Communication device, first communication device, communication device method, and first communication device method
By employing NAS security contexts for integrity checking based on access types, the solution addresses issues in AMF communication during UE mobility, ensuring reliable UE context transfer and registration in 5G networks.
Patent Information
- Application Number
- JP2024521292
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-10-22
- Filing Date
- 2022-10-12
- Publication Date
- 2025-08-13
- Estimated Expiration
- 2042-10-12
AI Technical Summary
Communication procedures between AMFs during mobility and registration processes in 5G networks are problematic due to unclear or failed integrity checks when a UE changes from a non-geographically selected AMF to a geographically selected AMF, leading to failures in UE context transfer.
The solution involves using a Non-Access Stratum (NAS) security context corresponding to the access type for integrity checking of registration request messages, ensuring accurate verification and successful UE context transfer between AMFs.
This approach ensures reliable and successful registration procedures by correctly verifying the integrity of messages, preventing failures in UE context transfer and maintaining seamless communication across different access types.
Smart Images

Figure 0007722574000001 
Figure 0007722574000002 
Figure 0007722574000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a communication device, a first communication device, a communication device method, and a first communication device method. [Background technology]
[0002] When a UE is registered to a PLMN through 3GPP access and non-3GPP access, the UE is registered to the same AMF. When a UE is registered to two different PLMNs through 3GPP access and non-3GPP access, the UE is registered to two different AMFs belonging to different PLMNs. The UE and the network maintain two independent 5GMM contexts and two independent 5GSM contexts, i.e., the UE and the network maintain a 5GMM context and a 5GSM context for 3GPP access, and a 5GMM context and a 5GSM context for non-3GPP access. Services accessed through one access (e.g., 3GPP access) are independent from services accessed through another access (e.g., non-3GPP access). When a UE moves from one registration area (e.g., an old registration area) to another registration area (e.g., a new registration area) or from one PLMN (e.g., an old PLMN) to another PLMN (e.g., a new PLMN), during the mobility procedure, the UE context (e.g., a 5GMM context or a 5GSM context) is transferred from the old AMF serving the old registration area to the new AMF serving the new registration area once the old AMF successfully verifies the integrity of the NAS container transferred from the new AMF to the old AMF.
[0003] If the UE registers to a PLMN only via non-3GPP access, the N3IWF may select a non-geographically selected AMF. Based on the operator's policy, the GUAMI of the assigned 5G-GUTI indicates whether the PLMN is served by a non-geographically selected AMF or a geographically selected AMF. When the UE registers to a non-geographically selected AMF via non-3GPP and the UE initiates a registration procedure through 3GPP access, a transfer from a non-geographically selected AMF to a geographically selected AMF occurs. In this case, for example, during an RRC connection establishment procedure, the UE sends an RRC Setup Complete message to the NG-RAN, including a NAS Registration Request message including a 5G-GUTI. The NAS Registration Request message may be referred to as a Registration Request message in this disclosure. When the NG-RAN receives the 5G-GUTI and determines that the 5G-GUTI indicates a non-geographically selected AMF, the NG-RAN directs (or transmits) the Registration Request message to the geographically selected AMF. In this case, the geographically selected AMF initiates a UE context transfer procedure with the non-geographically selected AMF. After the UE context transfer procedure is successfully performed in the geographically selected AMF, the UE is then registered with the geographically selected AMF through both 3GPP access and non-3GPP access.
[0004] Non-patent document 4 discloses registration by AMF reallocation procedure. [Prior art documents] [Non-patent literature]
[0005] [Non-Patent Document 1] 3GPP TR 21.905: "Vocabulary for 3GPP Specifications". V16.0.0 (2019-06) [Non-patent document 2] GSM Association Official Document NG.116: “Generic Network Slice Template” V2.0 (2019-10) - https: / / www.gsma.com / newsroom / wp-content / uploads / NG.116-v2.0.pdf [Non-patent document 3] 3GPP TS 23.501: "System architecture for the 5G System (5GS)". V17.2.0 (2021-09) [Non-patent document 4] 3GPP TS 23.502: "Procedures for the 5G System (5GS)". V17.2.0 (2021-09). [Non-patent document 5] 3GPP TS 33.501: “Security architecture and procedures for 5G system” v 17.3.0 (2021-09) Summary of the Invention [Problem to be solved by the invention]
[0006] When an AMF is changed from one AMF to another, problematic or unclear situations may arise regarding the communication procedures between nodes including the AMFs involved in the communication procedures. [Means for solving the problem]
[0007] In an aspect of the present disclosure, a communications device includes means for receiving a message including information regarding an access type, and means for using a Non Access Stratum (NAS) security context to perform integrity checking on the registration request message, the NAS security context corresponding to the information regarding the access type.
[0008] In an aspect of the present disclosure, a first communication device has means for communicating with a second communication device and means for sending a message including information regarding an access type, and a Non Access Stratum (NAS) security context corresponding to the information regarding the access type is used to perform integrity checking on the registration request message.
[0009] In an aspect of the present disclosure, a method of a communications device receives a message including information regarding an access type and uses a Non Access Stratum (NAS) security context to perform integrity checking on the registration request message, the NAS security context corresponding to the information regarding the access type.
[0010] In an aspect of the present disclosure, a method of a first communication device communicates with a second communication device, sending a message including information regarding an access type, and a Non Access Stratum (NAS) security context corresponding to the information regarding the access type is used to perform integrity checking on the registration request message. [Brief explanation of the drawings]
[0011] [Figure 1] Figure 1 is a signaling diagram of a first aspect (mobility procedure for AMF change from a non-geographically selected AMF to a geographically selected AMF). [Figure 2] FIG. 2 is a signaling diagram of the second aspect (combined registration procedure for UE for 3GPP and non-3GPP access). [Figure 3] FIG. 3 is a signaling diagram of a third aspect (registration procedure to a PLMN that does not support simultaneous registration procedure via 3GPP access and non-3GPP access). [Figure 4] Figure 4 is a signaling diagram of a fourth aspect (registration procedure for AMF relocation). [Figure 5] FIG. 5 is a diagram showing an outline of the system. [Figure 6] FIG. 6 is a block diagram illustrating a user equipment (UE). [Figure 7] FIG. 7 is a block diagram illustrating an (R)AN node. [Figure 8] FIG. 8 is a diagram illustrating a system overview of an (R)AN node based on the O-RAN architecture. [Figure 9] FIG. 9 is a block diagram showing a radio unit (RU). [Figure 10] FIG. 10 is a block diagram showing a distributed unit (DU). [Figure 11] FIG. 11 is a block diagram showing a centralized unit (CU). [Figure 12] FIG. 12 is a block diagram illustrating the Access and Mobility Management Function (AMF). [Figure 13] FIG. 13 is a block diagram illustrating Unified Data Management (UDM). [Figure 14] FIG. 14 shows the registration procedure. [Figure 15] FIG. 15 shows the registration procedure. [Figure 16] Figure 16 shows registration via AMF reassignment procedure. DETAILED DESCRIPTION OF THE INVENTION
[0012] <abbreviation> For purposes of this specification, the abbreviations given in Non-Patent Document 1 and the following apply: Abbreviations defined in this specification take precedence over the definition of the same abbreviation in Non-Patent Document 1 if the same abbreviation appears in that document.
[0013] 4G-GUTI 4G Globally Unique Temporary UE Identity 5GC 5G Core Network 5GLAN 5G Local Area Network 5GS 5G System 5G-AN 5G Access Network 5G-AN PDB 5G Access Network Packet Delay Budget 5G-EIR 5G-Equipment Identity Register 5G-GUTI 5G Globally Unique Temporary Identifier 5G-BRG 5G Broadband Residential Gateway 5G-CRG 5G Cable Residential Gateway 5G GM 5G Grand Master 5G-RG 5G Residential Gateway 5G-S-TMSI 5G S-Temporary Mobile Subscription Identifier 5G VN 5G Virtual Network 5QI 5G QoS Identifier AF Application Function AMF Access and Mobility Management Function AMF-G Geographically selected Access and Mobility Management Function AMF-NG Non-Geographically selected Access and Mobility Management Function AS Access Stratum ATSSS Access Traffic Steering, Switching, Splitting ATSSS-LL ATSSS Low-Layer AUSF Authentication Server Function AUTN Authentication token BMCA Best Master Clock Algorithm BSF Binding Support Function CAG Closed Access Group CAPIF Common API Framework for 3GPP northbound APIs CHF Charging Function CN PDB Core Network Packet Delay Budget CP Control Plane DAPS Dual Active Protocol Stacks DL Downlink DN Data Network DNAI DN Access Identifier DNN Data Network Name DRX Discontinuous Reception DS-TT Device-side TSN translator ePDG evolved Packet Data Gateway EBI EPS Bearer Identity EPS Evolved Packet System EUI Extended Unique Identifier FAR Forwarding Action Rule FN-BRG Fixed Network Broadband RG FN-CRG Fixed Network Cable RG FN-RG Fixed Network RG FQDN Fully Qualified Domain Name GFBR Guaranteed Flow Bit Rate GMLC Gateway Mobile Location Centre GPSI Generic Public Subscription Identifier GUAMI Globally Unique AMF Identifier GUTI Globally Unique Temporary UE Identity HR Home Routed (roaming) IAB Integrated access and backhaul IMEI / TAC IMEI Type Allocation Code IPUPS Inter PLMN UP Security I-SMF Intermediate SMF I-UPF Intermediate UPF LADN Local Area Data Network LBO Local Break Out (roaming) LMF Location Management Function LoA Level of Automation LPP LTE Positioning Protocol LRF Location Retrieval Function MCC Mobile country code MCX Mission Critical Service MDBV Maximum Data Burst Volume MFBR Maximum Flow Bit Rate MICO Mobile Initiated Connection Only MITM Man In the Middle MNC Mobile Network Code MPS Multimedia Priority Service MPTCP Multi-Path TCP Protocol N3IWF Non-3GPP InterWorking Function N3GPP Non-3GPP access N5CW Non-5G-Capable over WLAN NAI Network Access Identifier NAS Non-Access-Stratum NEF Network Exposure Function NF Network Function NGAP Next Generation Application Protocol NID Network identifier NPN Non-Public Network NR New Radio NRF Network Repository Function NSI ID Network Slice Instance Identifier NSSAA Network Slice-Specific Authentication and Authorization NSSAAF Network Slice-Specific Authentication and Authorization Function NSSAI Network Slice Selection Assistance Information NSSF Network Slice Selection Function NSSP Network Slice Selection Policy NSSRG Network Slice Simultaneous Registration Group NW-TT Network-side TSN translator NWDAF Network Data Analytics Function PCF Policy Control Function PDB Packet Delay Budget PDR Packet Detection Rule PDU Protocol Data Unit PEI Permanent Equipment Identifier PER Packet Error Rate PFD Packet Flow Description PLMN Public Land Mobile Network PNI-NPN Public Network Integrated Non-Public Network PPD Paging Policy Differentiation PPF Paging Proceed Flag PPI Paging Policy Indicator PSA PDU Session Anchor PTP Precision Time Protocol QFI QoS Flow Identifier QoE Quality of Experience RACS Radio Capabilities Signalling optimisation (R)AN (Radio) Access Network RG Residential Gateway RIM Remote Interference Management RQA Reflective QoS Attribute RQI Reflective QoS Indication RSN Redundancy Sequence Number SA NR Standalone New Radio SBA Service Based Architecture SBI Service Based Interface SCP Service Communication Proxy SD Slice Differentiator SEAF Security Anchor Functionality SEPP Security Edge Protection Proxy SMF Session Management Function SMSF Short Message Service Function SN Sequence Number SN name Serving Network Name. SNPN Stand-alone Non-Public Network S-NSSAI Single Network Slice Selection Assistance Information SSC Session and Service Continuity SSCMSP Session and Service Continuity Mode Selection Policy SST Slice / Service Type SUCI Subscription Concealed Identifier SUPI Subscription Permanent Identifier SV Software Version TMSI Temporary Mobile Subscriber Identity TNAN Trusted Non-3GPP Access Network TNAP Trusted Non-3GPP Access Point TNGF Trusted Non-3GPP Gateway Function TNL Transport Network Layer TNLA Transport Network Layer Association TSC Time Sensitive Communication TSCAI TSC Assistance Information TSN Time Sensitive Networking TSN GM TSN Grand Master TSP Traffic Steering Policy TT TSN Translator TWIF Trusted WLAN Interworking Function UCMF UE radio Capability Management Function UDM Unified Data Management UDR Unified Data Repository UDSF Unstructured Data Storage Function UL Uplink UL CL Uplink Classifier UPF User Plane Function URLLC Ultra Reliable Low Latency Communication URRP-AMF UE Reachability Request Parameter for AMF URSP UE Route Selection Policy VID VLAN Identifier VLAN Virtual Local Area Network VPLMN Visited PLMN W-5GAN Wireline 5G Access Network W-5GBAN Wireline BBF Access Network W-5GCAN Wireline 5G Cable Access Network W-AGF Wireline Access Gateway Function.
[0014] <Definition> For purposes of this specification, the terms and definitions given in Non-Patent Document 1 and the following apply: Terms defined in this specification take precedence over the definition of the same term in Non-Patent Document 1, if any.
[0015] <General Overview> Those skilled in the art will appreciate that elements in the figures may be shown in simplified form and not necessarily drawn to scale. Furthermore, with respect to the structure of a device, one or more components of the device may be represented by conventional symbols in the figures, and the figures may show only certain details relevant to understanding aspects of the present disclosure so as not to obscure the figures with details that will be readily apparent to those skilled in the art having the benefit of the description herein.
[0016] To promote an understanding of the principles of the present disclosure, reference will now be made to embodiments illustrated in the drawings and specific language will be used to describe those principles. It will nevertheless be understood that no limitation on the scope of the present disclosure is intended thereby. Such alterations and further modifications in the illustrated systems, and such further applications of the principles of the present disclosure as would normally occur to one skilled in the art, are to be construed as being within the scope of the present disclosure.
[0017] The terms "comprises," "comprising," or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a process or method comprising a list of steps not only includes those steps, but may also include other steps not expressly listed or inherent in such process or method. Similarly, the reference to one or more devices, entities, subsystems, elements, structures, or components preceded by "comprises" does not, absent further constraints, preclude the presence of other devices, subsystems, elements, structures, components, additional devices, additional subsystems, additional elements, additional structures, or additional components. Throughout this specification, the phrases "in an embodiment," "in another embodiment," and similar terms may all refer to the same embodiment, but do not necessarily do so.
[0018] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs. The systems, methods, and examples provided herein are illustrative only and are not intended to be limiting.
[0019] In the following specification and claims, reference will be made to a number of terms that shall be defined to have the following meanings: The singular forms "a," "an," and "the" include plural references unless the context clearly dictates otherwise.
[0020] As used herein, information refers to data and knowledge when data is meaningful information and represents values attributed to parameters. Furthermore, knowledge refers to an understanding of an abstract or concrete concept. It should be noted that this exemplary system is simplified to facilitate explanation of the subject matter of the present disclosure and is not intended to limit the scope of the present disclosure. Other devices, systems, and configurations may be used in addition to or instead of the system to implement aspects disclosed herein, and all such aspects are contemplated as being within the scope of the present disclosure.
[0021] The term "UE context" in the following aspects may refer to a 5GMM context, optionally a 5GMM context stored in the AMF. A 5G NAS security context may be part of the 5GMM context. The term "NAS security context" used below may refer to a 5G NAS security context as defined in 3GPP TS 26.210.
[0022] The AMF and the UE establish a common 5G NAS security context containing a single set of NAS keys and algorithms upon first registration through any access. The AMF and the UE also store parameters specific to each NAS connection in the common NAS security context, including two pairs of NAS COUNTs for each access (i.e., 3GPP access and non-3GPP access).
[0023] Each aspect and the elements included in each aspect described below can be implemented independently or in combination with each other. The aspects include different novel features. As such, the aspects contribute to achieving different objectives or solving different problems and achieving different advantages.
[0024] The registration procedure in all aspects may be, but is not limited to, an initial registration procedure, a mobility registration procedure, or a periodic registration procedure.
[0025] <First aspect> When the UE initiates a registration procedure through 3GPP access while already registered with a non-geographically selected AMF through non-3GPP access, the UE performs integrity protection for the registration request message including the assigned 5G-GUTI using the NAS security context and transmits an RRC Setup Complete message including the integrity-protected registration request message through 3GPP access. When the NG-RAN receives the RRC Setup Complete message including the integrity-protected registration request message during the RRC connection establishment procedure, the NG-RAN routes (or transmits) the integrity-protected registration request message to the geographically selected AMF. The geographically selected AMF (e.g., new AMF) then initiates a UE context transfer procedure with the non-geographically selected AMF (e.g., old AMF) through the N14 interface by transmitting a Namf_Communication_UEContextTransfer request message including the integrity-protected registration request message received from the UE. In this case, the old AMF does not know whether the registration request message is integrity protected by the NAS security context of the 3GPP access or the NAS security context of the non-3GPP access. This may lead to a failure of the integrity check for the registration request message. For example, this may lead to a failure of the integrity check for the registration request message because the security parameters in the NAS security context used by the old AMF for integrity check may be different from the security parameters in the NAS security context used by the UE. The mismatch in the NAS security context between the UE and the non-geographically selected AMF ultimately leads to a failure of the UE context transfer from the non-geographically selected AMF to the geographically selected AMF. As a result, the registration procedure over 3GPP access fails. For example, when a transfer from a non-geographically selected AMF to a geographically selected AMF occurs, there are cases where the integrity check for the UE context transfer by the AMF may fail.
[0026] The first aspect discloses a solution for the case where the AMF performs integrity check even when the AMF does not have an MM context corresponding to the access type indicated in the Namf_Communication_UEContextTransfer request message. The first aspect can solve the above problem statement. For example, the MM context may be a 5GMM context or a 5GSM context.
[0027] When the UE successfully registers with the AMF of the PLMN, the UE stores the current NAS security context in the ME memory or USIM card. When the UE performs a registration procedure to the PLMN through 3GPP access while registered through non-3GPP access (for example, when the UE performs a registration procedure to the PLMN through 3GPP access while registered with a non-geographically selected AMF through non-3GPP access), the UE protects the integrity of the registration request message using the integrity protection mechanism defined in Non-Patent Document 5 and sends an integrity-protected registration request message through the 3GPP access. The integrity-protected registration request message includes 5G-GUTI and an information element called NAS connection identifier configured in the 3GPP access.
[0028] When the geographically selected AMF receives the integrity protection registration request message from the UE, the geographically selected AMF sends a Namf_Communication_UEContextTransfer request message to the non-geographically selected AMF, including 5G-GUTI and an access type parameter set to 3GPP access (or any other indication for identifying 3GPP access) along with other information elements. The Namf_Communication_UEContextTransfer request message may include the integrity protection registration request message. The geographically selected AMF may be referred to as a geographical AMF or AMF-G in this disclosure. The non-geographically selected AMF may be referred to as a non-geographical AMF or AMF-NG in this disclosure. The Namf_Communication_UEContextTransfer request message may be referred to as a Namf_Communication_UEContextTransfer message in this disclosure. When the non-geographically selected AMF receives the Namf_Communication_UEContextTransfer request message, the non-geographically selected AMF finds the UE context related to the UE's 5G-GUTI received in the Namf_Communication_UEContextTransfer request message. The non-geographically selected AMF finds that no MM context exists for 3GPP access, but the non-geographically selected AMF performs integrity check of the received NAS message (e.g., an integrity-protected registration request message) by using a 0 (zero) value for the UL NAS COUNT integrity protection parameter for integrity check. If the integrity is successfully checked, the AMF-NG sends a Namf_Communication_UEContextTransfer response message to the AMF-G. The AMF-G completes the registration procedure for both 3GPP access and non-3GPP access, allocates a new 5G-GUTI, and sends the new 5G-GUTI to the UE.
[0029] Figure 1 shows the mobility procedure for AMF change from a non-geographically selected AMF to a geographically selected AMF.
[0030] The detailed procedure of the first embodiment is described below.
[0031] 0. The UE is registered with a non-geographically selected AMF through non-3GPP access, and a 5G-GUTI is assigned to the UE. A NAS security context is created for the non-3GPP access. For example, the UE and the non-geographically selected AMF have a non-3GPP access NAS security context. In addition, the UE is not yet registered with 3GPP access.
[0032] 1a-1b. The UE initiates a registration procedure over 3GPP access. The UE performs integrity protection for the registration request message using the NAS security context of the non-3GPP access. The registration request message includes 5G-GUTI and a NAS connection identifier configured for the non-3GPP access. The UE sends an integrity-protected registration request message. For example, the UE sends an RRC message including the integrity-protected registration request message. The integrity-protected registration request message may be referred to as a registration request message in this disclosure. The unique NAS connection identifier value (or the NAS connection identifier value) is set to "0x01" for 3GPP access and "0x02" for non-3GPP access. For example, the UE sets the NAS connection identifier to "0x01" for 3GPP access and includes the NAS connection identifier in the registration request message.
[0033] In another example, the integrity of the registration request message is protected using the common 5G NAS security context created in step 0 and a UL NAS COUNT that is set to zero for 3GPP access if a stored UL NAS COUNT does not exist for the 3GPP access, and in other cases using the stored UL NAS COUNT.
[0034] 2-3. When the NG-RAN receives an RRC message including a registration request message from the UE, the NG-RAN routes (or sends) the registration request message to a geographically selected AMF (AMF-G). The registration request message includes a 5G-GUTI. The 5G-GUTI may indicate a non-geographically selected AMF (i.e., AMF-NG).
[0035] 4. When the AMF-G receives the registration request message including the 5G-GUTI, the AMF-G identifies the target AMF using the 5G-GUTI received in the registration request message. The target AMF may be the AMF for which the AMF-G performs Namf_Communication_UEContextTransfer. The AMF-G sends a Namf_Communication_UEContextTransfer request message, and the Namf_Communication_UEContextTransfer request message includes the access type configured for 3GPP access (or any other indication for identifying 3GPP access), the integrity-protected NAS message, and the 5G-GUTI. The Namf_Communication_UEContextTransfer request message may include the NAS connection identifier received in the registration request message. The integrity-protected NAS message may be the integrity-protected registration request message received from the NG-RAN in step 4. The integrity-protected NAS message may be the integrity-protected registration request message received from the NG-RAN. The integrity-protected NAS message may be referred to as a full registration request or an integrity-protected full registration request NAS message in this disclosure. For example, if the AMF-G identifies AMF-NG as the target AMF using the 5G-GUTI received in the registration request message, the AMF-G sends a Namf_Communication_UEContextTransfer request message to the AMF-NG, and the Namf_Communication_UEContextTransfer request message includes an access type set to 3GPP access (or any other indication for identifying 3GPP access) and an integrity-protected NAS message.
[0036] 5. When AMF-NG receives the Namf_Communication_UEContextTransfer request message, AMF-NG decides to perform integrity checking of the integrity-protected NAS message using one of the following procedures:
[0037] i) The AMF-NG uses the NAS security context in AMF-NG for the UE that corresponds to the value received in the Access Type information element, which in this case is 3GPP access. The AMF-NG uses the common 5G NAS security context created in step 0 and a UL NAS COUNT that is set to zero if there is no UL NAS COUNT stored for the 3GPP access, or uses the NAS count stored for the 3GPP access.
[0038] ii) AMF-NG uses the NAS security context corresponding to the value received in the NAS connection identifier, which is a non-3GPP access. AMF-NG uses the 5G NAS security context based on the non-3GPP access for NAS message integrity verification.
[0039] For example, even if the access type in the Namf_Communication_UEContextTransfer request message is set to 3GPP access, AMF-NG uses the NAS security context of non-3GPP access to perform integrity check of received integrity-protected NAS messages.
[0040] For example, AMF-NG may determine that the access type in the Namf_Communication_UEContextTransfer request message is set to 3GPP and may perform integrity checking of the received integrity-protected NAS message using a NAS security context for non-3GPP access, even if the access type in the Namf_Communication_UEContextTransfer request message is set to 3GPP access.
[0041] For example, if AMF-NG receives a NAS connection identifier configured for non-3GPP access, AMF-NG may perform integrity checking of the received integrity-protected NAS message using the NAS security context of the non-3GPP access.
[0042] For example, if the AMF-NG determines that the NAS connection identifier is set to non-3GPP access, the AMF-NG may determine that the integrity-protected NAS message is protected by the non-3GPP access NAS security context. The AMF-NG may then perform integrity checking of the received integrity-protected NAS message using the non-3GPP access NAS security context.
[0043] In one example, the NAS connection identifier is sent as a clear text element in the registration request message in step 1. When AMF-NG receives the registration request message, it reads the NAS connection identifier and determines whether to use a NAS security context for 3GPP access or a NAS security context for non-3GPP access based on the value of the NAS connection identifier.
[0044] In one example, the NAS connection identifier is an optional information element. If the NAS connection identifier is absent, the 5G NAS security context for the access type is used to perform integrity checking.
[0045] In one example, if both a NAS connection identifier and an access type are present, the AMF-NG may use the 5G NAS security context for either the access type or the NAS connection identifier.
[0046] 6. If the integrity is successfully verified, the AMF-NG sends a Namf_Communication_UEContextTransfer response message to the AMF-G, which includes the 5GMM context for the UE's non-3GPP access.
[0047] 7. Upon receiving the Namf_Communication_UEContextTransfer response message, the AMF-G performs steps 6 to 19 in section 4.2.2.2.2 of non-patent document 4, and the AMF-G sends a registration accept message including the newly allocated 5G-GUTI to the UE.
[0048] 8. Upon receiving the registration accept message, the UE concludes that the UE is registered with the AMF-G for both 3GPP access and non-3GPP access. The UE sends a registration complete message to the AMF-G.
[0049] <Modification 1 of the first embodiment> In step 4, the AMF-G includes in the Namf_Communication_UEContextTransfer request message a new UL NAS COUNT of the integrity protection parameter set to 0. With this explicit indication from the AMF-G, the AMF-NG uses the value of the UL NAS COUNT of the integrity protection (i.e., the value "0") for integrity checking on the received NAS message.
[0050] <Modification 2 of the first embodiment> The principle of the first aspect may also be applied when the UE is registered with the first PLMN only through the first access and has a 5G NAS security context associated with the first PLMN, 5G-GUTI. The UE is not registered at all through the second access, i.e., the UE does not have any security context (e.g., any security context related to the second access), and the UE is in a deregistered state. The UE initiates registration with the second PLMN through the second access. In this case, the AMF-NG functions as the old AMF, i.e., the AMF of the first PLMN, and the AMF-G functions as the new AMF, i.e., the AMF of the second PLMN. The UE, the old AMF, and the new AMF follow the procedure as described in the first aspect to perform the registration procedure with the second PLMN through the second access.
[0051] In one example, when the UE is registering with the second PLMN through the second access, the UE includes the 5G-GUTI assigned by the first PLMN in the registration request message. In one example, when the UE initiates a registration procedure with the second PLMN through the second access, the UE sends the SUCI instead of the 5G-GUTI in the registration request message. In this case, the UE and the network perform one of the following methods to protect the integrity of the registration request message and verify the integrity of the received registration request message:
[0052] The UE protects the integrity of the registration request message using a common 5G NAS security context and a UL NAS COUNT set to zero. When the new AMF sends a registration request message to the old AMF, the old AMF uses the security context associated with the access type parameter received in the Namf_Communication_UEContextTransfer request message, i.e., the old AMF uses the security context for the NAS connection identifier corresponding to the access type to verify the integrity of the registration request message. In this case, the old AMF uses a common 5G NAS security context and a UL NAS COUNT set to zero to verify the integrity of the registration request message when the UE is not registered at all in the first PLMN through the second access. After the integrity is successfully verified, the old AMF sends the UE context to the new AMF.
[0053] The UE protects the integrity of the registration request message using the 5G NAS security context of the first access. The UE includes a NAS connection identifier information element having a value set as the NAS connection identifier of the 5G NAS security context used to protect the integrity of the registration request message. In this case, the NAS connection identifier value is set to the value of the NAS connection identifier corresponding to the first access. This information element is sent as clear text. When the old AMF receives the registration request message, the old AMF uses the 5G NAS security context corresponding to the value of the NAS connection identifier to verify the integrity of the received registration request message. If the integrity is successfully verified, the old AMF sends the UE context to the new AMF.
[0054] <Modification 3 of the first embodiment> Although the UE is accessing through 3GPP access, in step 1b the UE includes a NAS connection identifier configured for non-3GPP access in the registration request message. This is an explicit indication to the AMF-G that the UE has performed integrity protection for the registration request message using the NAS security context for non-3GPP access. With this indication, the AMF-G includes the access type configured for non-3GPP access in a Namf_Communication_UEContextTransfer request message and sends this message to AMF-NG in step 4. Then, in step 5, the AMF-NG performs integrity checking of the received integrity-protected NAS message using the NAS security context for non-3GPP access based on the received access type configured for non-3GPP access.
[0055] <Modification 4 of the first embodiment> In step 4, the AMF-G includes the access type set to non-3GPP access in a Namf_Communication_UEContextTransfer request message and sends this message to the AMF-NG if the AMF-G knows that the AMF-NG is a non-geographically selected AMF based on the assigned 5G-GUTI or local configuration in the AMF-G. Then, in step 5, the AMF-NG performs integrity checking of the received integrity-protected NAS message using the NAS security context of non-3GPP access based on the received access type set to non-3GPP access.
[0056] <Modification 5 of the first embodiment> Upon receiving the Namf_Communication_UEContextTransfer request message, the old AMF (e.g., AMF-NG) uses the 5G NAS security context for non-3GPP access (e.g., NAS security context for non-3GPP access) if the 5G-GUTI is assigned to the UE through non-3GPP access based on the GUAMI of the 5G-GUTI indicating a non-geographical AMF, and otherwise uses the 5G NAS security context for 3GPP access if the 5G-GUTI indicates that the 5G-GUTI is assigned through 3GPP access based on the GUAMI of the 5G-GUTI, e.g., a GUAMI indicating a geographical AMF.
[0057] <Second aspect> A UE registers with a PLMN (e.g., an old PLMN) through 3GPP access and non-3GPP access, and a single 5G-GUTI is assigned to the UE. For example, the UE registers with a geographically selected AMF in the old PLMN through 3GPP access and non-3GPP access. The geographically selected AMF in the old PLMN may be referred to as the old AMF in this disclosure. The UE then registers with a new PLMN via non-3GPP access only. This may occur, for example, when the UE registers with a geographically selected AMF in the old PLMN, and then the UE moves to a different country in airplane mode with only Wi-Fi access activated. In this case, the N3IWF in the new PLMN may select a non-geographically selected AMF in the new PLMN, and only the non-3GPP access 5GMM context (e.g., the non-3GPP access 5GMM context for the old PLMN) is transferred from the geographically selected AMF in the old PLMN to the non-geographically selected AMF in the new PLMN. The non-geographically selected AMF in the new PLMN may be referred to as the new AMF in this disclosure. The new AMF then assigns a 5G-GUTI for non-3GPP access to the UE.
[0058] Thereafter, when the UE registers to a new PLMN through 3GPP access (for example, when the UE registers to a geographically selected AMF in the new PLMN through 3GPP access), the UE sends a registration request message including a 5G-GUTI allocated by a non-geographically selected AMF in the new PLMN according to Non-Patent Document 4. In this case, the geographically selected new AMF in the new PLMN does not fetch the 3GPP access 5GMM context and the 3GPP access 5GSM context from the old AMF (for example, the geographically selected AMF in the old PLMN) according to Non-Patent Document 4. This leads to a loss of service through 3GPP access because all PDU sessions through 3GPP access cannot be transferred from the old AMF to the new AMF.
[0059] The second aspect discloses a method for obtaining a UE context for 3GPP access and a UE context for non-3GPP access from two different AMFs by a new AMF during a registration procedure. The second aspect can solve the above problem statement.
[0060] The second aspect discloses a registration procedure in PLMN2 (eg, new PLMN) in the following situation:
[0061] The UE has a valid 5G-GUTI1 associated with AMF1 in PLMN1 (e.g., old PLMN) and a corresponding security context (e.g., NAS security context 1) for 3GPP access.
[0062] The UE has a valid 5G-GUTI2 associated with AMF-NG in PLMN2 and a corresponding security context for non-3GPP access (eg, NAS security context 2).
[0063] In this case, the UE sends a registration request message including two NAS containers, namely 5G-GUTI1 and 5G-GUTI2. The UE uses NAS security context 1 for 5G-GUTI1 to integrity protect the registration request message sent to the AMF-G and includes the integrity-protected registration request message based on NAS security context 1 in the first of the two NAS containers. The UE uses security context 2 for 5G-GUTI2 to integrity protect the registration request message sent to the AMF-G and includes the integrity-protected registration request message based on NAS security context 2 in the second of the two NAS containers. When the AMF-G receives the registration request message, the AMF-G performs two UE context transfer procedures, one for 3GPP access for PLMN1 and the other for non-3GPP access for PLMN2. Once the AMF-G receives both the UE context for 3GPP access from AMF1 and the UE context for non-3GPP access from AMF-NG, the AMF-G completes the registration procedure for both 3GPP access and non-3GPP access.
[0064] 2 shows a procedure for fetching UE context for 3GPP access and non-3GPP access from two different AMFs belonging to two different PLMNs. In FIG. 2, PLMN2 (or the second PLMN) includes a non-3GPP access (or a non-3GPP access network), an NG-RAN, an AMF-G, and an AMF-NG. Additionally, in FIG. 2, PLMN1 (or the first PLMN) includes an AMF1 (or the first AMF). For example, PLMN1 is different from PLMN2. The non-3GPP access (or a non-3GPP access network) may be referred to as N3GPP in this disclosure.
[0065] The detailed procedure of the second embodiment is described below.
[0066] Step 0: The UE successfully registers with AMF1 in a first PLMN in both 3GPP access and non-3GPP access. In this case, 5G-GUTI1 is assigned to the UE. The first PLMN may be referred to as PLMN1 in this disclosure. For example, 5G-GUTI1 is assigned by AMF1. In addition, for example, the UE and AMF1 have a NAS security context for 5G-GUTI1. In step 0, a NAS security context for 5G-GUTI1 may be created during the registration procedure for both 3GPP access and non-3GPP access. The NAS security context for 5G-GUTI1 may be referred to as a NAS security context of 3GPP access for 5G-GUTI1 or security context 1 in this disclosure.
[0067] 1. The UE registers with a second PLMN through non-3GPP access. A non-geographically selected AMF (i.e., AMF-NG) is selected for the UE. In this case, 5G-GUTI2 for non-3GPP access is assigned to the UE. At this point, the UE and AMF1 still hold a UE context for 3GPP access related to 5G-GUTI1. The second PLMN may be referred to as PLMN2 in this disclosure. For example, 5G-GUTI2 is assigned by AMF-NG. For example, at this point, the UE and AMF1 still hold a UE context for 3GPP access corresponding to 5G-GUTI1. In addition, for example, the UE and AMF-NG have a NAS security context for 5G-GUTI2. In step 1, the NAS security context for 5G-GUTI2 may be created during the registration procedure to the second PLMN through non-3GPP access. The NAS security context for 5G-GUTI2 may be referred to in this disclosure as the NAS security context for non-3GPP access for 5G-GUTI2, or security context 2.
[0068] 2. The UE initiates a registration procedure to the second PLMN through 3GPP access. The UE performs integrity protection for the registration request message using the NAS security context for 5G-GUTI1, and the UE places the integrity-protected registration request message based on the NAS security context for 5G-GUTI1 in NAS container 1. The UE also performs integrity protection for the registration request message using the NAS security context for 5G-GUTI2, and the UE places the integrity-protected registration request message based on the NAS security context for 5G-GUTI2 in NAS container 2.
[0069] 3. The UE sends a registration request message, where the registration request message includes 5G-GUTI1, NAS container 1, 5G-GUTI2, and NAS container 2. 5G-GUTI1 may be configured with additional 5G-GUTIs. 5G-GUTI2 may be configured with additional 5G-GUTIs. For example, the UE sends 5G-GUTI1, NAS container 1 associated with 5G-GUTI1, 5G-GUTI2, and NAS container 2 associated with 5G-GUTI2. The UE may include information in the registration request message that allows the AMF-G to determine that 5G-GUTI1 is associated with NAS container 1 and information that allows the AMF-G to determine that 5G-GUTI2 is associated with NAS container 2.
[0070] 4. When the AMF-G receives the registration request message from the UE, the AMF-G sends a Namf_Communication_UEContextTransfer request message to AMF1, where the Namf_Communication_UEContextTransfer request message includes 5G-GUTI1, the NAS message with integrity protection in the received NAS container 1, and the access type set to 3GPP access. For example, the AMF-G sends a Namf_Communication_UEContextTransfer request message to AMF1, where the Namf_Communication_UEContextTransfer request message includes 5G-GUTI1, the received NAS container 1 including the registration request message with integrity protection based on the NAS security context for 5G-GUTI1, and the access type set to 3GPP access. For example, the AMF-G sends a Namf_Communication_UEContextTransfer request message to AMF1, and the Namf_Communication_UEContextTransfer request message includes 5G-GUTI1, NAS container 1 associated with 5G-GUTI1, and the access type set to 3GPP access. For example, the AMF-G determines that NAS container 1 is associated with 5G-GUTI1 based on 5G-GUTI1 or the information received from the UE in step 3, and sends a Namf_Communication_UEContextTransfer request message to AMF1, and the Namf_Communication_UEContextTransfer request message includes 5G-GUTI1, the received NAS container 1, and the access type set to 3GPP access.
[0071] 5. When AMF1 receives the Namf_Communication_UEContextTransfer request message, AMF1 uses the NAS security context of the 3GPP access for 5G-GUTI1 to perform integrity check of the integrity-protected NAS message in NAS container 1. For example, AMF1 determines that the access type in the Namf_Communication_UEContextTransfer request message is set to 3GPP access, and uses the NAS security context of the 3GPP access for 5G-GUTI1 to perform integrity check of the received integrity-protected NAS message (i.e., the received integrity-protected registration request message in NAS container 1).
[0072] 6. If the integrity is successfully confirmed, the AMF1 sends a Namf_Communication_UEContextTransfer response message to the AMF-G, which includes a 5GMM context for the UE's 3GPP access. The Namf_Communication_UEContextTransfer response message may include a 5GSM context for the UE's 3GPP access. The 5GMM context for the UE's 3GPP access and the 5GSM context for the UE's 3GPP access may be related to 5G-GUTI1.
[0073] 7. The AMF-G then sends a Namf_Communication_UEContextTransfer request message to the AMF-NG, where the Namf_Communication_UEContextTransfer request message includes 5G-GUTI2, the received NAS container 2 containing the integrity protected registration request message based on the NAS security context for 5G-GUTI2, and the access type set to 3GPP access. For example, the AMF-G sends a Namf_Communication_UEContextTransfer request message to the AMF-NG, where the Namf_Communication_UEContextTransfer request message includes 5G-GUTI2, the received NAS container 2 containing the integrity protected registration request message based on the NAS security context for 5G-GUTI2, and the access type set to 3GPP access. For example, the AMF-G sends a Namf_Communication_UEContextTransfer request message to the AMF-NG, where the Namf_Communication_UEContextTransfer request message includes 5G-GUTI2, NAS container 2 associated with 5G-GUTI2, and the access type set to 3GPP access. For example, the AMF-G determines that NAS container 2 is associated with 5G-GUTI2 based on 5G-GUTI2 or the information received from the UE in step 3, and sends a Namf_Communication_UEContextTransfer request message to the AMF-NG, where the Namf_Communication_UEContextTransfer request message includes 5G-GUTI2, the received NAS container 2, and the access type set to 3GPP access.
[0074] 8. When AMF-NG receives the Namf_Communication_UEContextTransfer request message, AMF-NG performs integrity check of the integrity-protected NAS message in NAS container 2 using the NAS security context for 5G-GUTI2, even if AMF-NG does not have an MM context for 3GPP access. In this case, AMF-NG uses the value of the integrity-protected UL NAS COUNT set to 0 for integrity check of the received NAS message (i.e., the integrity-protected NAS message in NAS container 2). For example, AMF-NG determines that the access type in the Namf_Communication_UEContextTransfer request message is set to 3GPP access and performs integrity check of the received integrity-protected NAS message (i.e., the received integrity-protected Registration Request message) using the NAS security context for 5G-GUTI2.
[0075] 9. If the integrity is successfully verified, the AMF-NG sends a Namf_Communication_UEContextTransfer response message to the AMF-G, which includes the 5GMM context for the UE's non-3GPP access. The Namf_Communication_UEContextTransfer response message may include the 5GSM context for the UE's non-3GPP access. The 5GMM context for the UE's non-3GPP access and the 5GSM context for the UE's non-3GPP access may be related to 5G-GUTI2.
[0076] 10. Upon receiving the Namf_Communication_UEContextTransfer response message in steps 6 and 9, the AMF-G performs steps 6 to 19 in section 4.2.2.2.2 of non-patent document 4, and the AMF-G sends a registration acknowledgement message including the newly allocated 5G-GUTI to the UE.
[0077] 11. Upon receiving the registration accept message, the UE concludes that the UE is registered with the AMF-G for both 3GPP and non-3GPP access. The UE sends a registration complete message to the AMF-G.
[0078] In one example, step 7 may be performed before step 4. For example, AMF-G sends a Namf_Communication_UEContextTransfer request message to AMF-NG and receives a Namf_Communication_UEContextTransfer response message from AMF-NG, and then AMF-G sends a Namf_Communication_UEContextTransfer request message to AMF1.
[0079] In one example, steps 4 and 7 may be performed simultaneously.
[0080] <First variant of the second embodiment> In one example, the UE includes only NAS container 2 and 5G-GUTI2, but not NAS container 1 and 5G-GUTI1. The AMF-G first performs steps 7 to 9, and then performs steps 4 to 7. After steps 7 to 9 are successfully performed and the UE context is successfully transferred from AMF-NG to AMF-G, the AMF-G performs step 4, and the AMF includes an information element indicating that the UE is verified and a SUPI (e.g., a SUPI for the UE) in a Namf_Communication_UEContextTransfer request message. The AMF-G sets this value when the UE is successfully verified in AMF-NG. When the AMF1 receives the Namf_Communication_UEContextTransfer request message including the information element and SUPI indicating that the UE is verified, the AMF1 sends the UE context to the AMF-G in a Namf_Communication_UEContextTransfer response message. The AMF-G completes the registration procedure as described in aspect 2.
[0081] <Third aspect> There may be cases where the N3IWF is connected only to a non-geographically selected AMF. That is, the N3IWF is not connected to any geographically selected AMF. In such a network topology, if the UE is already registered to a non-geographically selected AMF of a PLMN through a non-3GPP access and then performs a registration procedure to the PLMN through a 3GPP access, a new geographically selected AMF is selected. Since both accesses are connected to the same PLMN, the selected AMF is used for both the 3GPP access and the non-3GPP access. In this case, if the N3IWF cannot communicate with the selected AMF due to network topology limitations, the UE loses any services through the non-3GPP access. For example, when moving from a non-geographically selected AMF to a geographically selected AMF, the mobility procedure may be unclear depending on the network topology.
[0082] A third aspect discloses a method for dealing with a scenario where UE registration in both 3GPP access and non-3GPP access for the same AMF is not possible. The third aspect discloses a solution to the above problem statement.
[0083] A third aspect discloses a solution for the case where UE registration is not possible for the geographically selected AMF in both 3GPP and non-3GPP accesses because the N3IWF is only connected to the non-geographically selected AMF. In this case, the geographically selected AMF proceeds with the registration procedure for only one access according to the user subscription or operator policy. If the UE receives an indication that the UE cannot be connected simultaneously through both 3GPP and non-3GPP accesses, the UE does not initiate a registration procedure to a PLMN through one access while the UE is registered to the same PLMN through another access.
[0084] Figure 3 shows the registration procedure when the UE cannot be registered to the same AMF for 3GPP access and non-3GPP access simultaneously within a PLMN.
[0085] The detailed procedure of the third embodiment is described below.
[0086] 0. The UE is registered with a non-geographically selected AMF (i.e., AMF-NG) through non-3GPP access, and a 5G-GUTI is assigned to the UE. A NAS security context is created for the non-3GPP access. For example, the UE and the non-geographically selected AMF have a non-3GPP access NAS security context.
[0087] 1a-1b. The UE initiates a registration procedure over 3GPP access. The UE performs integrity protection on the registration request message using the NAS security context of the non-3GPP access. The UE sends a registration request message (e.g., an integrity-protected registration request message). The registration request message includes a 5G-GUTI, a user-preferred access type, and a NAS connection identifier set to 3GPP access. The user-preferred access type indicates an access type that is preferred (e.g., has a higher priority) for registration when registration over both access types is not possible. The user-preferred access type may be set to either 3GPP access or non-3GPP access. For example, a user-preferred access type set to 3GPP access indicates that the UE prefers registration over 3GPP access when registration over both access types is not possible. For example, a user-preferred access type set to non-3GPP access indicates that the UE prefers registration over non-3GPP access when registration over both access types is not possible. The unique NAS connection identifier value (or the value of the NAS connection identifier) is set to "0x01" for 3GPP access and to "0x02" for non-3GPP access.
[0088] 2. When the AMF-G receives a registration request message including a 5G-GUTI from the UE, the AMF-G identifies a target AMF using the 5G-GUTI received in the registration request message. The target AMF may be the AMF for which the AMF-G performs Namf_Communication_UEContextTransfer. The AMF-G sends a Namf_Communication_UEContextTransfer request message, and the Namf_Communication_UEContextTransfer request message includes an access type set to 3GPP access and an integrity-protected NAS message. The Namf_Communication_UEContextTransfer request message may include the NAS connection identifier received in the registration request message. The integrity-protected NAS message may be the integrity-protected registration request message received in step 2. The integrity-protected NAS message may be referred to as a full registration request or an integrity-protected full registration request NAS message in this disclosure. For example, if the AMF-G identifies the AMF-NG as the target AMF using the 5G-GUTI received in the registration request message, the AMF-G sends a Namf_Communication_UEContextTransfer request message to the AMF-NG, and the Namf_Communication_UEContextTransfer request message includes an access type set to 3GPP access (or any other indication for identifying 3GPP access) and an integrity protected NAS message.
[0089] 3. When the AMF-NG receives a Namf_Communication_UEContextTransfer request message from the AMF-G, the AMF-NG performs integrity checking of the integrity-protected NAS message using the NAS security context in the AMF-NG for the UE, even if the AMF-NG does not have an MM context for 3GPP access. In this case, the AMF-NG uses the 0 (zero) value of the UL NAS COUNT integrity protection parameter for integrity checking of the received integrity-protected NAS message.
[0090] If the integrity is successfully verified, the AMF-NG determines whether non-3GPP contexts (e.g., UE contexts for non-3GPP access, 5GMM contexts for non-3GPP access of the UE, and 5GSM contexts for non-3GPP access of the UE) can be transferred to the AMF-G. For example, if the N3IWF can only establish a connection with the AMF-NG, the AMF-NG determines that the non-3GPP contexts cannot be transferred to the AMF-G. For example, the AMF-NG takes into account the reachability between the N3IWF and the AMF-G and determines based on the network configuration of the N2 reference point between the N3IWF and the AMF-NG that the N3IWF can only establish a connection with the AMF-NG, and the AMF-NG determines that the non-3GPP contexts cannot be transferred to the AMF-G.
[0091] For example, AMF-NG determines that the access type in the Namf_Communication_UEContextTransfer request message is set to 3GPP and performs integrity check of the received integrity-protected NAS message using a NAS security context of non-3GPP access, even if the access type in the Namf_Communication_UEContextTransfer request message is set to 3GPP access.
[0092] For example, even if the access type in the Namf_Communication_UEContextTransfer request message is set to 3GPP access, AMF-NG uses the NAS security context of non-3GPP access to perform integrity check of received integrity-protected NAS messages.
[0093] For example, if AMF-NG receives a NAS connection identifier configured for non-3GPP access, AMF-NG may perform integrity checking of the received integrity-protected NAS message using the NAS security context of the non-3GPP access.
[0094] For example, if the AMF-NG determines that the NAS connection identifier is set to non-3GPP access, the AMF-NG may determine that the integrity-protected NAS message is protected by the non-3GPP access NAS security context. The AMF-NG may then perform integrity checking of the received integrity-protected NAS message using the non-3GPP access NAS security context.
[0095] 4. AMF-NG sends a Namf_Communication_UEContextTransfer response message to AMF-G containing a cause (or information) indicating that the non-3GPP context cannot be transferred to AMF-G.
[0096] For example, if AMF-NG takes into account the reachability between N3IWF and AMF-G and determines based on the network configuration of the N2 reference point between N3IWF and AMF-NG that N3IWF can only establish a connection with AMF-NG and that AMF-NG cannot transfer non-3GPP contexts to AMF-G, AMF-NG sends a Namf_Communication_UEContextTransfer response message to AMF-G.
[0097] For example, if AMF-NG takes into account the reachability between N3IWF and AMF-G and determines based on the network configuration of the N2 reference point between N3IWF and AMF-NG that N3IWF can only establish a connection with AMF-NG, and AMF-NG determines that non-3GPP contexts cannot be transferred to AMF-G, AMF-NG may send a Namf_Communication_UEContextTransfer response message to AMF-G that includes a cause (or information) indicating that N3IWF can only establish a connection with AMF-NG.
[0098] 5. Upon receiving a Namf_Communication_UEContextTransfer response message with a cause indicating that the non-3GPP context cannot be transferred (or a cause indicating that the N3IWF can only establish a connection with AMF-NG), depending on at least one of the operator's policy, the user subscription from the UDM (e.g., whether the 3GPP access subscription has a higher priority than the non-3GPP access, or whether the non-3GPP access subscription has a higher priority than the 3GPP access), and the user's preferred access type indicated in the registration request message in step 1b, the AMF-G may approve the registration procedure in 3GPP access and deregister the UE in non-3GPP access, or may reject the registration procedure in 3GPP access (e.g., if the non-3GPP access subscription has a higher priority). For example, the AMF-G performs option A (steps 6a to 7a) or option B (steps 6b to 7b). The operator's policy may indicate whether a 3GPP access subscription has higher priority than a non-3GPP access or whether a non-3GPP access subscription has higher priority than a 3GPP access. The operator's policy may be configured for the AMF-G, or the AMF-G may receive the operator's policy from another network node.
[0099] Option A:6a. If the AMF-G approves the registration procedure based on the decision in step 5, the AMF-G sends a registration accept message to the UE, with the registration result type (or registration result) set to 3GPP access. The registration result type set to 3GPP access may indicate the completion of registration for 3GPP access. In addition, the AMF-G includes an existing information element (e.g., 5GMM cause) or a new information element in the registration accept message to indicate that the AMF-G cannot simultaneously register the UE for 3GPP access and non-3GPP access. The existing information element (e.g., 5GMM cause) or the new information element may also indicate that the non-3GPP access cannot move to an AMF of geographical choice (e.g., AMF-G) or that the UE cannot be connected via both 3GPP access and non-3GPP access simultaneously.
[0100] For example, when the AMF-G receives the user's preferred access type set in the 3GPP access, the AMF-G approves the registration procedure in the 3GPP access, and the AMF-G sends a registration approval message.
[0101] For example, if the AMF-G receives a user subscription from the UDM indicating that the 3GPP access subscription has a higher priority than the non-3GPP access (or information indicating that the 3GPP access has a higher priority than the non-3GPP access), the AMF-G approves the registration procedure in the 3GPP access and sends a registration approval message.
[0102] For example, if the AMF-G determines that the operator's policy indicates that a 3GPP access subscription has higher priority than a non-3GPP access (or indicates that a 3GPP access has higher priority than a non-3GPP access), the AMF-G approves the registration procedure in the 3GPP access, and the AMF-G sends a registration approval message.
[0103] 7a. When the UE receives a registration accept message containing an existing information element or a new information element as described in step 6a, the UE considers the UE to be registered for 3GPP access only.
[0104] 8a. When the UE receives the registration accept message containing the existing or new information elements as described in step 6a, the UE initiates the UE-initiated deregistration procedure for non-3GPP access according to 3GPP TS 36.211.
[0105] Option B:6b. When the non-3GPP access subscription has a higher priority than the 3GPP access, if the AMF-G rejects the registration procedure based on the decision in step 5, the AMF-G rejects the registration procedure for the 3GPP access and sends a registration reject message including a new information element to the UE to indicate that the AMF-G cannot simultaneously register the UE for 3GPP access and non-3GPP access. The new information element may also indicate that the non-3GPP access cannot be moved to an AMF of geographical choice or that the UE cannot be connected through both 3GPP access and non-3GPP access simultaneously.
[0106] For example, if the AMF-G receives a user's preferred access type set to non-3GPP access, the AMF-G rejects the registration procedure in 3GPP access and sends a registration reject message.
[0107] For example, if the AMF-G receives a user subscription from the UDM indicating that a non-3GPP access subscription has a higher priority than 3GPP access (or information indicating that a non-3GPP access has a higher priority than 3GPP access), the AMF-G rejects the registration procedure in the 3GPP access and sends a registration reject message.
[0108] For example, if the AMF-G determines that the operator's policy indicates that a non-3GPP access subscription has higher priority than a 3GPP access (or indicates that a non-3GPP access has higher priority than a 3GPP access), the AMF-G rejects the registration procedure in the 3GPP access and sends a registration reject message.
[0109] 7b. When the UE receives a registration reject message containing the new information element as described in step 6b, the UE considers that the UE is registered only in non-3GPP access. For example, in step 7b, the UE is registered in AMF-NG through non-3GPP access.
[0110] 8b. The UE shall not initiate a registration procedure via 3GPP access while the UE is registered via non-3GPP access in the same PLMN.
[0111] <Variation 1 of the third embodiment> In step 7a, the UE may be registered with AMF-G through 3GPP access, and the UE may be registered with AMF-NG through non-3GPP access. In this case, the UE maintains a 5G-GUTI for the non-3GPP access and an associated MM context for the non-3GPP access. In this variant 1, even if both 3GPP access and non-3GPP access are provided by the same PLMN, the UE maintains two 5G-GUTIs, one for 3GPP access and another for non-3GPP access. In this case, step 8a is not performed by the UE to maintain the non-3GPP access registered with AMF-NG.
[0112] <Third variant 2> After step 8a, the UE may initiate the registration procedure over non-3GPP access using the 5G-GUTI allocated by the AMF-G.
[0113] <Third variant 3> Although the UE is accessing through 3GPP access, in step 1b the UE includes a NAS connection identifier configured for non-3GPP access in the registration request message. This is an explicit indication to the AMF-G that the UE has performed integrity protection for the registration request message using the NAS security context for non-3GPP access. With this indication, the AMF-G includes the access type configured for non-3GPP access in a Namf_Communication_UEContextTransfer request message and sends this message to AMF-NG in step 2. Then, in step 3, AMF-NG performs integrity checking of the received integrity-protected NAS message using the NAS security context for non-3GPP access based on the received access type configured for non-3GPP access.
[0114] <Variation 4 of the third embodiment> Although the UE is accessing through 3GPP access, in step 1b the UE includes a NAS connection identifier configured for non-3GPP access in the registration request message. This is an explicit indication to the AMF-G that the UE has performed integrity protection for the registration request message using the NAS security context for non-3GPP access. With this indication, the AMF-G includes the access type configured for non-3GPP access in a Namf_Communication_UEContextTransfer request message and sends this message to AMF-NG in step 2. Then, in step 3, AMF-NG performs integrity checking of the received integrity-protected NAS message using the NAS security context for non-3GPP access based on the received access type configured for non-3GPP access.
[0115] <Third variant 5> In step 2, the AMF-G includes the access type set to non-3GPP access in a Namf_Communication_UEContextTransfer request message and sends this message to the AMF-NG if the AMF-G knows that the AMF-NG is a non-geographically selected AMF based on the assigned 5G-GUTI or local configuration in the AMF-G. Then, in step 3, the AMF-NG performs integrity check of the received integrity-protected NAS message using the NAS security context of non-3GPP access based on the received access type set to non-3GPP access.
[0116] <Fourth aspect> When AMF relocation occurs during a registration procedure as defined in Non-Patent Document 4, the initial AMF sends a Namf_Communication_UEContextTransfer request message to the old AMF (AMF3) to obtain the UE context. The initial AMF (AMF1) may be the AMF for sending the Namf_Communication_UEContextTransfer request message. If the integrity is successfully confirmed, the old AMF sends the UE context to the initial AMF. If the initial AMF cannot process the request NSSAI but determines that the request NSSAI can be processed by the target AMF, the initial AMF forwards the registration request message to the target AMF (AMF2) via NG-RAN. There may be cases where the initial AMF decrypts the NAS message container of the registration request message and sends the registration request message included in the NAS message (or NAS container). However, when the integrity-protected registration request message received by the initial AMF from the UE is not sent from the initial AMF to the target AMF, it is unclear how the target AMF fetches the UE context from the old AMF. For example, when the initial AMF forwards a registration request message to the target AMF, it is not clear how the UE validation is performed by the old AMF. In this case, the registration request message received by the target AMF may not be the same as the one sent from the UE to the initial AMF, and the UE validation in the old AMF may fail.
[0117] A fourth aspect solves the above problem and discloses a method for fetching a UE context from an old AMF by a target AMF during an AMF relocation procedure when the target AMF does not have an integrity-protected registration request message. In a scenario in which an initial AMF receives a UE context from an old AMF after successfully verifying the integrity of the registration request message in the old AMF, when the UE integrity-protected registration request message passes the integrity verification in the old AMF, the initial AMF marks the UE as verified, i.e., the UE is a true UE. When the initial AMF sends a reroute NAS message to the NG-RAN, the initial AMF includes an information element and a SUPI (e.g., a SUPI for the UE) indicating that the UE has been verified. Upon receiving the reroute NAS message, the NG-RAN sends an initial NAS message including the information element and the SUPI to the target AMF. When the target AMF receives the reroute NAS message (or the initial NAS message) having the information element and the SUPI, the target AMF sends a Namf_Communication_UEContextTransfer request message to the old AMF, and the Namf_Communication_UEContextTransfer request message includes the SUPI and an information element indicating that the UE has been verified. When the target AMF receives the Namf_Communication_UEContextTransfer request message including the information element indicating that the UE has been verified and the SUPI, the target AMF sends a Namf_Communication_UEContextTransfer response message including the UE context corresponding to the SUPI. Upon receiving the message, the target AMF further processes the registration procedure.
[0118] The detailed steps of the fourth aspect are described below.
[0119] The initial AMF and target AMF register their functions in the NRF.
[0120] 1. The UE initiates the registration procedure in idle mode by sending a registration request message to the (R)AN in an RRC setup complete message during the RRC connection setup procedure, and the (R)AN sends a registration request message to the initial AMF in an initial UE message.
[0121] 2. If the AMF needs SUPI and / or UE subscription information to determine whether to reroute the registration request, or if the registration request was not sent with integrity protection or the integrity protection is indicated as failed, the AMF performs an identity request response procedure, an authentication procedure, and a security mode command procedure. The registration request may be referred to as a registration request message in this disclosure.
[0122] For example, during step 2, after successfully verifying the integrity of the registration request message in the old AMF, the initial AMF receives a UE context for the UE from the old AMF, and when the UE integrity protected registration request message passes the integrity verification in the old AMF, the initial AMF marks the UE as verified, i.e., the UE is a true UE. For example, the initial AMF sends a Namf_Communication_UEContextTransfer message to the old AMF to obtain the UE context, and receives a Namf_Communication_UEContextTransfer response including the UE context from the old AMF. Steps 4 to 9b in Figure 4.2.2.2.2-1 of Non-Patent Document 4 may be performed.
[0123] 3a. If the initial AMF requires the UE's subscription information to determine whether to reroute the registration request and the UE's slice selection subscription information is not provided by the old AMF, the AMF selects UDM.
[0124] 3b. From initial AMF to UDM: Nudm_SDM_Get(SUPI, slice selection subscription data). For example, the initial AMF sends Nudm_SDM_Get to the UDM, where Nudm_SDM_Get includes the SUPI and the slice selection subscription data. The initial AMF requests the UE's slice selection subscription data from the UDM by invoking the Nudm_SDM_Get service operation. The UDM may obtain this information from the UDR via Nudr_DM_Query(SUPI, slice selection subscription data). For example, the UDM may obtain this information from the UDR via Nudr_DM_Query, where Nudr_DM_Query includes the SUPI and the slice selection subscription data.
[0125] 3c. From UDM to initial AMF: Response to Nudm_SDM_Get. For example, the UDM sends a response to Nudm_SDM_Get to the initial AMF. The AMF obtains slice selection subscription data including the subscribe S-NSSAI. The UDM responds to the initial AMF with the slice selection data.
[0126] 4a. From the initial AMF to the NSSF: Nnssf_NSSelection_Get(Requested-NSSAI, [Mapping of Requested-NSSAI], Subscribed-S-NSSAI with default S-NSSAI indication, [NSSRG information] TAI, Authorized-NSSAI for other access types (if any), [Mapping of Authorized-NSSAI], PLMN ID of SUPI). For example, the initial AMF may send Nnssf_NSSelection_Get to the NSSF, where Nnssf_NSSelection_Get includes the Requested-NSSAI, Mapping of Requested-NSSAI, Subscribed-S-NSSAI with default S-NSSAI indication, NSSRG information, TAI, Authorized-NSSAI for other access types (if any), Mapping of Authorized-NSSAI, and PLMN ID of SUPI.
[0127] If slice selection is required and, for example, the initial AMF cannot provide service to all S-NSSAIs from the requested NSSAI that are allowed by the subscription information, the initial AMF invokes the Nnssf_NSSelection_Get service operation from the NSSF by including the requested NSSAI, optionally the mapping of the requested NSSAI, the subscribed S-NSSAI with the default S-NSSAI indication, the [NSSRG information], the allowed NSSAIs for other access types (if any), the mapping of the allowed NSSAIs, the PLMN ID of the SUPI, and the TAI of the UE.
[0128] If available, the AMF includes NSSRG information regarding the S-NSSAI of the HPLMN as defined in section 5.15.12 of non-patent document 3, and the NSSRG information includes information regarding whether the UE indicates support for subscription-based restrictions on simultaneous registration of network slices and whether the UDM indicates to provide all subscribed S-NSSAIs to non-supporting UEs.
[0129] 4b. From NSSF to initial AMF: Response to Nnssf_NSSelection_Get (list of AMF sets or AMF addresses, allowed NSSAI for first access type, [mapping of allowed NSSAI], [allowed NSSAI for second access type], [mapping of allowed NSSAI], [NSI ID], [NRF], [list of rejections (S-NSSAI, cause value)], [configured NSSAI for serving PLMN], [mapping of configured NSSAI]). For example, the NSSF may send a response to Nnssf_NSSelection_Get to the initial AMF, and the response to Nnssf_NSSelection_Get includes a list of AMF sets or AMF addresses, authorized NSSAIs for the first access type, mappings of authorized NSSAIs, authorized NSSAIs for the second access type, mappings of authorized NSSAIs, NSI IDs, NRFs, a list of rejections (S-NSSAI, cause values), configured NSSAIs for the serving PLMN, and mappings of configured NSSAIs.
[0130] The NSSF returns to the initial AMF the authorized NSSAIs for the first access type, optionally the mapping of the authorized NSSAIs, the authorized NSSAIs for the second access type (if any), optionally the mapping of the authorized NSSAIs, and the target AMF set or a list of candidate AMFs based on the configuration. The NSSF may return the NSI ID associated with the network slice instance corresponding to the specific S-NSSAI. The NSSF may return the NRF used to select an NF / service within the selected network slice instance. The NSSF may also return information about the rejection cause for the S-NSSAIs not included in the authorized NSSAIs. The NSSF may return the configured NSSAIs for the serving PLMN, and possibly the associated mapping of the configured NSSAIs. If NSSRG information was not included in the request, the NSSF provides the configured NSSAI.
[0131] 5. From the initial AMF to the old AMF: Namf_Communication_RegistrationStatusUpdate (cause of failure). For example, the initial AMF may send a Namf_Communication_RegistrationStatusUpdate including the cause of failure to the old AMF.
[0132] If another AMF is selected, the initial AMF sends a rejection indication to the old AMF indicating that the UE registration procedure was not fully completed in the initial AMF. The old AMF continues as if Namf_Communication_UEContextTransfer had never been received.
[0133] 6a. From initial AMF to NRF: Nnrf_NFDiscovery_Request(NF type, AMF set). For example, the initial AMF may send a Nnrf_NFDiscovery_Request to the NRF, where the Nnrf_NFDiscovery_Request includes the NF type and AMF set.
[0134] If the initial AMF does not have the target AMF address stored locally, and if the initial AMF intends to use direct reroute to the target AMF or if reroute via an (NG-R)AN message needs to include an AMF address, the initial AMF invokes the Nnrf_NFDiscovery_Request service operation from the NRF to find a suitable target AMF that has the NF capabilities required to serve the UE. The NF type is set to AMF. The AMF set is included in the Nnrf_NFDiscovery_Request.
[0135] 6b. From NRF to AMF: Response to Nnrf_NFDiscovery_Request (list of (AMF pointer, AMF address, plus additional selection rules and NF capabilities)). For example, the NRF may send a response to the Nnrf_NFDiscovery_Request to the initial AMF, and the response to the Nnrf_NFDiscovery_Request includes a list of (AMF pointer, AMF address, plus additional selection rules and NF capabilities).
[0136] The NRF responds with a list of potential target AMFs. The NRF may also provide details of the services offered by the candidate AMFs, along with notification endpoints for each type of notification service that the selected AMF has registered with the NRF, if available. Alternatively, the NRF provides a list of potential target AMFs and their capabilities, and optionally additional selection rules. Based on information about the registered NFs and the required capabilities, the target AMF is selected by the initial AMF.
[0137] If a security association is established between the UE and the initial AMF to avoid registration failure, the initial AMF shall forward the NAS message to the target AMF by performing step 7(A).
[0138] If the initial AMF is not part of the target AMF set and is unable to obtain a list of candidate AMFs by querying an NRF that has the target AMF set (for example, if an NRF pre-configured locally on the AMF does not provide the required information and a query to an appropriate NRF provided by the NSSF is not successful, or if the initial AMF has knowledge that the initial AMF is not authorized as a serving AMF), the initial AMF shall perform step 7(B) and forward the NAS message to the target AMF via the (R)AN, unless a security association has been established between the UE and the initial AMF, and the authorized NSSAI and AMF set are included to enable the (R)AN to select the target AMF.
[0139] 7(A). If, based on local policy and subscription information, the initial AMF decides to forward the NAS message directly to the target AMF, the initial AMF invokes Namf_Communication_N1MessageNotify to the target AMF to convey the rerouted NAS message. The Namf_Communication_N1MessageNotify service operation includes AN access information (e.g., information that enables the (R)AN to identify the N2 termination point, the CAG identifier of the CAG cell) and a full registration request message, as well as the UE's SUPI, an information element indicating that the UE is verified, and, if available, the MM context. If the initial AMF obtained information from the NSSF as described in step 4b, that information, excluding the AMF set or the list of AMF addresses, is included. The target AMF then updates the (R)AN with the new updated N2 termination point for the UE in a first message from the target AMF to the RAN in step 8. For example, after successfully checking the integrity of a registration request message in the old AMF, the initial AMF receives a UE context for the UE from the old AMF, and when the registration request message with UE integrity protection passes the integrity check in the old AMF, the initial AMF marks the UE as verified, i.e., if the UE is a true UE, the initial AMF includes an information element indicating that the UE has been verified in Namf_Communication_N1MessageNotify. For example, after successfully checking the integrity of a registration request message in the old AMF, the initial AMF receives a UE context for the UE from the old AMF, and when the registration request message with UE integrity protection passes the integrity check in the old AMF, the initial AMF marks the UE as verified, i.e., if the UE is a true UE, the initial AMF includes the UE context (e.g., the MM context for the UE) and an information element indicating that the UE has been verified in Namf_Communication_N1MessageNotify. The information element may indicate that the initial AMF receives the UE context for the UE from the old AMF after successfully verifying the integrity of the registration request message in the old AMF.The information element may indicate that when the registration request message of the UE integrity protection passes the integrity check in the old AMF, the initial AMF marks the UE as verified, i.e., the UE is a real UE. The information element may indicate that there is no need to perform integrity check on the registration request message.
[0140] If the target AMF receives a Namf_Communication_N1MessageNotify message containing a SUPI, an information element indicating that the UE is verified, and an MM context, the target AMF does not invoke the Namf_Communication_UEContextTransfer service and the target AMF continues the registration procedure as defined in non-patent document 4 (the target AMF corresponds to the new AMF).
[0141] 7(B). If, based on local policy and subscription information, the initial AMF decides to forward the NAS message to the target AMF via the (R)AN, unless the target AMF is not returned from the NSSF and is identified by the list of candidate AMFs, the initial AMF sends a reroute NAS message to the (R)AN (step 7a of step 7(B)). The reroute NAS message includes information about the target AMF and the full registration request message. If the initial AMF received the MM context from the old AMF in step 2 when the old AMF successfully verified the integrity of the registration request message or the authentication procedure was successfully performed in step 2, the initial AMF includes the SUPI and an information element indicating that the UE is verified. The (R)AN sends an initial UE message to the target AMF (step 7b of step 7(B)) indicating reroute by slicing, including the information from step 4b provided by the NSSF. The NG-RAN also includes the SUPI, the information element indicating that the UE is verified, and other received information elements in the reroute NAS message for the initial NAS message.
[0142] For example, after successfully checking the integrity of a registration request message in the old AMF, the initial AMF receives a UE context for the UE from the old AMF, and when the registration request message with UE integrity protection passes the integrity check in the old AMF, the initial AMF marks the UE as verified, i.e., if the UE is a true UE, the initial AMF includes in the reroute NAS message an information element indicating that the UE is verified. For example, after successfully checking the integrity of a registration request message in the old AMF, the initial AMF receives a UE context for the UE from the old AMF, and when the registration request message with UE integrity protection passes the integrity check in the old AMF, the initial AMF marks the UE as verified, i.e., if the UE is a true UE, the initial AMF includes in the reroute NAS message the UE context (e.g., the MM context for the UE) and an information element indicating that the UE is verified.
[0143] 8. If the target AMF receives the SUPI and an information element indicating that the UE is verified, the target AMF sends the SUPI and an information element indicating that the UE is verified to the old AMF in a Namf_Communication_UEContextTransfer message. Upon receiving a Namf_Communication_UEContextTransfer message with the SUPI and an information element indicating that the UE is verified, the old AMF sends the UE context to the target AMF in a Namf_Communication_UEContextTransfer response message without performing integrity check.
[0144] If the target AMF does not receive the SUPI and the information element indicating that the UE is verified, upon receiving the registration request message sent in step 7a of step 7(A) or step 7b of step 7(B), the target AMF continues the registration procedure as defined in 3GPP TS 36.110 (the target AMF corresponds to the new AMF), including the UE context obtained from the old AMF. If a 5G security context is obtained from the initial AMF, the target AMF continues to use the 5G security context instead of the 5G security context obtained from the old AMF. If the initial AMF decides to forward the NAS message to the target AMF (step 7(A)), the first message (initial context setup request or downlink NAS transport) from the target AMF to the (R)AN includes the AMF name of the initial AMF and the target AMF UE NGAP ID.
[0145] <Modification 1 of the fourth embodiment> In step 7a of 7(B), if the old AMF successfully verified the integrity of the registration request message or the initial AMF received the UE context from the old AMF in step 2 when the authentication procedure was successful in step 2, the initial AMF includes the SUPI, an information element indicating that the UE has been verified, and the MM context received from the old AMF. The (R)AN sends an initial UE message to the target AMF (step 7b) indicating reroute by slicing including the information from step 4b provided by the NSSF. The NG-RAN also includes the SUPI, the information element indicating that the UE has been verified, the MM context, and other received information elements in a reroute NAS message for the initial NAS message.
[0146] If the target AMF receives an initial NAS message including a SUPI, an information element indicating that the UE is verified, and an MM context, the target AMF does not invoke the Namf_Communication_UEContextTransfer service and the target AMF continues the registration procedure as defined in non-patent document 4 (the target AMF corresponds to the new AMF).
[0147] <Fourth variant 2> If the authentication procedure and the security mode command procedure are performed in step 2 of the fourth aspect, there is a case where the initial AMF has two registration request messages: one full registration request message (registration request message 1) received from the UE in step 1 and another one (registration request message 2) in the security command complete message. In this case, the initial AMF performs one of the following two options:
[0148] i) The initial AMF sends in a reroute NAS message the full registration request message (Registration Request Message 1) as received in step 1. When the target AMF receives this registration request message in the initial NAS message from the NG-RAN, the target AMF sends this registration request message to the old AMF in a Namf_Communication_UEContextTransfer request message to obtain the UE context from the old AMF.
[0149] ii) The initial AMF includes both Registration Request Message 1 and Registration Request Message 2 in a reroute NAS message to the (R)AN (e.g., NG-RAN). Upon receiving the reroute NAS message, the (R)AN includes these two Registration Request messages in an initial UE message to the target AMF. When the target AMF receives the initial UE message, the target AMF sends Registration Request Message 1 to the old AMF to obtain the UE context, and uses the information elements of Registration Request Message 2 to perform the registration procedure, for example, uses the requested NSSAI in Registration Request Message 2 to calculate the allowed NSSAI list.
[0150] In one example, the initial AMF puts the registration request message 1 into a first NAS PDU (an existing information element NAS PDU in the initial UE message) and puts the registration request message 2 into a second NAS PDU in the initial UE message (INITIAL UE MESSAGE). When the target AMF receives the initial registration request message from the (R)AN, the target AMF sends the first NAS PDU to the old AMF to obtain the UE context and uses the registration request message 2 in the second NAS PDU to process the registration procedure as defined above.
[0151] In one example, the initial AMF includes an explicit indication of which of the two registration request messages will be sent to the old AMF to obtain the UE context and which will be used to process the registration request message. Upon receiving the explicit indicator, the target AMF acts accordingly as described above.
[0152] <System Overview> FIG. 5 shows a schematic diagram of a mobile (cellular or wireless) telecommunications system 1 to which the above aspects are applicable.
[0153] The telecommunications system 1 represents an overview of a system capable of end-to-end communication, e.g., UEs 3 (or user equipment, "mobile devices" 3) communicating with other UEs 3 or service servers within a data network 20 via respective (R)AN nodes 5 and a core network 7.
[0154] The (R)AN node 5 supports any radio access, including 5G radio access technology (RAT), E-UTRA radio access technology, Beyond 5G RAT, 6G RAT, and non-3GPP RAT including wireless local area network (WLAN) technology as defined by the Institute of Electrical and Electronics Engineers (IEEE).
[0155] The (R)AN node 5 may be separated into a Radio Unit (RU), a Distributed Unit (DU), and a Centralized Unit (CU), which in some aspects may be connected to each other to form the (R)AN node 5 by employing an architecture such as that defined by the Open RAN (O-RAN) Alliance, where the above units are referred to as the O-RU, O-DU, and O-CU, respectively.
[0156] The (R)AN node 5 may be separated into control plane functions and user plane functions. Furthermore, multiple user plane functions may be allocated to support communications. In some aspects, user traffic may be distributed across multiple user plane functions, with user traffic in each user plane function being aggregated at both the UE 3 and the (R)AN node 5. This separated architecture may be referred to as "dual connectivity" or "multi-connectivity."
[0157] The (R)AN node 5 may also support communications using satellite access. In some aspects, the (R)AN node 5 may support satellite access and terrestrial access.
[0158] In addition, the (R)AN node 5 may also be referred to as an access node for non-wireless access, including fixed access as defined by the Broadband Forum (BBF) and optical access as defined by the Innovative Optical and Wireless Network (IOWN).
[0159] The core network 7 may include logical nodes (or "functions") that support communications in the telecommunications system 1. For example, the core network 7 may be a 5G Core Network (5GC) that includes, among other functions, control plane functions and user plane functions. Each function in a logical node may be considered a network function. A network function may be provided to another node by adapting a Service Based Architecture (SBA).
[0160] By applying network virtualization technologies such as those defined by the European Telecommunications Standards Institute, Network Functions Virtualization (ETSI NFV), network functions can be deployed as distributed, redundant, stateless, and scalable, providing services from several locations and providing several execution instances at each location.
[0161] The core network 7 may support a Non-Public Network (NPN), which may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0162] As is known, as a UE 3 moves around the geographic area covered by the telecommunications system 1, the UE 3 may move in and out of areas (i.e., radio cells) served by (R)AN nodes 5. To keep track of the UE 3 and facilitate movement between various (R)AN nodes 5, the core network 7 comprises at least one access and mobility management function (AMF) 70. The AMF 70 communicates with the (R)AN nodes 5 connected to the core network 7. In some core networks, a mobility management entity (MME) or mobility management node for Beyond 5G or a mobility management node for 6G may be used instead of the AMF 70.
[0163] The core network 7 also includes, among other things, a Session Management Function (SMF) 71, a User Plane Function (UPF) 72, a Policy Control Function (PCF) 73, a Network Exposure Function (NEF) 74, a Unified Data Management (UDM) 75, and a Network Data Analytics Function (NWDAF) 76. When a UE 3 roams into a visited Public Land Mobile Network (VPLMN), the home Public Land Mobile Network (HPLMN) of the UE 3 provides the UDM 75 and at least some of the functionality of the SMF 71, UPF 72, and PCF 73 to the roaming-out UE 3.
[0164] The UE 3 and each serving (R)AN node 5 are connected via an appropriate air interface (e.g., a so-called "Uu" interface and / or the like). Neighboring (R)AN nodes 5 are connected to each other via appropriate (R)AN node interfaces (e.g., a so-called "Xn" interface and / or the like). Each (R)AN node 5 is also connected to nodes in the core network 7 (e.g., so-called core network nodes) via appropriate interfaces (e.g., a so-called "N2" / "N3" interface and / or the like). From the core network 7, a connection is also provided to a data network 20. The data network 20 may be the Internet, a public network, an external network, a private network, or an internal network of a PLMN. If the data network 20 is provided by a PLMN operator or a Mobile Virtual Network Operator (MVNO), IP Multimedia Subsystem (IMS) services may be provided by the data network 20. The UE 3 may be connected to the data network 20 using IPv4, IPv6, IPv4v6, Ethernet, or unstructured data types.
[0165] The "Uu" interface may include a control plane of the Uu interface and a user plane of the Uu interface.
[0166] The user plane of the Uu interface is responsible for carrying user traffic between the UE 3 and the serving (R)AN node 5. The user plane of the Uu interface may have a layered structure with SDAP, PDCP, RLC, and MAC sublayers over the physical connection.
[0167] The control plane of the Uu interface is responsible for establishing, modifying, and releasing the connection between the UE 3 and the serving (R)AN node 5. The control plane of the Uu interface may have a hierarchical structure with RRC, PDCP, RLC, and MAC sublayers depending on the physical connection.
[0168] For example, the following messages are communicated at the RRC layer to support AS signaling:
[0169] - RRC Setup Request message: This message is sent from the UE 3 to the (R)AN node 5. In addition to the parameters disclosed by aspects of the present disclosure, the following parameters may be included together in the RRC Setup Request message: --establishmentCause and ue-Identity. The ue-Identity may have the value of ng-5G-S-TMSI-Part1 or a random value.
[0170] RRC Setup Message: This message is sent from the (R)AN node 5 to the UE 3. In addition to the parameters disclosed by aspects of the present disclosure, the following parameters may be included together in the RRC Setup message: --Master cell group (masterCellGroup) and radio bearer configuration (radioBearerConfig).
[0171] - RRC Setup Complete message: This message is sent from the UE 3 to the (R)AN node 5. In addition to the parameters disclosed by aspects of the present disclosure, the following parameters may be included together in the RRC Setup Complete message: --guami type (guami-Type), iab node indication (iab-NodeIndication), idle measurement available (idleMeasAvailable), mobility state (mobilityState), ng-5G-S-TMSI-Part2 (ng-5G-S-TMSI-Part2), registered AMF (registeredAMF), selected PLMN identity (selectedPLMN-Identity).
[0172] The UE 3 and the AMF 70 are connected via an appropriate interface (e.g., a so-called N1 interface and / or the like). The N1 interface is responsible for providing communication between the UE 3 and the AMF 70 to support NAS signaling. The N1 interface can be established in 3GPP access and non-3GPP access. For example, the following messages are communicated on the N1 interface:
[0173] Registration Request Message: This message is sent from the UE 3 to the AMF 70. In addition to the parameters disclosed by aspects of the present disclosure, the following parameters may be included together in the registration request message: --5GS registration type, ngKSI, 5GS mobile identity, Non-current native NAS key set identifier, 5GMM capability, UE security capability, Requested NSSAI, Last visited registered TAI, S1 UE network capability, Uplink data status, PDU session status, MICO indication, UE status, Additional GUTI, Allowed PDU session status, UE's usage setting, Requested DRX parameters, EPS NAS message container, LADN indication, Payload container type, Payload container container, Network slicing indication, 5GS update type, Mobile station classmark 2, Supported codecs, NAS message container, EPS bearer context status, Requested extended DRX parameters, T3324 value, UE radio capability IDID), Requested mapped NSSAI, Additional information requested, Requested WUS assistance information, N5GC indication, and Requested NB-N1 mode DRX parameters.
[0174] Registration Accept Message: This message is sent from the AMF 70 to the UE 3. In addition to the parameters disclosed by aspects of the present disclosure, the following parameters may be included together in the registration accept message: --5GS registration result, 5G-GUTI, Equivalent PLMNs, TAI list, Allowed NSSAI, Rejected NSSAI, Configured NSSAI, 5GS network feature support, PDU session status, PDU session reactivation result, PDU session reactivation result error cause, LADN information, MICO indication, Network slicing indication, Service area list, T3512 value, Non-3GPP de-registration timer value, T3502 value, Emergency number list list, Extended emergency number list, SOR transparent container, EAP message, NSSAI inclusion mode, Operator-defined access category definitions, Negotiated DRX parameters, Non-3GPP NW policies, EPS bearer context status, Negotiated extended DRX parameters, T3447 value, T3448 valuevalue, T3324 value, UE radio capability ID, UE radio capability ID deletion indication, Pending NSSAI, Ciphering key data, CAG information list, Truncated 5G-S-TMSI configuration, Negotiated WUS assistance information, Negotiated NB-N1 mode DRX parameters, and Extended rejected NSSAI.
[0175] Registration Complete Message: This message is sent from the UE 3 to the AMF 70. In addition to the parameters disclosed by the aspects of the present disclosure, the following parameters may be included together in the registration complete message: --SOR transparent container.
[0176] -Authentication Request Message: This message is sent from the AMF 70 to the UE 3. In addition to the parameters disclosed by aspects of the present disclosure, the following parameters may be included together in the Authentication Request message: --ngKSI, ABBA, Authentication parameter RAND (5G authentication challenge), Authentication parameter AUTN (5G authentication challenge), and EAP message.
[0177] Authentication Response Message: This message is sent from the UE 3 to the AMF 70. In addition to the parameters disclosed by aspects of the present disclosure, the following parameters may be present together in the authentication response message: Authentication response message identity, authentication response parameters, and EAP message.
[0178] -Authentication Result Message: This message is sent from the AMF 70 to the UE 3. In addition to the parameters disclosed by aspects of the present disclosure, the following parameters may be present together in the Authentication Result Message: --ngKSI, EAP message, and ABBA.
[0179] Authentication Failure Message: This message is sent from the UE 3 to the AMF 70. In addition to the parameters disclosed by aspects of the present disclosure, the following parameters may be present together in the Authentication Failure Message: --Authentication failure message identity, 5GMM cause, and authentication failure parameter.
[0180] -Authentication Rejection Message: This message is sent from the AMF 70 to the UE 3. In addition to the parameters disclosed by aspects of the present disclosure, the following parameters may be present together in the authentication rejection message: --EAP message.
[0181] - Service Request Message: This message is sent from the UE 3 to the AMF 70. In addition to the parameters disclosed by aspects of the present disclosure, the following parameters may be present together in the Service Request Message: --ngKSI, Service type, 5G-S-TMSI, Uplink data status, PDU session status, Allowed PDU session status, NAS message container.
[0182] - Service Authorization Message: This message is sent from the AMF 70 to the UE 3. In addition to the parameters disclosed by aspects of the present disclosure, the following parameters may be present together in the Service Authorization Message: --PDU session status, PDU session reactivation result, PDU session reactivation result error cause, EAP message, and T3448 value.
[0183] - Service Rejection Message: This message is sent from the AMF 70 to the UE 3. In addition to the parameters disclosed by aspects of the present disclosure, the following parameters may be present together in the Service Rejection Message: --5GMM cause, PDU session status, T3346 value, EAP message, T3448 value, and CAG information list.
[0184] Configuration Update Command Message: This message is sent from the AMF 70 to the UE 3. In addition to the parameters disclosed by aspects of the present disclosure, the following parameters may be present together in the Configuration Update Command message: --Configuration update indication, 5G-GUTI, TAI list, Allowed NSSAI, Service area list, Full name for network, Short name for network, Local time zone, Universal time and local time zone, Network daylight saving time, LADN information, MICO indication, Network slicing indication, Configured NSSAI, Rejected NSSAI, Operator-defined access category definitions, SMS indication, T3447 value, CAG information list, UE radio capability ID, UE radio capability ID deletion indication indication, 5GS registration result, Truncated 5G-S-TMSI configuration, Additional configuration indication, and Extended rejected NSSAI.
[0185] Configuration Update Complete message: This message is sent from the UE 3 to the AMF 70. In addition to the parameters disclosed by aspects of the present disclosure, the following parameters may be present together in the configuration update complete message: --Configuration update complete message identity.
[0186] <User equipment (UE)> FIG. 6 is a block diagram illustrating the main components of a mobile device 3 (UE 3). As shown, the UE 3 includes a transceiver circuit 31 operable to transmit signals to and receive signals from a connection node via one or more antennas 32. The UE 3 may also include a user interface 34 for inputting and outputting information from an external device. Although not necessarily illustrated, the UE 3 may have all the usual functions of a conventional mobile device, which may be provided by any one or any combination of hardware, software, and firmware, as needed. For example, the software may be pre-installed in memory and / or downloaded via a telecommunications network or from a removable data storage device (RMD). The controller 33 controls the operation of the UE 3 in accordance with software stored in the memory 36. The software includes, among other things, an operating system 361 and a communication control module 362 having at least a transceiver control module 3621. The communications control module 362 (using its transceiver control module) 3621) is responsible for handling (generating / sending / receiving) signaling and uplink / downlink data packets between the UE 3 and other nodes, such as the (R)AN node 5 and the AMF 10. Such signaling may include, for example, appropriately formatted signaling messages (e.g., registration request messages and associated response messages) related to access and mobility management procedures (for the UE 3). The controller 33 interacts with one or more Universal Subscriber Identity Modules (USIMs) 35. In the case of multiple USIMs 35, the controller 33 may activate only one USIM 35 or may activate multiple USIMs 35 simultaneously.
[0187] The UE 3 may, for example, support a Non-Public Network (NPN), which may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0188] UE3 may be, for example, an item of production or manufacturing equipment and / or an item of energy-related machinery (e.g., equipment or machinery such as boilers, engines, turbines, solar panels, wind turbines, hydroelectric generators, thermal generators, nuclear generators, batteries, nuclear systems and / or related equipment, heavy electrical machinery, pumps including vacuum pumps, compressors, fans, blowers, hydraulic equipment, pneumatic equipment, metalworking machinery, manipulators, robots and / or application systems thereof, tools, molds or dies, rolls, conveying equipment, lifting equipment, material handling equipment, textile machinery, sewing machinery, printing machinery and / or related machinery, paper converting machinery, chemical machinery, mining machinery and / or construction machinery and / or related equipment, agricultural, forestry, and / or fishing machinery and / or implements, safety and / or environmental protection equipment, tractors, precision bearings, chains, gears, power transmission equipment, lubrication equipment, valves, fittings, and / or application systems for any of the foregoing equipment or machines).
[0189] UE 3 may be, for example, an item of transportation equipment (e.g., vehicles, automobiles, motorcycles, bicycles, trains, buses, carts, rickshaws, ships and other watercraft, aircraft, rockets, satellites, drones, balloons, etc.).
[0190] The UE 3 may be, for example, an item of information and communications equipment (eg, information and communications equipment such as electronic computers and related equipment, communications and related equipment, electronic components, etc.).
[0191] The UE3 may be, for example, a refrigeration machine, a refrigeration machine application product, an item of commercial and / or service industry equipment, a vending machine, an automated service machine, an office machine or device, a consumer electronic device and appliance (e.g., consumer electronic appliances such as audio equipment, video equipment, loudspeakers, radios, televisions, microwave ovens, rice cookers, coffee machines, dishwashers, washing machines, dryers, electronic fans or related appliances, vacuum cleaners, etc.).
[0192] The UE 3 may be, for example, an electrical application system or device (eg, an electrical application system or device such as an x-ray system, a particle accelerator, a radioisotope device, a sonic device, an electromagnetic application device, a power application device, etc.).
[0193] The UE3 may be, for example, an electronic lamp, a lighting fixture, a measuring instrument, an analyzer, a tester, or a surveying or detecting device (e.g., a smoke alarm, a occupancy alarm sensor, a motion sensor, a radio tag, or other surveying or detecting device), a watch or wall clock, laboratory equipment, optical equipment, medical equipment and / or systems, a weapon, an item of cutlery, a hand tool, or the like.
[0194] UE3 may be, for example, a wireless-equipped personal digital assistant or related equipment (such as a wireless card or module designed to be attached to or inserted into another electronic device (e.g., a personal computer, electrical measuring machine)).
[0195] The UE 3 may be part of a device or system that uses various wired and / or wireless communication technologies to provide the applications, services, and solutions described below with respect to the "Internet of Things (IoT)."
[0196] Internet of Things devices (or "Things") may be equipped with appropriate electronics, software, sensors, network connectivity, and / or the like, allowing them to collect and exchange data with each other and with other communicating devices. IoT devices may comprise autonomous machines that follow software instructions stored in internal memory. IoT devices may operate without the need for human supervision or interaction. IoT devices may also remain stationary and / or idle for long periods of time. IoT devices may be implemented as part of (generally) stationary equipment. IoT devices may also be incorporated into non-stationary equipment (e.g., vehicles) or attached to animals or people being monitored / tracked.
[0197] It will be understood that IoT technology may be implemented on any communication device that can connect to a communication network to transmit / receive data, whether such communication device is controlled by human input or by software instructions stored in memory.
[0198] It will be appreciated that an IoT device is sometimes referred to as a Machine-Type Communication (MTC) device or a Machine-to-Machine (M2M) communication device, or a Narrow Band-IoT UE (NB-IoT UE). It will be appreciated that a UE 3 may support one or more IoT or MTC applications.
[0199] The UE 3 may be a smartphone or a wearable device (e.g., smart glasses, a smart watch, a smart ring, or a hearable device).
[0200] The UE3 may be a car, a connected car, an autonomous vehicle, a vehicle device, a motorcycle, or a Vehicle to Everything (V2X) communication module (e.g., a vehicle-to-vehicle communication module, a vehicle-to-infrastructure communication module, a vehicle-to-person communication module, and a vehicle-to-network communication module).
[0201] <(R)AN node> FIG. 7 is a block diagram illustrating the main components of an exemplary (R)AN node 5, e.g., a base station (eNB in LTE, gNB in 5G, a base station for Beyond 5G, or a base station for 6G). As shown, the (R)AN node 5 includes transceiver circuitry 51 operable to transmit signals to and receive signals from connected UEs 3 via one or more antennas 52, and to transmit signals to and receive signals from other network nodes (directly or indirectly) via a network interface 53. A controller 54 controls operation of the (R)AN node 5 according to software stored in memory 55. For example, the software may be pre-installed in the memory and / or downloaded via a telecommunications network or from a removable data storage device (RMD). The software includes, among other things, an operating system 551 and a communications control module 552 having at least a transceiver control module 5521.
[0202] The communication control module 552 (using its transceiver control sub-module) is responsible for processing (generating / sending / receiving) signaling between the (R)AN node 5 and other nodes such as the UE 3, another (R)AN node 5, the AMF 70, and the UPF 72, either directly or indirectly. The signaling may include, for example, properly formatted signaling messages related to the radio connection and connection with the core network 7 for a specific UE 3, particularly those related to connection establishment and maintenance, such as RRC connection establishment messages and other RRC messages, NG Application Protocol (NGAP) messages (i.e., messages based on the N2 reference point), Xn Application Protocol (XnAP) messages (i.e., messages based on the Xn reference point), etc. Such signaling may also include, in the case of transmission, for example, broadcast information (such as master information and system information).
[0203] When implemented, the controller 54 is also configured (by software or hardware) to handle related tasks such as UE mobility estimation and / or movement trajectory estimation.
[0204] (R)AN node 5 may support a Non-Public Network (NPN). The NPN may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0205] <System Overview of (R)AN Node 5 Based on the O-RAN Architecture> Figure 8 schematically shows the (R)AN node 5 based on the O-RAN architecture to which the (R)AN node 5 aspect is applicable.
[0206] The (R)AN node 5 based on the O-RAN architecture represents a system overview in which the (R)AN node is separated into a Radio Unit (RU) 60, a Distributed Unit (DU) 61, and a Centralized Unit (CU) 62. In some aspects, the units may be combined. For example, the RU 60 may be combined with the DU 61 as a combined / combined unit, and the DU 61 may be combined with the CU 62 as another combined / combined unit. Any functionality described for a unit (e.g., one of the RU 60, DU 61, and CU 62) may be implemented in the combined / combined unit. Furthermore, the CU 62 may be separated into two functional units, such as a CU Control plane (CP) and a CU User plane (UP). The CU CP has a control plane function in the (R)AN node 5. The CU UP has a user plane function in the (R)AN node 5. Each CU CP is connected to a CU UP via an appropriate interface (such as a so-called "E1" interface and / or the like).
[0207] The UE 3 and each serving RU 60 are connected via an appropriate air interface (e.g., a so-called "Uu" interface and / or the like). Each RU 60 is connected to a DU 61 via an appropriate interface (such as a so-called "fronthaul", "open fronthaul", "F1" interface, and / or the like). Each DU 61 is connected to a CU 62 via an appropriate interface (such as a so-called "midhaul", "open midhaul", "E2" interface, and / or the like). Each CU 62 is also connected to a node in the core network 7 (such as a so-called core network node) via an appropriate interface (such as a so-called "backhaul", "open backhaul", "N2" / "N3" interface, and / or the like). In addition, the user plane part of the DU 61 may also be connected to the core network node 7 via an appropriate interface (such as a so-called "N3" interface and / or the like).
[0208] Depending on the functionality split between the RU 60, DU 61, and CU 62, each unit provides a portion of the functionality provided by the (R)AN node 5. For example, the RU 60 may provide functionality for communicating with the UE 3 over the air interface, the DU 61 may provide functionality supporting the MAC and RLC layers, and the CU 62 may provide functionality supporting the PDCP, SDAP, and RRC layers.
[0209] <Radio Unit (RU)> FIG. 9 is a block diagram illustrating the main components of an exemplary RU 60, e.g., the RU portion of a base station (e.g., an eNB in LTE, a gNB in 5G, a base station for Beyond 5G, or a base station for 6G). As shown, the RU 60 includes a transceiver circuit 601 operable to transmit signals to and receive signals from an attached UE 3 via one or more antennas 602, and to transmit and receive signals to and from other network nodes or network portions via a network interface 603 (directly or indirectly). A controller 604 controls the operation of the RU 60 according to software stored in memory 605. For example, the software may be pre-installed in the memory and / or downloaded via a telecommunications network or from a removable data storage device (RMD). The software includes, among other things, an operating system 6051 and a communications control module 6052 having at least a transceiver control module 60521.
[0210] The communications control module 6052 (using its transceiver control sub-module) is responsible for handling (generating / sending / receiving) signaling between (e.g., directly or indirectly) the RU 60 and other nodes or entities, such as the UE 3, other RUs 60, and the DU 61. The signaling may include, for example, appropriately formatted signaling messages relating to the radio connection and connectivity with the RU 60 (for a particular UE 3), in particular the MAC and RLC layers.
[0211] When implemented, the controller 604 is also configured (by software or hardware) to handle related tasks such as UE mobility estimation and / or motion trajectory estimation.
[0212] The RU 60 may support a Non-Public Network (NPN), which may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0213] As described above, the RU 60 may be integrated / combined with the DU 61 as an integration / combination unit. Any function described for the RU 60 may be implemented in the integration / combination unit.
[0214] <Distributed Unit (DU)> FIG. 10 is a block diagram illustrating the main components of an exemplary DU 61, e.g., the DU portion of a base station (eNB in LTE, gNB in 5G, a base station for Beyond 5G, or a base station for 6G). As shown, the device includes a transceiver circuit 611 operable to transmit signals to and receive signals from other nodes or units (including the RU 60) via a network interface 612. A controller 613 controls the operation of the DU 61 according to software stored in memory 614. For example, the software may be pre-installed in memory 614 and / or downloaded via a telecommunications network or from a removable data storage device (RMD). The software includes, among other things, an operating system 6141 and a communication control module 6142 having at least a transceiver control module 61421. The communication control module 6142, using its transceiver control module 61421, is responsible for handling (generating / sending / receiving) signaling between the DU 61 and other nodes or units, such as the RU 60 and other nodes and units.
[0215] The DU 61 may support a Non-Public Network (NPN), which may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0216] As mentioned above, the RU 60 may be integrated / combined with the DU 61 or the CU 62 as an integrated / combined unit. Any functionality described for the DU 61 may be implemented in one of the integrated / combined units.
[0217] <Centralized Unit (CU)> FIG. 11 is a block diagram illustrating the main components of an exemplary CU 62, e.g., the CU portion of a base station (eNB in LTE, gNB in 5G, a base station for Beyond 5G, or a base station for 6G). As shown, the device includes a transceiver circuit 621 operable to transmit signals to and receive signals from other nodes or units (including the DU 61) via a network interface 622. A controller 623 controls the operation of the CU 62 according to software stored in memory 624. For example, the software may be pre-installed in the memory 624 and / or downloaded via a telecommunications network or from a removable data storage device (RMD). The software includes, among other things, an operating system 6241 and a communications control module 6242 having at least a transceiver control module 62421. The communication control module 6242, using its transceiver control module 62421, is responsible for handling (generating / sending / receiving) signaling between the CU 62 and other nodes or units, such as the DU 61 and other nodes and units.
[0218] CU 62 may support a Non-Public Network (NPN), which may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0219] As described above, the CU 62 may be integrated / combined with the DU 61 as an integration / combination unit. Any functionality described for the CU 62 may be implemented in the integration / combination unit.
[0220] <amf> 12 is a block diagram illustrating the main components of the AMF 70. As shown, the device includes a transceiver circuit 701 operable to transmit signals to and receive signals from other nodes (including UE 3) via a network interface 702. A controller 703 controls the operation of the AMF 70 in accordance with software stored in memory 704. For example, the software may be pre-installed in the memory 704 and / or downloaded via a telecommunications network or from a removable data storage device (RMD). The software includes, among other things, an operating system 7041 and a communications control module 7042 having at least a transceiver control module 70421. The communications control module 7042, using (its transceiver control module) 70421, is responsible for handling (generating / sending / receiving) signaling between the AMF 70 and other nodes, such as the UE 3 (e.g., via (R)AN node 5) and other nodes, such as other core network nodes (including core network nodes in the UE 3's HPLMN when the UE 3 is roaming in). Such signaling may include, for example, appropriately formatted signaling messages (e.g., registration request messages and associated response messages) relating to access and mobility management procedures (for the UE 3).
[0221] The AMF 70 may support a Non-Public Network (NPN), which may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0222] <udm> 13 is a block diagram illustrating the major components of the UDM 75. As shown, the device includes a transceiver circuit 751 operable to transmit signals to and receive signals from other nodes (including the AMF 70) via a network interface 752. A controller 753 controls the operation of the UDM 75 in accordance with software stored in memory 754. For example, the software may be pre-installed in memory 754 and / or downloaded via a telecommunications network or from a removable data storage device (RMD). The software includes, among other things, an operating system 7541 and a communications control module 7542 having at least a transceiver control module 75421. The communication control module 7542, using (its transceiver control module) 75421, is responsible for handling (generating / sending / receiving) signaling between the UDM 75 and other nodes, such as the AMF 70 and other core network nodes (including core network nodes in the UE 3's VPLMN when the UE 3 is roaming out). Such signaling may include, for example, appropriately formatted signaling messages (e.g., HTTP RESTful methods based on service-based interfaces) related to mobility management procedures (for the UE 3).
[0223] The UDM 75 may support a Non-Public Network (NPN), which may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0224] <Modifications and Replacements> Detailed embodiments have been described above. Still, those skilled in the art will appreciate that numerous modifications and alternatives may be made to the above embodiments while having the benefit of the disclosure embodied herein. By way of example only, many such alternatives and modifications are now described.
[0225] In the above description, the UE 3 and network devices are described for ease of understanding as having a number of separate modules (such as a communications control module). These modules may be provided in this manner for particular applications, for example, where an existing system is modified to implement the present disclosure; in other applications, for example, in a system designed with inventive features in mind from the beginning; however, these modules may not be recognizable as separate entities because they may be built into an overall operating system or code. These modules may also be implemented in software, hardware, firmware, or a mixture of these.
[0226] Each controller may comprise any suitable form of processing circuitry, including, but not limited to, one or more hardware-implemented computer processors, microprocessors, central processing units (CPUs), arithmetic logic units (ALUs), input / output (IO) circuitry, internal memory / cache (program and / or data), processing registers, communication buses (e.g., control buses, data buses, and / or address buses), direct memory access (DMA) functions, hardware or software-implemented counters, pointers, and / or timers, and / or the like.
[0227] In the above embodiments, a number of software modules have been described. Those skilled in the art will understand that the software modules may be provided in compiled or uncompiled form, and may be provided to the UE 3 and network devices as signals over a computer network or on a recording medium. Furthermore, the functions performed by some or all of the software may be performed using one or more dedicated hardware circuits. However, the use of software modules is preferred for updating the functions of the UE 3 and network devices, as they facilitate updating the UE 3 and network devices.
[0228] In the above embodiment, 3GPP wireless communication (radio access) technology is used, but any other wireless communication technology (e.g., WLAN, Wi-Fi, WiMAX, Bluetooth, etc.) and other fixed line communication technology (e.g., BBF access, cable access, optical access, etc.) can also be used in accordance with the above embodiment.
[0229] Items of user equipment may include, for example, communication devices such as mobile phones, smartphones, user appliances, personal digital assistants, laptop / tablet computers, web browsers, e-book readers, and / or the like. Such mobile (and even generally fixed) devices are typically operated by a user, although so-called "Internet of Things" (IoT) devices and similar machine-type communication (MTC) devices may also be connected to the network. For simplicity, this application will refer to mobile devices (or UEs) in the description, but it will be understood that the described techniques may be implemented on any (mobile and / or generally fixed) communication device that can connect to a communication network to transmit / receive data, whether such communication device is controlled by human input or by software instructions stored in memory.
[0230] Various other modifications will be apparent to those skilled in the art and will not be described in further detail here.
[0231] All or part of the exemplary aspects of the above disclosure may be described as follows, but are not limited to the following.
[0232] <4.2.2.2.2 Registration Overview> Figure 4.2.2.2.2-1: Registration procedure (see Figure 14).
[0233] 1. From UE to (R)AN: AN message (AN parameters, Registration Request (Registration Type, SUCI or 5G-GUTI or PEI, [Last Visited TAI (if available)], Security Parameters, [Requested NSSAI], [Requested NSSAI Mapping], [Default Configuration NSSAI Indication], [UE Radio Capability Update], [UE MM Core Network Capabilities], [PDU Session State], [List of PDU Sessions to be Activated], [Subsequent Request], [MICO Mode Preference], [Requested Active Time], [Requested DRX Parameters for E-UTRA and NR], [Requested DRX Parameters for NB-IoT], [Extended Idle Mode DRX Parameters], [Requested LAD Information LAD DNN or Indicator], [NAS Message Container], [Support for Restricting the Use of Improved Coverage], [Preferred Network Behavior], [UE Paging Availability Information], [UE Policy Container (List of PSI, Indication of UE Support for ANDSP, and Operating System Identifier)], and [UE Radio Capability ID], [Release Request Indicator], [Paging Restriction Information], PEI, [NSSRG Handling Support Indicator], [PLMN with Disaster State]).
[0234] NOTE 1: The UE Policy Container and its usage are defined in TS 23.503
[20] .
[0235] In the case of NG-RAN, the AN parameters include, for example, 5G-S-TMSI or GUAMI, selected PLMN ID (or PLMN ID and NID see clause 5.30 of TS 23.501 [2]), and NSSAI information, and the AN parameters also include an establishment cause. The establishment cause provides the reason for requesting establishment of an RRC connection. Whether and how the UE includes the NSSAI information as part of the AN parameters depends on the value of the Access Stratum Connection Establishment NSSAI Inclusion Mode parameter as specified in clause 5.15.9 of TS 23.501 [2].
[0236] If the UE is an IAB node accessing 5GS, the AN parameter shall also include an IAB indication.
[0237] The registration type indicates whether the UE wants to perform an initial registration (i.e., the UE is in RM-DEREGISTERED state), a mobility registration update (i.e., the UE is in RM-registered state and initiates the registration procedure for mobility or because the UE needs to update its capabilities or protocol parameters or needs to request a change in the set of network slices that the UE is allowed to use), a periodic registration update (i.e., the UE is in RM-registered state and initiates the registration procedure due to expiration of the periodic registration update timer see section 4.2.2.2.1), an emergency registration (i.e., the UE is in limited service state), or a disaster roaming registration.
[0238] If the UE uses E-UTRA, the UE indicates in the RRC connection establishment signaling associated with the registration request that the UE supports CIoT 5GS optimization related to AMF selection.
[0239] If the UE is performing an initial registration or disaster roaming registration, the UE shall indicate its UE identity in the registration request message as follows, which, for registration with a PLMN, are listed in order of decreasing priority: i) If the UE has a valid EPS GUTI, the 5G-GUTI is mapped from the EPS GUTI. ii) If available, the native 5G-GUTI assigned by the PLMN to which the UE is attempting to register; iii) If available, the native 5G-GUTI assigned by the equivalent PLMN to the PLMN to which the UE is attempting to register; iv) Native 5G-GUTI allocated by any other PLMN, if available. Note 2: This can also be a 5G-GUTI allocated via another access type. v) In other cases, the UE shall include its SUCI in the registration request as specified in TS 33.501
[15] .
[0240] If the UE is registering with an SNPN, when the UE is performing initial registration, the UE shall indicate its UE identity in the registration request message as follows, listed in descending order of preference: i) If available, a native 5G-GUTI assigned by the same SNPN to which the UE is attempting to register; ii) If available, the native 5G-GUTI assigned by any other SNPN together with the NID of the SNPN that assigned the 5G-GUTI; iii) In other cases, the UE shall include its SUCI in the registration request as specified in TS 33.501
[15] .
[0241] If the UE performing initial registration has both a valid EPS GUTI and a native 5G-GUTI, the UE shall also indicate the native 5G-GUTI as an additional GUTI. If multiple native 5G-GUTIs are available, the UE shall select a 5G-GUTI from items (ii) to (iv) in the above list in descending order of priority.
[0242] If the UE is sending a Registration Request message as an initial NAS message, the UE has a valid 5G NAS security context, and the UE needs to send non-cleartext IEs, the NAS message container shall be included (see clause 4.4.6 in TS 24.501
[25] ). If the UE does not need to send non-cleartext IEs, the UE shall send the Registration Request message without including a NAS message container.
[0243] If the UE does not have a valid 5G NAS security context, the UE shall send the Registration Request message without including a NAS message container. The UE shall include the entire Registration Request message (i.e., including cleartext and non-cleartext IEs) in the NAS message container sent as part of the Security Mode Complete message in step 9b.
[0244] If the UE is initially registered with native 5G-GUTI (i.e., the UE is in RM-DEREGISTERED state), the UE shall indicate the relevant GUAMI information in the AN parameters. If the UE is initially registered with its SUCI, the UE shall not indicate any GUAMI information in the AN parameters.
[0245] If the UE is performing initial registration or mobility registration and CIoT 5GS optimization is supported, the UE shall indicate its preferred network behavior (see clause 5.31.2 of TS 23.501 [2]). If S1 mode is supported, the preferred network behavior of the UE's EPC shall be included in the S1 UE network capabilities in the registration request message (see clause 8.2.6.1 of TS 24.501
[25] ).
[0246] For emergency registration, if the UE does not have a valid 5G-GUTI available, the SUCI shall be included, and if the UE does not have a SUPI and a valid 5G-GUTI, the PEI shall be included. Otherwise, the 5G-GUTI shall be included, which indicates the latest serving AMF.
[0247] The UE may provide the UE usage settings based on the UE configuration as defined in clause 5.16.3.7 of TS23.501[2]. The UE provides the Request-NSSAI (as described in clause 5.15.5.2.1 of TS23.501[2]), and if the UE supports subscription-based restrictions on concurrent registration of network slices and also takes into account NSSRG information restrictions as described in clause 5.15.12 of TS23.501[2], in the case of initial registration or mobility registration update, the UE includes a mapping of the Request-NSSAI (if available) that is a mapping of each S-NSSAI of the Request-NSSAI to the HPLMN S-NSSAI, so that the network can reliably verify whether the S-NSSAI in the Request-NSSAI is allowed based on the subscribed S-NSSAI. In case of inter-PLMN mobility, if the Serving PLMN S-NSSAI corresponding to the Established PDU Session does not exist in the UE, the relevant HPLMN S-NSSAI associated with the Established PDU Session shall be provided to the Requested NSSAI mapping as described in clause 5.15.5.2.1 of TS 23.501 [2].
[0248] If the UE is using the default configuration NSSAI as defined in TS23.501 [2], the UE shall include the default configuration NSSAI indication.
[0249] If the UE supports allocation of WUS assistance information from the AMF, the UE may include UE paging availability information (see TS23.501[2]).
[0250] In the case of a mobility registration update, the UE shall include in the list of PDU sessions to be activated those PDU sessions for which there is pending uplink data. When the UE includes the list of PDU sessions to be activated, it shall indicate only the PDU sessions associated with the access for which the registration request is made. As specified in TS 24.501
[25] , the UE shall include in the list of PDU sessions to be activated those PDU sessions that are always on and accepted by the network, even if there is no pending uplink data for that PDU session.
[0251] NOTE 3: If the UE is outside the coverage area of the LADN, the PDU session corresponding to the LADN is not included in the list of PDU sessions to be activated.
[0252] As defined in clause 5.4.4a of TS 23.501 [2], the UE MM Core Network Function is provided by the UE and processed by the AMF. As defined in clause 5.17.2.3.1 of TS 23.501 [2], the UE includes in the UE MM Core Network Function an indication of whether the UE supports the request type flag "Handover" for PDN connectivity requests during the attach procedure. If the UE supports "Strict Periodic Registration Timer Indication", the UE indicates the UE capability of "Strict Periodic Registration Timer Indication" in the UE MM Core Network Function. If the UE supports CAG, the UE indicates the UE capability of "CAG Supported" in the UE MM Core Network Function. If a UE operating with two or more USIMs supports one or more multi-USIM features and intends to use one or more multi-USIM features, the UE indicates one or more multi-USIM specific features described in clause 5.38 of TS 23.501 [2] in the UE MM Core Network Function.
[0253] As described in clause 5.6.5 of TS23.501[2], the UE may provide either the LADN DNN or an indication of the requested LADN information.
[0254] If available, the last visited TAI shall be included to help the AMF generate a registration area for the UE.
[0255] The security parameters are used for authentication and integrity protection (see TS 33.501
[15] ). The requested NSSAI indicates network slice selection assistance information (as defined in clause 5.15 of TS 23.501 [2]). The PDU session status indicates a previously established PDU session in the UE. If the UE is connected to two AMFs belonging to different PLMNs via 3GPP access and non-3GPP access, the PDU session status indicates the established PDU session of the current PLMN in the UE.
[0256] A subsequent request is included if the UE has pending uplink signaling, the UE does not include a list of activated PDU sessions, or the registration type indicates that the UE wants to perform an emergency registration. In the initial registration and mobility registration update, the UE provides the UE request DRX parameters as specified in clause 5.4.5 of TS 23.501 [2]. To request extended idle mode DRX, the UE may provide the extended idle mode DRX parameters as specified in clause 5.31.7.2 of TS 23.501 [2].
[0257] As described in TS23.501 [2], the UE provides a UE radio capability update indication.
[0258] The UE includes a preference for MICO mode and, optionally, a requested active time value if the UE wants to use MICO mode during active time.
[0259] The UE may indicate its service gap control capabilities in the UE MM core network function (see clause 5.31.16 of TS 23.501 [2]).
[0260] For UEs with a running service gap timer in the UE, the UE shall not set the subsequent request indicator or uplink data state in the registration request message, except for network access for restricted priority services such as emergency services or exception reporting (see clause 5.31.16 of TS 23.501 [2]).
[0261] If the UE supports RACS and has assigned a UE Radio Capability ID, the UE shall indicate the UE Radio Capability ID as defined in clause 5.4.4.1a of TS 23.501 [2] as a non-cleartext IE.
[0262] The PEI may be obtained from the UE at initial registration, as described in section 4.2.2.2.1.
[0263] If the UE supports subscription-based restriction on concurrent registrations of the network slicing feature, the UE includes an NSSRG handling support indication according to clause 5.15.12 of TS 23.501 [2]. The AMF stores in the UE context whether the UE supports this feature.
[0264] If a UE in MUSIM mode wants to enter CM-IDLE state immediately after, for example, performing mobility registration or periodic registration, the UE includes a release request indication and optionally provides paging restriction information.
[0265] When the UE is performing disaster roaming registration, if the UE does not have a valid 5G-GUTI indicating the PLMN with disaster status, and the PLMN with disaster status is not the UE's HPLMN, or the PLMN with disaster status is the UE's HPLMN but the UE does not provide its SUCI, the UE may indicate the PLMN with disaster status.
[0266] 2. If the 5G-S-TMSI or GUAMI is not included or does not indicate a valid AMF, the (R)AN selects an AMF based on the (R)AT and the requested NSSAI, if available.
[0267] The (R)AN selects the AMF as described in clause 6.3.5 of TS23.501 [2]. If the UE is in a CM-CONNECTED state, the (R)AN may forward the registration request message to the AMF based on the UE's N2 connection.
[0268] If the (R)AN cannot select an appropriate AMF, the (R)AN forwards the registration request to an AMF configured in the (R)AN to perform AMF selection.
[0269] 3. (R)AN to new AMF: N2 message (N2 parameters), registration request (as described in step 1) and [LTE-M indication].
[0270] If NG-RAN is used, the N2 parameters include the selected PLMN ID (or PLMN ID and NID see clause 5.30 of TS 23.501 [2]), location information and cell identity information for the cell in which the UE is camped, and a UE context request indicating that a UE context including security information needs to be set up in the NG-RAN.
[0271] If NG-RAN is used, the N2 parameter shall also contain the establishment cause and shall contain the IAB indication if an indication is received in the AN parameter in step 1.
[0272] Mapping of the request NSSAI is provided only if available.
[0273] If the registration type indicated by the UE is periodic registration update, steps 4 to 19 may be omitted.
[0274] If the establishment cause is associated with a priority service (e.g., MPS, MCS), the AMF includes a Message Priority header to indicate the priority information. As specified in TS 29.500
[17] , other NFs relay the priority information by including the Message Priority header in their service-based interfaces.
[0275] The RAT type used by the UE is determined (see clause 4.2.2.2.1) and based on that the AMF determines whether the UE is performing inter-RAT mobility to or from NB-IoT. If the AMF receives an LTE-M indication, the AMF considers that the RAT type is LTE-M and stores the LTE-M indication in the UE context.
[0276] If the UE includes a preferred network behavior, this defines the network behavior that the UE wants to support and be available in the network, as defined in clause 5.31.2 of TS 23.501 [2].
[0277] If the UE includes a preferred network behavior and the preferred network behavior that the UE indicates it supports is incompatible with network support, the AMF shall reject the registration request with an appropriate cause value (e.g., one that avoids retries in this PLMN).
[0278] If there is a service gap timer running in the UE context in the AMF for the UE and the subsequent request indication or uplink data status is not included in the registration request message, the AMF shall ignore the subsequent request indication and uplink data status and shall not take any action regarding the status.
[0279] If the UE included the UE radio capability ID in step 1 and the AMF supports RACS, the AMF stores the radio capability ID in the UE context.
[0280] For NR satellite access, if the AMF can determine, based on the selected PLMN ID and ULI (including cell ID) received from the gNB, that the UE is attempting to register with a PLMN that is not authorized to operate at the current UE location, the AMF should reject the registration request with a suitable cause value and, if known to the AMF, the country of the UE location. In other cases, for example, if the AMF does not know the UE location with sufficient accuracy to make a final decision, the AMF may proceed with the registration procedure and initiate a UE location procedure as specified in clause 6.10.1 of TS 23.273
[51] to prepare to deregister the UE if the information received from the LMF indicates that the UE is registered with a PLMN that is not authorized to operate at the UE location.
[0281] NOTE 4: Location information may not be guaranteed to be accurate enough for the AMF to determine the country in which the UE is located in all cases.
[0282] Note 5: Some countries use multiple MCCs, and some MCCs, such as 901, may be allowed in multiple countries, so the UE may register with a different MCC in the PLMN than the one returned to the UE.
[0283] Upon receiving a registration rejection for the country in which the UE is located, the UE shall attempt to register with a PLMN that is permitted to operate at the UE location as specified in TS 23.122
[22] .
[0284] For disaster roaming registration, the AMF determines whether disaster roaming service can be provided based on the ULI (including the cell ID) received from the NG-RAN, the PLMN with a disaster state derived from the UE's 5G-GUTI, derived from the UE's SUCI, or indicated by the UE, and the local configuration. If the current location does not receive disaster roaming service or disaster roaming service is not provided for the PLMN with a disaster state derived from the UE's 5G-GUTI, derived from the UE's SUCI, or indicated by the UE, the AMF should reject the registration request with a suitable cause value.
[0285] 4. [Conditional] From new AMF to old AMF: Namf_Communication_UEContextTransfer (full registration request) or from new AMF to UDSF: Nudsf_UnstructuredDataManagement_Query().
[0286] The new AMF determines the old AMF using the UE's 5G-GUTI. If the new AMF receives the NID in the registration request, the new AMF determines that the 5G-GUTI is assigned by the SNPN and uses the SNPN's 5G-GUTI and NID to determine the old AMF.
[0287] (With UDSF Deployment): If the UE's 5G-GUTI is included in the registration request and the serving AMF has changed since the last registration procedure, the new AMF and old AMF are in the same AMF set and UDSF is deployed, or the new AMF obtains the stored UE's SUPI and UE context directly from the UDSF using the Nudsf_UnstructuredDataManagement_Query service operation, or if UDSF is not deployed, the new AMF and old AMF may share the stored UE context via implementation-specific means. This also includes event subscription information by each NF consumer for a given UE. In this case, the new AMF uses the integrity protection full registration request NAS message to perform and verify integrity protection.
[0288] (Without UDSF Deployment): If the UE's 5G-GUTI is included in the registration request and the serving AMF has changed since the last registration procedure, the new AMF may invoke the Namf_Communication_UEContextTransfer service operation in the old AMF, including the integrity-protected full registration request NAS message and the access type, to request the UE's SUPI and UE context. For details of this service operation, see section 5.2.2.2.2. In this case, to verify integrity protection when the context transfer service operation execution corresponds to the requested UE, the old AMF uses either the 5G-GUTI and the integrity-protected full registration request NAS message, or the SUPI and an indication from the new AMF that the UE has been verified. The old AMF uses the 5G NAS security context for the access type to verify the integrity of the received full registration request message. In this case, the UE uses the common 5G NAS security context, the UL NAS COUNT, which is set to zero if the UL NAS COUNT corresponding to the access type is not stored, and the stored UL NAS COUNT and the NAS connection identifier corresponding to the access type. The old AMF also forwards the event subscription information by each NF consumer for the UE to the new AMF. If the old AMF has not yet reported a non-zero MO exception data counter to the (H-)SMF, the context response also includes the MO exception data counter.
[0289] If the old AMF has a PDU session for another access type (different from the access type indicated in this step) and if the old AMF determines that there is no possibility to relocate the N2 interface to the new AMF, the old AMF returns the UE's SUPI and indicates that the registration request has been verified for integrity protection, but does not include the remaining UE context.
[0290] For inter-PLMN movement, the UE context information includes the HPLMN S-NSSAI corresponding to the authorized NSSAI for each access type without the authorized NSSAI of the old PLMN.
[0291] NOTE 6: If the new AMF successfully authenticates the UE after a previous integrity check failure in the old AMF, the new AMF sets an indication that the UE is verified according to step 9a.
[0292] NOTE 7: The NF consumer does not need to resubscribe to events for the new AMF after the UE has successfully registered with the new AMF.
[0293] If the new AMF has already received the UE context from the old AMF during the handover procedure, steps 4, 5 and 10 shall be skipped.
[0294] For emergency registration, if the UE identifies itself with a 5G-GUTI that is not known to the AMF, steps 4 and 5 are skipped and the AMF immediately requests a SUPI from the UE. If the UE identifies itself with a PEI, the SUPI request shall be skipped. The permission of emergency registration without user identity depends on local regulations.
[0295] 5. [Conditional] From old AMF to new AMF: Response to Namf_Communication_UEContextTransfer (SUPI, UE context in AMF (according to Table 5.2.2.2.2-1)) or from UDSF to new AMF: Nudsf_UnstructuredDataManagement_Query(). The old AMF may start an implementation-specific (guard) timer for the UE context.
[0296] If the UDSF is queried in step 4, it responds to the new AMF with a Nudsf_UnstructuredDataManagement_Query execution for the relevant context including the established PDU session, and the old AMF includes the SMF information DNN, S-NSSAI and PDU session ID, active NGAP UE-TNLA binding in N3IWF / TNGF / W-AGF, and the old AMF includes information about the NGAP UE-TNLA binding. If the old AMF is queried in step 4, it responds to the new AMF with a Namf_Communication_UEContextTransfer execution by including the UE's SUPI and UE context.
[0297] If the old AMF holds information about the established PDU session and it is not an initial registration, the old AMF includes SMF information, DNN, S-NSSAI, and PDU session ID.
[0298] If the old AMF holds the UE context established via the N3IWF, W-AGF, or TNGF, the old AMF includes the CM state via the N3IWF, W-AGF, or TNGF. If the UE is in CM-CONNECTED state via the N3IWF, W-AGF, or TNGF, the old AMF includes information about the NGAP UE-TNLA binding.
[0299] If the old AMF fails to verify the integrity of the registration request NAS message, the old AMF shall indicate an integrity verification failure. If the new AMF is configured to allow emergency services for unauthenticated UEs, the new AMF shall operate as follows:
[0300] If the UE has only an emergency PDU session, the AMF skips the authentication and security procedures or acknowledges that authentication may fail and continues the mobility registration update procedure, or
[0301] If the UE has both emergency and non-emergency PDU sessions and authentication fails, the AMF continues the mobility registration update procedure and deactivates all non-emergency PDU sessions as specified in section 4.3.4.2.
[0302] Note 8: The new AMF may determine whether a PDU session is used for emergency services by checking whether the DNN matches the emergency DNN.
[0303] If the old AMF holds information about AM policy association and information about UE policy association (i.e., policy control request trigger to update UE policy as defined in TS 23.503
[20] ), the old AMF includes information about AM policy association, UE policy association, and PCF ID. In case of roaming, V-PCF ID and H-PCF ID are included.
[0304] If the old AMF was a consumer of the UE-related NWDAF service, the old AMF includes information about the active analysis subscription, i.e., subscription correlation ID, NWDAF identifier (i.e., instance ID or set ID), analysis ID, and associated analysis-specific data, in the Namf_Communication_UEContextTransfer response. The use of analysis information by the new AMF is specified in TS 23.288
[50] .
[0305] The handling of the UE radio capability ID in the new AMF during inter-PLMN movement is specified in TS 23.501 [2].
[0306] Note 9: If the new AMF uses UDSF for context retrieval, the interaction between the old AMF, new AMF, and UDSF due to simultaneous UE signaling in the old AMF is an implementation issue.
[0307] 6. [Conditional] New AMF to UE: Identity Request().
[0308] If the SUCI is not provided by the UE and is not obtained from the old AMF, the identity request procedure is initiated by the AMF sending an identity request message to the UE requesting the SUCI.
[0309] 7. [Conditional] UE to new AMF: Identity response().
[0310] The UE responds with an Identity Response message containing the SUCI, which the UE derives by using the public key of the provisioned HPLMN as specified in TS33.501
[15] .
[0311] 8. The AMF may decide to initiate UE authentication by invoking the AUSF. In that case, the AMF selects the AUSF based on the SUPI or SUCI as described in clause 6.3.4 of TS 23.501 [2].
[0312] If the AMF is configured to support emergency registration for unauthenticated SUPI and the UE indicates emergency registration as a registration type, the AMF skips authentication or the AMF acknowledges that authentication may fail and continues the registration procedure.
[0313] 9a. If authentication is required, the AMF requests it from the AUSF, and if the trace requirements for the UE are available in the AMF, the AMF provides the trace requirements to the AUSF in the request. When requested by the AMF, the AUSF shall perform authentication of the UE. Authentication is performed as described in TS 33.501
[15] . The AUSF selects a UDM as described in clause 6.3.8 of TS 23.501 [2] and obtains authentication data from the UDM.
[0314] Editor's note: In the case of disaster roaming registration, how the AUSF performs authentication of the UE is FFS (to be further considered).
[0315] Once the UE is authenticated, the AUSF provides the AMF with relevant security-related information. If the AMF provides the SUCI to the AUSF, the AUSF shall return the SUPI to the AMF only after successful authentication.
[0316] After successful authentication in the new AMF, triggered by an integrity check failure in the old AMF in step 5, the new AMF invokes step 4 above again and indicates that the UE is verified (i.e., via the reason parameter as specified in clause 5.2.2.2.2).
[0317] 9b If no NAS security context exists, NAS security initiation occurs as described in TS 33.501
[15] . If the UE did not have a NAS security context in step 1, the UE includes a Full Registration Request message as defined in TS 24.501
[25] .
[0318] As described in section 4.2.2.2.3, the AMF determines whether the registration request needs to be rerouted, where the initial AMF refers to the AMF.
[0319] 9c. If the 5G-AN requests a UE context, the AMF initiates an NGAP procedure to provide the 5G-AN with a security context as specified in TS38.413
[10] . If the AMF determines that EPS fallback is supported (e.g., based on the UE capabilities, subscription data, and local policies to support the request type flag "handover" for the PDN connectivity request during the attach procedure as defined in clause 5.17.2.3.1 of TS23.501 [2]), the AMF shall send an indication that "redirection for EPS fallback of voice is possible" to the 5G-AN as specified in TS38.413
[10] . Otherwise, the AMF shall indicate that "redirection for EPS fallback of voice is not possible." Additionally, if trace requirements for the UE are available in the AMF, the AMF provides the trace requirements to the 5G-AN in the NGAP procedure.
[0320] 9d. The 5G-AN stores the security context and informs the AMF. The 5G-AN uses the security context to protect messages exchanged with the UE as described in TS33.501
[15] .
[0321] 10. [Conditional] From new AMF to old AMF: Namf_Communication_RegistrationStatusUpdate (e.g., PDU session ID released due to unsupported slicing).
[0322] When the AMF is changed, the new AMF informs the old AMF that the UE's registration in the new AMF is complete by calling the Namf_Communication_RegistrationStatusUpdate service operation.
[0323] If the authentication / security procedures fail, the registration shall be rejected and the new AMF shall call the Namf_Communication_RegistrationStatusUpdate service operation with a rejection indication to the old AMF. The old AMF shall continue as if the UE context transfer service operation had never been received.
[0324] If one or more of the S-NSSAIs used in the old registration area cannot be served in the target registration area, the new AMF determines which PDU sessions cannot be supported in the new registration area. The new AMF invokes the Namf_Communication_RegistrationStatusUpdate service operation with the rejected PDU session ID to the old AMF. The new AMF then modifies the PDU session status accordingly. The old AMF informs the corresponding SMF to locally release the UE's SM context by invoking the Nsmf_PDUSession_ReleaseSMContext service operation.
[0325] If the new AMF has received information about the AM policy association and UE policy association in the UE context transfer in step 5 based on the local policy and decides not to use the PCF identified by the PCF ID for the AM policy association and UE policy association, the new AMF informs the old AMF that the AM policy association and UE policy association in the UE context will no longer be used, and PCF selection is performed in step 15.
[0326] If the new AMF receives information about the UE-related analysis subscription in the UE context transfer in step 5, the new AMF may take over the analysis subscription from the old AMF. Otherwise, if the new AMF decides to create a new analysis subscription instead, the new AMF may inform the old AMF that the analysis subscription (identified by the subscription correlation ID) is no longer needed, and the old AMF may then unsubscribe from the NWDAF analysis subscription for the UE according to TS 23.288
[50] .
[0327] 11. [CONDITIONAL] New AMF to UE: Identity Request / Response (PEI).
[0328] If the PEI is not provided by the UE and has not been obtained from the old AMF, the identity request procedure is initiated by the AMF sending an identity request message to the UE to obtain the PEI. The PEI shall be transmitted encrypted unless the UE has performed an emergency registration and is not authenticated.
[0329] For emergency registration, the UE may include the PEI in the registration request, in which case the PEI lookup is skipped.
[0330] If the UE supports RACS as indicated in the UE MM core network capabilities, the AMF shall use the UE's PEI to obtain the IMEI / TAC for the purpose of RACS operation.
[0331] 12. Optionally, the new AMF initiates the ME identity check by invoking the N5g-eir_EquipmentIdentityCheck_Get service operation (see clause 5.2.4.2.2).
[0332] PEI verification will be performed as described in Section 4.7.
[0333] For emergency registration, if the PEI is blocked, operator policy determines whether to continue or stop the emergency registration procedure.
[0334] 13. If step 14 is performed, the new AMF selects a UDM based on the SUPI, and the UDM can then select a UDR instance. See section 6.3.9 of TS23.501 [2].
[0335] The AMF selects the UDM as described in clause 6.3.8 of TS 23.501 [2].
[0336] 14a-c. If the AMF has changed since the last registration procedure, or if the UE provides a SUPI in the AMF that does not reference a valid context, or if the UE registers to the same AMF to which it has already registered for non-3GPP access (i.e., the UE is registered through non-3GPP access and initiates this registration procedure to add 3GPP access), the new AMF registers with the UDM using Nudm_UECM_Registration for the access to which it is registered (and subscribes to be notified when the UDM deregisters this AMF). In this case, if the AMF does not have event exposure subscription information for this UE, the AMF indicates it to the UDM. Then, if the UDM has existing applicable event exposure subscriptions for events discovered in the AMF (possibly obtained from the UDR) for either this UE or a group to which this UE belongs, the UDM calls the Namf_EventExposure_Subscribe service to recreate the event exposure subscription.
[0337] The AMF shall provide the "Homogeneous support of IMS voice over PS sessions" indication (see clause 5.16.3.3 of TS 23.501 [2]) to the UDM. The "Homogeneous support of IMS voice over PS sessions" indication shall not be included unless the AMF has completed its evaluation of the AMF on its support of "IMS voice over PS sessions" as specified in clause 5.16.3.2 of TS 23.501 [2].
[0338] During initial registration, if the AMF and UE support SRVCC from NG-RAN to UTRAN, the AMF provides the UE SRVCC functionality to the UDM.
[0339] If the AMF determines that only the UE SRVCC capabilities have changed, the AMF sends the UE SRVCC capabilities to the UDM.
[0340] NOTE 10: At this step, the AMF may not have all the information necessary to determine the setting of the IMS voice over PS session support indication (see clause 5.16.3.2 of TS 23.501 [2]) for this UE. Therefore, the AMF may send "Homogeneous support of IMS voice over PS session" later in this procedure.
[0341] If the AMF does not have subscription data for the UE, it uses Nudm_SDM_Get to obtain access and mobility subscription data, SMF selection subscription data, the UE context in the SMF data, and LCS mobile origination. If the AMF already has subscription data for the UE but the SoR update indicator in the UE context requests the AMF to obtain SoR information according to the NAS registration type ('initial registration' or 'emergency registration') (see Appendix C of TS23.122
[22] ), the AMF uses Nudm_SDM_Get to obtain steering of roaming information. This requires that the UDM can obtain this information from the UDR by Nudr_DM_Query. After a response is successfully received, the AMF subscribes to be notified using Nudm_SDM_Subscribe when the required data is modified, and the UDM can subscribe to the UDR by Nudr_DM_Subscribe. If GPSI is available in the UE subscription data, the GPSI is provided to the AMF in the access and mobility subscription data from the UDM. The UDM may provide an indication that subscription data for network slicing is updated for the UE. If the UE subscribes to MPS in the serving PLMN, the "MPS priority" is included in the access and mobility subscription data provided to the AMF. If the UE subscribes to MCX in the serving PLMN, the "MCX priority" is included in the access and mobility subscription data provided to the AMF. The UDM also provides an IAB operation authorization indication to the AMF as part of the access and mobility subscription data. The AMF shall trigger the setup of the UE context in the NG-RAN, or, if the initial setup is in step 9c, a modification of the UE context in the NG-RAN, including an indication that the IAB node is authorized.
[0342] Editor's note: In the case of disaster roaming registration, how the UDM provides the AMF with applicable subscription data for disaster roaming services is FFS (to be further considered).
[0343] The new AMF provides the UDM with the access type that the new AMF will provide service to the UE, and the access type is set to "3GPP access". The UDM stores the associated access type together with the serving AMF and does not remove AMF identification information associated with other access types, if any. The UDM may store it in the UDR information provided in the AMF registration by Nudr_DM_Update.
[0344] If the UE is registered to the old AMF for access and the old AMF and new AMF are in the same PLMN, the new AMF will send another / independent Nudm_UECM_Registration to update the UDM with the access type set to the access used in the old AMF after the old AMF relocation is successfully completed.
[0345] The new AMF creates a UE context for the UE after obtaining the access and mobility subscription data from the UDM. The access and mobility subscription data includes whether the UE is allowed to include the NSSAI in the 3GPP access RRC connection establishment in clear text. The access and mobility subscription data may include enhanced coverage restriction information. If received from the UDM and the UE included support for restricting the use of enhanced coverage in step 1, the AMF determines whether enhanced coverage is restricted for the UE as specified in clause 5.31.12 of TS 23.501 [2] and stores the updated enhanced coverage restriction information in the UE context.
[0346] The access and mobility subscription data may include NB-IoT UE priority.
[0347] The subscription data may include a service gap time parameter. If received from the UDM, the AMF stores this service gap time in the UE context in the AMF for the UE.
[0348] For emergency registrations where the UE is not successfully authenticated, the AMF shall not register with the UDM.
[0349] The AMF shall enforce mobility restrictions as specified in clause 5.3.4.1.1 of TS 23.501 [2]. For emergency registration, the AMF shall not check for mobility restrictions, access restrictions, regional restrictions, or subscription restrictions. For emergency registration, the AMF shall ignore any unsuccessful registration response from the UDM and continue the registration procedure.
[0350] Note 11: Instead of the Nudm_SDM_Get service operation, the AMF may use the Nudm_SDM_Subscribe service operation with an immediate report indication to trigger the UDM to return the subscribed data immediately if the corresponding functionality is supported by both the AMF and the UDM.
[0351] 14d. If the UDM stores the associated access type (e.g., 3GPP) with the serving AMF as indicated in step 14a, the UDM will thereby initiate a Nudm_UECM_DeregistrationNotification (see clause 5.2.3.2.2) to the old AMF corresponding to the same (e.g., 3GPP) access, if any. If the timer started in step 5 is not running, the old AMF may remove the UE context for the same access type. Otherwise, the AMF may remove the UE context for the same access type upon timer expiration. If the serving NF removal reason indicated by the UDM is initial registration, as described in clause 4.2.2.3.2, the old AMF will invoke the Nsmf_PDUSession_ReleaseSMContext(SM context ID) service operation to all associated SMFs of the UE to notify them that the UE is deregistered from the old AMF for the same access type. The SMF shall release the PDU session upon obtaining this notification.
[0352] If the old AMF established an AM policy association and a UE policy association with the PCF and the old AMF did not transfer the PCF ID to the new AMF (e.g., the new AMF is in a different PLMN), the old AMF performs the AMF-initiated policy association termination procedure as specified in clause 4.16.3.2 and the AMF-initiated UE policy association termination procedure as specified in clause 4.16.13.1. In addition, if the old AMF transferred the PCF ID in the UE context but the new AMF indicated in step 10 that the AM policy association information and the UE policy association information in the UE context will not be used, the old AMF performs the AMF-initiated policy association termination procedure as specified in clause 4.16.3.2 and the AMF-initiated UE policy association termination procedure as specified in clause 4.16.13.1.
[0353] If the old AMF has an N2 connection for the UE (e.g. because the UE was in RRC inactive but is now moving to E-UTRAN or to an area not served by the old AMF), the old AMF shall perform an AN release (see section 4.2.6) with a cause value indicating that the UE has already locally released the RRC connection in the NG-RAN.
[0354] If the UE context in the old AMF includes an authorized NSSAI that includes one or more S-NSSAIs that comply with NSAC, when the old AMF receives Nudm_UECM_DeregistrationNotification from the UDM, it sends an update request message for each S-NSSAI that complies with NSAC to the corresponding NSACF, with the update flag parameter (see section 4.2.11.2) set to decrease.
[0355] Once the registration procedure is complete, if the AMF does not indicate in step 14a that the event exposure subscription is unavailable, the AMF starts synchronizing the event exposure subscription with the UDM.
[0356] Note 12: The AMF may at any given time, based on local policy, initiate synchronization with the UDM even if an event is available in the UE context (e.g., as received from the old AMF). This may be done during subscription change related events.
[0357] 14e. [Conditional] If the old AMF does not have a UE context for another access type (i.e., non-3GPP access), the old AMF unsubscribes the UDM for subscription data using Nudm_SDM_unsubscribe.
[0358] 15. When the AMF decides to initiate PCU communication, the AMF functions as follows:
[0359] If the new AMF decides to use the (V-)PCF identified by the (V-)PCF ID included in the UE context from the old AMF in step 5, the AMF contacts the (V-)PCF identified by the (V-)PCF ID to obtain the policy. If the AMF decides to perform PCF discovery and selection, the AMF selects a (V-)PCF and may select an H-PCF (for roaming scenarios) as described in clause 6.3.7.1 of TS 23.501 [2] according to the V-NRF to H-NRF interaction described in clause 4.3.2.2.3.3.
[0360] 16. [Optional] The new AMF establishes / modifies the AM policy association. For emergency registration, this step is skipped.
[0361] If the new AMF selects a new (V-)PCF in step 15, the new AMF establishes an AM policy association with the selected (V-)PCF as defined in section 4.16.1.2.
[0362] If the (V-)PCF identified by the (V-)PCF ID included in the UE context from the old AMF is used, the new AMF performs AM policy association modification with the (V-)PCF as defined in clause 4.16.2.1.2.
[0363] When the AMF notifies the PCF of mobility restrictions (e.g., UE location) for adjustment, or when the PCF updates the mobility restrictions itself according to some conditions (e.g., application in use, date and time), the PCF shall provide the updated mobility restrictions to the AMF. If the subscription information includes trace requirements, the AMF shall provide the trace requirements to the PCF.
[0364] If the AMF supports DNN substitution, the AMF provides the PCF with the authorized NSSAI and, if available, a mapping of the authorized NSSAI.
[0365] If the PCF supports DNN replacement, the PCF provides a trigger for DNN replacement to the AMF.
[0366] 17. [Conditional] From AMF to SMF: Nsmf_PDUSession_UpdateSMContext ().
[0367] For an emergency registered UE (see TS23.501[2]), this step applies if the registration type is a mobility registration update.
[0368] AMF calls Nsmf_PDUSession_UpdateSMContext (see section 5.2.8.2.6) in the following scenarios:
[0369] If the list of PDU sessions to be activated is included in the registration request in step 1, the AMF sends an Nsmf_PDUSession_UpdateSMContext request to the SMF associated with the PDU session to activate the user plane connection for that PDU session. Steps 5 onwards described in clause 4.2.3.2 are performed to complete the user plane connection activation without sending RRC inactive support information and without sending an MM NAS service accept from the AMF to the (R)AN described in step 12 of clause 4.2.3.2. Once the user plane connection for the PDU session is activated, the AS layer in the UE indicates it to the NAS layer.
[0370] If the AMF determines in step 3 that the UE is performing inter-RAT mobility to or from NB-IoT, the AMF sends an Nsmf_PDUSession_UpdateSMContext request to the SMF associated with the UE PDU session so that the SMF can update the UE PDU session according to the "PDU session continuity on inter-RAT mobility" subscription data. Steps from step 5 onwards described in clause 4.2.3.2 are performed without sending an MM NAS service acceptance from the AMF to the (R)AN described in step 12 of clause 4.2.3.2.
[0371] When the serving AMF changes, the new serving AMF notifies the SMF for each PDU session that the new AMF has taken over responsibility for the signaling path to the UE, and the new serving AMF invokes the Nsmf_PDUSession_UpdateSMContext service operation using the SMF information received from the old AMF in step 5. It also indicates whether the PDU session is to be reactivated.
[0372] NOTE 13: When a UE moves into a different PLMN, the AMF in the serving PLMN may insert or change the V-SMF in the serving PLMN for the home routed PDU session. In this case, the same procedures as described in clause 4.23.3 apply for V-SMF change as for I-SMF change (i.e., by replacing I-SMF with V-SMF). If the same SMF is used during inter-PLMN change, session continuity may be supported depending on operator policy.
[0373] The steps from step 5 onwards described in section 4.2.3.2 are performed. If the insertion, removal or modification of an intermediate UPF is performed for a PDU session that is not included in the "reactivated PDU session", the procedure is performed without N11 and N2 interaction to update the N3 user plane between the (R)AN and the 5GC.
[0374] AMF invokes the Nsmf_PDUSession_ReleaseSMContext service operation to SMF in the following scenarios:
[0375] -If any PDU session state indicates to be released in the UE, the AMF invokes the Nsmf_PDUSession_ReleaseSMContext service operation to the SMF to release any network resources related to the PDU session.
[0376] If the serving AMF is changed, the new AMF shall wait until step 18 is completed for all SMFs associated with the UE. Otherwise, steps 19 to 22 may continue in parallel with this step.
[0377] 18. [Conditional] If the new AMF and old AMF are in the same PLMN, the new AMF sends a UE context modification request to the N3IWF / TNGF / W-AGF as specified in TS 29.413
[64] .
[0378] When the AMF is changed and the old AMF indicates that the UE is in CM-CONNECTED state via the N3IWF, W-AGF, or TNGF, and the new AMF and the old AMF are in the same PLMN, the new AMF creates an NGAP UE association for the N3IWF / TNGF / W-AGF to which the UE is connected, which automatically releases the existing NGAP UE association between the old AMF and the N3IWF / TNGF / W-AGF.
[0379] 19. The N3IWF / TNGF / W-AGF sends a UE context modification response to the new AMF.
[0380] 19a. [Conditional] After the new AMF receives a response message from the N3IWF, W-AGF, or TNGF in step 19, the new AMF registers with the UDM using Nudm_UECM_Registration as in step 14a, but with the access type set to "non-3GPP access". The UDM stores the associated access type with the serving AMF and does not remove AMF identities associated with other access types, if any. The UDM may store in the UDR information provided in the AMF registration by Nudr_DM_Update.
[0381] 19b. [Conditional] If the UDM stores the associated access type (i.e., non-3GPP) with the serving AMF as indicated in step 19a, it will cause the UDM to initiate a Nudm_UECM_DeregistrationNotification (see clause 5.2.3.2.2) to the old AMF corresponding to the same (i.e., non-3GPP) access. The old AMF will remove the UE context for the non-3GPP access.
[0382] 19c. Old AMF unsubscribes UDM from subscription data using Nudm_SDM_unsubscribe.
[0383] 20a.Empty.
[0384] 21. New AMF to UE: Registration Authorization (5G-GUTI, Registration Area, Mobility Restrictions, PDU Session State, Allowed NSSAI, Allowed NSSAI Mapping, Configured NSSAI for Serving PLMN, Configured NSSAI Mapping, NSSRG Information, Rejected S-NSSAI, Reserved NSSAI, Reserved NSSAI Mapping, Periodic Registration Update Timer, Active Time, Strict Periodic Registration Timer Indicator, LADN Information, Authorized MICO Mode, Indication of Support for IMS Voice in PS Sessions, Emergency Services Support Indicator, Authorized DRX Parameters for E-UTRA and NR, Authorized DRX Parameters for NB-IoT, Extended Admission Idle Mode DRX Parameters], [Paging Time Window], [Network Support for Interworking without N26], [Access Stratum Connection Establishment NSSAI Inclusive Mode], [Network Slicing Subscription Change Indication], [Operator-Defined Access Category Definition], [List of Equivalent PLMNs], [Improved Coverage Restriction Information], [Supported Network Behavior], [Service Gap Time], [UE Radio Capability ID for PLMN Allocation], [UE Radio Capability ID for PLMN Allocation Removal], [WUS Assistance Information], [Simplified 5G-S-TMSI Configuration], [Connection Release Support], [Paging Cause Indication Support for Voice Services], [Paging Restriction Support], [Reject Paging Request Support]).
[0385] If the Requested NSSAI does not contain an S-NSSAI that maps to an S-NSSAI of the HHPLMN that is subject to network slice-specific authentication and authorization, and the AMF determines that it cannot provide an S-NSSAI in the Authorized NSSAI for the UE within the current UE tracking area, and if it cannot further consider a default S-NSSAI that has not yet been involved in the current UE registration procedure, the AMF shall reject the UE registration and shall include a list of rejected S-NSSAIs in the rejection message, each with an appropriate rejection cause value.
[0386] The authorized NSSAI for the access type for the UE is included in the N2 message carrying the registration accept message. The authorized NSSAI includes only S-NSSAIs that do not require network slice-specific authentication and authorization based on subscription information, and S-NSSAIs for which network slice-specific authentication and authorization have previously been successful regardless of the access type based on the UE context in the AMF. The mapping of reserved NSSAIs is to map each S-NSSAI of the reserved NSSAI for the serving PLMN to the HPLMN S-NSSAI.
[0387] If the UE indicates that it supports network slice-specific authentication and authorization procedures in the UE MM core network function in the registration request, the AMF shall include in the pending NSSAI the S-NSSAI that is mapped to the S-NSSAI of the HPLMN whose subscription information indicates that it is subject to network slice-specific authentication and authorization, as described in clause 4.6.2.4 of TS 24.501
[25] . In such a case, the AMF shall then trigger the network slice-specific authentication and authorization procedures specified in clause 4.2.9.2 in step 25, except for S-NSSAIs for which network slice-specific authentication and authorization has already been initiated for the same S-NSSAI in another access type based on the network policy. The UE shall not attempt to re-register an S-NSSAI included in the list of pending NSSAIs until the network slice-specific authentication and authorization procedures are completed, regardless of the access type.
[0388] If the UE does not indicate that it supports network slice-specific authentication and authorization procedures in the UE 5GMM core network function in the registration request and the request NSSAI includes an S-NSSAI that is mapped to an HPLMN S-NSSAI that complies with network slice-specific authentication and authorization, the AMF includes the S-NSSAI in the request NSSAI in the reject S-NSSAI.
[0389] The following reasons may occur if the S-NSSAI cannot be provided in the Authorized NSSAI:
[0390] -All S-NSSAIs in the requesting NSSAI are subject to network slice-specific authentication and authorization, or
[0391] -If no request NSSAI was provided or none of the S-NSSAIs in the request NSSAI match any of the subscribe S-NSSAIs, all S-NSSAIs marked as default in the subscribe S-NSSAI are subject to network slice-specific authentication and authorization.
[0392] The AMF shall provide an empty Authorization NSSAI. Upon receiving the empty Authorization NSSAI and the Reserved NSSAI, the UE shall register in the PLMN but shall await the completion of network slice specific authentication and authorization procedures without attempting to use any services offered by the PLMN in any access until the UE receives the Authorization NSSAI, except for, for example, emergency services (see TS 24.501
[25] ).
[0393] The AMF stores the NB-IoT priority obtained in step 14 and associates it with the 5G-S-TMSI assigned to the UE.
[0394] If the registration request message received through 3GPP access does not include any paging restriction information, the AMF shall delete any paging restriction information stored for the UE and stop restricting paging accordingly.
[0395] If a registration request message received through 3GPP access contains a release request indication.
[0396] The AMF updates the UE context with any received paging restriction information and then implements it in a network-triggered service request procedure as described in section 4.2.3.3.
[0397] The AMF does not establish user plane resources and triggers the AN release procedure as described in section 4.2.6 after the registration procedure is completed.
[0398] The AMF sends a registration accept message to the UE indicating that the registration request is accepted. The 5G-GUTI is included when the AMF assigns a new 5G-GUTI. When receiving a registration request message of type "Initial Registration", "Mobility Registration Update", or "Disaster Roaming Registration" from the UE, the AMF shall include the new 5G-GUTI in the registration accept message. When receiving a registration request message of type "Periodic Registration Update" from the UE, the AMF shall include the new 5G-GUTI in the registration accept message. If the UE is already in RM-REGISTERED state via another access in the same PLMN, the UE shall use the 5G-GUTI received in the registration accept for both registrations. If the 5G-GUTI is not included in the registration accept, the UE shall use the 5G-GUTI assigned to the existing registration for the new registration as well. If the AMF assigns a new registration area, the AMF shall send the registration area to the UE via the registration accept message. For disaster roaming registration, the AMF allocates a registration area limited to the area with disaster conditions as specified in clause 5.40 of TS 23.501 [2]. If no registration area is included in the registration accept message, the UE shall consider the old registration area as valid. If mobility restrictions apply for the UE and the registration type is not emergency registration, the mobility restrictions are included. The AMF indicates the established PDU session in the PDU session state to the UE. The UE locally removes any internal resources related to the PDU session that are not marked as established in the received PDU session state. If the AMF invokes the Nsmf_PDUSession_UpdateSMContext procedure for UP activation of the PDU session in step 18 and receives a rejection from the SMF, the AMF indicates to the UE the PDU session ID and the reason why the user plane resources were not activated. When a UE is connected to two AMFs belonging to different PLMNs via 3GPP access and non-3GPP access, the UE locally removes any internal resources related to PDU sessions of the current PLMN that are not marked as established in the received PDU session status.If PDU session state information is present in the registration request, the AMF shall indicate the PDU session state to the UE.
[0399] If the RAT type is NB-IoT and the network is configured to use the control plane relocation indication procedure, the AMF shall include in the registration accept message the simplified 5G-S-TMSI configuration that a UE using control plane CIoT 5GS optimization shall use to create a simplified 5G-S-TMSI (see clause 5.31.4.3 of TS 23.501 [2]).
[0400] The authorized NSSAIs provided in the registration authorization are valid in the registration area and apply to all PLMNs with tracking areas included in the registration area. The mapping of authorized NSSAIs is to map each S-NSSAI of the authorized NSSAIs to the HPLMN S-NSSAI. The mapping of configuration NSSAIs is to map each S-NSSAI of the configuration NSSAIs for the serving PLMN to the HPLMN S-NSSAI.
[0401] If the UE indicates that it supports subscription-based restrictions on concurrent registration of network slice functions, the AMF shall include, if available, the NSSRG information defined in clause 5.15.12 of TS 23.501 [2].
[0402] If the UE does not indicate that it supports subscription-based restrictions on concurrent registrations of network slicing functions, the subscription information for the UE includes SRG information, and the AMF has provided a configuration NSSAI to the UE, the configuration NSSAI shall include the S-NSSAI in accordance with clause 5.15.12 of TS 23.501 [2].
[0403] The AMF shall include in the registration accept message the LADN information for the list of LADNs, as described in clause 5.6.5 of TS 23.501 [2], that are available within the registration area determined by the AMF for the UE. The AMF may include operator-defined access category definitions, as described in TS 24.501
[25] , to allow the UE to determine the applicable operator-specific access category definitions.
[0404] If the UE includes the MICO mode in the registration request, the AMF responds with a registration accept message indicating whether the MICO mode should be used. If the MICO mode is allowed for the UE, the AMF may include an active time value and / or a strict periodic registration timer indication in the registration accept message. The AMF determines the periodic registration update timer value, the active time value, and the strict periodic registration timer indication based on local configuration, expected UE behavior if available, UE indicated preferences, UE capabilities, UE subscription information, and network policies, or any combination thereof, to enable UE power saving, as described in clause 5.31.7 of TS 23.501 [2]. If the UE indicates the UE capability of the strict periodic registration timer indication in the registration request message as described in step 1, the AMF determines to apply the strict periodic registration timer indication to the UE. If the AMF provides the UE with a periodic registration update timer value together with the strict periodic registration timer indication, the UE and the AMF start the periodic registration update timer after this step as described in clause 5.31.7.5 of TS 23.501 [2].
[0405] In case of registration via 3GPP access, the AMF sets the support indication for IMS voice in PS sessions as described in clause 5.16.3.2 of TS 23.501 [2]. To set the support indication for IMS voice in PS sessions, the AMF may need to perform the UE capability match request procedure in clause 4.2.8a to check the compatibility of the radio capabilities of the UE and NG-RAN for IMS voice in PS. If the AMF does not receive the voice support match indicator from the NG-RAN in time, based on the implementation, the AMF may set the support indication for IMS voice in PS sessions and update it at a later stage.
[0406] During registration via 3GPP access, if the AMF obtains or determines the target NSSAI and the corresponding RFSP index according to local configuration to enable the NG-RAN to redirect the UE to a cell supporting a network slice that is not available in the current TA as described in clause 5.3.4.3.3 of TS23.501 [2], the AMF provides the target NSSAI and the corresponding RFSP index to the NG-RAN.
[0407] In case of registration via non-3GPP access, the AMF sets the IMS voice support indication in the PS session as described in clause 5.16.3.2a of TS 23.501 [2].
[0408] The emergency service support indicator informs the UE that emergency services are supported, i.e., the UE is able to request a PDU session for emergency services. If the AMF receives "MPS Priority" from the UDM as part of the access and mobility subscription data based on operator policy, the "MPS Priority" is included in the registration accept message to the UE to inform the UE whether the configuration of Access Identity 1 is valid in the selected PLMN, as specified in TS 24.501
[25] . If the AMF receives "MCX Priority" from the UDM as part of the access and mobility subscription data based on operator policy and the UE subscription to the MCX service, the "MCX Priority" is included in the registration accept message to the UE to inform the UE whether the configuration of Access Identity 2 is valid in the selected PLMN, as specified in TS 24.501
[25] . The acknowledged DRX parameters are defined in clause 5.4.5 of TS 23.501 [2]. If the UE included the requested DRX parameters for NB-IoT in the registration request message, the AMF includes the acknowledged DRX parameters for NB-IoT. The AMF configures network support for interworking without N26 parameters as described in clause 5.17.2.3.1 of TS 23.501 [2]. If the AMF approves the use of extended idle mode DRX, the AMF includes the extended idle mode DRX parameters and paging time window as described in clause 5.31.7.2 of TS 23.501 [2].
[0409] A network slicing subscription change indication is included if the UDM is intended to indicate to the UE that a subscription has changed. If the AMF includes a network slicing subscription change indication, the UE shall locally clear all network slicing configurations for all PLMNs and, if applicable, update the configuration for the current PLMN based on any information received.
[0410] As specified in clause 5.15.9 of TS 23.501 [2], the access stratum connection establishment NSSAI inclusion mode is included to instruct the UE which NSSAI, if any, to include in the access stratum connection establishment. The AMF may set the value to the modes of operation a, b, and c defined in clause 5.15.9 of TS 23.501 [2] for 3GPP access only if it indicates that the inclusion of the NSSAI in the RRC connection establishment grant is allowed.
[0411] For a UE registered in a PLMN, the AMF may provide a list of equivalent PLMNs, which shall be processed as specified in TS 24.501
[25] . For a UE registered in an SNPN, the AMF shall not provide a list of equivalent PLMNs to the UE.
[0412] If the UE included support for restricting the use of enhanced coverage in step 1, the AMF sends the enhanced coverage restriction information to the NG-RAN in the N2 message. The AMF also sends the enhanced coverage restriction information to the UE in the registration accept message.
[0413] If the UE receives the enhanced coverage restriction information in the registration accept message, the UE shall store this information and shall use the value of the enhanced coverage restriction information to determine whether to use the enhanced coverage feature.
[0414] If the UE and the AMF have negotiated to enable the MICO mode and the AMF uses an extended connection timer, the AMF provides the NG-RAN with an extended connection time value in this step (see clause 5.31.7.3 of TS 23.501 [2]). The extended connection time value indicates the minimum time that the RAN should keep the UE in RRC-CONNECTED state regardless of inactivity.
[0415] If the UE includes a preferred network behavior in the UE registration request, the AMF indicates the CIoT 5GS optimizations that it supports and approves in the supported network behavior information (see clause 5.31.2 of TS23.501 [2]).
[0416] The AMF may steer the UE from 5GC by rejecting the registration request. Before steering the UE from 5GC, the AMF should take into account the desired support network behavior (see clause 5.31.2 of TS 23.501 [2]) and the availability of EPC for the UE.
[0417] If the AMF authorizes the MICO mode and is aware that there may be mobile terminated data or signaling pending, the AMF shall maintain the N2 connection for at least the extended connection time as described in clause 5.31.7.3 of TS 23.501 [2] and provide the extended connection time value to the RAN.
[0418] The AMF includes the service gap time if it is present in the subscription information (steps 14a-c) or if the service gap time is updated by a subscriber data update notification to AMF procedure (see section 4.5.1) and the UE indicates UE service gap control capability.
[0419] If the UE receives a service gap time in the registration accept message, the UE shall store this parameter and apply the service gap control (see clause 5.31.16 of TS 23.501 [2]).
[0420] If the network supports WUS grouping (see TS 23.501 [2]), the AMF shall send WUS assistance information to the UE. If the UE provided UE paging availability information in step 1, the AMF shall take it into account when determining the WUS assistance information.
[0421] If the UE and AMF support RACS as defined in clause 5.4.4.1a of TS 23.501 [2], and the AMF needs to configure the UE with a UE radio capability ID, and the AMF already has a UE radio capability other than the NB-IoT radio capability for the UE, the AMF may provide the UE with the UE radio capability ID for the UE radio capability, which the UMF returns to the AMF in a Nucmf_assign service operation for this UE. Alternatively, if the UE and AMF support RACS, the AMF may provide an indication to the UE to delete any PLMN-assigned UE radio capability IDs in this PLMN (see clause 5.4.4.1a of TS 23.501 [2]).
[0422] If the UE is "CAG supported" and the AMF needs to update the UE's CAG information, the AMF may include the CAG information in the registration accept message as part of the mobility restriction.
[0423] If the UE indicates support for paging cause indication for voice service capability in the registration request message, and if the network supports and intends to apply paging cause indication for voice service capability for the UE, the AMF includes an indication that the UE supports paging cause indication for voice service capability in the N2 message carrying the registration accept message.
[0424] If the multi-USIM UE indicated support for one or more multi-USIM-specific features in the UE 5GMM core network capabilities in step 1, the AMF shall indicate to the multi-USIM UE whether the corresponding one or more multi-USIM-specific features described in clause 5.38 of TS 23.501 [2] are supported based on the network capabilities and network preferences (i.e., based on local network policies) by providing one or more of connection release support, paging cause indication for voice service support, paging restriction support, and reject paging request support indication. If the multi-USIM UE indicated support for paging cause indication for voice service capability, an AMF supporting paging cause indication for voice service shall include in the N2 message an indication that the UE supports paging cause indication for voice service capability. The AMF shall simply indicate paging restriction support together with either connection release support or reject paging request support. The UE shall simply use the multi-USIM-specific features that the AMF indicated as supported.
[0425] 21b. [Optional] The new AMF performs UE policy association establishment as defined in clause 4.16.11. For emergency registration, this step is skipped.
[0426] The new AMF sends a request to create an Npcf_UEPolicyControl to the PCF. The PCF sends a request to create an Npcf_UEPolicyControl to the new AMF.
[0427] The PCF triggers the UE configuration update procedure as defined in clause 4.2.4.3.
[0428] 22. [Conditional] UE to new AMF: Registration complete().
[0429] In step 21, after receiving the [Configuration NSSAI for Serving PLMN], [Configuration NSSAI Mapping], [NSSRG Information] and any of the network slicing subscription change indication or CAG information, if the UE has successfully updated itself, the UE sends a registration complete message to the AMF.
[0430] The UE sends a registration complete message to the AMF to inform it whether a new 5G-GUTI has been assigned.
[0431] If a new 5G-GUTI is assigned, the UE passes the new 5G-GUTI to the lower layer of that 3GPP access when the lower layer (either 3GPP access or non-3GPP access) indicates to the RM layer of the UE that the registration complete message has been successfully transferred across the air interface.
[0432] NOTE 14: The above is required because the NG-RAN may use the RRC inactive state and part of the 5G-GUTI is used to calculate paging frames (see TS38.304
[44] and TS36.304
[43] ). It is assumed that the registration completion is reliably signaled to the AMF after the 5G-AN acknowledges its reception to the UE.
[0433] If the list of PDU sessions to be activated is not included in the registration request and the registration procedure was not started in the CM-CONNECTED state, the AMF shall release the signaling connection with the UE according to clause 4.2.6.
[0434] If a subsequent request is included in the registration request, the AMF should not release the signaling connection after the registration procedure is completed.
[0435] If the AMF is aware that any signaling is pending in the AMF or between the UE and the 5GC, the AMF should not release the signaling connection immediately after the registration procedure is completed.
[0436] If the PLMN-assigned UE radio capability ID is included in step 21, the AMF stores the PLMN-assigned UE radio capability ID in the UE context when receiving the registration complete message.
[0437] If the UE receives a PLMN-assigned UE radio capability ID deletion indication in step 21, the UE shall delete the PLMN-assigned UE radio capability ID for this PLMN.
[0438] 23. [Conditional] AMF to UDM: If the access and mobility subscription data provided by the UDM to the AMF in 14b includes steering of roaming information with an indication that the UDM requests the UE to acknowledge receipt of this information, the AMF provides the UE response to the UDM using Nudm_SDM_Info. For more information on handling steering of roaming information, see TS 23.122
[22] .
[0439] 23a. For registration via 3GPP access, if the AMF does not release the signaling connection, the AMF sends RRC inactive support information to the NG-RAN.
[0440] For registration via non-3GPP access, if the UE is also in a CM-CONNECTED state in 3GPP access, the AMF sends RRC inactive assistance information to the NG-RAN.
[0441] The AMF also uses the Nudm_SDM_Info service operation to provide a response to the UDM that the UE has received and acted upon the CAG information or network slicing subscription change indication (see steps 21 and 22).
[0442] 24. [Conditional] From AMF to UDM: After step 14a, in parallel with any of the preceding steps, the AMF shall send the "Homogeneous support for IMS voice in PS sessions" indication to the UDM using Nudm_UECM_Update.
[0443] - if the AMF has evaluated the support of IMS voice in PS sessions (see clause 5.16.3.2 of TS 23.501 [2]), and
[0444] - if the AMF determines that it needs to update its homogeneous support for IMS voice in PS sessions (see clause 5.16.3.3 of TS 23.501 [2]).
[0445] 25. [Conditional] If the UE indicates that it supports network slice-specific authentication and authorization procedures in the UE MM Core Network Function in the Registration Request and any S-NSSAI in the HPLMN is subject to network slice-specific authentication and authorization, the related procedures are performed in this step (see Section 4.2.9.1). Once the network slice-specific authentication and authorization procedures are completed for all S-NSSAIs, the AMF shall trigger a UE Configuration Update procedure to convey the allowed NSSAIs, including the S-NSSAIs for which the network slice-specific authentication and authorization were successful, and shall include any rejected NSSAIs with an appropriate rejection cause value.
[0446] If the tracking area of the registration area was previously assigned as an unauthorized area with pending network slice-specific authentication and authorization, the AMF shall remove the mobility restriction.
[0447] The AMF stores an indication that the network slice-specific authentication and authorization is successful in the UE context for any S-NSSAI of the HPLMN that is subject to the network slice-specific authentication and authorization.
[0448] If, upon completing the network slice specific authentication and authorization procedures, the AMF determines that it cannot provide an S-NSSAI in the authorized NSSAI for a UE that has already been successfully authenticated and authorized by the PLMN, and if no default S-NSSAI can be further considered, the AMF shall perform the network-initiated deregistration procedure described in clause 4.2.2.3.3 and shall include a list of rejected S-NSSAIs in the explicit deregistration request message, each with an appropriate rejection cause value.
[0449] Mobility related event notifications to NF consumers are triggered at the end of this procedure in the cases described in clause 4.15.4.
[0450] <4.2.2.2.2 Registration Overview> Figure 4.2.2.2.2-1: Registration procedure (see Figure 15).
[0451] 1. From UE to (R)AN: AN message (AN parameters, Registration Request (Registration Type, SUCI or 5G-GUTI or PEI, [Last Visited TAI (if available)], Security Parameters, [Requested NSSAI], [Requested NSSAI Mapping], [Default Configuration NSSAI Indication], [UE Radio Capability Update], [UE MM Core Network Capabilities], [PDU Session State], [List of PDU Sessions to be Activated], [Subsequent Request], [MICO Mode Preference], [Requested Active Time], [Requested DRX Parameters for E-UTRA and NR], [Requested DRX Parameters for NB-IoT], [Extended Idle Mode DRX Parameters], [Requested LAD Information LAD DNN or Indicator], [NAS Message Container], [Support for Restricting the Use of Improved Coverage], [Preferred Network Behavior], [UE Paging Availability Information], [UE Policy Container (List of PSI, Indication of UE Support for ANDSP, and Operating System Identifier)], and [UE Radio Capability ID], [Release Request Indicator], [Paging Restriction Information], PEI, [NSSRG Handling Support Indicator], [PLMN with Disaster Condition], NAS Connection Identifier).
[0452] NOTE 1: The UE Policy Container and its usage are defined in TS 23.503
[20] .
[0453] In the case of NG-RAN, the AN parameters include, for example, 5G-S-TMSI or GUAMI, selected PLMN ID (or PLMN ID and NID see clause 5.30 of TS 23.501 [2]), and NSSAI information, and the AN parameters also include an establishment cause. The establishment cause provides the reason for requesting establishment of an RRC connection. Whether and how the UE includes the NSSAI information as part of the AN parameters depends on the value of the Access Stratum Connection Establishment NSSAI Inclusion Mode parameter as specified in clause 5.15.9 of TS 23.501 [2].
[0454] If the UE is an IAB node accessing 5GS, the AN parameter shall also include an IAB indication.
[0455] The registration type indicates whether the UE wants to perform an initial registration (i.e., the UE is in RM-DEREGISTERED state), a mobility registration update (i.e., the UE is in RM-registered state and initiates the registration procedure for mobility or because the UE needs to update its capabilities or protocol parameters or needs to request a change in the set of network slices that the UE is allowed to use), a periodic registration update (i.e., the UE is in RM-registered state and initiates the registration procedure due to expiration of the periodic registration update timer see section 4.2.2.2.1), an emergency registration (i.e., the UE is in limited service state), or a disaster roaming registration.
[0456] If the UE uses E-UTRA, the UE indicates in the RRC connection establishment signaling associated with the registration request that the UE supports CIoT 5GS optimization related to AMF selection.
[0457] If the UE is performing an initial registration or disaster roaming registration, the UE shall indicate its UE identity in the registration request message as follows, which, for registration with a PLMN, are listed in order of decreasing priority: i) If the UE has a valid EPS GUTI, the 5G-GUTI is mapped from the EPS GUTI. ii) If available, the native 5G-GUTI assigned by the PLMN to which the UE is attempting to register; iii) If available, the native 5G-GUTI assigned by the equivalent PLMN to the PLMN to which the UE is attempting to register; iv) Native 5G-GUTI allocated by any other PLMN, if available. Note 2: This can also be a 5G-GUTI allocated via another access type. v) In other cases, the UE shall include its SUCI in the registration request as specified in TS 33.501
[15] .
[0458] If the UE is registering with an SNPN, when the UE is performing initial registration, the UE shall indicate its UE identity in the registration request message as follows, listed in descending order of preference: i) If available, a native 5G-GUTI assigned by the same SNPN to which the UE is attempting to register; ii) If available, the native 5G-GUTI assigned by any other SNPN together with the NID of the SNPN that assigned the 5G-GUTI; iii) In other cases, the UE shall include its SUCI in the registration request as specified in TS 33.501
[15] .
[0459] If the UE performing initial registration has both a valid EPS GUTI and a native 5G-GUTI, the UE shall also indicate the native 5G-GUTI as an additional GUTI. If multiple native 5G-GUTIs are available, the UE shall select a 5G-GUTI from items (ii) to (iv) in the above list in descending order of priority.
[0460] If the UE is sending a Registration Request message as an initial NAS message, the UE has a valid 5G NAS security context, and the UE needs to send non-cleartext IEs, the NAS message container shall be included (see clause 4.4.6 in TS 24.501
[25] ). If the UE does not need to send non-cleartext IEs, the UE shall send the Registration Request message without including a NAS message container.
[0461] If the UE does not have a valid 5G NAS security context, the UE shall send the Registration Request message without including a NAS message container. The UE shall include the entire Registration Request message (i.e., including cleartext and non-cleartext IEs) in the NAS message container sent as part of the Security Mode Complete message in step 9b.
[0462] If the UE is initially registered with native 5G-GUTI (i.e., the UE is in RM-DEREGISTERED state), the UE shall indicate the relevant GUAMI information in the AN parameters. If the UE is initially registered with its SUCI, the UE shall not indicate any GUAMI information in the AN parameters.
[0463] If the UE is performing initial registration or mobility registration and CIoT 5GS optimization is supported, the UE shall indicate its preferred network behavior (see clause 5.31.2 of TS 23.501 [2]). If S1 mode is supported, the preferred network behavior of the UE's EPC shall be included in the S1 UE network capabilities in the registration request message (see clause 8.2.6.1 of TS 24.501
[25] ).
[0464] For emergency registration, if the UE does not have a valid 5G-GUTI available, the SUCI shall be included, and if the UE does not have a SUPI and a valid 5G-GUTI, the PEI shall be included. Otherwise, the 5G-GUTI shall be included, which indicates the latest serving AMF.
[0465] The UE may provide the UE usage settings based on the UE configuration as defined in clause 5.16.3.7 of TS23.501[2]. The UE provides the Request-NSSAI (as described in clause 5.15.5.2.1 of TS23.501[2]), and if the UE supports subscription-based restrictions on concurrent registration of network slices and also takes into account NSSRG information restrictions as described in clause 5.15.12 of TS23.501[2], in the case of initial registration or mobility registration update, the UE includes a mapping of the Request-NSSAI (if available) that is a mapping of each S-NSSAI of the Request-NSSAI to the HPLMN S-NSSAI, so that the network can reliably verify whether the S-NSSAI in the Request-NSSAI is allowed based on the subscribed S-NSSAI. In case of inter-PLMN mobility, if the Serving PLMN S-NSSAI corresponding to the Established PDU Session does not exist in the UE, the relevant HPLMN S-NSSAI associated with the Established PDU Session shall be provided to the Requested NSSAI mapping as described in clause 5.15.5.2.1 of TS 23.501 [2].
[0466] If the UE is using the default configuration NSSAI as defined in TS23.501 [2], the UE shall include the default configuration NSSAI indication.
[0467] If the UE supports allocation of WUS assistance information from the AMF, the UE may include UE paging availability information (see TS23.501[2]).
[0468] In the case of a mobility registration update, the UE shall include in the list of PDU sessions to be activated those PDU sessions for which there is pending uplink data. When the UE includes the list of PDU sessions to be activated, it shall indicate only the PDU sessions associated with the access for which the registration request is made. As specified in TS 24.501
[25] , the UE shall include in the list of PDU sessions to be activated those PDU sessions that are always on and accepted by the network, even if there is no pending uplink data for that PDU session.
[0469] NOTE 3: If the UE is outside the coverage area of the LADN, the PDU session corresponding to the LADN is not included in the list of PDU sessions to be activated.
[0470] As defined in clause 5.4.4a of TS 23.501 [2], the UE MM Core Network Function is provided by the UE and processed by the AMF. As defined in clause 5.17.2.3.1 of TS 23.501 [2], the UE includes in the UE MM Core Network Function an indication of whether the UE supports the request type flag "Handover" for PDN connectivity requests during the attach procedure. If the UE supports "Strict Periodic Registration Timer Indication", the UE indicates the UE capability of "Strict Periodic Registration Timer Indication" in the UE MM Core Network Function. If the UE supports CAG, the UE indicates the UE capability of "CAG Supported" in the UE MM Core Network Function. If a UE operating with two or more USIMs supports one or more multi-USIM features and intends to use one or more multi-USIM features, the UE indicates one or more multi-USIM specific features described in clause 5.38 of TS 23.501 [2] in the UE MM Core Network Function.
[0471] As described in clause 5.6.5 of TS23.501[2], the UE may provide either the LADN DNN or an indication of the requested LADN information.
[0472] If available, the last visited TAI shall be included to help the AMF generate a registration area for the UE.
[0473] The security parameters are used for authentication and integrity protection (see TS 33.501
[15] ). The requested NSSAI indicates network slice selection assistance information (as defined in clause 5.15 of TS 23.501 [2]). The PDU session status indicates a previously established PDU session in the UE. If the UE is connected to two AMFs belonging to different PLMNs via 3GPP access and non-3GPP access, the PDU session status indicates the established PDU session of the current PLMN in the UE.
[0474] A subsequent request is included if the UE has pending uplink signaling, the UE does not include a list of activated PDU sessions, or the registration type indicates that the UE wants to perform an emergency registration. In the initial registration and mobility registration update, the UE provides the UE request DRX parameters as specified in clause 5.4.5 of TS 23.501 [2]. To request extended idle mode DRX, the UE may provide the extended idle mode DRX parameters as specified in clause 5.31.7.2 of TS 23.501 [2].
[0475] As described in TS23.501 [2], the UE provides a UE radio capability update indication.
[0476] The UE includes a preference for MICO mode and, optionally, a requested active time value if the UE wants to use MICO mode during active time.
[0477] The UE may indicate its service gap control capabilities in the UE MM core network function (see clause 5.31.16 of TS 23.501 [2]).
[0478] For UEs with a running service gap timer in the UE, the UE shall not set the subsequent request indicator or uplink data state in the registration request message, except for network access for restricted priority services such as emergency services or exception reporting (see clause 5.31.16 of TS 23.501 [2]).
[0479] If the UE supports RACS and has assigned a UE Radio Capability ID, the UE shall indicate the UE Radio Capability ID as defined in clause 5.4.4.1a of TS 23.501 [2] as a non-cleartext IE.
[0480] The PEI may be obtained from the UE at initial registration, as described in section 4.2.2.2.1.
[0481] If the UE supports subscription-based restriction on concurrent registrations of the network slicing feature, the UE includes an NSSRG handling support indication according to clause 5.15.12 of TS 23.501 [2]. The AMF stores in the UE context whether the UE supports this feature.
[0482] If a UE in MUSIM mode wants to enter CM-IDLE state immediately after, for example, performing mobility registration or periodic registration, the UE includes a release request indication and optionally provides paging restriction information.
[0483] When the UE is performing disaster roaming registration, if the UE does not have a valid 5G-GUTI indicating the PLMN with disaster status, and the PLMN with disaster status is not the UE's HPLMN, or the PLMN with disaster status is the UE's HPLMN but the UE does not provide its SUCI, the UE may indicate the PLMN with disaster status.
[0484] If a 5G NAS security context corresponding to 3GPP access is used to protect the integrity of the registration request message, the UE includes a NAS connection identifier with a value set to 3GPP access. This information element may be sent as a cleartext IE.
[0485] 2. If the 5G-S-TMSI or GUAMI is not included or does not indicate a valid AMF, the (R)AN selects an AMF based on the (R)AT and the requested NSSAI, if available.
[0486] The (R)AN selects the AMF as described in clause 6.3.5 of TS23.501 [2]. If the UE is in a CM-CONNECTED state, the (R)AN may forward the registration request message to the AMF based on the UE's N2 connection.
[0487] If the (R)AN cannot select an appropriate AMF, the (R)AN forwards the registration request to an AMF configured in the (R)AN to perform AMF selection.
[0488] 3. (R)AN to new AMF: N2 message (N2 parameters), registration request (as described in step 1) and [LTE-M indication].
[0489] If NG-RAN is used, the N2 parameters include the selected PLMN ID (or PLMN ID and NID see clause 5.30 of TS 23.501 [2]), location information and cell identity information for the cell in which the UE is camped, and a UE context request indicating that a UE context including security information needs to be set up in the NG-RAN.
[0490] If NG-RAN is used, the N2 parameter shall also contain the establishment cause and shall contain the IAB indication if an indication is received in the AN parameter in step 1.
[0491] Mapping of the request NSSAI is provided only if available.
[0492] If the registration type indicated by the UE is periodic registration update, steps 4 to 19 may be omitted.
[0493] If the establishment cause is associated with a priority service (e.g., MPS, MCS), the AMF includes a Message Priority header to indicate the priority information. As specified in TS 29.500
[17] , other NFs relay the priority information by including the Message Priority header in their service-based interfaces.
[0494] The RAT type used by the UE is determined (see clause 4.2.2.2.1) and based on that the AMF determines whether the UE is performing inter-RAT mobility to or from NB-IoT. If the AMF receives an LTE-M indication, the AMF considers that the RAT type is LTE-M and stores the LTE-M indication in the UE context.
[0495] If the UE includes a preferred network behavior, this defines the network behavior that the UE wants to support and be available in the network, as defined in clause 5.31.2 of TS 23.501 [2].
[0496] If the UE includes a preferred network behavior and the preferred network behavior that the UE indicates it supports is incompatible with network support, the AMF shall reject the registration request with an appropriate cause value (e.g., one that avoids retries in this PLMN).
[0497] If there is a service gap timer running in the UE context in the AMF for the UE and the subsequent request indication or uplink data status is not included in the registration request message, the AMF shall ignore the subsequent request indication and uplink data status and shall not take any action regarding the status.
[0498] If the UE included the UE radio capability ID in step 1 and the AMF supports RACS, the AMF stores the radio capability ID in the UE context.
[0499] For NR satellite access, if the AMF can determine, based on the selected PLMN ID and ULI (including cell ID) received from the gNB, that the UE is attempting to register with a PLMN that is not authorized to operate at the current UE location, the AMF should reject the registration request with a suitable cause value and, if known to the AMF, the country of the UE location. In other cases, for example, if the AMF does not know the UE location with sufficient accuracy to make a final decision, the AMF may proceed with the registration procedure and initiate a UE location procedure as specified in clause 6.10.1 of TS 23.273
[51] to prepare to deregister the UE if the information received from the LMF indicates that the UE is registered with a PLMN that is not authorized to operate at the UE location.
[0500] NOTE 4: Location information may not be guaranteed to be accurate enough for the AMF to determine the country in which the UE is located in all cases.
[0501] Note 5: Some countries use multiple MCCs, and some MCCs, such as 901, may be allowed in multiple countries, so the UE may register with a different MCC in the PLMN than the one returned to the UE.
[0502] Upon receiving a registration rejection for the country in which the UE is located, the UE shall attempt to register with a PLMN that is permitted to operate at the UE location as specified in TS 23.122
[22] .
[0503] For disaster roaming registration, the AMF determines whether disaster roaming service can be provided based on the ULI (including the cell ID) received from the NG-RAN, the PLMN with a disaster state derived from the UE's 5G-GUTI, derived from the UE's SUCI, or indicated by the UE, and the local configuration. If the current location does not receive disaster roaming service or disaster roaming service is not provided for the PLMN with a disaster state derived from the UE's 5G-GUTI, derived from the UE's SUCI, or indicated by the UE, the AMF should reject the registration request with a suitable cause value.
[0504] 4. [Conditional] From new AMF to old AMF: Namf_Communication_UEContextTransfer (full registration request, NAS connection identifier) or from new AMF to UDSF: Nudsf_UnstructuredDataManagement_Query().
[0505] The new AMF determines the old AMF using the UE's 5G-GUTI. If the new AMF receives the NID in the registration request, the new AMF determines that the 5G-GUTI is assigned by the SNPN and uses the SNPN's 5G-GUTI and NID to determine the old AMF.
[0506] (With UDSF Deployment): If the UE's 5G-GUTI is included in the registration request and the serving AMF has changed since the last registration procedure, the new AMF and old AMF are in the same AMF set and UDSF is deployed, or the new AMF obtains the stored UE's SUPI and UE context directly from the UDSF using the Nudsf_UnstructuredDataManagement_Query service operation, or if UDSF is not deployed, the new AMF and old AMF may share the stored UE context via implementation-specific means. This also includes event subscription information by each NF consumer for a given UE. In this case, the new AMF uses the integrity protection full registration request NAS message to perform and verify integrity protection.
[0507] (Without UDSF deployment): If the UE's 5G-GUTI is included in the registration request and the serving AMF has changed since the last registration procedure, the new AMF may invoke the Namf_Communication_UEContextTransfer service operation in the old AMF, including the full registration request NAS message and access type, which can be integrity protected, to request the UE's SUPI and UE context. The old AMF may include the NAS connection identifier as received in the full registration request. For details of this service operation, see section 5.2.2.2.2. In this case, to verify integrity protection when a context transfer service operation execution corresponds to the requested UE, the old AMF uses either the 5G-GUTI and integrity-protected full registration request NAS message, or the SUPI and an indication from the new AMF that the UE has been verified. The old AMF also forwards event subscription information by each NF consumer for the UE to the new AMF. If the old AMF has not yet reported a non-zero MO exception data counter to the (H-)SMF, the context response also includes the MO exception data counter.
[0508] If the old AMF has a PDU session for another access type (different from the access type indicated in this step) and if the old AMF determines that there is no possibility to relocate the N2 interface to the new AMF, the old AMF returns the UE's SUPI and indicates that the registration request has been verified for integrity protection, but does not include the remaining UE context.
[0509] For inter-PLMN movement, the UE context information includes the HPLMN S-NSSAI corresponding to the authorized NSSAI for each access type without the authorized NSSAI of the old PLMN.
[0510] NOTE 6: If the new AMF successfully authenticates the UE after a previous integrity check failure in the old AMF, the new AMF sets an indication that the UE is verified according to step 9a.
[0511] NOTE 7: The NF consumer does not need to resubscribe to events for the new AMF after the UE has successfully registered with the new AMF.
[0512] If the new AMF has already received the UE context from the old AMF during the handover procedure, steps 4, 5 and 10 shall be skipped.
[0513] For emergency registration, if the UE identifies itself with a 5G-GUTI that is not known to the AMF, steps 4 and 5 are skipped and the AMF immediately requests a SUPI from the UE. If the UE identifies itself with a PEI, the SUPI request shall be skipped. The permission of emergency registration without user identity depends on local regulations.
[0514] 5. [Conditional] From old AMF to new AMF: Response to Namf_Communication_UEContextTransfer (SUPI, UE context in AMF (according to Table 5.2.2.2.2-1)) or from UDSF to new AMF: Nudsf_UnstructuredDataManagement_Query(). The old AMF may start an implementation-specific (guard) timer for the UE context.
[0515] If the UDSF is queried in step 4, it responds to the new AMF with a Nudsf_UnstructuredDataManagement_Query execution for the relevant context including the established PDU session, and the old AMF includes the SMF information DNN, S-NSSAI and PDU session ID, active NGAP UE-TNLA binding in N3IWF / TNGF / W-AGF, and the old AMF includes information about the NGAP UE-TNLA binding. If the old AMF is queried in step 4, it responds to the new AMF with a Namf_Communication_UEContextTransfer execution by including the UE's SUPI and UE context.
[0516] If the old AMF holds information about the established PDU session and it is not an initial registration, the old AMF includes SMF information, DNN, S-NSSAI, and PDU session ID.
[0517] If the old AMF holds the UE context established via the N3IWF, W-AGF, or TNGF, the old AMF includes the CM state via the N3IWF, W-AGF, or TNGF. If the UE is in CM-CONNECTED state via the N3IWF, W-AGF, or TNGF, the old AMF includes information about the NGAP UE-TNLA binding.
[0518] The old AMF uses the 5G NAS security context corresponding to the NAS connection identifier to verify the integrity of the full registration request.
[0519] If the old AMF fails to verify the integrity of the registration request NAS message, the old AMF shall indicate an integrity verification failure. If the new AMF is configured to allow emergency services for unauthenticated UEs, the new AMF shall operate as follows:
[0520] If the UE has only an emergency PDU session, the AMF skips the authentication and security procedures or acknowledges that authentication may fail and continues the mobility registration update procedure, or
[0521] If the UE has both emergency and non-emergency PDU sessions and authentication fails, the AMF continues the mobility registration update procedure and deactivates all non-emergency PDU sessions as specified in section 4.3.4.2.
[0522] Note 8: The new AMF may determine whether a PDU session is used for emergency services by checking whether the DNN matches the emergency DNN.
[0523] If the old AMF holds information about AM policy association and information about UE policy association (i.e., policy control request trigger to update UE policy as defined in TS 23.503
[20] ), the old AMF includes information about AM policy association, UE policy association, and PCF ID. In case of roaming, V-PCF ID and H-PCF ID are included.
[0524] If the old AMF was a consumer of the UE-related NWDAF service, the old AMF includes information about the active analysis subscription, i.e., subscription correlation ID, NWDAF identifier (i.e., instance ID or set ID), analysis ID, and associated analysis-specific data, in the Namf_Communication_UEContextTransfer response. The use of analysis information by the new AMF is specified in TS 23.288
[50] .
[0525] The handling of the UE radio capability ID in the new AMF during inter-PLMN movement is specified in TS 23.501 [2].
[0526] Note 9: If the new AMF uses UDSF for context retrieval, the interaction between the old AMF, new AMF, and UDSF due to simultaneous UE signaling in the old AMF is an implementation issue.
[0527] 6. [Conditional] New AMF to UE: Identity Request().
[0528] If the SUCI is not provided by the UE and is not obtained from the old AMF, the identity request procedure is initiated by the AMF sending an identity request message to the UE requesting the SUCI.
[0529] 7. [Conditional] UE to new AMF: Identity response().
[0530] The UE responds with an Identity Response message containing the SUCI, which the UE derives by using the public key of the provisioned HPLMN as specified in TS33.501
[15] .
[0531] 8. The AMF may decide to initiate UE authentication by invoking the AUSF. In that case, the AMF selects the AUSF based on the SUPI or SUCI as described in clause 6.3.4 of TS 23.501 [2].
[0532] If the AMF is configured to support emergency registration for unauthenticated SUPI and the UE indicates emergency registration as a registration type, the AMF skips authentication or the AMF acknowledges that authentication may fail and continues the registration procedure.
[0533] 9a. If authentication is required, the AMF requests it from the AUSF, and if the trace requirements for the UE are available in the AMF, the AMF provides the trace requirements to the AUSF in the request. When requested by the AMF, the AUSF shall perform authentication of the UE. Authentication is performed as described in TS 33.501
[15] . The AUSF selects a UDM as described in clause 6.3.8 of TS 23.501 [2] and obtains authentication data from the UDM.
[0534] Editor's note: In the case of disaster roaming registration, how the AUSF performs authentication of the UE is FFS (to be further considered).
[0535] Once the UE is authenticated, the AUSF provides the AMF with relevant security-related information. If the AMF provides the SUCI to the AUSF, the AUSF shall return the SUPI to the AMF only after successful authentication.
[0536] After successful authentication in the new AMF, triggered by an integrity check failure in the old AMF in step 5, the new AMF invokes step 4 above again and indicates that the UE is verified (i.e., via the reason parameter as specified in clause 5.2.2.2.2).
[0537] 9b If no NAS security context exists, NAS security initiation occurs as described in TS 33.501
[15] . If the UE did not have a NAS security context in step 1, the UE includes a Full Registration Request message as defined in TS 24.501
[25] .
[0538] As described in section 4.2.2.2.3, the AMF determines whether the registration request needs to be rerouted, where the initial AMF refers to the AMF.
[0539] 9c. If the 5G-AN requests a UE context, the AMF initiates an NGAP procedure to provide the 5G-AN with a security context as specified in TS38.413
[10] . If the AMF determines that EPS fallback is supported (e.g., based on the UE capabilities, subscription data, and local policies to support the request type flag "handover" for the PDN connectivity request during the attach procedure as defined in clause 5.17.2.3.1 of TS23.501 [2]), the AMF shall send an indication that "redirection for EPS fallback of voice is possible" to the 5G-AN as specified in TS38.413
[10] . Otherwise, the AMF shall indicate that "redirection for EPS fallback of voice is not possible." Additionally, if trace requirements for the UE are available in the AMF, the AMF provides the trace requirements to the 5G-AN in the NGAP procedure.
[0540] 9d. The 5G-AN stores the security context and informs the AMF. The 5G-AN uses the security context to protect messages exchanged with the UE as described in TS33.501
[15] .
[0541] 10. [Conditional] From new AMF to old AMF: Namf_Communication_RegistrationStatusUpdate (e.g., PDU session ID released due to unsupported slicing).
[0542] When the AMF is changed, the new AMF informs the old AMF that the UE's registration in the new AMF is complete by calling the Namf_Communication_RegistrationStatusUpdate service operation.
[0543] If the authentication / security procedures fail, the registration shall be rejected and the new AMF shall call the Namf_Communication_RegistrationStatusUpdate service operation with a rejection indication to the old AMF. The old AMF shall continue as if the UE context transfer service operation had never been received.
[0544] If one or more of the S-NSSAIs used in the old registration area cannot be served in the target registration area, the new AMF determines which PDU sessions cannot be supported in the new registration area. The new AMF invokes the Namf_Communication_RegistrationStatusUpdate service operation with the rejected PDU session ID to the old AMF. The new AMF then modifies the PDU session status accordingly. The old AMF informs the corresponding SMF to locally release the UE's SM context by invoking the Nsmf_PDUSession_ReleaseSMContext service operation.
[0545] If the new AMF has received information about the AM policy association and UE policy association in the UE context transfer in step 5 based on the local policy and decides not to use the PCF identified by the PCF ID for the AM policy association and UE policy association, the new AMF informs the old AMF that the AM policy association and UE policy association in the UE context will no longer be used, and PCF selection is performed in step 15.
[0546] If the new AMF receives information about the UE-related analysis subscription in the UE context transfer in step 5, the new AMF may take over the analysis subscription from the old AMF. Otherwise, if the new AMF decides to create a new analysis subscription instead, the new AMF may inform the old AMF that the analysis subscription (identified by the subscription correlation ID) is no longer needed, and the old AMF may then unsubscribe from the NWDAF analysis subscription for the UE according to TS 23.288
[50] .
[0547] 11. [CONDITIONAL] New AMF to UE: Identity Request / Response (PEI).
[0548] If the PEI is not provided by the UE and has not been obtained from the old AMF, the identity request procedure is initiated by the AMF sending an identity request message to the UE to obtain the PEI. The PEI shall be transmitted encrypted unless the UE has performed an emergency registration and is not authenticated.
[0549] For emergency registration, the UE may include the PEI in the registration request, in which case the PEI lookup is skipped.
[0550] If the UE supports RACS as indicated in the UE MM core network capabilities, the AMF shall use the UE's PEI to obtain the IMEI / TAC for the purpose of RACS operation.
[0551] 12. Optionally, the new AMF initiates the ME identity check by invoking the N5g-eir_EquipmentIdentityCheck_Get service operation (see clause 5.2.4.2.2).
[0552] PEI verification will be performed as described in Section 4.7.
[0553] For emergency registration, if the PEI is blocked, operator policy determines whether to continue or stop the emergency registration procedure.
[0554] 13. If step 14 is performed, the new AMF selects a UDM based on the SUPI, and the UDM can then select a UDR instance. See section 6.3.9 of TS23.501 [2].
[0555] The AMF selects the UDM as described in clause 6.3.8 of TS 23.501 [2].
[0556] 14a-c. If the AMF has changed since the last registration procedure, or if the UE provides a SUPI in the AMF that does not reference a valid context, or if the UE registers to the same AMF to which it has already registered for non-3GPP access (i.e., the UE is registered through non-3GPP access and initiates this registration procedure to add 3GPP access), the new AMF registers with the UDM using Nudm_UECM_Registration for the access to which it is registered (and subscribes to be notified when the UDM deregisters this AMF). In this case, if the AMF does not have event exposure subscription information for this UE, the AMF indicates it to the UDM. Then, if the UDM has existing applicable event exposure subscriptions for events discovered in the AMF (possibly obtained from the UDR) for either this UE or a group to which this UE belongs, the UDM calls the Namf_EventExposure_Subscribe service to recreate the event exposure subscription.
[0557] The AMF shall provide the "Homogeneous support of IMS voice over PS sessions" indication (see clause 5.16.3.3 of TS 23.501 [2]) to the UDM. The "Homogeneous support of IMS voice over PS sessions" indication shall not be included unless the AMF has completed an AMF evaluation of its support for "IMS voice over PS sessions" as specified in clause 5.16.3.2 of TS 23.501 [2].
[0558] During initial registration, if the AMF and UE support SRVCC from NG-RAN to UTRAN, the AMF provides the UE SRVCC functionality to the UDM.
[0559] If the AMF determines that only the UE SRVCC capabilities have changed, the AMF sends the UE SRVCC capabilities to the UDM.
[0560] NOTE 10: At this step, the AMF may not have all the information necessary to determine the setting of the IMS voice over PS session support indication (see clause 5.16.3.2 of TS 23.501 [2]) for this UE. Therefore, the AMF may send "Homogeneous support of IMS voice over PS session" later in this procedure.
[0561] If the AMF does not have subscription data for the UE, it uses Nudm_SDM_Get to obtain access and mobility subscription data, SMF selection subscription data, the UE context in the SMF data, and LCS mobile origination. If the AMF already has subscription data for the UE but the SoR update indicator in the UE context requests the AMF to obtain SoR information according to the NAS registration type ('initial registration' or 'emergency registration') (see Appendix C of TS23.122
[22] ), the AMF uses Nudm_SDM_Get to obtain steering of roaming information. This requires that the UDM can obtain this information from the UDR by Nudr_DM_Query. After a response is successfully received, the AMF subscribes to be notified using Nudm_SDM_Subscribe when the required data is modified, and the UDM can subscribe to the UDR by Nudr_DM_Subscribe. If GPSI is available in the UE subscription data, the GPSI is provided to the AMF in the access and mobility subscription data from the UDM. The UDM may provide an indication that subscription data for network slicing is updated for the UE. If the UE subscribes to MPS in the serving PLMN, the "MPS priority" is included in the access and mobility subscription data provided to the AMF. If the UE subscribes to MCX in the serving PLMN, the "MCX priority" is included in the access and mobility subscription data provided to the AMF. The UDM also provides an IAB operation authorization indication to the AMF as part of the access and mobility subscription data. The AMF shall trigger the setup of the UE context in the NG-RAN, or, if the initial setup is in step 9c, a modification of the UE context in the NG-RAN, including an indication that the IAB node is authorized.
[0562] Editor's note: In the case of disaster roaming registration, how the UDM provides the AMF with applicable subscription data for disaster roaming services is FFS (to be further considered).
[0563] The new AMF provides the UDM with the access type that the new AMF will provide service to the UE, and the access type is set to "3GPP access". The UDM stores the associated access type together with the serving AMF and does not remove AMF identification information associated with other access types, if any. The UDM may store it in the UDR information provided in the AMF registration by Nudr_DM_Update.
[0564] If the UE is registered to the old AMF for access and the old AMF and new AMF are in the same PLMN, the new AMF will send another / independent Nudm_UECM_Registration to update the UDM with the access type set to the access used in the old AMF after the old AMF relocation is successfully completed.
[0565] The new AMF creates a UE context for the UE after obtaining the access and mobility subscription data from the UDM. The access and mobility subscription data includes whether the UE is allowed to include the NSSAI in the 3GPP access RRC connection establishment in clear text. The access and mobility subscription data may include enhanced coverage restriction information. If received from the UDM and the UE included support for restricting the use of enhanced coverage in step 1, the AMF determines whether enhanced coverage is restricted for the UE as specified in clause 5.31.12 of TS 23.501 [2] and stores the updated enhanced coverage restriction information in the UE context.
[0566] The access and mobility subscription data may include NB-IoT UE priority.
[0567] The subscription data may include a service gap time parameter. If received from the UDM, the AMF stores this service gap time in the UE context in the AMF for the UE.
[0568] For emergency registrations where the UE is not successfully authenticated, the AMF shall not register with the UDM.
[0569] The AMF shall enforce mobility restrictions as specified in clause 5.3.4.1.1 of TS 23.501 [2]. For emergency registration, the AMF shall not check for mobility restrictions, access restrictions, regional restrictions, or subscription restrictions. For emergency registration, the AMF shall ignore any unsuccessful registration response from the UDM and continue the registration procedure.
[0570] Note 11: Instead of the Nudm_SDM_Get service operation, the AMF may use the Nudm_SDM_Subscribe service operation with an immediate report indication to trigger the UDM to return the subscribed data immediately if the corresponding functionality is supported by both the AMF and the UDM.
[0571] 14d. If the UDM stores the associated access type (e.g., 3GPP) with the serving AMF as indicated in step 14a, the UDM will thereby initiate a Nudm_UECM_DeregistrationNotification (see clause 5.2.3.2.2) to the old AMF corresponding to the same (e.g., 3GPP) access, if any. If the timer started in step 5 is not running, the old AMF may remove the UE context for the same access type. Otherwise, the AMF may remove the UE context for the same access type upon timer expiration. If the serving NF removal reason indicated by the UDM is initial registration, as described in clause 4.2.2.3.2, the old AMF will invoke the Nsmf_PDUSession_ReleaseSMContext(SM context ID) service operation to all associated SMFs of the UE to notify them that the UE is deregistered from the old AMF for the same access type. The SMF shall release the PDU session upon obtaining this notification.
[0572] If the old AMF established an AM policy association and a UE policy association with the PCF and the old AMF did not transfer the PCF ID to the new AMF (e.g., the new AMF is in a different PLMN), the old AMF performs the AMF-initiated policy association termination procedure as specified in clause 4.16.3.2 and the AMF-initiated UE policy association termination procedure as specified in clause 4.16.13.1. In addition, if the old AMF transferred the PCF ID in the UE context but the new AMF indicated in step 10 that the AM policy association information and the UE policy association information in the UE context will not be used, the old AMF performs the AMF-initiated policy association termination procedure as specified in clause 4.16.3.2 and the AMF-initiated UE policy association termination procedure as specified in clause 4.16.13.1.
[0573] If the old AMF has an N2 connection for the UE (e.g. because the UE was in RRC inactive but is now moving to E-UTRAN or to an area not served by the old AMF), the old AMF shall perform an AN release (see section 4.2.6) with a cause value indicating that the UE has already locally released the RRC connection in the NG-RAN.
[0574] If the UE context in the old AMF includes an authorized NSSAI that includes one or more S-NSSAIs that comply with NSAC, when the old AMF receives Nudm_UECM_DeregistrationNotification from the UDM, it sends an update request message for each S-NSSAI that complies with NSAC to the corresponding NSACF, with the update flag parameter (see section 4.2.11.2) set to decrease.
[0575] Once the registration procedure is complete, if the AMF does not indicate in step 14a that the event exposure subscription is unavailable, the AMF starts synchronizing the event exposure subscription with the UDM.
[0576] Note 12: The AMF may at any given time, based on local policy, initiate synchronization with the UDM even if an event is available in the UE context (e.g., as received from the old AMF). This may be done during subscription change related events.
[0577] 14e. [Conditional] If the old AMF does not have a UE context for another access type (i.e., non-3GPP access), the old AMF unsubscribes the UDM for subscription data using Nudm_SDM_unsubscribe.
[0578] 15. When the AMF decides to initiate PCU communication, the AMF functions as follows:
[0579] If the new AMF decides to use the (V-)PCF identified by the (V-)PCF ID included in the UE context from the old AMF in step 5, the AMF contacts the (V-)PCF identified by the (V-)PCF ID to obtain the policy. If the AMF decides to perform PCF discovery and selection, the AMF selects a (V-)PCF and may select an H-PCF (for roaming scenarios) as described in clause 6.3.7.1 of TS 23.501 [2] according to the V-NRF to H-NRF interaction described in clause 4.3.2.2.3.3.
[0580] 16. [Optional] The new AMF establishes / modifies the AM policy association. For emergency registration, this step is skipped.
[0581] If the new AMF selects a new (V-)PCF in step 15, the new AMF establishes an AM policy association with the selected (V-)PCF as defined in section 4.16.1.2.
[0582] If the (V-)PCF identified by the (V-)PCF ID included in the UE context from the old AMF is used, the new AMF performs AM policy association modification with the (V-)PCF as defined in clause 4.16.2.1.2.
[0583] When the AMF notifies the PCF of mobility restrictions (e.g., UE location) for adjustment, or when the PCF updates the mobility restrictions itself according to some conditions (e.g., application in use, date and time), the PCF shall provide the updated mobility restrictions to the AMF. If the subscription information includes trace requirements, the AMF shall provide the trace requirements to the PCF.
[0584] If the AMF supports DNN substitution, the AMF provides the PCF with the authorized NSSAI and, if available, a mapping of the authorized NSSAI.
[0585] If the PCF supports DNN replacement, the PCF provides a trigger for DNN replacement to the AMF.
[0586] 17. [Conditional] From AMF to SMF: Nsmf_PDUSession_UpdateSMContext ().
[0587] For an emergency registered UE (see TS23.501[2]), this step applies if the registration type is a mobility registration update.
[0588] AMF calls Nsmf_PDUSession_UpdateSMContext (see section 5.2.8.2.6) in the following scenarios:
[0589] If the list of PDU sessions to be activated is included in the registration request in step 1, the AMF sends an Nsmf_PDUSession_UpdateSMContext request to the SMF associated with the PDU session to activate the user plane connection for that PDU session. Steps 5 onwards described in clause 4.2.3.2 are performed to complete the user plane connection activation without sending RRC inactive support information and without sending an MM NAS service accept from the AMF to the (R)AN described in step 12 of clause 4.2.3.2. Once the user plane connection for the PDU session is activated, the AS layer in the UE indicates it to the NAS layer.
[0590] If the AMF determines in step 3 that the UE is performing inter-RAT mobility to or from NB-IoT, the AMF sends an Nsmf_PDUSession_UpdateSMContext request to the SMF associated with the UE PDU session so that the SMF can update the UE PDU session according to the "PDU session continuity on inter-RAT mobility" subscription data. Steps from step 5 onwards described in clause 4.2.3.2 are performed without sending an MM NAS service acceptance from the AMF to the (R)AN described in step 12 of clause 4.2.3.2.
[0591] When the serving AMF changes, the new serving AMF notifies the SMF for each PDU session that the new AMF has taken over responsibility for the signaling path to the UE, and the new serving AMF invokes the Nsmf_PDUSession_UpdateSMContext service operation using the SMF information received from the old AMF in step 5. It also indicates whether the PDU session is to be reactivated.
[0592] NOTE 13: When a UE moves into a different PLMN, the AMF in the serving PLMN may insert or change the V-SMF in the serving PLMN for the home routed PDU session. In this case, the same procedures as described in clause 4.23.3 apply for V-SMF change as for I-SMF change (i.e., by replacing I-SMF with V-SMF). If the same SMF is used during inter-PLMN change, session continuity may be supported depending on operator policy.
[0593] The steps from step 5 onwards described in section 4.2.3.2 are performed. If the insertion, removal or modification of an intermediate UPF is performed for a PDU session that is not included in the "reactivated PDU session", the procedure is performed without N11 and N2 interaction to update the N3 user plane between the (R)AN and the 5GC.
[0594] AMF invokes the Nsmf_PDUSession_ReleaseSMContext service operation to SMF in the following scenarios:
[0595] -If any PDU session state indicates to be released in the UE, the AMF invokes the Nsmf_PDUSession_ReleaseSMContext service operation to the SMF to release any network resources related to the PDU session.
[0596] If the serving AMF is changed, the new AMF shall wait until step 18 is completed for all SMFs associated with the UE. Otherwise, steps 19 to 22 may continue in parallel with this step.
[0597] 18. [Conditional] If the new AMF and old AMF are in the same PLMN, the new AMF sends a UE context modification request to the N3IWF / TNGF / W-AGF as specified in TS 29.413
[64] .
[0598] When the AMF is changed and the old AMF indicates that the UE is in CM-CONNECTED state via the N3IWF, W-AGF, or TNGF, and the new AMF and the old AMF are in the same PLMN, the new AMF creates an NGAP UE association for the N3IWF / TNGF / W-AGF to which the UE is connected, which automatically releases the existing NGAP UE association between the old AMF and the N3IWF / TNGF / W-AGF.
[0599] 19. The N3IWF / TNGF / W-AGF sends a UE context modification response to the new AMF.
[0600] 19a. [Conditional] After the new AMF receives a response message from the N3IWF, W-AGF, or TNGF in step 19, the new AMF registers with the UDM using Nudm_UECM_Registration as in step 14a, but with the access type set to "non-3GPP access". The UDM stores the associated access type with the serving AMF and does not remove AMF identities associated with other access types, if any. The UDM may store in the UDR information provided in the AMF registration by Nudr_DM_Update.
[0601] 19b. [Conditional] If the UDM stores the associated access type (i.e., non-3GPP) with the serving AMF as indicated in step 19a, it will cause the UDM to initiate a Nudm_UECM_DeregistrationNotification (see clause 5.2.3.2.2) to the old AMF corresponding to the same (i.e., non-3GPP) access. The old AMF will remove the UE context for the non-3GPP access.
[0602] 19c. Old AMF unsubscribes UDM from subscription data using Nudm_SDM_unsubscribe.
[0603] 20a.Empty.
[0604] 21. New AMF to UE: Registration Authorization (5G-GUTI, Registration Area, Mobility Restrictions, PDU Session State, Allowed NSSAI, Allowed NSSAI Mapping, Configured NSSAI for Serving PLMN, Configured NSSAI Mapping, NSSRG Information, Rejected S-NSSAI, Reserved NSSAI, Reserved NSSAI Mapping, Periodic Registration Update Timer, Active Time, Strict Periodic Registration Timer Indicator, LADN Information, Authorized MICO Mode, Indication of Support for IMS Voice in PS Sessions, Emergency Services Support Indicator, Authorized DRX Parameters for E-UTRA and NR, Authorized DRX Parameters for NB-IoT, Extended Admission Idle Mode DRX Parameters], [Paging Time Window], [Network Support for Interworking without N26], [Access Stratum Connection Establishment NSSAI Inclusive Mode], [Network Slicing Subscription Change Indication], [Operator-Defined Access Category Definition], [List of Equivalent PLMNs], [Improved Coverage Restriction Information], [Supported Network Behavior], [Service Gap Time], [UE Radio Capability ID for PLMN Allocation], [UE Radio Capability ID for PLMN Allocation Removal], [WUS Assistance Information], [Simplified 5G-S-TMSI Configuration], [Connection Release Support], [Paging Cause Indication Support for Voice Services], [Paging Restriction Support], [Reject Paging Request Support]).
[0605] If the Requested NSSAI does not contain an S-NSSAI that maps to an S-NSSAI of the HHPLMN that is subject to network slice-specific authentication and authorization, and the AMF determines that it cannot provide an S-NSSAI in the Authorized NSSAI for the UE within the current UE tracking area, and if it cannot further consider a default S-NSSAI that has not yet been involved in the current UE registration procedure, the AMF shall reject the UE registration and shall include a list of rejected S-NSSAIs in the rejection message, each with an appropriate rejection cause value.
[0606] The authorized NSSAI for the access type for the UE is included in the N2 message carrying the registration accept message. The authorized NSSAI includes only S-NSSAIs that do not require network slice-specific authentication and authorization based on subscription information, and S-NSSAIs for which network slice-specific authentication and authorization have previously been successful regardless of the access type based on the UE context in the AMF. The mapping of reserved NSSAIs is to map each S-NSSAI of the reserved NSSAI for the serving PLMN to the HPLMN S-NSSAI.
[0607] If the UE indicates that it supports network slice-specific authentication and authorization procedures in the UE MM core network function in the registration request, the AMF shall include in the pending NSSAI the S-NSSAI that is mapped to the S-NSSAI of the HPLMN whose subscription information indicates that it is subject to network slice-specific authentication and authorization, as described in clause 4.6.2.4 of TS 24.501
[25] . In such a case, the AMF shall then trigger the network slice-specific authentication and authorization procedures specified in clause 4.2.9.2 in step 25, except for S-NSSAIs for which network slice-specific authentication and authorization has already been initiated for the same S-NSSAI in another access type based on the network policy. The UE shall not attempt to re-register an S-NSSAI included in the list of pending NSSAIs until the network slice-specific authentication and authorization procedures are completed, regardless of the access type.
[0608] If the UE does not indicate that it supports network slice-specific authentication and authorization procedures in the UE 5GMM core network function in the registration request and the request NSSAI includes an S-NSSAI that is mapped to an HPLMN S-NSSAI that complies with network slice-specific authentication and authorization, the AMF includes the S-NSSAI in the request NSSAI in the reject S-NSSAI.
[0609] The following reasons may occur if the S-NSSAI cannot be provided in the Authorized NSSAI:
[0610] -All S-NSSAIs in the requesting NSSAI are subject to network slice-specific authentication and authorization, or
[0611] -If no request NSSAI was provided or none of the S-NSSAIs in the request NSSAI match any of the subscribe S-NSSAIs, all S-NSSAIs marked as default in the subscribe S-NSSAI are subject to network slice-specific authentication and authorization.
[0612] The AMF shall provide an empty Authorization NSSAI. Upon receiving the empty Authorization NSSAI and the Reserved NSSAI, the UE shall register in the PLMN but shall await the completion of network slice specific authentication and authorization procedures without attempting to use any services offered by the PLMN in any access until the UE receives the Authorization NSSAI, except for, for example, emergency services (see TS 24.501
[25] ).
[0613] The AMF stores the NB-IoT priority obtained in step 14 and associates it with the 5G-S-TMSI assigned to the UE.
[0614] If the registration request message received through 3GPP access does not include any paging restriction information, the AMF shall delete any paging restriction information stored for the UE and stop restricting paging accordingly.
[0615] If the registration request message received through the 3GPP access includes a release request indication.
[0616] The AMF updates the UE context with any received paging restriction information and then implements it in a network-triggered service request procedure as described in section 4.2.3.3.
[0617] The AMF does not establish user plane resources and triggers the AN release procedure as described in section 4.2.6 after the registration procedure is completed.
[0618] The AMF sends a registration accept message to the UE indicating that the registration request is accepted. The 5G-GUTI is included when the AMF assigns a new 5G-GUTI. When receiving a registration request message of type "Initial Registration", "Mobility Registration Update", or "Disaster Roaming Registration" from the UE, the AMF shall include the new 5G-GUTI in the registration accept message. When receiving a registration request message of type "Periodic Registration Update" from the UE, the AMF shall include the new 5G-GUTI in the registration accept message. If the UE is already in RM-REGISTERED state via another access in the same PLMN, the UE shall use the 5G-GUTI received in the registration accept for both registrations. If the 5G-GUTI is not included in the registration accept, the UE shall use the 5G-GUTI assigned to the existing registration for the new registration as well. If the AMF assigns a new registration area, the AMF shall send the registration area to the UE via the registration accept message. For disaster roaming registration, the AMF allocates a registration area limited to the area with disaster conditions as specified in clause 5.40 of TS 23.501 [2]. If no registration area is included in the registration accept message, the UE shall consider the old registration area as valid. If mobility restrictions apply for the UE and the registration type is not emergency registration, the mobility restrictions are included. The AMF indicates the established PDU session in the PDU session state to the UE. The UE locally removes any internal resources related to the PDU session that are not marked as established in the received PDU session state. If the AMF invokes the Nsmf_PDUSession_UpdateSMContext procedure for UP activation of the PDU session in step 18 and receives a rejection from the SMF, the AMF indicates to the UE the PDU session ID and the reason why the user plane resources were not activated. When a UE is connected to two AMFs belonging to different PLMNs via 3GPP access and non-3GPP access, the UE locally removes any internal resources related to PDU sessions of the current PLMN that are not marked as established in the received PDU session status.If PDU session state information is present in the registration request, the AMF shall indicate the PDU session state to the UE.
[0619] If the RAT type is NB-IoT and the network is configured to use the control plane relocation indication procedure, the AMF shall include in the registration accept message the simplified 5G-S-TMSI configuration that a UE using control plane CIoT 5GS optimization shall use to create a simplified 5G-S-TMSI (see clause 5.31.4.3 of TS 23.501 [2]).
[0620] The authorized NSSAIs provided in the registration authorization are valid in the registration area and apply to all PLMNs with tracking areas included in the registration area. The mapping of authorized NSSAIs is to map each S-NSSAI of the authorized NSSAIs to the HPLMN S-NSSAI. The mapping of configuration NSSAIs is to map each S-NSSAI of the configuration NSSAIs for the serving PLMN to the HPLMN S-NSSAI.
[0621] If the UE indicates that it supports subscription-based restrictions on concurrent registration of network slice functions, the AMF shall include, if available, the NSSRG information defined in clause 5.15.12 of TS 23.501 [2].
[0622] If the UE does not indicate that it supports subscription-based restrictions on concurrent registrations of network slicing functions, the subscription information for the UE includes SRG information, and the AMF has provided a configuration NSSAI to the UE, the configuration NSSAI shall include the S-NSSAI in accordance with clause 5.15.12 of TS 23.501 [2].
[0623] The AMF shall include in the registration accept message the LADN information for the list of LADNs, as described in clause 5.6.5 of TS 23.501 [2], that are available within the registration area determined by the AMF for the UE. The AMF may include operator-defined access category definitions, as described in TS 24.501
[25] , to allow the UE to determine the applicable operator-specific access category definitions.
[0624] If the UE includes the MICO mode in the registration request, the AMF responds with a registration accept message indicating whether the MICO mode should be used. If the MICO mode is allowed for the UE, the AMF may include an active time value and / or a strict periodic registration timer indication in the registration accept message. The AMF determines the periodic registration update timer value, the active time value, and the strict periodic registration timer indication based on local configuration, expected UE behavior if available, UE indicated preferences, UE capabilities, UE subscription information, and network policies, or any combination thereof, to enable UE power saving, as described in clause 5.31.7 of TS 23.501 [2]. If the UE indicates the UE capability of the strict periodic registration timer indication in the registration request message as described in step 1, the AMF determines to apply the strict periodic registration timer indication to the UE. If the AMF provides the UE with a periodic registration update timer value together with the strict periodic registration timer indication, the UE and the AMF start the periodic registration update timer after this step as described in clause 5.31.7.5 of TS 23.501 [2].
[0625] In case of registration via 3GPP access, the AMF sets the support indication for IMS voice in PS sessions as described in clause 5.16.3.2 of TS 23.501 [2]. To set the support indication for IMS voice in PS sessions, the AMF may need to perform the UE capability match request procedure in clause 4.2.8a to check the compatibility of the radio capabilities of the UE and NG-RAN for IMS voice in PS. If the AMF does not receive the voice support match indicator from the NG-RAN in time, based on the implementation, the AMF may set the support indication for IMS voice in PS sessions and update it at a later stage.
[0626] During registration via 3GPP access, if the AMF obtains or determines the target NSSAI and the corresponding RFSP index according to local configuration to enable the NG-RAN to redirect the UE to a cell supporting a network slice that is not available in the current TA as described in clause 5.3.4.3.3 of TS23.501 [2], the AMF provides the target NSSAI and the corresponding RFSP index to the NG-RAN.
[0627] In case of registration via non-3GPP access, the AMF sets the IMS voice support indication in the PS session as described in clause 5.16.3.2a of TS 23.501 [2].
[0628] The emergency service support indicator informs the UE that emergency services are supported, i.e., the UE is able to request a PDU session for emergency services. If the AMF receives "MPS Priority" from the UDM as part of the access and mobility subscription data based on operator policy, the "MPS Priority" is included in the registration accept message to the UE to inform the UE whether the configuration of Access Identity 1 is valid in the selected PLMN, as specified in TS 24.501
[25] . If the AMF receives "MCX Priority" from the UDM as part of the access and mobility subscription data based on operator policy and the UE subscription to the MCX service, the "MCX Priority" is included in the registration accept message to the UE to inform the UE whether the configuration of Access Identity 2 is valid in the selected PLMN, as specified in TS 24.501
[25] . The acknowledged DRX parameters are defined in clause 5.4.5 of TS 23.501 [2]. If the UE included the requested DRX parameters for NB-IoT in the registration request message, the AMF includes the acknowledged DRX parameters for NB-IoT. The AMF configures network support for interworking without N26 parameters as described in clause 5.17.2.3.1 of TS 23.501 [2]. If the AMF approves the use of extended idle mode DRX, the AMF includes the extended idle mode DRX parameters and paging time window as described in clause 5.31.7.2 of TS 23.501 [2].
[0629] A network slicing subscription change indication is included if the UDM is intended to indicate to the UE that a subscription has changed. If the AMF includes a network slicing subscription change indication, the UE shall locally clear all network slicing configurations for all PLMNs and, if applicable, update the configuration for the current PLMN based on any information received.
[0630] As specified in clause 5.15.9 of TS 23.501 [2], the access stratum connection establishment NSSAI inclusion mode is included to instruct the UE which NSSAI, if any, to include in the access stratum connection establishment. The AMF may set the value to the modes of operation a, b, and c defined in clause 5.15.9 of TS 23.501 [2] for 3GPP access only if it indicates that the inclusion of the NSSAI in the RRC connection establishment grant is allowed.
[0631] For a UE registered in a PLMN, the AMF may provide a list of equivalent PLMNs, which shall be processed as specified in TS 24.501
[25] . For a UE registered in an SNPN, the AMF shall not provide a list of equivalent PLMNs to the UE.
[0632] If the UE included support for restricting the use of enhanced coverage in step 1, the AMF sends the enhanced coverage restriction information to the NG-RAN in the N2 message. The AMF also sends the enhanced coverage restriction information to the UE in the registration accept message.
[0633] If the UE receives the enhanced coverage restriction information in the registration accept message, the UE shall store this information and shall use the value of the enhanced coverage restriction information to determine whether to use the enhanced coverage feature.
[0634] If the UE and the AMF have negotiated to enable the MICO mode and the AMF uses an extended connection timer, the AMF provides the NG-RAN with an extended connection time value in this step (see clause 5.31.7.3 of TS 23.501 [2]). The extended connection time value indicates the minimum time that the RAN should keep the UE in RRC-CONNECTED state regardless of inactivity.
[0635] If the UE includes a preferred network behavior in the UE registration request, the AMF indicates the CIoT 5GS optimizations that it supports and approves in the supported network behavior information (see clause 5.31.2 of TS23.501 [2]).
[0636] The AMF may steer the UE from 5GC by rejecting the registration request. Before steering the UE from 5GC, the AMF should take into account the desired support network behavior (see clause 5.31.2 of TS 23.501 [2]) and the availability of EPC for the UE.
[0637] If the AMF authorizes the MICO mode and is aware that there may be mobile terminated data or signaling pending, the AMF shall maintain the N2 connection for at least the extended connection time as described in clause 5.31.7.3 of TS 23.501 [2] and provide the extended connection time value to the RAN.
[0638] The AMF includes the service gap time if it is present in the subscription information (steps 14a-c) or if the service gap time is updated by a subscriber data update notification to AMF procedure (see section 4.5.1) and the UE indicates UE service gap control capability.
[0639] If the UE receives a service gap time in the registration accept message, the UE shall store this parameter and apply the service gap control (see clause 5.31.16 of TS 23.501 [2]).
[0640] If the network supports WUS grouping (see TS 23.501 [2]), the AMF shall send WUS assistance information to the UE. If the UE provided UE paging availability information in step 1, the AMF shall take it into account when determining the WUS assistance information.
[0641] If the UE and AMF support RACS as defined in clause 5.4.4.1a of TS 23.501 [2], and the AMF needs to configure the UE with a UE radio capability ID, and the AMF already has a UE radio capability other than the NB-IoT radio capability for the UE, the AMF may provide the UE with the UE radio capability ID for the UE radio capability, which the UMF returns to the AMF in a Nucmf_assign service operation for this UE. Alternatively, if the UE and AMF support RACS, the AMF may provide an indication to the UE to delete any PLMN-assigned UE radio capability IDs in this PLMN (see clause 5.4.4.1a of TS 23.501 [2]).
[0642] If the UE is "CAG supported" and the AMF needs to update the UE's CAG information, the AMF may include the CAG information in the registration accept message as part of the mobility restriction.
[0643] If the UE indicates support for paging cause indication for voice service capability in the registration request message, and if the network supports and intends to apply paging cause indication for voice service capability for the UE, the AMF includes an indication that the UE supports paging cause indication for voice service capability in the N2 message carrying the registration accept message.
[0644] If the multi-USIM UE indicated support for one or more multi-USIM-specific features in the UE 5GMM core network capabilities in step 1, the AMF shall indicate to the multi-USIM UE whether the corresponding one or more multi-USIM-specific features described in clause 5.38 of TS 23.501 [2] are supported based on the network capabilities and network preferences (i.e., based on local network policies) by providing one or more of connection release support, paging cause indication for voice service support, paging restriction support, and reject paging request support indication. If the multi-USIM UE indicated support for paging cause indication for voice service capability, an AMF supporting paging cause indication for voice service shall include in the N2 message an indication that the UE supports paging cause indication for voice service capability. The AMF shall simply indicate paging restriction support together with either connection release support or reject paging request support. The UE shall simply use the multi-USIM-specific features that the AMF indicated as supported.
[0645] 21b. [Optional] The new AMF performs UE policy association establishment as defined in clause 4.16.11. For emergency registration, this step is skipped.
[0646] The new AMF sends a request to create an Npcf_UEPolicyControl to the PCF. The PCF sends a request to create an Npcf_UEPolicyControl to the new AMF.
[0647] The PCF triggers the UE configuration update procedure as defined in clause 4.2.4.3.
[0648] 22. [Conditional] UE to new AMF: Registration complete().
[0649] In step 21, after receiving the [Configuration NSSAI for Serving PLMN], [Configuration NSSAI Mapping], [NSSRG Information] and any of the network slicing subscription change indication or CAG information, if the UE has successfully updated itself, the UE sends a registration complete message to the AMF.
[0650] The UE sends a registration complete message to the AMF to inform it whether a new 5G-GUTI has been assigned.
[0651] If a new 5G-GUTI is assigned, the UE passes the new 5G-GUTI to the lower layer of that 3GPP access when the lower layer (either 3GPP access or non-3GPP access) indicates to the RM layer of the UE that the registration complete message has been successfully transferred across the air interface.
[0652] NOTE 14: The above is required because the NG-RAN may use the RRC inactive state and part of the 5G-GUTI is used to calculate paging frames (see TS38.304
[44] and TS36.304
[43] ). It is assumed that the registration completion is reliably signaled to the AMF after the 5G-AN acknowledges its reception to the UE.
[0653] If the list of PDU sessions to be activated is not included in the registration request and the registration procedure was not started in the CM-CONNECTED state, the AMF shall release the signaling connection with the UE according to clause 4.2.6.
[0654] If a subsequent request is included in the registration request, the AMF should not release the signaling connection after the registration procedure is completed.
[0655] If the AMF is aware that any signaling is pending in the AMF or between the UE and the 5GC, the AMF should not release the signaling connection immediately after the registration procedure is completed.
[0656] If the PLMN-assigned UE radio capability ID is included in step 21, the AMF stores the PLMN-assigned UE radio capability ID in the UE context when receiving the registration complete message.
[0657] If the UE receives a PLMN-assigned UE radio capability ID deletion indication in step 21, the UE shall delete the PLMN-assigned UE radio capability ID for this PLMN.
[0658] 23. [Conditional] AMF to UDM: If the access and mobility subscription data provided by the UDM to the AMF in 14b includes steering of roaming information with an indication that the UDM requests the UE to acknowledge receipt of this information, the AMF provides the UE response to the UDM using Nudm_SDM_Info. For more information on handling steering of roaming information, see TS 23.122
[22] .
[0659] 23a. For registration via 3GPP access, if the AMF does not release the signaling connection, the AMF sends RRC inactive support information to the NG-RAN.
[0660] For registration via non-3GPP access, if the UE is also in a CM-CONNECTED state in 3GPP access, the AMF sends RRC inactive assistance information to the NG-RAN.
[0661] The AMF also uses the Nudm_SDM_Info service operation to provide a response to the UDM that the UE has received and acted upon the CAG information or network slicing subscription change indication (see steps 21 and 22).
[0662] 24. [Conditional] From AMF to UDM: After step 14a, in parallel with any of the preceding steps, the AMF shall send the "Homogeneous support for IMS voice in PS sessions" indication to the UDM using Nudm_UECM_Update.
[0663] - if the AMF has evaluated the support of IMS voice in PS sessions (see clause 5.16.3.2 of TS 23.501 [2]), and
[0664] - if the AMF determines that it needs to update its homogeneous support for IMS voice in PS sessions (see clause 5.16.3.3 of TS 23.501 [2]).
[0665] 25. [Conditional] If the UE indicates that it supports network slice-specific authentication and authorization procedures in the UE MM Core Network Function in the Registration Request and any S-NSSAI in the HPLMN is subject to network slice-specific authentication and authorization, the related procedures are performed in this step (see Section 4.2.9.1). Once the network slice-specific authentication and authorization procedures are completed for all S-NSSAIs, the AMF shall trigger a UE Configuration Update procedure to convey the allowed NSSAIs, including the S-NSSAIs for which the network slice-specific authentication and authorization were successful, and shall include any rejected NSSAIs with an appropriate rejection cause value.
[0666] If the tracking area of the registration area was previously assigned as an unauthorized area with pending network slice-specific authentication and authorization, the AMF shall remove the mobility restriction.
[0667] The AMF stores an indication that the network slice-specific authentication and authorization is successful in the UE context for any S-NSSAI of the HPLMN that is subject to the network slice-specific authentication and authorization.
[0668] If, upon completing the network slice specific authentication and authorization procedures, the AMF determines that it cannot provide an S-NSSAI in the authorized NSSAI for a UE that has already been successfully authenticated and authorized by the PLMN, and if no default S-NSSAI can be further considered, the AMF shall perform the network-initiated deregistration procedure described in clause 4.2.2.3.3 and shall include a list of rejected S-NSSAIs in the explicit deregistration request message, each with an appropriate rejection cause value.
[0669] Mobility related event notifications to NF consumers are triggered at the end of this procedure in the cases described in clause 4.15.4.
[0670] <4.2.2.2.3 Registration by AMF reassignment> For example, if the initial AMF is not an appropriate AMF to serve the UE, when the AMF receives the registration request, the AMF may need to reroute the registration request to another AMF. The registration by AMF reassignment procedure described in Figure 4.2.2.2.3-1 is used to reroute the UE's NAS messages to the target AMF during the registration procedure.
[0671] Figure 4.2.2.2.3-1: Registration via AMF reassignment procedure (see Figure 16).
[0672] The initial AMF and target AMF register their functions in the NRF.
[0673] 1. Steps 1 and 2 in Figure 4.2.2.2.2-1 occur, and the (R)AN sends a registration request message to the initial AMF within the initial UE message.
[0674] 2. If the AMF requires SUPI and / or UE subscription information to decide whether to reroute the registration request, or if the registration request was not sent with integrity protection or integrity protection is indicated as failed, the AMF performs steps 4 to 9a or 9b of Figure 4.2.2.2.2-1.
[0675] 3a. [Conditional] If the initial AMF requires the UE's subscription information to decide whether to reroute the registration request and the UE's slice selection subscription information was not provided by the old AMF, the AMF selects a UDM as described in clause 6.3.8 of TS 23.501 [2].
[0676] 3b. Initial AMF to UDM: Nudm_SDM_Get(SUPI, slice selection subscription data).
[0677] The initial AMF requests the UE's slice selection subscription data from the UDM by calling the Nudm_SDM_Get (see section 5.2.3.3.1) service operation. The UDM can obtain this information from the UDR via Nudr_DM_Query(SUPI, slice selection subscription data).
[0678] 3c. UDM to initial AMF: Response to Nudm_SDM_Get. AMF obtains slice selection subscription data including subscribe S-NSSAI.
[0679] The UDM responds to the initial AMF with slice selection data.
[0680] Editor's note: In the case of disaster roaming registration, how the UDM provides the AMF with applicable slice selection subscription data for disaster roaming services is FFS (requires further consideration).
[0681] 4a. [Conditional] From Initial AMF to NSSF: Nnssf_NSSelection_Get(Requested NSSAI, [Mapping of Requested NSSAI], Subscribed S-NSSAI with default S-NSSAI indication, [NSSRG Information] TAI, Allowed NSSAI for other access types (if any), [Mapping of Allowed NSSAI], PLMN ID of SUPI).
[0682] If slice selection is required (see clause 5.15.5.2.1 of TS 23.501 [2]) and, for example, the initial AMF cannot provide service for all S-NSSAIs from the requested NSSAI that are allowed by the subscription information, the initial AMF invokes the Nnssf_NSSelection_Get service operation from the NSSF by including the requested NSSAI, optionally the mapping of the requested NSSAI, the subscribed S-NSSAI with the default S-NSSAI indication, the [NSSRG Information], the allowed NSSAIs for other access types (if any), the mapping of the allowed NSSAIs, the PLMN ID of the SUPI, and the TAI of the UE.
[0683] If available, the AMF shall include NSSRG information regarding the S-NSSAI of the HPLMN as defined in clause 5.15.12 of TS 23.501 [2], including information on whether the UE has indicated support for subscription-based restrictions on concurrent network slice registrations and whether the UDM has indicated that it will provide all subscribed S-NSSAIs to non-supporting UEs.
[0684] 4b. [Conditional] From NSSF to Initial AMF: Response to Nnssf_NSSelection_Get (List of AMF sets or AMF addresses, Allowed NSSAI for first access type, [Allowed NSSAI mapping], [Allowed NSSAI for second access type], [Allowed NSSAI mapping], [NSI ID], [NRF], [List of Rejections (S-NSSAI, Cause value)], [Configuration NSSAI for Serving PLMN], [Configuration NSSAI mapping]).
[0685] The NSSF performs the steps specified in point (B) in clause 5.15.5.2.1 of TS 23.501 [2]. The NSSF returns to the initial AMF the authorized NSSAIs for the first access type, optionally the mapping of the authorized NSSAIs, the authorized NSSAIs for the second access type (if any), optionally the mapping of the authorized NSSAIs, and the target AMF set or a list of candidate AMFs based on the configuration. The NSSF may return the NSI ID associated with the network slice instance corresponding to the specific S-NSSAI. The NSSF may return the NRF used to select an NF / service within the selected network slice instance. The NSSF may also return information about the rejection cause for the S-NSSAIs not included in the authorized NSSAIs. The NSSF may return the configured NSSAIs for the serving PLMN and, optionally, the associated mapping of the configured NSSAIs. If NSSRG information was not included in the request, the NSSF will provide a configuration NSSAI as described in Section 5.15.12 of TS 23.501 [2].
[0686] NOTE 1: The NRF returned by the NSSF, if any, belongs to any level of NRF (see clause 6.2.6 of TS 23.501 [2]) depending on the operator's deployment decision.
[0687] 5. [Conditional] From initial AMF to old AMF: Namf_Communication_RegistrationStatusUpdate (cause of failure).
[0688] If another AMF is selected, the initial AMF sends a rejection indication to the old AMF indicating that the UE registration procedure was not fully completed in the initial AMF. The old AMF continues as if Namf_Communication_UEContextTransfer had never been received.
[0689] 6a. [Conditional] Initial AMF to NRF: Nnrf_NFDiscovery_Request(NF Type, AMF Set).
[0690] If the initial AMF does not have the target AMF address stored locally, and if the initial AMF intends to use direct reroute to the target AMF or if reroute via an (NG-R)AN message needs to include an AMF address, the initial AMF invokes the Nnrf_NFDiscovery_Request service operation from the NRF to find a suitable target AMF that has the NF capabilities required to serve the UE. The NF type is set to AMF. The AMF set is included in the Nnrf_NFDiscovery_Request.
[0691] 6b. [Conditional] NRF to AMF: Response to Nnrf_NFDiscovery_Request ((AMF pointer, AMF address, plus a list of additional selection rules and NF capabilities)).
[0692] The NRF responds with a list of potential target AMFs. The NRF may also provide details of the services offered by the candidate AMFs, along with notification endpoints for each type of notification service that the selected AMF has registered with the NRF, if available. Alternatively, the NRF provides a list of potential target AMFs and their capabilities, and optionally additional selection rules. Based on information about the registered NFs and the required capabilities, the target AMF is selected by the initial AMF.
[0693] If a security association is established between the UE and the initial AMF to avoid registration failure, the initial AMF shall forward the NAS message to the target AMF by performing step 7(A).
[0694] Note 2: When the initial AMF forwards a NAS message to the target AMF via the (R)AN, the security context in the initial AMF is not forwarded to the target AMF. In this case, the security contexts in the UE and the target AMF are not synchronized, so the UE rejects the NAS message sent from the target AMF.
[0695] NOTE 3: When AMF reallocation is performed by step 7(A), network slice isolation cannot be fully maintained.
[0696] If the initial AMF is not part of the target AMF set and is unable to obtain a list of candidate AMFs by querying an NRF that has the target AMF set (for example, if an NRF pre-configured locally on the AMF does not provide the required information and a query to an appropriate NRF provided by the NSSF is not successful, or if the initial AMF has knowledge that the initial AMF is not authorized as a serving AMF), the initial AMF shall perform step 7(B) and forward the NAS message to the target AMF via the (R)AN, unless a security association has been established between the UE and the initial AMF, and the authorized NSSAI and AMF set are included to enable the (R)AN to select the target AMF, as described in clause 6.3.5 of TS 23.501 [2].
[0697] 7(A). If, based on local policy and subscription information, the initial AMF decides to forward the NAS message directly to the target AMF, the initial AMF invokes Namf_Communication_N1MessageNotify to the target AMF to convey the rerouted NAS message. The Namf_Communication_N1MessageNotify service operation includes AN access information (e.g., information that enables the (R)AN to identify the N2 termination point, the CAG identifier of the CAG cell) and a full registration request message, as well as the UE's SUPI, an information element indicating that the UE is verified, and, if available, the MM context. If the initial AMF obtained information from the NSSF as described in step 4b, that information, excluding the AMF set or the list of AMF addresses, is included. The target AMF then updates the (R)AN with the new updated N2 termination point for the UE in a first message from the target AMF to the RAN in step 8.
[0698] 7(B). If, based on local policy and subscription information, the initial AMF decides to forward the NAS message to the target AMF via the (R)AN, unless the target AMF is identified in the list of candidate AMFs returned by the NSSF, the initial AMF sends a reroute NAS message to the (R)AN (step 7a). The reroute NAS message includes information about the target AMF and the full registration request message. If the old AMF successfully verified the integrity of the registration request message or the initial AMF received an MM context or a SUPUI without an MM context from the old AMF in step 2 when the authentication procedure was successful in step 2, the initial AMF includes the SUPUI and an information element indicating that the UE has been verified if the initial AMF obtained the information as described in step 4b. If the initial AMF obtained the information as described in step 4b, the information is included. The (R)AN sends an initial UE message to the target AMF (step 7b) indicating reroute by slicing, including the information from step 4b provided by the NSSF. The (R)AN also includes the SUPI, an information element indicating that the UE is verified, and other received information elements in the reroute NAS message for the initial NAS message.
[0699] 8. If the target AMF receives the SUPI and an information element indicating that the UE is verified, the target AMF sends the SUPI and an information element indicating that the UE is verified to the old AMF in a Namf_Communication_UEContextTransfer message. Upon receiving the Namf_Communication_UEContextTransfer message with the SUPI and an information element indicating that the UE is verified, the old AMF sends the UE context to the target AMF in a Namf_Communication_UEContextTransfer response message without performing integrity verification. If the target AMF does not receive the SUPI and an information element indicating that the UE is verified, after receiving the registration request message sent in step 7(A)a or step 7(B)b, the target AMF continues the registration procedure from steps 4 to 22 in Figure 4.2.2.2.2-1, including the UE context obtained from the old AMF (the target AMF corresponds to the new AMF). If the 5G security context is obtained from the initial AMF, the target AMF continues to use that 5G security context instead of the 5G security context obtained from the old AMF. If the initial AMF decides to forward the NAS message to the target AMF (step 7(A)), the first message (initial context setup request or downlink NAS transport) from the target AMF to the (R)AN includes the AMF name of the initial AMF and the target AMF UE NGAP ID.
[0700] As will be appreciated by those skilled in the art, the present disclosure may be embodied as a method and a system, and thus may take the form of an entirely hardware embodiment, a software embodiment, or an embodiment combining software and hardware aspects.
[0701] It will be understood that each block of the block diagrams can be implemented by computer program instructions. The computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus to create a machine, such that the instructions, executed by the processor of the computer or other programmable data processing apparatus, create means for implementing the function / acts specified in the block or blocks of the flowcharts and / or block diagrams. A general-purpose processor can be a microprocessor, but alternatively, the processor can be any conventional processor, controller, microcontroller, or state machine. A processor can also be implemented as a combination of computing devices, e.g., multiple microprocessors, one or more microprocessors, or any other such configuration.
[0702] The methods or algorithms described in connection with the examples disclosed herein may be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. The software module may reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. The storage medium may be coupled to the processor such that the processor can read information from, and write information to, the storage medium. Alternatively, the storage medium may be integrated into the processor. The processor and the storage medium may reside in an ASIC.
[0703] The previous description of examples of the present disclosure is provided to enable any person skilled in the art to make or use the disclosure. Various modifications to the examples will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other examples without departing from the spirit or scope of the present disclosure. Thus, the present disclosure is not intended to be limited to the examples set forth herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0704] Although the present disclosure has been shown and described in detail with reference to exemplary embodiments thereof, the present disclosure is not limited to such embodiments. It will be understood by those skilled in the art that various changes in form and details may be made without departing from the spirit and scope of the present disclosure as defined herein. For example, the above embodiments are not limited to 5GS, and the embodiments may also be applied to communication systems other than 5GS (e.g., 6G systems, Beyond 5G systems).
[0705] All or part of the exemplary aspects of the above disclosure may be described as, but are not limited to, the following supplementary notes.
[0706] Clause 1. A method of a non-geographically selective Access and Mobility Management Function (AMF) device, said method comprising: receiving a Namf_Communication_UEContextTransfer message from an AMF device of geographical selection, the Namf_Communication_UEContextTransfer message includes a registration request message and information indicating an access type set to 3rd Generation Partnership Project (3GPP) access; and if the Namf_Communication_UEContextTransfer message includes the information, performing integrity checking on the Registration Request message based on a Non-Access-Stratum (NAS) security context for non-3GPP access; A method comprising:
[0707] Supplementary Note 2. The method of Supplementary Note 1, further comprising sending a Namf_Communication_UEContextTransfer response message to the geographically selected AMF if the non-geographically selected AMF device successfully performs the integrity check.
[0708] Clause 3. A method of a geographically selective Access and Mobility Management Function (AMF) device, said method comprising: receiving a registration request message; the registration request message includes information indicating that the registration request message is integrity protected based on a Non-Access-Stratum (NAS) security context for non-3rd Generation Partnership Project (3GPP) access; and sending a Namf_Communication_UEContextTransfer message to a non-geographically selected AMF device; the Namf_Communication_UEContextTransfer message includes the information; and A method comprising:
[0709] Clause 4. A method of a geographically selective Access and Mobility Management Function (AMF) device, said method comprising: receiving a registration request message; the registration request message includes first information indicating that the registration request message is integrity protected based on a Non-Access-Stratum (NAS) security context for non-3GPP access, and second information indicating whether registration over 3GPP access or the non-3GPP access is preferred; sending a Namf_Communication_UEContextTransfer message to a non-geographically selected AMF device; receiving a Namf_Communication_UEContextTransfer response message from the non-geographically selected AMF device; The Namf_Communication_UEContextTransfer response message includes third information indicating that the User Equipment (UE) context for the non-3GPP access cannot be transferred or that a Non-3GPP InterWorking Function (N3IWF) can only establish a connection with the non-geographically selected AMF device; and sending a registration accept message if the second information indicates that the registration via the 3GPP access is preferred; The registration approval message includes fourth information indicating that the AMF device of the geographical selection cannot simultaneously register the UE for the 3GPP access and the non-3GPP access; and sending a registration reject message if the second information indicates that the registration via the non-3GPP access is preferred; the registration rejection message includes the fourth information; and A method comprising:
[0710] Supplementary Note 5. A method of user equipment (UE), the method comprising: Initiating the registration procedure; sending a registration request message; the registration request message includes first information indicating that the registration request message is integrity protected based on a Non-Access-Stratum (NAS) security context for non-3rd Generation Partnership Project (3GPP) access; and A method comprising:
[0711] Supplementary Note 6. The method of Supplementary Note 5, wherein the registration request message includes second information indicating whether registration over 3GPP access or registration over the non-3GPP access is preferred.
[0712] Appendix 7. receiving a registration accept message if the second information indicates that the registration via the 3GPP access is preferred; The registration acknowledgement message includes third information indicating that an AMF device of a geographical selection cannot simultaneously register a UE for the 3GPP access and the non-3GPP access; and receiving a registration reject message if the second information indicates that the registration via the non-3GPP access is preferred; the registration rejection message includes third information; and 7. The method of claim 6, further comprising:
[0713] Clause 8. A method of a non-geographically selective Access and Mobility Management Function (AMF) device, said method comprising: receiving a Namf_Communication_UEContextTransfer message from an AMF device of geographical selection, the Namf_Communication_UEContextTransfer message includes a registration request message and information indicating an access type set to 3rd Generation Partnership Project (3GPP) access; and if the Namf_Communication_UEContextTransfer message includes the information, performing integrity checking on the Registration Request message based on a Non-Access-Stratum (NAS) security context for non-3GPP access; When the non-geographically selected AMF device successfully performs the integrity check and determines that a Non-3GPP InterWorking Function (N3IWF) is connected only to the non-geographically selected AMF device, sending a Namf_Communication_UEContextTransfer response message to the non-geographically selected AMF device; The Namf_Communication_UEContextTransfer response message includes information indicating that the User Equipment (UE) context for the non-3GPP access cannot be transferred or that the N3IWF can only establish a connection with the non-geographically selected AMF device; and A method comprising:
[0714] Clause 9. A non-geographically selected Access and Mobility Management Function (AMF) device, said non-geographically selected AMF device comprising: A means for receiving a Namf_Communication_UEContextTransfer message from an AMF device of a geographical selection, comprising: The Namf_Communication_UEContextTransfer message includes a registration request message and information indicating an access type set to 3rd Generation Partnership Project (3GPP) access; means for performing integrity check on the Registration Request message based on a Non-Access-Stratum (NAS) security context for non-3GPP access if the Namf_Communication_UEContextTransfer message includes the information; A non-geographically selective AMF device comprising:
[0715] Supplementary Note 10. A non-geographically selected AMF device as described in Supplementary Note 9, further comprising means for sending a Namf_Communication_UEContextTransfer response message to the geographically selected AMF when the non-geographically selected AMF device successfully performs the integrity check.
[0716] Clause 11. An Access and Mobility Management Function (AMF) device of geographical selection, said AMF device comprising: a means for receiving a registration request message, the registration request message includes information indicating that the registration request message...
Claims
1. means for receiving a message from another communication device, the message including information regarding an access type and a registration request message; means for using a Non Access Stratum (NAS) security context to perform integrity checking on the registration request message; The NAS security context corresponds to information about the access type. Communication equipment.
2. The communication device is an Access and Mobility Management Function The communication device according to claim 1 .
3. The message is a Namf_Communication_UEContextTransfer message.
3. The communication device according to claim 1 or 2.
4. means for communicating with a second communication device; means for transmitting a message to the second communication device, the message including information regarding an access type and a registration request message; The message causes the second communication device to use a Non Access Stratum (NAS) security context corresponding to information about the access type to perform an integrity check on the registration request message. A first communication device.
5. The first communication device is an Access and Mobility Management Function The first communication device according to claim 4 .
6. The message is a Namf_Communication_UEContextTransfer message.
6. The first communication device according to claim 4 or 5.
7. receiving a message from another communication device, the message including information regarding an access type and a registration request message; using a Non Access Stratum (NAS) security context to perform integrity checking on the registration request message; The NAS security context corresponds to information about the access type. Method of communication device.
8. communicating with a second communication device; sending a message to the second communication device including information regarding an access type and a registration request message; The message causes the second communication device to use a Non Access Stratum (NAS) security context corresponding to information about the access type to perform an integrity check on the registration request message. A method of a first communication device.