Network slice-specific authentication and authorization

The solution addresses NSSAA challenges by storing pending NSSAIs for equivalent PLMNs, stopping back-off timers, and allowing services like location services, enhancing network efficiency and service availability in 3GPP 5G networks.

JP7725503B2Active Publication Date: 2025-08-19SAMSUNG ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2022571876
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-05-05
Filing Date
2021-05-24
Publication Date
2025-08-19
Estimated Expiration
2041-05-24

AI Technical Summary

Technical Problem

Existing 3GPP 5G network slice-specific authentication and authorization (NSSAA) procedures face issues with handling pending and permitted NSSAIs across equivalent PLMNs, failure to stop back-off timers during PDU session authentication, and blocking of location services when authorized NSSAI is unavailable.

Method used

The solution involves storing pending NSSAIs for each equivalent PLMN, stopping back-off timers upon receiving PDU SESSION AUTHENTICATION COMMAND messages, and allowing services like location services during NSSAA when authorized NSSAI is unavailable.

Benefits of technology

This approach enhances network efficiency by enabling seamless service access across equivalent PLMNs, optimizes signaling by stopping unnecessary back-off timers, and ensures essential services like location services are available even without authorized NSSAI.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007725503000011
    Figure 0007725503000011
  • Figure 0007725503000012
    Figure 0007725503000012
  • Figure 0007725503000013
    Figure 0007725503000013
Patent Text Reader

Abstract

A method and apparatus are provided for performing authentication and authorization in a network. [Solution] A method is disclosed for a user equipment (UE) in a wireless communication system, the method including: receiving a pending network slice selection assistance information (NSSAI) including one or more single network slice selection assistance information (S-NSSAI); and applying the received pending NSSAI to at least one second public land mobile network (PLMN) within a registration area, where the UE is assigned to a registration area including two or more tracking areas (TAs) including at least a first set of TAs belonging to a first public land mobile network (PLMN) in which the UE is registered.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a method, an apparatus, and a system for performing authentication and authorization in a network, and more particularly to a method, an apparatus, and a system for performing NSSAA in 3GPP 5G. [Background technology]

[0002] Certain examples of the present invention provide methods, devices, and systems for performing authentication and authorization in a network, for example, for performing NSSAA in 3GPP 5G.

[0003] Various acronyms, abbreviations and definitions used herein are defined at the end of the detailed description herein.

[0004] 3GPP 5GS defines the following (e.g., 3GPP standard specifications): A network slice (NS) is defined as a logical network that provides specific network functions and network characteristics. A network slice instance (NSI) is defined as a set of network function instances and required resources (e.g., compute, storage, and networking resources) that form a deployed NS. A network function (NF) is defined as a 3GPP-adopted or 3GPP-defined processing function in a network with defined functional operations and 3GPP-defined interfaces. An NS is identified by a single network slice selection assistance information (S-NSSAI).

[0005] Overview of registration areas and equivalent PLMNs applied to slicing

[0006] The AMF assigns a registration area to the UE during the registration procedure as described in the 3GPP standard specifications, which consists of a list of tracking area identifiers (TAIs) that can serve the UE in that registration area, each of which consists of one or more cells covering a geographical area.

[0007] A PLMN that has service capabilities equivalent to those of another PLMN is called an equivalent PLMN. These PLMNs are considered equivalent to each other by the UE with respect to PLMN selection and cell selection / reselection. If the AMF returns a list of TAIs to the UE during the registration procedure, this list may consist of the TAIs of PLMNs equivalent to the registered PLMN and the TAI of the registered PLMN.

[0008] When a UE requests registration to a set of slices, the network returns an allowed NSSAI to the UE, providing a set of tracking areas that can serve all slices within the allowed NSSAI for that particular registration area. If there is a PLMN equivalent to the registered PLMN, the tracking area identifier of the equivalent PLMN that can serve all slices within the allowed NSSAI is also sent back to the UE. Figures 1a and 1b provide an example of TAI allocation to registration areas based on the set of S-NSSAIs authorized for the UE, where the set of TAIs consists of TAIs from the registered PLMN and the equivalent PLMN.

[0009] In the example of Figures 1a and 1b, if the network returns an allowed NSSAI of {S-NSSAI-1, S-NSSAI-2, S-NSSAI-3}, the returned TAI list is TA#3 (registered PLMN), TA#6 (EPLMN1), and TA#9 (EPLMN2). Furthermore, when the UE registers in the RPLMN and receives an allowed NSSAI, this allowed NSSAI is stored for the RPLMN and separately for each EPLMN. Thus, in the above example, the allowed NSSAI is stored for the RPLMN and separately for EPLMN1 and EPLMN2.

[0010] This is described in the 3GPP standard specification as shown in Table 1.

[0011] [Table 1]

[0012] The above description means that the UE can go ahead and directly use the authorized NSSAI in the equivalent PLMN (ePLMN) without explicitly requesting it. This can occur when a UE in 5GMM-CONNECTED mode with an RRC inactive indication reselects an ePLMN whose TAI is already in the UE's registration area. Since the TAI is already authorized, the UE does not need to register and can directly transition to connected mode with a service request procedure and then request a PDU session for the slice in the UE's authorized NSSAI (applicable to this ePLMN).

[0013] Network slice-specific authentication and authorization (NSSAA) overview

[0014] NSSAA was introduced as part of 3GPP Rel-16. This feature allows the network to perform slice-specific authentication and authorization for a set of S-NSSAIs to allow a user to access these slices. This procedure is performed after the 5GMM authentication procedure has been completed and after the registration procedure has been completed. A high-level description of this feature can be found in the 3GPP standard specifications, and further details can be found in the 3GPP standard specifications. The specific features of the NSSAA procedure are summarized below.

[0015] The NSSAA procedure is access independent. That is, if a slice is successfully authorized, the NSSAA procedure is considered authorized for both access types (i.e., 3GPP and non-3GPP access types). The term "authorized" means that slice-specific authentication / authorization was successful for a specific S-NSSAI. However, this does not mean that the S-NSSAI can be used in the UE's current tracking area (TA) via 3GPP access.

[0016] When the UE registers with the network, if available in the UE, the UE may include the requested NSSAI in the registration request message. The following describes the network behavior as specified in the 3GPP standard specifications, as shown in Table 2.

[0017] [Table 2] TIFF0007725503000003.tif71158

[0018] Due to the ongoing NSSAA, if a UE does not have an authorized NSSAI, the UE cannot receive services, with some exceptions. For example, as shown in Table 3, the 3GPP standard specification states:

[0019] [Table 3]

[0020] The NSSAA can be restarted at any time as specified in the 3GPP standard specification, as shown in Table 4.

[0021] [Table 4]

[0022] As is clear from the above, the pending NSSAI defined in the 3GPP standard specification is provided by the serving PLMN during the registration procedure and indicates the S-NSSAI for which network slice-specific authentication and authorization procedures are pending.

[0023] Total number of S-NSSAI: The number of Allowed NSSAIs (A-NSSAIs) and Denied NSSAIs cannot exceed eight; and The number of Pending NSSAIs (P-NSSAIs) and Configured NSSAIs (C-NSSAIs) cannot exceed 16.

[0024] Overview of 5GSM secondary authentication

[0025] The 5GSM secondary authentication procedure is defined in the 3GPP standard. It allows the data network (DN) to (re)authenticate and (re)authorize the upper layers of the UE when the UE establishes a PDU session. This procedure can be performed during or after the UE Request PDU Session procedure that establishes a non-urgent PDU session. This procedure is initiated by the SMF and involves the network authenticating the UE using the Extensible Authentication Protocol (EAP) specified in IETF RFC 3748. The 3GPP standard provides a detailed overview of the EAP message exchange related to 5GSM secondary authentication. The EAP message exchange occurs between the UE acting as an EAP client and the DN-AAA server acting as an EAP server.

[0026] The above information is presented as background information only to aid in the understanding of the present invention. No determination has been made, and no assertion is being made, as to whether any of the above is applicable as prior art with respect to the present invention. Summary of the Invention [Problem to be solved by the invention]

[0027] It is an object of the present invention to at least partially address, solve, and / or mitigate at least one of the problems and / or disadvantages associated with the related art, e.g., at least one of the problems and / or disadvantages described herein. It is an object of the present invention to provide at least one advantage over the related art, e.g., at least one of the advantages described herein.

[0028] The embodiments or examples disclosed in the detailed description and / or drawings of this specification should be understood as examples useful for understanding the present invention. Various aspects, advantages, and salient features will become apparent to those skilled in the art from the following detailed description, which, taken in conjunction with the drawings, discloses embodiments of the invention.

[0029] Before embarking on the detailed description below, definitions of certain words and phrases used throughout this specification are provided: the terms "include" and "comprise," and their derivatives, mean open-ended inclusion; the term "or" is inclusive and / or; the phrases "associated with" and "associated therewith," and their derivatives, mean include, be included within, interconnect with, contain, be contained within, connect to or with, couple to or with, be communicable with, cooperate with, interleave, juxtapose, be proximate to, be bound to or with, have a property of, and the like. The term "controller" means any device, system, or portion thereof that controls at least one operation, and such a device may be implemented in hardware, firmware, or software, or a combination of at least two of the same. It should be noted that the functionality associated with a particular controller may be centralized or distributed, whether locally or remotely.

[0030] Additionally, various functions described below may be implemented or supported by one or more computer programs, each comprised of computer-readable program code and embodied in a computer-readable medium. The terms "application" and "program" refer to one or more computer programs, software components, sets of instructions, procedures, functions, objects, classes, instances, associated data, or portions thereof adapted for implementation in suitable computer-readable program code. The phrase "computer-readable program code" includes all types of computer code, including source code, object code, and executable code. The phrase "computer-readable medium" includes any type of medium accessible by a computer, such as read-only memory (ROM), random-access memory (RAM), hard disk drive, compact disc (CD), digital video disc (DVD), or other type of memory. "Non-transitory" computer-readable medium excludes wired, wireless, optical, or other communication links transmitting transient electrical or other signals. Non-transitory computer-readable media include media that can permanently store data and media that can store data and be later overwritten, such as rewritable optical disks and erasable memory devices.

[0031] Definitions of certain words and phrases are provided throughout this specification, and those of skill in the art should understand that in many, if not most, cases, such definitions apply to prior as well as future uses of the words and phrases so defined. [Means for solving the problem]

[0032] To achieve the above object, one aspect of the present invention provides a method for a user equipment (UE) in a wireless communication system, wherein the UE is assigned to a registration area including two or more tracking areas (TAs), the TA including at least a first set of TAs belonging to a first public land mobile network (PLMN) to which the UE is registered, the method including: receiving, in response to performing a network slice specific authentication and authorization (NSSAA) procedure, a pending network slice selection assistance information (NSSAI) including one or more single network slice selection assistance information (S-NSSAI); and applying the received pending NSSAI to at least one second PLMN in the registration area if the two or more TAs include at least one second set of TAs belonging to at least one second PLMN corresponding to the first PLMN.

[0033] In order to achieve the above object, another aspect of the present invention provides a method for a user equipment (UE) in a wireless communication system, the method including the steps of: starting a back-off timer (e.g., T3396, T3584, T3585) in response to receiving a first message (e.g., a 5GSM message); receiving a second message (e.g., a PDU SESSION AUTHENTICATION COMMAND message) for an authentication procedure of the UE when establishing or joining a data session (e.g., a PDU session); stopping the back-off timer in response to the second message; and transmitting a third message (e.g., a PDU SESSION AUTHENICATION COMPLETE message) in response to the second message.

[0034] In order to achieve the above object, a method according to yet another aspect of the present invention is a method for a user equipment (UE) in a network, the method including the steps of determining that the UE does not have an authorized NSSAI, and initiating or executing a procedure if a condition is met, the condition including a procedure related to a predefined type of service, transmission of a predefined type of data, and / or transmission of a NAS message.

[0035] The conditions further include an indication that the procedure is supported and received (e.g., from an AMF entity) and that the procedure is initiated or performed by a predefined default behavior if the UE does not have an allowed NSSAI (e.g., the 5G-LCS bit in the 5GS Network Capability Support IE set to "Location services via 5GC supported"), optionally an indication that the procedure is allowed and received (e.g., from an AMF entity) if the UE does not have an allowed NSSAI (e.g., a predetermined bit in the 5GS Network Capability Support IE set to a first predetermined value), and / or optionally an indication that the procedure is not allowed and not received if the UE does not have an allowed NSSAI (e.g., a predetermined bit in the 5GS Network Capability Support IE set to a second predetermined value). [Effects of the Invention]

[0036] According to the present invention, a method and apparatus for performing network slice specific authentication and authorization (NSSAA) can be provided. [Brief explanation of the drawings]

[0037] [Figure 1a] 1 is a table illustrating an exemplary allocation of TAs to registration areas based on authorized NSSAIs. [Figure 1b] FIG. 1 illustrates the relationship between the TAI of a registration area and the authorized NSSAI. [Figure 2]1 is a flow diagram illustrating a problem associated with a back-off timer and a solution according to a specific example of the present invention. [Figure 3] FIG. 2 is a block diagram of exemplary network entities that may be used in certain examples of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0038] 1a-3 described below, and the various embodiments used herein to illustrate the principles of the present invention, are for illustrative purposes only and should not be construed as limiting the scope of the invention in any way. Those skilled in the art will understand that the principles of the present invention may be implemented in any suitably configured system or device.

[0039] The following detailed description of examples of the present invention, with reference to the drawings, is provided to facilitate a comprehensive understanding of the present invention. Although the detailed description includes various specific details to facilitate understanding, they should be considered as merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the examples described herein without departing from the technical scope of the present invention.

[0040] The same or similar components are indicated by the same or similar reference numbers, even though they may be shown in different drawings.

[0041] Detailed descriptions of techniques, structures, configurations, functions, or processes known in the art may be omitted for clarity and conciseness, and to avoid obscuring the gist of the present invention.

[0042] The terms and words used in this specification are not limited to their bibliographical or standard meanings, but are merely used to enable a clear and consistent understanding of the present invention.

[0043] As used herein, the words "comprise," "include," and "contain," and variations of the above words, such as "comprising" and "comprises," mean "including but not limited to" and are not intended to exclude (do not exclude) other features, elements, components, integers, steps, processes, operations, functions, properties, attributes, and / or groups thereof.

[0044] As used herein, singular forms such as "a," "an," and "the" include plural forms unless the context requires otherwise. For example, a reference to an "object" includes a reference to one or more of such objects.

[0045] As used herein, language of the general form "X for Y" (where Y is any action, process, operation, function, activity, or step, and X is any means for performing that action, process, operation, function, activity, or step) includes, but is not necessarily exclusive of, means for which X is particularly adapted, configured, or arranged to perform Y.

[0046] It is to be understood that any feature, element, component, integer, step, process, operation, function, characteristic, attribute, and / or group thereof described or disclosed in connection with a particular aspect, embodiment, or example of the invention is applicable to any other aspect, embodiment, or example described herein, unless separately compatible therewith.

[0047] Particular examples of the present invention provide methods, apparatus, and systems for performing authentication and authorization in a network. The following examples are applicable to 3GPP 5G and use terminology related to 3GPP 5G. For example, particular examples of the present invention provide methods, apparatus, and systems for performing NSSAA in 3GPP 5G. However, those skilled in the art will understand that the techniques disclosed herein are not limited to these examples or to 3GPP 5G, but may be applied to any suitable system or standard, for example, one or more existing and / or next-generation wireless communication systems or standards.

[0048] For example, the functionality and other features of various network entities disclosed herein may be applied to corresponding or equivalent entities or features in other communication systems or standards. Corresponding or equivalent entities or features may be considered entities or functions that perform the same or similar role, function, operation, or purpose within a network. For example, in the following examples, the functionality of the AMF may be applied to any other suitable type of entity that performs access and mobility management functions, and the functionality of the SMF in the following examples may be applied to any other suitable type of entity that performs session management functions.

[0049] Those skilled in the art will appreciate that the present invention is not limited to the specific examples disclosed herein. The techniques disclosed herein are not limited to 3GPP 5G; In the examples disclosed herein, one or more entities may be replaced by one or more alternative entities that perform equivalent or corresponding functions, processes, or operations; In the examples disclosed herein, one or more messages are replaced with one or more alternative messages, signals, or other types of information carriers that communicate equivalent or corresponding information; One or more additional elements, entities, and / or messages may be added to the examples disclosed herein; In certain instances, one or more non-essential elements, entities, and / or messages may be omitted; A function, process, or operation of a particular entity in one example may be divided into two or more separate entities in another example; The functions, processes, or actions of two or more separate entities in one example may be performed by a single entity in another example; Information carried by a particular message in one example may be carried by two or more separate messages in another example; Information conveyed by two or more separate messages in one example may be conveyed by a single message in another example; The order in which the operations are performed may be changed in other examples where possible; and The transmission of information between network entities is not limited to the particular formats, types, and / or ordering of messages described in connection with the examples disclosed herein.

[0050] Particular examples of the present invention may be provided in the form of an apparatus / device / network entity configured to perform one or more defined network functions and / or methods therefor. Particular examples of the present invention may be provided in the form of a system (e.g., a network) including one or more such apparatus / device / network entities and / or methods therefor. For example, in the following example, the network may include a UE, an AMF, and an SMF.

[0051] Considering the related art, at least the following problems exist:

[0052] 1. Handling of Pending and Permitted NSSAIs

[0053] As mentioned above, if a registration area includes TAIs belonging to different PLMNs that are equivalent PLMNs, the UE stores the received authorized NSSAIs separately for each of the registered PLMN and the equivalent PLMN. However, if the network performs the NSSAA at registration and sends a pending NSSAI back to the UE, the UE only needs to store this pending NSSAI for the registered PLMN only.

[0054] Observation 1: A UE may have a pending NSSAI stored only for an RPLMN, but may not have a pending NSSAI stored for an EPLMN.

[0055] When the allowed NSSAI is configured in S-NSSAI-1 and the UE performs a mobility and periodic registration update with the RPLMN that triggers an NSSAI with S-NSSAI-1, the AMF sends a pending NSSAI back to the UE including S-NSSAI-1, and the UE stores the pending NSSAI.

[0056] Observation 2: A UE can have a pending NSSAI for an unauthorized RPLMN and an S-NSSAI-1 stored in an authorized NSSAI at the same time.

[0057] Furthermore, if the TAI list of the registration area contains a PLMN corresponding to the registered PLMN, the RPLMN stores only the pending NSSAI but stores the allowed NSSAIs of the RPLMN and the EPLMN, so that the UE (5GMM-Connected mode with RRC-inactive indication) can perform cell reselection of the EPLMN and access the service of S-NSSAI-1 receiving the NSSAI.

[0058] Observation 3: If the S-NSSAI has received the NSSAA of the RPLMN, the UE can access the services of the S-NSSAI in the EPLMN.

[0059] 2. 5GSM Secondary Authentication stops the 5GSM back-off timer

[0060] 5GSM congestion control is specified in the 3GPP standard specifications. Three types of congestion control back-off timers are described. In the case of DNN-based congestion control, the SMF can request the UE to start the back-off timer T3396. In the case of S-NSSAI-based congestion control, the SMF can request the UE to start the back-off timer T3585. In the case of S-NSSAI and DNN-based congestion control, the SMF can request the UE to start the back-off timer T3584. Whenever the network sends a downlink NAS message and the back-off timer is running, the UE stops the back-off timer and processes the network-initiated message.

[0061] One problem is that the 3GPP standard specification does not mention stopping the back-off timer when the UE receives a PDU SESSION AUTHENTICATION COMMAND.

[0062] The top two-thirds of Figure 2 illustrates a problem related to the back-off (BO) timer. In step 1, the UE sends a message (e.g., a PDU session modification request) to the SMF. In step 2, the SMF experiences congestion. In step 3, the SMF sends a message (e.g., a PDU session modification reject) containing one or more BO timer indications to the UE. In step 4, the UE starts one or more corresponding BO timers. As shown in step 5, the UE cannot send messages while the BO timer is running. In step 6, the SMF becomes free of congestion. In step 7, the SMF sends a PDU session authentication command message to the UE. As shown in step 8, the UE cannot send a response to the PDU session authentication command message because the BO timer is running. Therefore, in step 9, the SMF retransmits the message of step 7. This causes a problem in that steps 7 to 9 are repeated multiple times, as shown in step 10, resulting in unnecessary signaling and potentially causing related procedures to fail.

[0063] 3. Current NSSAA procedures may block location services.

[0064] If the network does not provide the UE with an authorized NSSAI in the registration accept message, the UE is not expected to initiate a request to obtain a service, e.g., a service request, unless the service is related to an emergency service, or the UE is a high-priority UE, etc. This behavior is expected because the restriction to obtain a service is directly related to access to slices via the SMF.

[0065] However, there are certain services, such as location services, that the UE can obtain regardless of the slice. Therefore, the UE may be permitted to receive such services when an authorized NSSAI is not available. This behavior is now lost, so the UE cannot obtain location services that are not related to an NSSAI.

[0066] In view of the above problems, certain embodiments of the present invention provide one or more of the following solutions.

[0067] 1. Handling of Pending and Permitted NSSAIs

[0068] A particular example of the present invention stores pending NSSAIs for each of the equivalent PLMNs whose registration area includes TAIs from these equivalent PLMNs.

[0069] In a particular example of the present invention, when the UE stores a pending NSSAI, the UE removes any S-NSSAI in the pending NSSAI from the allowed NSSAI.

[0070] In a particular example of the present invention, the UE deletes the S-NSSAI from the stored allowed NSSAI for the PLMN corresponding to the registered PLMN.

[0071] In a particular example, if the registration area of the UE includes the TAI of the equivalent PLMN, the UE also applies the pending NSSAI to the equivalent PLMN.

[0072] In a particular example, if a registration area includes TAIs belonging to different PLMNs that are equivalent PLMNs, for each of the equivalent PLMNs, the UE may replace the stored pending NSSAI with the pending NSSAI received at the registered PLMN.

[0073] In a particular example, if a registration accept including a pending NSSAI is received and the registration area includes an equivalent PLMN, the UE may store the pending NSSAI of the equivalent PLMN.

[0074] Thus, in a particular example, when a UE receives a pending NSSAI from the network and stores the pending NSSAI for a registered PLMN (RPLMN), if the registration area includes TAIs belonging to different PLMNs that are equivalent PLMNs, the UE further stores the received pending NSSAI for each equivalent PLMN. If the UE does not store the pending NSSAI for the equivalent PLMN (but stores the allowed NSSAI for the EPLMN), the UE (e.g., in 5GMM-Connected mode with RRC-Inactive Indication) can perform cell reselection to the EPLMN and access the service for the S-NSSAI receiving the NSSAI.

[0075] 2. Stopping the 5GSM backoff timer due to 5GSM secondary authentication

[0076] Particular examples of the present invention operate in accordance with the normative conditions added to TS 24.501 to stop back-off timers T3396, T3584 and T3485 running in the UE when the UE receives a PDU SESSION AUTHENTICATION COMMAND.

[0077] In a particular example, for a 5GSM secondary authentication procedure, when the UE receives a PDU session authentication command, the UE stops the back-off timer if the back-off timer is running.

[0078] The bottom third of Figure 2 shows a solution according to a particular example of the invention. Steps 6 to 9 of the bottom third of Figure 2 replace steps 6 to 10 of the middle third of Figure 2. In step 6, the SMF becomes free of congestion. In step 7, the SMF sends a message (e.g., a PDU session authentication command message) to the UE. In step 8, the UE stops one or more BO timers. Therefore, in step 9, the UE sends a message (e.g., a PDU session authentication complete message) to the SMF to perform / complete the related procedures.

[0079] 3. Allow other services during NSSAA if authorized NSSAI is unavailable

[0080] Certain examples of the present invention allow other services, such as the transfer of location service messages or other types of containers during an NSSAA, even if an authorized NSSAI is not available.

[0081] A particular example of the present invention allows the AMF to control whether these services can be used when an authorized NSSAI is not available. The AMF may initially indicate that certain services cannot be used during the NSSAA if an authorized NSSAI is not available. When an authorized NSSAI is available, the AMF may trigger a registration procedure from the UE to indicate that these services can now be used.

[0082] Those skilled in the art will recognize that, for all techniques disclosed herein, the situation when an authorized NSSAI is not available may be understood to include the situation when a pending NSSAI is sent to the UE without a selectively authorized NSSAI.

[0083] A particular example of the present invention provides a method for a user equipment (UE) in a wireless communication system, the UE being assigned to a registration area including two or more tracking areas (TAs), the registration area including at least a first set of TAs belonging to a first public land mobile network (PLMN) to which the UE is registered, the method comprising: receiving, in response to a network slice specific authentication and authorization (NSSSAA) procedure, a pending network slice selection assistance information (NSSAI) including one or more single NSSAIs (S-NSSAIs); and if the two or more TAs include at least one second set of TAs belonging to at least one second PLMN corresponding to the first PLMN, the received pending NSSAI is applicable to at least one second PLMN in the registration area.

[0084] In a particular example, the received pending NSSAI may be applicable to a TA of at least one second PLMN that can serve one or more S-NSSAIs in the received pending NSSAI.

[0085] In a particular example, the method may further include storing the received pending NSSAI for each of the at least one second PLMN.

[0086] In a particular example, storing the pending NSSAI for each of the at least one second PLMN may include replacing a previously stored pending NSSAI with the received pending NSSAI for each of the at least one second PLMN.

[0087] In a particular example, the pending NSSAI may be received in a NAS message (eg, a REGISTRATION ACCEPT message).

[0088] In a particular example, the received pending NSSAI may be applicable to the first PLMN (e.g., further including storing the received pending NSSAI for the first PLMN).

[0089] In a particular example, the method includes receiving an allowed NSSAI including one or more S-NSSAIs, and if the two or more TAs include at least one second set of TAs belonging to at least one second PLMN corresponding to the first PLMN, the received allowed NSSAI is applicable to each of the first PLMN and the at least one second PLMN in the registration area.

[0090] In certain examples, the method may further include storing the received allowed NSSAI for each of the first PLMN and the at least one second PLMN.

[0091] In a particular example, the method may further include receiving a set of TAs that can provide service to all S-NSSAIs within the allowed S-NSSAI.

[0092] In a particular example, the set of received TAs may include one or more TAs of a first PLMN and one or more TAs of at least one second PLMN. A particular example of the present invention provides a method for a user equipment (UE) in a wireless communication system, the method including: starting a back-off timer (e.g., T3396, T3584, T3585) in response to receiving a first message (e.g., a 5GSM message); receiving a second message (e.g., a PDU session authentication command message) of a procedure for authenticating the UE when establishing or joining a data session (e.g., a PDU session); stopping the back-off timer in response to the second message; and transmitting a third message (e.g., a PDU SESSION AUTHENICATION COMPLETE message) in response to the second message.

[0093] In a particular example, stopping the back-off timer may include stopping a timer (e.g., T3584) if the timer is running for the same [S-NSSAI, DNN] combination provided by the UE when the UE provided a single Network Slice Selection Assistance Information (S-NSSAI) and Data Network Name (DNN) during PDU session establishment.

[0094] In a particular example, stopping the backoff timer may include stopping a timer (e.g., T3584) if the UE did not provide an S-NSSAI during PDU session establishment and the timer is running for the same [no S-NSSAI, DNN] combination provided by the UE.

[0095] In a particular example, stopping the backoff timer may include stopping a timer (e.g., T3584) if the UE did not provide a DNN during PDU session establishment and the timer is running for the same [S-NSSAI, no DNN] combination provided by the UE.

[0096] In a particular example, stopping the backoff timer may include stopping a timer (e.g., T3584) if it is running for the same [no S-NSSAI, DNN] combination provided by the UE if the UE did not provide an S-NSSAI during PDU session establishment.

[0097] In a particular example, stopping the backoff timer may include, if the UE provided a data network name (DNN) during PDU session establishment, stopping a timer (e.g., T3396) if the timer is running for the DNN provided by the UE.

[0098] In a particular example, stopping the backoff timer may include stopping a timer (e.g., T3396) not associated with the DNN if the timer (e.g., T3396) is running if the UE did not provide a DNN during PDU session establishment.

[0099] In a particular example, stopping the backoff timer may include, if the UE provided an S-NSSAI during PDU session establishment, stopping a timer (e.g., T3585) if the timer is running for the S-NSSAI provided by the UE.

[0100] In a particular example, the step of stopping the backoff timer may include stopping a timer (e.g., T3585) not associated with the S-NSSAI if the timer (e.g., T3585) is running if the UE did not provide the S-NSSAI during PDU session establishment.

[0101] In a particular example, stopping the backoff timer may include stopping a timer (e.g., T3396) corresponding to a DNN that the UE considers associated with the PDU session if the timer (e.g., T3396) is running if the UE did not provide a DNN.

[0102] In a particular example, the UE may consider a DNN to be associated with a PDU session based on a value (e.g., a DNN value) returned by a network entity (e.g., an SMF entity) in a message (e.g., a PDU Session Establishment Accept message or a PDU Session Modification Accept message).

[0103] In a particular example, stopping the back-off timer may include stopping a timer (e.g., T3584) corresponding to the [S-NSSAI, DNN] combination that the UE considers to be associated with the PDU session if the timer (e.g., T3584) is running when the UE has not provided the [S-NSSAI, DNN] combination.

[0104] In a particular example, the UE may consider that the [S-NSSAI, DNN] combination is associated with a PDU session based on a value (e.g., an [S-NSSAI, DNN] combination value) returned by a network entity (e.g., an SMF entity) in a message (e.g., a PDU Session Establishment Accept message or a PDU Session Modification Accept message).

[0105] In a particular example, stopping the backoff timer may include stopping a timer (e.g., T3585) corresponding to an S-NSSAI that the UE considers to be associated with the PDU session if the timer (e.g., T3585) is running if the UE did not provide an S-NSSAI.

[0106] In certain examples, the UE may consider the S-NSSAI to be associated with a PDU session based on a value (e.g., the S-NSSAI value) returned by a network entity (e.g., an SMF entity) in a message (e.g., a PDU Session Establishment Accept message or a PDU Session Modification Accept message), or based on a value (e.g., the S-NSSAI value) that is considered to be associated with the PDU session after the VPLMN moves to the target 5GS system.

[0107] In a particular example, the procedure for authenticating the UE may include 5GSM secondary authentication.

[0108] In certain instances, stopping the backoff timer is not transparent to the 5GSM layer of the UE.

[0109] A particular example of the present invention provides a method for a user equipment (UE) in a network, the method comprising the steps of determining that the UE does not have an authorized NSSAI, and initiating or performing a procedure if conditions are met, the conditions including that the procedure relates to a service of a predefined type, transmission of data of a predefined type, and / or transmission of a NAS message.

[0110] In a particular example, the method may further include receiving a message (e.g., a NAS message) from a network entity (e.g., an AMF entity), which is one or more of the following: the message is received during an NSSAA procedure; the message is a registration accept message; the message indicates that an NSSAA is being performed; the message does not include an authorized NSSAI; and the message includes a pending NSSAI.

[0111] In certain examples, the step of initiating or executing the above procedure may include sending a Service Request message, a Control Plane Service Request message, or a NAS message (e.g., a UL NAS TRANSPORT message) (e.g., to an AMF entity).

[0112] In certain examples, the conditions may further include an indication that the procedure is supported and received (e.g., from an AMF entity) and that if the UE does not have an allowed NSSAI, the procedure is allowed to be initiated or executed by a predefined default behavior (e.g., the 5G-LCS bit in the 5GS Network Capability Support IE set to "Location Services via 5GC Supported"); optionally, an indication that the procedure is allowed and received (e.g., from an AMF entity) if the UE does not have an allowed NSSAI (e.g., the pre-determined bit in the 5GS Network Capability Support IE set to a first pre-determined value); and / or optionally, an indication that the procedure is allowed and not received if the UE does not have an allowed NSSAI (e.g., the pre-determined bit in the 5GS Network Capability Support IE set to a second pre-determined value).

[0113] In certain examples, the predefined type of service may be a service that is not associated with a PDU session, and / or the predefined type of data may be data that is not associated with a PDU session.

[0114] In a particular example, the predefined type of service may include a location service.

[0115] In certain examples, the predefined type of data may include one or more of an SMS; an LPP message; an SOR transparent container; a predefined type container; or a UE parameter update transparent container.

[0116] In a particular example, the condition may further include that a message (e.g., a DL NAS transport message) related to the procedure (e.g., sending a UL NAS transport message) is received from a network entity (e.g., an AMF entity).

[0117] In a particular example, the method may further include receiving an authorized NSSAI from a network entity (e.g., an AMF entity); receiving one or more messages from the network entity (e.g., an AMF entity); and performing a registration procedure to initiate or execute the above procedure in response to receiving at least a first message (e.g., a Configuration Update Command) (e.g., from the AMF entity).

[0118] In a particular example, the first message may include an indication that registration is requested.

[0119] In certain examples, the one or more messages may include a second message (eg, a Registration Accept message).

[0120] In certain examples, at least one of the above messages (e.g., the first message or the second message) may include an indication that the procedure is allowed, available, and / or supported.

[0121] In a particular example, the permitted NSSAI may be received in at least one of the above messages (eg, the first message or the second message).

[0122] A particular example of the present invention provides a method for a network entity (e.g., an AMF entity) in a network including the entity and a user equipment (UE), the method comprising: determining that the UE does not have an authorized NSSAI; and, if the UE does not have an authorized NSSAI, sending a first message to the UE indicating whether a particular procedure is authorized, available, or supported, the procedure relating to a service of a predefined type, transmission of data of a predefined type, and / or transmission of a NAS message.

[0123] In a particular example, the first message may indicate that the procedure is not allowed, is not available, and / or is not supported if the UE does not have an allowed NSSAI.

[0124] In certain examples, the method may further include determining that the UE has an allowed NSSAI and transmitting one or more messages including a second message indicating that the procedure is allowed, available, and / or supported.

[0125] In a particular example, the one or more messages may include a message (e.g., a Configuration Update Command message) to trigger the UE to perform a registration procedure to initiate or perform the above procedure.

[0126] In a particular example, the method may further include transmitting the authorized NSSAI to the UE.

[0127] In a particular example, the allowed NSSAI may be transmitted to the UE in a second message.

[0128] Particular examples of the present invention provide a first network entity (e.g., a UE, an AMF entity, and / or an SMF entity) configured to operate according to a method according to any example, embodiment, and / or aspect disclosed herein.

[0129] Particular examples of the present invention provide a second network entity (e.g., a UE, an AMF entity, and / or an SMF entity) configured to cooperate with a first network entity of any example, embodiment, aspect disclosed herein, and / or any of the examples described above.

[0130] Particular examples of the present invention provide a network (or wireless communication system) including a UE and one or more additional network entities according to any example, embodiment, and / or aspect disclosed herein.

[0131] Particular examples of the present invention provide a computer program comprising instructions that, when executed by a computer or processor, cause the computer or processor to perform a method according to any example, embodiment, and / or aspect disclosed herein.

[0132] A particular example of the invention provides a computer or processor readable data carrier having stored thereon a computer program according to the above examples.

[0133] A specific example of the invention will now be described in more detail.

[0134] 1. Handling of Pending and Permitted NSSAIs

[0135] To address the problem described in Observation 1 above, certain examples of the present invention store a pending NSSAI for each of the equivalent PLMNs whose registration area is composed of TAIs from these equivalent PLMNs. To address the problem described in Observation 3 above, certain examples of the present invention also delete the S-NSSAI from the stored allowed NSSAIs of the registered equivalent PLMNs. In such a case, when the UE receives a registration accept with the current PLMN that contains the pending NSSAI, for each of the equivalent PLMNs, the UE may replace any stored pending NSSAI with the pending NSSAI received with the registered PLMN, and delete the S-NSSAI included in the pending NSSAI, if present, from the stored allowed NSSAI for each access type and for all access types. For example:

[0136] Regarding Observation 1, particular examples of the present invention operate in accordance with normative statement 1) added to the 3GPP standard specification, as set forth below; and

[0137] Regarding Observation 3, particular examples of the present invention operate in accordance with normative statement 2) added to the 3GPP standard specification, as shown in Table 5.

[0138] [Table 5]

[0139] To address the problem described in Observation 2 above, in certain examples of the present invention, when the UE stores a pending NSSAI, the UE removes any S-NSSAI in the pending NSSAI from the allowed NSSAI. For example, certain examples of the present invention operate in accordance with normative statement 2) added to the 3GPP standard specification, as shown in Table 6 below.

[0140] [Table 6]

[0141] Particular examples of the present invention operate according to the modified subsections set forth above.

[0142] In the above, those skilled in the art will understand that if an NSSAI (e.g., a pending NSSAI or an allowed NSSAI) is applicable to PLMNs in a registration area, this may be considered equivalent to applying the pending NSSAI to the PLMNs of the registration area; or considering the pending NSSAI to be applicable to the PLMNs of the registration area. If an NSSAI (e.g., a pending NSSAI or an allowed NSSAI) is applicable to a PLMN or at least two PLMNs, the NSSAI may be stored for the PLMN or each PLMN.

[0143] Those skilled in the art will recognize that the pending NSSAI may be received in any suitable type of message, for example, the pending NSSAI is not limited to a REGISTRATION ACCEPT message and may be received in any NAS message.

[0144] 2.5GSM Secondary Authentication Stops 5GSM Backoff Timer

[0145] To address the issue of the UE stopping the back-off timer upon receipt of the above-mentioned PDU SESSION AUTHENTICATION COMMAND, certain examples of the present invention operate in accordance with the normative statements introduced in the 3GPP standard specification, as shown in Table 7 below.

[0146] [Table 7] TIFF0007725503000009.tif242159TIFF0007725503000010.tif63158

[0147] Particular examples of the present invention operate according to the modified subsection above.

[0148] 3. Allow other services during NSSAA, e.g. location services

[0149] In a particular example of the present invention, during any NSSAA procedure, if the UE receives any NAS message, for example a Registration Accept message, optionally with an "NSSAA performed" indicator set to "network slice specific authentication and authorization will be performed", and optionally without an allowed NSSAI, and optionally with a pending NSSAI, the UE determines that it can initiate an associated NAS procedure to send a location services message if the "5G-LCS" bit in the 5GS network feature support IE is set to "Location services via 5GC supported".

[0150] Thus, in a particular example of the present invention, if during an NSSAA the UE does not have an authorized NSSAI, the UE may be permitted to initiate a UE-initiated NAS transport procedure (i.e., be permitted to send a UL NAS transport message) for the purpose of sending a location service message. Similarly, in a particular example of the present invention, the UE may be permitted to initiate a service request procedure (i.e., be permitted to send a service request message or a control plane service request message) for the purpose of sending a location service message.

[0151] The above techniques are only applicable to other types of data that the UE can send in UL NAS transport messages, such as, but not limited to, SMS, LPP messages, SOR transparent containers, UE parameter update transparent containers, or other suitable types of containers.

[0152] More generally, in certain examples of the present invention, for any service or data not related to a PDU session, a UE may be permitted to initiate a service request procedure (e.g., by sending a Service Request message or a control plane Service Request message) to transmit the associated data or container (e.g., as listed above) even if the UE does not have an authorized NSSAI. Similarly, in certain examples of the present invention, a UE may be permitted to initiate a UE-initiated NAS transport procedure (e.g., by sending a UL NAS Transport message) to transmit the associated data or container (e.g., as listed above) even if the UE does not have an authorized NSSAI.

[0153] If the allowed NSSAI is not available to the UE, based on network policy, the AMF may not want the UE to use any other services, even if the other services are not associated with the slice. To enable this, certain examples of the present invention may apply one or more of the following techniques: The services may be any of SMS, location services, etc., or a combination of such services.

[0154] For services for which there is no means to exchange capabilities or negotiate support between the UE and the network, the default behavior may be fixed such that such services are allowed, or such services are not allowed, or such services may be allowed for the UE only if the UE receives the associated service (or messages) in a DL NAS transport message, and the UE may be allowed to respond to said service by sending associated data in a UL NAS transport message.

[0155] For example, if the UE receives a DL NAS transport message containing a UE Parameter Update Transparent Container, the UE Parameter Update Transparent Container, etc., is allowed to be sent by the UE in a UL NAS transport message.

[0156] Those skilled in the art will understand that the UE Parameter Update Transparent Container is used only as an example and that the techniques disclosed herein may be applied to other types of services or containers transmitted using NAS transport procedures.

[0157] For services that are only used after a feature or support indication has been negotiated between the UE and the network, e.g., SMS, location services, the UE determines whether or not it can send these services (even if an authorized NSSAI has not been received) based on what the network indicates for the corresponding services (or bit positions) in the 5GS network feature support IE.

[0158] In a specific example of the present invention, if the policy of the AMF is such that a service is not used when the UE does not have an authorized NSSAI, the AMF indicates that the service is not authorized or not supported in a corresponding bit of the appropriate IE in the registration accept message. For example, if the AMF does not want the UE to use location services when it cannot provide the UE with an authorized NSSAI for the NSSAI, the AMF sets the "5G-LCS" bit of the 5GS Network Capability Support IE to "Location services via 5GC not supported". The same operations and techniques can be used for other services, such as SMS, noting that another bit (i.e., the "SMS allowed" bit) in the corresponding IE (i.e., the 5GS Registration Result IE) must be set to an appropriate value (e.g., "SMS over NAS not allowed").

[0159] When the authorized NSSAI becomes available to the UE, the AMF uses a configuration update command message to trigger a registration procedure from the UE in 5GMM-Connected mode (referred to as Connected Mode) so that the corresponding service is authorized when the authorized NSSAI becomes available.

[0160] The AMF also selectively indicates "Registration Request" with the "RED" bit of the Configuration Update Indication IE. The AMF indicates that the registration procedure can be performed by the UE using the existing NAS signaling connection, i.e., without releasing the NAS signaling connection (or waiting for the network to release it). For example, the AMF uses a Signaling Connection Maintenance Request (SCMR) bit to set the SCMR bit to 1, thereby indicating that "release of the N1 NAS signaling connection is not required." Based on this, the UE performs the registration procedure in connected mode, i.e., using the current NAS signaling connection (without releasing the NAS signaling connection or waiting for the network to release the NAS signaling connection). When sending the registration request, the UE requests all services that it needs to use, e.g., SMS, location services, etc., by setting appropriate bits in the 5GMM Capabilities IE (e.g., "5G-LCS" may be set to indicate "LCS notification mechanism supported") and / or the 5GS Update Type IE (e.g., request the use of SMS by setting "SMS Requested" accordingly).

[0161] For example, if the AMF did not allow the use of SMS when an allowed NSSAI was not available, and if the AMF wants to allow the UE to use SMS provided that an allowed NSSAI is available, the AMF may send a Configuration Update Command message and include an SMS Indication IE with an SMS availability indication set to "SMS over NAS available". Optionally, the AMF performs the above action when sending the allowed NSSAI to the UE in the Configuration Update Command message. The AMF may optionally indicate "registration requested" with a "RED" bit in the Configuration Update Indication IE.

[0162] If the authorized NSSAI is not available and the AMF has not authorized another service, such as the forwarding or transport of location service messages, when the AMF is currently attempting to authorize the use of that service, the AMF shall send a configuration update command message to the UE using one or more of the following:

[0163] 1. The message indicates a "Registration Request" with the "RED" bit in the Configuration Update Indication IE.

[0164] 2. This message indicates another IE that can also be used to trigger the registration procedure from connected mode without releasing the NAS signaling connection. For this purpose, an existing or new IE containing relevant information or bits is used.

[0165] 3. Alternatively, the above actions may be performed by the AMF when sending the new allowed NSSAI in a Configuration Update Command message (i.e., the above actions or instructions may be performed in the same message that delivers the new allowed NSSAI).

[0166] 4. Optionally, the AMF indicates using a bit whether there has been an update regarding the use of a particular service (or data type) by the network; for example, an update means that a particular service (or data type) is allowed or not allowed. A new bit may be defined for each service (e.g., location service message, LPP, UE policy container, etc.), and this new bit may be defined in a new or existing IE. The AMF sets the corresponding bit to indicate whether the network's permission for service usage has changed (e.g., from not allowed to allowed, or vice versa). Based on this indication, selectively via at least one bit, for a particular service or data type, the bit is used as described above, and the UE performs a registration procedure (i.e., sends a registration request message) to request the UE for the particular service represented by the bit in question. The UE sends this registration via an NAS message indicating that (re)registration is requested, where, optionally, the (re)registration is performed by the UE using the existing NAS connection, i.e., for the purpose of (re)registration by the UE, the UE does not tear down the connection.

[0167] Alternatively, the AMF achieves the above by not providing a new authorized NSSAI using a Configuration Update Command message. The AMF uses one of the above actions to first trigger a registration procedure from the UE in connected mode, and then provides a new authorized NSSAI in a registration accept message. In the registration accept message, the AMF indicates which services the UE is currently authorized to use, assuming that an authorized NSSAI is available. Thus, relevant bits in relevant IEs are set to indicate that, for example, SMS or location service messages can currently be used.

[0168] Those skilled in the art will appreciate that the above techniques may be used in any suitable combination.

[0169] Figure 3 is a block diagram of exemplary network entities that may be used in examples of the present invention. For example, a UE, an AMF, an SMF, and / or any other suitable network entities may be provided in the form of the network entities shown in Figure 3. Those skilled in the art will understand that the network entities shown in Figure 3 may be implemented, for example, as network elements on dedicated hardware, as software instances running on dedicated hardware, or as virtualized functions instantiated on a suitable platform, for example, on a cloud infrastructure.

[0170] The entity 300 includes a processor (or controller) 301, a transmitter 303, and a receiver 305. The receiver 305 is configured to receive one or more messages or signals from one or more other network entities. The transmitter 303 is configured to transmit one or more messages or signals to one or more other network entities. The processor 301 is configured to perform one or more operations and / or functions as described above. For example, the processor 301 may be configured to perform operations of a UE, an AMF, and / or an SMF.

[0171] The techniques described herein can be implemented using any suitably configured device and / or system. Such a device and / or system can be configured to perform a method according to any aspect, embodiment, or example disclosed herein. Such a device can include one or more elements, such as one or more of a receiver, transmitter, transceiver, processor, controller, module, unit, etc., each configured to perform one or more corresponding processes, operations, and / or methods for implementing the techniques described herein. For example, an operation / function of X can be performed by a module configured to perform X (or an X module). One or more elements can be implemented in hardware, software, or any combination of hardware and software.

[0172] It is to be understood that examples of the present invention can be implemented in the form of hardware, software, or any combination of hardware and software, any of which software can be stored in the form of volatile or non-volatile storage, whether erasable or rewritable, such as ROM, or memory, such as RAM, memory chips, devices, or integrated circuits, or on an optically or magnetically readable medium, such as a CD, DVD, magnetic disk, or magnetic tape.

[0173] It will be understood that the storage devices and storage media are embodiments of machine-readable storage devices suitable for storing programs including instructions that, when executed, implement particular examples of the present invention. Accordingly, particular examples provide programs including code for implementing a method, apparatus, or system according to any example, embodiment, and / or aspect disclosed herein, and / or machine-readable storage devices for storing such programs. Furthermore, such programs may be transmitted electronically over any medium, such as communication signals conveyed over wired or wireless connections.

[0174] Although the present invention has been described in various embodiments, various changes and modifications may be suggested to those skilled in the art. [Explanation of symbols]

[0175] 300 entities 301 processor 303 Transmitter 305 Receiver

Claims

1. 1. A method for communication by a user equipment (UE) in a wireless communication system, comprising: The method comprises: sending a registration request message to an access and mobility management function (AMF); Receiving a registration accept message from the AMF, the registration accept message including a pending Network Slice Selection Assistance Information (NSSAI) associated with the registration area; and if the registration area includes multiple Tracking Area Identifiers (TAIs) belonging to different equivalent public land mobile networks (PLMNs), storing the pending NSSAI for each of the equivalent PLMNs.

2. 2. The method of claim 1, wherein the pending NSSAI includes one or more single network slice selection assistance information (S-NSSAI).

3. 3. The method of claim 2, wherein the pending NSSAI is applicable to a Tracking Area (TA) of at least one PLMN that serves the one or more S-NSSAIs in the pending NSSAI.

4. 2. The method of claim 1, wherein for each of the equivalent PLMNs, storing the pending NSSAI includes replacing any stored pending NSSAI with the pending NSSAI received in the registration accept message.

5. 1. A user equipment (UE) in a wireless communication system, comprising: The UE A transceiver; a processor connected to the transceiver; The processor: Sending a registration request message to an access and mobility management function (AMF); Receive a registration accept message from the AMF, the registration accept message including a pending network slice selection assistance information (NSSAI) associated with the registration area; 10. The UE according to claim 9, wherein if the registration area includes a plurality of tracking area identifiers (TAIs) belonging to different equivalent public land mobile networks (PLMNs), the UE is configured to store the pending NSSAI for each of the equivalent PLMNs.

6. 6. The UE of claim 5, wherein the pending NSSAI includes one or more single network slice selection assistance information (S-NSSAI).

7. 7. The UE of claim 6, wherein the pending NSSAI is applicable to a tracking area (TA) of at least one PLMN that serves the one or more S-NSSAIs in the pending NSSAI.

8. 6. The UE of claim 5, wherein for each of the equivalent PLMNs, the processor for storing the pending NSSAI is configured to replace any stored pending NSSAI with the pending NSSAI received in the registration accept message.