Wireless terminals and RAN nodes

By using NAS security parameters to authenticate wireless terminals in 5G networks, the issue of broadcasting SI to malicious terminals is addressed, ensuring secure and efficient resource utilization.

JP7679856B2Active Publication Date: 2025-05-20NEC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023127076
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-01-31
Filing Date
2023-08-03
Publication Date
2025-05-20
Estimated Expiration
2040-12-28

AI Technical Summary

Technical Problem

In 5G wireless communication networks, RAN nodes cannot effectively authenticate wireless terminals during on-demand SI requests, leading to potential resource wastage by broadcasting SI to malicious terminals.

Method used

Incorporating Non-Access Stratum (NAS) security parameters in the message sent by wireless terminals to RAN nodes during on-demand SI requests, which are then verified by core network nodes to authenticate the terminals before broadcasting the SI.

Benefits of technology

This solution prevents the broadcasting of on-demand SI to malicious wireless terminals, thereby conserving resources and ensuring secure communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007679856000001
    Figure 0007679856000001
  • Figure 0007679856000002
    Figure 0007679856000002
  • Figure 0007679856000003
    Figure 0007679856000003
Patent Text Reader

Abstract

To contribute to preventing the broadcast of on-demand system information (SI) in response to a request from a malicious wireless terminal.SOLUTION: A RAN node receives a message containing non-access stratum (NAS) security parameters from a wireless terminal within a procedure in which the wireless terminal requests the RAN node to broadcast on-demand SI. The RAN node sends an authentication request message containing the received NAS security parameters to a core network node in order to request authentication of the wireless terminal. The RAN node broadcasts the on-demand SI in response to receiving an authentication response message indicating successful authentication of the wireless terminal from the core network node.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present disclosure relates to wireless communication networks, and more particularly to broadcasting on-demand system information. [Background technology]

[0002] In a 5G system (5GS), system information (SI) includes a Master Information Block (MIB) and many System Information Blocks (SIBs), which are divided into Minimum SI and Other SI. Minimum SI is always broadcast periodically and includes basic information required for initial access and information required to obtain other SI. More specifically, Minimum SI includes MIB and SIB type 1 (SIB1).

[0003] The MIB is periodically transmitted on the Broadcast Channel (BCH) and the Physical Broadcast Channel (PBCH). The MIB contains information about the barring of the cell, and further contains essential physical layer information of the cell required to decode SIB1. More specifically, the MIB indicates the System Frame Number (SFN), the subcarrier spacing for SIB1 (subCarrierSpacingCommon), and the Physical Downlink Control Channel (PDCCH) configuration required to decode SIB1, etc.

[0004] SIB1 is also called Remaining Minimum SI (RMSI). SIB1 is transmitted periodically on the Downlink Shared Channel (DL-SCH) and the Physical Downlink Shared Channel (PDSCH). SIB1 indicates the availability and scheduling (e.g., periodicity and SI window size) of Other SI (Other SIBs). SIB1 further indicates whether Other SIBs are provided via periodic broadcast or on an on-demand basis. Furthermore, SIB1 contains information necessary for initial access.

[0005] Other SI includes all SIBs that are not broadcast in Minimum SI. These SIBs are either broadcast periodically on DL-SCH, broadcast on demand on DL-SCH (i.e., upon request from radio terminals (User Equipments (UEs)) that are Radio Resource Control (RRC)_IDLE or RRC_INACTIVE), or sent in a dedicated manner on DL_SCH to UEs that are RRC_CONNECTED. Other SI includes SIB2 to SIB9.

[0006] As mentioned above, in 5GS, Other SI can be broadcast on demand. Specifically, if the required system information is not being broadcast, a UE in RRC_IDLE or RRC_INACTIVE sends a request for specific system information to a Radio Access Network (RAN) node (e.g., base station, gNB). The request is sent within a contention-based random access procedure. In response to receiving the request from the UE, the RAN node broadcasts the requested system information.

[0007] More specifically, if a subset of random access resources (i.e., Physical Random Access Channel (PRACH) resources) for the required system information request is provided by SIB1, the UE selects a random access preamble from the subset and transmits the selected preamble. In this case, the SI request is transmitted in the random access preamble, i.e., in the first message (Msg1) of the (4-step) random access procedure. Otherwise, the UE transmits an SI request message (i.e., RRCSystemInfoRequest message) via the first RRC message transmission (i.e., the third message (Msg3) of the (4-step) random access procedure). The UE includes a list (i.e., requested-SI-List) indicating the required system information messages in the RRCSystemInfoRequest message.

[0008] 5GS system information and its acquisition are described, for example, in Section 7.3 of Non-Patent Document 1 and Section 5.2.2.3 of Non-Patent Document 2.

[0009] In this specification, the term "on-demand system information (SI)" is used. On-demand SI means system information that is broadcast on demand in response to a request from a wireless terminal (e.g., UE), such as Other SI in 5GS. In other words, on-demand SI is system information that is not periodically broadcast and is broadcast on demand in response to a request from a wireless terminal (e.g., UE). [Prior art documents] [Non-patent literature]

[0010] [Non-Patent Document 1] 3GPP TS 38.300 V15.8.0 (2019-12) "3rd Generation Partnership Project; Technical Specification Group Radio Access Network; NR; NR and NG-RAN Overall Description; Stage 2 (Release 15)", December 2019 [Non-Patent Document 2] 3GPP TS 38.331 V15.8.0 (2019-12) "3rd Generation Partnership Project; Technical Specification Group Radio Access Network; NR; Radio Resource Control (RRC) protocol specification (Release 15)", December 2019 Summary of the Invention [Problem to be solved by the invention]

[0011] The inventors have studied the procedure for requesting on-demand SI and found various problems. Specifically, for example, a RAN node (e.g., gNB) cannot identify or authenticate a wireless terminal (e.g., UE) in a random access procedure for requesting on-demand SI. Therefore, even if a malicious wireless terminal requests transmission of on-demand SI, the RAN node broadcasts the on-demand SI in response to the request. This may waste resources of the RAN node and wireless resources.

[0012] One of the objectives to be achieved by the embodiments disclosed herein is to provide an apparatus, a method, and a program that contribute to preventing broadcast of on-demand SI in response to a request from a malicious wireless terminal. It should be noted that this objective is only one of the objectives to be achieved by the embodiments disclosed herein. Other objectives or problems and novel features will become apparent from the description of this specification or the accompanying drawings. [Means for solving the problem]

[0013] In a first aspect, a wireless terminal includes at least one memory and at least one processor coupled to the at least one memory, the at least one processor configured to transmit a message to a RAN node within a procedure requesting the RAN node to broadcast an on-demand SI, the message including a Non-Access Stratum (NAS) security parameter.

[0014] In a second aspect, a RAN node includes at least one memory and at least one processor coupled to the at least one memory, the at least one processor configured to receive a message including Non-Access Stratum (NAS) security parameters from a wireless terminal in a procedure in which the wireless terminal requests the RAN node to broadcast an on-demand SI, the at least one processor further configured to transmit an authentication request message including the NAS security parameters to a core network node to request authentication of the wireless terminal, and the at least one processor further configured to broadcast the on-demand SI in response to receiving an authentication response message from the core network node indicating successful authentication of the wireless terminal.

[0015] In a third aspect, a core network node includes at least one memory and at least one processor coupled to the at least one memory, the at least one processor configured to receive an authentication request message from a Radio Access Network (RAN) node, the authentication request message including NAS security parameters transmitted by the wireless terminal in a procedure in which the wireless terminal requests the RAN node to broadcast an on-demand SI, and the at least one processor further configured to transmit an authentication response message to the RAN node indicating success or failure of authentication based on the NAS security parameters.

[0016] In a fourth aspect, a method performed by a wireless terminal includes transmitting a message to a RAN node including Non-Access Stratum (NAS) security parameters within a procedure requesting the RAN node to broadcast on-demand SI.

[0017] In a fifth aspect, a method performed by a RAN node includes the following steps: (a) receiving a message from a wireless terminal, the message including a Non-Access Stratum (NAS) security parameter, within a procedure in which the wireless terminal requests the RAN node to broadcast an on-demand SI; (b) sending an authentication request message including the NAS security parameters to a core network node to request authentication of the wireless terminal; and (c) broadcasting the on-demand SI in response to receiving an authentication response message from the core network node indicating successful authentication of the wireless terminal.

[0018] In a sixth aspect, a method performed by a core network node comprises the following steps: (a) receiving an authentication request message from a Radio Access Network (RAN) node, where the authentication request message includes NAS security parameters sent by the wireless terminal in a procedure in which the wireless terminal requests the RAN node to broadcast an on-demand SI; and (b) sending an authentication response message to the RAN node indicating success or failure of authentication based on the NAS security parameters.

[0019] In a seventh aspect, a program comprises instructions (software code) which, when loaded into a computer, causes the computer to carry out a method according to the fourth, fifth or sixth aspect above. Effect of the Invention

[0020] According to the above-described aspects, it is possible to provide an apparatus, a method, and a program that contribute to preventing broadcasting of on-demand SI in response to a request from a malicious wireless terminal. [Brief description of the drawings]

[0021]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

[0022] In the following, specific embodiments will be described in detail with reference to the drawings. In each drawing, the same or corresponding elements are denoted by the same reference numerals, and duplicated descriptions will be omitted as necessary for clarity of explanation.

[0023] The multiple embodiments described below can be implemented independently or in appropriate combination. These multiple embodiments have different novel features. Therefore, these multiple embodiments contribute to solving different objects or problems and provide different effects.

[0024] The following embodiments are described primarily for the 3rd Generation Partnership Project (3GPP) 5th generation mobile communication system (5G system (5GS)). However, these embodiments may be applied to other cellular communication systems that support on-demand SI transmission similar to 5GS.

[0025] <First embodiment> FIG. 1 shows an example of the configuration of a wireless communication network (i.e., 5GS) according to the present embodiment. Each of the elements shown in FIG. 1 is a network function, and provides an interface defined by 3GPP. Each of the elements (network functions) shown in FIG. 1 can be implemented, for example, as a network element on dedicated hardware, as a software instance running on dedicated hardware, or as a virtualized function instantiated on an application platform.

[0026] The wireless communication network shown in Fig. 1 may be provided by a Mobile Network Operator (MNO) or may be a Non-Public Network (NPN) provided by a party other than an MNO. If the cellular network shown in Fig. 1 is an NPN, it may be an independent network called a Stand-alone Non-Public Network (SNPN) or an NPN linked with an MNO network called a Public network integrated NPN.

[0027] In the example of Figure 1, the wireless communication network includes a wireless terminal (i.e., UE) 1, a RAN node (i.e., gNB) 2, and a core network node (i.e., Access and Mobility Management Function (AMF)) 3. The gNB 2 is deployed in a RAN (i.e., Next Generation Radio Access Network (NG-RAN)). The gNB 2 may include a gNB Central Unit (gNB-CU) and one or more gNB Distributed Units (gNB-DUs) in a cloud RAN (C-RAN) deployment.

[0028] AMF3 is one of the network functions in the 5G Core Network (5GC) Control Plane. AMF3 provides the termination of the RAN Control Plane (CP) interface (i.e., N2 interface). AMF3 terminates a single signaling connection (i.e., N1 NAS signalling connection) with UE1 and provides registration management, connection management, and mobility management. AMF3 provides NF services to NF service consumers (e.g., other AMFs, Session Management Function (SMF), and Authentication Server Function (AUSF)) over the service-based interface (i.e., Namf interface).

[0029] Next, a procedure for requesting on-demand SI according to this embodiment will be described below. In this embodiment, in order to determine whether the on-demand SI request (or the UE1 that sent it) is trustworthy, the Non-Access Stratum (NAS) security set up between the UE1 and the 5GC (AMF3) is used.

[0030] More specifically, UE1 transmits a message including the NAS security parameters to gNB2 in a procedure (i.e., a random access procedure) requesting gNB2 to transmit (broadcast) on-demand SI. Specifically, UE1 may transmit an Access Stratum (AS) message (e.g., a Radio Resource Control (RRC) message) including the NAS security parameters.

[0031] The gNB2 extracts the NAS security parameters from the message (e.g., RRC message) received from the UE1. Then, the gNB2 sends an authentication request message including the NAS security parameters received from the UE1 to the AMF3 to request authentication of the UE1. The authentication request message may be a newly defined N2 message (e.g., Authentication Required message). The authentication request message may include a cause IE indicating UE authentication for the transmission of on-demand SI.

[0032] In response to receiving the authentication request message from the gNB2, the AMF3 performs a verification using the received NAS security parameters. This allows the AMF3 to determine whether a genuine UE has sent the NAS security parameters (or an on-demand SI request). The AMF3 then sends an authentication response message to the gNB2. The authentication response message indicates the result (success or failure) of the UE authentication based on the NAS security parameters.

[0033] The authentication response message is used by gNB2 to determine whether to broadcast the requested on-demand SI. Specifically, gNB2 broadcasts the requested on-demand SI in response to receiving an authentication response message from AMF3 indicating successful authentication of UE1. In other words, if the authentication response message indicates successful UE authentication, the authentication response message triggers gNB2 to broadcast the on-demand SI. On the other hand, if the authentication response message indicates unsuccessful UE authentication, gNB2 may not broadcast the requested on-demand SI.

[0034] According to the above operation, gNB2 can use the NAS security set up between UE1 and 5GC (AMF3) to determine whether the request for on-demand SI (or UE1 that sent it) is trustworthy or not. Therefore, this operation can prevent broadcast of on-demand SI in response to requests from malicious UEs.

[0035] Figure 2 shows an example of the operation of UE1. In step 201, UE1 generates NAS security parameters. More specifically, the AS part of UE1 (eg, Radio Resource Control (RRC) layer) triggers the NAS part of UE1 to provide the NAS security parameters.

[0036] In some implementations, the NAS security parameters include at least a portion of the Message Authentication Code for NAS for Integrity (NAS-MAC) calculated by UE1. The NAS security parameters may include a UL_NAS_MAC formed by a portion of the 32-bit NAS-MAC (e.g., the first 16 bits). The NAS security parameters may further include at least a portion of the NAS COUNT used to calculate the NAS-MAC (e.g., the 5 least significant bits (LSBs)).

[0037] In step 202, UE1 sends an AS message (e.g., RRC message) to gNB2 containing the NAS security parameters in a procedure requesting gNB2 to broadcast the required on-demand SI. As already explained, the procedure may be a random access procedure. In this case, UE1 may send the NAS security parameters via the third message (Msg3) of the four-step random access procedure, i.e. the first RRC message.

[0038] The AS message (eg, RRC message) of step 202 may include at least a part of a UE temporary identifier assigned to UE1 by 5GC (eg, AMF3). The UE temporary identifier is used, for example, for contention resolution by gNB2, for routing (AMF selection) by gNB2, and for UE identification by AMF3. The temporary identifier may be a 5G-S-Temporary Mobile Subscription Identifier (5G-S-TMSI). 5G-S-TMSI has a length of 48 bits. 5G-S-TMSI consists of an AMF set ID (10 bits), an AMF pointer (6 bits), and a 5G TMSI (32 bits).

[0039] In the current 3GPP specifications, the bit length of the RRC message is 48 bits or 64 bits. Therefore, the size (bit length) of one or more information elements (i.e., NAS security parameters, or a part of the UE temporary identifier, or both) carried by the 48-bit or 64-bit RRC message (step 202) may be adjusted as necessary. Details of this will be described in another embodiment described later.

[0040] In step 203, UE1 attempts to receive on-demand SI. Specifically, UE1 attempts (or starts) receiving on-demand SI if it receives an acknowledgement for the SI request from gNB2. The acknowledgement for the SI request may be a fourth message (Msg4) of the random access procedure. Msg4 includes a MAC Protocol Data Unit (PDU) carrying a UE Contention Resolution Identity Medium Access Control (MAC) Control Element (CE).

[0041] FIG. 3 shows an example of the operation of gNB2. In step 301, gNB2 receives an AS message (e.g., RRC message) including NAS security parameters from UE1 in a procedure in which UE1 requests gNB2 to broadcast on-demand SI. As already explained, the procedure may be a random access procedure. In this case, gNB2 may receive the NAS security parameters via the third message (Msg3) of the four-step random access procedure, i.e., the first RRC message. Examples of NAS security parameters are similar to those explained with reference to FIG. 2. Furthermore, as explained with reference to FIG. 2, the AS message of step 301 may include at least a part of a UE temporary identifier (e.g., 5G-S-TMSI).

[0042] In step 302, the gNB2 sends an authentication request message including the NAS security parameters to the AMF3 to request UE authentication. The gNB2 may select the AMF3 based on the UE temporary identifier (e.g., 5G-S-TMSI) included in the AS message of step 301. The authentication request message may be a newly defined N2 message (e.g., Authentication Required message). The authentication request message may include a cause IE indicating UE authentication for the transmission of on-demand SI.

[0043] In step 303, the gNB2 receives an authentication response message indicating the result (success or failure) of the UE authentication from the AMF3. Then, the gNB2 broadcasts the requested on-demand SI if the authentication response message indicates success of the UE authentication.

[0044] FIG. 4 shows an example of the operation of the AMF3. In step 401, the AMF3 receives an authentication request message from the gNB2. The authentication request message includes the NAS security parameters sent by the UE1 in the procedure in which the UE1 requests the gNB2 to broadcast on-demand SI. An example of the NAS security parameters is the same as that described with reference to FIG. 2. The authentication request message may be a newly defined N2 message (e.g., Authentication Required message). The authentication request message may include a cause IE indicating UE authentication for transmission of on-demand SI.

[0045] In step 402, the AMF 3 performs verification using the received NAS security parameters, and then sends an authentication response message to the gNB 2. The authentication response message indicates the result (success or failure) of the UE authentication based on the NAS security parameters.

[0046] FIG. 5 shows an example of an on-demand SI request procedure according to the present embodiment. Steps 501 to 504 correspond to the first to fourth steps of the four-step contention-based random access procedure. In step 501, UE1 transmits a random access preamble for an on-demand SI request. More specifically, if a subset of random access resources (i.e., PRACH resources) for the required on-demand SI is provided by SIB1, UE selects a random access preamble from the subset and transmits the selected preamble. Otherwise, UE1 selects a random access preamble from normal random access resources and transmits the selected preamble.

[0047] In step 502, gNB2 transmits a Random Access Response (RAR) indicating an identifier of the detected preamble, timing alignment information, an initial uplink resource grant for the third message transmission, and an allocation of a temporary Cell Radio Network Temporary Identifier (C-RNTI).

[0048] In step 503, in response to receiving the RAR, UE1 transmits an RRC message for an on-demand SI request. The RRC message includes NAS security parameters. Specifically, the RRC message includes UL_NAS_MAC, which is a portion of the NAS-MAC calculated by UE1 (e.g., the first 16 bits), and a portion of the NAS COUNT used to calculate the NAS-MAC (e.g., the lowest 5 bits). The RRC message further includes at least a portion of the 5G-S-TMSI assigned to UE1 by 5GC (i.e., AMF3).

[0049] The RRC message of step 503 may or may not include a list of required system information messages (i.e., requested-SI-List). In particular, if a subset of the random access resources (i.e., PRACH resources) for the required on-demand SI is provided by SIB1, the RRC message does not need to include the requested-SI-List.

[0050] The RRC message in step 503 may be a modified version of an existing RRC System Info Request message (eg, an RRC System Info Request1 message). Specifically, the existing RRC System Info Request message is 48 bits long, whereas the RRC message in step 503 may be 64 bits long.

[0051] In step 504, the gNB2 sends a fourth message for contention resolution (Msg4). Msg4 includes a MAC PDU carrying a UE Contention Resolution Identity MAC CE.

[0052] In step 505, the gNB2 sends an authentication request message (e.g., an N2: Authentication Required message) to the AMF3. The authentication request message includes the NAS security parameters (i.e., UL_NAS_MAC and some bits of NAS COUNT) received from the UE1 in step 503.

[0053] The authentication request message further includes the 5G-S-TMSI of UE 1. If the RRC message of step 503 includes only a portion of the 5G-S-TMSI, the gNB 2 may estimate the entire 5G-S-TMSI.

[0054] The authentication request message may include other parameters related to NAS security. For example, the authentication request message may include other parameters necessary for the calculation of NAS-MAC / XNAS-MAC in the Integrity Algorithm used for NAS security. In one example, the Cell-ID may be used as a message to be protected in the calculation of NAS-MAC by UE1. In this case, gNB2 may include the Cell-ID in the authentication request message.

[0055] The authentication request message may include a cause IE indicating UE authentication for the transmission of on-demand SI.

[0056] In step 506, the AMF3 performs UE authentication based on the received NAS security parameters (i.e., UL_NAS_MAC and some bits of NAS COUNT). Specifically, the AMF3 calculates XNAS-MAC using the same inputs that the UE1 used to calculate NAS-MAC. Then, the AMF3 compares the received UL_NAS_MAC with the corresponding bits (e.g., first 16 bits) of XNAS-MAC. If they are the same, the AMF3 determines that the UE authentication is successful. In other words, the AMF3 determines that a genuine UE has sent the NAS security parameters (or the on-demand SI request).

[0057] In one example, a 32-bit NAS COUNT, a 5-bit bearer identity (i.e., BEARER), a 1-bit direction of transmission (i.e., DIRECTION), and a message to be protected (i.e., MESSAGE) are used in the calculation of NAS-MAC / XNAS-MAC. The AMF3 estimates the entire uplink NAS COUNT from some bits (e.g., 5 LSBs) of the received NAS COUNT. Specifically, the AMF3 may replace some bits (e.g., 5 LSBs) of the 32-bit uplink NAS COUNT managed by the AMF3 itself with some bits (e.g., 5 LSBs) of the NAS COUNT received from the UE1 via the gNB2. The BEARER bit is a predetermined fixed value (e.g., zero). The DIRECTION bit is 0 (zero) in the case of uplink. The MESSAGE bit may be a predetermined fixed value or may be the Cell-ID as described above.

[0058] The AMF 3 sends an authentication response message indicating the result of the UE authentication to the gNB 2. The AMF 3 may send an authentication success message (e.g., N2: Authentication Confirm message) if the UE authentication is successful, or may send an authentication failure message (e.g., N2: Authentication Failure message) if the UE authentication is unsuccessful.

[0059] In step 507, gNB2 broadcasts the requested on-demand SI in response to receiving the authentication response message indicating successful UE authentication. UE1 attempts to receive the on-demand SI after receiving the acknowledgement message (Msg4) in step 504, and receives the on-demand SI in step 507.

[0060] The procedure in FIG. 5 is an example and may be modified as appropriate. For example, the four-step random access procedure in FIG. 5 may be changed to a two-step random access procedure. The two-step random access procedure includes transmission of a message A from UE1 to gNB2 and transmission of a message B from gNB2 to UE1. Message A may include information similar to the first message (step 501) and the third message (step 503) of the four-step random access procedure. Message B may include information for contention resolution similar to the fourth message (step 504) of the four-step random access procedure.

[0061] Additionally or alternatively, in step 504, gNB2 may include in the acknowledgement message (Msg4) an indication of a waiting time until broadcasting of on-demand SI is started. The waiting time may be determined based on the time required to complete UE authentication (steps 505 and 506). The waiting time may be dynamically determined by gNB2. UE1 may delay the start of an attempt to receive on-demand SI taking into account the waiting time notified by gNB2. In this way, UE1 does not need to start receiving on-demand SI immediately after receiving the acknowledgement message (Msg4), and thus the power consumption of UE1 is reduced.

[0062] Additionally or alternatively, sending of an acknowledgement message (Msg4) (step 504) may occur after UE authentication (steps 505 and 506).

[0063] <Second embodiment> This embodiment describes a modification of the first embodiment. An example of the configuration of a wireless communication network according to this embodiment is similar to that shown in FIG.

[0064] FIG. 6 shows an example of the operation of the gNB2 according to this embodiment. In step 601, the gNB2 generates one authentication request message including multiple NAS security parameters received from multiple UEs1. The gNB2 may aggregate SI requests from multiple UEs received within a predefined time window. In some implementations, the gNB2 may generate one authentication request message including multiple NAS security parameters received from multiple UEs1 managed by the same AMF3. Alternatively, the gNB2 may generate one authentication request message including multiple NAS security parameters received from multiple UEs1 managed by the same AMF3 and that have requested the same on-demand SI message. In step 602, the gNB2 transmits the generated authentication request message to the AMF3.

[0065] Figure 7 shows an example of the operation of the AMF3 according to this embodiment. In step 701, an authentication request message including NAS security parameters sent by UEs1 is received from the gNB2. In step 702, the AMF3 sends an authentication response message to the gNB2 indicating the authentication result of each of these UEs. The gNB2 broadcasts one or more on-demand SI messages requested by the one or more successfully authenticated UEs.

[0066] As described above, in this embodiment, the gNB2 sends one authentication request message including multiple NAS security parameters received from multiple UEs1 to the AMF3, and the AMF3 sends one authentication response message indicating the authentication results of each of these UEs to the gNB2, which contributes to reducing the number of times that the authentication request message and the authentication response message are sent and received.

[0067] <Third embodiment> This embodiment describes a modification of the second embodiment. An example of the configuration of a wireless communication network according to this embodiment is similar to that shown in FIG.

[0068] Figure 8 shows an example of the operation of the gNB2 according to this embodiment. In step 801, the gNB2 generates an authentication request message including NAS security parameters received from UEs1 managed by the same AMF3 and requesting the same on-demand SI message. The gNB2 may aggregate SI requests from the UEs received within a predefined time window. In step 802, the gNB2 sends the generated authentication request message to the AMF3.

[0069] 9 shows an example of the operation of the AMF3 according to this embodiment. In step 901, an authentication request message is received from the gNB2. The authentication request message includes multiple NAS security parameters received from multiple UEs1 that have requested the same on-demand SI message.

[0070] In step 902, the AMF 3 transmits an authentication response message indicating successful authentication in response to successful authentication of at least one of the multiple UEs. The authentication response message does not need to indicate the authentication result of each of the multiple UEs, and it is sufficient to indicate the result of one authentication. If the AMF 3 successfully authenticates one of the multiple UEs associated with one authentication request message, the AMF 3 may skip (omit) authentication of the remaining UEs. If the AMF 3 successfully authenticates one of the multiple UEs associated with one authentication request message, the AMF 3 may immediately transmit an authentication response message indicating successful authentication without waiting for the completion of authentication of the remaining UEs. In response to receiving the authentication response message indicating successful authentication, the gNB 2 broadcasts the requested on-demand SI message.

[0071] As described above, in this embodiment, the gNB2 sends one authentication request message to the AMF3, including multiple NAS security parameters received from multiple UEs1 managed by the same AMF3 and requesting the same on-demand SI message. Then, the AMF3 sends an authentication response message indicating successful authentication in response to successful authentication of at least one of the multiple UEs, thereby making the UE authentication suitable for on-demand SI transmission.

[0072] Specifically, if the AMF3 has successfully authenticated one of the multiple UEs associated with one authentication request message, it can skip (omit) the authentication of the remaining UEs. This reduces the load of UE authentication on the AMF3. Also, if the AMF3 has successfully authenticated one of the multiple UEs associated with one authentication request message, it can immediately transmit an authentication response message indicating successful authentication without waiting for the completion of authentication of the remaining UEs. This reduces the delay in starting broadcasting of on-demand SI.

[0073] <Fourth embodiment> This embodiment describes a modification of the first embodiment. A configuration example of a wireless communication network according to this embodiment is similar to that shown in Fig. 1. This embodiment is directed to reducing the size of data to be transmitted from UE1 to gNB2 by an AS message (e.g., RRC message) for an on-demand SI request.

[0074] As already described, in the current 3GPP specifications, the bit length of the RRC message is 48 bits or 64 bits. In this embodiment, a specific example of adjusting the size (bit length) of one or more information elements (i.e., NAS security parameters, or a part of the UE temporary identifier, or both) carried by the 48-bit or 64-bit RRC message (e.g., steps 202 and 503) is provided. The following multiple specific examples may be used in appropriate combination.

[0075] In the first example, the size of the UL_NAS_MAC included in the NAS security parameters is adjusted. If a 64-bit RRC message includes the NAS security parameters in addition to the 5G-S-TMSI (48 bits), the NAS security parameters need to be 16 bits or less. For this purpose, the number of bits in the UL_NAS_MAC is reduced. For example, UE1 may use the first 11 bits or less of the calculated NAS_MAC as the UL_NAS_MAC.

[0076] In the second example, the size of some bits of the UL COUNT included in the NAS security parameters is adjusted, for example, UE1 may transmit the 4 LSBs or the 3 LSBs of the NAS COUNT.

[0077] In the third example, the 5G-S-TMSI is shortened. The complete 5G-S-TMSI has a length of 48 bits and consists of an AMF set ID (10 bits), an AMF pointer (6 bits), and a 5G TMSI (32 bits). The shortening of the 5G TMSI is not appropriate because it makes it difficult for AMF3 to identify the UE. On the other hand, the AMF set ID and the AMF pointer may be replaced with shortened bit strings as shown below.

[0078] The gNB2 manages a list of AMFs to which the gNB2 is connected. Figure 10 shows an example of an AMF list managed by the gNB2. The AMF list in Figure 10 shows six AMFs, and sequence numbers are assigned to these six AMFs. Therefore, by using the AMF list in Figure 10, the six AMFs connected to the gNB2 can be distinguished by a 3-bit word representing the sequence number. The example in Figure 10 is one example, and a data reduction effect can be obtained if the bit length of the replaced AMF sequence number (or identifier) ​​is smaller than the total size (i.e., 16 bits) of the AMF set ID and the AMF pointer.

[0079] In some implementations, as shown in FIG. 11, gNB2 periodically broadcasts an AMF list (e.g., FIG. 10) via a minimum SI (e.g., SIB1) or via another SIB (step 1101). UE1 receives the SIB carrying the AMF list. UE1 may then use the list to shorten the AMF set ID and AMF pointer in the 5G-S-TMSI included in the RRC message carrying the NAS security parameters (e.g., steps 202 and 503).

[0080] Next, the following describes configuration examples of UE1, gNB2, and AMF3 according to the above-mentioned embodiments. FIG. 12 is a block diagram showing a configuration example of UE1. A Radio Frequency (RF) transceiver 1201 performs analog RF signal processing to communicate with NG-RAN nodes. The RF transceiver 1201 may include multiple transceivers. The analog RF signal processing performed by the RF transceiver 1201 includes frequency up-conversion, frequency down-conversion, and amplification. The RF transceiver 1201 is coupled to an antenna array 1202 and a baseband processor 1203. The RF transceiver 1201 receives modulation symbol data (or OFDM symbol data) from the baseband processor 1203, generates a transmission RF signal, and provides the transmission RF signal to the antenna array 1202. The RF transceiver 1201 also generates a baseband reception signal based on the reception RF signal received by the antenna array 1202, and provides the baseband reception signal to the baseband processor 1203. The RF transceiver 1201 may include an analog beamformer circuit for beamforming, which may include, for example, multiple phase shifters and multiple power amplifiers.

[0081] The baseband processor 1203 performs digital baseband signal processing (data plane processing) and control plane processing for wireless communication. Digital baseband signal processing includes (a) data compression / decompression, (b) data segmentation / concatenation, (c) generation / decomposition of transmission format (transmission frame), (d) transmission line coding / decoding, (e) modulation (symbol mapping) / demodulation, and (f) generation of OFDM symbol data (baseband OFDM signal) by Inverse Fast Fourier Transform (IFFT). Meanwhile, control plane processing includes communication management of layer 1 (e.g., transmission power control), layer 2 (e.g., radio resource management, and hybrid automatic repeat request (HARQ) processing), and layer 3 (e.g., signaling related to attachment, mobility, and call management).

[0082] For example, the digital baseband signal processing by the baseband processor 1203 may include signal processing of a Service Data Adaptation Protocol (SDAP) layer, a Packet Data Convergence Protocol (PDCP) layer, a Radio Link Control (RLC) layer, a Medium Access Control (MAC) layer, and a Physical (PHY) layer. Also, the control plane processing by the baseband processor 1203 may include processing of a Non-Access Stratum (NAS) protocol, a Radio Resource Control (RRC) protocol, and MAC Control Elements (CEs).

[0083] The baseband processor 1203 may perform Multiple Input Multiple Output (MIMO) encoding and precoding for beamforming.

[0084] The baseband processor 1203 may include a modem processor (e.g., Digital Signal Processor (DSP)) that performs digital baseband signal processing and a protocol stack processor (e.g., Central Processing Unit (CPU) or Micro Processing Unit (MPU)) that performs control plane processing. In this case, the protocol stack processor that performs control plane processing may be shared with the application processor 1204 described later.

[0085] The application processor 1204 is also called a CPU, an MPU, a microprocessor, or a processor core. The application processor 1204 may include multiple processors (multiple processor cores). The application processor 1204 executes a system software program (operating system (OS)) and various application programs (e.g., a call application, a web browser, a mailer, a camera operation application, and a music playback application) read from the memory 1206 or a memory not shown, thereby implementing various functions of the UE1.

[0086] In some implementations, the baseband processor 1203 and the application processor 1204 may be integrated on a single chip, as shown by the dashed line (1205) in Figure 12. In other words, the baseband processor 1203 and the application processor 1204 may be implemented as a single System on Chip (SoC) device 1205. An SoC device may also be called a system Large Scale Integration (LSI) or a chipset.

[0087] The memory 1206 is a volatile memory or a non-volatile memory, or a combination thereof. The memory 1206 may include a plurality of physically independent memory devices. The volatile memory is, for example, a Static Random Access Memory (SRAM) or a Dynamic RAM (DRAM), or a combination thereof. The non-volatile memory is a Mask Read Only Memory (MROM), an Electrically Erasable Programmable ROM (EEPROM), a flash memory, or a hard disk drive, or any combination thereof. For example, the memory 1206 may include an external memory device accessible from the baseband processor 1203, the application processor 1204, and the SoC 1205. The memory 1206 may include an internal memory device integrated in the baseband processor 1203, the application processor 1204, or the SoC 1205. Furthermore, the memory 1206 may include a memory in a Universal Integrated Circuit Card (UICC).

[0088] The memory 1206 may store one or more software modules (computer programs) 1207 including instructions and data for performing the processes by the UE 1 described in the above-mentioned embodiments. In some implementations, the baseband processor 1203 or the application processor 1204 may be configured to read the software modules 1207 from the memory 1206 and execute them to perform the processes by the UE 1 described in the above-mentioned embodiments using the drawings.

[0089] In addition, the control plane processing and operations performed by UE1 described in the above embodiment can be realized by elements other than the RF transceiver 1201 and the antenna array 1202, i.e., at least one of the baseband processor 1203 and the application processor 1204, and the memory 1206 storing the software module 1207.

[0090] FIG. 13 is a block diagram showing a configuration example of a gNB2 according to the above embodiment. Referring to FIG. 13, the gNB2 includes a radio frequency transceiver 1301, a network interface 1303, a processor 1304, and a memory 1305. The RF transceiver 1301 performs analog RF signal processing to communicate with UEs including UE1. The RF transceiver 1301 may include multiple transceivers. The RF transceiver 1301 is coupled to an antenna array 1302 and a processor 1304. The RF transceiver 1301 receives modulation symbol data from the processor 1304, generates a transmit RF signal, and provides the transmit RF signal to the antenna array 1302. The RF transceiver 1301 also generates a baseband receive signal based on the receive RF signal received by the antenna array 1302, and provides the baseband receive signal to the processor 1304. The RF transceiver 1301 may include an analog beamformer circuit for beamforming. The analog beamformer circuitry includes, for example, multiple phase shifters and multiple power amplifiers.

[0091] The network interface 1303 is used to communicate with network nodes (eg, AMF3 and Session Management Function (SMF)). The network interface 1303 may include, for example, a network interface card (NIC) that complies with the IEEE 802.3 series.

[0092] The processor 1304 performs digital baseband signal processing (data plane processing) and control plane processing for wireless communication. The processor 1304 may include multiple processors. For example, the processor 1304 may include a modem processor (e.g., Digital Signal Processor (DSP)) that performs digital baseband signal processing and a protocol stack processor (e.g., Central Processing Unit (CPU) or Micro Processing Unit (MPU)) that performs control plane processing.

[0093] For example, digital baseband signal processing by the processor 1304 may include signal processing of a Service Data Adaptation Protocol (SDAP) layer, a Packet Data Convergence Protocol (PDCP) layer, a Radio Link Control (RLC) layer, a MAC layer, and a PHY layer, and control plane processing by the processor 1304 may include processing of Non-Access Stratum (NAS) messages, RRC messages, MAC CEs, and DCIs.

[0094] The processor 1304 may include a digital beamformer module for beamforming, which may include a Multiple Input Multiple Output (MIMO) encoder and a precoder.

[0095] The memory 1305 is configured by a combination of volatile memory and non-volatile memory. The volatile memory is, for example, Static Random Access Memory (SRAM) or Dynamic RAM (DRAM), or a combination thereof. The non-volatile memory is, for example, Mask Read Only Memory (MROM), Electrically Erasable Programmable ROM (EEPROM), flash memory, or a hard disk drive, or any combination thereof. The memory 1305 may include storage located remotely from the processor 1304. In this case, the processor 1304 may access the memory 1305 via the network interface 1303 or an I / O interface not shown.

[0096] The memory 1305 may store one or more software modules (computer programs) 1306 including instructions and data for performing the processing by the gNB2 described in the above-mentioned embodiments. In some implementations, the processor 1304 may be configured to read and execute the software modules 1306 from the memory 1305 to perform the processing by the gNB2 described in the above-mentioned embodiments.

[0097] In addition, if gNB2 is a gNB-CU, gNB2 may not include RF transceiver 1301 (and antenna array 1302).

[0098] FIG. 14 shows an example of the configuration of the AMF3. Referring to FIG. 14, the AMF3 includes a network interface 1401, a processor 1402, and a memory 1403. The network interface 1401 is used, for example, to communicate with RAN nodes and to communicate with other network functions (NFs) or nodes in the 5GC. The other NFs or nodes in the 5GC include, for example, other AMFs, Unified Data Management (UDM), Authentication Server Function (AUSF), Session Management Function (SMF), and Policy Control Function (PCF). The network interface 1401 may include, for example, a network interface card (NIC) conforming to the IEEE 802.3 series.

[0099] The processor 1402 may be, for example, a microprocessor, a Micro Processing Unit (MPU), or a Central Processing Unit (CPU). The processor 1402 may include multiple processors.

[0100] The memory 1403 is composed of a volatile memory and a non-volatile memory. The memory 1403 may include a plurality of physically independent memory devices. The volatile memory is, for example, a static random access memory (SRAM) or a dynamic RAM (DRAM), or a combination thereof. The non-volatile memory is, for example, a mask read only memory (MROM), an electrically erasable programmable ROM (EEPROM), a flash memory, or a hard disk drive, or any combination thereof. The memory 1403 may include a storage located away from the processor 1402. In this case, the processor 1402 may access the memory 1403 via the network interface 1401 or an I / O interface not shown.

[0101] The memory 1403 may store one or more software modules (computer programs) 1404 including instructions and data for performing processing by the AMF3 described in the above-mentioned embodiments. In some implementations, the processor 1402 may be configured to read the software modules 1404 from the memory 1403 and execute them to perform the processing of the AMF3 described in the above-mentioned embodiments.

[0102] As described with reference to FIG. 12, FIG. 13, and FIG. 14, each of the processors of UE1, gNB2, and AMF3 according to the above-mentioned embodiment executes one or more programs including instructions for causing a computer to perform the algorithm described with reference to the drawings. The program can be stored and provided to a computer using various types of non-transitory computer readable media. The non-transitory computer readable medium includes various types of tangible storage media. Examples of the non-transitory computer readable medium include magnetic recording media (e.g., flexible disks, magnetic tapes, hard disk drives), magneto-optical recording media (e.g., magneto-optical disks), Compact Disc Read Only Memory (CD-ROM), CD-R, CD-R / W, and semiconductor memory (e.g., mask ROM, programmable ROM (PROM), erasable PROM (EPROM), flash ROM, random access memory (RAM)). The program may also be provided to a computer by various types of transitory computer readable media. Examples of the temporary computer-readable medium include an electric signal, an optical signal, and an electromagnetic wave. The temporary computer-readable medium can provide the program to the computer via a wired communication path such as an electric wire or an optical fiber, or a wireless communication path.

[0103] The above-described embodiment is merely an example of the application of the technical idea obtained by the inventor of the present invention. In other words, the technical idea is not limited to the above-described embodiment, and various modifications are possible.

[0104] For example, some or all of the above embodiments may be described as, but are not limited to, the following supplementary notes.

[0105] (Appendix 1) A wireless terminal, At least one memory; at least one processor coupled to the at least one memory; Equipped with The at least one processor is configured to transmit a message including a Non-Access Stratum (NAS) security parameter to a Radio Access Network (RAN) node in a procedure requesting the RAN node to broadcast on-demand system information. Wireless terminal. (Appendix 2) the on-demand system information is broadcast by the RAN node in response to successful authentication by a core network based on the NAS security parameters; 2. A wireless terminal as defined in claim 1. (Appendix 3) The NAS security parameters include at least some bits of a Message Authentication Code for NAS for Integrity (NAS-MAC) calculated by the wireless terminal; 3. A wireless terminal according to claim 1 or 2. (Appendix 4) the NAS security parameters further include at least a portion of the bits of a NAS COUNT used to calculate the NAS-MAC; 4. A wireless terminal as defined in claim 3. (Appendix 5) The message may include: a first set of bits included in a temporary identifier assigned to the wireless terminal by a core network; and a third set of bits that is pre-mapped to the second set of bits included in the temporary identifier and has a shorter length than the second set of bits; Further comprising: 5. The wireless terminal according to claim 1, (Appendix 6) the at least one processor is configured to receive system information broadcast by the RAN node, the system information including a list indicating a correspondence between the second set of bits and a third set of bits; 6. A wireless terminal as defined in claim 5. (Appendix 7) The temporary identifier is a 5G-S-Temporary Mobile Subscription Identifier (5G-S-TMSI), the first set of bits is a 5G-TMSI; The second set of bits is an Access and Mobility Management Function (AMF) Set ID and an AMF Pointer. 7. A wireless terminal according to claim 5 or 6. (Appendix 8) the at least one processor is configured to receive an acknowledgment message from the RAN node after transmitting the message; the acknowledgement message indicating a waiting time before broadcasting the on-demand system information begins; 8. The wireless terminal according to claim 1, (Appendix 9) the procedure is a random access procedure initiated for a request for the system information. 9. The wireless terminal according to claim 1, (Appendix 10) A Radio Access Network (RAN) node, At least one memory; at least one processor coupled to the at least one memory; Equipped with The at least one processor: receiving a message including Non-Access Stratum (NAS) security parameters from a wireless terminal during a procedure in which the wireless terminal requests the RAN node to broadcast on-demand system information; sending an authentication request message to a core network node, the authentication request message including the NAS security parameters, to request authentication of the wireless terminal; broadcasting the on-demand system information in response to receiving an authentication response message from the core network node indicating successful authentication of the wireless terminal. It is configured as follows: RAN node. (Appendix 11) The NAS security parameters include at least some bits of a Message Authentication Code for NAS for Integrity (NAS-MAC) calculated by the wireless terminal; 10. The RAN node according to claim 10. (Appendix 12) the NAS security parameters further include at least a portion of the bits of a NAS COUNT used to calculate the NAS-MAC; 13. The RAN node according to claim 11. (Appendix 13) The message received from the wireless terminal comprises: a first set of bits included in a temporary identifier assigned to the wireless terminal by a core network; and a third set of bits that is pre-mapped to the second set of bits included in the temporary identifier and has a shorter length than the second set of bits; Further comprising: 13. The RAN node according to any one of Supplementary Notes 10 to 12. (Appendix 14) the at least one processor is configured to deduce the temporary identifier from the first set of bits and the third set of bits received from the wireless terminal and include the temporary identifier in the authentication request message. 13. The RAN node according to claim 13. (Appendix 15) the at least one processor is configured to periodically broadcast system information including a list indicating a correspondence between the second set of bits and a third set of bits. 15. The RAN node according to claim 13 or 14. (Appendix 16) The temporary identifier is a 5G-S-Temporary Mobile Subscription Identifier (5G-S-TMSI), the first set of bits is a 5G-TMSI; The second set of bits is an Access and Mobility Management Function (AMF) Set ID and an AMF Pointer. 16. The RAN node according to any one of Supplementary Notes 13 to 15. (Appendix 17) the at least one processor is configured to include in the authentication request message a plurality of NAS security parameters received from each of a plurality of wireless terminals that have requested the broadcast of the on-demand system information. 17. The RAN node according to any one of Supplementary Notes 10 to 16. (Appendix 18) the authentication response message is sent by the core network node if authentication of at least one of the plurality of wireless terminals is successful. 17. The RAN node according to claim 17. (Appendix 19) the at least one processor is configured to send an acknowledgement message to the wireless terminal after receiving the message from the wireless terminal; the acknowledgement message indicating a waiting time before broadcasting the on-demand system information begins; 19. The RAN node according to any one of Supplementary Notes 10 to 18. (Appendix 20) the procedure is a random access procedure initiated for a request for the system information. 20. The RAN node according to any one of Supplementary Notes 10 to 19. (Appendix 21) A core network node, At least one memory; at least one processor coupled to the at least one memory; Equipped with The at least one processor: receiving an authentication request message from a Radio Access Network (RAN) node, where the authentication request message includes NAS security parameters sent by the wireless terminal in a procedure in which the wireless terminal requests the RAN node to broadcast on-demand system information; sending an authentication response message to the RAN node indicating success or failure of authentication based on the NAS security parameters; It is configured as follows: Core network node. (Appendix 22) The authentication response message is used by the RAN node to determine whether to broadcast the on-demand system information. 22. A core network node according to claim 21. (Appendix 23) If the authentication response message indicates successful authentication, the authentication response message triggers the RAN node to broadcast the on-demand system information. 23. A core network node according to claim 21 or 22. (Appendix 24) The NAS security parameters include at least some bits of a Message Authentication Code for NAS for Integrity (NAS-MAC) calculated by the wireless terminal; A core network node according to any one of Supplementary Notes 21 to 23. (Appendix 25) the NAS security parameters further include at least a portion of the bits of a NAS COUNT used to calculate the NAS-MAC; 25. A core network node as claimed in claim 24. (Appendix 26) the authentication request message includes a plurality of NAS security parameters received by the RAN node from each of a plurality of wireless terminals that have requested the broadcast of the on-demand system information; A core network node according to any one of Supplementary Notes 21 to 25. (Appendix 27) the at least one processor is configured to, in response to successful authentication of at least one of the plurality of wireless terminals, transmit the authentication response message indicating successful authentication. 27. A core network node according to claim 26. (Appendix 28) 1. A method performed by a wireless terminal, comprising: transmitting a message to a Radio Access Network (RAN) node, the message including a Non-Access Stratum (NAS) security parameter, within a procedure requesting the RAN node to broadcast on-demand system information; method. (Appendix 29) 1. A method performed by a Radio Access Network (RAN) node, comprising: receiving a message from the wireless terminal, the message including Non-Access Stratum (NAS) security parameters, within a procedure in which the wireless terminal requests the RAN node to broadcast on-demand system information; sending an authentication request message to a core network node, the authentication request message including the NAS security parameters, to request authentication of the wireless terminal; and broadcasting the on-demand system information in response to receiving an authentication response message from the core network node indicating successful authentication of the wireless terminal; A method comprising: (Appendix 30) 1. A method performed by a core network node, comprising: receiving an authentication request message from a Radio Access Network (RAN) node, where the authentication request message includes NAS security parameters sent by the wireless terminal in a procedure in which the wireless terminal requests the RAN node to broadcast on-demand system information; and transmitting an authentication response message to the RAN node indicating success or failure of authentication based on the NAS security parameters; A method comprising: (Appendix 31) A program for causing a computer to perform a method for a wireless terminal, comprising: The method comprises transmitting a message to a Radio Access Network (RAN) node, the message including Non-Access Stratum (NAS) security parameters, within a procedure requesting the RAN node to broadcast on-demand system information; program. (Appendix 32) A program for causing a computer to perform a method for a Radio Access Network (RAN) node, comprising: The method comprises: receiving a message from the wireless terminal, the message including Non-Access Stratum (NAS) security parameters, within a procedure in which the wireless terminal requests the RAN node to broadcast on-demand system information; sending an authentication request message to a core network node, the authentication request message including the NAS security parameters, to request authentication of the wireless terminal; and broadcasting the on-demand system information in response to receiving an authentication response message from the core network node indicating successful authentication of the wireless terminal; A program that includes: (Appendix 33) A program for causing a computer to perform a method for a core network node, comprising: The method comprises: receiving an authentication request message from a Radio Access Network (RAN) node, where the authentication request message includes NAS security parameters sent by the wireless terminal in a procedure in which the wireless terminal requests the RAN node to broadcast on-demand system information; and transmitting an authentication response message to the RAN node indicating success or failure of authentication based on the NAS security parameters; A program that includes:

[0106] This application claims priority based on Japanese Patent Application No. 2020-015021, filed on January 31, 2020, the disclosure of which is incorporated herein in its entirety. [Explanation of symbols]

[0107] 1 UE 2gNB 3 AMF 1203 Baseband Processor 1204 Application Processor 1206 Memory 1207 Modules 1304 Processor 1305 Memory 1306 Modules 1402 processor 1403 Memory 1404 Modules

Claims

1. A wireless terminal, means for transmitting a message to a Radio Access Network (RAN) node within a procedure requesting the RAN node to broadcast on-demand system information; The message may include: A 5G TMSI included in a 5G-S-Temporary Mobile Subscription Identifier (5G-S-TMSI) assigned to the wireless terminal by a core network; A bit string that is pre-associated with the AMF set ID and AMF pointer included in the 5G-S-TMSI and is shorter than the total size of the AMF set ID and the AMF pointer; Including, Wireless terminal.

2. A Radio Access Network (RAN) node, comprising: means for receiving a message from a wireless terminal in a procedure in which the wireless terminal requests the RAN node to broadcast on-demand system information; The message may include: A 5G TMSI included in a 5G-S-Temporary Mobile Subscription Identifier (5G-S-TMSI) assigned to the wireless terminal by a core network; A bit string that is pre-associated with the AMF set ID and AMF pointer included in the 5G-S-TMSI and is shorter than the total size of the AMF set ID and the AMF pointer; Including, RAN node.

Citation Information

Patent Citations

  • Network nodes and methods performed therein for enabling communication in a communication network

    US20190045351A1