User plane integrity protection (up IP) capability signaling in 5g / 4g systems

By signaling UP IP support through spare bits in encryption algorithm fields, the method addresses the lack of UP IP in LTE networks, ensuring secure data transmission and compatibility with diverse RAN nodes, enhancing security and reliability in 4G and 5G systems.

JP2025128077APending Publication Date: 2025-09-02QUALCOMM INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025071215
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2020-09-18
Filing Date
2025-04-23
Publication Date
2025-09-02

AI Technical Summary

Technical Problem

Current communication networks lack support for user plane integrity protection (UP IP) in LTE access networks with an evolved packet core (EPC) or LTE with a 5G core, which is essential for secure and reliable data transmission in IoT and machine-to-machine communication systems.

Method used

Implementing a method to indicate UP IP support via setting unused or spare bits in the EPS Encryption Algorithm (EEA) or EPS Integrity Algorithm (EIA) bits in the 5G UE Security Capabilities IE and 4G S1 UE Security Capabilities IE, allowing wireless devices to signal UP IP support over eUTRA and NR, enabling compatibility with both legacy and 5G RAN nodes.

Benefits of technology

Enables secure detection of user plane data modifications in transit, enhancing network and device security across various communication technologies, including 4G and 5G networks, and facilitating seamless transitions between different RAN nodes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025128077000001_ABST
    Figure 2025128077000001_ABST
Patent Text Reader

Abstract

To provide methods, systems, and devices for supporting user plane integrity protection UP IP for communications with a radio access network (RAN).SOLUTION: A method may include indicating whether or not a wireless device supports UP IP over Evolved Universal Mobile Telecommunications System UMTS Terrestrial Radio Access eUTRA by including UP IP support indications in user equipment UE security capability information element IEs.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] Related Applications

[0001] This application claims the benefit of priority to U.S. Provisional Application No. 62 / 910,632, entitled "UP IP Capability Signaling In 5G / 4G Systems," filed October 4, 2019, the entire contents of which are hereby incorporated by reference into this specification for all purposes. [Background technology]

[0002]

[0002] Long Term Evolution (LTE), 5G new radio (NR), and other recently developed communication technologies enable wireless devices to communicate information at data rates (e.g., gigabits per second) that are orders of magnitude greater than those available just a few years ago.

[0003] Today's communication networks are also more secure, more tolerant to multipath fading, allow for lower network traffic latency, and offer better communication efficiency (e.g., in terms of bits / second per unit of bandwidth used, etc.). These and other recent improvements have facilitated the emergence of the Internet of Things (IoT), large-scale machine-to-machine (M2M) communication systems, autonomous vehicles, and other technologies that rely on consistent and secure communication. Summary of the Invention

[0004] Various aspects include a method for supporting user plane integrity protection (UP IP) for communications with a radio access network (RAN). Various aspects may include indicating whether a wireless device supports UP IP over evolved Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access (eUTRA) by setting one of an EPS Encryption Algorithm (EEA) bit or an EPS Integrity Algorithm (EIA) bit in a fifth generation (5G) user equipment (UE) security capability information element (IE). In some aspects, the same bit may also be used to indicate that the wireless device supports the same maximum data rate capability for UP IP over eUTRA. Various aspects may include indicating whether a wireless device supports UP IP over eUTRA by setting one of the EEA or EIA bits in a fourth generation (4G) S1 UE security capabilities IE. In some aspects, the same bit may also be used to indicate that the wireless device supports UP IP over New Radio (NR). In some aspects, a different bit in the 4G S1 UE security capabilities IE may indicate that the wireless device supports UP IP over NR.

[0005]

[0005] Various aspects may include determining whether a wireless device supports UP IP for an eUTRA connection established between the wireless device and the RAN; generating a first security capability information element including a first UP IP support indication, wherein the first UP IP support indication transmits the first security capability information element to a base station indicating whether the wireless device supports UP IP for the eUTRA connection established between the wireless device and the RAN. In some aspects, the first UP IP support indication may be a bit setting in the first security capability information element. In some aspects, the first security capability information element may be S1 UE security capabilities. In various aspects, the UP IP support indication may include determining whether a wireless device supports UP IP for an eUTRA connection established between the wireless device and the RAN; generating a first security capability information element including a first UP IP support indication, wherein the first UP IP support indication transmits the first security capability information element to a base station, the first security capability information element indicating whether the wireless device supports UP IP for the eUTRA connection established between the wireless device and the RAN. In some aspects, the first UP IP support indication may be a bit setting in the first security capability information element. In some aspects, the first security capability information element may be S1 UE security capabilities. In various aspects, the UP IP support indication may include determining whether a wireless device supports UP IP for the eUTRA connection established between the wireless device and the RAN It may indicate support for IP.

[0006]

[0006] Various aspects may further include generating a second security capabilities information element including a second UP IP supporting UE equipment computing device that supports a UP IP for an eUTRA connection established between the wireless device and the RAN or a UP IP for an NR connection established between the wireless device and the RAN, and transmitting the second security capabilities information element to the base station. In some aspects, the second UP IP support indication may be a bit setting in the second security capabilities information element. In some aspects, the second security capabilities information element may be 5G UE security capabilities.

[0007]

[0007] Various aspects may further include determining whether the wireless device supports UP IP for the NR connection established between the wireless device and the RAN, where generating a first security capabilities information element including the first UP IP support indication may include generating a first security capabilities information element including the first UP IP support indication and a third UP IP support indication, where the third UP IP support indication indicates whether the wireless device supports UP IP for the NR connection established between the wireless device and the RAN. In some aspects, the third UP IP support indication may be another bit setting in the first security capabilities information element.

[0008] Various aspects may include receiving a security capabilities information element including a UP IP support indication at a processor of a network computing device of a wireless device; and determining, based at least in part on the UP IP support indication, whether the security capabilities information element indicates that the wireless device supports UP IP for an eUTRA connection established with the wireless device. In some aspects, the UP IP support indication may be a bit setting in the security capabilities information element. In some aspects, the security capabilities information element may be an S1 UE security capability or a 5G UE security capability. Various aspects may further include determining whether the security capabilities information element indicates that the wireless device supports UP IP for an NR connection established with the wireless device. In some aspects, the UP IP support indication may indicate whether UP IP is supported for the NR connection. In some aspects, the security capabilities information element may include another UP IP support indication indicating whether UP IP is supported for the NR connection. In some aspects, the another UP IP support indication may be a different bit setting in the security capabilities information element. In various aspects, the UP IP support indication may indicate support for UP IP with one or more algorithms.

[0009] In some aspects, the RAN may be a 4G RAN or a 5G RAN. In some aspects, the RAN may be connected to an Evolved Packet Core (EPC) network or a Next Generation Core (NGC) network. In some aspects, the base station may be an eNodeB (eNB) or a Next Generation eNB (ng-eNB). In some aspects, the UP IP support indication may be delivered to one type of core network and may be used when the wireless device moves to another type of core network.

[0010]

[0010] Further aspects may include a wireless device having a processor configured to perform one or more operations of the methods summarized above. Further aspects may include a non-transitory processor-readable storage medium having stored thereon processor-executable instructions configured to cause a processor of the wireless device to perform the operations of the methods summarized above. Further aspects may include a wireless device having means for performing the functions of the methods summarized above. Further aspects include a system-on-chip for use in a wireless device including a processor configured to perform one or more operations of the methods summarized above. Further aspects include a system in a package including two system-on-chips for use in a wireless device including processors configured to perform one or more operations of the methods summarized above. Further aspects may include a network computing device having a processor configured to perform one or more operations of the methods summarized above. Further aspects may include a non-transitory processor-readable storage medium having stored thereon processor-executable instructions configured to cause a processor of the network computing device to perform the operations of the methods summarized above. Further aspects include a network computing device having means for performing the functions of the methods summarized above.

[0011]

[0011] The accompanying drawings, which are incorporated in and form part of this specification, illustrate exemplary embodiments of the claims and, together with the general description given above and the detailed description given below, serve to explain the features of the claims. [Brief explanation of the drawings]

[0012] [Figure 1A]

[0012] FIG. 1 is a system block diagram conceptually illustrating an exemplary communication system. [Figure 1B]

[0013] Diagram showing various deployment options for 4G and 5G radio access network connections to a 4G core network. [Figure 1C] Diagram showing various deployment options for 4G and 5G radio access network connections to a 4G core network. [Figure 1D] Diagram showing various deployment options for 4G and 5G radio access network connections to a 4G core network. [Figure 1E] Diagram showing various deployment options for 4G and 5G radio access network connections to a 4G core network. [Figure 1F]

[0014] Diagram showing various deployment options for 4G and 5G radio access network connections to a 5G core network. [Figure 1G] Diagram showing various deployment options for 4G and 5G radio access network connections to a 5G core network. [Figure 1H] Diagram showing various deployment options for 4G and 5G radio access network connections to a 5G core network. [Figure 1I] Diagram showing various deployment options for 4G and 5G radio access network connections to a 5G core network. [Figure 2]

[0015] Component block diagram illustrating an exemplary computing and wireless modem system suitable for implementing any of the various embodiments. [Figure 3]

[0016] FIG. 1 illustrates an example software architecture including radio protocol stacks for user and control planes in wireless communications, in accordance with various embodiments. [Figure 4]

[0017] Component block diagram illustrating a system configured to be executed by a processor of a wireless device for supporting user plane integrity protection (UP IP) for communications with a radio access network (RAN), in accordance with various embodiments. [Figure 5]

[0018] FIG. 1 is a process flow diagram illustrating a method for supporting user plane integrity protection for communications with a RAN, according to various embodiments. [Figure 6]

[0019] FIG. 1 is a process flow diagram illustrating a method for supporting user plane integrity protection for communications with a RAN, according to various embodiments. [Figure 7]

[0020] FIG. 1 is a process flow diagram illustrating a method for supporting user plane integrity protection for communications with a RAN, according to various embodiments. [Figure 8]

[0021] FIG. 1 is a process flow diagram illustrating a method for supporting user plane integrity protection for communications with a RAN, according to various embodiments. [Figure 9]

[0022] FIG. 1 is a process flow diagram illustrating a method for supporting user plane integrity protection for communications with a RAN, according to various embodiments. [Figure 10]

[0023] FIG. 1 is a component block diagram of a network computing device suitable for use with various embodiments. [Figure 11]

[0024] 1 is a component block diagram of a wireless device suitable for use with the various embodiments. DETAILED DESCRIPTION OF THE INVENTION

[0013]

[0025] Various embodiments will be described in detail with reference to the accompanying drawings. Wherever possible, the same reference numbers will be used throughout the drawings to refer to the same or like parts. References made to specific examples and implementations are for illustrative purposes only and do not limit the scope of the claims.

[0014]

[0026] Various aspects include a method for supporting user plane integrity protection (UP IP) for communications with a radio access network (RAN). Supporting UP IP may enable a wireless device and / or a network computing device to detect when user plane data has been modified in transit. Detecting modifications to user plane data may improve network and / or wireless device security.

[0015]

[0027] The terms “wireless device” or “computing device” are used interchangeably herein to refer to any one or all of wireless router devices, wireless appliances, cellular telephones, smartphones, portable computing devices, personal or mobile multimedia players, laptop computers, tablet computers, smartbooks, ultrabooks, palmtop computers, wireless email receivers, multimedia Internet-enabled cellular telephones, medical devices and equipment, biometric sensors / devices, wearable devices including smart watches, smart clothing, smart glasses, smart wristbands, smart jewelry (e.g., smart rings, smart bracelets, etc.), entertainment devices (e.g., wireless game controllers, music and video players, satellite radio, etc.), wireless network-enabled Internet of Things (IoT) devices including smart meters / sensors, industrial manufacturing equipment, large and small machines and appliances for home or business use, wireless communication elements in autonomous and semi-autonomous vehicles, wireless devices fixed to or embedded in various mobile platforms, global positioning system devices, and similar electronic devices that include memory, wireless communication components, and a programmable processor.

[0016]

[0028] The term "system on a chip" (SOC) is used herein to refer to a single integrated circuit (IC) chip containing multiple resources and / or processors integrated on a single substrate. A single SOC may include circuitry for digital, analog, mixed-signal, and radio frequency functions. A single SOC may also include any number of general-purpose and / or special-purpose processors (such as digital signal processors, modem processors, video processors, etc.), memory blocks (e.g., ROM, RAM, flash, etc.), and resources (e.g., timers, voltage regulators, oscillators, etc.). A SOC may also include software for controlling the integrated resources and processors and for controlling peripheral devices.

[0017]

[0029] The term "system in package" (SIP) may be used herein to refer to a single module or package containing multiple resources, computing units, cores, and / or processors on two or more IC chips, substrates, or SOCs. For example, a SIP may include a single substrate on which multiple IC chips or semiconductor dies are stacked in a vertical configuration. Similarly, a SIP may include one or more multi-chip modules (MCMs) on which multiple ICs or semiconductor dies are packaged into a unified substrate. A SIP may also include multiple independent SOCs packaged in close proximity and coupled to each other via high-speed communication circuits, such as on a single motherboard or in a single wireless device. The proximity of the SOCs facilitates high-speed communication and sharing of memory and resources.

[0018]

[0030] The term "multi-core processor" may be used herein to refer to a single integrated circuit (IC) chip or chip package that includes two or more independent processing cores (e.g., a CPU core, an Internet Protocol (IP) core, a graphics processor unit (GPU) core, etc.) configured to read and execute program instructions. A SOC may include multiple multi-core processors, and each processor in a SOC may be referred to as a core. The term "multiprocessor" may be used herein to refer to a system or device that includes two or more processing units configured to read and execute program instructions.

[0019]

[0031] Various embodiments are described herein using the term “server” to refer to any computing device capable of functioning as a server, such as a master exchange server, web server, mail server, document server, content server, or any other type of server. A server may be a dedicated computing device or may be a computing device that includes a server module (e.g., running an application that can cause the computing device to operate as a server). A server module (e.g., a server application) may be a full-featured server module or may be a simplified server module or secondary server module (e.g., a simplified server application or secondary server application) configured to provide synchronization services between dynamic databases on the receiver device. A simplified server or secondary server may be a scaled-down version of server-type functionality that may be implemented on the receiver device, thereby enabling it to function as an Internet server (e.g., a corporate email server) only to the extent necessary to provide the functionality described herein.

[0020]

[0032] User plane integrity protection enables network operator computing devices and wireless devices (e.g., user equipment (UE) computing devices) to detect when user plane data has been modified in transit between them. User plane integrity protection, at least over the air interface, is currently available for fifth-generation (5G) access networks with a 5G core, but not for long-term evolution (LTE) access networks with an evolved packet core (EPC) or LTE with a 5G core. Integrity protection is currently specified for the control plane to protect signaling messages, but is currently only partially specified for the 5G user plane. There are various options for how 5G and fourth-generation (4G) technologies can be implemented with each other, such as Option 1—Evolved Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access (eUTRA) with EPC, Option 2—New Radio (NR) Standalone with 5G Core, Option 3—EPC-based Dual Connectivity of eUTRA and NR Radio Access Technology (RAT), Option 4—5G Core-based Dual Connectivity (NR Master-eUTRA Secondary), Option 5—5G Core with eUTRA, and Option 7—5G Core-based Dual Connectivity (eUTRA Master-NR Secondary). Therefore, it may be beneficial to support user plane integrity protection (UP IP) in the various different implementation options for 5G and 4G.

[0021]

[0033] Support for UP IP over NR by a 5G wireless device is signaled to the 5G network using a user equipment (UE) security capability information element (IE) during registration of the wireless device to the 5G system. Section 9.11.3.54 of the 3rd Generation Partnership Project (3GPP®) Technical Specification (TS) (3GPP TS) 24.501 describes the UE security capability IE for the 5G system. The UE security capability IE indicates supported NR integrity protection algorithms for NR and eUTRA. Fourth-generation (4G) UE security capabilities, such as Evolved Packet System (EPS) UE security capabilities, are indicated to the network using a separate IE in the 5G system, called the S1 UE security capability IE in the 5G system; a similar IE is used when the wireless device registers with EPS and is defined in sections 9.9.3.34 and 9.9.3.53 of 3GPP TS 24.301. As described herein, the IE used when registering with the EPS is called the 4G S1 UE Security Capabilities IE.

[0022]

[0034] Various embodiments may allow for separate indication of UP IP support to the network via eUTRA. A separate indication of IP support may be added to signaling of support of UP IP by a 5G wireless device via NR in a 5G system. In various embodiments, a separate indication of UP IP support via eUTRA may be indicated when the wireless device begins supporting UP IP via eUTRA. Various embodiments may enable a wireless device to indicate support of UP IP via eUTRA when the wireless device connects to a 5G Core (5GC) via a base station in a 5G Radio Access Network (RAN), such as a Next Generation eNB (ng-eNB). Various embodiments may enable a wireless device to indicate support of UP IP via eUTRA when the wireless device connects to a 4G core network, such as an EPC, via a base station of a 4G RAN, such as an eNodeB (eNB). Various embodiments may enable a wireless device to indicate support of UP IP via eUTRA and NR when the wireless device connects to a 4G core network, such as an EPC, via a base station of a 4G RAN, such as an eNB. In some embodiments, the UP IP support indication may be delivered to one type of core network (e.g., EPC or 5GC) but may be used when the wireless device moves to another type of core network (e.g., EPC or 5GC).

[0023]

[0035] Various embodiments include a method for supporting User Plane Integrity Protection (UP IP) for communications with a Radio Access Network (RAN). Various embodiments may include indicating whether a wireless device supports UP IP over eUTRA by setting one of an unused or spare Evolved Packet System (EPS) Encryption Algorithm (EEA) bit or an EPS Integrity Algorithm (EIA) bit in a 5G UE Security Capabilities IE. In some embodiments, the same bit may also be used to indicate that the wireless device supports the same maximum data rate capability for UP IP over eUTRA. Various embodiments may include indicating whether a wireless device supports UP IP over eUTRA by setting one of an unused or spare EEA bit or an EIA bit in a 4G S1 UE Security Capabilities IE. In some embodiments, the same bit may also be used to indicate that the wireless device supports UP IP over New Radio (NR). In some embodiments, a different bit in the 4G S1 UE Security Capabilities IE may indicate that the wireless device supports UP IP over NR. Indicating whether a wireless device supports UP IP via eUTRA by setting one of the unused or spare bits in the 5G UE Security Capability IE and / or the 4G S1 UE Security Capability IE may enable the wireless device to interact with legacy 4G RAN nodes, such as legacy eNBs, that do not support UP IP. For example, legacy 4G RAN nodes may ignore the unused or spare bits in the 5G UE Security Capability IE and / or the 4G S1 UE Security Capability IE. In this manner, various embodiments may enable a wireless device to transition between legacy 4G RAN nodes and 4G RAN nodes and 5G RAN nodes that support UP IP without determining the state of UP IP support of any particular RAN node to which the wireless device may connect.

[0024]

[0036] 1A is a system block diagram illustrating an exemplary communication system 100 suitable for implementing any of the various embodiments. The communication system 100 may be a fifth-generation (5G) New Radio (NR) network or any other suitable network, such as an LTE network, a 5G network, etc. Although FIG. 1A illustrates a 5G network, later-generation networks may include the same or similar elements. Accordingly, references to 5G networks and 5G network elements in the following description are for illustrative purposes and not intended to be limiting.

[0025]

[0037] Communications system 100 may include a heterogeneous network architecture including a core network 140 and various mobile devices (also referred to as user equipment (UE) computing devices) (shown in FIG. 1A as wireless devices 120a-120e). Communications system 100 may also include several base stations (shown as BS 110a, BS 110b, BS 110c, and BS 110d) and other network entities. A base station is an entity that communicates with the wireless devices (mobile devices or UEs) and may also be referred to as a Node B, Node B, LTE evolved Node B (eNB), access point (AP), radio head, transmit / receive point (TRP), new radio base station (NR BS), 5G Node B (NB), next generation Node B (gNB), etc. Each base station may provide communication coverage for a particular geographic area. In 3GPP, the term "cell" can refer to a base station coverage area, a base station subsystem serving this coverage area, or a combination thereof, depending on the context in which the term is used.

[0026]

[0038] Base stations 110a-110d may provide communication coverage for a macro cell, a pico cell, a femto cell, another type of cell, or a combination thereof. A macro cell may cover a relatively large geographic area (e.g., a few kilometers in radius) and may allow unrestricted access by mobile devices with service subscriptions. A pico cell may cover a relatively small geographic area and may allow unrestricted access by mobile devices with service subscriptions. A femto cell may cover a relatively small geographic area (e.g., a home) and may allow restricted access by mobile devices that have association with the femto cell (e.g., mobile devices in a closed subscriber group (CSG)). A base station for a macro cell may be referred to as a macro BS. A base station for a pico cell may be referred to as a pico BS. A base station for a femto cell may be referred to as a femto BS or a home BS. 1A, base station 110a may be a macro BS for macro cell 102a, base station 110b may be a pico BS for pico cell 102b, and base station 110c may be a femto BS for femto cell 102c. Base stations 110a-110d may support one or more (e.g., three) cells. The terms “eNB,” “base station,” “NR BS,” “gNB,” “TRP,” “AP,” “Node B,” “5G NB,” and “cell” may be used interchangeably herein.

[0027]

[0039] In some examples, the cells may not be fixed, and the geographic area of ​​the cells may move according to the location of the mobile base station. In some examples, the base stations 110a-110d may be interconnected to each other and to one or more other base stations or network nodes (not shown) in the communication system 100 through various types of backhaul interfaces, such as direct physical connections, virtual networks, or combinations thereof, using any suitable transport network.

[0028]

[0040] The base stations 110a-110d may communicate with the core network 140 via wired or wireless communication links 126. The wireless devices 120a-120e (UE computing devices) may communicate with the base stations 110a-110d via wireless communication links 122.

[0029]

[0041] The wired communication link 126 may use various wired networks (e.g., Ethernet, TV cable, telephone, fiber optic, and other forms of physical network connections) that may use one or more wired communication protocols, such as Ethernet, Point-to-Point Protocol, High-Level Data Link Control (HDLC), Advanced Data Communication Control Protocol (ADCCP), and Transmission Control Protocol / Internet Protocol (TCP / IP).

[0030]

[0042] The communications system 100 may also include a relay station (e.g., relay BS 110d). A relay station is an entity that can receive a transmission of data from an upstream station (e.g., a base station or a mobile device) and transmit a transmission of data to a downstream station (e.g., a wireless device or a base station). A relay station may also be a mobile device that can relay a transmission to another wireless device. In the example shown in FIG. 1A, relay station 110d may communicate with the macro base station 110a and the wireless device 120d to facilitate communication between the base station 110a and the wireless device 120d. A relay station may also be referred to as a relay base station, a relay base station, a relay, etc.

[0031]

[0043] Communications system 100 may be a heterogeneous network including different types of base stations, e.g., macro base stations, pico base stations, femto base stations, relay base stations, etc. These different types of base stations may have different transmit power levels, different coverage areas, and different susceptibility to interference in communications system 100. For example, macro base stations may have high transmit power levels (e.g., 5-40 watts), while pico base stations, femto base stations, and relay base stations may have lower transmit power levels (e.g., 0.1-2 watts).

[0032]

[0044] Network controller 130 may couple to a set of base stations and may provide coordination and control for these base stations. Network controller 130 may communicate with the base stations via a backhaul. The base stations may also communicate with each other directly or indirectly, e.g., via wireless or wireline backhaul.

[0033]

[0045] Wireless devices (UE computing devices) 120a, 120b, 120c may be dispersed throughout communication system 100, and each wireless device may be fixed or mobile. A wireless device may also be referred to as an access terminal, UE, terminal, mobile station, subscriber unit, station, etc.

[0034]

[0046] The macro base station 110a may communicate with the communication network 140 via a wired or wireless communication link 126. The wireless devices 120a, 120b, 120c may communicate with the base stations 110a-110d via a wireless communication link 122.

[0035]

[0047] The wireless communication links 122, 124 may include multiple carrier signals, frequencies, or frequency bands, each of which may include multiple logical channels. The wireless communication links 122, 124 may utilize one or more radio access technologies (RATs). Examples of RATs that may be used in the wireless communication links include 3GPP LTE, 3G, 4G, 5G (e.g., NR), GSM, Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Worldwide Interoperability for Microwave Access (WiMAX), Time Division Multiple Access (TDMA), and other mobile telephony cellular RATs. Further examples of RATs that may be used in one or more of the various wireless communication links 122, 124 within the communication system 100 include medium-range protocols such as Wi-Fi, LTE-U, LTE-Direct, LAA, MuLTEfire, as well as ZigBee, Bluetooth, and Bluetooth Low Energy. This includes relatively short-range RATs such as Energy (LE).

[0036]

[0048] Some wireless networks (e.g., LTE) utilize orthogonal frequency division multiplexing (OFDM) on the downlink and single-carrier frequency division multiplexing (SC-FDM) on the uplink. OFDM and SC-FDM partition the system bandwidth into multiple (K) orthogonal subcarriers, also commonly referred to as tones, bins, etc. Each subcarrier may be modulated with data. Generally, modulation symbols are sent in the frequency domain with OFDM and in the time domain with SC-FDM. The spacing between adjacent subcarriers may be fixed, and the total number of subcarriers (K) may depend on the system bandwidth. For example, the subcarrier spacing may be 15 kHz, and the minimum resource allocation (called a "resource block") may be 12 subcarriers (or 180 kHz). Thus, the nominal fast file transfer (FFT) size may be equal to 128, 256, 512, 1024, or 2048 for system bandwidths of 1.25, 2.5, 5, 10, or 20 megahertz (MHz), respectively. The system bandwidth may also be partitioned into subbands. For example, a subband may cover 1.08 MHz (i.e., 6 resource blocks), and there may be 1, 2, 4, 8, or 16 subbands for system bandwidths of 1.25, 2.5, 5, 10, or 20 MHz, respectively.

[0037]

[0049] Although the description of some embodiments may use terminology and examples related to LTE technology, various embodiments may be applicable to other wireless communication systems, such as New Radio (NR) or 5G networks. NR utilizes OFDM with cyclic prefix (CP) on the uplink (UL) and downlink (DL) and may include support for half-duplex operation using time division duplexing (TDD). A single component carrier bandwidth of 100 MHz may be supported. An NR resource block may span 12 subcarriers with a subcarrier bandwidth of 75 kHz for a 0.1 ms duration. Each radio frame may consist of 50 subframes with a length of 10 ms. Thus, each subframe may have a length of 0.2 ms. Each subframe may indicate the link direction (i.e., DL or UL) of data transmission, and the link direction of each subframe may be dynamically switched. Each subframe may contain DL / UL data as well as DL / UL control data. Beamforming may be supported, and the beam direction may be dynamically configured. Multiple-input multiple-output (MIMO) transmission with precoding may also be supported. MIMO configurations in the DL may support up to eight transmit antennas with up to eight streams and multi-layer DL transmission with up to two streams per wireless device. Multi-layer transmission with up to two streams per wireless device may be supported. Multiple cell aggregation with up to eight serving cells may be supported. Alternatively, NR may support different air interfaces other than an OFDM-based air interface.

[0038]

[0050] Some mobile devices may be considered machine-type communication (MTC) mobile devices or evolved or extended machine-type communication (eMTC) mobile devices. MTC and eMTC mobile devices include, for example, a robot, a drone, a remote device, a sensor, a meter, a monitor, a location tag, etc. that may communicate with a base station, another device (e.g., a remote device), or some other entity. A wireless node may provide, for example, connectivity for or to a network (e.g., a wide area network such as the Internet or a cellular network) via a wired or wireless communication link. Some mobile devices may be considered Internet of Things (IoT) devices or may be implemented as NB-IoT (narrowband Internet of Things) devices. Wireless devices 120a-e may be included within a housing that stores components of the wireless device, such as a processor component, a memory component, similar components, or a combination thereof.

[0039]

[0051] In some implementations, two or more mobile devices 120a-e (e.g., shown as wireless device 120a and wireless device 120e) may communicate directly (e.g., without using a base station 110 as an intermediary for communicating with each other) using one or more sidelink channels 124. For example, the wireless devices 120a-e may communicate using peer-to-peer (P2P) communication, device-to-device (D2D) communication, a vehicle-to-everything (V2X) protocol (which may include a vehicle-to-vehicle (V2V) protocol, a vehicle-to-infrastructure (V2I) protocol, or similar protocol), a mesh network, or similar network, or a combination thereof. In this case, the wireless devices 120a-e may perform scheduling operations, resource selection operations, and other operations described elsewhere herein as being performed by the base station 110a.

[0040]

[0052] In general, any number of communication systems and any number of wireless networks may be deployed in a given geographic area. Each communication system and wireless network may support a particular RAT and may operate on one or more frequencies. A RAT may also be referred to as a radio technology, air interface, etc. A frequency may also be referred to as a carrier, frequency channel, etc. Each frequency may support a single RAT in a given geographic area to avoid interference between communication systems of different RATs. In some cases, 4G / LTE and / or 5G / NR RAT networks may be deployed. For example, a 5G non-standalone (NSA) network may utilize both a 4G / LTE RAT on the 4G / LTE RAN side of the 5G NSA network and a 5G / NR RAT on the 5G / NR RAN side of the 5G NSA network. Both the 4G / LTE RAN and the 5G / NR RAN may connect to each other and to a 4G / LTE core network (e.g., an Evolved Packet Core (EPC) network) in the 5G NSA network. Other example network configurations may include a 5G Standalone (SA) network in which a 5G / NR RAN connects to a 5G core network.

[0041]

[0053] For example, 5G and 4G technologies may be deployed together. As a specific example, Figures 1B-1E show various deployment options for 4G and 5G RAN connections to a 4G core network, and Figures 1F-1I show various deployment options for 4G and 5G RAN connections to a 5G core network.

[0042]

[0054] 1A-1I, as shown in FIG. 1B, an exemplary LTE / NR EPC connection deployment option may include Option 1—a standalone LTE RAN including base stations (e.g., base stations 110a-d), such as eNB 156, connected to EPC 154 (e.g., core network 140). EPC 154 may include a mobility management entity (MME) server 150 and a packet data network and serving gateway (P / SGW) server 152. Wireless devices 158 (e.g., wireless devices 120a-120e) may connect to eNB 156 and transmit / receive user plane data to eNB 156, which may transmit / receive user plane data to EPC 154 via an S1-U interface with P / SGW server 152. As shown in FIG. 1C, an exemplary LTE / NR EPC connection deployment option may include Option 3—a master cell group (MCG) split bearer with a non-standalone LTE anchor connected to EPC 154. In such a deployment, a master base station, such as a master eNB (MeNB) 162 (e.g., base stations 110a-110d), may control a secondary gNB (SgNB) 164 (e.g., 110a-110d). The MeNB 162 may connect to the SgNB 164 and provide the SgNB 164's connection to the EPC 154. The wireless device 158 may connect to the MeNB 162 or the SgNB 164 and transmit / receive user plane data to the MeNB 162 or the SgNB 164. The SgNB 164 may transmit / receive user plane data from the MeNB 162 via an X2-U interface. The MeNB 162 may transmit / receive user plane data to the EPC 154 via an S1-U interface with the P / SGW server 152. As shown in FIG. 1D, an exemplary LTE / NR EPC connection deployment option may include option 3a—Secondary Cell Group (SCG) bearer with a non-standalone LTE anchor connected to the EPC 154. In such a deployment, SgNB164 may connect to EPC154.The wireless device 158 may connect to the SgNB 164 and transmit / receive user plane data to the SgNB 164, which may transmit / receive user plane data to the EPC 154 via an S1-U interface with the P / SGW server 152. As shown in FIG. 1E, an exemplary LTE / NR EPC connection deployment option may include option 3x - SCG split bearer with a non-standalone LTE anchor connected to the EPC 154. The SgNB 164 may connect to the MeNB 162 and provide the MeNB 162's connection to the EPC 154. The wireless device 158 may connect to either the MeNB 162 or the SgNB 164 and transmit / receive user plane data to either the MeNB 162 or the SgNB 164. The MeNB 162 may transmit / receive user plane data from the SgNB 164 via an X2-U interface. The SgNB 164 may transmit / receive user plane data to the EPC 154 via an S1-U interface with the P / SGW server 152.

[0043]

[0055] As shown in FIG. 1F, an exemplary LTE / NR 5GC connection deployment option may include Option 5—a standalone LTE RAN including a base station (e.g., base stations 110a-d), such as eNB 156, connected to Next Generation Core (NGC) 174 (e.g., core network 140). In such a deployment, eNB 156 may be an enhanced LTE (eLTE) base station configured to connect 5GC, such as NGC 174. EPC 154 may include a control plane function (CPF) server 170 and a user plane function (UPF) server 172. Wireless devices 158 (e.g., wireless devices 120a-e) may connect to eNB 156 and transmit / receive user plane data to eNB 156, which may transmit / receive user plane data to NGC 174 via an N3 interface with UPF server 172. As shown in FIG. 1G, an exemplary LTE / NR 5GC connection deployment option may include Option 7—an MCG split bearer with a non-standalone LTE anchor connected to NGC 174. In such a deployment, a master base station such as the MeNB 162 (e.g., base stations 110a-110d) may control the SgNB 164 (e.g., 110a-110d). In such a deployment, the MeNB 162 may be an eLTE base station configured to connect a 5GC, such as an NGC 174. The MeNB 162 may connect to the SgNB 164 and provide the connection of the SgNB 164 to the NGC 174. The wireless device 158 may connect to the MeNB 162 or the SgNB 164 and send / receive user plane data to the MeNB 162 or the SgNB 164. The SgNB 164 may send / receive user plane data from the MeNB 162 via the Xn interface. The MeNB 162 may send / receive user plane data to the NGC 174 via the N3 interface with the UPF server 172. As shown in FIG. 1H, an exemplary LTE / NR 5GC connection deployment option may include option 7a - SCG bearers with a non-standalone LTE anchor connected to an NGC 174. In such a deployment, the SgNB 164 may connect to the NGC 174.The wireless device 158 may connect to the SgNB 164 and transmit / receive user plane data to the SgNB 164, which may transmit / receive user plane data to the NGC 174 via an N3 interface with the UPF server 172. As shown in FIG. 1I, an exemplary LTE / NR 5GC connection deployment option may include an SCG split bearer with a non-standalone LTE anchor connected to option 7x-NGC 174. The SgNB 164 may connect to the MeNB 162 and provide the MeNB 162's connection to the NGC 174. The wireless device 158 may connect to either the MeNB 162 or the SgNB 164 and transmit / receive user plane data to either the MeNB 162 or the SgNB 164. The MeNB 162 may transmit / receive user plane data from the SgNB 164 via an Xn interface. The SgNB 164 may transmit / receive user plane data to the NGC 174 via an N3 interface with the UPF server 172.

[0044]

[0056] The deployment options shown in Figures 1B-1I are merely example deployment options, and other deployment options exist. The example deployment options shown in Figures 1B-1I, as well as other deployment options, may be used with various embodiments.

[0045]

[0057] 2 is a component block diagram illustrating an exemplary computing and wireless modem system 200 suitable for implementing any of the various embodiments. The various embodiments may be implemented on a number of single processor and multi-processor computer systems, including systems on a chip (SOC) or systems in a package (SIP).

[0046]

[0058] 1A-2 , the illustrated exemplary wireless device 200 (which may be a SIP in some embodiments) includes two SOCs 202, 204 coupled to a clock 206, a voltage regulator 208, and a wireless transceiver 266 configured to transmit and receive wireless communications via an antenna (not shown) to and from a network wireless device, such as a base station 110a. In some embodiments, the first SOC 202 operates as the wireless device's central processing unit (CPU), carrying out instructions of a software application program by performing arithmetic, logic, control, and input / output (I / O) operations specified by the instructions. In some embodiments, the second SOC 204 may operate as a dedicated processing unit. For example, the second SOC 204 may operate as a dedicated 5G processing unit responsible for managing high-volume, high-speed (e.g., 5 Gbps, etc.), and / or very high-frequency, short-wavelength (e.g., 28 GHz mmWave spectrum, etc.) communications.

[0047]

[0059] The first SOC 202 may include a digital signal processor (DSP) 210, a modem processor 212, a graphics processor 214, an application processor (AP) 216, one or more coprocessors 218 (e.g., vector coprocessors) connected to one or more of these processors, memory 220, custom circuitry 222, system components and resources 224, an interconnect / bus module 226, one or more temperature sensors 230, a thermal management unit 232, and thermal power envelope (TPE) components 234. The second SOC 204 may include a 5G modem processor 252, a power management unit 254, an interconnect / bus module 264, multiple mmWave transceivers 256, memory 258, and various additional processors 260, such as application processors, packet processors, etc.

[0048]

[0060] Each processor 210, 212, 214, 216, 218, 252, 260 may include one or more cores, and each processor / core may perform operations independent of the other processors / cores. For example, a first SOC 202 may include a processor that runs a first type of operating system (e.g., FreeBSD, LINUX, OS X, etc.) and a processor that runs a second type of operating system (e.g., MICROSOFT WINDOWS 10). Additionally, any or all of processors 210, 212, 214, 216, 218, 252, 260 may be included as part of a processor cluster architecture (e.g., a synchronous processor cluster architecture, an asynchronous or heterogeneous processor cluster architecture, etc.).

[0049]

[0061] The first and second SOCs 202, 204 may include various system components, resources, and custom circuits for managing sensor data, analog-to-digital conversion, wireless data transmission, and for performing other specialized operations, such as decoding data packets and processing encoded audio and video signals for rendering in a web browser. For example, the system components and resources 224 of the first SOC 202 may include power amplifiers, voltage regulators, oscillators, phase-locked loops, peripheral bridges, data controllers, memory controllers, system controllers, access ports, timers, and other similar components used to support processors and software clients running on the wireless device. The system components and resources 224 and / or custom circuitry 222 may also include circuitry for interfacing with peripheral devices, such as cameras, electronic displays, wireless communication devices, external memory chips, etc.

[0050]

[0062] The first and second SOCs 202, 204 may communicate via an interconnect / bus module 250. The various processors 210, 212, 214, 216, 218 may be interconnected to one or more memory elements 220, system components and resources 224, custom circuitry 222, and a thermal management unit 232 via an interconnect / bus module 226. Similarly, the processor 252 may be interconnected to a power management unit 254, an mmWave transceiver 256, memory 258, and various additional processors 260 via an interconnect / bus module 264. The interconnect / bus modules 226, 250, 264 may include arrays of reconfigurable logic gates and / or implement a bus architecture (e.g., CoreConnect, AMBA, etc.). Communication may be provided by an advanced interconnect such as a high-performance network-on-chip (NoC).

[0051]

[0063] The first and / or second SOC 202, 204 may further include input / output modules (not shown) for communicating with resources external to the SOC, such as a clock 206, a voltage regulator 208, and one or more wireless transceivers 266. Resources external to the SOC (e.g., clock 206, voltage regulator 208) may be shared by two or more of the internal SOC processors / cores.

[0052]

[0064] In addition to the exemplary SIP 200 described above, various embodiments may be implemented in a wide variety of computing systems, which may include a single processor, multiple processors, multi-core processors, or any combination thereof.

[0053]

[0065] FIG. 3 illustrates an example of a software architecture 300 including radio protocol stacks for the user plane and control plane in wireless communications between a base station 350 (e.g., base stations 110a-110d, 156, 162, 164, 176, 182) and a wireless device (also referred to as a UE or UE computing device) 320 (e.g., wireless devices 120a-120e, 158, 200).

[0054]

[0066] 1A-3 , a wireless device 320 may implement a software architecture 300 to communicate with a base station 350 of a communication system (e.g., 100). In various embodiments, layers in the software architecture 300 may form logical connections with corresponding layers in the software of the base station 350. The software architecture 300 may be distributed among one or more processors (e.g., processors 212, 214, 216, 218, 252, 260). While illustrated with respect to one radio protocol stack, in a multi-SIM (Subscriber Identity Module) wireless device, the software architecture 300 may include multiple protocol stacks, each of which may be associated with a different SIM (e.g., two protocol stacks associated with two SIMs, respectively, in a dual-SIM wireless communication device). While described below with respect to an LTE communication layer, the software architecture 300 may support any of a variety of standards and protocols for wireless communication and / or may include additional protocol stacks supporting any of a variety of standards and protocols for wireless communication.

[0055]

[0067] The software architecture 300 may include a non-access stratum (NAS) 302 and an access stratum (AS) 304. The NAS 302 may include functions and protocols to support packet filtering, security management, mobility control, session management, and traffic and signaling between a wireless device's SIM (e.g., SIM 204) and its core network 140. The AS 304 may include functions and protocols to support communication between the SIM (e.g., SIM 204) and supported access network entities (e.g., base stations). In particular, the AS 304 may include at least three layers (Layer 1, Layer 2, and Layer 3), each of which may include various sublayers.

[0056]

[0068] In the user and control planes, Layer 1 (L1) of the AS 304 may be a physical layer (PHY) 306 that may oversee functions that enable transmission and / or reception over the air interface. Examples of such physical layer 306 functions may include cyclic redundancy check (CRC) attachment, coding blocks, scrambling and descrambling, modulation and demodulation, signal measurement, MIMO, etc. The physical layer may include various logical channels, including a physical downlink control channel (PDCCH) and a physical downlink shared channel (PDSCH).

[0057]

[0069] In the user and control planes, Layer 2 (L2) of the AS 304 may be responsible for the link between the wireless device 320 and the base station 350 on the physical layer 306. In various embodiments, Layer 2 may include a media access control (MAC) sublayer 308, a radio link control (RLC) sublayer 310, and a packet data convergence protocol (PDCP) 312 sublayer, each of which forms a logical connection that terminates at the base station 350.

[0058]

[0070] In the control plane, Layer 3 (L3) of the AS 304 may include a radio resource control (RRC) sublayer 3. Although not shown, the software architecture 300 may include additional Layer 3 sublayers, as well as various upper layers above Layer 3. In various embodiments, the RRC sublayer 313 may provide functions including broadcasting system information, paging, and establishing and releasing RRC signaling connections between the wireless device 320 and the base station 350.

[0059]

[0071] In various embodiments, the PDCP sublayer 312 may provide uplink functions including multiplexing between various radio bearers and logical channels, sequence number addition, handover data processing, integrity protection, ciphering, and header compression. In the downlink, the PDCP sublayer 312 may provide functions including in-order delivery of data packets, duplicate data packet detection, integrity verification, decryption, and header recovery.

[0072] In the uplink, the RLC sublayer 310 may provide segmentation and concatenation of upper layer data packets, retransmission of lost data packets, and automatic repeat request (ARQ). In the downlink, the RLC sublayer 310 functions may include reordering of data packets to compensate for out-of-order reception, reassembly of upper layer data packets, and ARQ.

[0060]

[0073] In the uplink, the MAC sublayer 308 may provide functions including multiplexing between logical and transport channels, random access procedures, logical channel priorities, and hybrid ARQ (HARQ) operations. In the downlink, MAC layer functions may include intra-cell channel mapping, demultiplexing, discontinuous reception (DRX), and HARQ operations.

[0061]

[0074] While the software architecture 300 may provide functionality for transmitting data over a physical medium, the software architecture 300 may further include at least one host layer 314 to provide data transfer services to various applications in the wireless device 320. In some embodiments, the application-specific functionality provided by the at least one host layer 314 may provide an interface between the software architecture and the general-purpose processor 206.

[0062]

[0075] In other embodiments, software architecture 300 may include one or more upper logical layers (e.g., transport, session, presentation, application, etc.) that provide host layer functionality. For example, in some embodiments, software architecture 300 may include a network layer (e.g., IP layer) where a logical connection terminates at a packet data network (PDN) gateway (PGW). In some embodiments, software architecture 300 may include an application layer where a logical connection terminates at another device (e.g., an end-user device, a server, etc.). In some embodiments, software architecture 300 may further include a hardware interface 316 between physical layer 306 and communications hardware (e.g., one or more radio frequency (RF) transceivers) in AS 304.

[0063]

[0076] 4 is a component block diagram illustrating a system 400 for supporting user plane integrity protection (UP IP) for communications with a RAN, in accordance with various embodiments. In some embodiments, the system 400 may include one or more computing platforms 402 and / or one or more remote platforms 404. With reference to FIGS. 1A-4 , the computing platform 402 may include a base station (e.g., base stations 110a-110e, 156, 162, 164, 176, 182, 350) and / or a wireless device (e.g., wireless device 120a-120e, 158, 200, 320). The remote platform 404 may include a base station (e.g., base stations 110a-110e, 156, 162, 164, 176, 182, 350) and / or a wireless device (e.g., wireless device 120a-120e, 158, 200, 320).

[0064]

[0077] The computing platform 402 may include a processor 422 configured with machine-readable instructions 406. The machine-readable instructions 406 may include one or more instruction modules. The instruction modules may include computer program modules. The instruction modules may include one or more of a user equipment (UE) computing device determination module 408, a security capabilities IE generation module 410, a security capabilities IE transmission module 412, a security capabilities IE reception module 414, a security capabilities IE determination module 416, and / or other instruction modules.

[0065]

[0078] The UE computing device determination module 408 may be configured to determine whether the wireless device supports a UP IP for an eUTRA connection established between the wireless device and the RAN. In various embodiments, determining whether the wireless device supports a UP IP for eUTRA may include checking a capability setting of the wireless device. The user equipment computing device determination module 408 may be configured to determine whether the wireless device supports a UP IP for an NR connection established between the wireless device and the RAN. In various embodiments, determining whether the wireless device supports a UP IP for an NR connection may include checking a capability setting of the wireless device. Determining whether to support IP may include checking the capability settings of the wireless device.

[0066]

[0079] The security capabilities IE generation module 410 may be configured to generate one or more security capabilities IEs including one or more UP IP support indications. The UP IP support indication may be a bit setting in the security capabilities IE. For example, the security capabilities IE may be a 5G UE security capabilities IE or an S1 UE security capabilities IE. The UP IP support indication indicates that the wireless device supports UP IP support for an eUTRA connection established between the wireless device and the RAN. The UP IP support indication may indicate whether the wireless device supports UP IP and / or whether the wireless device supports UP IP for an NR connection established between the wireless device and the RAN. The UP IP support indication may indicate UP IP support with several integrity algorithms. The first UP IP support indication may be a setting of one of an Evolved Packet System (EPS) Encryption Algorithm (EEA) bit or an EPS Integrity Algorithm (EIA) bit in the 5G UE security capability IE or the S1 UE security capability IE. In various embodiments, two or more security capability IEs may be generated by the security capability IE generation module 410. For example, a first security capability IE and a second security capability IE may be generated. As a specific example, the first security capability IE may be the S1 UE security capability IE and the second security capability IE may be the 5G UE security capability IE, or vice versa. In various embodiments, the security capability IE generation module 410 generates two UP IP support indications. The security capabilities IE may be configured to generate a security capabilities IE that includes an IP support indication. For example, each UP IP support indication may be a separate bit setting in the security capabilities IE. One bit setting may indicate whether the wireless device supports UP IP for eUTRA, and another bit setting may indicate whether the wireless device supports UP IP for an NR connection established between the wireless device and the RAN.

[0067]

[0080] The security capabilities IE transmission module 412 may be configured to transmit the security capabilities IE to a base station of the RAN. By way of example, the base station may be an eNB or an ng-eNB. In some embodiments, the security capabilities IE may be transmitted to the RAN via another node.

[0068]

[0081] The security capabilities IE receiving module 414 may be configured to receive a security capabilities IE.

[0069]

[0082] The security capabilities IE determination module 416 may be configured to determine, based at least in part on the UP IP support indication, whether the security capabilities IE indicates that the wireless device supports UP IP for an eUTRA connection established with the wireless device. The security capabilities IE determination module 416 may be configured to determine whether the security capabilities IE indicates that the wireless device supports UP IP for an NR connection established with the wireless device.

[0070]

[0083] 5 illustrates a process flow diagram of an example method 500 for supporting UP IP for communication with a RAN, according to various embodiments. With reference to FIGS. 1A-5, method 500 may be implemented by a processor (e.g., 210, 212, 214, 216, 218, 252, 260, 422) of a wireless device (e.g., wireless device 120a-120e, 158, 200, 320, 402).

[0071]

[0084] At block 502, the processor may perform operations including determining whether the wireless device supports UP IP for an eUTRA connection established between the wireless device and the RAN. In various embodiments, determining whether the wireless device supports UP IP for eUTRA may include checking a capability setting of the wireless device.

[0072]

[0085] At block 504, the processor may perform operations including generating a first security capabilities IE including a first UP IP support indication. The first UP IP support indication may indicate whether the wireless device supports UP IP for an eUTRA connection established between the wireless device and the RAN. In some embodiments, the first security capabilities IE may be a 4G S1 UE security capabilities IE. In some embodiments, the first security capabilities IE may be a 5G UE security capabilities IE. In various embodiments, the first UP IP support indication may be a bit setting in the first security capabilities IE. For example, the first UP IP support indication may be a setting of one of the EEA bit or the EIA bit in the 4G S1 UE security capabilities IE or the 5G UE security capabilities IE. In some embodiments, a setting of a bit in the 4G S1 UE security capability IE, such as a setting of one of the EEA bit or the EIA bit in the 4G S1 UE security capability IE, may indicate that the wireless device supports both a UP IP for an eUTRA connection established between the wireless device and the RAN and a UP IP for an NR connection established between the wireless device and the RAN. In various embodiments, the first UP IP support indication may indicate UP IP support with one or more (e.g., several) integrity algorithms.

[0073]

[0086] At block 506, the processor may perform operations including transmitting the first security capabilities IE to a base station. In some embodiments, the base station may be a base station of the RAN. In some embodiments, the base station may be a base station external to the RAN and may be configured to forward the first security capabilities IE to a network device of the RAN, such as a base station of the RAN, an MME server of the RAN, etc. For example, the first security capabilities IE may be transmitted as part of a wireless device registration request transmitted to the RAN.

[0074]

[0087] 6 illustrates a process flow diagram of an example method 600 for supporting UP IP for communication with a RAN, according to various embodiments. With reference to FIGS. 1A-6, the method 600 may be implemented by a processor (e.g., 210, 212, 214, 216, 218, 252, 260, 422) of a wireless device (e.g., wireless device 120a-120e, 158, 200, 320, 402).

[0075]

[0088] At blocks 502, 504, and 506, the processor may perform the operations of like-numbered blocks of the method 500 described with reference to FIG.

[0076]

[0089] At block 608, the processor may perform operations including generating a second security capabilities IE including a second UP IP support indication. In a network including both 4G RAN elements and 5G RAN elements, two security capabilities IEs may be provided to the RAN, such as one security capabilities IE for the 4G system and one security capabilities IE for the 5G system. Each security capabilities IE may separately indicate whether the wireless device supports UP IP for eUTRA connections and / or UP IP for NR connections. For example, the first security capabilities IE may be a 4G S1 UE security capabilities IE, and the second security capabilities IE may be a 5G UE security capabilities IE. In various embodiments, the second UP IP support indication may be a bit setting in the second security capabilities IE. For example, the second UP IP support indication may be a setting of one of the EEA bit or the EIA bit in the 4G S1 UE security capabilities IE or the 5G UE security capabilities IE, depending on the type of the second security capabilities IE. In various embodiments, the second UP IP support indication may indicate UP IP support with one or more (eg, several) integrity algorithms.

[0077]

[0090] At block 610, the processor may perform operations including transmitting the second security capabilities IE to a base station. In some embodiments, the base station may be a base station of the RAN. In some embodiments, the base station may be a base station external to the RAN and may be configured to forward the second security capabilities IE to a network device of the RAN, such as a base station of the RAN, an MME server of the RAN, etc. For example, the second security capabilities IE may be transmitted as part of a wireless device registration request transmitted to the RAN.

[0078]

[0091] 6 shows a method 600 for transmitting two separate security capabilities IEs, such as one security capabilities IE for 4G systems and another security capabilities IE for 5G systems, in other networks, only one security capabilities IE may be generated and transmitted because the network may be configured to share security capabilities IEs and / or indications of support for UP IP by wireless devices between 4G and 5G systems. In such networks that share wireless device support for UP IP indication across 4G and 5G systems, re-registration of wireless devices may not be required when traversing between 4G and 5G coverage.

[0079]

[0092] 7 shows a process flow diagram of an example method 700 for supporting UP IP for communications with a RAN in accordance with various embodiments. With reference to FIGS. 1A-7, method 700 may be implemented by a processor (e.g., 210, 212, 214, 216, 218, 252, 260, 422) of a wireless device (e.g., wireless device 120a-120e, 158, 200, 320, 402). In various embodiments, the operations of method 700 may be implemented in conjunction with the operations of methods 500 (FIG. 5) and / or 600 (FIG. 6). For example, the operations of method 700 may be performed as part of generating a first security capabilities IE upon determining, at block 502, whether the wireless device supports UP IP for an eUTRA connection established between the wireless device and the RAN.

[0080]

[0093] At block 712, the processor may perform operations including determining whether the wireless device supports UP IP for the NR connection established between the wireless device and the RAN. In various embodiments, determining whether the wireless device supports UP IP for the NR connection may include checking a capability setting of the wireless device.

[0081]

[0094] At block 714, the processor may perform operations including generating a first security capabilities IE including a first UP IP support indication and a third UP IP support indication. The third UP IP support indication may indicate whether the wireless device supports UP IP for an NR connection established between the wireless device and the RAN. In some embodiments, the first security capabilities IE includes a 4G UP IP support indication. In various embodiments, the first UP IP support indication may be a bit setting in the first security capabilities IE, and the third UP The IP support indication may be a different bit setting in the first security capabilities IE. For example, the first UP IP support indication may be a setting of one of the EEA bit or the EIA bit in the 4G S1 UE security capabilities IE, and the third UP IP support indication may be a setting of another of the EEA bit or the EIA bit in the 4G S1 UE security capabilities IE.

[0082]

[0095] In response to generating the first security capabilities IE, the processor may perform the operations of block 506 described with reference to Figures 5 and 6 to transmit the first security capabilities IE.

[0083]

[0096] 8 shows a process flow diagram of an example method 800 for supporting UP IP for communications with a RAN, according to various embodiments. With reference to FIGS. 1A-8, method 800 may be implemented by a processor of a network computing device (e.g., base stations 110a-110e, 156, 162, 164, 176, 182, 350, 402, network controller 130, and / or other network entity). In various embodiments, the operations of method 800 may be implemented in conjunction with the operations of methods 500 (FIG. 5), 600 (FIG. 6), and / or 700 (FIG. 7).

[0084]

[0097] At block 816, the processor may perform operations including receiving a security capabilities IE of a wireless device (e.g., wireless device 120a-120e, 200, 320). The security capabilities IE may be received as part of a wireless device registration and / or authentication procedure. The security capabilities IE may include a UP IP support indication. In some embodiments, the security capabilities IE may include a 4G IP support indication. The security capability ID may be an S1 UE security capability IE. In some embodiments, the security capability IE may be a 5G UE security capability IE. In various embodiments, the UP IP support indication may indicate UP IP support with one or more (e.g., several) integrity algorithms. In various embodiments, the UP IP support indication may be a bit setting in the security capability IE. For example, the UP IP support indication may be a setting of one of the EEA bit or the EIA bit in the 4G S1 UE security capability IE or the 5G UE security capability IE. In some embodiments, the security capability IE may be received directly from the wireless device, such as by a base station of the RAN. In some embodiments, the security capability ID may be received from the wireless device via forwarding from another network computing device, such as forwarded from a base station or forwarded from an MME server.

[0085]

[0098] At block 818, the processor may perform operations including determining, based at least in part on the UP IP support indication, whether the security capabilities IE indicates that the wireless device supports UP IP for an eUTRA connection established with the wireless device. In various embodiments, a bit setting of the UP IP support indication in the security capabilities IE may indicate whether the wireless device supports UP IP for an eUTRA connection established with the wireless device. For example, setting one of the EEA bit or EIA bit in the 4G S1 UE security capabilities IE or the 5G UE security capabilities IE to a value of “1” may indicate that the wireless device supports UP IP for eUTRA. In some embodiments, setting a bit in the 4G S1 UE security capabilities IE, such as setting one of the EEA bit or EIA bit in the 4G S1 UE security capabilities IE, may indicate that the wireless device supports both UP IP for an eUTRA connection established between the wireless device and the RAN and UP IP for an NR connection established between the wireless device and the RAN. In various embodiments, the UP IP support indication may be a bit setting in the security capabilities IE.

[0086]

[0099] At block 820, the network computing device may use the determined capabilities of the wireless device to support UP IP for eUTRA connections and / or UP IP for NR connections to establish a user plane connection with integrity protection by the wireless device.

[0087]

[0100] 9 shows a process flow diagram of an example method 900 for supporting UP IP for communication with a RAN, according to various embodiments. With reference to FIGS. 1A-9, method 900 may be implemented by a processor of a network computing device (e.g., base stations 110a-110e, 156, 162, 164, 176, 182, 350, 402, network controller 130, and / or other network entity). In various embodiments, the operations of method 900 may be implemented in conjunction with the operations of methods 500 (FIG. 5), 600 (FIG. 6), and / or 700 (FIG. 7).

[0088]

[0101] In blocks 816 and 818, the processor may perform the operations of like-numbered blocks of method 800 described with reference to FIG.

[0089]

[0102] At block 920, the processor may perform operations including determining whether the security capabilities IE indicates that the wireless device supports UP IP for an NR connection established with the wireless device. In some embodiments, the UP IP support indication may have a dual meaning, indicating that the wireless device both supports UP IP for eUTRA and supports UP IP for NR. In some embodiments, the security capabilities IE may include more than one UP IP support indication. For example, one UP IP support indication, such as a one bit setting, may indicate that the wireless device supports UP IP for an eUTRA connection, and another UP IP support indication, such as a different bit setting, may indicate that the wireless device supports UP IP for an NR connection.

[0090]

[0103] Various embodiments may be implemented on various wireless network devices, an example of which is shown in FIG. 10 in the form of a wireless network computing device 1000 that functions as a network element of a communications network, such as a base station (e.g., base stations 110a-110e, 156, 162, 164, 176, 182, 350, 402). Such a network computing device may include at least the components shown in FIG. 10. With reference to FIGS. 1A-10, network computing device 1000 may typically include a processor 1001 coupled to volatile memory 1002 and mass non-volatile memory, such as a disk drive 1003. Network computing device 1000 may also include a peripheral memory access device, such as a floppy disk drive, compact disk (CD), or digital video disk (DVD) drive 1006, coupled to processor 1001. The network computing device 1000 may also include a network access port 1004 (or interface) coupled to the processor 1001 for establishing a data connection with a network, such as the Internet and / or a local area network coupled to other system computers and servers. The network computing device 1000 may include one or more antennas 1007 for transmitting and receiving electromagnetic radiation, which may be connected to a wireless communications link. The network computing device 1000 may include additional access ports, such as USB, Firewire, Thunderbolt, etc., for coupling to peripherals, external memory, or other devices.

[0091]

[0104] Various embodiments may be implemented on various computing devices, such as wireless devices (e.g., wireless devices 120a-120e, 158, 200, 320, 402), an example of which is shown in FIG. 11 in the form of a smartphone 1100. With reference to FIGS. 1A-11 , the smartphone 1100 may include a first SOC 202 (e.g., a SOC-CPU) coupled to a second SOC 204 (e.g., a 5G-enabled SOC). The first and second SOCs 202, 204 may be coupled to internal memory 1106, 1116, a display 1112, and a speaker 1114. Additionally, the smartphone 1100 may include an antenna 1104 for transmitting and receiving electromagnetic radiation, which may be connected to a wireless data link, and / or a cellular telephone transceiver 266 coupled to one or more processors in the first and / or second SOCs 202, 204. Smartphone 1100 also typically includes menu selection buttons or rocker switches 1120 for receiving user input.

[0092]

[0105] The typical smartphone 1100 also includes a sound encoding / decoding (CODEC) circuit 1110 that digitizes sound received from the microphone into data packets suitable for wireless transmission and decodes the received sound data packets to generate analog signals that are provided to a speaker to generate sound. One or more of the processors in the first and second SOCs 202, 204, the wireless transceiver 1108, and the CODEC 1110 may also include digital signal processor (DSP) circuitry (not separately shown).

[0093]

[0106] The processors of the wireless network computing device 1000 and the smartphone 1100 may be any programmable microprocessor, microcomputer, or one or more multiple processor chips that can be configured by software instructions (applications) to perform various functions, including those of the various embodiments described below. In some mobile devices, multiple processors may be provided, such as one processor in the SOC 204 dedicated to wireless communication functions and one processor in the SOC 202 dedicated to running other applications. Typically, software applications may be stored in memory 1106, 1116 before being accessed and loaded into the processor. The processors may include sufficient internal memory to store application software instructions.

[0094]

[0107] As used herein, terms such as “component,” “module,” and “system” are intended to include, but are not limited to, computer-related entities, such as hardware, firmware, a combination of hardware and software, software, or software in execution, configured to perform particular operations or functions. For example, a component may be, but is not limited to, a process running on a processor, a processor, an object, an executable, a thread of execution, a program, and / or a computer. By way of example, both an application running on a wireless device and the wireless device may be referred to as a component. One or more components may reside within a process and / or thread of execution, and a component may be localized on one processor or core and / or distributed among two or more processors or cores. Furthermore, these components may execute from various non-transitory computer-readable media having various instructions and / or data structures stored thereon. Components may communicate via local and / or remote process, function or procedure calls, electronic signals, data packets, memory read / writes, and other known network-, computer-, processor-, and / or process-related communication methods.

[0095]

[0108] A number of different cellular and mobile communication services and standards may become available or are contemplated in the future, all of which may implement and benefit from various embodiments. Such services and standards include, for example, Third Generation Partnership Project (3GPP), Long Term Evolution (LTE) systems, third generation wireless mobile communication technologies (3G), fourth generation wireless mobile communication technologies (4G), fifth generation wireless mobile communication technologies (5G), Global System for Mobile Communications (GSM), Universal Mobile Telecommunications System (UMTS), 3GSM, General Packet Radio Service (GPRS), and Code Division Multiple Access (CDMA) systems (e.g., cdmaOn). e, CDMA1020™), Enhanced Data Rates for GSM Evolution (EDGE), Advanced Mobile Phone System (AMPS), Digital AMPS (IS-136 / TDMA), Evolution Data Optimized (EV-DO), Digital Enhanced Cordless Telecommunications (DECT), Worldwide Interoperability for Microwave Access (WiMAX), Wireless Local Area Network (WLAN), Wi-Fi Protected Access I and II (WPA, WPA2), and Integrated Digital Enhanced Network (iDEN). Each of these technologies involves, for example, the transmission and reception of voice, data, signaling, and / or content messages. It should be understood that any reference to terminology and / or technical details pertaining to a particular telecommunications standard or technology is for illustrative purposes only and is not intended to limit the scope of the claims to a particular communication system or technology unless expressly stated in the claim language.

[0096]

[0109] The various embodiments shown and described are provided merely as examples to illustrate various features of the claims. However, features shown and described with respect to any given embodiment are not necessarily limited to the associated embodiment and may be used or combined with other illustrated and described embodiments. Furthermore, the claims are not intended to be limited by any single exemplary embodiment. For example, one or more of the operations of methods 500, 600, 700, 800, and / or 900 may be replaced by or combined with one or more operations of methods 500, 600, 700, 800, and / or 900.

[0097]

[0110] The above method descriptions and process flow diagrams are provided merely as illustrative examples and do not require or imply that the operations of the various embodiments must be performed in the order presented. As will be appreciated by one of ordinary skill in the art, the order of operations in the above embodiments may be performed in any order. Words such as "then," "then," and "next" do not limit the order of operations; rather, these words are used to guide the reader through the method descriptions. Furthermore, references to claim elements in the singular, using, for example, the articles "a," "an," or "the," should not be construed as limiting the element to the singular.

[0098]

[0111] The various illustrative logical blocks, modules, components, circuits, and algorithmic operations described in connection with the embodiments disclosed herein may be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability between hardware and software, the various illustrative components, blocks, modules, circuits, and operations have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends on the particular application and design constraints imposed on the overall system. Those skilled in the art may implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the claims.

[0099]

[0112] The hardware used to implement the various example logic, logic blocks, modules, and circuits described in connection with the embodiments disclosed herein may be implemented or performed using general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general-purpose processor may be a microprocessor, but alternatively, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of receiver smart objects, e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in association with a DSP core, or any other such combination. Alternatively, some operations or methods may be performed by circuitry that is specific to a given function.

[0100]

[0113] In one or more embodiments, the functions described may be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functions may be stored as one or more instructions or code on a non-transitory computer-readable or processor-readable storage medium. The operations of a method or algorithm disclosed herein may be embodied in a processor-executable software module or processor-executable instructions, which may reside on a non-transitory computer-readable or processor-readable storage medium. A non-transitory computer-readable or processor-readable storage medium may be any storage medium that can be accessed by a computer or processor. By way of example and not limitation, such a non-transitory computer-readable or processor-readable storage medium may include RAM, ROM, EEPROM, flash memory, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage smart objects, or any other medium that can be used to store desired program code in the form of instructions or data structures and that can be accessed by a computer. As used herein, disk and disc include compact discs (CDs), laser discs, optical discs, digital versatile discs (DVDs), floppy disks, and Blu-ray discs, where disks typically reproduce data magnetically and discs reproduce data optically with a laser. Combinations of the above are also included within the scope of non-transitory computer-readable medium and non-transitory processor-readable medium. Furthermore, the operations of a method or algorithm may reside as one code and / or instruction, any combination of code and / or instructions, or set of code and / or instructions on a non-transitory processor-readable storage medium and / or a non-transitory computer-readable storage medium, which may be incorporated into a computer program product.

[0101]

[0114] The previous description of the disclosed embodiments is provided to enable any person skilled in the art to make or use the claims. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments without departing from the scope of the claims. Thus, the present disclosure is not intended to be limited to the embodiments shown herein but is to be accorded the widest scope consistent with the following claims and the principles and novel features disclosed herein.

Claims

1. 1. A method for supporting User Plane Integrity Protection (UP IP) for communication with a Radio Access Network (RAN), comprising: determining, by a processor of a wireless device, whether the wireless device supports UP IP for an evolved Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access (eUTRA) connection established between the wireless device and a RAN; generating, by the processor, a first security capabilities information element (IE) including a first UP IP support indication, wherein the first UP IP support indication indicates whether the wireless device supports UP IP for an eUTRA connection established between the wireless device and the RAN; transmitting, by the processor, the first security capabilities IE to a base station.

2. The method of claim 1 , wherein the first UP IP support indication is a bit setting in the first security capabilities IE.

3. 3. The method of claim 2, wherein the first security capabilities IE is an S1 user equipment (UE) security capability or a fifth generation (5G) UE security capability.

4. generating, by the processor, a second security capabilities IE including a second UP IP support indication, wherein the second UP IP support indication indicates whether the wireless device supports UP IP for an eUTRA connection established between the wireless device and the RAN or supports UP IP for a New Radio (NR) connection established between the wireless device and the RAN; The method of claim 2 , further comprising: transmitting, by the processor, the second security capabilities IE to the base station.

5. The method of claim 4 , wherein the second UP IP support indication is a bit setting in the second security capabilities IE.

6. 2. The method of claim 1, further comprising: determining, by the processor, whether the wireless device supports UP IP for a New Radio (NR) connection established between the wireless device and the RAN; and generating the first security capabilities IE including the first UP IP support indication comprises generating the first security capabilities IE including the first UP IP support indication and a second UP IP support indication, wherein the second UP IP support indication indicates whether the wireless device supports UP IP for the NR connection established between the wireless device and the RAN.

7. The method of claim 6 , wherein the second UP IP support indication is a different bit setting in the first security capabilities IE.

8. The method of claim 1 , wherein the RAN is connected to an Evolved Packet Core (EPC) network or a Next Generation Core (NGC) network.

9. The method of claim 8 , wherein the RAN is a fourth generation (4G) RAN or a 5G RAN.

10. The method of claim 1 , wherein the first UP IP support indication indicates support for UP IP with one or more algorithms.

11. determining whether a wireless device supports user plane integrity protection (UP IP) for an evolved Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access (eUTRA) connection established between the wireless device and a radio access network (RAN); generating a first security capabilities information element (IE) including a first UP IP support indication, wherein the first UP IP support indication indicates whether the wireless device supports UP IP for an eUTRA connection established between the wireless device and the RAN; transmitting the first security capabilities IE to a base station; 1. A wireless device comprising: a processor configured with processor-executable instructions to:

12. 12. The wireless device of claim 11, wherein the processor is further configured with processor-executable instructions to generate the first UP IP support indication as a bit setting in the first security capabilities IE.

13. 13. The wireless device of claim 12, wherein the processor is further configured with processor-executable instructions to generate the first security capabilities IE as a bit setting in one of S1 user equipment (UE) security capabilities or fifth generation (5G) UE security capabilities.

14. The processor: generating a second security capabilities IE including a second UP IP support indication, wherein the second UP IP support indication indicates whether the wireless device supports UP IP for an eUTRA connection established between the wireless device and the RAN or supports UP IP for a New Radio (NR) connection established between the wireless device and the RAN; 13. The wireless device of claim 12, further configured with processor-executable instructions for: transmitting the second security capabilities IE to the base station.

15. 15. The wireless device of claim 14, wherein the processor is further configured with processor-executable instructions to generate the second UP IP support indication as a bit setting in the second security capabilities IE.

16. The processor: determining whether the wireless device supports UP IP for a New Radio (NR) connection established between the wireless device and the RAN; generating the first security capabilities IE including the first UP IP support indication by generating the first security capabilities IE including the first UP IP support indication and a second UP IP support indication, wherein 13. The wireless device of claim 12, further configured with processor-executable instructions to: The IP support indication indicates whether the wireless device supports UP IP for an NR connection established between the wireless device and the RAN.

17. 17. The wireless device of claim 16, wherein the processor is further configured with processor-executable instructions to generate the second UP IP supported indication as another bit setting in the first security capabilities IE.

18. 13. The wireless device of claim 12, wherein the processor is further configured with processor-executable instructions to generate the first UP IP support indication to indicate support for UP IP using one or more algorithms.

19. 1. A method for supporting User Plane Integrity Protection (UP IP) for communication with a Radio Access Network (RAN), comprising: receiving, at a processor of a network computing device, a security capabilities information element (IE) of a wireless device, the security capabilities IE including a UP IP support indication; determining, at the processor, whether the security capabilities IE indicates that the wireless device supports UP IP for an evolved Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access (eUTRA) connection established with the wireless device based at least in part on the UP IP support indication; and using the determined capability of the wireless device to support UP IP for an eUTRA connection or UP IP for an NR connection to establish a user plane connection with integrity protection by the wireless device.

20. 20. The method of claim 19, wherein the UP IP support indication is a bit setting in the security capabilities IE.

21. 21. The method of claim 20, wherein the security capabilities IE is an S1 user equipment (UE) security capability or a fifth generation (5G) UE security capability.

22. 20. The method of claim 19, further comprising: determining, in the processor, whether the security capabilities IE indicates that the wireless device supports UP IP for a new radio (NR) connection established with the wireless device.

23. 23. The method of claim 22, wherein the UP IP support indication indicates whether the UP IP is supported for an NR connection.

24. 23. The method of claim 22, wherein the security capabilities IE includes a separate UP IP support indication indicating whether the UP IP is supported for an NR connection.

25. 25. The method of claim 24, wherein the different UP IP support indication is a different bit setting in the security capabilities IE.

26. 20. The method of claim 19, wherein the RAN is connected to an Evolved Packet Core (EPC) network or a Next Generation Core (NGC) network.

27. 27. The method of claim 26, wherein the RAN is a fourth generation (4G) RAN or a fifth generation (5G) RAN.

28. receiving a security capabilities information element (IE) of the wireless device, the security capabilities IE including a user plane integrity protection (UP IP) support indication; determining, based at least in part on the UP IP support indication, whether the security capabilities IE indicates that the wireless device supports UP IP for an evolved Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access (eUTRA) connection established with the wireless device; and using the determined capability of the wireless device to support UP IP for eUTRA connection or UP IP for NR connection to establish a user plane connection with integrity protection by the wireless device; 1. A network computing device comprising: a processor configured with processor-executable instructions to perform:

29. 29. The network computing device of claim 28, wherein the processor is further configured with processor-executable instructions to determine whether the security capabilities IE indicates that the wireless device supports UP IP for an evolved Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access (eUTRA) connection established with the wireless device based on a bit setting in the security capabilities IE indicating one of S1 user equipment (UE) security capabilities or fifth-generation (5G) UE security capabilities.

30. The processor:

30. The network computing device of claim 28, further configured with processor-executable instructions to determine whether the security capabilities IE indicates that the wireless device supports UP IP for a New Radio (NR) connection established with the wireless device.