprises information that explicitly indicates the radio access capabilities of the wireless device or comprises a manufacturer-specific capabilities identity mapped to the radio access capabilities of the wireless device 14. In general, in this respect, Figure 3 represents a method carried out by a radio network node according to other specific embodiments. The method includes establishing a control plane connection between a wireless device and the radio network node (block 300) and activating access layer security to secure the control plane connection (block 310). The method further includes, after access layer security is activated, receiving, from the wireless device via the control plane connection, radio access capability information indicating the wireless device's radio access capabilities (block 320). The method may include transmitting, from the radio network node to the wireless device, a capacity query requesting radio access capabilities from the wireless device (Block 330). In this case, the radio access capability information may be received in response to the capacity query. In some implementations, the capacity query is transmitted before access layer security is activated; that is, Block 330 occurs before Block 310. In this case, then, radio access capacity information can be received in Block 320 after access layer security is activated in Block 310, even though the capacity query was sent in Block 330 before access layer security was activated. In other embodiments, the capacity query is transmitted only upon or after the activation of access layer security. In fact, in some embodiments, the method may also include checking whether access layer security is enabled to secure the control plane connection (Block 340), and transmitting the capacity query may include transmitting the capacity query only if access layer security is enabled to secure the control plane connection according to this check. The capacity query may be transmitted upon or after the activation of access layer security. In some implementations, the method may include waiting to transmit any capacity query until it occurs or after the activation of access layer security. In other embodiments, the method may include, before access layer security is activated, transmitting a first capability query to the wireless device via the control plane connection, requesting a first piece of radio access capability information from the wireless device. The method may then include, after access layer security is activated, transmitting a second capability query to the wireless device via the control plane connection, requesting a second piece of radio access capability information from the wireless device. The radio access capability information received via the control plane connection after access layer security is activated may be the second piece of radio access capability information. The method may include receiving, from the wireless device via the control plane connection, a first piece of radio access capability information before access layer security is activated. A second piece of radio access capability information may be received via the control plane connection after access layer security is activated. In some embodiments, the first piece of radio access capability information indicates one or more of the following: frequency bands supported by the wireless device; discontinuous receive cycle lengths supported by the wireless device; or feature group information indicating support for different types of measurement reports.The first and second parts can be a first and second segment of RRC. In some embodiments, the control plane connection is an RRC connection, and the radio access capabilities information is transmitted in one or more RRC messages. The radio access capabilities information may include information that explicitly states the radio access capabilities of the wireless device or include a capabilities identity mapped to the radio access capabilities of the wireless device. Alternatively or additionally, the wireless device 14 and / or the radio network node 12 in one or more embodiments retroactively check whether the radio access capabilities information 20 was received by the radio network node 12 with the information integrity intact.For example, radio network node 12 can transmit a derivative (e.g., a hash value) of the received information back to wireless device 14 so that device 14 can verify the integrity of the information received by radio network node 12 and perhaps report integrity issues to the network as needed. Therefore, this and other implementations for retroactive integrity checking can ensure that network 10 does not store and / or otherwise use radio access capability information 20 that was not received with its integrity intact, while at the same time, in some implementations, there is no requirement that the transmission of the information be delayed until the AS security is activated. In general, in this respect, Figure 4 represents a method carried out by a wireless device according to other particular embodiments. The method includes establishing a control plane connection between the wireless device and a radio network node (block 400). The method may further include (for example, before access layer security is activated to secure the control plane connection) transmitting, to the radio network node via the control plane connection, radio access capability information indicating the wireless device's radio access capabilities (block 410). The method also includes creating a derivative of the transmitted radio access capability information (block 420).The method also includes (for example, during or after a procedure that activates access layer security to secure the control plane connection) transmitting the created derivative to the radio network node; or receiving, from the radio network node, a derivative of radio access capability information received by the radio network node and verifying whether the created derivative matches the received derivative (block 430). In some embodiments, the method includes receiving, from the radio network node, the radio access capability information derivative received by the radio network node and verifying whether the created derivative matches the received derivative. The method may also include transmitting a message to the radio network node indicating either procedure completion or procedure failure, depending on whether the created derivative matches the received derivative according to this verification. The message may include the radio access capability information. The method may include transmitting a message to the radio network node indicating whether the created derivative matches the received derivative. The method may also include receiving the received derivative in a Security Mode Command message during the procedure, where the procedure is a Security Mode Command procedure. In some embodiments, the method includes receiving the received derivative within a message that is protected with respect to integrity and / or protected with respect to confidentiality. The method may also include triggering an RRC connection reset or a recovery from the unreachable layer in response to verifying that the created derivative does not match the received derivative. In other embodiments, the method includes transmitting the created derivative to the radio network node. The control plane connection may be an RRC connection, and radio access capability information may be transmitted in one or more RRC messages. In some embodiments, radio access capabilities information includes information that explicitly indicates the radio access capabilities of the wireless device or includes a manufacturer-specific capability identity mapped to the radio access capabilities of the wireless device. In some implementations, the created derivative is a hash value of the transmitted radio access capability information. In some embodiments, the method comprises transmitting the created derivative to the radio communications network node in or with a completed security mode message. In some embodiments, radio access capability information is transmitted before access layer security is activated over the control plane connection. In other embodiments, the method transmits the created derivative, or receives the derivative from the radio network node, during or after a procedure to activate access layer security over the control plane connection. In one such embodiment, the procedure activates access layer security to secure the control plane connection by activating confidentiality protection and / or integrity protection on the control plane connection. Figure 5 represents a method carried out by a radio network node according to other particular embodiments. The method includes establishing a control plane connection between a wireless device and the radio network node (block 500). The method includes (for example, before activating access layer security to secure the control plane connection) receiving, from the wireless device via the control plane connection, radio access capability information indicating the wireless device's radio access capabilities (block 510). The method further includes creating a derivative of the received radio access capability information (block 520).The method then includes (for example, during or after a procedure that activates access layer security to secure the control plane connection) transmitting the created derivative to the wireless device; or receiving, from the wireless device, a derivative of radio access capabilities information transmitted by the wireless device and verifying whether the created derivative matches the received derivative (block 530). In some implementations, the method includes receiving the derivative. The method may also include transmitting a message to the wireless device indicating either the completion of a procedure or the failure of the procedure, depending respectively on whether the created derivative matches the received derivative according to the verification. The procedure may be a procedure for activating access layer security on the control plane connection. The method may include transmitting a message to the wireless device indicating whether the created derivative matches the received derivative. The method may include receiving the derivative within a message that is protected in terms of integrity and / or protected in terms of confidentiality. The method may include triggering an RRC connection reset or a recovery from the unaccessible stratum in response to verifying that the created derivative does not match the received derivative. In some embodiments, the method involves transmitting the created derivative to the wireless device. In some embodiments, the method includes transmitting the created derivative within a Security Mode Command message, for example, during a Security Mode Command procedure. The method may also include transmitting the created derivative within a message that is integrity-protected and / or confidentiality-protected. In some implementations, the control plane connection is an RRC connection, and radio access capability information is transmitted in one or more RRC messages. This radio access capability information may include information that explicitly states the radio access capabilities of the wireless device or comprise a manufacturer-specific capability identity mapped to the radio access capabilities of the wireless device. In some implementations, the created derivative is a hash value of the received radio access capability information. In some implementations, radio access capability information is received before the activation of access layer security on the control plane connection. In some embodiments, the method comprises transmitting the created derivative, or receiving the derivative from the wireless device, during or after a procedure to activate access layer security on the control plane connection. In one such embodiment, the procedure activates access layer security to secure the control plane connection by activating confidentiality protection and / or integrity protection on the control plane connection. Still other implementations effectively label, flag, contaminate, or otherwise mark radio access capability information as having been received by the wireless communication network before the AS security activation, as having not been verified for integrity, and / or as having been transmitted wirelessly without confidentiality protection. Therefore, such a label, flag, contamination, or mark serves as a warning to any node in the network that the information is subject to the possibility of improper manipulation and / or leakage. In this way, network nodes can handle the radio access capability information accordingly.For example, in some implementations, the network may allow the storage and / or use of information for a limited time if the information is tagged, contaminated, or marked as described above, but may effectively delete the information after certain events and / or time lapses, so that the information (if it has been manipulated or leaked) does not propagate and / or have a long-term impact. In another example, some network nodes may trigger the reacquisition of information from the device's radio access capabilities if that information was tagged, contaminated, or marked. Figure 6 illustrates some embodiments in this regard. As shown, a wireless device 14 can transmit radio access capability information 28 to the RAN / CN 10C via a control plane connection 18. The radio access capability information 28 indicates the radio access capabilities of the wireless device 14. The radio access capability information 28 can be correlated with the radio access capability information 20 described in Figure 1, but without regard to whether the information 28 is transmitted before or after the activation of the AS security 24.Alternatively or additionally, the radio access capabilities information 28 can correspond to the first part 19 of the radio access capabilities information described in Figure 1 that is received before the activation of the AS security 24. As shown, a network node 30A in network 10 (for example, RAN / CN 10C) transmits control signaling 32 to another network node 30B in network 10. In some embodiments, the control signaling 32 indicates that (or if) radio access capability information 28 was received from wireless device 14 before access layer security 24 was activated. In other embodiments, the control signaling 32 indicates alternatively or additionally that (or if) the radio access capability information 28 has not been verified for integrity and / or was received from wireless device 14 without confidentiality protection. In one or more embodiments, the control signaling 32 indicates either of these pieces of information with a tag, flag, contamination, or other mark associated with the radio access capability information 28.The label, flag, contamination, or other mark may, for example, be transmitted with, included in, or mapped to the radio access capabilities information 28. Figure 6, as an example, shows that control signaling 32 may include both the radio access capabilities information 28 and a flag 34, for example, indicating that (or if) the radio access capabilities information 28 was received from the wireless device 14 before access layer security 24 was activated. In one or more embodiments where network nodes 30A and 30B are involved in a wireless device handover 14, control signaling 32 can be included in the handover signaling between network nodes 30A and 30B. For example, when network nodes 30A and 30B are radio communication network nodes (e.g., base stations), control signaling 32 can be included in a handover request from network node 30A to network node 30B. In some embodiments, the network node 30B receiving control signaling 32 may reject, ignore, or reacquire radio access capability information 28 if the control signaling 28 indicates that the information 28 was received from wireless device 14 before access layer security 24 was activated, has not been verified for integrity, and / or was received from wireless device 14 without confidentiality protection. Alternatively or additionally, the network node 30B may determine how to handle radio access capability information 28 based on the control signaling 32. For example, this may involve determining whether or not to store, and / or for how long to store, the radio access capability information 28 at the network node 30B.In such an embodiment, for example, network node 30B may refrain from storing radio access capability information 28 within network node 30B and / or refrain from forwarding radio access capability information 28 to another network node if control signaling 32 indicates that access layer security 24 was active when the radio access capability information 28 was received from wireless device 14, that the integrity of the radio access capability information 28 has not been verified, and / or that the radio access capability information 28 was received without confidentiality protection. These and other embodiments may thus limit the propagation and / or long-term impact of radio access capability information 28 under these circumstances. In view of the above variations and modifications, Figure 7 represents a method carried out by network node 30A according to other particular embodiments. The method includes transmitting, to network node 30B, control signaling 32 indicating that (or if) information 28 of radio access capabilities was received from a wireless device 14 before the access layer security 24 was activated, its integrity has not been verified and / or it was received from the wireless device 14 without confidentiality protection (block 700). The method may include transmitting radio access capabilities information 28 to network node 30B (Block 710), and control signaling 32 may be transmitted in association with radio access capabilities information 28. In some embodiments, control signaling 32 is included in a handover request to network node 30B, where network nodes 30A and 30B are each a radio network node. In other embodiments, network node 30A may be a radio network node and network node 30B may be a core network node. The core network node may be an MME or may implement an AMF. In some embodiments, the method may further comprise: (i) before transmitting the control signaling, determining that the access layer security was not activated when radio access capability information was received from the wireless device; (ii) in response to such determination, requesting the radio access capability information from the wireless device after the access layer security was activated; and (iii) generating the control signaling to indicate that the access layer security was activated when the radio access capability information was received from the wireless device. In some embodiments, radio access capabilities information comprises information that explicitly indicates the radio access capabilities of the wireless device or comprises a capabilities identity mapped to the radio access capabilities of the wireless device. In other embodiments, network node 30A is a central network node and the other network node 30B is a central network node. Figure 8 represents a corresponding method carried out by network node 30B according to other particular embodiments. The method includes receiving, from network node 30A, control signaling 32 indicating that (or if) information 28 of radio access capabilities was received from a wireless device 14 before the access layer security 24 was activated, its integrity has not been verified and / or it was received from the wireless device 14 without confidentiality protection (block 800). The method may also include receiving radio access capabilities information 28 from network node 30A (Block 20), and control signaling 32 may be received in association with radio access capabilities information 28. In some embodiments, control signaling 32 is included in a network node 30A handover request, for example, where network nodes 30A, 30B are each a radiocommunications network node. In some embodiments, the method may further include requesting radio access capability information 28 from the wireless device 14 after activation of access layer security 24, or accepting radio access capability information 28 received from the network node 30A, depending on the control signaling 32 (Block 820). Network node 30A can be a core network node, and network node 30B can be a radio communications network node. The core network node can be an MME or implement an AMF. In some embodiments, the method may include receiving radio access capability information 28 from network node 30A and determining how to process the received radio access capability information 28 based on control signaling 32. This determination may include deciding whether or not to store the radio access capability information at network node 30B.The method may alternatively or additionally include storing or refraining from storing the received radio access capability information 28 at network node 30B, depending on whether access layer security 24 was enabled when the radio access capability information 28 was received from wireless device 14, whether the integrity of the radio access capability information has been verified, and / or whether the radio access capability information was received without confidentiality protection (Block 830). The determination may alternatively or additionally include determining whether or not to forward the received radio access capability information 28 to another network node.The method may alternatively or additionally include forwarding or refraining from forwarding the received radio access capability information 28, depending on whether or not access layer security 24 was enabled when the radio access capability information 28 was received from the wireless device 14, whether or not the integrity of the radio access capability information has been verified, and / or whether or not the radio access capability information was received without confidentiality protection. In some embodiments, the control signaling and / or radio access capability information received includes an identifier of a node or cell that retrieved the radio access capability information from the wireless device or another node. The radio access capability information may include information that explicitly states the radio access capabilities of the wireless device or include a capability identity mapped to the radio access capabilities of the wireless device. In some embodiments, network node 30B is a core network node, and the other network node 30A is a core network node. In other embodiments of this document, control signaling 32 may alternatively or additionally indicate one or more restrictions or limitations on the storage, use, and / or propagation of radio access capability information 28. For example, control signaling 32 may indicate a limited time window during which radio access capability information 28 may be stored, used, and / or propagated. Alternatively or additionally, control signaling 32 may indicate limited form(s) and / or purpose(s) for which radio access capability information 28 may be used. These and other embodiments may similarly limit the propagation and / or long-term impact of radio access capability information 28. Figure 9 represents a method carried out by a network node in a wireless communication network 10 according to other particular embodiments. The method includes acquiring radio access capability information 28 from a wireless device 14 (Block 900). The radio access capability information 28 of the wireless device 14 indicates the wireless access capabilities of the wireless device 14. The method also includes determining whether the wireless communication network 10 received the radio access capability information 28 from the wireless device 14 before the access layer security 24 was activated for the wireless device 14 (Block 910). The method in some embodiments further includes, if the wireless communication network 10 received the radio access capabilities information 28 of the wireless device 14 before the access stratum security 24 for the wireless device 14 was activated according to said determination, reacquiring the radio access capabilities information 28 of the wireless device 14 after the access stratum security 24 for the wireless device 14 is activated (Block 920).Alternatively or additionally, the method may include, if the wireless communication network 10 received the radio access capabilities information 28 from the wireless device 14 before the access stratum security 24 was activated for the wireless device 14 as determined, refraining from storing the radio access capabilities information 28 on the network node and / or refraining from forwarding the radio access capabilities information 28 from the network node to another network node (Block 930). The embodiments described herein also include corresponding apparatus. For example, the embodiments described herein include a wireless device configured to perform any of the steps of any of the embodiments described above for the wireless device. The embodiments also include a wireless device comprising processing circuitry and power supply circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the wireless device. The power supply circuitry is configured to supply power to the wireless device. The embodiments further include a wireless device comprising processing circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the wireless device. In some embodiments, the wireless device further comprises communication circuitry. The embodiments further include a wireless device comprising processing circuitry and memory. The memory contains instructions executable by the processing circuitry, whereby the wireless device is configured to perform any of the steps of any of the embodiments described above for the wireless device. The embodiments also include a user equipment (UE). The UE comprises an antenna configured to send and receive wireless signals. The UE also comprises radio communication front-end circuitry connected to the antenna and processing circuitry, and configured to condition signals communicated between the antenna and the processing circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the wireless device. In some embodiments, the UE also comprises an input interface connected to the processing circuitry and configured to allow input of information into the UE for processing by the processing circuitry.The UE may include an output interface connected to the processing circuitry and configured to output information from the UE that has been processed by the processing circuitry. The UE may also include a battery connected to the processing circuitry and configured to supply power to the UE. The realizations in this document also include a network node configured to carry out any of the steps of any of the realizations described above for the network node. The embodiments also include a network node comprising processing circuitry and power supply circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the network node. The power supply circuitry is configured to supply power to the network node. The embodiments also include a network node comprising processing circuitry. The processing circuitry is configured to perform any of the steps of any of the embodiments described above for the network node. In some embodiments, the network node also comprises communication circuitry. The embodiments also include a network node comprising processing circuitry and memory. The memory contains instructions executable by the processing circuitry, whereby the network node is configured to carry out any of the steps of any of the embodiments described above for the network node. More specifically, the devices described above can carry out the methods of this document and any other processing by implementing any circuitry, units, modules, or functional means. In one embodiment, for example, the devices comprise respective circuits or circuitry configured to carry out the steps shown in the method figure. The circuits or circuitry in this respect may comprise circuits dedicated to carrying out certain functional processing and / or one or more microprocessors together with memory. For example, the circuitry may include one or more microprocessors or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs), special-purpose digital logic, and the like.The processing circuitry may be configured to execute program code stored in memory, which may include one or more types of memory, such as read-only memory (ROM), random-access memory, cache memory, flash memory devices, optical storage devices, etc. The program code stored in memory may include program instructions for executing one or more telecommunications and / or data communication protocols, as well as instructions for performing one or more of the techniques described herein, in various embodiments. In embodiments that employ memory, the memory stores program code that, when executed by the processor or processors, performs the techniques described herein. Figure 10, for example, illustrates a wireless device 1000 implemented according to one or more embodiments. As shown, the wireless device 1000 includes processing circuitry 1010 and communication circuitry 1020. The communication circuitry 1020 (e.g., radio communication circuitry) is configured to transmit and / or receive information to and / or from one or more other nodes, for example, using any communication technology. Such communication may occur using one or more antennas that are either internal or external to the wireless device 1000. The processing circuitry 1010 is configured to perform the processing described above, such as executing instructions stored in memory 1030. In this respect, the processing circuitry 1010 may also implement certain functional modules, units, or means. Figure 11 illustrates a schematic block diagram of a wireless device 1100 in a wireless network according to other embodiments (e.g., the wireless network shown in Figure 25). As shown, the wireless device 1100 implements various modules, units, or functional means, for example, by means of the processing circuitry 1010 of Figure 10 and / or by means of software code. These modules, units, or functional means, for example, for implementing the method(s) herein, include, for example: a connection-establishment unit 1110 configured to establish a control plane connection between the wireless device and a radio network node, and an activation unit 1120 configured to activate access layer security in order to secure the control plane connection.The 1100 wireless device also includes an 1130 transmit unit configured to, after access layer security is activated, transmit to the radio network node via the control plane connection, radio access capability information indicating the wireless device's radio access capabilities. Figure 12 illustrates another working implementation of a 1200 wireless device, according to some embodiments, and includes a 1210 connection-establishment unit configured to establish a control plane connection between the wireless device and a radio network node. The 1200 wireless device also includes a 1220 transmission unit configured to, before access layer security is activated to secure the control plane connection, transmit radio access capability information to the radio network node via the control plane connection. This information indicates the wireless device's radio access capabilities. The 1200 wireless device also includes a 1230 creation unit configured to create a derivative of the transmitted radio access capability information.The 1220 transmit unit is also configured to, during or after a procedure that activates access layer security to secure the control plane connection, transmit the created derivative to the radio network node. The 1200 wireless device also includes a 1240 receive unit configured to, during or after the procedure that activates access layer security to secure the control plane connection, receive from the radio network node a derivative of radio access capability information received by the radio network node and verify whether the created derivative matches the received derivative. Figure 13 illustrates a network node 1300, such as a radio communications network node or a core network node, implemented according to one or more embodiments. As shown, the network node 1300 includes processing circuitry 1310 and communication circuitry 1320. The communication circuitry 1320 is configured to transmit and / or receive information to and / or from one or more other nodes, for example, using any communication technology. The processing circuitry 1310 is configured to perform the processing described above, such as executing instructions stored in memory 1330. The processing circuitry 1310 may implement certain functional modules, units, or means. Figure 14 illustrates a schematic block diagram of a radio network node 1400 in a wireless network according to several other embodiments. As shown, the network node 1400 implements various modules, units, or functional means, for example, by means of the processing circuitry 1310 of Figure 13 and / or by means of software code. These modules, units, or functional means, for example, for implementing the method(s) described herein, include, for example: a connection-establishment unit 1410 configured to establish a control plane connection between a wireless device and the radio network node, and an activation unit 1420 configured to activate access layer security in order to secure the control plane connection.The 1400 wireless device also includes a 1430 receiving unit configured to, after access layer security is activated, receive from the wireless device via the control plane connection, radio access capability information indicating the wireless device's radio access capabilities. Figure 15 illustrates another working implementation of a radio network node 1500, according to some embodiments, and includes a connection-establishment unit 1510 configured to establish a control plane connection between a wireless device and the radio network node. The radio network node 1500 also includes a receive unit 1520 configured to receive, before access layer security is activated to secure the control plane connection, radio access capability information from the wireless device via the control plane connection. This information indicates the wireless device's radio access capabilities. The radio network node 1500 also includes a creation unit 1530 configured to create a derivative of the received radio access capability information.The 1520 receiving unit is also configured to, during or after a procedure that activates access layer security to secure the control plane connection, receive a derivative of radio access capability information transmitted by the wireless device and verify whether the created derivative matches the received derivative. The 1500 radio network node also includes a 1540 transmitting unit configured to, during or after the procedure that activates access layer security to secure the control plane connection, transmit the created derivative to the wireless device. Figure 16 illustrates another working implementation of a 1600 network node, according to some embodiments, and includes a 1610 transmission unit configured to transmit, to another network node, control signaling that indicates whether or not access layer security was enabled when radio access capability information was received from a wireless device indicating the wireless device's radio access capabilities. Figure 17 illustrates another working implementation of a 1700 network node, according to some embodiments, and includes a 1710 receiving unit configured to receive, from another network node, control signaling indicating whether or not access layer security was enabled when radio access capability information was received from a wireless device indicating the wireless device's radio access capabilities. Those skilled in the art will also appreciate that the implementations of this document also include corresponding computer programs. A computer program comprises instructions that, when executed on at least one processor of a device, cause the device to perform any of the respective processing operations described above. A computer program in this respect may comprise one or more code modules corresponding to the means or units described above. The implementations also include a medium containing the software. This medium may comprise an electronic signal, an optical signal, a radio communication signal, or a computer-readable storage medium. In this respect, realizations of this document also include a computer program product stored on a computer-readable non-transient (storage or recording) medium and comprising instructions that, when executed by a processor of an apparatus, cause the apparatus to function as described above. The embodiments further include a software product comprising program code portions for carrying out the steps of any of the embodiments herein when the software product is executed by a computer device. This software product may be stored on a computer-readable recording medium. Additional embodiments are described below. At least some of these embodiments may be described as applicable in certain contexts and / or types of wireless networks for illustrative purposes, but the embodiments are similarly applicable in other contexts and / or types of wireless networks not explicitly described. In one or more of the following embodiments, a UE is analyzed as an example of the wireless device 14 in Figure 1, the network (in general) or the gNB (specifically) is analyzed as an example of the radio network node 12 in Figure 1, and AS capabilities or UE capabilities are analyzed as an example of radio access capabilities indicated by the radio access capabilities information 20 in Figure 1. Figure 18 illustrates a simplified wireless communication system with a UE 102 communicating with one or more access nodes 103-104, which in turn are connected to a network node 106. The access nodes 103-104 are part of the radio access network 100. For wireless communication systems compliant with the 3GPP Evolved Packet System (EPS) standard specifications (also referred to as Long-Term Evolution, LTE, or 4G), as specified in 3GPP TS 36.300 and related specifications, access nodes 103-104 typically correspond to an Evolved NodeB (eNB), and network node 106 typically corresponds to either a Mobility Management Entity (MME) and / or a Service Gateway (SGW). The eNB is part of the radio access network 100, which in this case is the E-UTRAN (Evolved Universal Terrestrial Radio Access Network), while the MME and the SGW are both part of the EPC (Evolved Packet Core Network). The eNBs are interconnected via the X2 interface and are connected to the EPC via the S1 interface, more specifically via S1-C to the MME and via S1-U to the SGW. For wireless communication systems compliant with the 3GPP 5GS System Standard Specifications (also referred to as New Radiocommunications, NR, or 5G), as specified in 3GPP TS 38.300 and related specifications, access nodes 103-104 typically correspond to a 5G NodeB (gNB), and network node 106 typically corresponds to either an Access and Mobility Management Function (AMF) and / or a User Plane Function (UPF). The gNB is part of the radio access network 100, which in this case is the NG-RAN (Next Generation Radio Access Network), while the AMF and UPF are both part of the 5G Core Network (5GC). The gNBs are interconnected via the Xn interface and are connected to the 5GC via the NG interface, more specifically via the NG-C to the AMF and via the NG-U to the UPF.To enable rapid mobility between NR and LTE and avoid a core network switch, LTE eNBs can also connect to the 5G-CN via the NG-U / NG-C and support the Xn interface. An eNB connected to the 5GC is called a next-generation eNB (ng-eNB) and is considered part of the NG-RAN. To allow for a wide range of UE implementations, different UE capabilities are specified in LTE and NR. These UE capabilities are sent by the UE to the network when a connection is established, and the network uses them to select a configuration supported by the UE. In general, UE capabilities can be classified into two categories depending on which layer of the protocol hierarchy the given capability relates to. Access stratum (AS) capabilities are portions of capability information that depend on the access technology, such as the UE's power class and supported frequency bands. AS capabilities are used by the radio access network (i.e., eNB / gNB). Non-access stratum (NAS) capabilities are those that are not related to access, such as supported security algorithms. NAS capabilities are used by the core network (i.e., EPC or 5GC). For convenience and without loss of generality, only AS capabilities will be discussed. Furthermore, unless otherwise specified, the term UE capabilities refers to AS capabilities.The AS capabilities (also referred to as UE capabilities) will now be analyzed as an example of the radio access capabilities indicated by information 20 on radio access capabilities in Figure 1. UE capabilities are transferred using RRC signaling from the UE to the radio access node. To avoid requiring UEs to send AS capabilities across the radio interface each time the UE transitions to connected mode (i.e., when the UE-specific context is created in the radio access network), the radio access node stores the AS capabilities in the core network (i.e., MME / AMF) while the UE is in standby mode. On subsequent transitions to connected mode, the access node can retrieve the AS capabilities from the core network instead of requesting them again from the UE. AS capabilities are typically retrieved from the UE when the UE is first incorporated into the network. Since the core network has no valid UE capability information stored in this case, it will not provide UE capabilities to the radio access node when the initial UE context is established after the RRC connection is established. This will cause the radio access node to retrieve the UE capabilities from the UE using the UE capability transfer procedure and upload them to the core network. Initial incorporation and capability retrieval are illustrated in Figure 19 for the NR case. Figure 19 shows that the RAN retrieves UE capabilities, and these are stored in the CN upon initial incorporation into the network. The next time the UE connects to the network, such as for a service request, the UE's capabilities are stored in the core network and provided to the radio access node as part of establishing the UE's initial context. This is illustrated in Figure 21 for the NR case. Figure 21 shows that UE capabilities are stored in the CN and retrieved by the RAN upon connection establishment. In both LTE and NR, the network can request the UE to provide its capabilities for specific RAT(s) in the UE capacity inquiry message. When the UE responds, it includes its capabilities for each of the specified RATs in a specific RAT capacity container in the UE capacity information message. For NR, the network can further request the UE to provide NR capabilities only for a restricted set of band combinations in order to reduce the size of the capacity information that needs to be transferred. In connected-mode mobility (i.e., a handover), UE capabilities are transferred to the destination access node either from the source access node or from the source core network, depending on the handover type. For intra-RAT handovers (i.e., NR-to-NR or LTE-to-LTE), UE capabilities are transferred directly from the source access node to the destination access node in the inter-node messages exchanged between the source and destination access nodes. For inter-RAT handovers (i.e., LTE-to-NR or NR-to-LTE), UE capabilities are transferred from the source core network to the destination core network, which then forwards them to the destination access node. Traditionally, UE capabilities have been considered static information, meaning they can be retrieved once and then stored in the core network for future use. However, in recent years, UE providers have demanded the ability to dynamically change UE capabilities depending on the scenario and environment in which the UE operates. Therefore, in LTE NR and later versions, the UE can inform the core network that it has updated its UE capabilities during the tracking area update procedure, triggering the core network to initiate a new UE capability retrieval process. There is an ongoing study within 3GPP called Radio Capacity Signaling Optimizations (RACS), see TR 23.743, which considers multiple solutions for efficiently transferring UE capacities from the UE to the network. The mechanisms analyzed in the study include UE capacity segmentation, UE capacity compression, and assigning a short ID to UE capacities, referred to as the UE capacity ID. The motivation for studying these improvements is that UE capacities tend to become very large in NRs due to the numerous combinations of bands and radio parameters. In some cases, the bandwidth is even larger than 65 kB. Today, UE capabilities can be retrieved before the AS security is activated, meaning they are sent across the air interface without confidentiality and integrity protection. When retrieved before AS security is activated, this lack of integrity protection means an attacker can manipulate UE capabilities and thus negatively impact communication between the UE and the network. This attack is compounded by the fact that the manipulated UE capabilities are stored on the network and could potentially be used for a long time (i.e., the attack is a so-called persistent attack). Furthermore, when recovered before the AS security activation, the lack of confidentiality protection implies a privacy risk since an attacker can potentially use the UE's capabilities to identify and track the UE. The solutions analyzed in the version 16 study paper on Radio Capability Signaling Optimizations (RACS), including segmentation, compression, and ID mapping for UE capabilities, are vulnerable to threats similar to UE and network privacy manipulation. In the case of UE capability compression, the compressed UE capabilities could be altered by a man-in-the-middle attack. In the case of UE capability segmentation, individual segments could be altered by a man-in-the-middle attack. In the case of solutions with UE capability IDs, the UE capability ID could be modified, or the mapping of UE capability IDs across the RAN and core network could be manipulated, indicating incorrect capabilities for a specific UE capability ID. Certain aspects of this disclosure and its implementations may provide solutions to these or other challenges. To ensure the integrity of EU capabilities, the following solutions may be considered: a) Only allow the recovery of UE capabilities after the activation of AS security; b) UE capabilities can be retrieved from the UE before AS security activation, but the creation (as a hash value) is then securely sent back to the UE or network so that the UE or network can verify the integrity of the previously retrieved UE capabilities; c) Only a minimal portion of UE capabilities can be recovered prior to the activation of AS security (e.g., the capabilities required to initiate early measurement reports); and d) UE capabilities can be recovered before the AS security activation, but are then tagged so that the subsequent recipient is aware of this fact and can decide whether to request UE capabilities again. Solutions (a) and (c) are also beneficial from the user privacy point of view, since in these solutions no UE capability information is revealed, or only a minimum of it is revealed, through the air interface. It should be noted that most of the solutions / features described below for LTE and NR in this document also apply to LTE connected to a 5GC. Where the term LTE is used hereafter without further specification, it refers to LTE-EPC. The lessons described herein can be applied to both AS and NAS capabilities, as well as radio and security capabilities. The lessons are not intended to be limited to EPS or 5GS only. The lessons can also be applied when UE capabilities are compressed, segmented, or represented by a capability ID assigned to the network / UE. Some implementations in this document enable the system to detect if UE capabilities have been improperly manipulated during transmission between the UE and the network. These implementations can also minimize privacy exposure due to exposed UE capabilities during transmission between the UE and the network. The implementations offer the advantage of preventing an attacker from manipulating wirelessly transmitted UE capabilities and thereby causing damage to the network or the UE, such as service degradation. Alternatively or additionally, the implementations provide the advantage of mitigating the aforementioned privacy risk. More specifically, in one embodiment, the UE (e.g., as wireless device 14 in Figure 1) checks that the AS security (e.g., AS security 24) has been activated before it broadcasts its capabilities to the network (e.g., as represented by radio network node 12 in Figure 1). This is illustrated in the signaling diagram in Figure 20 for the NR case. Figure 20 illustrates the transmission of UE capabilities after AS security activation. In Step 1, the networks send the UE capability query message to the UE. Upon receiving the UE capability query message, the UE checks that AS security has been activated (Step 2). If AS security has not been activated, the UE can ignore the message, send a UE capability rejection, or trigger some error recovery mechanism such as NAS recovery.Provided the check in the previous step is successful, the UE responds with the UE capabilities information message, which includes the UE's capabilities (Step 3). Another variation of the previous solution is to allow the UE capacity query message to be sent before the AS security activation, but not the UE capacity information message containing the UE capabilities. This means that even if the UE receives a UE capacity query before the security activation, it waits until the AS security activation has been successful. Only after successful AS security activation does the UE respond with the UE capacity information message. This also covers scenarios where UE capabilities are segmented, compressed, or represented by a capability ID assigned to the network / UE. Yet another variation of the above solution is that the network waits to send the UE capacity query message to the UE until AS security has been enabled. In some implementations, a hash value is used as an example of a UE capability derivative. This is intended as an example and is not exhaustive. Other examples of derivatives include a UE capability size, a keyed hash value, a message authentication code generated using a cryptographic integrity protection algorithm, a digital signature using public / private key cryptography, or any other method that allows both the UE and the network to create the same derivative. In one implementation, UE capabilities can be sent by the UE to the network before the AS security activation, but the network sends a derivative (e.g., a hash value) to the UE after the AS security activation so that the UE can verify the integrity of the UE capabilities received from the network. An example of this solution is illustrated in Figure 22 for the NR case.Figure 22 illustrates a solution that uses a hash value of UE capabilities sent after AS security activation. In this example solution, the network sends the UE capability query message to the UE (Step 1). The UE responds with a UE capability information message containing the UE capabilities (Step 2). Upon AS security activation, the network includes a hash value of the UE capabilities received in the previous step in the security mode command (Step 3). Note that the security mode command is sent with integrity protection. The UE verifies that the hash value of the UE capabilities sent in Step 2 matches the hash value received from the network (Step 4). If the verification fails, the UE can trigger an appropriate failover mechanism, such as security mode failure, RRC reset, or NAS recovery.The UE can also send a security mode complete message and include UE capabilities again. Note that the security mode complete message is protected for security purposes. Whenever the check in the previous step is successful, the UE responds with the security mode complete message, indicating to the network that the hash value verification was successful (Step 5). Note that, in the example above, the hash value is sent in the security mode command message, but in principle, any downlink message sent after the AS security activation could be used. It is also possible to reverse the roles of the UE and the network; that is, the UE can send the hash value to the network after the AS security activation, and then the network performs the verification. If the hash value is sent from the UE to the network using a new procedure (i.e., the security mode command procedure is not reused), then a new response message from the network to the UE can indicate the verification result. If the UE sends the hash value to the network in the security mode complete message, the following can occur. If the verification fails, the network can attempt to release the UE by sending an RRC release message. Alternatively, the network can simply ignore the UE, as this will ultimately trigger a NAS reset or recovery on the UE side.Another option is for the RAN to indicate that the verification failed to the CN, which, in turn, takes some appropriate action, for example, triggering a release from the UE. In another embodiment, for a UE capacity exchange based on a compression solution before AS security is activated, the hash value can be provided for either the compressed or uncompressed capacities, or even both. In another embodiment, for an RRC-based slicing solution, when UE capacity is segmented and swapped from the UE to the network before AS security is activated, the hash value is provided for each segment after AS security is activated. The network can then perform a cross-check to determine whether any of the UE capacity segments have been tampered with. In another embodiment, in the case of a capability ID mapping solution provided by a UE or network vendor, where the capability ID is exchanged from the UE to the network before AS security is activated, the hash value for the capability ID can be provided after AS security activation. This would prevent mapping corruption between a vendor-assigned UE capability ID and the UE capability in the AMF or RAN node's mapping database. In the event of a UE capability change, the UE can use a new UE capability ID or reuse the same capability ID with a delta configuration indication or the hash value of the new capability ID. The delta configuration hash value can be swapped after AS security activation. The same applies to a filtered capacity request. In this case, the UE could respond with a new capacity ID or a capacity ID along with a delta configuration indication. The hash value of the new capacity ID or the hash value of the delta configuration should be swapped after the AS security activation. In this solution, the UE only sends a minimal portion of its capabilities if AS security has not been activated. This minimal portion could be predefined in the standard, or the network could specify which portions are needed when requesting UE capabilities. The full set of UE capabilities would be transmitted later, after AS security is activated. This solution could be useful in cases where certain UE capabilities (such as supported bands) are needed initially to configure, for example, UE measurement reports. An example of this solution is illustrated in Figure 23 for the NR case. Figure 23 illustrates only a minimal portion of the UE capabilities sent before AS activation. In this example solution, the network sends the UE capability query message to the UE (Step 1).Since the UE capacity query message was received before the AS security activation, the UE only includes a minimal set of UE capabilities in the UE capability information message sent to the network. Note that, with this solution, capabilities acquired early can benefit from being reacquired after the start of security or protection provided by the solutions described above. In another embodiment, for an RRC-based solution where UE capabilities are segmented, UE capability segmentation is performed in such a way that non-sensitive / non-confidential UE capability segments are exchanged before security is activated, and the remaining sensitive / confidential UE capability segments are exchanged after security activation. The RAN node is designed to process the UE capability segments individually before and after security activation. Once the onboarding procedure is complete, the RAN node can exchange the multiple UE capability segments as a single record to the core network. Another possibility is to allow UE capabilities to be recovered without integrity protection, but only allow them to be stored in the core network or forwarded to another access node if they were recovered with integrity protection. This way, an attacker's manipulation of UE capabilities has only a local effect, as the manipulated capabilities would only be used in a single cell / node. This solution can be generalized by including an indicator alongside the UE capabilities to inform the subsequent recipient whether the UE capabilities were received with integrity protection.When UE capabilities are forwarded within the network (for example, between a core network node and a radio access node, between two core network nodes, or between two radio access nodes), the receiving node, depending on its security policy, might choose to re-request the UE capabilities if they were received without integrity protection. This can be useful, for example, in a multi-vendor network where different network providers supply equipment to different parts of the network and where the providers have different implementations or apply different security policies. Figure 24 illustrates an Xn-based handover in the NRs, where the destination gNB re-requests UE capabilities because the UE capabilities forwarded from the destination gNB were received without integrity protection. As part of preparing for the handover, the source gNB sends a handover request to the destination gNB, which includes the UE capabilities along with an indication of whether the UE capabilities were originally received with protected integrity (Step 1). In this example, the UE capabilities were received without integrity protection. If the destination gNB accepts the handover, it responds with a handover request acknowledgment message that includes the handover command (i.e., the RRC reconfiguration message) to be sent to the UE (Step 2). The source gNB triggers the handover by sending the UE the handover command (i.e., the RRC reconfiguration message) received in the previous step. The UE performs a random access to the cell specified in the handover order (Step 4). The UE sends the handover complete message to the destination gNB (Step 5). Since the UE capabilities received from the source gNB were recovered without integrity protection, the destination gNB requests the UE capabilities again by sending a UE capability query message to the UE (Step 6). Note that AS security is activated at this point, as a handover can only be performed after AS security is activated. The UE sends its UE capabilities to the gNB in the UE capability information message (Step 7). The destination gNB loads the newly recovered UE capabilities into the AMF and indicates that the capabilities were recovered with integrity protection (Step 8). Note that the source access node could also extract UE capabilities from the UE after the AS security activation, since the source access node could track previously extracted UE capabilities that were not received with security protection. Note also that the core network node (i.e., AMF / MME), which stores the UE capabilities and an indication of whether they were recovered with integrity protection, would later provide both elements when UE capabilities are subsequently provided to the access node or another core network node. To trace the source of incorrectly allocated capabilities, an identifier of the node or cell that acquires and / or loads the UE capabilities can be attached to and / or stored with the UE capabilities on an access node(s) and / or core network node(s). When an inconsistency and / or error in forwarded / stored UE capabilities is suspected or detected, this node or cell identifier can be used to identify the origin of the capabilities and assist in first-cause analysis. To protect the node / cell ID and / or stored UE capabilities, the node / cell ID and / or UE capabilities may be signed (or have a cryptographic authentication code attached) by the UE, the access node, and / or the central network node. Some of the implementations in this document are applicable to protecting an RRC UECapabilityInformation message that indicates a UE's radio access capabilities. This message can be vulnerable to tampering over the air when sent before the AS security activation. For example, a rogue base station could act as a man-in-the-middle and intercept the RRC UECapabilityInformation message over the air. The rogue base station could then modify the message values to reduce the indicated capability level and forward it to the real base station, causing the UE to operate with only limited radio capabilities. This could adversely affect communication between the UE and the network. The effect is exacerbated if the tampered UE capabilities are stored in the network and used for an extended period.In some situations, it could be equivalent to a denial-of-service attack on the UE. Consequently, some implementations refrain from using an unprotected uplink RRC UECapabilityInformation message. That is, the RRC UECapabilityInformation message will not be sent unprotected after AS security is activated. This ensures that the RRC UECapabilityInformation message cannot be improperly manipulated after AS security is activated. More specifically, this means that the network should not send the RRC UECapabilityEnquir message to the UE before AS security has been activated. Alternatively, or additionally, when the UE receives an RRC UECapabilityEnquir message from a base station, the UE should first verify that AS security has been activated, i.e., that an RRC security mode command procedure has been successfully performed.If the above verification is successful, the UE will send a corresponding RRC UECapabilityInformation message to the base station as an encrypted and integrity-protected message. Otherwise, if the above verification fails—that is, if an RRC security mode command procedure was not performed or failed—the UE should not send an RRC UECapabilityInformation message to the base station. The UE can send the RRC UECapabilityInformation message to the base station later, after the AS security has been activated. However, if the uplink RRC UECapabilityInformation message is used unprotected, such as for early service / connectivity optimization, other implementations provide a contamination mechanism so that the system can recover from improper handling of an uplink RRC UECapabilityInformation message. This allows the system to support a recovery mechanism with respect to an improperly handled uplink RRC UECapabilityInformation message. More specifically, according to some implementations, the network will contaminate UE capabilities if they are received in an unprotected RRC UECapabilityInformation message before the AS security activation, so that the network (e.g., the same gNB / AMF or a different gNB / AMF during handovers) can determine whether those UE capabilities were received before or after the AS security activation.Once a successful security activation is performed, depending on the security policy, the network may re-query UE capabilities if they were previously received without security protection. To re-query UE capabilities, the network can send the UE a Boolean flag in the AS's SMCommand message, a hash of locally stored UE capabilities, or a new UECapabilityEnquire and RRC message. Therefore, some implementations provide a mechanism to protect an uplink RRC UECapabilitylnformation message in the first place and to recover, if necessary, from an improperly manipulated uplink RRC UECapabilitylnformation message. In some implementations, the network (the gNB, AMF, or any other network function) could send a signal to the UE indicating that the UE will not send an RRC UECapabilityInformation message before the AS security wake-up. This signal could be sent in an RRC message or a NAS message, protected by AS security and NAS security, respectively. Subsequently, when the UE receives an RRC UECapabilityEnquire message before the AS security wake-up, the UE will use this signal to determine whether or not to respond with an RRC UECapabilityInformation message before the AS security wake-up. Note that, in some implementations, the RAN activates AS security (both encryption and integrity protection) using the initial security activation procedure. The RRC messages used to activate security (command and successful response) are integrity-protected, while encryption is initiated only after the procedure is complete. That is, the response to the message used to activate security is not encrypted, while subsequent messages are both integrity-protected and encrypted. In one or more implementations, the AS applies four different security keys: one for RRC signaling integrity protection (KRRCint), one for RRC signaling encryption (KRRCenc), one for user data integrity protection (KUPint), and one for user data encryption (KUPenc). All four AS keys are created from the KgNB key. The KgNB is based on the KAMF key (as specified in TS 33.501), which is handled by higher layers. In some implementations, the network initiates the security mode command procedure toward a UE in RRC_CONNECTED. The UE will create the KgNB key, create the KRRCint key associated with the integrityProtAlgorithm specified in the SecurityModeCommand message, and request lower layers to verify the integrity protection of the SecurityModeCommand message, using the algorithm specified by the integrityProtAlgorithm as included in the SecurityModeCommand message and the KRRCint key.If the SecurityModeCommand message passes the integrity protection check, the UE will create the KRRCenc key and the KUPenc key associated with the cipheringAlgorithm indicated in the SecurityModeCommand message, create the KUPint key associated with the integrityProtAlgorithm indicated in the SecurityModeCommand message, configure lower layers to apply Signaling Radio Communications (SRB) Carrier Integrity Protection using the indicated algorithm and the KRRCint key immediately (i.e., integrity protection will be applied to all subsequent messages received and sent by the UE, including the SecurityModeComplete message), and configure lower layers to apply SRB encryption using the indicated algorithm and the KRRCenc key after completing the procedure (i.e., encryption will be applied to all subsequent messages received and sent by the UE, except for the SecurityModeComplete message, which is sent unencrypted).At this point, the UE will consider the AS security to be enabled and will present the SecurityModeComplete message to lower layers for transmission, after which the procedure ends. Otherwise, if the SecurityModeCommand message fails the integrity protection check, the UE will continue using the configuration used before receiving the SecurityModeCommand message (i.e., it will not apply integrity protection or encryption) and will present the SecurityModeFailure message to lower layers for transmission, after which the procedure ends. Although the subject matter described herein can be implemented in any appropriate type of system using any suitable components, the embodiments disclosed herein are described in relation to a wireless network, such as the example wireless network illustrated in Figure 25. For simplicity, the wireless network in Figure 25 represents only the 2506 network, the 2560 and 2560b network nodes, and the 2510, 2510b, and 2510c wireless devices. In practice, a wireless network may further include any additional elements suitable for supporting communication between wireless devices or between a wireless device and another communication device, such as a landline telephone, a service provider, or any other network node or end device. Of the components illustrated, the 2560 network node and the 2510 wireless device (VVD) are shown in greater detail.The wireless network can provide communication and other types of services to one or more wireless devices to facilitate access by wireless devices and / or the use of services provided by, or through, the wireless network. A wireless network can encompass and / or interact with any type of communication, telecommunications, data, cellular, and / or radio communications network, or other similar system. In some implementations, the wireless network may be configured to operate according to specific standards or other predefined rules or procedures. Thus, particular implementations of a wireless network may implement communication standards such as the Global System for Mobile Communications (GSM), the Universal System for Mobile Telecommunications (UMTS), Long Term Evolution (LTE), Narrowband Internet of Things (NB-IoT), and / or other suitable 2G, 3G, 4G, or 5G standards; or wireless local area network (WLAN) standards, such as the 802.IEEE 11; and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability Standards for Microwave Access (WiMax), Bluetooth, Z-Wave and / or ZigBee. The 2506 network may comprise one or more backhaul networks, core networks, IP networks, public switched telephone networks (PSTNs), packet data networks, optical networks, wide area networks (WANs), local area networks (LANs), wireless local area networks (WLANs), wired networks, wireless networks, metropolitan area networks, and other networks to enable communication between devices. The 2560 network node and the WD 2510 comprise several components that are described in more detail later. These components work together to provide network node and / or wireless device functionality, such as providing wireless connections in a wireless network. In different embodiments, the wireless network may comprise an indefinite number of wired or wireless networks, network nodes, base stations, controllers, wireless devices, repeater stations, and / or any other components or systems that can facilitate or participate in the communication of data and / or signals, whether by wired or wireless connections. As used herein, a network node refers to equipment capable of, configured, arranged, and / or operational to communicate directly or indirectly with a wireless device and / or other equipment or network nodes on the wireless network in order to enable and / or provide wireless access to the wireless device and / or to perform other functions (e.g., management) on the wireless network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points), base stations (BSs) (e.g., radio base stations, B-Nodes, evolved B-Nodes (eNBs), and NR B-Nodes (gNBs)).Base stations can be classified according to the extent of the coverage they provide (or, in other words, their transmission power level) and can then also be referred to as femto-base stations, pico-base stations, micro-base stations, or macro-base stations. A base station can be a relay node or a relay donor node that controls a relay. A network node can also include one or more (or all) parts of a distributed radio base station, such as centralized digital units and / or remote radio units (RRUs), sometimes referred to as Remote Radio Heads (RRHs). Such remote radio units may or may not have an integrated antenna in the form of a radio module with an integrated antenna.The components of a distributed radio communications base station can also be referred to as nodes in a distributed antenna system (DAS). Further examples of network nodes include multi-standard radio equipment (MSR) such as MSR base stations (BSs), network controllers such as radio network controllers (RNCs) or base station controllers (BSCs), base transceiver stations (BTSs), transmit points, transmit nodes, multicell / multicast coordination entities (MCEs), core network nodes (e.g., MSCs, MMEs), O&M nodes, OSS nodes, SON nodes, positioning nodes (e.g., E-SMLCs), and / or MDTs. As an additional example, a network node can be a virtual network node, as described in more detail later.However, more generally, network nodes can represent any suitable device (or group of devices) capable, configured, arranged and / or operational to enable and / or provide a wireless device with access to the wireless network or to provide some service to a wireless device that has accessed the wireless network. In Figure 25, the network node 2560 includes processing circuitry 2570, a device-readable medium 2580, an interface 2590, auxiliary equipment 2584, a power supply 2586, power circuitry 2587, and an antenna 2562. Although the network node 2560 illustrated in the wireless network example in Figure 25 may represent a device that includes the illustrated combination of hardware components, other embodiments may comprise network nodes with different combinations of components. It is to be understood that a network node comprises any suitable combination of hardware and / or software necessary to perform the tasks, features, functions, and methods disclosed herein.Furthermore, although the components of the 2560 network node are represented as individual boxes located within a larger box, or nested within multiple boxes, in practice, a network node may comprise multiple different physical components that constitute a single illustrated component (for example, the 2580 device-readable medium may comprise multiple independent hard disk drives, as well as multiple RAM modules). Similarly, the network node 2560 can be composed of multiple physically independent components (e.g., a NodeB component and an RNC component, or a BTS component and a BSC component, etc.), each of which may have its own respective components. In certain scenarios where the network node 2560 comprises multiple independent components (e.g., BTS and BSC components), one or more of the independent components may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each exclusive pair of NodeB and RNC may, in some cases, be considered a single independent network node. In some implementations, the network node 2560 may be configured to support multiple radio access technologies (RATs).In such embodiments, some components may be duplicated (for example, a separate device-readable 2580 medium for different RATs) and some components may be reused (for example, RATs may share the same 2562 antenna). The 2560 network node may also include multiple sets of the various illustrated components for different wireless technologies integrated into the 2560 network node, such as GSM, WCDMA, LTE, NR, Wi-Fi, or Bluetooth wireless technologies. These wireless technologies may be integrated into the same chip or chipset, or into different chips or chipsets, and into other components within the 2560 network node. The 2570 processing circuitry is configured to perform any determination, calculation, or similar operations (for example, certain obtaining operations) described herein as provided by a network node. These operations performed by the 2570 processing circuitry may include processing information obtained by the 2570 processing circuitry, for example, by converting the obtained information into other information, comparing the obtained or converted information with information stored on the network node, and / or performing one or more operations on the basis of the obtained or converted information, and, as a result of such processing, making a determination. The 2570 processing circuitry may comprise a combination of one or more microprocessors, controllers, microcontrollers, central processing units, digital signal processors, application-specific integrated circuits, arrays of programmable gates, or any other computing device, resource, or suitable combination of hardware, software, and / or coded logic, operational to provide, either individually or in conjunction with other components of the 2560 network node, such as the 2580 device-readable medium, the functionality of the 2560 network node. For example, the 2570 processing circuitry may execute instructions stored on the 2580 device-readable medium or in memory within the 2570 processing circuitry. Such functionality may include providing any of the various wireless benefits, functions, or features discussed herein.In some implementations, the 2570 processing circuitry may include a system-on-a-chip (SoC). In some embodiments, the 2570 processing circuitry may include one or more of the 2572 radio frequency (RF) transceiver circuitry and the 2574 baseband processing circuitry. In some embodiments, the 2572 radio frequency (RF) transceiver circuitry and the 2574 baseband processing circuitry may be on separate chips (or chipsets), boards, or units, such as radio communication units and digital units. In alternative embodiments, some or all of the 2572 RF transceiver circuitry and the 2574 baseband processing circuitry may be on the same chip or chipset, board, or unit. In certain embodiments, some or all of the functionality described herein as provided by a network node, base station, eNB, or other such network device may be performed by 2570 processing circuitry executing instructions stored on device-readable 2580 medium or in memory within the 2570 processing circuitry. In alternative embodiments, some or all of the functionality may be provided by 2570 processing circuitry without executing instructions stored on a separate or discrete device-readable medium, such as by means of a permanent connection. In either embodiment, whether or not instructions stored on device-readable storage medium are executed, the 2570 processing circuitry may be configured to perform the described functionality.The benefits provided by this functionality are not limited to the 2570 processing circuitry alone or other components of the 2560 network node, but are enjoyed by the 2560 network node as a whole and / or end users and the wireless network in general. Device-readable media 2580 may comprise any form of computer-readable volatile or non-volatile memory including, without limitation, persistent storage modules, solid-state memory, remotely mounted memory, magnetic media, optical media, random-access memory (RAM), read-only memory (ROM), mass storage media (e.g., a hard disk drive), removable storage media (e.g., a flash storage drive, a Compact Disc (CD), or a Digital Video Disc (DVD)), and / or any other non-transient, device-readable and / or computer-executable volatile or non-volatile memory devices that store information, data, and / or instructions that can be used by the processing circuitry 2570.The device-readable medium 2580 can store any suitable instructions, data, or information, including a computer program, software, or application comprising one or more logic, rules, code, tables, etc., and / or other instructions suitable for execution by the processing circuitry 2570 and use by the network node 2560. The device-readable medium 2580 can also be used to store any calculations performed by the processing circuitry 2570 and / or any data received through the interface 2590. In some embodiments, the processing circuitry 2570 and the device-readable medium 2580 can be considered integrated. Interface 2590 is used for wired or wireless signaling and / or data communication between network node 2560, network 2506, and / or WDs 2510. As illustrated, interface 2590 comprises port(s) / terminal(s) 2594 for sending and receiving data, for example, to and from network 2506 via a wired connection. Interface 2590 also includes radio front-end circuitry 2592, which can be coupled to, or in certain embodiments be part of, antenna 2562. The radio front-end circuitry 2592 comprises filters 2598 and amplifiers 2596. The radio front-end circuitry 2592 can be connected to antenna 2562 and processing circuitry 2570. The radio communications front stage circuitry can be configured to condition signals communicated between the antenna 2562 and the processing circuitry 2570.The radio front-end circuitry 2592 can receive digital data to be transmitted to other network nodes or WDs via a wireless connection. The radio front-end circuitry 2592 can convert the digital data into a radio signal with the appropriate channel and bandwidth parameters using a combination of filters 2598 and / or amplifiers 2596. The radio signal can then be transmitted via antenna 2562. Similarly, when receiving data, antenna 2562 can receive radio signals, which are then converted into digital data by the radio front-end circuitry 2592. The digital data can then be transferred to the processing circuitry 2570. In other embodiments, the interface may comprise different components and / or combinations of different components. In certain alternative embodiments, the 2560 network node may not include separate 2592 radio front-end circuitry; instead, the 2570 processing circuitry may comprise radio front-end circuitry and may connect to the 2562 antenna without separate 2592 radio front-end circuitry. Similarly, in some embodiments, all or part of the 2572 RF transceiver circuitry may be considered part of the 2590 interface. In still other embodiments, the 2590 interface may include one or more 2594 ports or terminals, 2592 radio front-end circuitry, and 2572 RF transceiver circuitry, as part of a radio unit (not shown), and the 2590 interface may communicate with the 2574 baseband processing circuitry, which is part of a digital unit (not shown). The 2562 antenna may include one or more antennas, or antenna arrays, configured to send and / or receive wireless signals. The 2562 antenna may be coupled to the 2590 radio front-end circuitry and may be any type of antenna capable of wirelessly transmitting and receiving data and / or signals. In some embodiments, the 2562 antenna may comprise one or more omnidirectional, sector, or panel antennas operative for transmitting / receiving radio signals between, for example, 2 GHz and 66 GHz. An omnidirectional antenna may be used to transmit / receive radio signals in any direction, a sector antenna may be used to transmit / receive radio signals from devices within a particular area, and a panel antenna may be a line-of-sight antenna used to transmit / receive radio signals in a relatively straight line.In some cases, the use of more than one antenna may be referred to as MIMO. In certain implementations, antenna 2562 may be independent of network node 2560 and may be connectable to network node 2560 via an interface or port. Antenna 2562, interface 2590, and / or processing circuitry 2570 may be configured to perform any receive operations and / or certain acquisition operations described herein as performed by a network node. Any information, data, and / or signals may be received from a wireless device, another network node, and / or any other network equipment. Similarly, antenna 2562, interface 2590, and / or processing circuitry 2570 may be configured to perform any transmit operations described herein as performed by a network node. Any information, data, and / or signals may be transmitted to a wireless device, another network node, and / or any other network equipment. The power circuitry 2587 may comprise, or be coupled to, power management circuitry and is configured to supply power to the network node 2560 components to perform the functionality described herein. The power circuitry 2587 may be powered from the power supply 2586. The power supply 2586 and / or the power circuitry 2587 may be configured to provide power to the various network node 2560 components in a format suitable for the respective components (e.g., with a voltage and current level required for each respective component). The power supply 2586 may be either included in, or external to, the power circuitry 2587 and / or the network node 2560.For example, the network node 2560 can be connected to an external power source (e.g., a power outlet) via an input interface or circuitry such as an electrical cable, through which the external power source supplies power to the power circuitry 2587. As a further example, the power source 2586 can comprise a power supply in the form of a battery or battery pack that is connected to, or integrated into, the power circuitry 2587. The battery can provide backup power in the event of a failure of the external power source. Other types of power sources, such as photovoltaic devices, can also be used. Alternative implementations of the 2560 network node may include additional components beyond those shown in Figure 25 that may be responsible for providing certain aspects of the network node's functionality, including any of the functionalities described herein and / or any functionality necessary to support the subject matter described herein. For example, the 2560 network node may include user interface equipment to allow information to be entered into the 2560 network node and to allow information to be output from the 2560 network node. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for the 2560 network node. As used herein, wireless device (WD) refers to a device capable, configured, arranged, and / or operational to communicate wirelessly with network nodes and / or other wireless devices. Unless otherwise specified, the term WD may be used interchangeably herein with user equipment (UE). Wireless communication may involve transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other signal types suitable for carrying information through the air. In some embodiments, a WD may be configured to transmit and / or receive information without direct human interaction. For example, a WD may be designed to transmit information to a network on a predetermined schedule, when triggered by an internal or external event, or in response to network requests.Examples of a WD include, but are not limited to, a smartphone, mobile phone, cell phone, Voice over IP (VoP) phone, wireless local loop phone, desktop computer, personal digital assistant (PDA), wireless cameras, gaming console or device, music storage device, playback device, wearable terminal device, wireless endpoint, mobile station, tablet, laptop computer, laptop embedded equipment (LEE), laptop mounted equipment (LME), smart device, customer premises equipment (CPE), wireless, vehicle mounted wireless terminal device, etc.A Device Warehouse (WD) can support device-to-device (D2D) communication, for example, by implementing a 3GPP standard for sidelink communication, vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle-to-everything (V2X), and in this case, it can be referred to as a D2D communication device. As another specific example, in an Internet of Things (IoT) scenario, a WD can represent a machine or other device that performs monitoring and / or measurements and transmits the results of those monitoring and / or measurements to another WD and / or a network node. In this case, the WD can be a machine-to-machine (M2M) device, which, in a 3GPP context, can be referred to as an MTC device. As a particular example, the WD can be a Unit Enablement (UE) implementing the 3GPP Narrowband IoT (NB-IoT) standard.Specific examples of such machines or devices include sensors, measuring devices such as electric meters, industrial machinery, or household or personal appliances (e.g., refrigerators, televisions, etc.) and wearable personal devices (e.g., watches, fitness trackers, etc.). In other scenarios, a WD may represent a vehicle or other equipment capable of monitoring and / or reporting its operational status or other functions associated with its operation. A WD as described above may represent the endpoint of a wireless connection, in which case the device may be referred to as a wireless terminal. Furthermore, a WD as described above may be mobile, in which case it may also be referred to as a mobile device or mobile terminal. As illustrated, the WD 2510 wireless device includes an antenna 2511, an interface 2514, processing circuitry 2520, a device-readable medium 2530, user interface equipment 2532, auxiliary equipment 2534, a power supply 2536, and power circuitry 2537. The WD 2510 may include multiple sets of one or more of the illustrated components for different wireless technologies supported by the WD 2510, such as GSM, WCDMA, LTE, NR, WiFi, WiMAX, NB-IoT, or Bluetooth wireless technologies, to name a few. These wireless technologies may be integrated on the same chips or chipsets as other components within the WD 2510 or on different chips or chipsets. Antenna 2511 may include one or more antennas or antenna arrays configured to send and / or receive wireless signals and is connected to interface 2514. In certain alternative embodiments, antenna 2511 may be independent of WD 2510 and may be connectable to WD 2510 via an interface or port. Antenna 2511, interface 2514, and / or processing circuitry 2520 may be configured to perform any of the receive or transmit operations described herein as being performed by a WD. Any information, data, and / or signals may be received from a network node and / or another WD. In some embodiments, the radio front-end circuitry and / or antenna 2511 may be considered an interface. As illustrated, interface 2514 comprises radio front-end circuitry 2512 and an antenna 2511. The radio front-end circuitry 2512 comprises one or more filters 2518 and amplifiers 2516. The radio front-end circuitry 2514 is connected to the antenna 2511 and the processing circuitry 2520 and is configured to condition signals communicated between the antenna 2511 and the processing circuitry 2520. The radio front-end circuitry 2512 may be coupled to or form part of the antenna 2511. In some embodiments, WD 2510 may not include separate radio front-end circuitry 2512; instead, the processing circuitry 2520 may comprise radio front-end circuitry and may be connected to the antenna 2511.Similarly, in some embodiments, part or all of the RF transceiver circuitry 2522 may be considered part of the interface 2514. The radio front-end circuitry 2512 may receive digital data to be transmitted to other network nodes or WDs via a wireless connection. The radio front-end circuitry 2512 may convert the digital data into a radio signal having the appropriate channel and bandwidth parameters using a combination of filters 2518 and / or amplifiers 2516. The radio signal may then be transmitted by the antenna 2511. Likewise, when receiving data, the antenna 2511 may receive radio signals, which are then converted into digital data by the radio front-end circuitry 2512. The digital data may then be transferred to the processing circuitry 2520.In other embodiments, the interface may comprise different components and / or combinations of different components. The 2520 processing circuitry may comprise a combination of one or more microprocessors, controllers, microcontrollers, central processing units, digital signal processors, application-specific integrated circuits, arrays of programmable gates, or any other computing device, resource, or suitable combination of hardware, software, and / or coded logic, operational to provide, either individually or in conjunction with other WD 2510 components, such as the 2530 device-readable media, the functionality of the WD 2510. Such functionality may include providing any of the various wireless features or benefits discussed herein. For example, the 2520 processing circuitry may execute instructions stored on the 2530 device-readable media or in memory within the 2520 processing circuitry to provide the functionality disclosed herein. As illustrated, the 2520 processing circuitry includes one or more of the 2522 RF transceiver circuitry, the 2524 baseband processing circuitry, and the 2526 application processing circuitry. In other embodiments, the processing circuitry may comprise different components and / or combinations of different components. In certain embodiments, the 2520 processing circuitry of the WD 2510 may comprise a System-on-a-Chip (SOC). In some embodiments, the 2522 RF transceiver circuitry, the 2524 baseband processing circuitry, and the 2526 application processing circuitry may be on separate chips or chipsets. In alternative embodiments, some or all of the 2524 baseband processing circuitry and the 2526 application processing circuitry may be combined on one chip or chipset, and the 2522 RF transceiver circuitry may be on a separate chip or chipset.In other alternative embodiments, some or all of the RF transceiver circuitry 2522 and the baseband processing circuitry 2524 may be on the same chip or chipset, and the application processing circuitry 2526 may be on a separate chip or chipset. In still other alternative embodiments, some or all of the RF transceiver circuitry 2522, the baseband processing circuitry 2524, and the application processing circuitry 2526 may be combined on the same chip or chipset. In some embodiments, the RF transceiver circuitry 2522 may be part of the interface 2514. The RF transceiver circuitry 2522 may condition RF signals for the processing circuitry 2520. In certain embodiments, some or all of the functionality described herein as being performed by a WD may be provided by processing circuitry 2520 that executes instructions stored on a device-readable medium 2530, which in certain embodiments may be a computer-readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry 2520 without executing instructions stored on a separate or discrete device-readable storage medium, such as by permanent wiring. In either of these particular embodiments, whether or not instructions stored on a device-readable storage medium are executed, the processing circuitry 2520 may be configured to perform the described functionality.The benefits provided by this functionality are not limited to the 2520 processing circuitry alone or other components of the WD 2510, but are enjoyed by the WD 2510 as a whole and / or end users and the wireless network in general. The 2520 processing circuitry may be configured to perform any determination, calculation, or similar operations (for example, certain obtaining operations) described herein as being performed by a WD. These operations, performed by the 2520 processing circuitry, may include processing information obtained by the 2520 processing circuitry, for example, by converting the obtained information into other information, comparing the obtained or converted information with information stored by the WD 2510, and / or performing one or more operations on the basis of the obtained or converted information, and, as a result of such processing, making a determination. Device-readable media (2530) may be operational for storing a computer program, software, or application that includes one or more logic, rules, code, tables, etc., and / or other instructions suitable for execution by processing circuitry (2520). Device-readable media (2530) may include computer memory (e.g., Random Access Memory (RAM) or Read-Only Memory (ROM)), mass storage media (e.g., a hard disk), removable storage media (e.g., a Compact Disc (CD) or a Digital Video Disc (DVD)), and / or any other volatile or non-volatile, non-transient, device-readable and / or computer-executable memory devices that store information, data, and / or instructions that can be used by processing circuitry (2520).In some embodiments, the processing circuitry 2520 and the device-readable medium 2530 can be considered to be integrated. The 2532 user interface equipment can provide components that allow a human user to interact with the WD 2510. This interaction can take many forms, such as visual, auditory, tactile, etc. The 2532 user interface equipment can be operational to produce output for the user and to allow the user to provide input to the WD 2510. The type of interaction can vary depending on the type of 2532 user interface equipment installed on the WD 2510. For example, if the WD 2510 is a smartphone, the interaction might be via a touchscreen; if the WD 2510 is a smart meter, the interaction might be through a display that provides consumption (for example, the number of gallons consumed) or a speaker that provides an audible alert (for example, if smoke is detected).The 2532 user interface equipment may include input interfaces, devices, and circuitry, and output interfaces, devices, and circuitry. The 2532 user interface equipment is configured to allow input of information into the WD 2510 and is connected to the 2520 processing circuitry to allow the 2520 processing circuitry to process the input information. The 2532 user interface equipment may include, for example, a microphone, a proximity or other sensor, keys / buttons, a touch display module, one or more cameras, a USB port, or other input circuitry. The 2532 user interface equipment is also configured to allow output of information from the WD 2510 and to allow the 2520 processing circuitry to output information from the WD 2510.The 2532 user interface equipment may include, for example, a speaker, a display module, vibration circuitry, a USB port, a headphone interface, or other output circuitry. By using one or more of the 2532 user interface equipment's interfaces, devices, and input / output circuitry, the WD 2510 can communicate with end users and / or the wireless network and enable them to benefit from the functionality described herein. The 2534 auxiliary equipment is operational to provide more specific functionality that cannot generally be performed by WDs. This may include specialized sensors for taking measurements for various purposes, interfaces for additional types of communication, such as wired communications, etc. The inclusion and type of components in the 2534 auxiliary equipment may vary depending on the implementation and / or scenario. In some embodiments, the power source 2536 may take the form of a battery or battery pack. Other types of power sources, such as an external power supply (e.g., a wall outlet), photovoltaic devices, or power cells, may also be used. The WD 2510 may further comprise power circuitry 2537 to deliver power from the power source 2536 to the various parts of the WD 2510 that require power from the power source 2536 to perform any functionality described or indicated herein. The power circuitry 2537, in certain embodiments, may comprise power management circuitry.The power circuitry 2537 may be operative in an additional or alternative manner to receive power from an external power source; in such a case, the WD 2510 may be connected to the external power source (such as a wall outlet) by means of input circuitry or an interface such as a power cord. The power circuitry 2537 may also be operative in certain embodiments to deliver power from an external power source to the power supply 2536. This may be, for example, for charging the power supply 2536. The power circuitry 2537 may perform any formatting, conversion, or other modification of the power from the power supply 2536 to make the power suitable for the respective components of the WD 2510 to which it is supplied. Figure 26 illustrates one embodiment of a user equipment (UE) according to various aspects described herein. As used herein, a user equipment (UE) may not necessarily have a user in the sense of a human user who owns and / or operates the device. Instead, a UE may represent a device that is intended for sale to, or operation by, a human being, but which may not be, or may not initially be, associated with a specific human user (e.g., a smart sprinkler controller). Alternatively, a UE may represent a device that is not intended for sale to, or operation by, an end user, but which may be associated with or operated by a user (e.g., a smart electricity meter).The UE 26200 can be any UE identified by the 3rd Generation Partnership Project (3GPP), including an NB-IoT UE, a Machine-Type Communication (MTC) UE, and / or an Enhanced MTC (eMTC) UE. The UE 2600, as illustrated in Figure 26, is an example of a WD configured for communication according to one or more communication standards promulgated by the 3rd Generation Partnership Project (3GPP), such as the 3GPP GSM, UMTS, LTE, and / or 5G standards. As mentioned earlier, the terms WD and UE can be used interchangeably. Therefore, although Figure 26 is a UE, the components discussed herein are equally applicable to a WD, and vice versa. In Figure 26, the UE 2600 includes processing circuitry 2601 that is operatively coupled to the input / output interface 2605, the radio frequency (RF) interface 2609, the network connection interface 2611, memory 2615 including random access memory (RAM) 2617, read-only memory (ROM) 2619, and the storage medium 2621 or similar, the communication subsystem 2631, the power supply 2633, and / or any other component, or any combination thereof. The storage medium 2621 includes the operating system 2623, the application program 2625, and data 2627. In other embodiments, the storage medium 2621 may include other similar types of information. Certain UEs may use all of the components shown in Figure 26, or only a subset of the components. The level of integration between components may vary from one UE to another.In addition, certain UEs may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc. In Figure 26, the 2601 processing circuitry can be configured to process computer instructions and data. The 2601 processing circuitry can be configured to implement any operational sequential state machine to execute machine instructions stored as machine-readable computer programs in memory, such as one or more hardware-implemented state machines (e.g., in discrete logic, FPGA, ASIC, etc.); programmable logic together with appropriate firmware; one or more stored programs, general-purpose processors such as a microprocessor or a Digital Signal Processor (DSP), together with appropriate software; or any combination thereof. For example, the 2601 processing circuitry could include two central processing units (CPUs). The data could be information in a format suitable for use by a computer. In the depicted embodiment, the 2605 input / output interface can be configured to provide a communication interface to an input device, an output device, or an input / output device. The UE 2600 can be configured to use an output device via the 2605 input / output interface. An output device can use the same type of interface port as an input device. For example, a USB port can be used to provide input to and output from the UE 2600. The output device can be a speaker, sound card, video card, display module, monitor, printer, actuator, transmitter, smart card, another output device, or any combination thereof. The UE 2600 can be configured to use an input device via the 2605 input / output interface to allow a user to capture information on the UE 2600.The input device may include a touch-sensitive or presence-sensitive display module, a camera (e.g., a digital camera, digital video camera, webcam, etc.), a microphone, a sensor, a mouse, a trackball mouse, a directional pad, a touchpad, a scroll wheel, a smart card, and similar devices. The presence-sensitive display module may include a capacitive or resistive touch sensor to capture user input. A sensor may be, for example, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, another similar sensor, or any combination thereof. For example, the input device may consist of an accelerometer, a magnetometer, a digital camera, a microphone, and an optical sensor. In Figure 26, the RF interface 2609 can be configured to provide a communication interface to RF components such as a transmitter, receiver, and antenna. The network connection interface 2611 can be configured to provide a communication interface to network 2643a. Network 2643a can encompass wired and / or wireless networks such as a local area network (LAN), a wide area network (WAN), a computer network, a wireless network, a telecommunications network, another similar network, or any combination thereof. For example, network 2643a could comprise a Wi-Fi network. The network connection interface 2611 can be configured to include a receiver / transmitter interface used to communicate with one or more other devices over a communication network using one or more communication protocols, such as Ethernet, TCP / IP, SONET, ATM, or similar protocols.The 2611 network connection interface can implement receiver and transmitter functionality appropriate for communication network links (e.g., optical, electrical, and similar). The transmitter and receiver functions can share circuit components, software, or firmware, or alternatively, they can be implemented separately. The 2617 RAM can be configured to interface via the 2602 bus with the 2601 processing circuitry to provide storage or caching of data or computer instructions during the execution of software programs such as the operating system, application programs, and device drivers. The 2619 ROM can be configured to provide computer instructions or data to the 2601 processing circuitry. For example, the 2619 ROM can be configured to store low-level, invariant system code or data for basic system functions such as basic input / output (I / O), booting, or receiving keystrokes from a keyboard that are stored in non-volatile memory.The storage medium 2621 can be configured to include memory such as RAM, ROM, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, floppy disks, hard disks, removable cartridges, or flash storage units. For example, the storage medium 2621 can be configured to include the operating system 2623, the application program 2625 such as a web browser application, a widget or gadget engine, or another application, and a data file 2627. The storage medium 2621 can store, for use by the UE 2600, any of a variety of different operating systems or combinations of operating systems. The 2621 storage medium can be configured to include a variety of physical disk drives, such as a redundant array of independent disks (RAID), a floppy disk drive, a flash memory drive, a USB flash storage drive, an external hard disk drive, a miniature memory drive, a USB pen drive, a USB key drive, a high-density digital versatile disc (HD-DVD) optical disc drive, an internal hard disk drive, a Blu-ray optical disc drive, a holographic digital data storage (HDDS) optical disc drive, an external dual in-line mini memory module (DIMM), a synchronous dynamic random-access memory (SDRAM), an external micro-DIMM SDRAM, a smart card memory such as a subscriber identity module or a removable user identity module (SIM / RUIM), other memory, or any combination thereof.The 2621 storage medium may allow the UE 2600 to access computer-executable instructions, application programs, or similar data stored on transient or non-transient memory media, to download or load data. A manufactured item, such as one that utilizes a communication system, may be tangibly embodied in the 2621 storage medium, which may comprise a device-readable medium. In Figure 26, the processing circuitry 2601 can be configured to communicate with network 2643b using the communication subsystem 2631. Network 2643a and network 2643b can be the same network or networks, or different networks. The communication subsystem 2631 can be configured to include one or more transceivers used to communicate with network 2643b. For example, the communication subsystem 2631 can be configured to include one or more transceivers used to communicate with one or more remote transceivers of another wirelessly communicative device, such as another WD, UE, or base station in a radio access network (RAN) using one or more communication protocols, such as IEEE 802.26, CDMA, WCDMA, GSM, LTE, UTRAN, WiMAX, or similar protocols.Each transceiver may include a 2633 transmitter and / or a 2635 receiver to implement the appropriate transmitter or receiver functionality for the RAN links (e.g., frequency allocations and the like). Furthermore, the 2633 transmitter and 2635 receiver of each transceiver may share circuit components, software, or firmware, or alternatively, they may be implemented separately. In the illustrated embodiment, the communication functions of the 2631 communication subsystem may include data communication, voice communication, multimedia communication, short-range communication such as Bluetooth, near-field communication, location-based communication such as the use of the Global Positioning System (GPS) to determine a location, other similar communication functions, or any combination thereof. For example, the 2631 communication subsystem may include cellular communication, Wi-Fi communication, Bluetooth communication, and GPS communication. The 2643b network may encompass wired and / or wireless networks such as a local area network (LAN), a wide area network (WAN), a computer network, a wireless network, a telecommunications network, other similar networks, or any combination thereof. For example, the 2643b network may be a cellular network, a Wi-Fi network, and / or a near-field network.The 2613 power supply can be configured to provide alternating current (AC) or direct current (DC) power to UE 2600 components. The features, benefits, and / or functions described herein can be implemented in one of the UE 2600 components or distributed among multiple UE 2600 components. Furthermore, the features, benefits, and / or functions described herein can be implemented in any combination of hardware, software, or firmware. For example, the 2631 communication subsystem can be configured to include any of the components described herein. Additionally, the 2601 processing circuitry can be configured to communicate with any of these components via the 2602 bus. In another example, any of these components can be represented by program instructions stored in memory that, when executed by the 2601 processing circuitry, perform the corresponding functions described herein.In another example, the functionality of any of these components can be distributed between the processing circuitry 2601 and the communication subsystem 2631. In yet another example, the computationally undemanding functions of any of these components can be implemented in software or firmware, and the computationally demanding functions can be implemented in hardware. Figure 27 is a schematic block diagram illustrating a 2700 virtualization environment in which functions implemented by certain implementations can be virtualized. In this context, virtualization means creating virtual versions of appliances or devices, which may include the virtualization of hardware platforms, storage devices, and networking resources.As used herein, virtualization can be applied to a node (for example, a virtualized base station or a virtualized radio access node) or a device (for example, a UE, a wireless device, or any other type of communication device) or components thereof, and refers to an implementation in which at least some of the functionality is implemented in the form of one or more virtual components (for example, by means of one or more applications, components, functions, virtual machines, or containers running on one or more physical processing nodes in one or more networks). In some embodiments, some or all of the functions described herein may be implemented in the form of virtual components running on one or more virtual machines deployed in one or more virtual environments hosted by one or more hardware nodes.Furthermore, in implementations where the virtual node is not a radio access node or does not require radio connectivity (e.g., a core network node), then the network node can be fully virtualized. The functions may be implemented by means of one or more 2720 applications (which may alternatively be called software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) operational to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein. The 2720 applications run in a 2700 virtualization environment provided by 2730 hardware comprising 2760 processing circuitry and 2790 memory. The 2790 memory contains 2795 instructions executable by the 2760 processing circuitry, whereby the 2720 application is operational to provide one or more of the features, benefits, and / or functions disclosed herein. The 2700 virtualization environment comprises 2730 general-purpose or special-purpose network hardware devices comprising one or more 2760 processors or processing circuitry, which may be off-the-shelf (COTS) processors, dedicated Application-Specific Integrated Circuits (ASICs), or any other type of processing circuitry, including digital or analog hardware components or special-purpose processors. Each hardware device may comprise 2790-1 memory, which may be non-persistent memory for temporarily storing 2795 instructions or software executed by the 2760 processing circuitry. Each hardware device may comprise one or more 2770 network interface controllers (NICs), also known as network interface cards, which include a 2780 physical network interface.Each hardware device may also include non-transient, persistent, machine-readable storage media 2790-2 that have, stored therein, software 2795 and / or instructions executable by the processing circuitry 2760. The software 2795 may include any type of software, including software for creating instances of one or more virtualization layers 2750 (also referred to as hypervisors), software for running virtual machines 2740, as well as software that enables you to execute functions, features, and / or benefits described in connection with certain embodiments described herein. Virtual machines 2740 comprise virtual processing, virtual memory, virtual networking or interface, and virtual storage, and can be run using a corresponding 2750 virtualization layer or hypervisor. Different implementations of the 2720 virtual appliance instance can be deployed on one or more of the 2740 virtual machines, and these implementations can be carried out in various ways. During operation, the 2760 processing circuitry runs 2795 software to create an instance of the hypervisor or 2750 virtualization layer, sometimes referred to as the virtual machine monitor (VMM). The 2750 virtualization layer can present a virtual operating platform that is seen as networking hardware by the 2740 virtual machine. As shown in Figure 27, the 2730 hardware can be a standalone network node with generic or specific components. The 2730 hardware can include the 27225 antenna and can implement some functions through virtualization. Alternatively, the 2730 hardware can be part of a larger hardware group (for example, such as in a data center or customer premises equipment (CPE)) where many hardware nodes work together and are managed by the 27100 Management and Orchestration (MANO), which, among other things, oversees the lifecycle management of the 2720 applications. Hardware virtualization is sometimes referred to as network functions virtualization (NFV). NFV can be used to consolidate many types of network equipment into industry-standardized, high-volume physical storage, physical switches, and server hardware, which may be located in data centers and on-premises at the customer's site. In the context of NFV, a 2740 virtual machine can be a software implementation of a physical machine that runs programs as if they were running on a non-virtualized physical machine. Each 2740 virtual machine, and that portion of the 2730 hardware that runs that virtual machine—whether dedicated hardware and / or hardware shared with other 2740 virtual machines—forms a separate virtual network element (VNE). Even within the context of NFV, the Virtual Network Function (VNF) is responsible for handling specific network functions that run on one or more virtual machines 2740 on top of the hardware networking infrastructure 2730 and corresponds to application 2720 in Figure 27. In some embodiments, one or more 27200 radiocommunication units, each including one or more 27220 transmitters and one or more 27210 receivers, may be coupled to one or more 27225 antennas. The 27200 radiocommunication units may communicate directly with 2730 hardware nodes by means of one or more appropriate network interfaces and may be used in combination with the virtual components to provide a virtual node with radiocommunication capabilities, such as a radiocommunication access node or a base station. In some embodiments, some signaling can be carried out using the 27230 control system, which can alternatively be used for communication between the 2730 hardware nodes and the 27200 radio communication units. Figure 28 illustrates a telecommunications network connected via an intermediate network to a host computer according to some embodiments. In particular, with reference to Figure 28, according to one embodiment, a communication system includes a telecommunications network 2810, such as a 3GPP-type cellular network, comprising an access network 2811, such as a radio access network, and a core network 2814. The access network 2811 comprises a plurality of base stations 2812a, 2812b, 2812c, such as NBs, eNBs, gNBs, or other types of wireless access points, each defining a corresponding coverage area 2813a, 2813b, 2813c. Each base station 2812a, 2812b, 2812c is connectable to the core network 2814 via a wired or wireless connection 2815. A first UE 2891 located in the coverage area 2813c is configured to wirelessly connect to, or be sought by, the corresponding base station 2812c.A second UE 2892 in the 2813a coverage area is wirelessly connectable to the corresponding 2812a base station. Although this example illustrates a plurality of 2891, 2892 UEs, the disclosed embodiments are equally applicable to a situation where a single UE is in the coverage area or where a single UE is connecting to the corresponding 2812 base station. The telecommunications network 2810 is in turn connected to a host computer 2830, which may be embodied in the hardware and / or software of a standalone server, a cloud-deployed server, a distributed server, or as processing resources in a server farm. The host computer 2830 may be owned or controlled by a service provider, or may be operated by or on behalf of the service provider. The connections 2821 and 2822 between the telecommunications network 2810 and the host computer 2830 may extend directly from the core network 2814 to the host computer 2830 or may pass through an optional intermediate network 2820. The intermediate network 2820 may be one of, or a combination of more than one of, a public, private, or hosted network; the intermediate network 2820, if any, may be a backbone or the Internet. In particular, the intermediate network 2820 may comprise two or more subnets (not shown). The communication system in Figure 28, as a whole, enables connectivity between the connected UEs 2891 and 2892 and the host computer 2830. This connectivity can be described as an over-the-top (OTT) connection 2850. The host computer 2830 and the connected UEs 2891 and 2892 are configured to communicate data and / or signaling via the OTT connection 2850, using the access network 2811, the core network 2814, any intermediate networks 2820, and any additional infrastructure (not shown) as intermediaries. The OTT connection 2850 can be transparent in that the participating communication devices through which the OTT connection 2850 passes are unaware of the uplink and downlink communication routing.For example, base station 2812 may not be informed, or does not need to be informed, about the past routing of an incoming downlink communication with data originating from host computer 2830 to be forwarded (i.e., delivered) to a connected UE 2891. Similarly, base station 2812 does not need to be aware of the future routing of an outgoing uplink communication originating from UE 2891 to host computer 2830. Example implementations of the UE, base station, and host computer discussed in the preceding paragraphs will be described below with reference to Figure 29. Figure 29 illustrates a host computer communicating with a user computer via a base station through a partially wireless connection, according to some embodiments. In the communication system 2900, the host computer 2910 comprises hardware 2915, including a communication interface 2916 configured to establish and maintain a wired or wireless connection with a communication device interface other than the communication system 2900. The host computer 2910 further comprises processing circuitry 2918, which may have storage and / or processing capabilities.In particular, the 2918 processing circuitry may comprise one or more programmable processors, application-specific integrated circuits, arrays of programmable gates, or combinations thereof (not shown) adapted to execute instructions. The 2910 host computer further comprises 2911 software, which is stored on or accessible from the 2910 host computer and is executable by the 2918 processing circuitry. The 2911 software includes a 2912 host application. The host application 2912 can be operational to provide a service to a remote user, such as the UE 2930, by connecting via the OTT connection 2950 that terminates at the UE 2930 and the host computer 2910. In providing the service to the remote user, the host application 2912 can provide user data that is transmitted using the OTT connection 2950. The communication system 2900 further includes a base station 2920 provided in a telecommunications system and comprising hardware 2925 that enables it to communicate with the host computer 2910 and the UE 2930. The hardware 2925 may include a communication interface 2926 for establishing and maintaining a wired or wireless connection with an interface of a communication device other than the communication system 2900, as well as a radio communication interface 2927 for establishing and maintaining at least one wireless connection 2970 with the UE 2930 located within a coverage area (not shown in Figure 29) served by the base station 2920. The communication interface 2926 may be configured to facilitate a connection 2960 to the host computer 2910.The connection 2960 can be direct or can pass through a core network (not shown in Figure 29) of the telecommunications system and / or through one or more intermediate networks outside the telecommunications system. In the embodiment shown, the hardware 2925 of the base station 2920 further includes processing circuitry 2928, which may comprise one or more programmable processors, application-specific integrated circuits, arrays of programmable gates, or combinations thereof (not shown) adapted to execute instructions. The base station 2920 further has software 2921 stored internally or accessible via an external connection. The 2900 communication system also includes the UE 2930, which has already been referenced. Its hardware 2935 may include a radio communication interface 2937 configured to establish and maintain a wireless connection 2970 with a base station serving a coverage area in which the UE 2930 is currently located. The UE 2930 hardware 2935 also includes processing circuitry 2938, which may comprise one or more programmable processors, application-specific integrated circuits, arrays of programmable gates, or combinations thereof (not shown) adapted to execute instructions. The UE 2930 further comprises software 2931, which is stored on or accessible by the UE 2930 and is executable by the processing circuitry 2938. The software 2931 includes a client application 2932.The client application 2932 can be used to provide a service to a human or non-human user via the UE 2930, with support from the host computer 2910. On the host computer 2910, a running host application 2912 can communicate with the running client application 2932 via an OTT connection 2950 that terminates at the UE 2930 and the host computer 2910. In providing the service to the user, the client application 2932 can receive request data from the host application 2912 and provide user data in response to that request data. The OTT connection 2950 can transfer both the request data and the user data. The client application 2932 can interact with the user to generate the user data it provides. It should be noted that the host computer 2910, base station 2920, and UE 2930 illustrated in Figure 29 may be similar or identical to the host computer 2830, one of the base stations 2812a, 2812b, or 2812c, and one of the UEs 2891 or 2892 in Figure 28, respectively. That is, the internal operation of these entities may be as shown in Figure 29, and regardless, the topology of the surrounding network may be that of Figure 28. In Figure 29, the OTT connection 2950 is drawn abstractly to illustrate communication between the host computer 2910 and the UE 2930 via the base station 2920, without explicit reference to any intermediary devices or the precise routing of messages through these devices. The network infrastructure can determine the routing, which can be configured to be hidden from the UE 2930, the service provider operating the host computer 2910, or both. While the OTT connection 2950 is active, the network infrastructure can also make decisions that dynamically change the routing (for example, based on load balancing or network reconfiguration). The 2970 wireless connection between the UE 2930 and the 2920 base station is consistent with the lessons learned from the implementations described throughout this disclosure. One or more of the various implementations enhance the performance of OTT services provided to the UE 2930 using the 2950 OTT connection, in which the 2970 wireless connection forms the final segment. More specifically, the lessons learned from these implementations help prevent an attacker from manipulating the over-the-air UE capabilities and thereby causing damage to the network or the UE, such as service degradation. The implementations also provide the advantage of mitigating privacy risks. This provides benefits such as enhanced security and privacy for users, as well as improved network and UE performance. A measurement procedure can be provided to monitor data rate, latency, and other factors where the implementation(s) offer improvements. An optional network function can also be provided to reconfigure the OTT 2950 connection between the host computer 2910 and the UE 2930 in response to variations in measurement results. The measurement procedure and / or the network function for reconfiguring the OTT 2950 connection can be implemented in the host computer 2910's software 2911 and hardware 2915, or in the UE 2930's software 2931 and hardware 2935, or both.In embodiments, sensors (not shown) can be deployed on or associated with communication devices through which the OTT connection 2950 passes. The sensors can participate in the measurement procedure by supplying values of the monitored quantities exemplified above, or by supplying values of other physical quantities from which the software 2911, 2931 can calculate or estimate the monitored quantities. Reconfiguration of the OTT connection 2950 can include message format, relay settings, preferred routing, etc. The reconfiguration need not affect the base station 2920 and may be unknown or imperceptible to the base station 2920. Such procedures and functionalities may be known and may have been implemented in the art.In certain implementations, the measurements may involve proprietary UE signaling that facilitates measurements of flow rate, propagation times, latency, and the like from the 2910 host computer. The measurements may be implemented so that the 2911 and 2931 software causes messages, in particular empty or "dummy" messages, to be transmitted using the 2950 OTT connection while monitoring propagation times, errors, etc. Figure 30 is a flowchart illustrating a method implemented in a communication system, according to one embodiment. The communication system includes a host computer, a base station, and a UE, which may be those described with reference to Figures 28 and 29. For the sake of simplicity in this disclosure, only references to the drawings in Figure 30 will be included in this section. In step 3010, the host computer provides user data. In substep 3011 (which may be optional) of step 3010, the host computer provides the user data by running a host application. In step 3020, the host computer initiates a transmission that carries the user data to the UE. In step 3030 (which may be optional), the base station transmits to the UE the user data that was carried in the transmission initiated by the host computer, according to the embodiments described throughout this disclosure.In step 3040 (which can also be optional), the UE runs a client application associated with the host application run by the host computer. Figure 31 is a flowchart illustrating a method implemented in a communication system, according to one embodiment. The communication system includes a host computer, a base station, and a UE, which may be those described with reference to Figures 28 and 29. For the sake of simplicity in this disclosure, only references to the drawings in Figure 31 will be included in this section. In step 3110 of the method, the host computer provides user data. In an optional substep (not shown), the host computer provides the user data by running a host application. In step 3120, the host computer initiates a transmission that carries the user data to the UE. The transmission may pass through the base station, as taught in the embodiments described throughout this disclosure. In step 3130 (which may be optional), the UE receives the user data carried in the transmission. Figure 32 is a flowchart illustrating a method implemented in a communication system, according to one embodiment. The communication system includes a host computer, a base station, and a UE, which may be those described with reference to Figures 28 and 29. For the sake of simplicity, this section will only include references to the drawings in Figure 32. In step 3210 (which may be optional), the UE receives input data provided by the host computer. Alternatively, in step 3220, the UE provides user data. In substep 3221 (which may be optional) of step 3220, the UE provides the user data by running a client application. In substep 3211 (which may be optional) of step 3210, the UE runs a client application that provides the user data in response to the input data received from the host computer.In providing user data, the running client application may also consider user input received from the user. Regardless of the specific method used to provide the user data, the UE initiates, in substep 3230 (which may be optional), the transmission of the user data to the host computer. In step 3240 of the method, the host computer receives the user data transmitted from the UE, according to the principles of the implementations described throughout this disclosure. Figure 33 is a flowchart illustrating a method implemented in a communication system, according to one embodiment. The communication system includes a host computer, a base station, and a UE, which may be those described with reference to Figures 28 and 29. For the sake of simplicity in this disclosure, this section will only include references to the drawings in Figure 33. In step 3310 (which may be optional), based on the embodiments described throughout this disclosure, the base station receives user data from the UE. In step 3320 (which may be optional), the base station initiates the transmission of the received user data to the host computer. In step 3330 (which may be optional), the host computer receives the user data carried in the transmission initiated by the base station. Any appropriate steps, methods, features, functions, or benefits disclosed herein may be carried out through one or more functional units or modules of one or more virtual appliances. Each virtual appliance may comprise several of these functional units. These functional units may be implemented by processing circuitry, which may include one or more microprocessors or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or more types of memory such as read-only memory (ROM), random-access memory (RAM), cache memory, flash memory devices, optical storage devices, and so forth.The program code stored in memory includes program instructions for executing one or more telecommunications and / or data communications protocols, as well as instructions for carrying out one or more of the techniques described herein. In some implementations, processing circuitry may be used to enable the respective functional unit to perform corresponding functions according to one or more embodiments of this disclosure. In view of the foregoing, the embodiments described herein generally include a communication system comprising a host computer. The host computer may comprise processing circuitry configured to provide user data. The host computer may also comprise a communication interface configured to forward user data to a cellular network for transmission to a user equipment (UE). The cellular network may comprise a base station having a radio communication interface and processing circuitry, the processing circuitry of the base station being configured to perform any of the steps of any of the embodiments described above for a base station. In some implementations, the communication system also includes the base station. In some embodiments, the communication system also includes the UE, where the UE is configured to communicate with the base station. In some embodiments, the host computer's processing circuitry is configured to run a host application, thereby providing user data. In this case, the user equipment (UE) comprises processing circuitry configured to run a client application associated with the host application. Embodiments herein also include a method implemented in a communication system comprising a host computer, a base station, and a user equipment (UE). The method comprises, on the host computer, providing user data. The method may also comprise, on the host computer, initiating a transmission that carries the user data to the UE via a cellular network comprising the base station. The base station performs any of the steps of any of the embodiments described above for a base station. In some embodiments, the method further comprises transmitting user data at the base station. In some embodiments, user data is provided to the host computer by running a host application. In this case, the method further comprises running a client application associated with the host application at the UE. The embodiments described herein also include a user equipment (UE) configured to communicate with a base station. The UE comprises a radio communications interface and processing circuitry configured to perform any of the embodiments described above for a UE. The embodiments described herein further include a communication system comprising a host computer. The host computer comprises processing circuitry configured to provide user data and a communication interface configured to forward user data to a cellular network for transmission to a user equipment (UE). The UE comprises a radio communication interface and processing circuitry. The UE components are configured to perform any of the steps of any of the embodiments described above for a UE. In some implementations, the cellular network also includes a base station configured to communicate with the UE. In some implementations, the host computer's processing circuitry is configured to run a host application, thereby providing user data. The UE's processing circuitry is configured to run a client application associated with the host application. The embodiments also include a method implemented in a communication system comprising a host computer, a base station, and a user equipment (UE). The method comprises, on the host computer, providing user data and initiating a transmission that carries the user data to the UE via a cellular network comprising the base station. The UE performs any of the steps of any of the embodiments described above for a UE. In some embodiments, the method also includes, in the UE, receiving user data from the base station. The embodiments described herein further include a communication system comprising a host computer. The host computer comprises a communication interface configured to receive user data originating from a transmission from a user equipment (UE) to a base station. The UE comprises a radio communication interface and processing circuitry. The UE's processing circuitry is configured to perform any of the steps in any of the embodiments described above for a UE. In some implementations, the communication system also includes the UE. In some embodiments, the communication system also includes the base station. In this case, the base station comprises a radio communication interface configured to communicate with the UE and a communication interface configured to forward user data transmitted from the UE to the base station to the host computer. In some implementations, the host computer's processing circuitry is configured to run a host application. The UE's processing circuitry is then configured to run a client application associated with the host application, thereby providing user data. In some implementations, the host computer's processing circuitry is configured to run a host application, thereby providing request data. The UE's processing circuitry is then configured to run a client application associated with the host application, thereby providing user data in response to the request data. The embodiments described herein also include a method implemented in a communication system comprising a host computer, a base station, and a user equipment (UE). The method comprises, on the host computer, receiving user data transmitted to the base station from the UE. The UE performs any of the steps of any of the embodiments described above. In some embodiments, the method further comprises, on the UE, providing the user data to the base station. In some embodiments, the method also includes, on the UE, running a client application, thereby providing the user data to be transmitted. The method may further include, on the host computer, running a host application associated with the client application. In some embodiments, the method further comprises, on the UE, running a client application and, on the UE, receiving input data in the client application. The input data is provided on the host computer running a host application associated with the client application. The user data to be transmitted is provided by the client application in response to the input data. The embodiments also include a communication system comprising a host computer. The host computer comprises a communication interface configured to receive user data originating from a transmission from a user equipment (UE) to a base station. The base station comprises a radio communication interface and processing circuitry. The processing circuitry of the base station is configured to perform any of the steps of any of the embodiments described above for a base station. In some implementations, the communication system also includes the base station. In some implementations, the communication system also includes the UE. The UE is configured to communicate with the base station. In some implementations, the host computer's processing circuitry is configured to run a host application. The UE is then configured to run a client application associated with the host application, thereby providing the user data to be received by the host computer. The embodiments further include a method implemented in a communication system comprising a host computer, a base station, and a user device (UD). The method comprises, on the host computer, receiving user data from the base station originating from a transmission received by the base station from the UD. The UD performs any of the steps of any of the embodiments described above for a UD. In some embodiments, the method also includes, at the base station, receiving user data from the UE. In some embodiments, the method also includes, at the base station, initiating a transmission of the received user data to the host computer. In general, all terms used herein should be interpreted according to their common meaning in the relevant technical field, unless a different meaning is clearly given and / or the same meaning is implied from the context in which they are used. All references to an element, apparatus, component, means, step, etc., should be interpreted broadly as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise. The steps of any of the methods disclosed herein need not be carried out in the exact order disclosed, unless a step is explicitly described as following or preceding another step and / or it is implicitly implied that one step must follow or precede another step.Any feature of any of the embodiments disclosed herein may be applied to any other embodiment, where appropriate. Likewise, any advantage of any embodiment may be applied to any other embodiment, and vice versa. Other objectives, features, and advantages of the accompanying embodiments will become evident from the description. The term unit may have the conventional meaning corresponding to the field of electronics, electrical devices and / or electronic devices and may include, for example, electrical and / or electronic circuitry, devices, modules, processors, memories, solid-state and / or discrete logic devices, computer programs or instructions to produce respective tasks, procedures, calculations, outputs and / or display functions, etc., such as those described in this document. Some of the embodiments covered herein are described more fully with reference to the accompanying drawings. Other embodiments, however, are contained within the scope of the subject matter disclosed herein. The subject matter disclosed herein should not be interpreted as being limited solely to the embodiments set forth herein; rather, these embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.
Claims
1. A method carried out by a network node (30B, 1300) in a wireless communication network (10), the method comprising: acquiring (900) radio access capability information (20, 28) of a wireless device (14), wherein the radio access capability information (28, 20) of the wireless device (14) indicates the radio access capability of the wireless device (14); determining (930) whether or not to forward the radio access capability information from the network node (30B, 1300) to another network node in the wireless communication network, wherein the determination is to: forward the radio access capability information if the network node has received the radio access capability information after the access layer security for the wireless device has been activated,wherein access layer security is established between the wireless device and the network node; or refraining from forwarding radio access capability information if the network node (30B) has received the radio access capability information before access layer security has been activated for the wireless device, wherein access layer security is not established between the wireless device and the network node; and forwarding, or refraining from forwarding, the radio access capability information from the network node (30B) to the other network node as determined (930).
2. The method of claim 1, comprising: determining whether or not to store the radio access capability information in the network node,wherein the storage determination is: refrain from storing the radio access capability information (28) on the network node if the wireless communication network (10) has received the radio access capability information (28) from the wireless device (14) before the access stratum security (24) for the wireless device (14) has been activated, refraining from storing the radio access capability information, or store the radio access capability information (28) on the network node if the wireless communication network (10) has received the radio access capability information (28) from the wireless device (14) after the access stratum security (24) for the wireless device (14) has been activated, storing the radio access capability information; and storing or refraining from storing,the information (28) of radio access capabilities in the network node according to the storage determination.
3. The method of claim 1 or 2, wherein the wireless device is a user equipment, UE, and wherein the radio access capability information is acquired using a radio resource control capability transfer procedure, RRC, from the UE, wherein the network node receives the radio access capability information from the wireless device in response to transmitting a capability query to the wireless device.
4. The method of claim 3,wherein forwarding comprises: forwarding the radio access capability information if the network node has acquired the radio access capability information using the UE's RRC capability transfer procedure after access layer security has been activated for the wireless device; and / or abstaining from forwarding comprises: refraining from forwarding the radio access capability information if the network node has acquired the radio access capability information using the UE's RRC capability transfer procedure before access layer security has been activated for the wireless device.
5. The method of any of claims 1-4,wherein the information on radio access capabilities indicates the radio access capabilities of the wireless device for each of one or more radio access technologies.
6. The method of any of claims 1-5, comprising: determining (910) whether the wireless communication network (10) has received the radio access capabilities information (28) of the wireless device (14) before the access layer security (24) for the wireless device (14) has been activated; and whether the wireless communication network (10) has received the radio access capabilities information (28) of the wireless device (14) before the access layer security (24) for the wireless device (14) has been activated according to such determination,reacquiring (920) the radio access capability information (28) of the wireless device (14) after the access layer security (24) for the wireless device (14) has been activated.
7. The method of claim 6, wherein reacquiring the radio access capability information (28) of the wireless device (14) after the access layer security (24) for the wireless device (14) has been activated comprises, after the access layer security (24) for the wireless device (14) has been activated: transmitting to the wireless device (14) a capability query requesting the radio access capability information (28) of the wireless device (14); and receiving the radio access capability information (28) of the wireless device (14) as a response to the capability query.
8. The method of claim 6 or 7,wherein the reacquisition of the radio access capability information (28) of the wireless device (14) comprises receiving the radio access capability information (28) of the wireless device (14) over a control plane connection after the access layer security (24) has been activated to secure the control plane connection.
9. The method of claim 8, wherein the control plane connection is a Radio Resource Control (RRC) connection.
10. The method of any of claims 6-9, wherein the reacquisition of the radio access capability information (28) of the wireless device (14) after the access layer security (24) for the wireless device (14) has been activated comprises retrieving the radio access capability information (28) of the wireless device (14) using a Radio Resource Control (RRC) capability transfer procedure.User Equipment, UE, after successfully performing an Access Layer Security Mode Command (24) procedure, SMC.
11. The method of any of claims 1-10, wherein the radio access capabilities information (28) comprises: one of multiple Radio Resource Control, RRC, segments indicating the radio access capabilities of the wireless device (14); or an identifier mapped to the radio access capabilities of the wireless device (14).
12. The method of any of claims 1-11, wherein the network node (30B) is a New Radio B Node, gNB, a Next Generation Evolved B Node, ng-eNB, or an Evolved B Node, eNB.
13. A network node (30B, 1300) configured for use in a wireless communication network (10), the network node (30B, 1300) comprising: communication circuits (1320); and processing circuits (1310) configured to: acquire information (20,28) of radio access capabilities of the wireless device (14), wherein the information (28) of radio access capabilities of the wireless device (14) indicates radio access capabilities of the wireless device (14); determining (930) whether or not to forward the radio access capabilities information from network node (30B, 1300) to another network node in the wireless communication network, wherein the determination is: to forward the radio access capabilities information if the network node has received the radio access capabilities information after the access stratum security for the wireless device has been activated,wherein access layer security has been activated between the wireless device and the network node; or refraining from forwarding the radio access capability information if the network node (30B) has received the radio access capability information before access layer security has been activated for the wireless device, wherein access layer security is not activated between the wireless device and the network node; and forwarding, or refraining from forwarding, the Radio Access Capability Information from the network node (30B) to the other network node as determined (930).
14. The network node of claim 13, wherein the processing circuits (1310) are configured to carry out the method of any of claims 2-12.
15. A computer program comprising instructions that, when executed by at least one processor of a network node (30B, 1300), cause the node (30B,1300) network carry out the method of any of claims 1-12.,