Network slice-specific authentication and authorization
The method and apparatus for network slice-specific authentication and authorization in 3GPP 5G address roaming issues and procedure conflicts by managing registration messages with specific IEs, ensuring accurate authentication and preventing incorrect PDU session releases, thereby improving user experience and system stability.
Patent Information
- Application Number
- JP2022559978
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-03-30
- Filing Date
- 2021-03-29
- Publication Date
- 2025-08-13
- Estimated Expiration
- 2041-03-29
AI Technical Summary
Existing 3GPP 5G network slice-specific authentication and authorization (NSSAA) procedures do not adequately handle roaming scenarios, leading to incorrect PDU session releases and undefined behaviors in case of procedure conflicts, abnormal cases, and service request prohibitions, which disrupt user experience.
A method and apparatus for network slice-specific authentication and authorization that includes transmitting and receiving registration request and accept messages with specific information elements (IEs) to manage periodic or mobility registration updates, ensuring accurate handling of pending NSSAIs and resolving conflicts between authentication and other procedures.
Enables accurate and efficient network slice-specific authentication and authorization in 3GPP 5G, preventing incorrect PDU session releases and clarifying UE behavior in various scenarios, thus enhancing user experience and system stability.
Smart Images

Figure 0007723006000002 
Figure 0007723006000003 
Figure 0007723006000004
Abstract
Description
[Technical Field]
[0001] The present invention relates to a method and apparatus for performing network slice-specific authentication and authorization, and more particularly to a method and apparatus that enable accurate operation for network slice-specific authentication and authorization in 3GPP 5G. [Background technology]
[0002] 4th generation (4 th Since the commercialization of 4G (5th Generation) communication systems, an improved 5th generation (5G) system has been developed to meet the increasing demand for wireless data traffic. th Efforts have been made to develop 5G (Next Generation) or pre-5G communication systems. Therefore, 5G or pre-5G communication systems are also called "Beyond 4G Networks" or "Post-LTE Systems."
[0003] To achieve higher data rates, 5G communication systems are being considered for implementation in higher frequency (mmWave) bands, such as the 60 GHz band. To reduce propagation loss of wireless waveforms and increase transmission distances, technologies such as beamforming, massive multi-input multi-output (massive MIMO), full dimensional MIMO (FD-MIMO), array antennas, analog beamforming, and large scale antennas are being discussed for 5G communication systems.
[0004] In addition, in the 5G communication system, development is underway to improve the system network based on evolved small cells, advanced small cells, cloud Radio Access Network (cloud RAN), ultra-dense networks, device-to-device (D2D) communications, wireless backhaul, moving networks, cooperative communications, CoMP (Coordinated Multi-Points), and receiver-side interference cancellation.
[0005] In 5G systems, hybrid FSK and QAM modulation (FQAM) and sliding window superposition coding (SWSC) are being developed as advanced coding modulation (ACM) techniques, and filter bank multi-carrier (FBMC), non-orthogonal multiple access (NOMA), and sparse code multiple access (SCMA) are being developed as advanced access techniques.
[0006] The following documents are referenced herein: [1] 3GPP® TS 23.501 V16.4.0; [2] 3GPP® TS 23.502 V16.4.0; and [3] 3GPP® TS 24.501 V16.4.0.
[0007] In the 3GPP® 5G system, the following definitions are made (e.g., in [1]): A network slice (NS) is defined as a logical network that provides specific network functions and network characteristics. A network slice instance (NSI) is defined as a set of network function instances and required resources (e.g., compute, storage, and network resources) that form a deployed NS. A network function (NF) is defined as a 3GPP®-adopted or 3GPP®-defined processing function in a network with defined functional operations and 3GPP®-defined interfaces.
[0008] The NS is identified by a single network slice selection assistance information (S-NSSAI).
[0009] Overview of Network Slice-Specific Authentication and Authorization (NSSAA)
[0010] NSSAA was introduced as part of 3GPP Rel-16. This feature allows the network to perform slice-specific authentication and authorization for a set of S-NSSAIs to allow users to access these slices. This procedure is performed after the 5G mobility management (5GMM) authentication procedure and the registration procedure are completed. An overview of this feature is given in [1], while more details are given in [2] and [3]. Important details about the NSSAA procedure are summarized in this section.
[0011] The NSSAA procedure is access independent, i.e., once a slice is successfully authorized, it is considered authorized for both access types (i.e., 3GPP and non-3GPP access types).
[0012] The term "authorized" means that slice-specific authentication / authorization was successful for a particular S-NSSAI, but this does not mean that the S-NSSAI will be used in the UE's current tracking area (TA) via 3GPP access.
[0013] If available to the UE when the UE registers with the network, the UE includes a requested NSSAI (R-NSAI) in the registration request message.
[0014] Below, we explain the network operation specified in [3].
[0015] If the UE indicates support for network slice specific authentication and authorization, and: a) The requested NSSAI Information Element (IE) is: 1) subject to network slice-specific authentication and authorization; and 2) If the network slice-specific authentication and authorization procedure includes only an S-NSSAI for which the S-NSSAI has not been initiated, The Access and Mobility Management Function (AMF) includes the following in the REGISTRATION ACCEPT message:
[0016] 1) An "NSSAA to be performed" indicator in the 5GS Registration Result IE set to indicate whether network slice-specific authentication and authorization procedures are performed by the network; 2) A pending NSSAI containing one or more S-NSSAIs for which network slice-specific authentication and authorization is performed; and 3) The current registration area in the list of "non-allowed tracking areas" in the Service Area List IE; or b) If the requested NSSAI IE contains one or more S-NSSAIs that are subject to network slice specific authentication and authorization, the AMF shall include in the Registration Accept message: 1) An authorized NSSAI that is not subject to network slice-specific authentication and authorization or that includes an S-NSSAI or a mapped S-NSSAI for which network slice-specific authentication and authorization has been successfully performed; and 2) A pending NSSAI, if present, containing one or more S-NSSAIs for which network slice-specific authentication and authorization is performed.
[0017] If the UE indicates support for network slice specific authentication and authorization and: a) the UE does not include the requested NSSAI in the REGISTRATION REQUEST message, or none of the S-NSSAIs in the requested NSSAI in the REGISTRATION REQUEST message is present in the subscribed S-NSSAI; and b) All S-NSSAIs in subscribed S-NSSAIs are subject to network slice-specific authentication and authorization.
[0018] The AMF includes in the REGISTRATION ACCEPT message: a) An "NSSAA to be performed" indicator in the 5GS Registration Result IE indicating whether network slice-specific authentication and authorization procedures are performed by the network; b) A pending NSSAI containing one or more S-NSSAIs for which network slice-specific authentication and authorization is performed; and c) The current registered area in the list of "non-allowed tracking areas" in the Service Area List IE.
[0019] The NSSAA may be reinstated at any time as provided in Section 5.15.10 of [1].
[0020] This procedure can be invoked at any time for a UE supported by AMF, for example, in the following cases:
[0021] a. The UE is registered with the AMF and one of the S-NSSAIs of the HPLMN that is mapped to the S-NSSAI in the requested NSSAI requests network slice-specific authentication and authorization (see Section 5.15.5.2.1 for details), and if the network slice-specific authentication and authorization of the S-NSSAI is successful, adds it to the NSSAIs allowed by the AMF; or b. The network slice-specific AAA server triggers UE re-authentication and re-authorization of the S-NSSAI; or c. The AMF decides to initiate network slice-specific authentication and authorization procedures for a specific S-NSSAI that was previously authorized based on operator policy or subscription changes.
[0022] In the case of recertification and reauthorization (b. and c. above), the following applies:
[0023] If an S-NSSAI requiring network slice-specific authentication and authorization is included in the allowed NSSAI for each access type, the AMF selects the access type to be used to perform the network slice-specific authentication and authorization procedures based on the network policy.
[0024] If network slice-specific authentication and authorization for some S-NSSAIs in the allowed NSSAIs is not successful, the AMF updates the allowed NSSAIs for each access type to the UE via the UE configuration update procedure.
[0025] If network slice-specific authentication and authorization for all S-NSSAIs in the allowed NSSAIs fails, the AMF performs the network-initiated deregistration procedure described in TS 23.502 [2], clause 4.2.2.3.3, and includes a list of rejected S-NSSAIs in the explicit deregistration request message, each with an appropriate rejection reason value.
[0026] Overview of S-NSSAI IE and its handling during roaming
[0027] The S-NSSAI IE is encoded as shown in FIG.
[0028] If the UE is in the home PLMN (Public Land Mobile Network) (HPLMN), the mapped HPLMN SST (octet 7) and mapped HPLMN SD (octets 8-10) do not apply. In fact, in the HPLMN, these octets correspond to the SST field (octet 3) and the SD field (octets 4-6), respectively.
[0029] On the other hand, when the UE is roaming in a visited PLMN (VPLMN), the UE includes mapped slice information corresponding to the slices in use in the VPLMN. For example, assume that in VPLMN1, the UE has the following S-NSSAI entry in its allowed NSSAIs, as shown in Figure 2:
[0030] The above basically means that the slice [V1-Cars, V1-BMW] being accessed in VPLMN1 corresponds to the slice [H1-Cars, H1-BMW] in HPLMN. Note that the SD field and the mapped HPLMN SD field are optional, as shown in Figure 1.
[0031] The network slice selection assistance information (NSSAI) is a list of single-NSSAIs (S-NSSAIs), and there are different types of NSSAIs, such as requested NSSAIs (with a maximum of 8 entries), allowed NSSAIs (with a maximum of 8 entries), configured NSSAIs (with a maximum of 16 entries), and pending NSSAIs (with a maximum of 8 entries).
[0032] The NSSAI IE is encoded as shown in Figure 3.
[0033] The requested mapped NSSAI is of the type of the encoded mapped NSSAI, as shown in FIG.
[0034] The mapped NSSAI contains a list of mapped S-NSSAI entries, and each mapped S-NSSAI entry is encoded as shown in FIG.
[0035] The requested mapped NSSAI IE is sent in the following roaming cases:
[0036] - The UE moves between visited PLMNs and attempts to transfer protocol data unit (PDU) sessions between these visited PLMNs.
[0037] - The UE has a PDU session established with the source VPLMN.
[0038] The UE knows the mapped HPLMN slice information (i.e., the mapped HPLMN SST and optionally the mapped HPLMN SD) of the PDU session established with the source VPLMN, and - The UE does not have any slice information for the target VPLMN (i.e., no configured or allowed NSSAI).
[0039] As an example to illustrate this, assume that a UE resides in VPLMN1 and has a PDU session with S-NSSAI {V1-Cars, H-Cars}. For simplicity, the value V-Cars corresponds at least to the SST field of Figure 1, but may also include the SD field of Figure 1. Similarly, for simplicity, the value H-Cars corresponds at least to the mapped HPLMN SST field of Figure 1, but may also include the mapped HPLMN SD field of Figure 1.
[0040] When the UE moves from VPLMN1 to a target VPLMN, e.g., VPLMN2, and the UE does not have any slice information for VPLMN2, the UE includes the requested mapped NSSAI IE in the registration request message sent in VPLMN2. Here, if the UE does not have slice information for VPLMN2, the non-access stratum (NAS) message does not include the requested NSSAI IE.
[0041] Assume that a UE in VPLMN1 has two PDU sessions, each associated with one of the following S-NSSAIs:
[0042] -{V1-Cars, H-Cars}; and -{V1-SmartPhone, H-SmartPhone} Further, assume that the UE has the following slice information for potential target VPLMN2:
[0043] -{V2-Cars, H-Cars} When the UE enters the VPLMN2, the UE includes the following IE in the registration request message:
[0044] - Requested NSSAI IE which may contain the entries {V2-Cars, H-Cars}. This IE is sent because the UE has slice information for VPLMN2 and the mapped slice components, i.e. the "H-Cars" value, match the mapped slice components of the existing PDU session.
[0045] -Requested Mapped NSSAI IE which may contain the entry {H-SmartPhone}. This IE may be included because the UE does not have slice information for the mapped slice component of an existing PDU session, i.e. VPLMN2, that matches the value "H-SmartPhone".
[0046] In the above example, the AMF considers both the requested NSSAI IE and the requested mapped NSSAI IE to send the allowed NSSAI IE to the UE in the registration accept message.
[0047] For example, to clarify how slicing works, note that if the UE has {V2-SmartPhone, H-SmartPhone} as slice information for VPLMN2, the UE will only include the requested NSSAI IE in the registration request message because the mapped slice information of the existing PDU session from VPLMN1 matches the mapped slice information of VPLMN2. In this case, the requested mapped NSSAI IE will not be included in the registration request message.
[0048] In summary, it should be understood that in the case of roaming, the UE can send only the Requested NSSAI IE, or the Requested Mapped NSSAI IE, or both the Requested NSSAI IE and the Requested Mapped NSSAI IE in the Registration Request message. The decision of which IEs to include depends on whether the UE has slice information for the target VPLMN and whether there is a match between the mapped components of the S-NSSAI associated with the existing PDU session from the source VPLMN.
[0049] Finally, it is important to note that if the UE receives an allowed NSSAI IE in the Registration Accept message, and: - the entry in the Allowed NSSAI IE does not match the complete S-NSSAI of an existing PDU session, or - the mapped slice information of the entry in the Allowed NSSAI IE (i.e., the mapped HPLMN SST and the optionally mapped HPLMN SD) does not match the mapped slice information of an existing PDU session; In that case, the UE may locally release PDU sessions whose associated S-NSSAI does not match any of the allowed NSSAI IE entries as described above. This behavior is described in [3] as follows:
[0050] For each active PDU session in the UE, if the allowed NSSAI does not contain any of the following: a) An S-NSSAI that matches the S-NSSAI of the PDU session; or b) A mapped S-NSSAI that matches the mapped S-NSSAI of the PDU session; The UE may perform local release of all such PDU sessions except for persistent PDU sessions.
[0051] The above information is presented solely as background information to aid in the understanding of the present invention. No determination is made, and no assertion is made, as to whether any of the above is applicable as prior art with respect to the present invention. Summary of the Invention [Problem to be solved by the invention]
[0052] The present invention has been made in consideration of the above-mentioned conventional technology, and an object of the present invention is to provide a method and apparatus for performing network slice-specific authentication and authorization. [Means for solving the problem]
[0053] In order to achieve the above object, one aspect of the present invention provides a user equipment (UE) method, comprising the steps of: transmitting, by the UE, a registration request message including a registration type information element (IE) indicating a periodic registration update or a mobility registration update to a network entity; The method includes: receiving, by the UE, a registration accept message including pending network slice selection assistance information (NSSAI) from the network entity; and determining, by the UE, based on the registration accept message, to invalidate a previously received allowed NSSAI.
[0054] To achieve the above object, a method by a network entity according to one aspect of the present invention includes the steps of: receiving, by the network entity, a registration request message from a user equipment (UE) including a registration type information element (IE) indicating a periodic registration update or a mobility registration update; and transmitting, by the network entity, a registration accept message to the UE including pending network slice selection assistance information (NSSAI).
[0055] In order to achieve the above object, one aspect of the present invention provides a user equipment (UE) comprising: a transceiver; and at least one processor configured to control the transceiver to transmit a registration request message including a registration type information element (IE) indicating a periodic registration update or a mobility registration update to a network entity, and to receive a registration accept message including a pending network slice-specific authentication and authorization (NSSAI) from the network entity, wherein the at least one processor is further configured to invalidate a previously received allowed NSSAI based on the registration accept message.
[0056] In order to achieve the above object, according to one aspect of the present invention, a network entity includes a transceiver and at least one processor configured to control the transceiver to receive a registration request message from a user equipment (UE) including a registration type information element (IE) indicating a periodic registration update or a mobility registration update, and to transmit a registration accept message to the UE including pending network slice-specific authentication and authorization (NSSAI). [Effects of the Invention]
[0057] According to the present invention, a method and apparatus can be provided that enable accurate operation for network slice-specific authentication and authorization in 3GPP (registered trademark) 5G. [Brief explanation of the drawings]
[0058] [Figure 1] Indicates the S-NSSAI information element. [Figure 2] An example of an S-NSSAI value is shown below. [Figure 3] Indicates the NSSAI information element. [Figure 4] Indicates the mapped NSSAI information element. [Figure 5] Indicates the mapped S-NSSAI content. [Figure 6] FIG. 2 is a block diagram of an exemplary network entity used in one embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0059] An object of an embodiment of the present invention is to at least partially address, solve and / or mitigate at least one of the problems and / or disadvantages associated with the related art, such as at least one of the problems and / or disadvantages described herein above.An object of an embodiment of the present invention is to provide at least one advantage over the related art, such as at least one of the advantages described herein.
[0060] The invention is defined in the independent claims. Advantageous features are defined in the dependent claims.
[0061] Other aspects, advantages, and salient features will become apparent to those skilled in the art from the following detailed description, which, taken in conjunction with the drawings, discloses embodiments of the invention.
[0062] Before describing the modes for the invention below, it is desirable to provide definitions of certain words and phrases used throughout this specification: The terms "include" and "comprise," as well as their derivatives, mean inclusion without limitation. The term "or" is an inclusive term meaning and / or. The phrase "associated with" and its derivatives means include, be included within, interconnect with, contain, be contained within, connect to or with, couple to or with, be communicable with, cooperate with, interleave, juxtapose, be proximate to, be bound to or with, have, have a property of, have a relationship to or with, etc. The term "controller" means any device, system, or portion thereof that controls at least one operation. Such a controller may be implemented in hardware or a combination of hardware with software and / or firmware. It should be noted that the functionality associated with any particular controller may be centralized or distributed, whether locally or remotely.
[0063] Furthermore, various functions described below are implemented or supported by one or more computer programs, each of which is comprised of computer-readable program code and embodied in a computer-readable recording medium. The terms "application" and "program" refer to one or more computer programs, software components, sets of instructions, procedures, functions, objects, classes, instances, associated data, or portions thereof suitable for implementation in suitable computer-readable program code. The phrase "computer-readable program code" includes all types of computer code, including source code, object code, and executable code. The phrase "computer-readable recording medium" includes any type of medium accessible by a computer, such as read-only memory (ROM), random-access memory (RAM), hard disk drive, compact disc (CD), digital video disc (DVD), or any other type of memory. A "non-transitory" computer-readable recording medium excludes wired, wireless, optical, or other communication links that transmit transient electrical or other signals. Non-transitory computer-readable recording media include media that can permanently store data and media that can store data and later be overwritten, such as rewritable optical disks or erasable memory devices.
[0064] Definitions of certain words and phrases are provided throughout this specification, and those of skill in the art should understand that in many, if not most, cases, such definitions apply to prior as well as future uses of the words and phrases so defined.
[0065] For a more complete understanding of the present invention and its advantages, reference is now made to the following description taken in conjunction with the drawings in which like reference characters represent like parts and in which:
[0066] 1-6, discussed below, and the various embodiments used to illustrate the principles of the present invention herein, are for illustrative purposes only and should not be construed as limiting the scope of the invention in any way. Those skilled in the art will understand that the principles of the present invention may be implemented in any suitably configured system or device.
[0067] The following detailed description of embodiments of the present invention, with reference to the drawings, is provided to aid in a comprehensive understanding of the present invention, as defined by the claims. Although the detailed description includes various specific details to aid in understanding, they should be considered as merely exemplary. Accordingly, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope of the present invention.
[0068] The same or similar components are indicated by the same or similar reference numerals, and the same or similar components may be shown in different drawings.
[0069] Detailed descriptions of techniques, structures, configurations, functions, or processes known in the art are omitted for clarity and conciseness, and to avoid obscuring the gist of the present invention.
[0070] The terms and words used in this specification are not limited to their bibliographical or standard meanings, but are used merely to enable a clear and consistent understanding of the invention.
[0071] Throughout the description and claims of this specification, the words "comprise," "include," and "contain," and variations of these words, such as "comprising" and "comprises," mean "including but not limited to" and are not intended to exclude (or exclude) other features, elements, components, integers, steps, processes, operations, functions, properties, attributes, and / or groups thereof.
[0072] Throughout the description and claims of this specification, the singular forms "a," "an," and "the" include the plural forms unless the context clearly dictates otherwise. For example, a reference to an "object" includes a reference to one or more of such objects.
[0073] Throughout the description and claims of this specification, language of the general form "X for Y" (where Y is any action, process, operation, function, activity, or step, and X is a means for performing that action, process, operation, function, activity, or step) includes, but is not necessarily exclusive of, means for which X is particularly adapted, configured, or arranged to perform Y.
[0074] It is to be understood that any feature, element, component, integer, step, process, operation, function, property, attribute, and / or group thereof described or disclosed in connection with a particular aspect, embodiment, example, or claim of the invention is applicable to any other aspect, embodiment, example, or claim described herein, unless separately compatible therewith.
[0075] Embodiments of the present invention provide methods, apparatuses, and systems for performing network slice-specific authentication and authorization. The following embodiments are applicable to 3GPP® 5G and use terminology related to 3GPP® 5G. For example, embodiments of the present invention provide methods, apparatuses, and systems that enable accurate operation for network slice-specific authentication and authorization in 3GPP® 5G. However, those skilled in the art will understand that the techniques disclosed herein are not limited to these examples or 3GPP® 5G, but may be applied to any suitable system or standard, for example, one or more existing and / or future generation wireless communication systems or standards.
[0076] For example, the functionality and other features of various network entities disclosed herein apply to corresponding or equivalent entities or features in other communication systems or standards. Corresponding or equivalent entities or features are considered to be entities or functions that perform the same or similar role, function, operation, or purpose within a network. For example, in the following embodiments, the functionality of the AMF applies to any other suitable type of entity that performs mobility management functions.
[0077] Those skilled in the art will appreciate that the present invention is not limited to the embodiments disclosed herein. The technology disclosed herein is not limited to 3GPP 5G.
[0078] In the embodiments disclosed herein, one or more entities may be replaced by one or more alternative entities that perform equivalent or corresponding functions, processes, or operations.
[0079] In the examples disclosed herein, one or more of the messages may be replaced by one or more alternative messages, signals, or other types of information carriers that communicate equivalent or corresponding information.
[0080] One or more additional elements, entities, and / or messages may be added to the examples disclosed herein.
[0081] In embodiments, one or more non-essential elements, entities, and / or messages may be omitted.
[0082] In one example, the function, process, or operation of a particular entity is, in the alternative, divided between two or more separate entities.
[0083] In one example, the functions, processes, or actions of two or more individual entities may in the alternative be performed by a single entity.
[0084] In one example, information carried by a particular message is in the alternative carried by two or more separate messages.
[0085] Information conveyed by two or more separate messages in one example is conveyed by a single message in the alternative.
[0086] Where possible, alternatives change the order in which operations are performed.
[0087] The transmission of information between network entities is not limited to the particular format, type, and / or order of messages described in connection with the examples disclosed herein.
[0088] Embodiments of the present invention are provided in the form of apparatuses / devices / network entities configured to perform one or more defined network functions and / or methods therefor, and in the form of systems (e.g., networks) including one or more such apparatuses / devices / network entities and / or methods therefor.
[0089] For example, in the following example, the network includes a user equipment (UE) and an access and mobility management function (AMF) entity.
[0090] The 5G core (5GC) AMF receives all connection and session-related information from the UE (N1 / N2), but is only responsible for handling connection and mobility management tasks. All messages related to session management are forwarded to the session management function (SMF) via the N11 standard interface. The AMF acts as an access point to 5GC. The functional description of the AMF is described in 3GPP TS 23.501 V16.3.0, Section 6.2.1.
[0091] From the perspective of the related art, at least the following problems exist:
[0092] ≪1. The NSSAI does not consider the requested mapped NSSAI IE, which may cause the UE to incorrectly release the PDU session, thereby affecting the user experience.≫
[0093] As described above, when the UE is roaming, the UE includes only the requested NSSAI IE, only the requested mapped NSSAI IE, or both the requested NSSAI IE and the requested mapped NSSAI IE in the registration request message.
[0094] Since the current NSSAA procedure does not consider roaming UEs, it is unclear what the AMF does when the requested mapped NSSAI IE is received and how it affects NSSAA.
[0095] With regard to roaming, as described above, if the UE receives an authorized NSSAI IE in a registration accept message in which any S-NSSAI entry in the authorized NSSAI or any mapped S-NSSAI component of an S-NSSAI entry in the authorized NSSAI does not match the mapped S-NSSAI information of an existing PDU session, the UE performs a local release of these PDU sessions. This is an incorrect operation that may lead to unnecessary release of PDU sessions and disruption of the user experience. For example, the authorized NSSAI may not contain an S-NSSAI that matches the slice information of an existing PDU session because the slice is subject to the NSSAI. Therefore, slice information for which a potential match exists may be present in the pending NSSAI IE. Therefore, in this case, considering only the authorized NSSAI IE may lead to premature and incorrect release of the PDU session locally at the UE.
[0096] ≪2. Procedure conflicts are not taken into consideration.≫
[0097] NAS specifications [3] generally consider collisions between different NAS procedures or messages and, in some cases, specify which procedure or message is given priority depending on the collision procedure in question. There are several collision cases that may occur during NSSAA that have not yet been considered, thus leaving UE and network behavior unclear when such cases occur. The following cases are identified as lacking defined behavior:
[0098] Case 1: Conflict between authentication procedures and NSSAA procedures
[0099] As mentioned above, NSSAA may occur after the authentication procedure is completed. However, the same AMF that initiates the NSSAA procedure may also initiate the authentication procedure. This is because resumption of the authentication procedure can occur at any time in connected mode. For example, assume that a UE is registered via one access, e.g., a 3GPP access, and the UE is in connected mode with the network performing NSSAA. Then, the UE registers with the same PLMN or AMF via a second access, e.g., a non-3GPP access. The AMF has a policy of performing authentication after each initial registration. In this case, even if NSSAA is in progress, the AMF initiates the authentication procedure and sends an authentication request message to the UE. The authentication request message may be received at the UE after (or before) the UE receives a network slice-specific authentication command message, but before the UE responds with a network slice-specific authentication complete message. The UE then needs to specify the behavior to be followed in terms of which message should be prioritized. The same question can be asked of the AMF. That is, if the AMF sends a network slice-specific authentication command message to the UE and then sends an authentication request message, and the AMF has not yet received an authentication response but has received a network slice-specific authentication completion message, it is not clear whether the AMF will accept the latter or wait until the authentication procedure is completed.
[0100] Case 2: Conflict between general UE configuration update procedure and NSSAA procedure
[0101] The general UE configuration update procedure can be initiated at any time when the UE is in connected mode. Similarly, the NSSAA procedure can be initiated at any time for a UE that is in connected mode. Therefore, these procedures may collide, and related messages may be sent by the AMF at approximately the same time, and therefore the UE will receive these messages at approximately the same time. While the NAS specification [3] normally defines the receiver behavior in case of a collision, the current specification does not define the behavior for collisions of these procedures. Embodiments of the present invention aim to solve this problem by specifying the above exact behavior to mitigate such collisions.
[0102] Case 3: Conflict between service request procedures and NSSAA procedures
[0103] The UE initiates a service request procedure when in connected mode. At the same time, the network initiates an NSSAA for the UE in connected mode. For example, the UE is in 5GMM-CONNECTED mode via non-3GPP access, and then the UE performs a registration procedure via 3GPP access. The AMF indicates that it can perform an NSSAA in the 5GS Registration Result IE and can include a Pending NSSAI IE in the Registration Accept message, but the AMF may not be able to include an Allowed NSSAI IE in the NAS message. At or near the same time, the UE could send a service request message via non-3GPP access, but this may not occur under existing requirements. Currently, there is no mechanism to handle this collision.
[0104] 3. Lack of methods for handling abnormal cases
[0105] The NAS specification [3] describes how to handle and recover from abnormal cases that may arise.
[0106] Case 1: Failure to send a network slice-specific authentication complete message due to a tracking area identity (TAI) change from a lower layer Section 5.4.7.2.4 of [3] identifies the following anomaly cases for NSSAA:
[0107] a) Failure to send a network slice-specific authentication complete message due to a TAI change from the lower layer
[0108] If the current TAI is not present in the TAI list, the network slice-specific authentication and authorization procedures are aborted and the mobility and periodic registration update registration procedures are initiated, indicating "mobility registration updating" in the 5GS registration type IE of the registration request message.
[0109] If the current TAI is still part of the TAI list, how to re-execute the ongoing procedure that triggered the network slice-specific authentication and authorization procedure depends on the UE implementation.
[0110] The above case means that during an ongoing NSSAA, the UE enters a new tracking area identity (TAI) that does not exist in the UE's current list of TAIs, and therefore the UE needs to perform the registration procedure again.
[0111] While the above behavior is fine, it remains to be considered how the UE should handle the requested NSSAI IE that may be sent in the registration request procedure.
[0112] Note that there is a requirement that a UE with a pending NSSAI not include the S-NSSAI in the pending NSSAI when the UE retransmits a registration request unless a specific condition occurs. However, as described above, before entering a new TAI, the UE may have received the pending NSSAI IE but not the allowed NSSAI IE, or may have received both IEs. In either case, as the UE transitions to a new TAI, this new area is served by a new AMF. Therefore, if the UE does not retransmit the requested NSSAI IE, the decision (by the AMF) of the entry of the allowed NSSAI IE may differ from the case when the UE actually transmits the requested NSSAI IE. Therefore, not transmitting the requested NSSAI IE may lead to improper behavior or undesirable results. The present invention analyzes different cases and determines whether the requested NSSAI IE should be included in a registration request message following an abnormal case to avoid undesirable results.
[0113] Case 2: NSSAI performed for S-NSSAI that is in the Allowed NSSAI list or not in the Pending NSSAI
[0114] The UE registers with the network, e.g., during initial registration, and obtains the allowed NSSAI using an S-NSSAI entry, e.g., S-NSSAI X. The network also provides a pending NSSAI list for which NSSAIs are to be performed in the registration accept message.
[0115] The UE then receives a network slice-specific authentication complete message for an S-NSSAI that is already in the UE's allowed NSSAI list or is not in the UE's pending NSSAI list, e.g., S-NSSAI X. This is an abnormal case, and the UE behavior for handling such a scenario has not yet been defined.
[0116] Case 3: Unnecessary disconnection of NAS
[0117] To prevent unnecessary maintenance of the NAS connection, the UE may occasionally start timer T3540 to protect the maximum period during which the network is expected to release the NAS signaling connection. The cases in which the UE starts T3540 are described in section 5.3.1.3 of the NAS specification in [3].
[0118] However, the current conditions for initiating T3540, especially related to the registration procedure, which upon expiry may lead to a local disconnection of the NAS connection in the UE, are not complete and therefore need to be updated, otherwise the NAS connection may be disconnected earlier than necessary.
[0119] 4. Problems prohibiting service request procedures during NSSAA
[0120] The AMF indicates that the NSSAA is pending by including an "NSSAA to be performed" indicator in the 5GS Registration Result IE, and the AMF may include the pending NSSAA IE without including any allowed NSSAA IEs in the Registration Accept message. In this case, the UE will not perform any service request procedures except for emergency services, high priority access, or in response to a call or notification via non-3GPP access.
[0121] However, while an NSSAA is in progress, the UE may be in 5GMM-CONNECTED mode via non-3GPP access. If the lower layer connectivity of the non-3GPP access is lost, there is an already existing trigger that allows the UE to perform a service request procedure to reset the NAS connection when the lower layers (of the non-3GPP access) indicate that the connectivity has been restored, as specified in section 5.6.1.1 of [3].
[0122] This procedure is used when:
[0123] A UE in 5GMM-IDLE mode via a non-3GPP access receives an indication from a lower layer of the non-3GPP access that an access stratum connection has been established between the UE and the network; or However, the ongoing NSSAA prohibition of the service request procedure leads to the following contradictory requirements at the UE:
[0124] On the other hand, loss of lower layer connectivity requires initiation of a service request procedure, On the other hand, ongoing NSSAA procedures prohibit the initiation of a service request procedure, since loss of lower layer connectivity is not one of the exceptions identified for initiating a service request procedure.
[0125] 5. There is a fallback indication from the lower layer and an NSSAA complete message sent by the UE.
[0126] A UE in 5GMM-CONNECTED mode receives a fallback indication from lower layers as described in section 5.3.1.2 of the NAS specification in [3] (reproduced below for reference).
[0127] If a UE in 5GMM-CONNECTED mode over 3GPP access receives a fallback indication from lower layers and the UE has no pending NAS procedures and no pending uplink user data for a PDU session with already established user plane resources, the UE shall: a) Enter 5GMM-IDLE mode; and b) Initiate the registration procedure for mobility and periodic registration updates and include an Uplink Data Status IE in the Registration Request message indicating the PDU sessions for which user plane resources were active, if any, before receiving the fallback indication (see Section 5.5.1.3 for additional details).
[0128] If a UE in 5GMM-CONNECTED mode over 3GPP access receives a fallback indication from lower layers and the UE has pending uplink user data for a PDU session that already has established user plane resources but no pending procedures, the UE shall: a) Enter 5GMM-IDLE mode; and b) Include an Uplink Data Status IE in the Service Request message indicating the PDU sessions for which user plane resources were in the active state before initiating the Service Request procedure and receiving the Fallback Indication (see Section 5.6.1 for additional details).
[0129] If a UE in 5GMM-CONNECTED mode over 3GPP access receives a fallback indication from lower layers and the UE has a pending registration procedure, service request procedure, or deregistration procedure, the UE shall: a) Enter 5GMM-IDLE mode; b) proceed with pending procedures; and c) If the pending procedure is a service request or registration procedure, the UE includes an Uplink Data Status IE in the service request message or registration request message, which indicates the PDU sessions with pending user data to be transmitted via 3GPP access, if any, for which user plane resources were not active before receiving the fallback instruction from lower layers, and the PDU sessions for which user plane resources were active before receiving the fallback instruction, if any (see sections 5.5.1.3 and 5.6.1 for details).
[0130] If a UE in 5GMM-CONNECTED mode over 3GPP access receives a fallback indication from lower layers and the UE has a pending NAS procedure other than a registration procedure, a service request procedure, or a deregistration procedure, the UE shall: a) Enter 5GMM-IDLE mode; b) initiates a service request procedure and includes an Uplink Data Status IE in the service request message, if present, indicating the PDU session for which user plane resources were in the active state before receiving the fallback indication (see clause 5.6.1 for additional details); and c) Upon successful completion of the service request procedure, proceed to any pending procedures.
[0131] The above cases apply when the UE is in an authorized area or when the UE is not in an unauthorized area.
[0132] UE: a) is in an unauthorized area or is not in an authorized area; b) When in 5GMM-CONNECTED mode via 3GPP access; c) upon receiving a fallback indication from a lower layer; and d) If there is no pending signaling: UE: a) Enter 5GMM-IDLE mode; and b) Initiate the above registration procedures for mobility and periodic registration updates. The UE shall not include an uplink data status IE in the registration request message unless the PDU session for which the user plane resources were active is an emergency PDU session or the UE is configured for high priority access in the selected PLMN.
[0133] In the above cases where the UE receives a fallback indication from lower layers, if the UE is in a non-authorized area or is not in a licensed area, the UE shall behave as specified in clause 5.3.5.
[0134] A particular behavior to note is that if the UE has a pending procedure other than a registration procedure, a service request procedure or a deregistration procedure, after receiving a fallback indication from the lower layer, the UE will initiate the service request procedure from idle mode, and after the above procedure is completed, the UE will continue with the pending NAS procedure.
[0135] During the registration procedure, the UE receives a pending NSSAI list in the registration accept message, and the network then initiates NSSAA. The UE receives a network slice-specific authentication command message, and the UE must respond to this message. Therefore, the UE has a pending NAS message that is not a registration procedure, a service request procedure, or a deregistration procedure. The UE then receives a fallback instruction from the lower layer. Because there are some requirements that prevent the UE from initiating a service request procedure during NSSAA, recovery from fallback conflicts with the above requirements if the NSSAI selectively authorized by the UE is not useful. In this case, UE behavior must be defined to enable proper recovery from fallback.
[0136] Handling of Timer T3346 when UE receives NSSAA NAS message
[0137] The UE is in 5GMM-CONNECTED mode with NAS congestion control timer T3346 running. The UE then receives an NSSAA network slice-specific authentication command message. The UE does not stop timer T3346 if it is currently running and this is incorrect behavior.
[0138] 7. Impact on NSSAA during periodic renewal registration procedures
[0139] The UE is not instructed to send the requested NSSAI during regular registration, which means that the NSSAI information requested by the UE has not changed since the last signaling or registration to the network. However, if the allowed NSSAI for the UE has changed, the AMF provides the new allowed NSSAI in the registration accept message.
[0140] Currently, providing the UE with the allowed NSSAI and / or pending NSSAI during the registration procedure depends on whether the UE has sent the requested NSSAI and the content of the requested NSSAI. For example, the UE may not have slice information for the current PLMN and therefore may not be able to send the requested NSSAI even if registration is not triggered due to periodic registration. In this case, the AMF considers the UE's default slice.
[0141] However, as mentioned above, if the UE does not provide the requested NSSAI during periodic registration, the AMF will consider the UE's default slice and therefore provide an incorrect authorized NSSAI. Therefore, the current NSSAA procedure needs to consider whether the UE performs periodic registration and determine the content of the pending NSSAA accordingly. The current handling of the registration request message does not currently take this into account and therefore needs to be updated for correct handling and execution of the NSSAA procedure.
[0142] In view of the above problems, embodiments of the present invention provide one or more of the following solutions.
[0143] ≪1. Solution to enable NSSAA in roaming (and non-roaming) cases≫
[0144] As mentioned above, the roaming UE includes the requested mapped NSSAI IE in the registration request message, and the S-NSSAI included in this IE is subject to the NSSAA.
[0145] Therefore, the AMF is provided to take into consideration the mapped S-NSSAI content in the requested mapped NSSAI IE in addition to the S-NSSAI entry in the requested NSSAI IE, if the latter is included in the registration request message.
[0146] In addition to its current behavior, AMF can also perform the following actions:
[0147] If the UE does not support NSSAA, the UE sends the requested mapped NSSAI IE in the registration request, and the S-NSSAI entry in the IE is subject to NSSAA and optionally = The requested NSSAI IE is not included in the registration request message, or = The requested NSSAI IE is included in the registration request message, and the entries in the requested NSSAI IE are subject to the NSSAA.
[0148] The AMF then rejects the registration by sending a Registration Reject message, including 5GMM cause #62 "No network slices available", and the AMF also includes the rejected NSSAI IE, where the SST field of the rejected S-NSSAI is included in the requested mapped NSSAI IE and the NSSAI is set to the required mapped HPLMN SST, and the SD field of the rejected S-NSSAI is set to the mapped HPLMN SD field if the latter is included in the requested mapped NSSAI IE.
[0149] - If the requested mapped NSSAI entries are not subject to NSSAA and the AMF policy allows the UE to use these slices to transfer the associated PDU session, the AMF includes the corresponding S-NSSAI in the Allowed NSSAI IE and sends the IE to the UE in the Registration Accept message.
[0150] If the UE supports NSSAA and the UE included a requested mapped NSSAI IE whose entries in the requested mapped NSSAI are subject to NSSAA in the registration request message, the AMF shall include the S-NSSAI corresponding to the pending NSSAI IE and send the above IE in a registration accept message to the UE. Note that the pending NSSAI IE contains the entry from the requested NSSAI IE if the latter was included in the registration request message by the UE.
[0151] If the registration request message from the UE is rejected by the NSSAI, the AMF considers different cases: whether the message contains a requested mapped NSSAI IE or whether the message contains a requested NSSAI IE. The AMF operations are provided as follows:
[0152] = If the registration request message includes the requested mapped NSSAI IE but does not include the requested NSSAI IE, and NSSAI is canceled or fails for all entries in the requested mapped NSSAI IE (or all entries are rejected for the current registration area or rejected for the current PLMN), and optionally there is no entry that the network allows the UE to use without NSSAI or there is no default S-NSSAI allowed for the UE, the network sends a registration rejection and includes the rejected NSSAI IE. For each rejected S-NSSAI entry in the rejected NSSAI IE, the AMF sets the cause of the rejection to "S-NSSAI is not available due to the failed or revoked network slice-specific authentication and authorization."
[0153] = If the registration request message contains the requested mapped NSSAI IE and the requested NSSAI IE, and the NSSAI is canceled or failed for all entries of both IEs (or all entries are rejected for the current registration area or rejected for the current PLMN), and optionally the network allows the UE to use without an NSSAI or there is no default S-NSSAI allowed for the UE, the network sends a registration reject and includes the rejected NSSAI IE. For each rejected S-NSSAI entry in the rejected NSSAI IE, the AMF sets the cause of the rejection to "S-NSSAI is not available due to the failed or revoked network slice-specific authentication and authorization." The deregistration request message contains a 5GMM cause indicating #62 "No network slices available."
[0154] =If the AMF sends a Rejected NSSAI IE due to NSSAA failure or NSSAA cancellation, or if the UE does not support NSSAA and all S-NSSAIs requested by the UE (in the requested mapped NSSAI IE, or in the requested NSSAI IE, or both) are subject to NSSAA, the entry in the Rejected NSSAI IE is set to the mapped S-NSSAI (i.e., the S-NSSAI of the HPLMN). The Registration Reject message includes a 5GMM cause indicating #62 "No network slices available".
[0155] Alternatively, if any of the above occurs for a UE in connected mode, i.e., the AMF considers the content of the requested mapped NSSAI IE and / or the content of the requested NSSAI IE, and if the NSSAI fails for all entries in the above IEs, and optionally there is no default slice allowed for the UE, or optionally an entry in the IE is rejected for the current PLMN or registration area, the AMF sends a deregistration request message and sets the 5GMM cause to #62 "No network slices available". The AMF also includes the rejected NSSAI.
[0156] When NSSAA is performed, the UE receives a Registration Accept message with a pending NSSAI IE and optionally an allowed NSSAI IE. According to current operation, if the UE receives an allowed NSSAI IE that does not match between the S-NSSAI entry and the S-NSSAI associated with the PDU session or between the mapped S-NSSAI (allowed NSSAI entry) and the mapped S-NSSAI associated with the PDU session, the UE locally releases the mismatched PDU session as described above.
[0157] However, during NSSAA, the S-NSSAI associated with the PDU session may not be in the Allowed NSSAI IE, but may be in the Pending NSSAI IE. Therefore, a UE supporting NSSAA may not ignore the content of the Pending NSSAI IE before concluding or deciding that the PDU session is to be released. Therefore, the following is provided:
[0158] If the UE receives an Allowed NSSAI IE and a Pending NSSAI IE, even if there is no match between: = S-NSSAI in the Allowed NSSAI IE and S-NSSAI of each and every PDU session, or = Mapped S-NSSAI of the entry in the Allowed NSSAI IE and the mapped S-NSSAI of each and every PDU session, The UE checks for a match between the following, as described above: = S-NSSAI entry in the Pending S-NSSAI IE and S-NSSAI of each and every PDU session, or = Mapped S-NSSAI of the entry in the Pending NSSAI IE and the mapped S-NSSAI of each and every PDU session.
[0159] If a match exists, the UE may not release the PDU session for which the match occurred and wait to determine whether the session can be released after the NSSAI is completed and obtains the allowed NSSAI IE, at which point the UE may perform the check again. Optionally, the UE may perform the check again (e.g., with an allowed NSSAI entry) after the pending NSSAI list is empty.
[0160] As described above, if there is no match with any entry in the pending NSSAI IE, the UE locally releases the PDU session (for each PDU session for which no match occurs) except for persistent PDU sessions or emergency service PDU sessions.
[0161] If the UE does not receive an allowed NSSAI IE but receives a pending NSSAI IE, the UE maintains the PDU session until the allowed NSSAI IE is received, and then the UE performs the check as described above to determine whether to release the PDU session.
[0162] Alternatively, the UE performs a check on the entries in the Pending NSSAI IE as described above, i.e. the UE checks for a match between:
[0163] * S-NSSAI entry in the Pending S-NSSAI IE and S-NSSAI of each and every PDU session, or * Mapped S-NSSAI of the entry in the Pending S-NSSAI IE and the mapped S-NSSAI of each and every PDU session.
[0164] If a match exists, the UE holds the PDU session for which the match occurred until an allowed NSSAI IE is received, after which the UE performs a check again and then determines whether the PDU session can be released.
[0165] As described above, if there is no match with any entry in the pending NSSAI IE, the UE locally releases the PDU session except for persistent PDU sessions or emergency service PDU sessions.
[0166] The above provided embodiment is also achieved by the following checks in the UE:
[0167] For each PDU session active in the UE, if the UE indicates support for network slice specific authentication and authorization, and: 1) The UE receives a pending NSSAI but does not receive an authorized NSSAI, and all mapped S-NSSAIs in the pending NSSAI do not match the mapped S-NSSAIs of the PDU session; 2) When the UE receives a pending NSSAI and an allowed NSSAI, and i) A permitted NSSAI does not include any of the following: A) An S-NSSAI that matches the S-NSSAI of the PDU session; and B) A mapped S-NSSAI that matches the mapped S-NSSAI of the PDU session; and ii) If all mapped S-NSSAIs in the pending NSSAI do not match the mapped S-NSSAI of the PDU session; or 3) If the UE receives an Allowed NSSAI but does not receive a Pending NSSAI, and the Allowed NSSAI does not contain any of the following: i) an S-NSSAI that matches the S-NSSAI of the PDU session; or ii) a mapped S-NSSAI that matches the mapped S-NSSAI of the PDU session; The UE performs a local release of all such PDU sessions except for the emergency PDU session, if present.
[0168] Optionally, the UE will always maintain the PDU session as long as it has a non-empty pending NSSAI or, optionally, as long as the 5GS Registration Result IE indicates "NSSAA to be performed". When the UE receives an allowed and / or rejected NSSAI and, as part of storing this information, the UE's pending NSSAI becomes empty, the UE performs a check of the allowed NSSAI (as specified in the current TS 24.501 and described above) to determine whether the session can be maintained. In other words, the UE maintains the PDU session until it receives an allowed NSSAI and / or until the UE's pending NSSAI becomes empty, after which the UE checks the allowed NSSAI to verify a match between:
[0169] - the S-NSSAI of the Allowed NSSAI IE and the S-NSSAI of each and every PDU session, or - The mapped S-NSSAI of the entry in the Allowed NSSAI IE and the mapped S-NSSAI of each and every PDU session.
[0170] As mentioned above, if no match exists, the UE releases the PDU sessions for which no match exists, except for PDU sessions for emergency services or high priority access.
[0171] It should be noted that the above provided embodiments also apply in the non-roaming case, i.e., when the UE does not send the requested mapped NSSAI IE. It should be noted that the above provided embodiments also apply when the UE performs an inter-system change from S1 mode (i.e., from EPS) to N1 mode (i.e., to 5GS), and optionally when the N26 interface is supported in said system.
[0172] Furthermore, such a check may be performed between what the UE sends in {Requested NSSAI IE or Requested Mapped NSSAI IE} and the entry in {Allowed NSSAI IE or Pending NSSAI IE}.
[0173] It should be noted that some or all of the above checks (i.e., the UE's checks to determine whether it can locally release the PDU session based on the received NSSAI information) are also performed when the UE receives the same information or a subset of that information (i.e., only authorized NSSAIs, or only pending NSSAIs, or both authorized and pending NSSAIs) as a configuration update command message.
[0174] It should be noted that the term "mapped S-NSSAI in the pending NSSAI" also refers to the S-NSSAI entry in the pending NSSAI.
[0175] 2. Solutions for handling conflicts between NSSAA procedures and other procedures
[0176] Case 1: Solution to the conflict between authentication procedures and NSSAA procedures
[0177] As described above, during NSSAA, the network initiates the NSSAA procedure and then the authentication procedure.
[0178] If the UE receives (substantially simultaneously with or immediately after) a network slice-specific authentication command message via any access type (e.g., 3GPP access or non-3GPP access) and the UE also receives an authentication request message via any access type (e.g., 3GPP access or non-3GPP access), where the access type for one of the NAS messages is not necessarily the same as the access type for which the other NAS message is received, the UE ignores or aborts the NSSAA procedure (i.e., ignores the network slice-specific authentication command message) and continues the authentication procedure (i.e., processes the authentication request message). Alternatively, the UE first processes the authentication request message and successfully completes procedures for authentication and optionally security mode control before responding to the network slice-specific authentication command message. In this case, the UE only sends the network slice-specific authentication complete message after sending the authentication response or security mode complete message.
[0179] It should be noted that the embodiments provided above apply to conflicts between NSSAA procedures and security control procedures.
[0180] Therefore, if a UE receives a network slice-specific authentication command message via an access type and (approximately simultaneously or shortly thereafter) receives a security mode command message via the same access type, the UE may prioritize handling the security mode command message (i.e., prioritize the security mode control procedure) compared to the network slice-specific authentication command message (i.e., compared to the NSSAA procedure). The UE may ignore the network slice-specific authentication command message (i.e., ignore or abort the NSSAA procedure) and process the security mode command message (i.e., continue the security mode control procedure). Alternatively, the UE may first complete the ongoing security mode control procedure, and after the procedure is successfully completed (i.e., after the UE sends a security mode complete message), the UE may then process the network slice-specific authentication command message and possibly respond with a network slice-specific authentication complete message.
[0181] Case 2: Solution to the conflict between general UE configuration update procedure and NSSAA procedure
[0182] As described above, during NSSAA, the network initiates an NSSAA procedure and then initiates a general UE configuration update procedure. If the UE receives (substantially simultaneously with or immediately after) a network slice-specific authentication command message via any access type (e.g., 3GPP access or non-3GPP access) and also receives a configuration update command message via any access type (e.g., 3GPP access or non-3GPP access), where the access type on which one of the NAS messages is received is not necessarily the same as the access type on which the other NAS message is received, and the configuration update command message indicates that registration is requested (e.g., using a “registration requested” bit in the configuration update indication IE or other means used to indicate a registration request), the UE ignores or aborts the NSSAA procedure (i.e., ignores the network slice-specific authentication command message) and proceeds with the general UE configuration update procedure (i.e., processes the configuration update command message).
[0183] Alternatively, the embodiments provided above apply when the configuration update command message does not include any parameters other than the registration instruction (e.g., when the message does not include any other IEs other than the configuration update instruction IE).
[0184] Alternatively, the embodiment provided above applies when the configuration update command message indicates that registration is required and the message includes a network slicing indication IE with the NSSCI bit (see [3]) set to "network slicing subscription changed".
[0185] Alternatively, the embodiments provided above may not apply, i.e., if the UE is requested to perform registration while in connected mode, e.g., if a MICO (Mobile Initiated Connection Only) Indication IE is present in the Configuration Update Command message, the UE continues with both the NSSAA procedure and the general UE Configuration Update procedure. Note that while the presence of the MICO Indication IE is an example of a case where the UE is requested to perform a registration procedure in connected mode, there may be other cases where the UE is requested to perform registration in connected mode, and in these cases the above embodiments do not apply.
[0186] =Note: "The provided embodiment above may not apply" means that the UE does not ignore the NSSAA procedure, the UE continues to process both the network slice-specific authentication command message and the configuration update command message, and none of the above procedures are discontinued.
[0187] Case 3: Solution to conflict between service request procedures and NSSAA procedures
[0188] As mentioned above, during an ongoing NSSAA procedure, for example via 3GPP access, the UE initiates a service request procedure via a non-3GPP procedure.
[0189] If the AMF receives a service request message via non-3GPP access from a UE in 5GMM-CONNECTED mode via non-3GPP access: If the AMF initiates NSSAA for the UE via the same or a different access, - And optionally, if the AMF sends a registration accept message to the UE via another access (before the start of the NSSAA), where the message includes a pending NSSAI IE and a 5GS registration result IE indicating "NSSAA to be performed", and the message does not include an allowed NSSAI IE.
[0190] And the AMF receives a service request message from a UE that is in 5GMM-CONNECTED mode, optionally from a UE via a non-3GPP access, and optionally the service request message includes an uplink data status IE; The AMF aborts the service request procedure (i.e., ignores the service request message) and proceeds to the NSSAA procedure (i.e., sends a network slice-specific authentication command message to the UE if not already sent, or processes a network slice-specific authentication complete message from the UE if received).
[0191] Otherwise, if the above conditions are not met, the AMF will process both procedures simultaneously.
[0192] 3. Handling in Abnormal Conditions
[0193] Case 1: Failure to send network slice-specific authentication complete message due to TAI change from lower layer
[0194] As described in [3], when the identified abnormal cases occur, the UE aborts the network slice-specific authentication and authorization procedures and initiates the mobility and periodic registration update registration procedures indicating "mobility registration updating" in the 5GS registration type IE of the registration request message. In this case, the UE includes the requested NSSAI IE, or the requested mapped NSSAI IE, or both IEs, even if the S-NSSAI entries that comprise these IEs are present in the pending NSSAI IE.
[0195] Alternatively, even if the UE has a pending NSSAI list in which the requested NSSAI IE or the requested mapped NSSAI IE or the two IEs previously contained an S-NSSAI entry, the IEs are included if the UE sent the requested NSSAI IE or the requested mapped NSSAI IE or the two IEs in the previous or last registration procedure.
[0196] Case 2: NSSAI performed for S-NSSAI that is in the Allowed NSSAI list or not in the Pending NSSAI
[0197] The UE performs a registration procedure, for example for initial registration, and the UE obtains the granted NSSAI in a registration accept message that includes a pending NSSAI.
[0198] After the registration procedure is completed, the AMF initiates an NSSAA and sends a network slice-specific authentication command message with the S-NSSAI field set to a value that is present in the allowed NSSAI or not present in the pending NSSAI. Optionally, if this occurs after initial registration, the UE considers it an abnormal case or an error.
[0199] If the UE considers the network slice-specific authentication command message to be problematic or erroneous, or an abnormal case, such as but not limited to the example scenario discussed above, the UE sends a 5GMM status message to the AMF as defined in [3]. In this case, the UE uses a new 5GMM cause code indicating an NSSAA error, such as "Network Slice-Specific Authorization and Authentication Error." It should be noted that this is an example 5GMM cause code, but other values can be defined for this purpose.
[0200] Alternatively, a new 5GMM message is used for this purpose. For example, a new network slice-specific authentication rejection message is defined to report errors or abnormal cases such as the above scenarios. The new message includes at least the S-NSSAI received in the corresponding network slice-specific authentication command message, a 5GMM cause, and optionally an Extensible Authentication Protocol (EAP) message. The EAP message is the same message as the one received in the corresponding network slice-specific authentication command message.
[0201] When the UE sends a 5GMM status message or a new NAS message as provided above, the UE selectively sends a list of allowed NSSAIs and pending NSSAIs to the AMF and informs the AMF of the S-NSSAIs available to the UE for each list. The new messages provided above, i.e., network slice-specific authentication messages, are shown in Table 1 below.
[0202] [Table 1]
[0203] It should be noted that IEs in messages such as those listed above may be mandatory (indicated by an "M" in the Presence column) or optional (indicated by an "O" in the Presence column), or vice versa, even though some may be mandatory.
[0204] When the AMF receives a new message or a 5GMM status message as provided above with a new 5GMM cause code, the AMF resumes the NSSAA procedure using the correct S-NSSAI. If the 5GMM cause code indicates that the S-NSSAI is incorrect, the AMF may resume the NSSAA procedure using the correct S-NSSAI by ensuring that the selectively used S-NSSAI is actually part of the pending NSSAI list at the UE, where the latter may also have been received by the AMF.
[0205] Performing an NSSAA for an S-NSSAI that is not in the pending NSSAI list may be an error or may not be an abnormal case. For example, this may occur for a default S-NSSAI that the UE has not requested but for which the AMF must perform an NSSAA. Therefore, an alternative approach is for the UE to continue processing the associated NSSAA message even if the S-NSSAI for which the NSSAA is being performed is not in the pending NSSAIs (or is in any allowed NSSAIs).
[0206] Another way to indicate to the UE that the NSSAA procedure is not erroneous is to include a new instruction in the network slice-specific authentication command message to inform the recipient (e.g., UE) that the procedure was intentional, i.e., not an error. The instruction can be in any format, such as defining an action, where the action is set to, for example, "initial NSSAA," "reauthentication," or "default slice NSSAA." This instruction is in the form of a new IE. This instruction is typically used to indicate to the UE why a particular NSSAA message is being sent. The UE uses this instruction to identify whether the message being sent is for an initial NSSAA or an NSSAA retry, and then takes specific action accordingly. For example, if the network is reauthenticating a particular S-NSSAI that exists in the allowed NSSAA, the UE will block 5GSM requests related to the S-NSSAI if the UE knows that the NSSAA procedure will be retried and therefore will not consider it an error.
[0207] Currently, the involvement of the UE, and in particular the 5GMM entity at the UE, in the NSSAI is for the NAS to forward the contents of the NETWORK SLICE-SPECIFIC SESSION AUTHENTICATION COMMAND message to upper layers. However, the UE (or NAS or 5GMM entity) may be suited to perform other actions, such as ensuring that the S-NSSAI received in the message is part of any combination of the following:
[0208] - Pending NSSAI List; - Authorized NSSAI; or -NSSAI rejected.
[0209] The UE then takes one of the provided actions when the condition for the check occurs.
[0210] Alternatively, the UE also checks whether the S-NSSAI is neither part of an allowed NSSAI nor part of a pending NSSAI, and if so, the UE considers this an error and takes one of the actions provided above.
[0211] It should be noted that if the AMF receives a network slice-specific session authentication complete message and the S-NSSAI included in the message is not valid, for example, if it does not match any of the S-NSSAIs in progress, or if it is not part of the S-NSSAI being executed by the NSSAA or is not part of the pending NSSAI list in the AMF, the AMF shall ignore or discard the received message and resend a network slice-specific session authentication command message with a valid S-NSSAI (i.e., not the same as one for which the NSSAA is in progress, not yet completed, or known to be invalid). This requires the AMF to store the S-NSSAI sent in the network slice-specific authentication message and compare it with the S-NSSAI received in the network slice-specific session authentication complete message. If there is no match, or if the S-NSSAI received in the network slice-specific session authentication complete message is not part of the S-NSSAI for which an NSSAA is in progress (as described in the various ways above), the AMF ignores the received message or optionally aborts the existing procedure and preferably resends a network slice-specific session authentication command message with a valid S-NSSAI.
[0212] It should be noted that throughout this specification, the term "NSSAA to be performed" is synonymous with receiving a 5GS Registration Result IE with an "NSSAA to be performed" indicator set to "network slice-specific authentication and authorization is to be performed."
[0213] Case 3: Unnecessary disconnection of NAS
[0214] To ensure that T3540 is correctly initiated during the registration procedure, in addition to what is specified in section 5.3.1.3 of the NAS specification in [3] for case (b) (i.e., reception of registration acceptance by the UE), the UE must also check the following conditions: - whether the registration acceptance message indicates "NSSAA to be performed" in the 5GS Registration Result IE, or -Whether the registration accept message includes a pending NSSAI (i.e., does not include a pending NSSAI IE).
[0215] The above registration acceptance: -Indicate "NSSAA to be performed" in the 5GS Registration Result IE, or - if it contains a pending NSSAI (i.e., it does not contain a pending NSSAI IE), The UE does not start T3540.
[0216] If T3540 is running in the UE, the UE stops T3540 when it receives a network slice-specific authentication command message.
[0217] ≪4. Permission for some ongoing NSSAA procedures≫
[0218] The UE is in 5GMM-CONNECTED mode via at least non-3GPP access and optionally via 3GPP access, and the AMF may be performing an NSSAA procedure via non-3GPP access or optionally via 3GPP access. The UE may have received a Pending NSSAI IE in the Registration Accept message but not an Allowed NSSAI IE, and the 5GS Registration Result IE may indicate "NSSAA to be performed".
[0219] While the NSSAA is in progress, the UE may lose its lower layer connectivity via the non-3GPP access. When connectivity is restored, the NAS receives an indication from the lower layers of the non-3GPP access that an access stratum connection is established between the UE and the network. Even while the NSSAA is in progress, the UE initiates a service request procedure and sends a service request message via the non-3GPP access even while the NSSAA is in progress using the conditions described above.
[0220] As described above, this can be achieved by applying a restriction on the service request procedure to the UE such that it does not initiate the service request procedure (i.e., does not send a service request message) during an ongoing NSSAA procedure from 5GMM-CONNECTED mode (optionally, if the UE receives a pending NSSAI, does not receive an authorized NSSAI, and the 5GS Registration Result IE indicates "NSSAA performed"). Therefore, the above restriction does not apply to a UE in 5GMM-IDLE mode. Therefore, when a UE in 5GMM-IDLE mode via non-3GPP access receives an indication from the lower layers of the non-3GPP access that an access stratum connection is established between the UE and the network, the UE can and does send a service request message via the non-3GPP access to establish an NAS connection with the network. The UE can send a service request message even if an NSSAA is ongoing via 3GPP access using the above conditions (e.g., even if the UE has not received an authorized NSSAI in the registration accept message, or regarding what the UE has or has not received in the registration accept message). It should be noted that the above provided embodiments apply to both initial registration and registration for mobility and periodic updates.
[0221] It should be noted that the UE can send a service request message in 5GMM-CONNECTED mode if it is so operating in order to request the establishment of user plane resources for a PDU session for emergency services or a PDU session with exception data reports that it will send. Similarly, if the UE is so operating for exception data reporting or if it is a high priority access UE (i.e. for sending CIoT user data or location services or optionally UL NAS transport messages using SMS), it can send data via the control plane.
[0222] Alternatively, when the NAS receives an indication from the non-3GPP access lower layer that an access stratum connection has been established between the UE and the network, the UE sends a Registration Request message instead of a Service Request procedure. If the S-NSSAI is included in the UE's current pending NSSAI list, but the UE included the requested NSSAI IE and / or the requested mapped NSSAI IE during the last registration procedure (or if the UE has slice information for the current PLMN), the UE includes the requested NSSAI IE and / or the requested mapped NSSAI IE.
[0223] It should be noted that the embodiments provided above apply during any other procedure and are not limited to the registration procedure. For example, if a future Configuration Update Command message provides the UE with a pending NSSAI, optionally providing an unauthorized NSSAI, and optionally considering the UE as not having a valid authorized NSSAI based on the content of the message, and a lower layer connection fails and is later established (as described above), the embodiments provided above still apply. Thus, the embodiments provided above are not limited to only the registration procedure, but also apply during any procedure or at any time in connected mode where the UE determines if there is no authorized NSSAI.
[0224] The NAS specification [3] allows a UE to initiate a 5GSM procedure, such as a PDU Session Establishment procedure, already during an NSSAA if the above conditions are met (i.e., the UE received a Pending NSSAI IE in the Registration Accept message but not an Authorized NSSAI IE, and the 5GS Registration Result IE may have indicated "NSSAA to be performed"). However, when the UE sends a PDU Session Establishment Request message (in the above UL NAS Transport message), the UE may not include the S-NSSAI IE in the UL NAS Transport message because the UE does not yet have an Authorized NSSAI. Alternatively, the UE may include the S-NSSAI IE and set it to a value preconfigured in the UE.
[0225] 5. Recovery from Fallback During NSSAA
[0226] As described above, the UE may receive a fallback indication during the NSSAA, and therefore the UE has a pending NAS procedure (e.g., the UE needs to send an NAS message in response to a network slice-specific authentication command message). When a fallback occurs, the UE may take any of the following measures as provided embodiments for recovering from the fallback:
[0227] The UE is permitted to initiate a service request procedure (i.e., send a service request message) to recover from fallback, as currently specified. To allow this, the current restriction that a service request procedure may not be permitted during NSSAA needs to be updated, and more exceptions defined to address this issue. For example, the above restriction (which prohibits a UE from initiating a service request procedure during NSSAA) may not apply to a service request procedure initiated from 5GMM-IDLE mode. Thus, the UE may have a pending NSSAI and may send a service request message from 5GMM-IDLE mode to recover from fallback during an NSSAA procedure (optionally, if the UE does not have an permitted NSSAI and the UE receives an "NSSAA to be performed" indicator, indicating that an NSSAA is to be performed).
[0228] = Optionally, the above is only allowed if the UE is already registered in the system or if the NSSAA is following a registration procedure with the 5GS registration type IE set to "Mobility Registration Update" or "Periodic Registration Update".
[0229] = Optionally, when sending a Service Request message, the UE does not include the Uplink Data Status IE unless the corresponding PDU session (a specific bit is set to 1 in the IE) is associated with an S-NSSAI that exists in an allowed NSSAI, or is associated with an S-NSSAI for which no NSSAI is ongoing, or the PDU session is "always on PDU session", or the PDU session had user plane resources established prior to the fallback indication.
[0230] Alternatively, to recover from fallback, the UE sends a Registration Request message with the 5GS Registration Type IE set to "Mobility Registration Update". The UE is allowed to include the requested NSSAI IE or the requested mapped NSSAI IE in the Registration Request sent to recover from fallback even if an entry exists in the pending NSSAI or the UE has a pending NSSAI.
[0231] It should be noted that the embodiments provided above also apply whenever the UE is in connected mode, an NSSAA is in progress, and the UE receives a fallback indication. Thus, the UE behavior described above is not limited to scenarios that occur only during the registration procedure. The embodiments provided above still apply when other procedures are in progress or to UEs in connected mode in general.
[0232] = Optionally, when sending a Service Request message, the UE does not include the Uplink Data Status IE unless the corresponding PDU session (a specific bit is set to 1 in the IE) is associated with an S-NSSAI that exists in an allowed NSSAI, or is associated with an S-NSSAI for which no NSSAI is in progress, or the PDU session is always a PDU session.
[0233] When the AMF receives a service request message or a registration request message as described above and has an ongoing NSSAA procedure, the AMF processes the service request message or the registration request message and optionally aborts the NSSAA procedure. The AMF decides to do so based on the fact that the NAS message is received as an initial NAS message from the N2 interface and protocol executed between the NG-RAN and the AMF.
[0234] 6. Stopping timer T3346 when the UE receives an NSSAA NAS message
[0235] The UE is provided to stop timer T3346, if running, upon receiving the network slice-specific authentication command message. Thus, the UE stops timer T3346, if running, upon receiving the network slice-specific authentication command message.
[0236] <7. Solutions for considering types of NSSAA registration renewal>
[0237] The current handling of NSSAA provides that when an NAS message is received from a UE that is not in narrow band-N1 (NB-N1) mode, it is performed only when the 5GS Registration Type IE indicates "Mobility Registration Update" in the Registration Request message. Therefore, the AMF takes the action currently specified in TS 24.501 when an NAS message is received from a UE that is not in NB-N1 mode and the 5GS Registration Type IE indicates "Mobility Registration Update" in the Registration Request message.
[0238] The AMF may have new NSSAI information for the UE, i.e., the authorized NSSAI previously sent to the UE may have changed. The new NSSAI that the UE can use also requires that an NSSAA be performed. In practice, the AMF is required to restart NSSAA for the UE due to internal policy or in response to a request from an NSSAA-related AAA server. The UE then sends a registration request with a 5GS registration type IE indicating "periodic registration update" or "mobility registration update" for a UE in NB-N1 mode. Thus, the following is provided:
[0239] The AMF need not take any action if the authorized NSSAI has not changed for the UE and does not require the NSSAI to be resumed for the UE; and If the authorized NSSAIs (or S-NSSAIs that the UE is authorized to use) are changed and at least one of the new S-NSSAIs requests an NSSAA, the AMF shall: = send an authorized NSSAI to the UE, where if an authorized NSSAI exists, it contains an S-NSSAI for which no resumption of the NSSAI is requested; or = Send a pending NSSAI containing the S-NSSAI for which NSSAA needs to be resumed. Furthermore, if the UE cannot be provided with an authorized NSSAI, the AMF also sets the "NSSAA to be performed" indication in the 5GS Registration Result IE. The content of the pending NSSAI also includes the default slice (i.e., the slice marked as the default slice in the UE's subscription information and for which NSSAA is requested to be started or resumed).
[0240] During a periodic registration procedure (i.e., the 5GS Registration Type IE indicates "periodic registration updating") or during a registration procedure where the 5GS Registration Type IE is set to "mobility registration updating", the UE receives the pending NSSAI in a Registration Accept message. The UE shall act in the same manner as currently specified when the same information is received in a Registration Accept message as part of a registration procedure that is not triggered due to a periodic update.
[0241] The 5GS Registration Result IE indicates "NSSAA to be performed" in the Registration Accept message, and the 5GS Registration Type IE in the Registration Request message is: a) "periodic registration updating" (i.e., the above procedure was triggered by a periodic registration update), or b) "Mobility Registration Update", indicating that the UE is in NB-N1 mode (i.e., the procedure is not triggered by an NB-N1 mode UE due to a periodic registration update); The UE considers any previously stored allowed NSSAIs to be invalid, i.e., the UE deletes any stored allowed NSSAIs.
[0242] The embodiment provided above, i.e., considering the stored authorized NSSAI invalid, alternatively applies to all UEs that send a Registration Request message with the 5GS Registration Type IE set to "Mobility Registration Update". Note that the UE subsequently obtains a 5GS Registration Result IE indicating "NSSAA performed" in the Registration Accept message.
[0243] It should be noted that throughout this specification, the term "NSSAA to be performed" is synonymous with the "NSSAA to be performed indicator" being set to "network slice-specific authentication and authorization is to be performed."
[0244] It should be noted that the AMF may also reject a Registration Request message for a UE where the 5GS Registration Type IE indicates "periodic registration updating" (i.e., the above procedure is triggered by periodic registration update) or indicates "mobility registration updating" and the UE is in NB-N1 mode (i.e., the above procedure is not triggered for NB-N1 mode UEs for periodic registration update) if the NSSAI is canceled for all slices, even if the UE has not sent the requested NSSAI IE (or requested mapped NSSAI IE) in the Registration Request message. The AMF shall take the same actions as provided earlier in this document (for cases where the AMF needs to consider the requested mapped NSSAI IE and / or the requested NSSAI IE).
[0245] An embodiment of the present invention provides a method for a network entity (e.g., an AMF entity), which includes the operation of sending to the UE: an authorized NSSAI including an S-NSSAI that does not require NSSAA resumption and / or a pending NSSAI including an S-NSSAI that requires NSSAA resumption, if the authorized NSSAI of the UE has changed from the authorized NSSAI previously sent to the UE, and if at least one new S-NSSAI requests an NSSAA. Those skilled in the art will understand that this technique applies to cases such as those described in item 7 (i.e., when the UE is performing a periodic update or when an NB-N1 mode UE is sending a registration request for mobility update). In both cases, the AMF does not receive the requested NSSAI, and therefore the embodiment includes: (a) an authorized NSSAI with slices that are authorized for use, and (b) sending a pending NSSAI if an NSSAA is required for some (potentially new) slices.
[0246] An embodiment of the present invention provides a method for a network entity (e.g., an AMF entity), the method including: when an authorized NSSAI for a UE has changed from an authorized NSSAI previously sent to the UE and at least one new S-NSSAI requires an NSSAA, sending to the UE: an authorized NSSAI including an S-NSSAI for which NSSAA resumption is not required, and / or a pending NSSAI including an S-NSSAI for which NSSAA resumption is required. Those skilled in the art will appreciate that this technique can be generalized to all types of registration requests where the UE can revoke the authorized NSSAI if an "NSSAA to be performed" is received.
[0247] Figure 6 is a block diagram of an exemplary network entity used in an embodiment of the present invention. For example, the UE and / or the AMF may be provided in the form of the network entity shown in Figure 6. Those skilled in the art will understand that the network entity shown in Figure 6 may be implemented as a software instance running on dedicated software, for example as a network element in dedicated hardware, or as a virtualized function instantiated on a suitable platform, for example a cloud infrastructure.
[0248] The entity includes a processor (or controller) 601, a transmitter 603, and a receiver 605. The receiver 605 is configured to receive one or more messages or signals from one or more other network entities. The transmitter 603 is configured to transmit one or more messages or signals to one or more other network entities. The processor 601 is configured to perform one or more operations and / or functions as described above. For example, the processor 601 is configured to perform UE or AMF operations.
[0249] The techniques described herein may be implemented using any suitably configured apparatus and / or system. Such an apparatus and / or system may be configured to perform a method according to any aspect, embodiment, example, or claim disclosed herein. Such an apparatus may include one or more elements, such as one or more receivers, transmitters, transceivers, processors, controllers, modules, units, etc., each configured to perform one or more corresponding processes, operations, and / or method steps for implementing the techniques described herein. For example, operation / function X may be performed by a module configured to perform X (or an X module). One or more elements may be embodied in hardware, software, or any combination of hardware and software.
[0250] It will be understood that embodiments of the present invention may be embodied in the form of hardware, software, or any combination of hardware and software, any such software being stored in the form of volatile or non-volatile storage, whether erasable or rewritable, such as a ROM, or in the form of memory, such as a RAM, memory chip, device, or integrated circuit, or on an optically or magnetically readable recording medium, such as a CD, DVD, magnetic disk, or magnetic tape.
[0251] It will be understood that the above-mentioned storage devices and storage media are embodiments of a computer-readable storage device suitable for storing a program or programs containing instructions that, when executed, implement embodiments of the present invention. Accordingly, embodiments provide a program containing code for implementing a method, apparatus, or system according to any example, embodiment, aspect, and / or claim disclosed herein, and / or a computer-readable storage device storing such a program. Furthermore, such a program may be transmitted electronically via any medium, such as, for example, a communication signal transmitted via a wired or wireless connection.
[0252] Although the present invention has been described in various embodiments, various changes and modifications may be suggested to those skilled in the art, and it is intended that the present invention encompasses all such changes and modifications falling within the scope of the appended claims. [Explanation of symbols]
[0253] 601 Processor (or controller) 603 Transmitter 605 Receiver
Claims
1. 1. A method for a user equipment (UE), comprising: The UE sending a registration request message including registration type information to a network entity; receiving, by the UE, a registration accept message including pending network slice selection assistant information (NSSAI) and registration result information having an indicator indicating that network slice-specific authentication and authorization (NSSAA) is performed, from the network entity; determining, by the UE, based on the registration accept message, that a previously received allowed NSSAI is invalid; initiating a service request procedure when the UE in an idle mode gets an indication that an access stratum connection has been established between the UE and the network entity, or when the UE in a connected mode gets a fallback indication and has a pending procedure.
2. 2. The method of claim 1, wherein the registration accept message does not include an allowed network slice selection assistance information (NSSAI).
3. 2. The method of claim 1, wherein the UE in the idle mode over a non-3GPP access obtains an indication from a lower layer of the non-3GPP access that an access stratum connection has been established between the UE and the network entity.
4. 2. The method of claim 1, wherein the pending procedure is a Network Slice Specific Authentication and Authorization (NSSAA) procedure.
5. 2. The method of claim 1, wherein if the registration type information indicates a periodic registration update or a mobility registration update, the UE is in a narrowband mode that allows access to a fifth generation (5G) network.
6. 1. A method of a network entity, comprising: receiving, by the network entity, a registration request message from a user equipment (UE), the registration request message including registration type information; the network entity sending a REGISTRATION ACCEPT message to the UE indicating that a previously sent allowed NSSAI (network slice selection assistant information) is invalid; The registration accept message includes a pending NSSAI and registration result information having an indicator indicating that network slice-specific authentication and authorization (NSSAA) is performed; A method, characterized in that a service request procedure is initiated when the UE in an idle mode receives an indication that an access stratum connection has been established between the UE and the network entity, or when the UE in a connected mode receives a fallback indication and has a pending procedure.
7. 7. The method of claim 6, wherein the registration accept message does not include an allowed network slice selection assistance information (NSSAI).
8. 7. The method of claim 6, wherein the UE in the idle mode over a non-3GPP access obtains an indication from a lower layer of the non-3GPP access that an access stratum connection has been established between the UE and the network entity.
9. 7. The method of claim 6, wherein the pending procedure is a Network Slice Specific Authentication and Authorization (NSSAA) procedure.
10. A user equipment (UE) comprising: A transceiver; at least one processor that controls the transceiver; The at least one processor Sending a registration request message including registration type information to a network entity; Receive a registration accept message from the network entity, the registration accept message including pending network slice selection assistant information (NSSAI) and registration result information having an indicator indicating that network slice-specific authentication and authorization (NSSAA) is performed; is configured to invalidate a previously received Allowed NSSAI based on the registration acceptance message; 1. A UE configured to initiate a service request procedure when the UE in an idle mode receives an indication that an access stratum connection has been established between the UE and the network entity, or when the UE in a connected mode receives a fallback indication and has a pending procedure.
11. 11. A UE according to claim 10, characterized in that it is adapted to operate according to the method of any one of claims 2 to 5.
12. A network entity comprising: A transceiver; at least one processor that controls the transceiver; The at least one processor receiving a registration request message from a user equipment (UE) including registration type information; configured to send a REGISTRATION ACCEPT message to the UE indicating that a previously sent allowed NSSAI is invalid; The registration accept message includes a pending NSSAI and registration result information having an indicator indicating that network slice-specific authentication and authorization (NSSAA) is performed; A network entity characterized in that a service request procedure is initiated when the UE in an idle mode receives an indication that an access stratum connection has been established between the UE and the network entity, or when the UE in a connected mode receives a fallback indication and has a pending procedure.
13. A network entity adapted to operate according to the method of any one of claims 7 to 9.