Steering of roaming in wireless communication networks
Patent Information
- Application Number
- JP2025131577
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2018-04-13
- Filing Date
- 2025-08-06
- Publication Date
- 2026-01-08
AI Technical Summary
Existing wireless communication networks face challenges in efficiently directing user equipment (UE) to preferred public land mobile networks (PLMNs) due to issues such as unsecured data transmission, modification of SOR data by intermediate nodes, and inability to update persistent information in UICC, leading to prolonged registration in undesired networks and inefficient battery usage.
A method and system for secure packet delivery of SOR data using Extensible Authentication Protocol (EAP) in 5G networks, ensuring data integrity and updating UICC information, allowing UE to perform PLMN searches at optimal times and considering battery and mode constraints.
Enables timely and secure redirection of UE to preferred networks, optimizing battery life and ensuring compliance with operator preferences, while preventing data modification by intermediate nodes.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical Field]
[0001] (Priority Claim) This application claims priority to U.S. Provisional Patent Application No. 62 / 635,483, filed February 26, 2018, and U.S. Patent Application No. 15 / 952,846, filed April 13, 2018, the entire contents of which are hereby expressly incorporated by reference herein in their entireties.
[0002] (Technical field) TECHNICAL FIELD This disclosure relates to roaming in wireless communication networks. [Background technology]
[0003] (background) User equipment (UE) steering in a visited public land mobile network (VPLMN) is a procedure that allows a home public land mobile network (HPLMN) to update the UE's list of preferred PLMN / access technology combinations via non-access stratum (NAS) signaling. The HPLMN updates the list of preferred PLMN / access technology combinations, for example, depending on the public land mobile network (PLMN) where the UE is registered or when required by HPLMN operator policy. UE steering in a VPLMN is also known as roaming steering (SOR). SOR allows an HPLMN to steer a user equipment (UE) from one network to another. SOR is a technique by which a roaming UE is encouraged by the HPLMN to roam to a preferred destination network. For example, a UE is registered on one public land mobile network (PLMN), and for some reason, the UE's HPLMN wants the UE to register on another PLMN. Summary of the Invention [Means for solving the problem]
[0004] The present specification also provides, for example, the following items: (Item 1) 1. A method in a mobile equipment (ME), said method comprising: the ME sending a registration message to a visited public land mobile network (VPLMN); receiving, by the ME, a first message from a Home Public Land Mobile Network (HPLMN) through the VPLMN; the ME determining that the first message failed a security check; in response to determining that the first message failed the security check, the ME sends a second message to the VPLMN, the second message including an indication that the first message failed the security check; A method comprising: (Item 2) Item 2. The method of item 1, wherein the first message is a REGISTRATION ACCEPT message. (Item 3) Item 2. The method of item 1, wherein the second message is a REGISTRATION COMPLETE message. (Item 4) Item 1. The method of item 1, wherein the second message further includes at least one of an indication that the ME is in a manual network selection mode or an indication that the VPLMN is on a user-controlled PLMN list. (Item 5) Item 10. The method of item 1, further comprising the ME reading an indication from a Universal Integrated Circuit Card (UICC) that the ME expects to receive Solicitation of Roaming (SOR) data in the first message. (Item 6) Item 6. The method of item 5, wherein the SOR data includes a list of preferred PLMNs. (Item 7) Item 10. The method of item 1, further comprising the ME reading from a UICC an indication that the ME is expected to send a response to the first message. (Item 8) A mobile equipment (ME), the ME comprising: Memory and at least one hardware processor communicatively coupled to the memory; wherein the hardware processor comprises: sending a registration message to a visited public land mobile network (VPLMN); receiving a first message from a Home Public Land Mobile Network (HPLMN) through the VPLMN; determining that the first message failed a security check; in response to determining that the first message failed the security check, sending a second message to the VPLMN that includes an indication that the first message failed the security check; The ME is configured to: (Item 9) Item 9. The ME according to item 8, wherein the first message is a REGISTRATION ACCEPT message. (Item 10) 9. The ME according to item 8, wherein the second message is a REGISTRATION COMPLETE message. (Item 11) 9. The ME of claim 8, wherein the second message further includes at least one of an indication that the ME is in a manual network selection mode or an indication that the VPLMN is on a user-controlled PLMN list. (Item 12) Item 9. The ME of item 8, wherein the at least one hardware processor is further configured to read an indication from a Universal Integrated Circuit Card (UICC) that the ME expects to receive roaming guidance (SOR) data in the first message. (Item 13) Item 13. The ME of item 12, wherein the SOR data includes a list of preferred PLMNs. (Item 14) 9. The ME of claim 8, wherein the at least one hardware processor is further configured to read an indication from a UICC that the ME is expected to send a response to the first message. (Item 15) A non-transitory computer-readable medium containing instructions that, when executed, sending a registration message to a visited public land mobile network (VPLMN); receiving a first message from a Home Public Land Mobile Network (HPLMN) through the VPLMN; determining that the first message failed a security check; sending a second message to the VPLMN in response to determining that the first message failed the security check, the second message including an indication that the first message failed the security check; A non-transitory computer-readable medium that causes a mobile device (ME) to perform operations comprising: (Item 16) Item 16. The non-transitory computer-readable medium of item 15, wherein the first message is a REGISTRATION ACCEPT message. (Item 17) Item 16. The non-transitory computer-readable medium of item 15, wherein the second message is a REGISTRATION COMPLETE message. (Item 18) Item 16. The non-transitory computer-readable medium of item 15, wherein the second message further includes at least one of an indication that the ME is in a manual network selection mode or an indication that the VPLMN is on a user-controlled PLMN list. (Item 19) Item 16. The non-transitory computer-readable medium of item 15, wherein the operations further comprise the ME reading an indication from a Universal Integrated Circuit Card (UICC) that the ME expects to receive Solicitation of Roaming (SOR) data in the first message. (Item 20) 16. The non-transitory computer-readable medium of claim 15, wherein the operations further comprise the ME reading from a UICC an indication that the ME is expected to send a response to the first message. (Detailed explanation) The present disclosure relates to directed roaming (SOR) in wireless communication networks (i.e., directing a user equipment (UE) in a visited public land mobile network (VPLMN)). In some wireless networks, such as fifth-generation (5G) networks, a home operator (e.g., a home public land mobile network (HPLMN)) may direct a UE from one network to another. For example, a UE is registered with one public land mobile network (PLMN), and the UE's HPLMN may want to register the UE with another PLMN.
[0005] A UE may perform a PLMN search to find an alternative PLMN. For example, when the UE first powers up, the UE may perform an initial PLMN search. After the UE powers up, the UE may perform a PLMN search periodically. A periodic PLMN search, for example, allows the UE to find a PLMN that has a higher priority than the UE's current PLMN (the PLMN to which the UE is currently registered is also referred to as the UE's VPLMN or registered PLMN (RPLMN)). For example, if the UE is in a VPLMN (second network) that is not its HPLMN (first network), the UE may periodically search for the HPLMN. A periodic PLMN search may occur when a timer expires. An example of such a timer is a timer known as timer T. A PLMN search may occur only when the UE is in an IDLE mode, an IDLE state, a 5GMM-IDLE mode, or a CM-IDLE state, such as a state in which there is no active communication occurring with the network. If the UE performs PLMN search / selection in CONNECTED mode, the radio must disconnect from the current PLMN, thus losing any connectivity. Therefore, if timer T expires, the UE must wait until the UE is in IDLE mode to perform a PLMN search.
[0006] In some cases, such as in a fourth-generation (4G), third-generation (3G), or second-generation (2G) system, when a UE attaches to a VPLMN, the HPLMN sends a short message (SM) containing a secured packet (as defined in ETSI TS 102 225). This secured packet includes at least one PLMN identity. The SM is received by the UE's mobile equipment (ME), and based on the indications (e.g., code points) in the SM, the ME determines that some or all of the contents of the SM pertain to the UE's Universal Integrated Circuit Card (UICC). The UICC then receives the SM, unpacks the SM, and determines that the SM contains a secured packet. The secured packet's contents update the preferred operator PLMN list (e.g., the top entry) in the UICC, and the UICC sends a Universal Subscriber Identity Module (USIM) Application Toolkit (USAT) REFRESH command to the ME. Upon receiving the REFRESH command, the ME reads the preferred operator PLMN list from the UICC or from the REFRESH command if a PLMN list is included and stores the list in the ME's memory. The ME then performs a PLMN search taking into account the PLMNs in the updated preferred operator PLMN list. The updated preferred operator PLMN list may have changed as a result of the secured packet. One will appreciate that the preferred operator PLMN list is an entry in a USIM application that can only be modified by an entity (e.g., a home service provider, HPLMN) that has the necessary keys to allow the modification to be performed. However, it may be any application that provides functionality to the ME to indicate which network should be selected when the UE performs PLMN selection.
[0007] In some cases, such as in 5G networks, an authentication procedure (which is part of the registration procedure) may be used to convey a list of networks or PLMNs (or a list of preferred PLMN and access technology combinations) to the UE. FIG. 1 is a data flow diagram 100 illustrating an example process of using the authentication procedure to convey a list of preferred PLMN and access technology combinations. Data flow diagram 100 is from 3GPP CT1 contribution C1-180462, which is hereby incorporated by reference. Data flow diagram 100 includes a UE 102, a VPLMN Access and Mobility Management Function (AMF) node 104, a HPLMN Authentication Server Function (AUSF) node 106, and a HPLMN Centralized Data Management (UDM) node 108. The UE 102 may include an ME and a (removable) memory module. An example of a memory module is a UICC. The UICC may include a Subscriber Identity Module (SIM), a Universal SIM (USIM), or a Removable User Identity Module (R-UIM), collectively known as a UICC application. The ME and UICC may use the USAT command set defined in 3GPP TS 31.111 to exchange data and request each other to perform actions on behalf of other entities. The UE may also be known as a Mobile Station (MS). Nodes 104, 106, and 108 may be core network components. The AMF may include access and mobility management functions such as registration management, connection management, mobility management, and access authentication and authorization. The AUSF may provide UE authentication services. The UDM may have functionality similar to a Home Location Register (HLR) or Home Subscriber Server (HSS), such as generating 3GPP Authentication and Key Agreement (AKA) authentication credentials. In this disclosure, access technology refers to wireless access technology. [Brief explanation of the drawings]
[0008] DESCRIPTION OF THE DRAWINGS [Figure 1] FIG. 1 is a data flow diagram illustrating an exemplary process for using authentication procedures to communicate a list of preferred public land mobile network (PLMN) and access technology combinations.
[0009] [Figure 2] FIG. 2 is a data flow diagram illustrating an exemplary SOR procedure, according to some implementations of the present disclosure.
[0010] [Figure 3A] 3A-3B illustrate a data flow diagram of an exemplary registration procedure from 3GPP TS 23.502. [Figure 3B] 3A-3B illustrate a data flow diagram of an exemplary registration procedure from 3GPP TS 23.502.
[0011] [Figure 4A] 4A-4C illustrate example illustrations of including a device type indicator in a REGISTRATION REQUEST message according to some implementations of the present disclosure. [Figure 4B] 4A-4C illustrate example illustrations of including a device type indicator in a REGISTRATION REQUEST message according to some implementations of the present disclosure. [Figure 4C] 4A-4C illustrate example illustrations of including a device type indicator in a REGISTRATION REQUEST message according to some implementations of the present disclosure.
[0012] [Figure 5]FIG. 5 illustrates an example illustration of including a device type indicator in an Extensible Authentication Protocol (EAP) message, according to some implementations of the present disclosure.
[0013] [Figure 6] FIG. 6 is a data flow diagram illustrating an example procedure using EAP signaling to send SOR data, according to some implementations of the present disclosure.
[0014] [Figure 7] FIG. 7 is a data flow diagram illustrating an example process of using EAP signaling to obtain SOR data in a fifth generation (5G) network, according to some implementations of the present disclosure.
[0015] [Figure 8A] 8A-8E illustrate example illustrations of sending SOR data in EAP-Authentication and Key Agreement (AKA) according to some implementations of the present disclosure. [Figure 8B] 8A-8E illustrate example illustrations of sending SOR data in EAP-Authentication and Key Agreement (AKA) according to some implementations of the present disclosure. [Figure 8C] 8A-8E illustrate example illustrations of sending SOR data in EAP-Authentication and Key Agreement (AKA) according to some implementations of the present disclosure. [Figure 8D] 8A-8E illustrate example illustrations of sending SOR data in EAP-Authentication and Key Agreement (AKA) according to some implementations of the present disclosure. [Figure 8E]8A-8E illustrate example illustrations of sending SOR data in EAP-Authentication and Key Agreement (AKA) according to some implementations of the present disclosure.
[0016] [Figure 9] FIG. 9 illustrates an example illustration of a REFRESH command according to some implementations of the present disclosure.
[0017] [Figure 10] FIG. 10 illustrates an example illustration of an Environment File (EF) for the data “Operator Controlled PLMN Selector with Access Technology,” according to some implementations of the present disclosure.
[0018] [Figure 11] FIG. 11 is a data flow diagram illustrating an exemplary SOR procedure according to some implementations of the present disclosure.
[0019] [Figure 12A] 12A-12B illustrate an example illustration for the SOR procedure of FIG. 11, according to some implementations of the present disclosure. [Figure 12B] 12A-12B illustrate an example illustration for the SOR procedure of FIG. 11, according to some implementations of the present disclosure.
[0020] [Figure 13] FIG. 13 is a schematic diagram illustrating an example network node according to some implementations of the present disclosure.
[0021] [Figure 14] FIG. 14 is a schematic diagram illustrating an example UE device according to some implementations of the present disclosure.
[0022] [Figure 15A]15A-15F illustrate example illustrations of navigating a UE in a Visited PLMN (VPLMN) during and after registration, in accordance with some implementations of the present disclosure. [Figure 15B] 15A-15F illustrate example illustrations of navigating a UE in a Visited PLMN (VPLMN) during and after registration, in accordance with some implementations of the present disclosure. [Figure 15C] 15A-15F illustrate example illustrations of navigating a UE in a Visited PLMN (VPLMN) during and after registration, in accordance with some implementations of the present disclosure. [Figure 15D] 15A-15F illustrate example illustrations of navigating a UE in a Visited PLMN (VPLMN) during and after registration, in accordance with some implementations of the present disclosure. [Figure 15E] 15A-15F illustrate example illustrations of navigating a UE in a Visited PLMN (VPLMN) during and after registration, in accordance with some implementations of the present disclosure. [Figure 15F] 15A-15F illustrate example illustrations of navigating a UE in a Visited PLMN (VPLMN) during and after registration, in accordance with some implementations of the present disclosure.
[0023] Like reference numbers and designations in the various drawings indicate like elements. DETAILED DESCRIPTION OF THE INVENTION
[0024] In FIG. 1 , during steps 5-7 of the authentication procedure, the HPLMN UDM 108 may send SOR data (e.g., a list of preferred PLMNs, a list of preferred PLMN and access technology combinations, or an HPLMN protection list of preferred PLMN / access technology combinations) to the UE 102. For example, if the HPLMN wants the UE to register with a different PLMN (a third network), the HPLMN UDM 108 may send the SOR data. However, after the UE 102 receives the SOR data, the UE cannot perform a PLMN search because it is in connected mode during the authentication phase (as discussed above, a PLMN search is performed when the UE is in IDLE mode). In some cases, timer T is not set until the UE completes the registration procedure. That is, timer T starts upon completion of the registration procedure, and the UE does not perform a PLMN search until timer T expires. As a result, the UE 102 may be registered with an unpreferred PLMN for a significant period of time. However, it is in the operator's interest to direct the UE to a different PLMN at the earliest convenient time (requiring the UE to perform a PLMN search), for example, before an attach or registration attempt has been successfully completed. Furthermore, if the UE is not attached or registered to the network, it cannot receive SMs, and therefore a UE in the authentication phase cannot receive secured packets containing SOR data using existing procedures in 2G, 3G, or 4G systems.
[0025] In addition to the UE being in an undesired PLMN for a long time, the SOR data delivery in FIG. 1 also has the following problems. First, in steps 5-7, the SOR data is sent to the UE 102 in clear text. As a result, the SOR data may be modified by the VPLMN node 104. Second, authentication procedures in 5G networks use the Extensible Authentication Protocol (EAP). In some cases, data in the first EAP packet may be modified and even removed by the VPLMN node 104, and the receiving UE 102 and the sending HPLMN node 108 are unaware that this has occurred. Third, persistent information in the USIM or UICC may not be updated, causing the HPLMN to repeatedly send the SOR data if possible. The UICC or USIM (e.g., a memory module) contains persistent data or information. Persistent data refers to data stored in memory that is not accessed or even erased or deleted, for example, upon reboot of the device or a module within the device. For example, the ME reads, e.g., "Operator Controlled PLMN Selector with Access Technology" data or other data from the USIM or UICC, such as after the ME is powered up or turned on. The ME may read the data at other times, such as upon receipt of a REFRESH command. The ME may modify the "Operator Controlled PLMN Selector with Access Technology" data based on the received SOR data, and modifications made by the ME should be synchronized to the USIM or UICC so that the persistent data is updated and updated information is available, e.g., after a reboot, power-up, or start-up. However, write access to some UICC or USIM data, including the "Operator Controlled PLMN Selector with Access Technology," is protected as previously described.Only the HPLMN operator has the credentials for write access to this data; neither the VPLMN nor the ME has these credentials. This means that after receiving the SOR data, the ME in the UE 102 cannot update the persistent data in the UICC or USIM, which may cause the HPLMN to send the SOR data repeatedly.
[0026] In some cases, the UE may be in a manual network selection mode. In the manual network selection mode, the UE selects a PLMN without necessarily considering the HPLMN's preferences. In the automatic network selection mode, the UE considers the HPLMN's preferences when selecting a PLMN. In the manual network selection mode, the device selects a VPLMN or network according to the UE's preferences, so SOR may not occur. Another reason the UE selects a network or VPLMN is because the VPLMN is included in the "User Controlled PLMN Selector with Access Technology" list. For example, the UE finds a network on the "User Controlled PLMN Selector with Access Technology" list. The user / application adds a PLMN entry(ies) to the "User Controlled PLMN Selector with Access Technology" list and similarly performs manual network selection (i.e., the UE is selecting a network for a specific reason). Therefore, if the UE selects a VPLMN and network in the "User Controlled PLMN Selector with Access Technology," SOR does not occur.
[0027] In some cases, the UE may be battery-constrained (or resource-constrained). Because PLMN searching (e.g., a network discovery process) consumes battery power and there is no guarantee that alternative networks will be available, it may be desirable for the SOR operation to take into account whether the UE is battery-constrained in order to extend battery life. In some cases, the UE may be mobility-constrained, such as a fixed UE, and it may be desirable not to perform SOR because the PLMNs available to the UE are not likely to change.
[0028] The SOR procedure according to the methods and systems described herein allows an operator to direct a UE to a different PLMN at the earliest convenient time, for example, before an attachment or registration attempt is successfully completed. The described approach uses secured packets to deliver SOR data so that intermediate nodes along the path cannot modify the SOR data. The described approach may also update persistent information in the UICC based on the SOR data. The described method also informs the PLMN whether the UE is prevented from moving based on the SOR information due to automatic network selection mode, a user-controlled PLMN selector list, or manual network selection mode. Another reason a UE may be prevented from selecting a different PLMN is because the currently registered PLMN remains the highest-priority PLMN. Finally, the secured packet may fail an integrity check on the UICC. In either of these cases, the ME may be required to transmit a second secured packet to the network via the USAT by the memory module. The second secured packet may indicate to the network the reason the UE cannot select another PLMN or the integrity check failure. In some cases, a security check may comprise an integrity check. In this disclosure, the terms "security check" and "integrity check" are interchangeable. A security check may also determine by the ME or UICC that one to many information elements, indicators, SOR data, or secure packets are received in a received message that should be present (expected) in the received message. The determination may be based on configuration in the ME and / or UICC.
[0029] 5G terminology used in this disclosure is explained below.
[0030] 5G System Mobility Management (5GMM)-IDLE mode: This term is used independently. A UE in 5GMM-IDLE mode means that the UE can either be in 5GMM-IDLE mode on a 3GPP access or in 5GMM-IDLE mode on a non-3GPP access.
[0031] 5GMM-CONNECTED mode: This term is used independently. A UE in 5GMM-CONNECTED mode means that the UE can either be in 5GMM-CONNECTED mode on a 3GPP access or in 5GMM-CONNECTED mode on a non-3GPP access.
[0032] 5GMM-IDLE mode over 3GPP access: A UE is in 5GMM-IDLE mode over 3GPP access when there is no N1 Non-Access Stratum (NAS) signaling connection between the UE and the network over the 3GPP access. The term 5GMM-IDLE mode over 3GPP access as used in this disclosure corresponds to the term Connection Management IDLE (CM-IDLE) state for 3GPP access as used in 3GPP TS 23.501.
[0033] 5GMM-CONNECTED mode over 3GPP access: A UE is in 5GMM-CONNECTED mode over 3GPP access when there is an N1 NAS signaling connection between the UE and the network over the 3GPP access. The term 5GMM-CONNECTED mode over 3GPP access as used in this document corresponds to the term CM-CONNECTED state for 3GPP access as used in 3GPP TS 23.501.
[0034] 5GMM-IDLE mode over non-3GPP access: When there is no N1 NAS signaling connection between the UE and the network over the non-3GPP access, the UE is in 5GMM-IDLE mode over the non-3GPP access. The term 5GMM-IDLE mode over non-3GPP access as used in this disclosure corresponds to the term CM-IDLE state for non-3GPP access as used in 3GPP TS 23.501.
[0035] 5GMM-CONNECTED mode over non-3GPP access: A UE is in 5GMM-CONNECTED mode over non-3GPP access when it has an N1 NAS signaling connection between the UE and the network over non-3GPP access. The term 5GMM-CONNECTED mode over non-3GPP access as used in this disclosure corresponds to the term CM-CONNECTED state for non-3GPP access as used in 3GPP TS 23.501.
[0036] Access Stratum Connection: A peer-to-peer access stratum connection either between a UE and a Next Generation Radio Access Network (NG-RAN) for 3GPP access or between a UE and an N31WF for non-3GPP access. An access stratum connection for 3GPP access corresponds to a Radio Resource Control (RRC) connection over the Uu reference point. The creation of an access stratum connection for non-3GPP access corresponds to the completion of an IKE_SA_INIT transformation (see IETF RFC 7296) over the NWu reference point.
[0037] N1 NAS signaling connection: A peer-to-peer N1 mode connection between the UE and the AMF. The N1 NAS signaling connection is either a chain of an RRC connection via the Uu reference point and an NG connection via the N2 reference point for 3GPP access, or a chain of an IPsec tunnel via the NWu reference point and an NG connection via the N2 reference point for non-3GPP access.
[0038] The 5G PLMN discovery procedure is described as follows:
[0039] The PLMN search procedure for 5G is substantially identical to the PLMN search procedure for a PLMN using an EPC or GPRS core network. As discussed above, a PLMN search occurs initially, and a PLMN search also occurs periodically. A periodically occurring PLMN search occurs when a timer (e.g., Timer T discussed above) expires. A periodically occurring PLMN search searches for higher priority PLMNs.
[0040] For example, 3GPP TS 23.122 provides the following description of the PLMN search procedure: When the MS is in a VPLMN, it periodically attempts to acquire service in its HPLMN (if the EHPLMN list does not exist or is empty), or one of its EHPLMNs (if an EHPLMN list exists), or in a higher priority PLMN / access technology combination listed in the "User-Controlled PLMN Selector" or "Operator-Controlled PLMN Selector," by scanning according to the requirements that apply in i), ii), and iii) below. If the mobile has a stored "equivalent PLMN" list, the mobile only selects a PLMN if the PLMN is of higher priority than the current serving PLMN stored in the "equivalent PLMN" list and is of the same country. For this purpose, the value of timer T may be stored in the SIM. The interpretation of the stored value depends on the radio capacity supported by the MS. The MS selects and attempts registration in other PLMN / access technology combinations, if available and admissible, in the following order: i) either the HPLMN (if the EHPLMN list does not exist or is empty) or the highest priority EHPLMN available (if an EHPLMN list exists); ii) each PLMN / access technology combination in the "User Controlled PLMN Selector with Access Technology" data file in the SIM (in order of preference); iii) each PLMN / access technology combination in the "Operator Controlled PLMN Selector with Access Technology" data file in the SIM (in order of preference).
[0041] In addition to using the "Operator Controlled PLMN Selector" list, the device or UE may also use a "User Controlled PLMN Selector with Access Technology" list. When performing a PLMN search, if the device finds a PLMN that is in the "User Controlled PLMN Selector with Access Technology", the device will choose this PLMN (which has a higher priority) over any PLMN in the "Operator Controlled PLMN Selector".
[0042] In a general description of elements, a UE may be referred to as a mobile electronic device, user device, mobile station, subscriber station, portable electronic device, mobile communication device, wireless modem, wireless terminal, mobile equipment, Session Initiation Protocol (SIP) user agent, set-top box, test equipment, or embedded modem. Examples of UEs may include mobile phones, personal data assistants (PDAs), smartphones, laptops, tablet personal computers (PCs), pagers, portable computers, portable gaming devices, wearable electronic devices, or other mobile communication devices having components for communicating data over a wireless communication network. The wireless communication network may include wireless links across at least one of a licensed tier and an unlicensed tier.
[0043] Other examples of UE include mobile electronic devices and fixed electronic devices. A UE may include an ME device and a removable memory module, such as a UICC, that contains a SIM application, a USIM application, or an R-UIM application (all of which are known as UICC applications). The term "UE" may also refer to any hardware or software component that can terminate a communication session for a user. In addition, the terms "user equipment," "UE," "user equipment device," "user agent," "UA," "user device," and "mobile device" may be used interchangeably herein. A UICC may also be a secure element that contains UICC applications that perform similar functionality.
[0044] Wireless communication networks consist of Radio Access Networks (RANs), fixed Ethernet networks, TM or other access networks such as IEEE 802.11 WLAN, a core network (CN), and external networks. The RAN may comprise one or more radio access technologies. The radio access technologies may be 3GPP access technologies or non-3GPP access technologies. In some implementations, the radio access technologies may be Global System for Mobile communications (GSM) TM), Interim Standard 95 (IS-95), Universal Mobile Telecommunications System (UMTS), CDMA2000 (Code Division Multiple Access), Evolved Universal Mobile Telecommunications System (UMTS), Long Term Evolution (LTE), LTE-Advanced, or 5G access technology. In some examples, the core network may be an Evolved Packet Core (EPC) or 5G Core. The core network may include an AMF, a Session Management Function (SMF), a UDM, an Authentication, Authorization, and Accounting (AAA) server, or other network nodes or entities.
[0045] 2 is a data flow diagram 200 illustrating an example SOR procedure according to some implementations of the present disclosure. The data flow diagram 200 includes a UE having a UICC 202 and an ME 204, a first network node 206, a second network node 208, and a third network node 210. The first network node 206 may be an AMF or SMF node, such as a PLMN a, of a first VPLMN (second network). The second network node 208 may be an AMF or SMF node, such as a PLMN b, of a second VPLMN (third network). The third network node 210 may be a UDM node of a HPLMN (first network).
[0046] In step 1, the ME 204 sends a message to the first network node 206 to begin a registration / attach procedure with the PLMNa. For example, the ME 204 sends a REGISTRATION REQUEST message to the first network node 206. In some cases, an N1 NAS signaling connection between the ME 204 and the first network node 206 may carry the REGISTRATION REQUEST message. The UE may use a 3GPP access technology or a non-3GPP access technology. The N1 NAS signaling connection may be over a 3GPP access or a non-3GPP access. For example, the UE may be in 5GMM-CONNECTED mode over a 3GPP access, and an N1 NAS signaling connection over 3GPP exists between the UE and the first network node 206.
[0047] In step 1a, the first network node 206 forwards the message in step 1 (e.g., REGISTRATION REQUEST) to the third network node 210 within the HPLMN. The first network node 206 may forward the message to the third network node 210 without passing through the second network node 208. In some cases, as discussed in FIGS. 3A-5, the messages in steps 1 and 1a may include an indication of the device type (e.g., battery-constrained or mobility-constrained) and operating mode (e.g., manual network selection mode). This indication may help the third network node 210 within the HPLMN determine whether to send SOR data to the UE. For example, if the UE is battery-constrained, mobility-constrained, or in manual network selection mode, a node within the HPLMN (e.g., the third network node) may not send SOR data to the UE.
[0048] In step 2, the third network node 210 sends a secured packet to the first network node 206. The secured packet may include SOR data. In step 3, as discussed in FIGS. 6-8E, the first network node 206 sends the secured packet received in step 2 to the ME 204. That is, the secured packet is received during the registration / attach procedure. In some cases, in step 3, the secured packet is received within a DL NAS TRANSPORT message. In some other implementations, step 3 may be a REGISTRATION ACCEPT message or an ATTACH ACCEPT message including the SOR data or the secured packet. In some cases, EAP is used for an authentication procedure in the registration procedure (e.g., 5G networks use EAP for authentication), and the secured packet may be received within an EAP message. In some cases, the secured packet may be a packet within an SM, and thus a "secured packet" may be exchanged for an "SM including a secured packet."
[0049] In step 4, the ME 204 determines, by an indication (e.g., a code point) in the message received in step 3, that the content pertains to a UICC, and the ME 204 sends the secured packet to the UICC 202. The UICC 202 decodes the secured packet and extracts the SOR data. In some cases, during steps 2-4, the secured packet is encoded by the third network node 210 in the HPLMN and decoded by the UICC 202, while intermediate entities such as the first network node 206 and the ME 204 do not decode the secured packet. Based on the SOR data, the UICC 202 can make a decision on whether to trigger a PLMN search.
[0050] In step 5, the ME 204 receives an indication from the UICC 202. The indication may indicate to the ME 204 to terminate the ongoing registration / attachment procedure and trigger a PLMN search. In some cases, the indication from the UICC 202 may be received via a USAT command. The USAT command may be a REFRESH command. The REFRESH command may include an indication that a SOR procedure should be initiated. In some cases, as discussed in FIG. 9, the REFRESH command in step 5 may optionally include a list of preferred PLMNs so that the ME 204 may perform a PLMN search based on the list. In some cases, the REFRESH command does not include a list of preferred PLMNs, and the REFRESH command triggers the ME 204 to download an environment file from the UICC 202 that includes the list of preferred PLMNs. The ME 204 then performs a PLMN search based on the downloaded list.
[0051] In step 6, based on the indication in step 5, the ME 204 may terminate the registration / attach procedure with the PLMNa. In some cases, to terminate the registration / attach procedure, the ME 204 may release the N1 NAS signaling connection between the ME 204 and the first network node 206. In some cases, terminating the registration / attach procedure includes the ME 204 sending an authentication failure message or a REGISTRATION COMPLETE message to the first network node 206. The authentication failure message or the REGISTRATION COMPLETE message may include an indicator and may indicate either unsuccessful reception of the secured packet (e.g., that the secured packet failed an integrity check, as discussed below), successful reception of the secured packet, or that the ME will not perform a PLMN search due to discretionary authority. The indicator indicating failure may prevent the network (e.g., the PLMNa) from retransmitting messages related to the registration procedure. The indication of failure may be further authorized to indicate the actual reason, examples of which include, but are not limited to, PLMN search, PLMN is temporarily not authorized, etc. When the indicator indicates successful reception, the indicator identifies to the network that the secured packet was successfully received, and the ME performs PLMN search. When the indicator indicates that the ME will not perform PLMN search, the indicator may be authorized to indicate the reason, such as the ME is in manual network selection mode, the VPLMN (RPLMN) is on the user-controlled PLMN list, there are no other available PLMNs, the PLMN is temporarily not authorized, etc.
[0052] In step 7, the ME 204 may begin a PLMN search to find an alternative network (e.g., PLMNb) to attach or register to. In step 8, the ME 204 begins the registration / attach procedure with PLMNb.
[0053] In some cases, after ME 204 receives the USAT command in step 5, if the ME selects the network (RPLMN) because the ME is a device type, such as, but not limited to, battery-constrained, resource-constrained, or mobility-constrained, or because the network was on the user-controlled PLMN list (i.e., the network is the user's preferred PLMN), ME 204 does not perform a PLMN search until either when periodic PLMN search timer T expires or when ME 204 performs a PLMN search for other reasons. In some cases, if the UE is in manual network selection mode when ME 204 receives the USAT command in step 5, or if the ME selected the network (RPLMN) because the network was on the user-controlled PLMN list, the UE refrains from performing a PLMN search. The user-controlled PLMN list is also referred to as a "User Controlled PLMN Selector with Access Technology list." In some cases, the ME 204 may inform the network (e.g., a node of the HPLMN (e.g., a third network or a node of the third network)) that the ME 204 is in manual network selection mode or that the ME selected a network (RPLMN) because the network is on the user-controlled PLMN list and the node of the HPLMN (third network node) did not send SOR data.
[0054] In some cases, the indication received from UICC 202 in step 5 indicates that the secured packet failed an integrity check at the UICC. The indication that the secured packet failed an integrity check causes ME 204 to remove the PLMN (e.g., PLMNa) that the UE is attempting to register to from the "Operator Controlled PLMN Selector with Access Technology" list stored within ME 204, and optionally, to add the PLMN to a forbidden PLMN list (e.g., EF FPLMNThe PLMN search may include a PLMNa in (forbidden PLMN). In some cases, if the current registration / attach procedure with the PLMNa is for emergency services, the UE starts a PLMN search after the need for emergency services no longer exists. In some implementations, in step 6, the ME may send a message to the network, such as a REGISTRATER COMPLETE message or an ATTACH COMPLETE message, containing an indication that the secured packet failed the integrity check / security check, that the VPLMN is on the user-controlled PLMN list, or that the ME is in manual network selection mode. Sending the message may depend on the ME being configured to respond (e.g., the ME is configured to respond to the REGISTRATION ACCEPT / ATTACH ACCEPT message in step 3). This configuration may be stored in an Open Mobile Alliance (OMA) Device Management (DM) file in the ME, read from the UICC and then stored in the ME, or received in the REGISTRATION ACCEPT / ATTACH ACCEPT message in step 3. In some cases, the ME is configured to expect to receive the SOR data in the REGISTRATION ACCEPT / ATTACH ACCEPT message in step 3, for example as an indication in the REGISTRATION ACCEPT / ATTACH ACCEPT message in step 3, or as an indication in the SOR data or secured packet that was in the REGISTRATION ACCEPT / ATTACH ACCEPT message in step 3. This configuration may be stored in an OMA DM file in the ME, or may be read from the UICC and then stored in the ME.
[0055] In some cases, when the UE is in manual network selection mode, the following procedure may be performed. 1. The ME begins the registration / attachment procedure with the VPLMN. 2. The ME receives a first secured packet containing SOR data, for example from a UDM in the HPLMN. 3. The UE determines that the UE is in manual network selection mode. 4. The ME sends a first secured packet to the UICC with an indication that the UE is in manual network selection mode. 5. The ME receives a second secured packet from the UICC, the second secured packet including an indication that the ME is in a manual network selection mode. 6. The ME may optionally send a second secured packet (e.g., HPLMN) to the network and optionally include an indication that the ME is in manual network selection mode so that the HPLMN does not send SOR data. In some cases, the ME may continue its current registration / attachment procedure with the VPLMN.
[0056] In some cases, if the UE is in manual network selection mode or if the UE selected a PLMN that was on the user-controlled PLMN list, the following procedure may be performed. 1. The ME begins the registration / attachment procedure with the VPLMN. 2. The ME receives a secured packet containing SOR data, for example from a UDM in the HPLMN. For example, the secured packet may be received using EAP, as shown in Figures 6-8E. 3. The ME sends the secured packet to the UICC. 4. The ME receives an indication from the UICC to perform a PLMN search. For example, a USAT REFRESH command from the UICC may include an indicator to perform a PLMN search. 5. Because the ME is in manual network selection mode or the UE selected a PLMN that was on the user-controlled PLMN list, the ME decides not to perform a PLMN search and continues the registration / attach procedure with the current VPLMN. For example, the ME may send an EAP-Response message to the network, where the EAP message, e.g., EAP-Response, may include an indication of why the ME is continuing the PLMN search, e.g., that it is in manual network selection mode or that the UE used a user-controlled PLMN list.
[0057] In this disclosure, the techniques described for when the UE is in manual network selection mode are also applicable when the ME selects a network (PLMN) in the "User Controlled PLMN Selector with Access Technology" list.
[0058] As discussed above, in step 1 of Figure 2, the ME may indicate its device type (e.g., battery-constrained device, mobility-constrained device, and in manual network selection mode). Figures 4A-5 illustrate two methods for indicating the device type. Figures 3A-3B illustrate a data flow diagram 300 of an example registration procedure from 3GPP TS 23.502. Figures 4A-4C illustrate the REGISTRATION While FIG. 5 illustrates including a device type indicator in a REQUEST message (e.g., step 1 of FIG. 3A), FIG. 5 illustrates including a device type indicator in an EAP message (i.e., step 9 of FIG. 3A).
[0059] 4A-4C illustrate an example illustration of including a device type indicator in a REGISTRATION REQUEST message according to some implementations of the present disclosure. For example, the registration initiation procedure described in 3GPP TS 24.501 may be modified to include the underlined text shown in FIGS. 4A-4C. Table 8.2.5.1.1 in FIG. 4B and Table 9.8.2.2.1 in FIG. 4C illustrate that a REGISTRATION REQUEST message may include a new information element, “Device Type,” to indicate whether the UE is a battery- or resource-constrained device, a mobility-constrained device, and / or in manual network selection mode. In some implementations, the setting of the battery-constrained indicator may change when the device is connected to a power source, such that the ME may send a mobility management message including the device type. Those skilled in the art will recognize that message names, code point names, etc., are used in this disclosure for illustrative purposes and that other message names and code point names may be used. For example, the indicator may be sent using a new information element or by extending an existing information element. In this disclosure, occurrences of "shall" may be "may" or "should."
[0060] Figure 5 illustrates an example illustration of including a device type indicator in an EAP message according to some implementations of the present disclosure. For example, 3GPP TS 24.302 may be modified to include the underlined text shown in Figure 5. Table 8.2.X.1-1 in Figure 5 indicates that the EAP-Response / AKA'-Challenge message may include an AT_SORInfo_REQUEST attribute that includes a device type indicator.
[0061] As discussed above, in steps 2-3 of Figure 2, the HPLMN (e.g., UDM) may send a secure packet containing SOR data to the UE. Figures 6-8E illustrate methods for sending SOR data.
[0062] 6 is a data flow diagram 600 illustrating an example procedure using EAP signaling to send SOR data according to some implementations of the present disclosure. The data flow diagram 600 includes a UE 602, an AAA server 604 in a VPLMN, and a database or UDM 606 in an HPLMN. The AAA server 604 may also be replaced with an AMF and / or UDM. In step 4, the AAA server 604 in the VPLMN sends an authentication challenge to the UE 602. The authentication challenge may include an AT_SORInfo_REQUEST_SUPPORTED attribute (described in section 8.2.X.1 of FIG. 8C ) indicating that the AAA server 604 supports the UE 602 requesting SOR data. In step 5, in response to receiving an indication that the AAA server 604 supports the UE 602 requesting SOR data, the UE 602 sends an authentication response to the AAA server 604, and optionally, if the UE is battery-constrained or operating in a manual network selection mode, the authentication response includes an AT_SORInfo_REQUEST attribute (described in section 8.2.X.2 of FIG. 8E) indicating that the UE 602 requests SOR data. In step 6, the AAA server 604 forwards the authentication response to the database 606 in the HPLMN. The authentication response in step 6 also includes an AT_SORInfo_REQUEST attribute indicating that the UE 602 requests SOR data. The UDM / HSS / HLR take into account the UE's operating mode and whether the UE is battery-constrained. In step 7, in response to receiving an indicator that UE 602 requests SOR data, database 606 in HPLMN sends an authentication acknowledgment to AAA server 604, where the authentication acknowledgment includes an AT_SORInfo_RESP attribute (described in section 8.2.X.3 of Figures 8D-8E) that contains the SOR data. In step 8, AAA server 604 forwards the authentication acknowledgment to UE 602. The authentication acknowledgment in step 8 also includes an AT_SORInfo_RESP attribute that contains the SOR data.
[0063] FIG. 7 is a data flow diagram 700 illustrating an example process using EAP signaling to obtain SOR data in a 5G network according to some implementations of the present disclosure. The example process is also applicable to other EAP framework methods, such as EAP methods used to access wireless local area networks (WLANs), and the names of the functions may differ. The data flow diagram 700 includes a UE 702, a Security Anchor Functionality (SEAF) or AMF node 704 in a VPLMN, an Authentication Server Function (AUSF) node 706 in a HPLMN, and a UDM / Authentication credential Repository and Processing Function (ARPF) node 708 in the HPLMN. Similar to FIG. 6, in step 4 of FIG. 7, the EAP-Request / AKA'-Challenge may include an AT_SORInfo_REQUEST_SUPPORTED attribute indicating that the SEAF / AMF 704 supports the UE 702 requesting SOR data. In steps 5 and 6 of Figure 7, the EAP-Response / AKA'-Challenge may include an AT_SORInfo_REQUEST attribute indicating that the UE 702 requests SOR data. The messages in steps 7 and 8 of Figure 7 may include an AT_SORInfo_RESP attribute containing the SOR data. In some cases, the decision to send an indication that SOR is supported in steps 2 and / or 3 is based on the network and / or location where the UE requested to register. In some cases, the data sent in step 7 may be sent in step 3.
[0064] 8A-8E illustrate example illustrations of sending SOR data within EAP-AKA' according to some implementations of the present disclosure. For example, 3GPP TS 24.302 may be modified to include the underlined text shown in FIGS. 8A-8E.
[0065] In some cases, the ME may receive a USAT REFRESH command from the UICC in step 5 of Figure 2. The REFRESH command may optionally include a list of PLMNs for 5G access technologies (e.g., NG or E-UTRAN connected to a 5G core network) or a PLMN with Access Technology (PLMNwAct) list that includes an access technology selector that includes the radio access technology (RAT) used to determine whether to perform a 5G SOR procedure or direct the UE from one VPLMN to another VPLMN.
[0066] Figure 9 illustrates an example description of the REFRESH command according to some implementations of the present disclosure. For example, 3GPP TS 31.111 may be amended to include the underlined sentences shown in Figure 9 so that the REFRESH command includes two new parameters: "(5G) PLMN List" and "(5G) PLMNwAcT List." In some cases, the PLMN list and PLMNwAcT list may define preferred PLMNs in a prioritized order. The ME may obtain the PLMN list or PLMNwAcT list from the REFRESH command and perform a PLMN search based on the list (e.g., starting with the higher priority PLMNs).
[0067] 10 illustrates an example description of an environment file (EF) for the data "Operator Controlled PLMN Selector with Access Technology" according to some implementations of the present disclosure. For example, 3GPP TS 31.102 may be modified as shown in FIG. 10 to illustrate three different embodiments: a 5G system supported by new radio (NR) access (5GS), a 5G system supported by E-UTRA (5GS), or an EPS (EPC supported by E-UTRA). In some cases, the EF file EF OPLMNwACTis on the UICC and contains preferred PLMNs in order of preference. The REFRESH command causes the ME to refresh the EF in its memory so that the ME can perform a PLMN search based on the preferred PLMNs (e.g., starting with the highest priority PLMN). OPLMNwACT may be triggered to download.
[0068] In some cases, the 5G SOR procedure or the steering of a UE from one VPLMN to another VPLMN may involve terminating an ongoing registration procedure with at least one of a REGISTRATION COMPLETE message, an authentication failure message, or releasing the N1 NAS signaling connection.
[0069] In some cases, when a UE (or ME, UE and ME are interchangeable in this disclosure) terminates an ongoing registration procedure, the UE continues to operate as if the UE had been switched on or the UE had recovered from a lack of coverage, and the UE selects the highest priority PLMN that is available. Alternatively, when a UE terminates an ongoing registration procedure, the UE selects the highest priority PLMN (if available) using all access technologies with which the UE previously discovered the previous highest priority PLMN. If the UE fails to discover a higher priority PLMN than the previous highest priority PLMN, the UE discovers the higher priority PLMN as needed using all available access technologies.
[0070] Alternatively, if the UE is battery constrained or the network was selected either because the UE is operating in manual network selection mode or the UE selected a PLMN from a user-controlled PLMN list, when the ME performs a PLMN search, for example because the periodic search timer T has expired, the ME may ignore the REFRESH command but may use the updated Preferred Operator PLMN list loaded into its memory. The ME continues to operate as if it had been switched on or had lost PLMN coverage.
[0071] Figure 11 is a data flow diagram 1100 illustrating an example SOR procedure according to some implementations of the present disclosure. Data flow diagram 1100 modifies the procedure in Figure 1 based on techniques described in this disclosure. Figures 12A-12B illustrate an example explanation for the SOR procedure of Figure 11 according to some implementations of the present disclosure. Figures 12A-12B show modifications to 3GPP CT1 contribution C1-180462.
[0072] 15A-15F illustrate example illustrations of guiding a UE in a VPLMN during and after registration in accordance with some implementations of the present disclosure. The example illustrations in FIGS. 15A-15F may be included in 3GPP TS 23.122. Message 6 (i.e., REGISTRATION ACCEPT) in Diagram C.1.1 of FIGS. 15A-15B may be in step 3 of FIG. 2. Message 10 (i.e., REGISTRATION COMPLETE) in Diagram C.1.1 of FIGS. 15A-15B may be in step 6 of FIG. 2.
[0073] In some cases, if the SOR data (e.g., a secured packet containing a protected HPLMN list of preferred PLMN / access technology combinations) is successfully received (e.g., a successful security check), and if the VPLMN with which the ME is currently attempting to register is not the user's preferred PLMN and the ME is not in manual selection mode, the ME may terminate the current registration procedure and perform a PLMN search based on the SOR data, for example, after completion of the REGISTRATION / ATTACH procedure (step 10) or before any of steps 7-9. In some cases, if the SOR data is successfully received and the VPLMN with which the ME is currently attempting to register is the user's preferred PLMN or the ME is in manual selection mode, the ME may continue the current registration procedure and not perform a PLMN search. In some cases, if the SOR data is not successfully received (e.g., a security check fails or the ME is configured to receive SOR data but does not receive it), and if the VPLMN with which the ME is currently attempting to register is not the user's preferred PLMN and the ME is not in manual selection mode, the ME may terminate the current registration procedure and perform a PLMN search. In some cases, if the SOR data is not successfully received and the VPLMN with which the ME is currently attempting to register is not the user's preferred PLMN or the ME is in manual selection mode, the ME may continue the current registration procedure and not perform a PLMN search.
[0074] In message 10 of Figure C.1.1 in Figures 15A-15B (i.e., REGISTRATION COMPLETE), the ME, if configured, may send one or more indications indicating that SOR data is not received, that the SOR data failed a security check, that the VPLMN in which the ME is currently attempting to register is the user's preferred PLMN, or that the ME is in manual selection mode. As shown in the text in Figures 15C-15E, there may be two options for the action associated with message 10. In the second option, if the SOR data is not successfully received (e.g., an unsuccessful or failed security check), action 10a may be performed, and if the SOR data is successfully received (a successful security check), action 10b may be performed.
[0075] FIG. 13 schematically illustrates an example network node 1300 according to some implementations of the present disclosure. For example, network nodes 206, 208, 210, 604, 606, 704, 706, and 708 may be implemented by the network node 1300. The illustrated device 1300 includes a processing module 1302, a wired communication subsystem 1304, and a wireless communication subsystem 1306. The wireless communication subsystem 1306 may receive data traffic and control traffic from UEs. In some implementations, the wireless communication subsystem 1306 may include a receiver and a transmitter. The wired communication subsystem 1304 may be configured to transmit and receive control information between other access node devices via a backhaul connection. The processing module 1302 may include one or more processing components (alternatively referred to as a “processor” or “central processing unit” (CPU)) capable of executing instructions associated with one or more of the processes, steps, or actions described above in connection with one or more of the implementations disclosed herein. Processing module 1302 may also include other auxiliary components such as random access memory (RAM), read-only memory (ROM), secondary storage (e.g., a hard disk drive, flash memory or other non-transitory storage medium), etc. Processing module 1302 may execute specific instructions and commands to provide wireless or wired communication using wired communication subsystem 1304 or wireless communication subsystem 1306. Various other components may also be included within device 1300.
[0076] FIG. 14 schematically illustrates an example UE 1400 apparatus according to some implementations of the present disclosure. The example UE 1400 includes a processing unit 1402, a computer-readable storage medium 1404 (e.g., ROM or flash memory), a wireless communication subsystem 1406, an interface 1408, and an I / O interface 1410. The processing unit 1402 may include one or more processing components (alternatively referred to as a “processor” or “central processing unit” (CPU)) configured to execute instructions associated with one or more of the processes, steps, or actions described above in connection with one or more of the implementations disclosed herein. The processing unit 1402 may also include other auxiliary components, such as random access memory (RAM) and read-only memory (ROM). The computer-readable storage medium 1404 may be embodied by a non-transitory medium configured to store an operating system (OS) of the device 1400 and various other computer-executable software programs for performing one or more of the processes, steps, or actions described above.
[0077] The wireless communication subsystem 1406 may be configured to provide wireless communication for data or control information provided by the processing unit 1402. The wireless communication subsystem 1406 may include, for example, one or more antennas, receivers, transmitters, local oscillators, mixers, and digital signal processing (DSP) units. In some implementations, the subsystem 1406 may support multiple-input multiple-output (MIMO) transmission. In some implementations, the receiver in the wireless communication subsystem 1406 may be an advanced receiver or a baseline receiver. The two receivers may be implemented with the same, similar, or different receiver processing algorithms.
[0078] The user interface 1408 may include, for example, one or more of a screen or touch screen (e.g., a liquid crystal display (LCD), a light emitting display (LED), an organic light emitting display (OLED), a microelectromechanical systems (MEMS) display), a keyboard or keypad, a trackball, a speaker, and a microphone. The I / O interface 1410 may include, for example, a universal serial bus (USB) interface. Those skilled in the art will readily recognize that various other components may also be included in the exemplary UE device 1400.
[0079] While operations are depicted in the figures in a particular order, this should not be understood as requiring such operations to be performed in the particular order shown, i.e., sequential order, or that all of the illustrated operations be performed, to achieve desired results. In certain situations, multitasking and parallel processing may be employed. Moreover, the separation of various system components in the implementations described above should not be understood as requiring such separation in all implementations; the described program components and systems may generally be integrated together in a single software product or packaged within multiple software products.
[0080] Also, techniques, systems, subsystems, and methods described and shown as separate or distinct in various implementations may be combined or integrated with other systems, modules, techniques, or methods. Other items shown or discussed as being coupled or directly coupled or in communication with each other may be indirectly coupled or in communication, electrically, mechanically, or otherwise, through some interface, device, or intermediate component. Other examples of variations, substitutions, and alternatives may be ascertained and made by those skilled in the art.
[0081] While the foregoing detailed description has illustrated, described, and pointed out basic and salient features of the present disclosure as applied to various implementations, it will be understood that various omissions, substitutions, and changes in the form and details of the illustrated systems may be made by those skilled in the art. Additionally, the order of method steps is not implied by the order appearing in the claims.
Claims
1. A user equipment (UE), comprising: the UE comprises a processor; The processor: sending a registration request message to a visited public land mobile network (VPLMN); receiving a registration accept message from the VPLMN, the registration accept message including roaming guidance information received from a Home Public Land Mobile Network (HPLMN); determining whether the roaming guidance information includes a list of preferred public land mobile network (PLMN) / access technology combinations and whether a security check of the roaming guidance information is successful; based on determining that the roaming guidance information includes the list of preferred PLMN / access technology combinations and that a security check of the roaming guidance information is successful; replacing the highest priority entry in an operator-controlled PLMN selector with the received list of preferred PLMN / access technology combinations into an access technology list; sending a registration complete message to the VPLMN, the registration complete message including a transparent container including a UE response to the HPLMN; adding the VPLMN to a list of forbidden PLMNs maintained at the UE based on determining that the security check of the roaming guidance information fails; To do The UE is configured to:
2. The UE of claim 1, wherein the processor is further configured to send the registration completion message on condition that the security check of the roaming guidance information fails or the list of preferred PLMN / access technology combinations is not included in the roaming guidance information, and the registration completion message includes an indication that the security check has failed.
3. A UE as described in claim 1, wherein a unified data management (UDM) node requests a response to the response to the registration accept message from the UE.
4. The UE of claim 1, wherein the UE includes a Universal Integrated Circuit Card (UICC).
5. A UE as described in claim 4, wherein the roaming guidance information is included in a security protected packet.
6. The UE of claim 5, wherein the processor is configured to transmit the security-protected packet to the UICC.
7. The UE of claim 6, wherein the processor is configured to receive an indication from the UICC regarding whether the security check of the roaming guidance information was successful.
8. The UE of claim 7, wherein the indication is included in a USAT command.
9. A method implemented by a user equipment (UE), the method comprising: sending a registration request message to a visited public land mobile network (VPLMN); receiving a registration accept message from the VPLMN, the registration accept message including roaming guidance information received from a Home Public Land Mobile Network (HPLMN); determining whether the roaming guidance information includes a list of preferred public land mobile network (PLMN) / access technology combinations and whether a security check of the roaming guidance information is successful; based on determining that the roaming guidance information includes the list of preferred PLMN / access technology combinations and that a security check of the roaming guidance information is successful; replacing the highest priority entry in an operator-controlled PLMN selector with the received list of preferred PLMN / access technology combinations into an access technology list; sending a registration complete message to the VPLMN, the registration complete message including a transparent container including a UE response to the HPLMN; adding the VPLMN to a list of forbidden PLMNs maintained at the UE based on determining that the security check of the roaming guidance information fails; To do A method comprising:
10. The method of claim 9, further comprising sending the registration completion message based on determining that the security check of the roaming guidance information fails or that the list of preferred PLMN / access technology combinations is not included in the roaming guidance information, wherein the registration completion message includes an indication that the security check has failed.
11. The method of claim 9, wherein a unified data management (UDM) node requests a response to the response to the registration accept message from the UE.
12. The method of claim 9, wherein the UE includes a Universal Integrated Circuit Card (UICC).
13. The method of claim 12, wherein the roaming guidance information is included in a secure packet.
14. The method of claim 13, wherein the UICC receives the security-protected packet.
15. The method of claim 14, further comprising receiving an indication from the UICC as to whether the security check of the roaming guidance information was successful.
16. A non-transitory machine-readable storage medium comprising instructions that, when executed, sending a registration request message to a visited public land mobile network (VPLMN); receiving a registration accept message from the VPLMN, the registration accept message including roaming guidance information received from a Home Public Land Mobile Network (HPLMN); determining whether the roaming guidance information includes a list of preferred public land mobile network (PLMN) / access technology combinations and whether a security check of the roaming guidance information is successful; based on determining that the roaming guidance information includes the list of preferred PLMN / access technology combinations and that a security check of the roaming guidance information is successful; replacing the highest priority entry in an operator-controlled PLMN selector with the received list of preferred PLMN / access technology combinations into an access technology list; sending a registration complete message to the VPLMN, the registration complete message including a transparent container including a user equipment (UE) response to the HPLMN; adding the VPLMN to a list of forbidden PLMNs maintained at the UE based on determining that the security check of the roaming guidance information fails; To do a non-transitory machine-readable storage medium for instructing the UE to:
17. A non-transitory machine-readable storage medium as described in claim 16, wherein the instructions further instruct the UE to send the registration completion message based on determining that the security check of the roaming guidance information fails or that the list of preferred PLMN / access technology combinations is not included in the roaming guidance information, and the registration completion message includes an indication that the security check failed.
18. The non-transitory machine-readable storage medium of claim 16, wherein a unified data management (UDM) node requests a response to the response to the registration accept message from the UE.
19. The non-transitory machine-readable storage medium of claim 16, wherein the UE includes a Universal Integrated Circuit Card (UICC), the roaming guidance information is contained in a security-protected packet, the UE is instructed to send the security-protected packet to the UICC, and the UICC provides an indication to the UE as to whether the security check of the roaming guidance information was successful.
20. The method of claim 9, wherein the VPLMN added to the list of prohibited PLMNs is an undesirable PLMN.