System and method for secure update of configuration parameters supplied to a user device

The use of NAS messages with security protection mechanisms addresses the inefficiency and security gaps in existing UE configuration updates by enabling secure, transparent updates in mobile networks without dedicated elements, enhancing security and efficiency.

JP7709497B2Active Publication Date: 2025-07-16NOKIA TECHNOLOGIES OY
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023148582
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2018-10-06
Filing Date
2023-09-13
Publication Date
2025-07-16
Estimated Expiration
2039-10-04

AI Technical Summary

Technical Problem

Existing mobile networks require dedicated network elements for over-the-air updates of UE configuration parameters, which is inefficient and lacks end-to-end security for parameter updates.

Method used

Utilizing Non-Access Stratum (NAS) messages for secure and transparent updates of UE configuration parameters through the control plane, employing security protection mechanisms like secured packets and integrity protection using the UE's NAS security context.

Benefits of technology

Provides end-to-end security for UE configuration parameter updates without the need for dedicated network elements, ensuring secure and efficient updates in both next-generation and previous-generation mobile networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007709497000010
    Figure 0007709497000010
  • Figure 0007709497000011
    Figure 0007709497000011
  • Figure 0007709497000012
    Figure 0007709497000012
Patent Text Reader

Abstract

To provide a mobile device and a method that update configuration parameters on user equipment (UE) using control plane functionalities.SOLUTION: An AMF element of a mobile network receives a control plane message from a UDM element, the message including a UE configuration parameter update for UE. The UE configuration parameter update is security protected via a secured packet, integrity protection, etc. The AMF element transparently sends the UE configuration parameter update to the UE. Thus, the AMF element inserts the UE configuration parameter update (that is security protected) in a container of a Non-Access Stratum (NAS) message, and sends the NAS message to the UE. The UE then updates its configuration parameters based on the update when security checks are completed.SELECTED DRAWING: Figure 13
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Cross - Reference to Related Applications This non - provisional patent application claims the priority of U.S. Provisional Patent Application No. 62 / 742,341, filed on October 6, 2018, and is incorporated herein by reference in its entirety as if fully set forth herein.

[0002] This disclosure relates to the field of communication systems, and more particularly to the update of mobile devices.

Background Art

[0003] Service providers or carriers implement mobile networks that provide a number of voice and data services to end - users of mobile phones or other mobile devices / terminals, generally referred to as user equipment (UE). Some examples of voice services are voice calls, call forwarding, in - call incoming calls, etc. Some examples of data services are Internet access, streaming audio, streaming video, online games, Internet Protocol television (IP - TV), etc. A mobile network is a type of network where the last link to the end - user is wireless. A mobile network generally includes a core network and one or more radio access networks (RAN) that exchange signaling and data with the UE via a wireless interface.

[0004] The UE is typically provided with the subscriber's International Mobile Subscriber Identity (IMSI), security authentication, encryption information, and other configuration parameters. There may be cases where the UE's home network needs to update one or more of the UE's configuration parameters. For example, the UE's home network may update the configuration parameters when a subscription change occurs, when a new service is assigned, when the mobile network migrates from Long-Term Evolution (LTE) to a next-generation network, and so on. Therefore, it is beneficial to identify an enhanced procedure for updating the configuration parameters in the UE. Summary of the Invention

[0005] Embodiments described herein provide for updating UE configuration parameters using Non-Access Stratum (NAS) messages. As an overview, a mobile network migrating to a next-generation network may include an Unified Data Management (UDM) and an Access and Mobility Management Function (AMF). The UDM within the UE's home network is configured to assemble a UE configuration parameter update for the UE with security protection (e.g., secured packet, integrity protection, etc.). The UDM sends the security-protected UE configuration parameter update to the AMF. The AMF is then configured to transparently send the UE configuration parameter update to the UE using an NAS message. In this case as well, the UE configuration parameter update is security-protected within the NAS message. The UE is configured to update its UE configuration parameters based on the update provided in the NAS message when it receives the NAS message. One technical advantage of this procedure is that end-to-end security is provided for the UE configuration parameter update. Another technical advantage is that native control plane functions can be used to update the UE configuration parameters. Therefore, no dedicated network element needs to be deployed to provide the update to the UE.

[0006] One embodiment comprises an AMF element of a mobile network. The AMF element includes a processor(s) and a memory including computer program code executable by the processor. The processor is configured to cause the AMF element to receive, from a UDM element, a control plane message including a UE configuration parameter update for the UE. The UE configuration parameter update is security protected according to a protection mechanism. The processor is further configured to cause the AMF element to insert the security protected UE configuration parameter update into a container of a first NAS message, the container being designated for the UE configuration parameter update. The processor is further configured to cause the AMF element to send a first NAS message having a container including the security protected UE configuration parameter update to the UE.

[0007] In other embodiments, the UE configuration parameter update is encapsulated within a secured packet according to a protection mechanism.

[0008] In other embodiments, the UE configuration parameter update is integrity protected using the UE's NAS security context according to a protection mechanism.

[0009] In other embodiments, the UE configuration parameter update is encapsulated within a secured packet, and the secured packet is integrity protected using the UE's NAS security context according to a protection mechanism.

[0010] In other embodiments, the first NAS message comprises a NAS registration acceptance message sent to the UE during a NAS registration procedure. The processor is further configured to cause the AMF element to receive, from the UE during a NAS registration procedure, a second NAS message having a container including a UE confirmation response indicating that a UE configuration parameter update has been received, and to send another control plane message having the UE confirmation response to the UDM element. The second NAS message received from the UE may comprise a NAS registration completion message or an uplink NAS transport message.

[0011] In other embodiments, the first NAS message comprises a downlink NAS transport message of a NAS transport procedure that is executed after the NAS registration procedure. The processor is further configured to cause the AMF element to receive from the UE a second NAS message having a container including a UE confirmation response from the UE indicating that a UE configuration parameter update has been received, and to cause the UDM element to transmit another control plane message having the UE confirmation response. The second NAS message comprises an uplink NAS transport message.

[0012] Other embodiments comprise a method of performing an update procedure for updating UE configuration parameters provided to a UE. The method comprises receiving, at an AMF element, from a UDM element, a control plane message including a UE configuration parameter update for the UE. The UE configuration parameter update is security protected according to a protection mechanism. The method further comprises inserting, at the AMF element, the security protected UE configuration parameter update into a container of a first NAS message, the container being designed for the UE configuration parameter update. The method further comprises transmitting, from the AMF element to the UE, a first NAS message having a container including the security protected UE configuration parameter update.

[0013] In other embodiments, the UE configuration parameter update is encapsulated within a secured packet according to a protection mechanism.

[0014] In other embodiments, the UE configuration parameter update is integrity protected using a UE's NAS security context according to a protection mechanism.

[0015] In other embodiments, the UE configuration parameter update is encapsulated within a secured packet, and the secured packet is integrity protected using a UE's NAS security context according to a protection mechanism.

[0016] In another embodiment, the first NAS message comprises a NAS registration acceptance message sent from the AMF element to the UE during the NAS registration procedure.

[0017] In another embodiment, the method further comprises receiving, at the AMF element from the UE during the NAS registration procedure, a second NAS message having a container that includes a UE confirmation response indicating that a UE configuration parameter update has been received, and sending, from the AMF element to the UDM element, another control plane message having the UE confirmation response. The second NAS message may comprise a NAS registration completion message or an uplink NAS transport message.

[0018] In another embodiment, the first NAS message comprises a downlink NAS transport message of a NAS transport procedure executed after the NAS registration procedure.

[0019] In another embodiment, the method further comprises receiving, at the AMF element from the UE, a second NAS message having a container that includes a UE confirmation response from the UE indicating that a UE configuration parameter update has been received, and sending, from the AMF element to the UDM element, another control plane message having the UE confirmation response. The second NAS message comprises an uplink NAS transport message.

[0020] In another embodiment, the method further comprises receiving, at the UE from the AMF element, a first NAS message having a container that includes a UE configuration parameter update for the UE protected by security, performing a security check at the UE to verify the UE configuration parameter update, and updating one or more of the UE configuration parameters based on the UE configuration parameter update when the UE configuration parameter update is verified.

[0021] In other embodiments, when the first NAS message includes a re-registration indicator, the method further comprises initiating a NAS registration procedure at the UE to re-register using the updated UE configuration parameters at the UE.

[0022] Other embodiments comprise a UE including a universal integrated circuit card (UICC) hosting a universal subscriber identity module (USIM), a processor, and a memory including computer program code executable by the processor. At least one of the UICC and the memory stores UE configuration parameters for the UE. The processor is configured to cause the UE to receive, from an AMF element, a first NAS message having a container including a UE configuration parameter update for the UE that is security protected according to a protection mechanism. The UICC and / or the processor are configured to cause the UE to perform a security check to verify the UE configuration parameter update and, when the UE configuration parameter update is verified, update one or more of the UE configuration parameters based on the UE configuration parameter update.

[0023] In other embodiments, the UE configuration parameter update is encapsulated within a secured packet within the container of the first NAS message.

[0024] In other embodiments, the UE configuration parameter update is integrity protected using the UE's NAS security context.

[0025] In other embodiments, the UE configuration parameter update is encapsulated within a secured packet within the container of the first NAS message, and the secured packet is integrity protected using the UE's NAS security context.

[0026] In other embodiments, the first NAS message comprises a NAS registration acceptance message sent to the UE during a NAS registration procedure.

[0027] In other embodiments, when the NAS registration acceptance message includes a UE confirmation response indicator, the processor is further configured to cause the UE to send a second NAS message having a container including a UE confirmation response from the UE indicating that a UE configuration parameter update has been received to the AMF element. The second NAS message may comprise a NAS registration completion message or an uplink NAS transport message.

[0028] In other embodiments, the first NAS message comprises a downlink NAS transport message for a NAS transport procedure executed after the NAS registration procedure.

[0029] In other embodiments, when the downlink NAS transport message includes a UE confirmation response indicator, the processor is further configured to cause the UE to send an uplink NAS transport message having a container including a UE confirmation response from the UE indicating that a UE configuration parameter update has been received to the AMF element.

[0030] In other embodiments, when the first NAS message includes a reregistration indicator, the processor is further configured to cause the UE to initiate a NAS registration procedure to reregister using the updated UE configuration parameters.

[0031] Other embodiments include an AMF element including means for receiving a control plane message including a UE configuration parameter update for the UE from a UDM element. The UE configuration parameter update is security protected according to a protection mechanism. The AMF element further includes means for inserting the security protected UE configuration parameter update into a container of the first NAS message and means for sending the first NAS message having a container including the security protected UE configuration parameter update to the UE.

[0032] Another embodiment includes a UE comprising means for storing UE configuration parameters for the UE. The UE includes means for receiving, from an AMF element, a first NAS message having a container including a UE configuration parameter update for the UE that is security protected according to a protection mechanism; means for performing a security check to verify the UE configuration parameter update; and means for updating one or more of the UE configuration parameters based on the UE configuration parameter update when the UE configuration parameter update is verified.

[0033] The above summary provides a basic understanding of some aspects of the present specification. This summary is not an extensive overview of the present specification. It is not intended to identify key or critical elements of the present specification nor to delineate the scope of particular embodiments of the present specification or the scope of the claims. Its sole purpose is to present some concepts of the present specification in a simplified form as a prelude to the more detailed description that follows.

[0034] Hereinafter, some embodiments of the present invention will be described by way of example with reference to the accompanying drawings. In all the drawings, the same reference numerals represent the same elements or the same type of elements.

Brief Description of the Drawings

[0035]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Best Mode for Carrying Out the Invention

[0036] The figures and the following description show specific exemplary embodiments. Accordingly, those skilled in the art will understand that, although not explicitly described or illustrated herein, various configurations that embody the principles of the embodiments and are within the scope of the embodiments can be devised. Further, all examples described herein are intended to assist in understanding the principles of the embodiments and should not be construed as being limited to such specifically described examples and conditions. As a result, the concept(s) of the present invention is not limited to the specific embodiments or examples described below, but is limited by the claims and their equivalents.

[0037] Figure 1 shows a mobile network 100 in an exemplary embodiment. The mobile network 100 (also referred to as a cellular network) is a type of network where the last link is wireless and provides voice and / or data services to multiple devices. The mobile network 100 can be a third-generation (3G), fourth-generation (4G), and / or next-generation network (e.g., fifth-generation (5G)).

[0038] The mobile network 100 is illustrated as providing communication services to UE110 (and to other UEs not shown). The UE110 can enable voice services, data services, machine-to-machine (M2M) or machine-type communication (MTC) services, Internet of Things (IoT) services, and / or other services. The UE110 can be an end-user device such as a mobile phone (e.g., a smartphone), a tablet or PDA, a computer having a mobile broadband adapter.

[0039] The mobile network 100 includes one or more radio access networks (RANs) 120 that communicate with the UE 110 via a wireless interface 122. The RAN 120 may support evolved UMTS terrestrial radio access network (E-UTRAN) access, wireless local area network (WLAN) access, fixed access, satellite radio access, new radio access technology (RAT), and the like. As an example, the RAN 120 may include an E-UTRAN or a next-generation RAN (NG-RAN) that includes one or more base stations 124 distributed across a geographical area. The base station 124 may include an entity that uses wireless communication technology to communicate with the UE in licensed spectrum and interface the UE with the core network. The base station 124 within the E-UTRAN is called an evolved NodeB (eNodeB). The base station 124 within the NG-RAN is called a gNodeB (NR base station) and / or an ng-eNodeB (LTE base station supporting a 5G core network). As another example, the RAN 120 may include a WLAN that includes one or more wireless access points (WAPs) 125. The WLAN is a network through which the UE can connect to a local area network (LAN) via a wireless (radio) connection. The WAP 125 is a node that uses wireless communication technology to communicate with the UE over unlicensed spectrum and provides the UE with access to the core network. An example of the WAP 125 is a WiFi access point operating in the 2.4 GHz or 5 GHz wireless band. The term "base station" as used herein may refer to an eNodeB, a gNodeB, an ng-eNodeB, a WAP, and the like.

[0040] UE 110 can connect to cell 126 of RAN 120 and access core network 130. Therefore, RAN 120 represents the radio interface between UE 110 and core network 130. Core network 130 is the central part of mobile network 100 that provides various services to customers connected by RAN 120. An example of core network 130 is the evolved packet core (EPC) network proposed by 3GPP for LTE. Another example of core network 130 is the 5G core network proposed by 3GPP. Core network 130 includes network element 132 which may include servers, devices, apparatuses, or equipment (including hardware) that provide services to UE 110. Network element 132 in the EPC network may include a mobility management entity (MME), a serving gateway (S-GW), a packet data network gateway (P-GW), etc. Network element 132 in the 5G network may include an access and mobility management function (AMF), a session management function (SMF), a policy control function (PCF), an application function (AF), a user plane function (UPF), etc.

[0041] Figure 2 shows an evolved packet core (EPC) network 200, which is the core network of LTE. The EPC network 200 includes a mobility management entity (MME) 214, a serving gateway (S-GW) 215, a packet data network gateway (P-GW) 216, a home subscriber server (HSS) 217, and a policy and charging rules function (PCRF) 218, and may include other elements not shown, such as an IP multimedia subsystem (IMS) application server. In the EPC network 200, user data (also referred to as the "user plane") and signaling (also referred to as the "control plane") are separated. The MME 214 processes the control plane within the EPC network 200. For example, the MME 214 processes signaling related to the mobility and security of E-UTRAN access. The MME 214 is responsible for tracking and paging the idle-mode UE 110. The S-GW 215 and P-GW 216 process the user plane. The S-GW 215 and P-GW 216 transfer data traffic between the UE 110 and an external data network 240 (DN or packet data network (PDN)). The S-GW 215 is an interconnection point between the radio side and the EPC network 200 and provides services to the UE 110 by routing incoming and outgoing IP packets. The S-GW 215 is also an anchor point for mobility within LTE (i.e., in the case of handover between eNodeBs) and between LTE and other 3GPP accesses. The P-GW 216 is an interconnection point between the EPC network 200 and the external data network 240 (i.e., an entry or exit point of the data network 240) and routes packets between the data network 240. The HSS 217 is a database that stores user-related and subscriber-related information. The PCRF 218 is a node or entity in the EPC network 200 that provides a policy and charging control (PCC) solution in the EPC network 200 and formulates PCC rules for the services requested by the end user.

[0042] MME214 is connected to RAN120 (i.e., eNodeB) via the S1-MME interface, and S-GW215 is connected to RAN120 via the S1-U interface. MME214 is connected to S-GW215 via the S11 interface and to HSS217 via the S6a interface. PCRF218 is connected to P-GW216 via the Gx interface, thereby providing the transfer of policy and charging rules from PCRF218 to the policy and charging enforcement function (PCEF) within P-GW216. PCRF218 is connected to S-GW215 via the Gxx interface, and S-GW215 is connected to P-GW216 via the S5 interface.

[0043] Figure 3 shows a non-roaming architecture 300 of a next-generation network. The architecture in Figure 3 is in reference point representation and is further described in 3GPP TS23.501 (v15.3.0), which is incorporated herein by reference as if fully set forth herein. Architecture 300 consists of network functions (NFs) of the core network, and the network functions of the control plane are separated from the user plane. The control plane of the core network includes an authentication server function (AUSF) 310, an integrated data management (UDM) 312, a network slice selection function (NSSF) 313, an access and mobility management function (AMF) 314, a session management function (SMF) 316, a policy control function (PCF) 318, and an application function (AF) 320. The user plane of the core network includes one or more user plane functions (UPF) 324 that communicate with the data network 240. UE110 can access the control plane and the user plane of the core network via (R)AN120.

[0044] AUSF310 is configured to support the authentication of UE110. UDM312 is configured to store the subscription data / information of UE110. UDM312 may store three types of user data related to subscription, policy, and session context (e.g., the location of the UE). AMF314 is configured to provide UE-based authentication, authorization, mobility management, etc. SMF316 is configured to provide the following functions, namely, session management (SM), allocation and management of UE Internet Protocol (IP) addresses, selection and control of UPF(s), termination of the interface to PCF318, policy enforcement and the control part of service quality (QoS), lawful interception, termination of the SM part of NAS messages, downlink data notification (DNN), roaming function, local enforcement processing for applying the QoS of service level agreement (SLA), charging data collection and charging interface, etc. When UE110 has multiple sessions, different SMFs may be assigned to each session for individual management and may provide different functions for each session in some cases. PCF318 supports a unified policy framework for managing the behavior of the network and is configured to provide policy rules for control plane functions such as QoS enforcement, charging, access control, traffic routing, etc. AF320 provides information related to the packet flow to PCF318. Based on this information, PCF318 is configured to determine policy rules related to mobility and session management to properly operate AMF314 and SMF316.

[0045] UPF324 supports various user plane operations and functions, such as packet routing and forwarding, traffic processing (e.g., QoS enforcement), an anchor point for in-RAT / inter-RAT mobility (if applicable), packet inspection and policy rule enforcement, lawful interception (UP collection), traffic accounting and reporting, etc. The data network 240 is not part of the core network and provides Internet access, operator services, third-party services, etc. For example, the International Telecommunication Union (ITU) classifies 5G mobile network services into three categories: high-speed large-capacity (eMBB), ultra-high-reliability low-latency communication (uRLLC), massive machine-type communication (mMTC) or massive Internet of Things (MIoT). eMBB focuses on services with high bandwidth requirements, such as HD video, virtual reality (VR), augmented reality (AR), etc. uRLLC focuses on services that are sensitive to latency, such as autonomous driving and remote management. mMTC and MIoT focus on services that include high requirements for connection density, such as smart cities and smart agriculture. The data network 240 can be configured to provide these and other services.

[0046] The architecture 300 includes the following reference points. The N1 reference point is implemented between the UE 110 and the AMF 314. The N2 reference point is implemented between the (R)AN 120 and the AMF 314. The N3 reference point is implemented between the (R)AN 120 and the UPF 324. The N4 reference point is implemented between the SMF 316 and the UPF 324. The N5 reference point is implemented between the PCF 318 and the AF 320. The N6 reference point is implemented between the UPF 324 and the data network 240. The N7 reference point is implemented between the SMF 316 and the PCF 318. The N8 reference point is implemented between the UDM 312 and the AMF 314. The N9 reference point is implemented between two UPFs 324. The N10 reference point is implemented between the UDM 312 and the SMF 316. The N11 reference point is implemented between the AMF 314 and the SMF 316. The N12 reference point is implemented between the AMF 314 and the AUSF 310. The N13 reference point is implemented between the UDM 312 and the AUSF 310. The N14 reference point is implemented between two AMFs. The N15 reference point is implemented between the PCF 318 and the AMF 314 in a non-roaming scenario. The N22 reference point is implemented between the NSSF 313 and the AMF 314.

[0047] Figure 4 shows the roaming architecture 400 of the next-generation network. The architecture in Figure 4 is a local breakout scenario in reference point representation, which is further described in 3GPP TS 23.501 (v15.3.0). In the roaming scenario, the visited public land mobile network (VPLMN) 402 and the home PLMN (HPLMN) 404 are shown. The HPLMN 404 identifies the PLMN in which the mobile subscriber's profile is held. The VPLMN is the PLMN in which the mobile subscriber is roaming when leaving the HPLMN. A user roaming in another network receives subscription information from the HPLMN 404. In the local breakout scenario, the PCF 318 (hPCF), the UDM 312, and the AUSF 310 are present within the HPLMN 404 of the UE 110. Other network functions including the visited PCF (vPCF) 418 are present within the VPLMN 402.

[0048] FIG. 5 shows a radio protocol stack 500 such as the wireless interface 122. As described herein, the user plane 512 includes a set of protocols used to transfer actual user data over the network, and the control plane 514 includes protocols used to control and establish user connections and bearers within the network. With respect to the user plane 512 and the control plane 514, the radio protocol stack 500 includes a physical (PHY) layer 501, a media access control (MAC) layer 502, a radio link control (RLC) layer 503, and a packet data convergence protocol (PDCP) layer 504. The control plane 514 further includes a radio resource control (RRC) layer 505 and a non-access stratum (NAS) layer 506.

[0049] The physical layer 501 transmits all information from the MAC transport channel via the wireless interface. Data and signaling messages are transmitted on physical channels between different levels of the physical layer 501. The physical channels are divided into physical data channels and physical control channels. The physical data channels can include a physical downlink shared channel (PDSCH), a physical broadcast channel (PBCH), a physical multicast channel (PMCH), a physical uplink shared channel (PUSCH), and a physical random access channel (PRACH). The physical control channels can include a physical control format indicator channel (PCFICH), a physical hybrid ARQ indicator channel (PHICH), a physical downlink control channel (PDCCH), and a physical uplink control channel (PUCCH).

[0050] The MAC layer 502 is responsible for the mapping between logical channels and transport channels, multiplexing MAC service data units (SDUs) from one or different logical channels into transport blocks (TBs) that are delivered to the physical layer on the transport channel, demultiplexing MAC SDUs from one or different logical channels from the transport blocks delivered from the physical layer on the transport channel, reporting scheduling information, error correction by hybrid automatic repeat request (HARQ), prioritization among UEs by dynamic scheduling, prioritization among the logical channels of one UE, and prioritization of logical channels. The RLC layer 503 is responsible for the transfer of protocol data units (PDUs) of the upper layer, error correction by ARQ, and concatenation, segmentation, and reconstruction of RLC SDUs. The RLC layer 503 is also responsible for resegmentation of RLC data PDUs, rearrangement of RLC data PDUs, duplicate detection, discarding of RLC SDUs, RLC re-establishment, and detection of protocol errors. The PDCP layer 504 is responsible for header compression and decompression of IP data, transfer of data (user plane or control plane), maintenance of PDCP sequence numbers (SNs), in-order delivery of upper layer PDUs upon re-establishment of the lower layer, duplicate elimination of lower layer SDUs upon re-establishment of the lower layer of radio bearers mapped in RLC acknowledged mode (AM), encryption and decryption of user plane data and control plane data, integrity protection and integrity verification of control plane data, discard based on timers, duplicate discard, etc. The RRC layer 505 is responsible for broadcasting system information related to NAS, broadcasting system information related to the access stratum (AS), paging, establishment, maintenance, and release of the RRC connection between the UE and the RAN, security functions including key management, establishment, configuration, maintenance, and release of point-to-point radio bearers (RBs). The NAS layer 506 represents the top layer of the control plane 514 between the UE and the core network (e.g., MME / AMF), supports UE mobility and session management procedures, and establishes and maintains an IP connection between the UE and the core network.

[0051] Each UE 110 receiving services from a mobile network is supplied with configuration parameters. The home network (i.e., HPLMN) may desire to update one or more of the configuration parameters within the UE. In previous mobile networks, the update of configuration parameters was performed using an over-the-air (OTA) mechanism. In the OTA mechanism, it was necessary to deploy a dedicated network element called an OTA gateway. When the update of configuration parameters was performed, the network operator's backend system sent a service request to the OTA gateway. Various OTA "bearers" were specified to send service requests such as the Short Message Service (SMS), Unstructured Supplementary Service Data (USSD), Hypertext Transfer Protocol (HTTP), etc. to the UE. The OTA gateway mapped the service request to an OTA "bearer" so that the service request was sent to the UE. For example, when the SMS bearer was used, the OTA gateway encapsulated the updated configuration parameters in one or more SMS messages. Next, the OTA gateway sent the SMS message to the Short Message Service Center (SMSC), and the SMS center sent the SMS message to the UE. It is desirable to provide a native control plane solution that the network operator can use to update UE configuration parameters without deploying a dedicated network element such as an OTA gateway. Also, it is desirable to provide a solution in which UE configuration parameters are security protected.

[0052] In the embodiments described in this specification, the network transparently sends a security-protected UE configuration parameter update to the UE via a control plane NAS message. For example, the UE configuration parameter update can be security-protected using a secured packet, using the integrity protection key of the NAS security context, or both. When receiving a UE configuration parameter update in a NAS message, the UE may update its own UE configuration parameters. The solution provided in this specification is described in relation to a next-generation network (e.g., 5G), but similar solutions may be provided in previous or subsequent generation networks. Further details of the embodiments are shown below.

[0053] FIG. 6 is a block diagram of UE 110 in an exemplary embodiment. UE 110 includes a wireless interface component 602, one or more processors 604, a memory 606, a user interface component 608, and a battery 610. The wireless interface component 602 is a hardware component representing the local wireless resources of UE 110, such as an RF unit 620 (e.g., a transceiver) and one or more antennas 622, which are used for wireless communication with a base station (e.g., base station 124) via wireless or “over-the-air” signals. The processor 604 represents the internal circuitry, logic, hardware, software, etc. that provide the functionality of UE 110. The processor 604 can be configured to execute software instructions 640 loaded into the memory 606. The processor 604 can include a set of one or more processors or can include multi-processor cores, depending on the particular embodiment. The processor 604 can execute one or more applications 630. These applications 630 can access downlink (DL) data via RAN 120 and the core network 130 and can also generate uplink (UL) data for transfer to a destination via RAN 120 and the core network 130. The memory 606 is a computer-readable storage medium for data, instructions 640, applications, etc., and is accessible by the processor 604. The memory 606 is a hardware storage device capable of storing information temporarily and / or permanently. The memory 606 can include random access memory (RAM) or any other volatile or non-volatile storage device. The user interface component 608 is a hardware component for interacting with an end user. For example, the user interface component 608 can include a display 650, a screen, a touch screen, etc. (e.g., a liquid crystal display (LCD), a light-emitting diode (LED) display, etc.).The user interface component 608 may include a keyboard or keypad 652, a tracking device (e.g., trackball or track pad), a speaker, a microphone, etc.

[0054] UE 110 also includes a Universal Integrated Circuit Card (UICC) 660, which is a hardware device that provides security and integrity functions to the UE 110. Although not shown in FIG. 6, the UICC 660 may include a processor (i.e., a central processing unit (CPU)), a memory (e.g., read-only memory (ROM), RAM, electrically erasable programmable read-only memory (EEPROM)), and input / output (I / O) circuitry. The UICC 660 may host or store a Universal Subscriber Identity Module (USIM) 662 that stores information such as an International Mobile Subscriber Identity (IMSI), security authentication and encryption information, and other home operator configuration information.

[0055] The UICC 660 and / or the memory 606 may store home operator information used to configure the UE 110, which is referred to herein as UE configuration parameters 664. One or more of the UE configuration parameters 664 may be used exclusively by the UICC 660, and one or more of the UE configuration parameters 664 may be used by the processor 604. The UE configuration parameters 664 may include a routing indicator, a home network identifier (e.g., PLMN identification information and MCC / MNC information), a home network protection scheme identifier, a home network public key identifier, a home network public certificate, network selection information (e.g., a list of operator-controlled PLMN selectors using access technologies), and / or other information. The UE configuration parameters 664 may represent data pre-supplied by the network operator or data supplied by the network through update procedures discussed below. The UE 110 may include various other components not specifically shown in FIG. 6.

[0056] FIG. 7 is a functional model of the UE 110 in an exemplary embodiment. The UE 110 can be subdivided into domains such as a mobile device (ME) 702 and a USIM 662. As described above, the functions of the USIM 662 can be executed by a processor and memory on the UICC 660. The functions of the ME 702 can be executed by the processor 604 and the memory 606. The ME 702 performs wireless transmission and includes applications. The USIM 662 includes data and procedures for uniquely and securely identifying itself. These functions are typically incorporated into a stand-alone smart card such as the UICC 660. As described above, one or more of the UE configuration parameters 664 can be exclusively stored in the USIM 662 for use or processing within the UICC 660, and one or more of the UE configuration parameters 664 can be exclusively stored in the ME 702 for use or processing within the ME 702.

[0057] FIG. 8 is a block diagram of an AMF element 314 in an exemplary embodiment. As described above, the AMF element 314 is configured to provide UE-based authentication, authorization, mobility management, etc. In this embodiment, the AMF element 314 includes the following subsystems operating on one or more platforms, namely, a network interface component 802 and an update manager 804. The network interface component 802 may include circuits, logic, hardware, means, etc. configured to exchange control plane messages or signaling with other network elements and / or UEs (e.g., via the RAN 120). The network interface component 802 may operate using various protocols (including the NAS protocol) or reference points. The update manager 804 may include circuits, logic, hardware, means, etc. configured to handle the update of UE configuration parameters in the UE. One or more of the subsystems of the AMF element 314 may be implemented on a hardware platform composed of analog and / or digital circuits. One or more of the subsystems of the AMF element 314 may be implemented on a processor 830 that executes instructions stored in a memory 832. The processor 830 includes an integrated hardware circuit configured to execute instructions, and the memory 832 is a non-transitory computer-readable storage medium for data, instructions, applications, etc., and is accessible by the processor 830. The AMF element 314 may include various other components not specifically shown in FIG. 8.

[0058] FIG. 9 is a block diagram of a UDM element 312 in an exemplary embodiment. As described above, the UDM element 312 is configured to store access and mobility subscription data of a UE. In this embodiment, the UDM element 312 includes the following subsystems operating on one or more platforms, namely, a network interface component 902, a subscriber data repository 904, and an update manager 906. The network interface component 902 may include circuits, logic, hardware, means, etc. configured to exchange control plane messages or signaling with other network elements. The network interface component 902 may operate using various protocols or reference points. The subscriber data repository 904 may include circuits, logic, hardware, means, etc. configured to store access and mobility subscription data. The update manager 906 may include circuits, logic, hardware, means, etc. configured to process updates of UE configuration parameters in the UE. One or more of the subsystems of the UDM element 312 may be implemented on a hardware platform composed of analog and / or digital circuits. One or more of the subsystems of the UDM element 312 may be implemented on a processor 930 that executes instructions stored in a memory 932. The UDM element 312 may include various other components not specifically shown in FIG. 9.

[0059] When the UE registers with the network or after the UE has registered with the network, an update procedure may be executed or invoked. FIGS. 10-12 show general update procedures executed by the UDM element 312, the AMF element 314, and the UE 110. Further details of the update procedure will be described in the following exemplary message diagrams. Therefore, the flowcharts provided in this specification may be supplemented by the update procedures described in relation to the message diagrams.

[0060] FIG. 10 is a flowchart illustrating a method 1000 for performing an update procedure in a UDM element 312 in an exemplary embodiment. The steps of method 1000 will be described with reference to the UDM element 312 of FIG. 9, but one of ordinary skill in the art will understand that method 1000 may be performed on other network elements or devices. Also, the steps of the flowchart described herein are not all inclusive and may include other steps not shown, and the steps may be performed in an alternative order.

[0061] In this embodiment, it may be assumed that the UE 110 is registered with the network via the NAS registration procedure or is already registered with the network. The update manager 906 of the UDM element 312 initiates an update procedure to update one or more of the UE configuration parameters 664 within the UE 110 (step 1002). For example, the update manager 906 may process the UE configuration information stored in the subscriber data repository 904 and determine that an update to the UE configuration parameters 664 is necessary or desirable. The update manager 906 assembles a UE configuration parameter update for the UE 110 (step 1004). The UE configuration parameter update includes information, commands, instructions, etc. used to perform an update of the UE configuration parameters 664 in the UE 110. For example, the UE configuration parameter update may include one or more updated UE configuration parameters of the UE 110 as part of the access and mobility subscription data.

[0062] The Update Manager 906 applies security protection to the UE configuration parameter update according to one or more protection mechanisms (step 1006). In one embodiment, the protection mechanism can be a secured packet. Thus, the Update Manager 906 can configure or encapsulate the UE configuration parameter update within a secured packet to apply security protection (optional step 1008). Generally, a secured packet contains an application message to which a specific mechanism has been applied. The application message is a command or data exchanged between a network element and the UICC. The transmitter adds a security header (command header) at the beginning of the application message and applies the required security to a part of the command header and the entire application message. The resulting structure is called a (secured) command packet that contains the secured data as the payload. The Update Manager 906 can access a local secured packet library or a remote secured packet library to configure or encapsulate the UE configuration parameter update within a secured packet. In other embodiments, the protection mechanism can be integrity protection. Thus, the Update Manager 906 can apply integrity protection to the UE configuration parameter update using the NAS security context of the UE 110 (optional step 1010). NAS security is used to securely deliver NAS signaling messages between the UE 110 and the AMF element 314 in the control plane using a NAS security key. The NAS security context is a collection of NAS security keys and parameters used to protect NAS messages. The NAS security key is generated when the UE 110 is authenticated to the network. Thus, after authentication, the Update Manager 906 can apply integrity protection to the UE configuration parameter update using the integrity protection key of the NAS security context.In yet other embodiments, the update manager 906 may protect the UE configuration parameter update using both the securitized packet and the NAS security context (optional step 1012). Next, the update manager 906 may insert or otherwise include the security-protected UE configuration parameter update into the control plane message (step 1014).

[0063] The update manager 906 may also insert or otherwise include a UE confirmation response indicator into the control plane message (optional step 1016). The UE confirmation response indicator may be included when the home network desires a confirmation response from the UE 110 regarding the success of the security check of the UE configuration parameter update. The update manager 906 may also insert or otherwise include a reregistration indicator into the control plane message (optional step 1016). The reregistration indicator may be included when the home network desires the UE 110 to reregister with the network using the updated UE configuration parameters. Next, the update manager 906 transmits, via the network interface component 902, a control plane message including the security-protected UE configuration parameter update and the UE confirmation response indicator and / or the reregistration indicator (if requested) to the AMF element 314 (step 1018).

[0064] FIG. 11 is a flowchart illustrating a method 1100 for performing an update procedure at the AMF element 314 in an exemplary embodiment. The steps of method 1100 will be described with reference to the AMF element 314 of FIG. 8, but those skilled in the art will understand that method 1100 may be performed at other network elements or devices.

[0065] The update manager 804 of the AMF element 314 receives, via the network interface component 802, a control plane message including a security-protected UE configuration parameter update from the UDM element 312 (step 1102). The update manager 804 inserts the security-protected UE configuration parameter update into a container of the NAS message (step 1104). The transmission of the security-protected UE configuration parameter update is considered to be "transparent" to the AMF element 314. Therefore, the update manager 804 is programmed to transfer the security-protected UE configuration parameter update without modification or change. Thus, the update manager 804 may insert the security-protected UE configuration parameter update received in the control plane message from the UDM element 312 into a "transparent" container designed for the UE configuration parameter update. An example of such a transparent container will be described in more detail below.

[0066] The type of NAS message used by the AMF element 314 to transfer the security-protected UE configuration parameter update may depend on the NAS procedure being executed. For example, when the NAS registration procedure is being executed, the NAS message may include a NAS registration acceptance message. When the NAS transport procedure is being executed, the NAS message may include a DL NAS transport message. Next, the update manager 804 sends the NAS message to the UE 110 via the network interface component 802 (step 1106).

[0067] FIG. 12 is a flowchart showing a method 1200 for performing an update procedure at the UE 110 in an exemplary embodiment. The steps of the method 1200 will be described with reference to the UE 110 of FIGS. 6 and 7, but those skilled in the art will understand that the method 1200 may be executed on other devices.

[0068] UE110 receives NAS messages from the AMF element 314 (e.g., via the ME702) (step 1202). The ME702 or the USIM662 performs a security check to verify that the security-protected UE configuration parameter update contained in the container of the NAS message has been provided by the home network of the UE110 (i.e., the HPLMN) (step 1204). For example, the ME702 or the USIM662 may calculate a checksum to determine whether the received security-protected UE configuration parameter update matches the security-protected UE configuration parameter update sent by the UDM element 312. When the security check fails, the ME702 or the USIM662 discards the security-protected UE configuration parameter update (step 1206). When the security check succeeds, the ME702 or the USIM662 updates one or more UE configuration parameters 664 provided to the UE110 based on the UE configuration parameter update (step 1208). As described above, the UE configuration parameter update may be encapsulated within a secured packet. In this scenario, the USIM662 is configured to decrypt or unpack the UE configuration parameter update from the secured packet using a secured packet library. Next, the USIM662 updates one or more UE configuration parameters 664 that are local to the USIM662 based on the UE configuration parameter update.

[0069] When the NAS message includes a UE confirmation response indicator, the ME702 or the USIM662 sends a NAS message having a container including the UE confirmation response to the AMF element 314 (optional step 1210). The transmission of the UE confirmation response is considered to be "transparent" to the AMF element 314. Accordingly, the ME702 or the USIM662 is programmed to insert the UE confirmation response into a "transparent" container designed for the UE confirmation response. An example of such a transparent container will be described in more detail below.

[0070] The type of NAS message may depend on the NAS procedure being executed. For example, when the NAS registration procedure is being executed, the NAS message may include a NAS registration completion message or a UL NAS transport message. When the NAS transport procedure is being executed, the NAS message may include a UL NAS transport message.

[0071] In FIG. 11, the update manager 804 of the AMF element 314 receives, via the network interface component 802, a NAS message having a container including a UE confirmation response from the UE 110 (optional step 1108). Next, the update manager 804 transmits, via the network interface component 802, a control plane message having a UE confirmation response to the UDM element 312 (optional step 1110). In FIG. 10, the update manager 906 of the UDM element 312 receives, via the network interface component 902, a control plane message having a UE confirmation response from the AMF element 314 (optional step 1020). Next, the update manager 906 verifies that the UE confirmation response was provided by the UE 110 (optional step 1022).

[0072] In FIG. 12, when the NAS message from the AMF element 314 includes a reregistration indicator, the UE 110 starts (e.g., via the ME 702) the NAS registration procedure to reregister using the updated UE configuration parameters (optional step 1212). Thereafter, the update procedure may end.

[0073] Hereinafter, an example of executing the update procedure in a further embodiment is provided.

[0074] Example 1: Update Procedure During Registration Using Secured Packets Figure 13 is a message diagram showing the registration update procedure in an exemplary embodiment. In this embodiment, UE110 is in the idle mode (e.g., RRC_IDLE). UE110 starts the NAS registration procedure by sending a NAS registration request to the AMF element 314 (S1). In response to the NAS registration request (of type "new"), the AMF element 314 may start an authentication procedure to authenticate UE110 (S2). For the authentication procedure, the AMF element 314 may communicate with the AUSF element 310 and the UDM element 312. For example, the AMF element 314 may send an authentication request (i.e., Nausf_UEAuthentication_Authenticate request) to the AUSF element 310. In response to receiving the authentication request, the AUSF element 310 may send an authentication request (i.e., Nudm_UEAuthentication_Get request) to the UDM element 312. The UDM element 312 hosts functions related to the Authentication Repository and Processing Function (ARPF) that selects an authentication method and calculates (if necessary) the authentication data and key material (e.g., tokens) for the AUSF element 310. The UDM element 312 may send an authentication response (i.e., Nudm_UEAuthentication_Get response) containing an authentication vector (AV) and other information to the AUSF element 310. Next, the AUSF element 310 may send an authentication response (i.e., Nuasf_UEAuthentication_Authenticate response) containing the AV and other information to the AMF element 314. The AMF element 314 is configured to execute an authentication procedure with UE110 using the information provided by the UDM / AUSF. For example, the AMF element 314 may send the authentication request together with the authentication token from the AV to UE110, and UE110 attempts to verify the authentication token. If successful, UE110 calculates a response token and sends an authentication response with the response token, which is received by the AMF element 314. The AMF element 314 may format or generate another authentication request (i.e., Nausf_UEAuthentication_Authenticate request) and insert the response token from UE110 into the authentication request together with other information.Next, the AMF element 314 may send an authentication request to the AUSF element 310. The AUSF element 310 may verify whether the response token from the UE 110 matches the expected response token and send an authentication response (i.e., Nausf_UEAuthentication_Authenticate response) indicating success / failure of authentication to the AMF element 314.

[0075] After authentication, the AMF element 314 may initiate NAS security procedures for establishing a NAS security context (S3). As part of the NAS security procedures, the AMF element 314 selects NAS security algorithms (or a plurality of algorithms) for encryption and integrity protection. Next, the AMF element 314 sends a security mode command message indicating the NAS security algorithm(s), ngKSI, and other information to the UE 110. The UE 110 derives corresponding keys for protecting subsequent NAS messages using the ngKSI and the NAS security algorithm. As a result, a NAS security context is established between the UE 110 and the AMF element 314. Next, the UE 110 sends a security mode complete message to the AMF element 314.

[0076] As a further part of the NAS registration procedure, the AMF element 314 sends a subscription data request (e.g., Nudm_SDM_Get message) to the UDM element 312 of the HPLMN to obtain, among other information, the access and mobility subscription data of the UE 110 (S4). When the user subscription information indicates to start a UE configuration parameter update (e.g., routing ID update), the UDM element 312 starts the update procedure. The UDM element 312 assembles a UE configuration parameter update that includes one or more updated UE configuration parameters. Next, the UDM element 312 applies security protection to the UE configuration parameter update by accessing the security packet library and encapsulating the UE configuration parameter update within a security packet. An example of a security packet and a security packet structure is disclosed in 3GPP TS131.115 (v.9.0.0), which is incorporated herein by reference as if fully set forth herein. Next, the UDM element 312 sends a subscription data response (e.g., Nudm_SDM_Get response) including the security packet to the AMF element 314 (S5). The UDM element 312 may also include a UE confirmation response indicator and / or a reregistration indicator in the subscription data response.

[0077] As yet another part of the registration procedure, the AMF element 314 may also send a subscribe message (e.g., Nudm_SDM_Subscribe) to the UDM element 312 to subscribe to notifications of changes in UE configuration parameters (not shown in FIG. 13).

[0078] The AMF element 314 is configured to transparently transmit the secured packet to the UE 110 as part of the update procedure. Accordingly, the AMF element 314 formats or generates the NAS registration acceptance message and inserts the secured packet into the container of the NAS registration acceptance message. The AMF element 314 may also insert a UE confirmation response indicator and / or a reregistration indicator (if applicable) into the container of the NAS registration acceptance message. Next, the AMF element 314 transmits the NAS registration acceptance message to the UE 110 (S6).

[0079] In this embodiment, the container of the NAS registration acceptance message is designed for UE configuration parameter update. Table 1 shows an example of the message content of the NAS registration acceptance message.

[0080] [Table 1]

[0081] In this example, the NAS registration acceptance message includes a newly defined UE configuration parameter update container information element (IE). Further description of the NAS protocol can be found in 3GPP TS24.301 (v15.4.0), which is incorporated herein by reference as if fully set forth herein. Table 2 is an example of the UE configuration parameter update container IE. Since the AMF element 314 inserts the secured packet into the container without modifying the secured packet, this container is considered transparent.

[0082] [Table 2]

[0083] Table 3 shows an example of the UE configuration parameter update header of the UE configuration parameter update container IE.

[0084] [Table 3]

[0085] In the header, the RRR bit can be used as a re-registration indicator. The UE ACK bit can be used as a UE confirmation response indicator. The data type bit can be used to indicate whether the container is used in a NAS message sent from the network to the UE (e.g., value = 0) or in a NAS message sent from the UE to the network (e.g., value = 1).

[0086] When ME702 receives a NAS registration acceptance message, it may operate as if it has received an SMS message with the protocol identifier set to "SIM data download", the data encoding method set to "class 2 message", and the SMS payload being a secured packet. ME702 routes or uploads the secured packet to USIM662 (S7). USIM662 performs a security check to verify that the secured packet was sent by the UDM element 312 of the home network. If the security check fails, USIM662 discards the UE configuration parameter update and continues the registration procedure. If the security check succeeds, USIM662 uses the secured packet library to unpack the UE configuration parameter update from the secured packet. After verifying the integrity / replay protection of the secured packet, USIM662 updates one or more of the UE configuration parameters 664 based on the UE configuration parameter update.

[0087] If the network requests a confirmation response from UE110 and the security check is successful, USIM662 may send the UE confirmation response to ME702 (S8). ME702 formats or generates other NAS messages and transfers the UE confirmation response to AMF element 314. In the example shown in FIG. 13, ME702 formats the NAS registration complete message and inserts the UE confirmation response into the container of the NAS registration complete message. The container of the NAS registration complete message is designed for the UE confirmation response. Table 4 shows an example of the message content of the NAS registration complete message.

[0088]

Table 4

[0089] In this example, the NAS registration complete message includes a newly defined UE confirmation response container IE. Table 5 is an example of the UE confirmation response container IE.

[0090]

Table 5

[0091] Table 6 shows an example of the UE confirmation response header.

[0092]

Table 6

[0093] In other examples, USIM662 may apply security protection to the UE confirmation response by accessing the secure packet library and encapsulating the UE confirmation response within a secure packet. Therefore, ME702 may insert the secure packet into the UE confirmation response container IE.

[0094] Next, ME702 sends a NAS registration completion message having a container including a UE confirmation response to AMF element 314 (S9). AMF element 314 sends an information message having a UE confirmation response (e.g., Nudm_SDM_Info message) to UDM element 312 (S10). Next, UDM element 312 may verify that the UE confirmation response was provided by UE110.

[0095] In the alternative example shown in FIG. 13, ME702 may use another type of NAS message to send a UE confirmation response to AMF element 314. In this alternative example, ME702 formats a UL NAS transport message and inserts the UE confirmation response into a container of the UL NAS transport message. In the payload container IE of the UL NAS transport message, the payload container type value may be designed for the UE confirmation response. Next, ME702 sends a UL NAS transport message having a container including the UE confirmation response to AMF element 314 (S9a). Then, AMF element 314 sends an information message having a UE confirmation response (e.g., Nudm_SDM_Info message) to UDM element 312 (S10a).

[0096] The network indicates that re-registration of UE110 is required. If the security check is successful, UE110 deregisters and uses the updated UE configuration parameters to restart a new NAS registration procedure (S11).

[0097] Example 2: Update procedure after registration using a secured packet Figure 14 is a message diagram showing the post-registration update procedure in an exemplary embodiment. In this embodiment, UE 110 is already registered with the network and is in the connected mode (i.e., RRC-CONNECTED). At some point after registration, the UDM element 312 may receive a command or process a local policy and determine that the UE configuration parameters in UE 110 need to be updated. Accordingly, the UDM element 312 starts the update procedure and assembles the UE configuration parameter update. Next, the UDM element 312 applies security protection to the UE configuration parameter update by accessing the secure packet library and encapsulating the UE configuration parameter update in a secure packet. Next, the UDM element 312 sends an update notification (e.g., Nudm_SDM_UpdateNotification) including the secure packet to the AMF element 314 (S1). The UDM element 312 may also include a UE confirmation response indicator and / or a reregistration indicator in the update notification.

[0098] As part of the update procedure, the AMF element 314 is configured to transparently send the secure packet to UE 110. Accordingly, the AMF element 314 formats or generates a downlink (DL) NAS transport message and inserts the secure packet into the container of the DL NAS transport message. The AMF element 314 may also insert a UE confirmation response indicator and / or a reregistration indicator (if applicable) into the container of the DL NAS transport message. In this embodiment, the container of the DL NAS transport message is designed for UE configuration parameter update. The AMF element 314 may set the payload container type IE to "UE configuration parameter container" and set the payload container IE to the secure packet. Next, the AMF element 314 sends the DL NAS transport message to UE 110 (S2).

[0099] When ME702 receives a DL NAS transport message, it may operate as if it has received an SMS message with the protocol identifier set to "SIM Data Download", the data encoding scheme set to "Class 2 Message", and the SMS payload being a secured packet. ME702 routes or uploads the secured packet to USIM662 (S3). USIM662 performs a security check to verify that the secured packet was sent by the UDM element 312 of the home network. If the security check fails, USIM662 discards the UE configuration parameter update. If the security check succeeds, USIM662 unpacks the UE configuration parameter update from the secured packet using the secured packet library. After verifying the integrity / replay protection of the secured packet, USIM662 updates one or more of the UE configuration parameters 664 based on the UE configuration parameter update.

[0100] If the network requests a confirmation response from UE110 and the security check succeeds, USIM662 may send the UE confirmation response to ME702 (S4). ME702 formats or generates a UL NAS transport message and inserts the UE confirmation response into the container of the UL NAS transport message. The container of the UL NAS transport message is designed for the UE confirmation response. Next, ME702 sends a UL NAS transport message having the container containing the UE confirmation response to the AMF element 314 (S5). The AMF element 314 sends an information message (e.g., Nudm_SDM_Info message) having the UE confirmation response to the UDM element 312 (S6). Next, the UDM element 312 may verify that the UE confirmation response was provided by UE110.

[0101] The network indicates that re-registration of UE110 is necessary. If the security check is successful, UE110 deregisters and uses the updated UE configuration parameters to restart the new NAS registration procedure (not shown).

[0102] Example 3: Update procedure during registration using a security key FIG. 15 is a message diagram showing the registration update procedure in an exemplary embodiment. In this embodiment, UE 110 starts the NAS registration procedure by sending a NAS registration request to AMF element 314 (S1). In response to the NAS registration request (of type "new"), AMF element 314 may start an authentication procedure to authenticate UE 110 (S2). When UE 110 is authenticated to the network, AMF element 314 may start NAS security procedures to establish a NAS security context (S3). With UE 110 authenticated and the NAS security context established, AMF element 314 sends a subscription data request (e.g., Nudm_SDM_Get message) to the UDM element 312 of the HPLMN to obtain, among other information, the access and mobility subscription data of UE 110 (S4). When the user subscription information indicates to start a UE configuration parameter update (e.g., routing ID update), UDM element 312 starts the update procedure. UDM element 312 assembles the UE configuration parameter update and applies integrity protection to the UE configuration parameter update using the NAS security context of UE 110. To do so, UDM element 312 sends a protection request (e.g., Nausf_ParameterProtectionRequest) with the UE configuration parameter update to AUSF element 310 (S5). AUSF element 310 identifies the NAS count (constructed from the NAS sequence number) and calculates integrity protection information based on the NAS security context of UE 110, e.g., the AUSF message authentication code (MAC) and NAS count of the UE configuration parameter update. AUSF element 310 may also calculate the MAC (X-UE-MAC) expected from UE 110. Next, AUSF element 310 sends a protection response (e.g., Nausf_ParameterProtectionResponse) with the integrity protection information (i.e., AUSF-MAC, NAS count, and X-UE-MAC) to UDM element 312 (S6).Next, the UDM element 312 sends a subscription data response (e.g., Nudm_SDM_Get response) containing UE configuration parameter updates and integrity protection information (i.e., AUSF-MAC and NAS count) to the AMF element 314 (S7). The UDM element 312 may also include a UE confirmation response indicator and / or a reregistration indicator in the subscription data response.

[0103] As part of the update procedure, the AMF element 314 is configured to transparently send the UE configuration parameter update to the UE 110. Thus, the AMF element 314 formats or generates a NAS registration acceptance message and inserts the UE configuration parameter update, along with integrity protection information (e.g., AUSF-MAC and NAS count), into the container of the NAS registration acceptance message. The AMF element 314 may also insert a UE confirmation response indicator and / or a reregistration indicator (if applicable) into the container of the NAS registration acceptance message. Next, the AMF element 314 sends the NAS registration acceptance message to the UE 110 (S8).

[0104] In this example, the NAS registration acceptance message includes a newly defined UE configuration parameter update container IE. Table 7 is an example of the UE configuration parameter update container IE.

[0105]

Table 7

[0106] This container is considered transparent because the AMF element 314 inserts the UE configuration parameter update into the container without modifying it. As described in Example 1, the UE ACK bit in the UE configuration parameter update header may be used to indicate that the network is requesting a confirmation response from the UE, and the RRR bit may be used to indicate that the network is requesting reregistration.

[0107] In response to receiving the NAS registration acceptance message, the ME702 of the UE110 performs a security check to verify that the UE configuration parameter update was sent by the UDM element 312 of the home network. For example, the ME702 calculates the UE-MAC for the UE configuration parameter update and the NAS count, and compares the UE-MAC with the AUSF-MAC. If the MACs match, it is verified that the UE configuration parameter update is from the home network, and the security check is successful. If the security check fails, the ME702 discards the UE configuration parameter update and continues the registration procedure. If the security check is successful, the ME702 and / or the USIM662 update one or more of the UE configuration parameters 664 based on the UE configuration parameter update.

[0108] If the network requests a confirmation response from the UE110 and the security check is successful, the ME702 formats the NAS registration completion message and inserts the UE-MAC into the container of the NAS registration completion message. The container of the NAS registration completion message is designed for the UE confirmation response. In this example, the NAS registration completion message includes a newly defined UE confirmation response container IE. Table 8 is an example of the UE confirmation response container IE.

[0109]

Table 8

[0110] Next, the ME702 sends the NAS registration completion message having the container including the UE-MAC to the AMF element 314 (S9). The AMF element 314 sends an information message having the UE-MAC (for example, the Nudm_SDM_Info message) to the UDM element 312 (S10). Next, the UDM element 312 can compare the UE-MAC calculated by the UE110 with the X-UE-MAC calculated by the AUSF element 310 to verify that the UE confirmation response was provided by the UE110.

[0111] The network indicates that re-registration of UE110 is required. If the security check is successful, UE110 deregisters and starts a new NAS registration procedure again (not shown) using the updated UE configuration parameters.

[0112] Example 4: Update procedure after registration using a security key FIG. 16 is a message diagram showing an update procedure after registration in an exemplary embodiment. In this embodiment, UE110 is already registered with the network and is in the connected mode. At some point after registration, the UDM element 312 may receive an instruction or process a local policy to determine that the UE configuration parameters in UE110 need to be updated. Accordingly, the UDM element 312 starts an update procedure and assembles a UE configuration parameter update. The UDM element 312 also applies integrity protection to the UE configuration parameter update using the NAS security context of UE110. To do so, the UDM element 312 sends a protection request (e.g., Nausf_ParameterProtectionRequest) with the UE configuration parameter update to the AUSF element 310 (S1). The AUSF element 310 identifies the NAS count and calculates integrity protection information based on the NAS security context of UE110, e.g., AUSF-MAC and NAS count for the UE configuration parameter update. The AUSF element 310 may also calculate the MAC expected from UE110 (X-UE-MAC). Next, the AUSF element 310 sends a protection response (e.g., Nausf_ParameterProtectionResponse) with the integrity protection information (i.e., AUSF-MAC, NAS count, and X-UE-MAC) to the UDM element 312 (S2). Next, the UDM element 312 sends an update notification (e.g., Nudm_SDM_UpdateNotification) including the UE configuration parameter update and the integrity protection information (i.e., AUSF-MAC and NAS count) to the AMF element 314 (S3). The UDM element 312 may also include a UE confirmation response indicator and / or a re-registration indicator in the update notification.

[0113] As part of the update procedure, the AMF element 314 is configured to transparently send UE configuration parameter updates to the UE 110. Thus, the AMF element 314 formats or generates a DL NAS transport message and inserts the UE configuration parameter update, along with integrity information (e.g., AUSF-MAC and NAS count), into the container of the DL NAS transport message. The AMF element 314 may also insert a UE confirmation response indicator and / or a reregistration indicator (if applicable) into the container of the DL NAS transport message. In this embodiment, the container of the DL NAS transport message is designed for UE configuration parameter updates. Next, the AMF element 314 sends the DL NAS transport message to the UE 110 (S4).

[0114] In response to receiving the DL NAS transport message, the ME 702 of the UE 110 performs a security check to verify that the UE configuration parameter update was sent by the UDM element 312 of the home network. If the security check fails, the ME 702 discards the UE configuration parameter update. If the security check succeeds, the ME 702 and / or the USIM 662 update one or more of the UE configuration parameters 664 based on the UE configuration parameter update.

[0115] The network requests a confirmation response from UE110. If the security check is successful, ME702 formats the UL NAS transport message and inserts the UE-MAC into the container of the UL NAS transport message. The container of the UL NAS transport message is designed for the UE confirmation response. Next, ME702 sends the UL NAS transport message with the container containing the UE-MAC to the AMF element 314 (S5). The AMF element 314 sends the information message with the UE-MAC (for example, the Nudm_SDM_Info message) to the UDM element 312 (S6). Next, the UDM element 312 can verify that the UE confirmation response was provided by UE110 by comparing the UE-MAC calculated by UE110 with the X-UE-MAC calculated by the AUSF element 310.

[0116] The network indicates that re-registration of UE110 is required. If the security check is successful, UE110 deregisters and uses the updated UE configuration parameters to restart the new NAS registration procedure again (not shown).

[0117] Example 5: Update procedure during registration using a secured packet and a security key FIG. 17 is a message diagram showing the registration update procedure in an exemplary embodiment. In this embodiment, the UE 110 starts the NAS registration procedure by sending a NAS registration request to the AMF element 314 (S1). In response to the NAS registration request (of type "new"), the AMF element 314 may start an authentication procedure to authenticate the UE 110 (S2). After the authentication of the UE 110, the AMF element 314 may start a NAS security procedure to establish a NAS security context (S3). With the UE 110 authenticated and the NAS security context established, the AMF element 314 sends a subscription data request (e.g., Nudm_SDM_Get message) to the UDM element 312 of the HPLMN to obtain, among other information, the access and mobility subscription data of the UE 110 (S4). When the user subscription information indicates to start a UE configuration parameter update (e.g., routing ID update), the UDM element 312 starts the update procedure. The UDM element 312 assembles a UE configuration parameter update including one or more updated UE configuration parameters. Next, the UDM element 312 applies security protection to the UE configuration parameter update by accessing the secure packet library and encapsulating the UE configuration parameter update within a secure packet.

[0118] The UDM element 312 also applies integrity protection to the secured packet using the NAS security context of the UE 110. To do so, the UDM element 312 sends a protection request (e.g., Nausf_ParameterProtectionRequest) with the secured packet to the AUSF element 310 (S5). The AUSF element 310 identifies the NAS count and calculates integrity protection information based on the NAS security context of the UE 110, e.g., the AUSF-MAC and NAS count of the secured packet. The AUSF element 310 may also calculate the MAC expected from the UE 110 (X-UE-MAC). Next, the AUSF element 310 sends a protection response (e.g., Nausf_ParameterProtectionResponse) with the integrity protection information (i.e., AUSF-MAC, NAS count, and X-UE-MAC) to the UDM element 312 (S6). Next, the UDM element 312 sends a subscription data response (e.g., Nudm_SDM_Get response) including the secured packet and the integrity protection information (i.e., AUSF-MAC and NAS count) to the AMF element 314 (S7). The UDM element 312 may also include a UE confirmation response indicator and / or a reregistration request in the subscription data response.

[0119] The AMF element 314 is configured to transparently send the secured packet to the UE 110 as part of the update procedure. Thus, the AMF element 314 formats or generates a NAS registration acceptance message and inserts the secured packet into the container of the NAS registration acceptance message. The AMF element 314 may also insert a UE confirmation response indicator and / or a reregistration request (if applicable), together with the AUSF-MAC and NAS count, into the container of the NAS registration acceptance message. In this example, the NAS registration acceptance message includes a newly defined UE configuration parameter update container IE. Table 9 is an example of the UE configuration parameter update container IE.

[0120]

Table 9

[0121] Since the AMF element 314 inserts the secured packet into the container without modifying the secured packet, this container is considered to be transparent. Next, the AMF element 314 transmits a NAS registration acceptance message to the UE 110 (S8). In response to receiving the NAS registration acceptance message, the ME 702 of the UE 110 performs a security check to verify that the secured packet was sent by the UDM element 312 of the home network. If the security check fails, the ME 702 discards the secured packet and continues the registration procedure. If the security check succeeds, the ME 702 routes or uploads the secured packet to the USIM 662 (S9). The USIM 662 also performs a security check to verify that the secured packet was sent by the UDM element 312 of the home network. If the security check fails, the USIM 662 discards the UE configuration parameter update. If the security check succeeds, the USIM 662 unpacks the UE configuration parameter update from the secured packet using the secured packet library. Next, the USIM 662 updates one or more of the UE configuration parameters 664 based on the UE configuration parameter update.

[0122] If the network requests a confirmation response from the UE 110 and the security check succeeds, the ME 702 formats a NAS registration completion message and inserts the UE-MAC into the container of the NAS registration completion message. Next, the ME 702 transmits the NAS registration completion message to the AMF element 314 (S11). The AMF element 314 transmits an information message having the UE-MAC (e.g., Nudm_SDM_Info message) to the UDM element 312 (S10). Next, the UDM element 312 can verify that the UE confirmation response was provided by the UE 110 by comparing the UE-MAC calculated by the UE 110 with the X-UE-MAC calculated by the AUSF element 310.

[0123] The network indicates that re-registration of UE110 is required. If the security check is successful, UE110 de-registers and starts a new NAS registration procedure (not shown) using the updated UE configuration parameters.

[0124] Example 6: Update procedure after registration using a secured packet and a security key FIG. 18 is a message diagram showing an update procedure after registration in an exemplary embodiment. In this embodiment, UE110 is already registered with the network and is in a connected mode. At some point after registration, the UDM element 312 may receive an instruction to determine that the UE configuration parameters in UE110 need to be updated or process a local policy. Accordingly, the UDM element 312 starts an update procedure and assembles a UE configuration parameter update. Next, the UDM element 312 applies security protection to the UE configuration parameter update by accessing the secured packet library and encapsulating the UE configuration parameter update in a secured packet.

[0125] The UDM element 312 also applies integrity protection to the encrypted packet using the NAS security context of the UE 110. To do so, the UDM element 312 sends a protection request (e.g., Nausf_ParameterProtectionRequest) with the encrypted packet to the AUSF element 310 (S1). The AUSF element 310 identifies the NAS count and calculates integrity protection information based on the NAS security context of the UE 110, such as the AUSF-MAC and NAS count of the encrypted packet. The AUSF element 310 may also calculate the MAC expected from the UE 110 (X-UE-MAC). Next, the AUSF element 310 sends a protection response (e.g., Nausf_ParameterProtectionResponse) with the integrity protection information (i.e., AUSF-MAC, NAS count, and X-UE-MAC) to the UDM element 312 (S2). Next, the UDM element 312 sends an update notification (e.g., Nudm_SDM_UpdateNotification) including the encrypted packet and the integrity protection information (i.e., AUSF-MAC and NAS count) to the AMF element 314 (S3). The UDM element 312 may also include a UE confirmation response indicator and / or a reregistration request in the update notification.

[0126] As part of the update procedure, the AMF element 314 is configured to transparently send the encrypted packet to the UE 110. Accordingly, the AMF element 314 formats or generates a DL NAS transport message and inserts the encrypted packet into the container of the DL NAS transport message. The AMF element 314 may also insert a UE confirmation response indicator and / or a reregistration indicator (if applicable) into the container of the DL NAS transport message, together with the AUSF-MAC and NAS count. Next, the AMF element 314 sends the DL NAS transport message to the UE 110 (S4).

[0127] In response to receiving a DL NAS transport message, the ME702 of UE110 performs a security check to verify that the secured packet was sent by the UDM element 312 of the home network. If the security check fails, ME702 discards the secured packet. If the security check succeeds, ME702 routes or uploads the secured packet to the USIM662 (S5). The USIM662 also performs a security check to verify that the secured packet was sent by the UDM element 312 of the home network. If the security check fails, USIM662 discards the UE configuration parameter update. If the security check succeeds, USIM662 unpacks the UE configuration parameter update from the secured packet using the secured packet library. Next, USIM662 updates one or more of the UE configuration parameters 664 based on the UE configuration parameter update. USIM662 also sends a UE confirmation response to ME702 (S6).

[0128] If the network requests a confirmation response from UE110 and the security check succeeds, ME702 formats the UL NAS transport message and inserts the UE-MAC into the container of the UL NAS transport message. Next, ME702 sends the UL NAS transport message to the AMF element 314 (S7). The AMF element 314 sends an information message with the UE-MAC (e.g., Nudm_SDM_Info message) to the UDM element 312 (S8). Next, the UDM element 312 can verify that the UE confirmation response was provided by UE110 by comparing the UE-MAC calculated by UE110 with the X-UE-MAC calculated by the AUSF element 310.

[0129] The network indicates that re-registration of UE110 is necessary. If the security check is successful, UE110 shall deregister and use the updated UE configuration parameters to restart the new NAS registration procedure (not shown).

[0130] Any of the various elements or modules illustrated or described in this specification may be implemented as hardware, software, firmware, or any combination thereof. For example, an element may be implemented as dedicated hardware. Dedicated hardware elements may be referred to by terms such as "processor", "controller", or some similar term. When functions are provided by a processor, they may be provided by a single dedicated processor, a single shared processor, or multiple individual processors where some of them may be shared. Further, the explicit use of the terms "processor" or "controller" should not be construed to refer only to hardware capable of executing software, and without limitation, may implicitly include digital signal processor (DSP) hardware, network processors, application specific integrated circuits (ASICs) or other circuits, field programmable gate arrays (FPGAs), read-only memory (ROM) for storing software, random access memory (RAM), non-volatile storage, logic, or any other physical hardware component or module.

[0131] Also, an element may be implemented as instructions executable by a processor or computer for performing the functions of that element. Some examples of instructions are software, program code, and firmware. The instructions are operable to direct the processor to perform the functions of the element when executed by the processor. The instructions may be stored in a storage device readable by the processor. Some examples of storage devices are digital or solid state memories, magnetic storage media such as magnetic disks and magnetic tapes, hard drives, or optically readable digital data storage media.

[0132] As used herein, the term "circuit" can refer to one or more or all of the following: (a) An embodiment of a circuit consisting only of hardware (e.g., an embodiment consisting only of analog and / or digital circuits), (b) A combination of a hardware circuit and software, e.g., the following (where applicable): (i) A combination of an analog and / or digital hardware circuit(s) and software / firmware, (ii) Any part of a hardware processor(s) (including a digital signal processor(s)) that uses software to cooperate to cause a device such as a mobile phone or a server to perform various functions, software, and memory(s), (c) A hardware circuit(s) and / or processor(s) (e.g., a microprocessor(s) or a part of a microprocessor(s)) that requires software (e.g., firmware) to operate, but the software may not be present if not necessary for operation.

[0133] This definition of circuit applies to all uses of this term in this application, including any claims. As a further example, the term "circuit" as used in this application also includes an embodiment of a mere hardware circuit or processor (or processors), or a part of a hardware circuit or processor, and the software and / or firmware associated therewith (or therewith). The term "circuit" also includes, for example, a baseband integrated circuit or a processor integrated circuit for a mobile device, or a similar integrated circuit within a server, a cellular network device, or other computing or network device, if it corresponds to an element of a particular claim.

[0134] Particular embodiments have been described herein, but the scope of the disclosure is not limited to those particular embodiments. The scope of the disclosure is defined by the following claims and any equivalents thereof.

Claims

1. A user equipment (UE), comprising: a universal subscriber identity module (USIM) storing UE configuration parameters for the UE; at least one processor; at least one memory storing instructions; wherein the instructions, when executed by the at least one processor, cause the UE to at least:[ receive, from an access and mobility management function (AMF) during non-access stratum (NAS) transport procedures, a downlink NAS transport message having a container within a secured packet encapsulated with a UE configuration parameter update for the UE, wherein the UE configuration parameter update encapsulated within the secured packet of the downlink NAS transport message includes a routing indicator parameter; perform a first security check on the downlink NAS transport message by a mobile equipment (ME) domain of the UE to verify the UE configuration parameter update encapsulated within the secured packet; transfer the secured packet to the USIM if the first security check is successful; perform a second security check using the USIM to verify the UE configuration parameter update encapsulated within the secured packet within the container of the downlink NAS transport message; update one or more of the UE configuration parameters stored in the USIM based on the UE configuration parameter update encapsulated within the secured packet within the container of the downlink NAS transport message if the second security check is successful; a UE that causes the above to be performed.[

2. The UE according to claim 1, wherein the USIM is present on a universal integrated circuit card (UICC) within the UE.[

3. The instructions, when executed by the at least one processor, cause the UE to:[ When the downlink NAS transport message includes a UE confirmation response indicator, further cause an uplink NAS transport message including a container including a UE confirmation response from the UE indicating that the UE configuration parameter update has been received by the UE to be transmitted to the AMF element. The UE according to claim 1.

4. When executed by the at least one processor, the instruction causes the UE to When the downlink NAS transport message includes a reregistration indicator, further cause the UE to initiate a NAS registration procedure to reregister the UE using the updated UE configuration parameters updated on the USIM of the UE. The UE according to claim 1.

5. In a user equipment (UE), during non-access stratum (NAS) transport procedures, receiving, from an access and mobility management function (AMF), the downlink NAS transport message having a container including a UE configuration parameter update for the UE encapsulated within a secured packet within the container of the downlink NAS transport message, wherein the UE configuration parameter update encapsulated within the secured packet within the container of the downlink NAS transport message includes a routing indicator parameter; performing a first security check on the downlink NAS transport message by a mobile equipment (ME) domain of the UE to verify the secured packet within the container of the downlink NAS transport message; transferring the secured packet to a universal subscriber identity module (USIM) that communicates operably with the UE when the first security check is successful; performing a second security check using the USIM to verify the UE configuration parameter update encapsulated within the secured packet within the container of the downlink NAS transport message; If the second security check is successful, use the USIM to update one or more of the UE configuration parameters stored in the USIM based on the UE configuration parameter update encapsulated in the secure packet within the container of the downlink NAS transport message. The method comprising the above. **Claim 6** The method according to claim 5, wherein the USIM is present on a Universal Integrated Circuit Card (UICC) within the UE. **Claim 7** The method according to claim 5, further comprising transmitting, from the UE to the AMF element, an uplink NAS transport message including a container including a UE confirmation response from the UE indicating that the UE configuration parameter update has been received by the UE, when the downlink NAS transport message includes a UE confirmation response indicator. **Claim 8** The method according to claim 5, further comprising starting a NAS registration procedure to re-register the UE using the updated UE configuration parameters, when the downlink NAS transport message includes a re-registration indicator. **Claim 9** An Access and Mobility Management Function (AMF) element, comprising at least one processor, and at least one memory storing instructions, wherein the instructions, when executed by the at least one processor, cause the AMF element to at least generate a downlink NAS transport message including a container including a UE configuration parameter update for a User Equipment (UE) encapsulated within a secure packet within the downlink NAS transport message during a first Non-Access Stratum (NAS) transport procedure, wherein the UE configuration parameter update encapsulated within the secure packet within the container of the downlink NAS transport message includes a routing indicator parameter; transmit the downlink NAS transport message towards the UE; be performed, and the downlink NAS transport message is (i) Cause the mobile equipment (ME) domain of the UE to perform a first security check on the downlink NAS transport message to verify the secured packet within the container of the downlink NAS transport message; (ii) If the first security check is successful, cause the ME domain of the UE to transfer the secured packet to a universal subscriber identity module (USIM) that communicates operably with the UE; (iii) Cause the USIM to perform a second security check to verify the UE configuration parameter update encapsulated within the secured packet within the container of the downlink NAS transport message; (iv) If the second security check is successful, cause the USIM to update one or more of the UE configuration parameters stored in the USIM based on the UE configuration parameter update encapsulated within the secured packet within the container of the downlink NAS transport message; An AMF element operable to operate as described above.

10. When executed by the at least one processor, the instructions cause the AMF element to at least If the downlink NAS transport message includes a UE confirmation response indicator, further cause the UE to send to the AMF element an uplink NAS transport message including a container encapsulating a UE confirmation response from the UE that the UE configuration parameter update has been received by the UE in response to the downlink NAS transport message. The AMF element according to claim 9.

11. When executed by the at least one processor, the instructions cause the AMF element to at least If the downlink NAS transport message includes a reregistration indicator, further cause the UE to initiate a NAS registration procedure to reregister using the updated UE configuration parameters in response to the reregistration indicator within the downlink NAS transport message. The AMF element according to claim 9.

12. When executed by the at least one processor, the instructions cause the AMF element to Receiving, from an integrated data management (UDM) element, a control plane message including the UE configuration parameter update for the UE; Inserting the UE configuration parameter update into the downlink NAS transport message; The AMF element according to claim 9, further causing the above to be performed.

13. Generating a downlink NAS transport message including a container encapsulating a UE configuration parameter update for a user equipment (UE) within a container of the downlink NAS transport message during a first non-access stratum (NAS) transport procedure, wherein the UE configuration parameter update encapsulated within the secure packet of the downlink NAS transport message includes a routing indicator parameter; Transmitting the downlink NAS transport message towards the UE; Comprising, the downlink NAS transport message is operable to: (i) cause a first security check to be performed on a mobile equipment (ME) domain of the UE to verify the secure packet within the container of the downlink NAS transport message; (ii) if the first security check is successful, cause the secure packet to be transferred to a universal subscriber identity module (USIM) that communicates operably with the UE in the ME domain of the UE; (iii) cause a second security check to be performed on the USIM to verify the UE configuration parameter update encapsulated within the secure packet within the container of the downlink NAS transport message; (iv) if the second security check is successful, cause the USIM to update one or more of the UE configuration parameters stored in the USIM based on the UE configuration parameter update encapsulated within the secure packet within the container of the downlink NAS transport message.

14. When the downlink NAS transport message includes a UE confirmation response indicator, the method includes: Causing the AMF element to transmit an uplink NAS transport message including a container including a UE confirmation response from the UE indicating that the UE configuration parameter update has been received by the UE, the method according to claim 13, further comprising.

15. When the downlink NAS transport message includes a reregistration indicator, the method further comprises causing the UE to initiate a NAS registration procedure to reregister the UE using the updated UE configuration parameters, the method according to claim 14.

16. Receiving, from an integrated data management (UDM) element, a control plane message including the UE configuration parameter update for the UE; Inserting the UE configuration parameter update into the container of the downlink NAS transport message; The method according to claim 15, further comprising.

Citation Information

Patent Citations

  • De-registration method in wireless communication system and device therefor

    WO2018097601A1