Method of UE, geographically selected AMF device, UE, and geographically selected AMF device
By initiating a registration procedure with integrity-protected NAS containers for both 3GPP and non-3GPP access, the UE context transfer between AMFs is successfully managed, addressing the issue of service loss during mobility.
Patent Information
- Application Number
- JP2024521291
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-10-22
- Filing Date
- 2022-10-12
- Publication Date
- 2025-10-22
- Estimated Expiration
- 2042-10-12
AI Technical Summary
When a user equipment (UE) moves from a non-geographically selected AMF to a geographically selected AMF, there is a risk of losing service due to the geographically selected AMF's inability to obtain the UE context, which can result from a mismatch in NAS security contexts.
The UE initiates a registration procedure by transmitting a registration request message that includes integrity-protected NAS containers using different NAS security contexts for 3GPP and non-3GPP access, allowing the geographically selected AMF to perform a UE context transfer with the non-geographically selected AMF.
Ensures successful transfer of UE context between AMFs, maintaining service continuity during mobility by ensuring integrity protection and context transfer even when NAS security contexts differ.
Smart Images

Figure 0007758175000001 
Figure 0007758175000002 
Figure 0007758175000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a method for a UE, a method for a geographically selected AMF device, a UE, a geographically selected AMF device, and a method for a communication terminal. [Background technology]
[0002] When a UE is registered to a PLMN via 3GPP access and non-3GPP access, the UE is registered to the same AMF. When a UE is registered to two different PLMNs via 3GPP access and non-3GPP access, the UE is registered to two different AMFs belonging to different PLMNs. The UE and the network maintain two independent 5GMM contexts and two independent 5GSM contexts, i.e., the UE and the network maintain a 5GMM context and a 5GSM context for 3GPP access, and a 5GMM context and a 5GSM context for non-3GPP access. Services accessed via one access (e.g., 3GPP access) are independent from services accessed via another access (e.g., non-3GPP access). During a mobility procedure when a UE moves from one registration area (e.g., an old registration area) to another registration area (e.g., a new registration area) or from one PLMN (e.g., an old PLMN) to another PLMN (e.g., a new PLMN), the UE context (e.g., a 5GMM context or a 5GSM context) is transferred from the old AMF providing the old registration area to the new AMF providing the new registration area when the integrity check of the NAS container transferred from the new AMF to the old AMF is successfully performed in the old AMF.
[0003] If the UE is registered to a PLMN only via non-3GPP access, the N3IWF may select a non-geographically selected AMF. Based on the operator's policy, the GUAMI of the assigned 5G-GUTI indicates whether the PLMN is served by a non-geographically selected AMF or a geographically selected AMF. If the UE initiates a registration procedure via 3GPP access while the UE is registered to a non-geographically selected AMF via non-3GPP access, mobility from a non-geographically selected AMF to a geographically selected AMF is performed. In this case, for example, during an RRC connection establishment procedure, the UE sends an RRC setup complete message to the NG-RAN, including a NAS registration request message that includes the 5G-GUTI. The NAS registration request message may be referred to as a registration request message in this specification. If the NG-RAN receives the 5G-GUTI and determines that the 5G-GUTI indicates a non-geographically selected AMF, the NG-RAN directs (or sends) a registration request message to the geographically selected AMF. In this case, the geographically selected AMF initiates a UE context transfer procedure with the non-geographically selected AMF. After the UE context transfer procedure is successfully performed with the geographically selected AMF, the UE is registered with the geographically selected AMF via both 3GPP access and non-3GPP access. [Prior art documents] [Non-patent literature]
[0004] [Non-Patent Document 1] 3GPP TR 21.905: "Vocabulary for 3GPP Specifications". V16.0.0 (2019-06) [Non-patent document 2] GSM Association Official Document NG.116: “Generic Network Slice Template” V2.0 (2019-10) - https: / / www.gsma.com / newsroom / wp-content / uploads / NG.116-v2.0.pdf [Non-patent document 3] 3GPP TS 23.501: "System architecture for the 5G System (5GS)". V17.2.0 (2021-09) [Non-patent document 4] 3GPP TS 23.502: "Procedures for the 5G System (5GS)". V17.2.0 (2021-09). [Non-Patent Document 5] 3GPP TS 33.501: “Security architecture and procedures for 5G system” v 17.3.0 (2021-09) Summary of the Invention [Problem to be solved by the invention]
[0005] When a UE moves from one PLMN to another and mobility occurs from a non-geographically selected AMF to a geographically selected AMF, the geographically selected AMF may not be able to obtain the UE context, which may result in a loss of service. [Means for solving the problem]
[0006] According to an aspect of the present disclosure, a method in a user equipment (UE) includes initiating a registration procedure. The method includes transmitting a registration request message. The registration request message includes a first 5G Globally Unique Temporary Identifier (5G-GUTI), a first Non-Access-Stratum (NAS) container, a second 5G-GUTI, and a second NAS container. The first NAS container includes a first integrity-protected registration request message. The first integrity-protected registration request message is a registration request message integrity-protected based on a first NAS security context. The second NAS container includes a second integrity-protected registration request message. The second integrity-protected registration request message is a registration request message integrity-protected based on a second NAS security context.
[0007] According to an aspect of the present disclosure, a method in a geographically selected Access and Mobility Management Function (AMF) device includes receiving a registration request message. The registration request message includes a first 5G Globally Unique Temporary Identifier (5G-GUTI), a first Non-Access-Stratum (NAS) container, a second 5G-GUTI, and a second NAS container. The first NAS container includes a first integrity-protected registration request message, integrity-protected based on a first NAS security context. The second NAS container includes a second integrity-protected registration request message, integrity-protected based on a second NAS security context. The method includes transmitting a first Namf_Communication_UEContextTransfer message. The first Namf_Communication_UEContextTransfer message includes the first 5G-GUTI and the first integrity-protected registration request message. The method includes receiving a first Namf_Communication_UEContextTransfer response message, the first Namf_Communication_UEContextTransfer response message including a first user equipment (UE) context associated with the first 5G-GUTI. The method includes transmitting a second Namf_Communication_UEContextTransfer message, the second Namf_Communication_UEContextTransfer message including the second 5G-GUTI and the second integrity-protected registration request message. The method includes receiving a second Namf_Communication_UEContextTransfer response message, the second Namf_Communication_UEContextTransfer response message including a second UE context associated with the second 5G-GUTI.
[0008] According to an aspect of the present disclosure, a user equipment (UE) comprises means for initiating a registration procedure. The user equipment comprises means for transmitting a registration request message. The registration request message includes a first 5G Globally Unique Temporary Identifier (5G-GUTI), a first Non-Access-Stratum (NAS) container, a second 5G-GUTI, and a second NAS container. The first NAS container includes a first integrity-protected registration request message. The first integrity-protected registration request message is a registration request message integrity-protected based on a first NAS security context. The second NAS container includes a second integrity-protected registration request message. The second integrity-protected registration request message is a registration request message integrity-protected based on a second NAS security context.
[0009] According to an aspect of the present disclosure, a geographically selected access and mobility management function (AMF) device comprises means for receiving a registration request message. The registration request message includes a first 5G Globally Unique Temporary Identifier (5G-GUTI), a first Non-Access-Stratum (NAS) container, a second 5G-GUTI, and a second NAS container. The first NAS container includes a first integrity-protected registration request message, integrity-protected based on a first NAS security context. The second NAS container includes a second integrity-protected registration request message, integrity-protected based on a second NAS security context. The geographically selected access and mobility management function device comprises means for transmitting a first Namf_Communication_UEContextTransfer message. The first Namf_Communication_UEContextTransfer message includes the first 5G-GUTI and the first integrity-protected registration request message. The geographically selected access and mobility management function device comprises means for receiving a first Namf_Communication_UEContextTransfer response message. The first Namf_Communication_UEContextTransfer response message includes a first user equipment (UE) context associated with the first 5G-GUTI. The geographically selected access and mobility management function device comprises means for transmitting a second Namf_Communication_UEContextTransfer message. The second Namf_Communication_UEContextTransfer message includes the second 5G-GUTI and the second integrity-protected registration request message. The geographically selected access and mobility management function device comprises means for receiving the second Namf_Communication_UEContextTransfer response message.The second Namf_Communication_UEContextTransfer response message includes a second UE context associated with a second 5G-GUTI.
[0010] According to an aspect of the present disclosure, a method for a communications terminal includes registering a first access with a first Public Land Mobile Network (PLMN). The method includes storing, in the first PLMN, a first temporary identifier and a first Network Access Stratum (NAS) container for the first access associated with a first core network device. The method includes registering with a second PLMN via a second access. The method includes registering with the second PLMN via the second access, and then registering with the second PLMN via the first access. The method includes storing, in the second PLMN, a second temporary identifier and a second NAS container for the second access associated with a geographically selected core network device. The method includes transmitting the first temporary identifier, the first NAS container, the second temporary identifier, and the second NAS container to the geographically selected core network device. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 1 is a signaling diagram of a first aspect (mobility procedure involving an AMF change from a non-geographically selected AMF to a geographically selected AMF). [Figure 2] FIG. 2 is a signaling diagram of the second aspect (joint registration procedure of a UE for 3GPP and non-3GPP access). [Figure 3] FIG. 3 is a signaling diagram of a third aspect (registration procedure to a PLMN that does not support simultaneous registration procedure via 3GPP access and non-3GPP access). [Figure 4] Figure 4 is a signaling diagram of the fourth aspect (registration procedure with AMF relocation). [Figure 5]FIG. 5 is a diagram showing an outline of the system. [Figure 6] FIG. 6 is a block diagram illustrating a user equipment (UE). [Figure 7] FIG. 7 is a block diagram of an (R)AN node. [Figure 8] FIG. 8 is a diagram illustrating a system overview of an (R)AN node based on the O-RAN architecture. [Figure 9] FIG. 9 is a block diagram showing a Radio Unit (RU). [Figure 10] FIG. 10 is a block diagram illustrating a Distributed Unit (DU). [Figure 11] FIG. 11 is a block diagram showing a Centralized Unit (CU). [Figure 12] FIG. 12 is a block diagram illustrating the Access and Mobility Management Function (AMF). [Figure 13] FIG. 13 is a block diagram illustrating Unified Data Management (UDM). [Figure 14] FIG. 14 is a diagram showing the registration procedure. [Figure 15] FIG. 15 is a diagram showing the registration procedure. [Figure 16] Figure 16 is a diagram showing registration with AMF re-allocation procedure. DETAILED DESCRIPTION OF THE INVENTION
[0012] <abbreviation> For the purposes of this document, the abbreviations in Non-Patent Document 1 and those shown below apply. Abbreviations defined in this document take precedence over the same abbreviations defined in Non-Patent Document 1 if any.
[0013] 4G-GUTI 4G Globally Unique Temporary UE Identity 5GC 5G Core Network 5GLAN 5G Local Area Network 5GS 5G System 5G-AN 5G Access Network 5G-AN PDB 5G Access Network Packet Delay Budget 5G-EIR 5G-Equipment Identity Register 5G-GUTI 5G Globally Unique Temporary Identifier 5G-BRG 5G Broadband Residential Gateway 5G-CRG 5G Cable Residential Gateway 5G GM 5G Grand Master 5G-RG 5G Residential Gateway 5G-S-TMSI 5G S-Temporary Mobile Subscription Identifier 5G VN 5G Virtual Network 5QI 5G QoS Identifier AF Application Function AMF Access and Mobility Management Function AMF-G Geographically selected Access and Mobility Management Function AMF-NG Non-Geographically selected Access and Mobility Management Function AS Access Stratum ATSSS Access Traffic Steering, Switching, Splitting ATSSS-LL ATSSS Low-Layer AUSF Authentication Server Function AUTN Authentication token BMCA Best Master Clock Algorithm BSF Binding Support Function CAG Closed Access Group CAPIF Common API Framework for 3GPP northbound APIs CHF Charging Function CN PDB Core Network Packet Delay Budget CP Control plane DAPS Dual Active Protocol Stacks DL Downlink DN Data Network DNAI DN Access Identifier DNN Data Network Name DRX Discontinuous Reception DS-TT Device-side TSN translator ePDG evolved Packet Data Gateway EBI EPS Bearer Identity EPS Evolved Packet System EUI Extended Unique Identifier FAR Forwarding Action Rule FN-BRG Fixed Network Broadband RG FN-CRG Fixed Network Cable RG FN-RG Fixed Network RG FQDN Fully Qualified Domain Name GFBR Guaranteed Flow Bit Rate GMLC Gateway Mobile Location Centre GPSI Generic Public Subscription Identifier GUAMI Globally Unique AMF Identifier GUTI Globally Unique Temporary UE Identity HR Home Routed (roaming) IAB Integrated access and backhaul IMEI / TAC IMEI Type Allocation Code IPUPS Inter PLMN UP Security I-SMF Intermediate SMF I-UPF Intermediate UPF LADN Local Area Data Network LBO Local Break Out (roaming) LMF Location Management Function LoA Level of Automation LPP LTE Positioning Protocol LRF Location Retrieval Function MCC Mobile country code MCX Mission Critical Service MDBV Maximum Data Burst Volume MFBR Maximum Flow Bit Rate MICO Mobile Initiated Connection Only MITM Man In the Middle MNC Mobile Network Code MPS Multimedia Priority Service MPTCP Multi-Path TCP Protocol N3IWF Non-3GPP InterWorking Function N3GPP Non-3GPP access N5CW Non-5G-Capable over WLAN NAI Network Access Identifier NAS Non-Access-Stratum NEF Network Exposure Function NF Network Function NGAP Next Generation Application Protocol NID Network identifier NPN Non-Public Network NR New Radio NRF Network Repository Function NSI ID Network Slice Instance Identifier NSSAA Network Slice-Specific Authentication and Authorization NSSAAF Network Slice-Specific Authentication and Authorization Function NSSAI Network Slice Selection Assistance Information NSSF Network Slice Selection Function NSSP Network Slice Selection Policy NSSRG Network Slice Simultaneous Registration Group NW-TT Network-side TSN translator NWDAF Network Data Analytics Function PCF Policy Control Function PDB Packet Delay Budget PDR Packet Detection Rule PDU Protocol Data Unit PEI Permanent Equipment Identifier PER Packet Error Rate PFD Packet Flow Description PLMN Public Land Mobile Network PNI-NPN Public Network Integrated Non-Public Network PPD Paging Policy Differentiation PPF Paging Proceed Flag PPI Paging Policy Indicator PSA PDU Session Anchor PTP Precision Time Protocol QFI QoS Flow Identifier QoE Quality of Experience RACS Radio Capabilities Signalling optimisation (R)AN (Radio) Access Network RG Residential Gateway RIM Remote Interference Management RQA Reflective QoS Attribute RQI Reflective QoS Indication RSN Redundancy Sequence Number SA NR Standalone New Radio SBA Service Based Architecture SBI Service Based Interface SCP Service Communication Proxy SD Slice Differentiator SEAF Security Anchor Functionality SEPP Security Edge Protection Proxy SMF Session Management Function SMSF Short Message Service Function SN Sequence Number SN name Serving Network Name. SNPN Stand-alone Non-Public Network S-NSSAI Single Network Slice Selection Assistance Information SSC Session and Service Continuity SSCMSP Session and Service Continuity Mode Selection Policy SST Slice / Service type SUCI Subscription Concealed Identifier SUPI Subscription Permanent Identifier SV Software Version TMSI Temporary Mobile Subscriber Identity TNAN Trusted Non-3GPP access Network TNAP Trusted Non-3GPP access Point TNGF Trusted Non-3GPP Gateway Function TNL Transport Network Layer TNLA Transport Network Layer Association TSC Time Sensitive Communication TSCAI TSC Assistance Information TSN Time Sensitive Networking TSN GM TSN Grand Master TSP Traffic Steering Policy TT TSN Translator TWIF Trusted WLAN Interworking Function UCMF UE radio Capability Management Function UDM Unified Data Management UDR Unified Data Repository UDSF Unstructured Data Storage Function UL Uplink UL CL Uplink Classifier UPF User plane Function URLLC Ultra Reliable Low Latency Communication URRP-AMF UE Reachability Request Parameter for AMF URSP UE Route Selection Policy VID VLAN Identifier VLAN Virtual Local Area Network VPLMN Visited PLMN W-5GAN Wireline 5G Access Network W-5GBAN Wireline BBF Access Network W-5GCAN Wireline 5G Cable Access Network W-AGF Wireline Access Gateway Function
[0014] <Definition> For the purposes of this document, the abbreviations listed in Non-Patent Document 1 and below apply. If the same abbreviation is defined in Non-Patent Document 1, the abbreviation defined in this document takes precedence over the same abbreviation in Non-Patent Document 1.
[0015] <General> Those skilled in the art will appreciate that elements in the figures are illustrated for simplicity and may not necessarily be drawn to scale. Furthermore, due to the structure of the device, one or more components of the device may be represented in the figures with conventional symbols, and the figures may show only certain details relevant to understanding aspects of the present disclosure so as not to obscure the figures with details that will be readily apparent to those skilled in the art having the benefit of the description herein.
[0016] For the purposes of promoting an understanding of the principles of the present disclosure, reference will be made to the embodiments illustrated in the drawings and specific language will be used to describe them. It will, however, be understood that no limitation on the scope of the disclosure is intended thereby. Such changes and further modifications in the illustrated systems, and further applications of the principles of the present disclosure as would normally occur to one skilled in the art, are to be construed as being within the scope of the present disclosure.
[0017] The terms "comprises," "comprising," or other variations thereof, are intended to cover a non-exclusive inclusion, such that a process or method comprising a list of steps may include not only those steps, but also other steps not expressly listed or inherent in such process or method. Similarly, the term "comprises... a" preceding one or more devices, entities, subsystems, elements, structures, or components does not, absent further constraints, preclude the presence of other devices, subsystems, elements, structures, components, additional devices, additional subsystems, additional elements, additional structures, or additional components. Throughout this specification, the appearances of the phrases "in an aspect," "in another aspect," and similar language may, but do not necessarily, all refer to the same aspect.
[0018] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs. The systems, methods, and examples provided herein are illustrative only and are not intended to be limiting.
[0019] In the following specification and claims, reference will be made to a number of terms that shall be defined to have the following meanings: The singular forms "a," "an," and "the" include plural references unless the context clearly dictates otherwise.
[0020] As used herein, information is associated with data and knowledge because data is meaningful information and represents values attributed to parameters. Further knowledge refers to an understanding of abstract or concrete concepts. Note that this exemplary system is simplified to facilitate explanation of the disclosed subject matter and is not intended to limit the scope of the present disclosure. Other devices, systems, and configurations may be used in addition to or instead of the system to implement aspects disclosed herein, and all such aspects are considered to be within the scope of the present disclosure.
[0021] The term "UE context" in the following aspects may refer to the 5GMM context stored in the AMF and optionally the 5GSM context. The 5G NAS security context may be part of the 5GMM context. The term "NAS security context" used below may refer to the 5G NAS security context defined in 3GPP TS 23.2014-01-10 06:24 PM
[0022] The AMF and the UE establish a common 5G NAS security context containing a single set of NAS keys and algorithms during the first registration for any access. The AMF and the UE also store parameters specific to each NAS connection in the common NAS security context, including two sets of NAS COUNTs for each access (i.e., 3GPP access and non-3GPP access).
[0023] Each aspect and element included in each aspect described below may be implemented independently or in combination with others. These aspects include different novel features. As such, these aspects contribute to achieving different objectives or solving different problems, and to achieving different advantages.
[0024] The registration procedure in each aspect may be, but is not limited to, an initial registration procedure, a mobility registration procedure, or a periodic registration procedure.
[0025] <First aspect> When the UE initiates a registration procedure via 3GPP access while already registered with a non-geographically selected AMF via non-3GPP access, the UE performs integrity protection of the registration request message including the assigned 5G-GUTI using the NAS security context and sends an RRC Setup Complete message including the integrity-protected registration request message via 3GPP access. When the NG-RAN receives the RRC Setup Complete message including the integrity-protected registration request message during the RRC connection establishment procedure, the NG-RAN routes (or sends) the integrity-protected registration request message to the geographically selected AMF. Then, the geographically selected AMF (e.g., new AMF) initiates a UE context transfer procedure with the non-geographically selected AMF (e.g., old AMF) via the N14 interface by sending a NAMF_Communication_UEContextTransfer request message including the integrity-protected registration request message received from the UE. In this case, the old AMF does not know whether the integrity of the registration request message is protected by the NAS security context of the 3GPP access or the NAS security context of the non-3GPP access. This may cause the integrity check of the registration request message to fail. For example, the security parameters of the NAS security context used by the old AMF for the integrity check may differ from the security parameters of the NAS security context used by the UE. This may cause the integrity check of the registration request message to fail. The mismatch in the NAS security context between the UE and the non-geographically selected AMF ultimately leads to a failure of the UE context transfer from the non-geographically selected AMF to the geographically selected AMF. As a result, the registration procedure over the 3GPP access fails.For example, when mobility occurs from a non-geographically selected AMF to a geographically selected AMF, the integrity check for the transfer of the UE context by the AMF may fail.
[0026] The first aspect discloses a solution in which the AMF performs an integrity check even when the AMF does not have an MM context corresponding to the access type indicated in the Namf_Communication_UEContextTransfer request message. The first aspect can solve the above problem. For example, the MM context may be a 5GMM context or a 5GSM context.
[0027] When the UE successfully registers with the AMF of the PLMN, the UE saves the current NAS security context in the ME memory or USIM card. When the UE performs a registration procedure to a PLMN over 3GPP access while the UE is registered over non-3GPP access (e.g., when the UE performs a registration procedure to a PLMN over 3GPP access while the UE is registered over non-geographically selected AMF over non-3GPP access), the UE protects the integrity of the registration request message using the integrity protection mechanism defined in Non-Patent Document 5 and sends the integrity-protected registration request message over the 3GPP access. The integrity-protected registration request message includes 5G-GUTI and an information element called a NAS connection identifier configured in the 3GPP access.
[0028] When the geographically selected AMF receives the integrity-protected registration request message from the UE, the geographically selected AMF sends a Namf_Communication_UEContextTransfer request message including 5G-GUTI and an access type parameter set to 3GPP access (or other notation for identifying 3GPP access) along with other information elements to the non-geographically selected AMF. The Namf_Communication_UEContextTransfer request message may include the integrity-protected registration request message. The geographically selected AMF may be referred to as a geographical AMF or AMF-G in this disclosure. The non-geographically selected AMF may be referred to as a non-geographical AMF or AMF-NG in this disclosure. In this disclosure, the Namf_Communication_UEContextTransfer request message may be referred to as a Namf_Communication_UEContextTransfer message. When the non-geographically selected AMF receives the Namf_Communication_UEContextTransfer request message, the non-geographically selected AMF finds the UE context associated with the 5G-GUTI of the UE received in the Namf_Communication_UEContextTransfer request message. Although the non-geographically selected AMF finds that no MM context for 3GPP access exists, the non-geographically selected AMF performs an integrity check of the received NAS message (e.g., an integrity-protected registration request message) by using a 0 (zero) value for the UL NAS COUNT integrity protection parameter for the integrity check. If the integrity check is successful, the AMF-NG sends a Namf_Communication_UEContextTransfer response message to the AMF-G.The AMF-G completes the registration procedure for both 3GPP access and non-3GPP access, allocates a new 5G-GUTI, and sends the new 5G-GUTI to the UE.
[0029] Figure 1 shows a mobility procedure involving an AMF change from a non-geographically selected AMF to a geographically selected AMF.
[0030] The detailed procedure of the first embodiment is described below.
[0031] 0. The UE is registered with a non-geographically selected AMF via non-3GPP access, and a 5G-GUTI is assigned to the UE. An NAS security context is created for the non-3GPP access. For example, the UE and the non-geographically selected AMF have a NAS security context for the non-3GPP access. Furthermore, the UE is not yet registered with the 3GPP access.
[0032] 1a-1b. The UE initiates the registration procedure over 3GPP access. The UE performs integrity protection of the registration request message using the NAS security context of the non-3GPP access. The registration request message includes 5G-GUTI and a NAS connection identifier configured for the non-3GPP access. The UE sends the integrity-protected registration request message. For example, the UE sends an RRC message including the integrity-protected registration request message. The integrity-protected registration request message may be referred to as a registration request message in this disclosure. The unique NAS connection identifier value (or the NAS connection identifier value) is set to "0x01" for 3GPP access and "0x02" for non-3GPP access. For example, the UE sets the NAS connection identifier to "0x01" for 3GPP access and includes the NAS connection identifier in the registration request message.
[0033] In another example, the registration request message is integrity protected using the common 5G NAS security context created in step 0 and a UL NAS COUNT for 3GPP access that is set to zero if no UL NAS COUNT for 3GPP access is stored, otherwise the stored UL NAS COUNT is used.
[0034] 2-3. When the NG-RAN receives an RRC message containing a registration request message from the UE, the NG-RAN routes (or sends) the registration request message to the geographically selected AMF (AMF-G). The registration request message includes a 5G-GUTI. The 5G-GUTI can indicate a non-geographically selected AMF (i.e., AMF-NG).
[0035] 4. When the AMF-G receives the registration request message including the 5G-GUTI, it identifies the target AMF using the 5G-GUTI in the received registration request message. The target AMF may be the AMF on which the AMF-G executes Namf_Communication_UEContextTransfer. The AMF-G sends a Namf_Communication_UEContextTransfer request message including an access type set to 3GPP access (or other notation identifying 3GPP access), an integrity-protected NAS message, and the 5G-GUTI. The Namf_Communication_UEContextTransfer request message may include the NAS connection identifier received in the registration request message. The integrity-protected NAS message may be the integrity-protected registration request message received from the NG-RAN in step 4. The integrity-protected NAS message may be the integrity-protected registration request message received from the NG-RAN. The integrity-protected NAS message may be referred to in this disclosure as a complete Registration Request or an integrity-protected complete Registration Request NAS message. For example, when the AMF-G identifies the AMF-NG as the target AMF using the 5G-GUTI received in the Registration Request message, the AMF-G sends a Namf_Communication_UEContextTransfer request message to the AMF-NG, the message including the access type set to 3GPP access (or other notation for identifying 3GPP access) and the integrity-protected NAS message.
[0036] 5. When AMF-NG receives the Namf_Communication_UEContextTransfer request message, AMF-NG decides to perform an integrity check on the integrity-protected NAS message using one of the following procedures:
[0037] i) The AMF-NG uses the NAS security context in AMF-NG for the UE that corresponds to the value received in the Access Type information element, which in this case is 3GPP access. The AMF-NG uses the common 5G NAS security context created in step 0 and a UL NAS COUNT that is set to zero if there is no UL NAS COUNT stored for 3GPP access, or uses the stored NAS COUNT for 3GPP access.
[0038] ii) AMF-NG uses the NAS security context corresponding to the value received in the NAS connection identifier, which is a non-3GPP access. AMF-NG uses the 5G NAS security context based on the non-3GPP access to check the integrity of the NAS message.
[0039] For example, AMF-NG performs integrity checks on received integrity-protected NAS messages using a NAS security context for non-3GPP access even if the access type in the Namf_Communication_UEContextTransfer request message is set to 3GPP access.
[0040] For example, AMF-NG may determine that the access type in the Namf_Communication_UEContextTransfer request message is set to 3GPP access and perform an integrity check on the received integrity-protected NAS message using a NAS security context of non-3GPP access even if the access type of the Namf_Communication_UEContextTransfer request message is set to 3GPP access.
[0041] For example, if the AMF-NG receives a NAS connection identifier configured for non-3GPP access, it may perform an integrity check of the received integrity-protected NAS message using the NAS security context of the non-3GPP access.
[0042] For example, if the AMF-NG determines that the NAS connection identifier is set to non-3GPP access, it may determine that the integrity-protected NAS message is protected by the NAS security context of the non-3GPP access. The AMF-NG may then perform an integrity check on the received integrity-protected NAS message using the NAS security context of the non-3GPP access.
[0043] In one example, the NAS connection identifier is sent as a clear text element in the registration request message of step 1. When AMF-NG receives the registration request message, it reads the NAS connection identifier and determines whether to use a NAS security context for 3GPP access or a NAS security context for non-3GPP access based on the value of the NAS connection identifier.
[0044] In one example, the NAS connection identifier is an optional information element. If the NAS connection identifier is not present, the integrity check is performed using the 5G NAS security context associated with the access type.
[0045] In one example, if both a NAS connection identifier and an access type are present, the AMF-NG may use the 5G NAS security context associated with either the access type or the NAS connection identifier.
[0046] 6. If the integrity check is successful, the AMF-NG sends a Namf_Communication_UEContextTransfer response message to the AMF-G, which includes the 5GMM context for the UE's non-3GPP access.
[0047] 7. Upon receiving the Namf_Communication_UEContextTransfer response message, the AMF-G performs steps 6 to 19 of section 4.2.2.2.2 of non-patent document 4, and the AMF-G sends a registration accept message including the newly assigned 5G-GUTI to the UE.
[0048] 8. Upon receiving the registration accept message, the UE concludes that the UE is registered with the AMF-G for both 3GPP and non-3GPP access. The UE sends a Registration complete message to the AMF-G.
[0049] <Modification 1 of the First Aspect> In step 4, the AMF-G includes in the Namf_Communication_UEContextTransfer request message a new UL NAS COUNT for integrity protection parameter set to 0. With this explicit indication from the AMF-G, the AMF-NG uses the value of the UL NAS COUNT for integrity protection (i.e., the value "0") for integrity checking of received NAS messages.
[0050] <Modification 2 of the First Aspect> The principles of the first aspect can also be applied when the UE is registered with the first PLMN only in the first access and has a 5G NAS security context associated with the first PLMN, 5G-GUTI. The UE is not registered in the second access, i.e., the UE has no security context (e.g., a security context related to the second access) and is in a deregistered state. The UE initiates registration through the second access to the second PLMN. In this case, the AMF-NG operates like the old AMF, i.e., the AMF of the first PLMN, and the AMF-G operates like the new AMF, i.e., the AMF of the second PLMN. The UE, the old AMF, and the new AMF perform the registration procedure to the second PLMN through the second access according to the procedure described in the first aspect.
[0051] In one example, when the UE is registering to the second PLMN via the second access, the UE includes the 5G-GUTI assigned by the first PLMN in the registration request message. In one example, when the UE initiates a registration procedure to the second PLMN via the second access, the UE sends the SUCI instead of the 5G-GUTI in the registration request message. In this case, the UE and the network perform one of the following methods to protect the integrity of the registration request message and check the integrity of the received registration request message:
[0052] The UE protects the integrity of the registration request message using a common 5G NAS security context and a UL NAS COUNT set to zero. When the new AMF sends a registration request message to the old AMF, the old AMF uses the security context associated with the access type parameter received in the NAMF_Communication_UEContextTransfer request message, that is, the old AMF checks the integrity of the registration request message using the security context associated with the NAS connection identifier corresponding to the access type. In this case, since the UE has never registered to the first PLMN via a second access, the old AMF checks the integrity of the registration request message using a common 5G NAS security context and a UL NAS COUNT set to zero. After the integrity check is successful, the old AMF sends the UE context to the new AMF.
[0053] The UE integrity protects the registration request message using the 5G NAS security context of the first access. The UE includes a NAS connection identifier information element having a value set as the NAS connection identifier of the 5G NAS security context used to protect the integrity of the registration request message. In this case, the value of the NAS connection identifier is set to the value of the NAS connection identifier corresponding to the first access. This information element is sent as clear text. When the old AMF receives the registration request message, the old AMF checks the integrity of the received registration request message using the 5G NAS security context corresponding to the value of the NAS connection identifier. If the integrity check is successful, the old AMF sends the UE context to the new AMF.
[0054] <Modification 3 of the First Aspect> In step 1b, the UE includes a NAS connection identifier set to non-3GPP access in the registration request message, even though the UE is accessing via 3GPP access. This is an explicit indication to the AMF-G that the UE has performed integrity protection of the registration request message using the NAS security context of non-3GPP access. With this indication, the AMF-G includes the access type set to non-3GPP access in a Namf_Communication_UEContextTransfer request message and sends this message to AMF-NG in step 4. Then, AMF-NG performs an integrity check of the received integrity-protected NAS message using the NAS security context of non-3GPP access based on the received access type set to non-3GPP access in step 5.
[0055] <Modification 4 of the First Aspect> In step 4, the AMF-G includes the access type set to non-3GPP access in the NAM_Communication_UEContextTransfer request message and sends this message to the AMF-NG if the AMF-G detects that the AMF-NG is a non-geographically selected AMF based on the assigned 5G-GUTI or local configuration within the AMF-G. The AMF-NG then performs an integrity check of the received integrity-protected NAS message using the NAS security context of the non-3GPP access based on the received access type set to non-3GPP access in step 5.
[0056] <Modification 5 of the First Aspect> When the old AMF (e.g., AMF-NG) receives the Namf_Communication_UEContextTransfer request message, if the 5G-GUTI is allocated to the UE via non-3GPP access based on the GUAMI of the 5G-GUTI indicating a non-geographical AMF, it uses the 5G NAS security context associated with the non-3GPP access (e.g., the NAS security context of the non-3GPP access); otherwise, if the 5G-GUTI indicates that the 5G-GUTI is allocated via 3GPP access based on the GUAMI of the 5G-GUTI, e.g., a GUAMI indicating a geographical AMF, it uses the 5G NAS security context associated with the 3GPP access.
[0057] <Second aspect> A UE registers with a PLMN (e.g., an old PLMN) via 3GPP access and non-3GPP access, and a single 5G-GUTI is assigned to the UE. For example, the UE registers with a geographically selected AMF in the old PLMN via 3GPP access and non-3GPP access. The geographically selected AMF in the old PLMN may be referred to as the old AMF in this disclosure. The UE then registers with a new PLMN via non-3GPP access only. This may occur, for example, when the UE registers with a geographically selected AMF in the old PLMN, then the UE is set to airplane mode, moves to another country, and only Wi-Fi access is active. In this case, the N3IWF of the new PLMN may select a non-geographically selected AMF in the new PLMN, and only the non-3GPP access 5GMM context (e.g., the non-3GPP access 5GMM context associated with the old PLMN) is transferred from the geographically selected AMF of the old PLMN to the non-geographically selected AMF of the new PLMN. The non-geographically selected AMF in the new PLMN may be referred to as the new AMF in this disclosure. The new AMF then assigns a 5G-GUTI for non-3GPP access to the UE.
[0058] Subsequently, when the UE registers to a new PLMN via 3GPP access (e.g., when the UE registers to a geographically selected AMF in the new PLMN via 3GPP access), the UE sends a registration request message including a 5G-GUTI allocated by a non-geographically selected AMF in the new PLMN according to Non-Patent Document 4. In this case, according to Non-Patent Document 4, the new AMF geographically selected in the new PLMN does not fetch the 5GMM context of the 3GPP access and the 5GSM context of the 3GPP access from the old AMF (e.g., the AMF geographically selected in the old PLMN). This results in a loss of service on the 3GPP access because all PDU sessions on the 3GPP access cannot be transferred from the old AMF to the new AMF.
[0059] The second aspect discloses a method for obtaining a UE context for 3GPP access and a UE context for non-3GPP access from two different AMFs by a new AMF during a registration procedure. The second aspect can solve the above problem.
[0060] The second aspect discloses a registration procedure in PLMN2 (eg, a new PLMN) in the following situation:
[0061] The UE has a valid 5G-GUTI 1 associated with AMF1 of PLMN1 (e.g., old PLMN) and a corresponding security context for 3GPP access (e.g., NAS security context 1).
[0062] The UE has a valid 5G-GUTI 2 associated with AMF-NG of PLMN2 and a corresponding security context for non-3GPP access (e.g., NAS security context 2).
[0063] In this case, the UE sends a registration request message including two NAS containers, 5G-GUTI 1 and 5G-GUTI 2. The UE performs integrity protection of the registration request message sent to the AMF-G using NAS security context 1 associated with 5G-GUTI 1 and includes the integrity-protected registration request message based on NAS security context 1 in the first of the two NAS containers. The UE performs integrity protection of the registration request message sent to the AMF-G using security context 2 associated with 5G-GUTI 2 and includes the integrity-protected registration request message based on NAS security context 2 in the second of the two NAS containers. When the AMF-G receives the registration request message, it performs two UE context transfer procedures: one for 3GPP access with PLMN1 and one for non-3GPP access with PLMN2. When the AMF-G receives both the UE context for 3GPP access from the AMF1 and the UE context for non-3GPP access from the AMF-NG, it completes the registration procedures for both 3GPP access and non-3GPP access.
[0064] 2 shows a procedure for obtaining UE context related to 3GPP access and non-3GPP access from two different AMFs belonging to two different PLMNs. In FIG. 2, PLMN2 (or second PLMN) includes non-3GPP access (or non-3GPP access network), NG-RAN, AMF-G, and AMF-NG. Also in FIG. 2, PLMN1 (or first PLMN) includes AMF1 (or first AMF). For example, PLMN1 is different from PLMN2. The non-3GPP access (or non-3GPP access network) may be referred to as N3GPP in this disclosure.
[0065] The detailed procedure of the second embodiment is described below.
[0066] Step 0: The UE successfully registers with AMF1 of a first PLMN for both 3GPP access and non-3GPP access. In this case, 5G-GUTI 1 is assigned to the UE. The first PLMN may be referred to as PLMN1 in this disclosure. For example, 5G-GUTI 1 is assigned by AMF1. Also, for example, the UE and AMF1 have a NAS security context associated with 5G-GUTI 1. The NAS security context associated with 5G-GUTI 1 may be created during the registration procedure for both 3GPP access and non-3GPP access in step 0. The NAS security context associated with 5G-GUTI 1 may be referred to as the NAS security context of the 3GPP access associated with 5G-GUTI 1 or security context 1 in this disclosure.
[0067] 1. The UE registers with a second PLMN via non-3GPP access. A non-geographically selected AMF (i.e., AMF-NG) is selected for the UE. In this case, 5G-GUTI 2 for non-3GPP access is allocated to the UE. At this point, the UE and AMF1 still retain a UE context for 3GPP access related to 5G-GUTI 1. The second PLMN may be referred to as PLMN 2 in this disclosure. For example, 5G-GUTI 2 is allocated by the AMF-NG. For example, at this point, the UE and AMF1 still retain a UE context for 3GPP access corresponding to 5G-GUTI 1. Furthermore, for example, the UE and AMF-NG have a NAS security context related to 5G-GUTI 2. The NAS security context related to 5G-GUTI 2 may be created during the registration procedure to the second PLMN via non-3GPP access in step 1. The NAS security context associated with 5G-GUTI 2 may be referred to in this disclosure as the NAS security context of a non-3GPP access associated with 5G-GUTI 2, or security context 2.
[0068] 2. The UE initiates a registration procedure to the second PLMN via 3GPP access. The UE performs integrity protection of the registration request message using the NAS security context associated with 5G-GUTI 1, and the UE places this integrity-protected registration request message based on the NAS security context associated with 5G-GUTI 1 in NAS container 1. The UE also performs integrity protection of the registration request message using the NAS security context associated with 5G-GUTI 2, and the UE places this integrity-protected registration request message based on the NAS security context associated with 5G-GUTI 2 in NAS container 2.
[0069] 3. The UE sends a registration request message including 5G-GUTI 1, NAS container 1, 5G-GUTI 2, and NAS container 2. An additional 5G-GUTI may be configured in 5G-GUTI 1. An additional 5G-GUTI may be configured in 5G-GUTI 2. For example, the UE sends 5G-GUTI 1, NAS container 1 associated with 5G-GUTI 1, 5G-GUTI 2, and NAS container 2 associated with 5G-GUTI 2. The UE may include, in the registration request message, information that allows the AMF-G to determine that 5G-GUTI 1 is associated with NAS container 1 and information that allows the AMF-G to determine that 5G-GUTI 2 is associated with NAS container 2.
[0070] 4. When the AMF-G receives the registration request message from the UE, the AMF-G sends a Namf_Communication_UEContextTransfer request message to the AMF1, including 5G-GUTI 1, the integrity-protected NAS message in the received NAS container 1, and the access type set to 3GPP access. For example, the AMF-G sends a Namf_Communication_UEContextTransfer request message to the AMF1, including 5G-GUTI 1, the received NAS container 1 including the registration request message that is integrity-protected based on the NAS security context associated with 5G-GUTI 1, and the access type set to 3GPP access. For example, the AMF-G sends a Namf_Communication_UEContextTransfer request message to the AMF1, including 5G-GUTI 1, the NAS container 1 associated with 5G-GUTI 1, and the access type set to 3GPP access. For example, based on information received from 5G-GUTI 1 or the UE in step 3, AMF-G determines that NAS container 1 is associated with 5G-GUTI 1 and sends a Namf_Communication_UEContextTransfer request message to AMF1, which includes 5G-GUTI 1, the received NAS container 1, and the access type set to 3GPP access.
[0071] 5. When AMF1 receives the Namf_Communication_UEContextTransfer request message, AMF1 performs an integrity check of the integrity-protected NAS message in NAS Container 1 using the NAS security context of the 3GPP access associated with 5G-GUTI 1. For example, AMF1 determines that the access type in the Namf_Communication_UEContextTransfer request message is set to 3GPP access and performs an integrity check of the received integrity-protected NAS message (i.e., the integrity-protected Registration Request message received in NAS Container 1) using the NAS security context of the 3GPP access associated with 5G-GUTI 1.
[0072] 6. If the integrity check is successful, the AMF1 sends a Namf_Communication_UEContextTransfer response message to the AMF-G, which includes the 5GMM context for the UE's 3GPP access. The Namf_Communication_UEContextTransfer response message may include the 5GSM context for the UE's 3GPP access. The 5GMM context for the UE's 3GPP access and the 5GSM context for the UE's 3GPP access may be associated with 5G-GUTI 1.
[0073] 7. Next, the AMF-G sends to the AMF-NG a Namf_Communication_UEContextTransfer request message including 5G-GUTI 2, the integrity protected NAS message in the received NAS container 2, and the access type set to 3GPP access. For example, the AMF-G sends to the AMF-NG a Namf_Communication_UEContextTransfer request message including 5G-GUTI 2, the received NAS container 2 including the integrity protected registration request message based on the NAS security context associated with 5G-GUTI 2, and the access type set to 3GPP access. For example, the AMF-G sends to the AMF-NG a Namf_Communication_UEContextTransfer request message including 5G-GUTI 2, the NAS container 2 associated with 5G-GUTI 2, and the access type set to 3GPP access. For example, based on information received from 5G-GUTI 2 or the UE in step 3, the AMF-G determines that NAS container 2 is associated with 5G-GUTI 2 and sends a Namf_Communication_UEContextTransfer request message to the AMF-NG, including 5G-GUTI 2, the received NAS container 2, and the access type set to 3GPP access.
[0074] 8. When AMF-NG receives the Namf_Communication_UEContextTransfer request message, AMF-NG performs an integrity check of the integrity-protected NAS message in NAS Container 2 using the NAS security context associated with 5G-GUTI 2, even if AMF-NG does not have an MM context for 3GPP access. In this case, AMF-NG uses the value of the UL NAS COUNT for integrity protection, and this value is set to 0 for the integrity check of the received NAS message (i.e., the integrity-protected NAS message in NAS Container 2). For example, AMF-NG determines that the access type in the Namf_Communication_UEContextTransfer request message is set to 3GPP access and performs an integrity check of the received integrity-protected NAS message (i.e., the received integrity-protected Registration Request message) using the NAS security context associated with 5G-GUTI 2.
[0075] 9. If the integrity check is successful, the AMF-NG sends a Namf_Communication_UEContextTransfer response message to the AMF-G, which includes a 5GMM context for the UE's non-3GPP access. The Namf_Communication_UEContextTransfer response message may include a 5GSM context for the UE's non-3GPP access. The 5GMM context for the UE's non-3GPP access and the 5GSM context for the UE's non-3GPP access may be associated with 5G-GUTI 2.
[0076] 10. Upon receiving the Namf_Communication_UEContextTransfer response message in steps 6 and 9, the AMF-G executes steps 6 to 19 of section 4.2.2.2.2 of 3GPP TS 23.2144-1000, and the AMF-G sends a registration accept message including the newly allocated 5G-GUTI to the UE.
[0077] 11. Upon receiving the registration accept message, the UE concludes that it is registered in the AMF-G for both 3GPP and non-3GPP access. The UE sends a registration complete message to the AMF-G.
[0078] In one example, step 7 may be performed before step 4. For example, AMF-G sends a Namf_Communication_UEContextTransfer request message to AMF-NG, receives a Namf_Communication_UEContextTransfer response message from AMF-NG, and then AMF-G sends a Namf_Communication_UEContextTransfer request message to AMF1.
[0079] In one example, steps 4 and 7 may be performed simultaneously.
[0080] <First Modification of the Second Aspect> In one example, the UE includes only NAS container 2 and 5G-GUTI 2, but not NAS container 1 and 5G-GUTI 1. The AMF-G first performs steps 7 to 9, and then performs steps 4 to 7. After steps 7 to 9 are successfully performed and the UE context is successfully transferred from AMF-NG to AMF-G, the AMF-G performs step 4, and the AMF includes an information element indicating that the UE is validated and a SUPI (e.g., a SUPI related to the UE) in the Namf_Communication_UEContextTransfer request message. When the UE is successfully validated in AMF-NG, the AMF-G sets this value. When AMF1 receives a Namf_Communication_UEContextTransfer request message containing an information element indicating that the UE is enabled and a SUPI, AMF1 sends the UE context to AMF-G in a Namf_Communication_UEContextTransfer response message. The AMF-G completes the registration procedure as described in aspect 2.
[0081] <Third aspect> There may be cases where the N3IWF is connected only to a non-geographically selected AMF. That is, the N3IWF is not connected to a geographically selected AMF. In such a network topology, if the UE performs a registration procedure to a PLMN via 3GPP access while already registered via non-3GPP access using the PLMN's non-geographically selected AMF, a new geographically selected AMF is selected and the selected AMF is used for both 3GPP access and non-3GPP access because both accesses are connected to the same PLMN. In this case, the UE loses service via non-3GPP access because the N3IWF cannot communicate with the selected AMF due to network topology restrictions. For example, when performing mobility from a non-geographically selected AMF to a geographically selected AMF, the mobility procedure may be unclear depending on the network topology.
[0082] A third aspect discloses a method for handling a scenario where a UE cannot register for both 3GPP access and non-3GPP access with the same AMF. The third aspect discloses a solution to the above problem.
[0083] A third aspect discloses a solution for the case where the UE cannot register with the geographically selected AMF for both 3GPP access and non-3GPP access because the N3IWF is only connected to the non-geographically selected AMF. In this case, the geographically selected AMF proceeds with the registration procedure for only one access according to the user's subscription or the operator's policy. If the UE receives an indication that it cannot be simultaneously connected to both 3GPP access and non-3GPP access, the UE does not initiate a registration procedure to a PLMN via one access while it is registered via another access to the same PLMN.
[0084] Figure 3 shows the registration procedure when the UE cannot be registered to the same AMF for simultaneous 3GPP and non-3GPP access within a PLMN.
[0085] The detailed procedure of the third embodiment will be described below.
[0086] 0. The UE is registered with a non-geographically selected AMF (i.e., AMF-NG) via non-3GPP access, and a 5G-GUTI is assigned to the UE. A NAS security context is created for the non-3GPP access. For example, the UE and the non-geographically selected AMF have a NAS security context for the non-3GPP access.
[0087] 1a-1b. The UE initiates a registration procedure via 3GPP access. The UE performs integrity protection of the registration request message using the NAS security context of the non-3GPP access. The UE sends a registration request message (e.g., an integrity-protected registration request message). The registration request message includes a 5G-GUTI, a user preferred access type, and a NAS connection identifier set to 3GPP access. The user preferred access type indicates which access type is preferred for registration (e.g., with a higher priority) if registration for both access types is not possible. The user preferred access type can be set to either 3GPP access or non-3GPP access. For example, a user preferred access type set to 3GPP access indicates that registration via 3GPP access is preferred by the UE if registration via both access types is not possible. For example, a user preferred access type set to non-3GPP access indicates that registration via non-3GPP access is preferred by the UE if registration via both access types is not possible. The unique NAS connection identifier value (or the value of the NAS connection identifier) is set to "0x01" for 3GPP access and to "0x02" for non-3GPP access.
[0088] 2. When the AMF-G receives a Registration Request message including the 5G-GUTI from the UE, the AMF-G identifies the target AMF using the 5G-GUTI received in the Registration Request message. The target AMF may be the AMF on which the AMF-G performs Namf_Communication_UEContextTransfer. The AMF-G sends a Namf_Communication_UEContextTransfer request message including an access type set to 3GPP access and an integrity-protected NAS message. The Namf_Communication_UEContextTransfer request message may include the NAS connection identifier received in the Registration Request message. The integrity-protected NAS message may be the integrity-protected Registration Request message received in step 2. The integrity-protected NAS message may be referred to in this disclosure as a complete Registration Request or an integrity-protected complete Registration Request NAS message. For example, if the AMF-G identifies the AMF-NG as the target AMF using the 5G-GUTI received in the registration request message, the AMF-G sends a Namf_Communication_UEContextTransfer request message to the AMF-NG, including an access type set to 3GPP access (or other notation identifying 3GPP access) and an integrity-protected NAS message.
[0089] 3. When the AMF-NG receives a Namf_Communication_UEContextTransfer request message from the AMF-G, the AMF-NG performs an integrity check of the integrity-protected NAS message using the NAS security context in the AMF-NG for the UE, even if the AMF-NG does not have an MM context for 3GPP access. In this case, the AMF-NG uses the 0 (zero) value of the UL NAS COUNT integrity protection parameter to check the integrity of the received integrity-protected NAS message.
[0090] If the integrity check is successful, the AMF-NG determines whether non-3GPP contexts (e.g., UE contexts related to non-3GPP access, 5GMM contexts for non-3GPP access of the UE, and 5GSM contexts for non-3GPP access of the UE) can be transferred to the AMF-G. For example, if the N3IWF can only establish a connection with the AMF-NG, the AMF-NG determines that the non-3GPP contexts cannot be transferred to the AMF-G. For example, the AMF-NG considers the reachability between the N3IWF and the AMF-G and determines based on the network configuration of the N2 reference point between the N3IWF and the AMF-NG that the N3IWF can only establish a connection with the AMF-NG, and determines that the non-3GPP contexts cannot be transferred to the AMF-G.
[0091] For example, AMF-NG determines that the access type in the Namf_Communication_UEContextTransfer request message is set to 3GPP access and performs an integrity check on the received integrity-protected NAS message using a NAS security context for non-3GPP access, even if the access type of the Namf_Communication_UEContextTransfer request message is set to 3GPP access.
[0092] For example, AMF-NG performs integrity checks on received integrity-protected NAS messages using a NAS security context for non-3GPP access even if the access type in the Namf_Communication_UEContextTransfer request message is set to 3GPP access.
[0093] For example, if the AMF-NG receives a NAS connection identifier configured for non-3GPP access, it may perform an integrity check of the received integrity-protected NAS message using the NAS security context of the non-3GPP access.
[0094] For example, if the AMF-NG determines that the NAS connection identifier is set to non-3GPP access, it may determine that the integrity-protected NAS message is protected by the NAS security context of the non-3GPP access. The AMF-NG may then perform an integrity check on the received integrity-protected NAS message using the NAS security context of the non-3GPP access.
[0095] 4. AMF-NG sends a Namf_Communication_UEContextTransfer response message to AMF-G containing the cause (or information) that the non-3GPP context cannot be transferred to AMF-G.
[0096] For example, if AMF-NG considers the reachability between N3IWF and AMF-G and determines based on the network configuration of the N2 reference point between N3IWF and AMF-NG that N3IWF can only establish a connection with AMF-NG and AMF-NG determines that non-3GPP contexts cannot be transferred to AMF-G, it sends a Namf_Communication_UEContextTransfer response message to AMF-G.
[0097] For example, if AMF-NG considers the reachability between N3IWF and AMF-G and determines, based on the network configuration of the N2 reference point between N3IWF and AMF-NG, that N3IWF can only establish a connection with AMF-NG and that AMF-NG cannot transfer non-3GPP context to AMF-G, it sends a Namf_Communication_UEContextTransfer response message to AMF-G containing a cause (or information) indicating that N3IWF can only establish a connection with AMF-NG.
[0098] 5. Upon receiving a Namf_Communication_UEContextTransfer response message with a cause indicating that the non-3GPP context cannot be transferred (or a cause indicating that the N3IWF can only establish a connection with AMF-NG), depending on at least one of the operator's policy, the user's subscription from the UDM (e.g., subscription for 3GPP access has higher priority than non-3GPP access, or subscription for non-3GPP access has higher priority than 3GPP access), and the user preferred access type indicated in the registration request message of step 1b, the AMF-G can either accept the registration procedure via 3GPP access and deregister the UE via non-3GPP access, or reject the registration procedure via 3GPP access (e.g., when subscription for non-3GPP access has higher priority). For example, the AMF-G performs either option A (steps 6a to 7a) or option B (steps 6b to 7b). The operator's policy may indicate whether a subscription for 3GPP access is preferred over non-3GPP access or whether a subscription for non-3GPP access is preferred over 3GPP access. The operator's policy may be configured in the AMF-G or the AMF-G may receive the operator's policy from another network node.
[0099] Option A: 6a. Based on the determination of step 5, if the AMF-G accepts the registration procedure, the AMF-G sends a registration accept message to the UE, with the registration result type (or registration result) set to 3GPP access. The registration result type set to 3GPP access may indicate the completion of registration for 3GPP access. The AMF-G further includes an existing information element (e.g., 5GMM cause) or a new information element in the registration accept message to indicate that the AMF-G cannot register the UE to 3GPP access and non-3GPP access simultaneously. The existing information element (e.g., 5GMM cause) or the new information element may also indicate that the non-3GPP access cannot move to a geographically selected AMF (e.g., AMF-G) or that the UE cannot be connected via both 3GPP access and non-3GPP access simultaneously.
[0100] For example, if the AMF-G receives a user preferred access type set to 3GPP access, the AMF-G accepts the registration procedure via 3GPP access and sends a registration accept message.
[0101] For example, if the AMF-G receives a user subscription from the UDM indicating that the subscription for 3GPP access has higher priority than non-3GPP access (or information indicating that 3GPP access has priority over non-3GPP access), the AMF-G accepts the registration procedure via 3GPP access and sends a registration accept message.
[0102] For example, if the AMF-G determines that the operator's policy indicates that a 3GPP access subscription has higher priority than non-3GPP access (or indicates that 3GPP access has higher priority than non-3GPP access), the AMF-G accepts the registration procedure via 3GPP access and the AMF-G sends a registration accept message.
[0103] 7a. When the UE receives a registration accept message containing an existing information element or a new information element as described in step 6a, the UE considers itself registered for 3GPP access only.
[0104] 8a. When the UE receives the registration accept message containing the existing or new information element as described in step 6a, the UE initiates the UE initiated deregistration procedure for non-3GPP access according to 3GPP TS 36.210.
[0105] Option B: 6b. If the AMF-G rejects the registration procedure because the subscription for non-3GPP access takes priority over 3GPP access based on the decision in step 5, the AMF-G rejects the registration procedure for 3GPP access and sends a registration reject message to the UE, including a new information element indicating that the AMF-G cannot simultaneously register the UE for 3GPP access and non-3GPP access. The new information element may also indicate that the non-3GPP access cannot be moved to a geographically selected AMF or that the UE cannot simultaneously connect to both 3GPP access and non-3GPP access.
[0106] For example, if the AMF-G receives a user preferred access type set to non-3GPP access, the AMF-G rejects the registration procedure in 3GPP access and sends a registration reject message.
[0107] For example, if the AMF-G receives from the UDM a user subscription indicating that the non-3GPP access subscription has higher priority than the 3GPP access (or information indicating that the non-3GPP access has higher priority than the 3GPP access), the AMF-G rejects the registration procedure via the 3GPP access and sends a registration reject message.
[0108] For example, if the AMF-G determines that the operator's policy indicates that the non-3GPP access subscription has higher priority than the 3GPP access (or that the non-3GPP access has higher priority than the 3GPP access), the AMF-G rejects the registration procedure via the 3GPP access and sends a registration reject message.
[0109] 7b. If the UE receives a registration reject message containing the new information element as described in step 6b, the UE assumes that the UE is registered only in non-3GPP access. For example, in step 7b, the UE is registered in AMF-NG via non-3GPP access.
[0110] 8b. The UE shall not initiate a registration procedure via 3GPP access while the UE is registered via non-3GPP access within the same PLMN.
[0111] <Modification 1 of the third aspect> In step 7a, the UE can register with AMF-G via 3GPP access, and the UE can register with AMF-NG via non-3GPP access. In this case, the UE maintains a 5G-GUTI for non-3GPP access and an associated MM context for non-3GPP access. In this variant 1, even if both 3GPP access and non-3GPP access are provided by the same PLMN, the UE maintains two 5G-GUTIs, one for 3GPP access and one for non-3GPP access. In this case, step 8a is not performed by the UE to maintain non-3GPP access registered with AMF-NG.
[0112] <Modification 2 of the third aspect> After step 8a, the UE may initiate the registration procedure via non-3GPP access using the 5G-GUTI allocated by the AMF-G.
[0113] <Modification 3 of the third aspect> In step 1b, the UE includes a NAS connection identifier set to non-3GPP access in the registration request message, even though the UE is accessing via 3GPP access. This is an explicit indication to the AMF-G that the UE has performed integrity protection of the registration request message using the NAS security context of non-3GPP access. With this indication, the AMF-G includes the access type set to non-3GPP access in a Namf_Communication_UEContextTransfer request message and sends this message to AMF-NG in step 2. Then, AMF-NG performs an integrity check of the received integrity-protected NAS message using the NAS security context of non-3GPP access based on the received access type set to non-3GPP access in step 3.
[0114] <Modification 4 of the third aspect> In step 1b, the UE includes a NAS connection identifier set to non-3GPP access in the registration request message, even though the UE is accessing via 3GPP access. This is an explicit indication to the AMF-G that the UE has performed integrity protection of the registration request message using the NAS security context of non-3GPP access. With this indication, the AMF-G includes the access type set to non-3GPP access in a Namf_Communication_UEContextTransfer request message and sends this message to AMF-NG in step 2. Then, AMF-NG performs an integrity check of the received integrity-protected NAS message using the NAS security context of non-3GPP access based on the received access type set to non-3GPP access in step 3.
[0115] <Modification 5 of the Third Aspect> In step 2, the AMF-G includes the access type set to non-3GPP access in the NAM_Communication_UEContextTransfer request message and sends this message to the AMF-NG if the AMF-G detects that the AMF-NG is a non-geographically selected AMF based on the assigned 5G-GUTI or the AMF-G's local configuration. The AMF-NG then performs an integrity check of the received integrity-protected NAS message using the NAS security context of the non-3GPP access based on the received access type set to non-3GPP access in step 3.
[0116] <Fourth aspect> As defined in Non-Patent Document 4, when AMF relocation occurs during the registration procedure, the initial AMF sends a Namf_Communication_UEContextTransfer request message to the old AMF (AMF3) to obtain the UE context. The initial AMF (AMF1) may be the AMF for sending the Namf_Communication_UEContextTransfer request message. If the integrity check is successful, the old AMF sends the UE context to the initial AMF. If the initial AMF cannot process the requested NSSAI but the initial AMF determines that the requested NSSAI can be processed by the target AMF, the initial AMF forwards the registration request message to the target AMF (AMF2) via NG-RAN. The initial AMF may decipher the NAS message container of the registration request message and send the registration request message included in the NAS message (or NAS container). However, because the integrity-protected registration request message received by the initial AMF from the UE is not sent from the initial AMF to the target AMF, it is unclear how the target AMF obtains the UE context from the old AMF. For example, it is also unclear how the UE validity check is performed by the old AMF when the initial AMF forwards the registration request message to the target AMF. In this case, the registration request message received by the target AMF may not be the same as the one sent from the UE to the initial AMF, and the UE validity check in the old AMF may fail.
[0117] The fourth aspect solves the above problem and discloses a method for a target AMF to acquire a UE context from an old AMF during an AMF relocation procedure when the target AMF does not have an integrity-protected registration request message. In a scenario in which the initial AMF receives a UE context from the old AMF after the integrity check of the registration request message in the old AMF is successful, the initial AMF marks the UE as enabled, that is, the UE is a genuine UE, because the UE's integrity-protected registration request message passed the integrity check in the old AMF. When the initial AMF sends a reroute NAS message to the NG-RAN, the initial AMF includes an information element indicating that the UE is enabled and a SUPI (e.g., a SUPI associated with the UE). Upon receiving the reroute NAS message, the NG-RAN sends an initial NAS message including the information element and the SUPI to the target AMF. When the target AMF receives the reroute NAS message (or initial NAS message) including the above information element and SUPI, the target AMF sends a Namf_Communication_UEContextTransfer request message including the SUPI and an information element indicating that the UE is enabled to the old AMF. When the target AMF receives the Namf_Communication_UEContextTransfer request message including the SUPI and an information element indicating that the UE is enabled, the target AMF sends a Namf_Communication_UEContextTransfer response message including the UE context corresponding to the SUPI. When the target AMF receives this message, it further processes the registration procedure.
[0118] The detailed steps of the fourth embodiment are described below.
[0119] The initial AMF and target AMF register their capabilities with the NRF.
[0120] 1. The UE initiates the registration procedure in idle mode by sending a registration request message to the (R)AN in an RRC setup complete message during the RRC connection setup procedure, and the (R)AN sends a registration request message to the initial AMF in an Initial UE message.
[0121] 2. If the AMF needs SUPI and / or UE subscription information to decide whether to reroute the registration request, or if the registration request was not sent integrity protected or if integrity protection is indicated as having failed, the AMF performs an identity request response procedure, an authentication procedure, and a security mode command procedure. The registration request may also be referred to as a registration request message in this disclosure.
[0122] For example, during step 2, the initial AMF receives the UE context of the UE from the old AMF after the integrity check of the registration request message in the old AMF is successful, and since the UE's integrity-protected registration request message passed the integrity check in the old AMF, the initial AMF marks the UE as enabled, that is, the UE is a real UE. For example, the initial AMF sends a Namf_Communication_UEContextTransfer message to the old AMF to obtain the UE context, and receives a Namf_Communication_UEContextTransfer response including the UE context from the old AMF. Steps 4 to 9b in Figure 4.2.2.2.2-1 of Non-Patent Document 4 may be performed.
[0123] 3a. If the initial AMF requires the UE's subscription information to determine whether to reroute the registration request and the UE's slice selection subscription information was not provided by the old AMF, the AMF selects UDM.
[0124] 3b. Initial AMF to UDM: Nudm_SDM_Get(SUPI, Slice Selection Subscription data) For example, the initial AMF sends Nudm_SDM_Get, which includes the SUPI and slice selection subscription data, to the UDM. The initial AMF calls the Nudm_SDM_Get service operation to request the UE's slice selection subscription data from the UDM. The UDM may obtain this information from the UDR by Nudr_DM_Query(SUPI, slice selection subscription data). For example, the UDM may obtain this information from the UDR by Nudr_DM_Query, which includes the SUPI and slice selection subscription data.
[0125] 3c. UDM to initial AMF: Response to Nudm_SDM_Get. For example, UDM sends a response to Nudm_SDM_Get to the initial AMF. The AMF obtains slice selection subscription data including Subscribed S-NSSAI. The UDM responds to the initial AMF with the slice selection data.
[0126] 4a. Initial AMF to NSSF: Nnssf_NSSelection_Get(Requested NSSAI, Mapping Of Requested NSSAI, Subscribed S-NSSAI(s) with the default S-NSSAI indication, NSSRG information, TAI, Allowed NSSAI for the other access type (if any), Mapping of Allowed NSSAI, PLMN ID of SUPI). For example, the initial AMF may send an Nnssf_NSSelection_Get to the NSSF containing the requested NSSAI, the requested NSSAI mapping, the Subscribed S-NSSAI with the default S-NSSAI indication, the NSSRG information, the TAI, the allowed NSSAIs for other access types (if any), the allowed NSSAI mapping, and the PLMN ID of the SUPI.
[0127] If a slice needs to be selected, for example, if the initial AMF cannot provide service for all S-NSSAIs of the requested NSSAI that are allowed by the subscription information, the initial AMF invokes the Nnssf_NSSelection_Get service operation from the NSSF by including the requested NSSAI, optionally the mapping of the requested NSSAI, the Subscribed S-NSSAI with the default S-NSSAI indication, the [NSSRG Information], the allowed NSSAIs of other access types (if any), the mapping of the allowed NSSAI, the PLMN ID of the SUPI, and the TAI of the UE.
[0128] If available, the AMF includes NSSRG information about the S-NSSAI of the HPLMN as defined in section 5.15.12 of non-patent document 3, including information on whether the UE has indicated support for the subscription-based restrictions to simultaneous registration of network slices and whether the UDM has indicated that all Subscribed S-NSSAIs are to be provided to non-supporting UEs.
[0129] 4b. NSSF to initial AMF: Response to Nnssf_NSSelection_Get (AMF Set or list of AMF addresses, Allowed NSSAI for the first access type, Mapping of Allowed NSSAI, Allowed NSSAI for the second access type, Mapping of Allowed NSSAI, NSI ID, NRF, List of rejected (S-NSSAI(s), cause value(s)), Configured NSSAI for the Serving PLMN, Mapping of Configured NSSAI). For example, the NSSF may send a response to Nnssf_NSSelection_Get to the initial AMF including an AMF set or list of AMF addresses, allowed NSSAIs for the first access type, allowed NSSAI mappings, allowed NSSAIs for the second access type, allowed NSSAI mappings, NSI ID, NRF, rejected list (S-NSSAI, cause value), configured NSSAIs of the serving PLMN, and configured NSSAI mappings.
[0130] The NSSF returns to the Initial AMF the allowed NSSAIs for the first access type, optional allowed NSSAI mappings, the allowed NSSAIs for the second access type (if any), optional allowed NSSAI mappings, a Target AMF Set, or a list of candidate AMFs based on the configuration. The NSSF may return the NSI ID associated with the network slice instance corresponding to the specific S-NSSAI. The NSSF may return the NRF used to select the NF / service within the selected network slice instance. It may also return information about the rejection cause of the S-NSSAI not included in the allowed NSSAI. The NSSF may return the configured NSSAIs of the serving PLMN and possibly the associated configured NSSAI mappings. If NSSRG information was included in the request, the NSSF provides the configured NSSAIs.
[0131] 5. Initial AMF to old AMF: Namf_Communication_RegistrationStatusUpdate (failure cause). For example, the initial AMF may send a Namf_Communication_RegistrationStatusUpdate including the failure cause to the old AMF.
[0132] If a different AMF is selected, the initial AMF sends a rejection indication to the old AMF, indicating that the UE registration procedure was not fully completed by the initial AMF. The old AMF continues as if Namf_Communication_UEContextTransfer had never been received.
[0133] 6a. Initial AMF to NRF: Nnrf_NFDiscovery_Request (NF type, AMF set). For example, the initial AMF may send a Nnrf_NFDiscovery_Request including the NF type and AMF set to the NRF.
[0134] If the initial AMF does not store the target AMF address locally and the initial AMF uses direct reroute to the target AMF, or if the AMF address needs to be included in the reroute via (NG-R)AN message, the initial AMF invokes the Nnrf_NFDiscovery_Request service operation from the NRF to find a suitable target AMF with the NF capabilities required to provide services to the UE. The NF type is set to AMF. The AMF set is included in the Nnrf_NFDiscovery_Request.
[0135] 6b. NRF to AMF: Response to Nnrf_NFDiscovery_Request (list of (AMF pointer, AMF address, and additional selection rules and NF capabilities)). For example, the NRF may send a response to Nnrf_NFDiscovery_Request to the initial AMF that includes a list of (AMF pointer, AMF address, and additional selection rules and NF capabilities).
[0136] The NRF replies with a list of potential target AMFs. The NRF may also provide details of the services offered by the candidate AMFs, along with notification endpoints (if available) for each type of notification service that the selected AMF has registered with the NRF. Alternatively, a list of potential target AMFs and their capabilities, and optionally additional selection rules, may be provided. Based on information about registered NFs and required capabilities, a target AMF is selected by the initial AMF.
[0137] If a security association has been established between the UE and the initial AMF, the initial AMF performs step 7(A) to forward the NAS message to the target AMF to avoid registration failure.
[0138] If the initial AMF is not part of the target AMF set and cannot obtain a list of candidate AMFs by querying the NRF using the target AMF set (for example, an NRF pre-configured locally on the AMF does not provide the requested information, a query to an appropriate NRF provided by the NSSF is not successful, or the initial AMF knows that it is not authorized as a serving AMF), and if a security association has not been established between the UE and the initial AMF, the initial AMF performs step 7(B) and forwards the NAS message to the target AMF via the (R)AN; the authorized NSSAI and AMF set are included to allow the (R)AN to select the target AMF.
[0139] 7(A). If the initial AMF decides to forward the NAS message directly to the target AMF based on local policy and subscription information, the initial AMF invokes Namf_Communication_N1MessageNotify to the target AMF, carrying the rerouted NAS message. The Namf_Communication_N1MessageNotify service operation includes AN access information (e.g., information that allows the (R)AN to identify the N2 termination point, the CAG identifier of the CAG cell), the full Registration Request message and the UE's SUPI, an information element indicating that the UE is enabled, and the MM context, if available. If the initial AMF obtained information from the NSSF as described in step 4b, that information, excluding the AMF set or the list of AMF addresses, is included. Then, in step 8, the target AMF updates the (R)AN with the UE's new updated N2 termination point in the first message from the target AMF to the RAN. For example, after the integrity check of the registration request message in the old AMF is successful, the initial AMF receives the UE context of the UE from the old AMF, and the UE's integrity-protected registration request message passes the integrity check in the old AMF, so the initial AMF marks the UE as enabled, i.e., the UE is authentic, and the initial AMF includes an information element indicating that the UE is enabled in the Namf_Communication_N1MessageNotify.For example, after the integrity check of the registration request message in the old AMF is successful, the initial AMF receives the UE context of the UE from the old AMF, and the UE's integrity-protected registration request message passes the integrity check in the old AMF, so the initial AMF marks the UE as enabled, i.e., the UE is authentic, and the initial AMF includes the UE context (e.g., the UE's MM context) and an information element indicating that the UE is enabled in the Namf_Communication_N1MessageNotify.The information element may indicate that the initial AMF receives the UE context of the UE from the old AMF after an integrity check of the registration request message in the old AMF is successful. The information element may indicate that the initial AMF marks the UE as enabled, i.e., the UE is a real UE, because the UE's integrity-protected registration request message passed the integrity check in the old AMF. The information element may indicate that there is no need to perform an integrity check of the registration request message.
[0140] If the target AMF receives a Namf_Communication_N1MessageNotify message containing a SUPI, an information element indicating that the UE is enabled, and an MM context, the target AMF does not invoke the Namf_Communication_UEContextTransfer service and continues the registration procedure as defined in non-patent document 4 (the target AMF corresponds to the new AMF).
[0141] 7(B). If the initial AMF decides, based on local policy and subscription information, to forward the NAS message to the target AMF via the (R)AN unless the target AMF is not returned from the NSSF and is identified by the list of candidate AMFs, the initial AMF sends a reroute NAS message to the (R)AN (step 7(B), step 7a). The reroute NAS message includes information about the target AMF and the complete registration request message. If the initial AMF received the MM context from the old AMF in step 2 because the old AMF successfully checked the integrity of the registration request message or because the authentication procedure was successfully performed in step 2, the initial AMF includes the SUPI and an information element indicating that the UE is enabled. The (R)AN sends an initial UE message indicating reroute by slicing to the target AMF, including the information from step 4b provided by the NSSF (step 7(B), step 7b). The NG-RAN also includes the SUPI, the information element indicating that the UE is enabled, and other received information elements in the reroute NAS message to the initial NAS message.
[0142] For example, after the integrity check of the registration request message in the old AMF is successful, the initial AMF receives the UE context of the UE from the old AMF, and the UE's integrity-protected registration request message passes the integrity check in the old AMF, so the initial AMF marks the UE as enabled, that is, if the UE is a real UE, the initial AMF includes in the reroute NAS message an information element indicating that the UE is enabled.For example, after the integrity check of the registration request message in the old AMF is successful, the initial AMF receives the UE context of the UE from the old AMF, and the UE's integrity-protected registration request message passes the integrity check in the old AMF, so the initial AMF marks the UE as enabled, that is, if the UE is a real UE, the initial AMF includes in the reroute NAS message the UE context (e.g., the UE's MM context) and an information element indicating that the UE is enabled.
[0143] 8. If the target AMF receives the SUPI and an information element indicating that the UE is enabled, the target AMF sends the SUPI and an information element indicating that the UE is enabled to the old AMF in a Namf_Communication_UEContextTransfer message. Upon receiving a Namf_Communication_UEContextTransfer message containing the SUPI and an information element indicating that the UE is enabled, the old AMF sends the UE context to the target AMF in a Namf_Communication_UEContextTransfer response message without performing an integrity check.
[0144] If the target AMF does not receive the information element indicating SUPI and the UE is enabled, upon receiving the registration request message sent in step 7(A) step 7a or step 7(B) step 7b, the target AMF continues the registration procedure defined in 3GPP TS 23.01 (the target AMF corresponds to the new AMF), which includes the UE context obtained from the old AMF. If a 5G security context is received from the initial AMF, the target AMF continues to use that context instead of the 5G security context obtained from the old AMF. If the initial AMF decides to forward a NAS message to the target AMF (step 7(A), the first message from the target AMF to the (R)AN (either an Initial Context Setup Request or a Downlink NAS Transport) includes the AMF name of the initial AMF and the target AMF UE NGAP ID.
[0145] <Modification 1 of the Fourth Aspect> In step 7a of 7(B), if the initial AMF received the UE context from the old AMF in step 2 because the old AMF successfully checked the integrity of the registration request message or because the authentication procedure was successfully performed in step 2, the initial AMF includes the SUPI, an information element indicating that the UE is enabled, and the MM context received from the old AMF. The (R)AN sends an initial UE message indicating reroute by slicing to the target AMF, including the information from step 4b provided by the NSSF (step 7b). The NG-RAN also includes the SUPI, the information element indicating that the UE is enabled, the MM context, and other received information elements in the reroute NAS message to the initial NAS message.
[0146] When the target AMF receives an initial NAS message containing a SUPI, an information element indicating that the UE is enabled, and an MM context, the target AMF does not invoke the Namf_Communication_UEContextTransfer service but continues the registration procedure defined in non-patent document 4 (the target AMF corresponds to the new AMF).
[0147] <Modification 2 of the Fourth Aspect> If the authentication procedure and security mode command procedure are performed in step 2 of the fourth aspect, the initial AMF may have two registration request messages: one (registration request message 1) in the full registration request message received from the UE in step 1 and another (registration request message 2) in the security command complete message. In this case, the initial AMF performs one of the following two options:
[0148] i) The initial AMF sends the full registration request message (Registration Request Message 1) received in step 1 in a reroute NAS message. When the target AMF receives this registration request message in the initial NAS message from the NG-RAN, the target AMF sends this registration request message to the old AMF in a Namf_Communication_UEContextTransfer request message to obtain the UE context from the old AMF.
[0149] ii) The initial AMF includes both Registration Request Message 1 and Registration Request Message 2 in a reroute NAS message to the (R)AN (e.g., NG-RAN). Upon receiving the reroute NAS message, the (R)AN includes these two Registration Request messages in an initial UE message to the target AMF. When the target AMF receives the initial UE message, it sends Registration Request Message 1 to the old AMF to obtain the UE context and performs the registration procedure using the information elements of Registration Request Message 2, e.g., calculates the allowed NSSAI list using the requested NSSAI in Registration Request Message 2.
[0150] In one example, the initial AMF places a registration request message 1 in the first NAS PDU (an existing information element NAS PDU in the initial UE message) and places a registration request message 2 in the second NAS PDU of the INITIAL UE MESSAGE. When the target AMF receives the initial registration request message from the (R)AN, the target AMF sends the first NAS PDU to the old AMF to obtain the UE context and uses the registration request message 2 in the second NAS PDU to process the registration procedure defined above.
[0151] In one example, the initial AMF includes an explicit indication of which of the two registration request messages to send to the old AMF to obtain the UE context and which to use to process the registration request message. Upon receiving these explicit indicators, the target AMF performs the appropriate actions as described above.
[0152] <System Overview> FIG. 5 shows a schematic representation of a mobile (cellular or wireless) telecommunications system 1 to which the above aspects are applicable.
[0153] The telecommunications system 1 represents an overview of a system capable of end-to-end communication, e.g., UEs 3 (or user equipment, "mobile devices" 3) communicating with other UEs 3 or service servers in a data network 20 via respective (R)AN nodes 5 and a core network 7.
[0154] The (R)AN node 5 supports any radio access technology, including 5G radio access technology (RAT), E-UTRA radio access technology, Beyond 5G RAT, 6G RAT, and non-3GPP RAT, including wireless local area network (WLAN) technology defined by the Institute of Electrical and Electronics Engineers (IEEE).
[0155] The (R)AN node 5 can be divided into a Radio Unit (RU), a Distributed Unit (DU), and a Centralized Unit (CU). In some aspects, the (R)AN node 5 can be configured by adopting an architecture defined by the Open RAN (O-RAN) Alliance, where each unit is connected to each other and is referred to as an O-RU, O-DU, and O-CU, respectively.
[0156] The (R)AN node 5 may be split into control plane functions and user plane functions. Furthermore, multiple user plane functions may be allocated to support communications. In some aspects, user traffic may be distributed across multiple user plane functions, with user traffic across each user plane function being aggregated to both the UE 3 and the (R)AN node 5. This split architecture is sometimes referred to as "dual connectivity" or "multi-connectivity."
[0157] The (R)AN node 5 may also support communications using satellite access. In some aspects, the (R)AN node 5 may support satellite access and terrestrial access.
[0158] The (R)AN node 5 can also be called an access node for non-wireless access, which includes fixed-line access defined by the Broadband Forum (BBF) and optical access defined by Innovative Optical and Wireless Network (IOWN).
[0159] The core network 7 may include logical nodes (or "functions") for supporting communications in the telecommunications system 1. For example, the core network 7 may be a 5G Core Network (5GC) including, among other things, control plane functions and user plane functions. Each function within a logical node can be considered as a network function. The network functions may be provided to another node by applying a Service Based Architecture (SBA).
[0160] By adopting Network Functions Virtualization (ETSI NFV), a network virtualization technology defined by the European Telecommunications Standards Institute, network functions can be deployed as distributed, redundant, stateless, and scalable functions, delivering services from multiple locations with multiple execution instances at each location.
[0161] The core network 7 may support a Non-Public Network (NPN), which may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0162] As is known, when a UE 3 moves within a geographic area covered by the telecommunications system 1, it may move in and out of areas (i.e., radio cells) served by (R)AN nodes 5. To track the UE 3 and facilitate movement between different (R)AN nodes 5, the core network 7 comprises at least one access and mobility management function (AMF) 70. The AMF 70 communicates with the (R)AN nodes 5 connected to the core network 7. In some core networks, a mobility management entity (MME), a mobility management node for beyond 5G, or a mobility management node for 6G may be used instead of the AMF 70.
[0163] The core network 7 also includes, among other things, a Session Management Function (SMF) 71, a User plane Function (UPF) 72, a Policy Control Function (PCF) 73, a Network Exposure Function (NEF) 74, a Unified Data Management (UDM) 75, and a Network Data Analytics Function (NWDAF) 76. When a UE 3 is roaming in a visited Public Land Mobile Network (VPLMN), the home Public Land Mobile Network (HPLMN) of the UE 3 provides the UDM 75 and at least some of the functionality of the SMF 71, UPF 72, and PCF 73 to the roaming-out UE 3.
[0164] The UE 3 and each serving (R)AN node 5 are connected via an appropriate air interface (such as the so-called "Uu" interface). Adjacent (R)AN nodes 5 are connected to each other via appropriate (R)AN node 5 to (R)AN node interfaces (so-called "Xn" interfaces). Each (R)AN node 5 is also connected to nodes within the core network 7 (such as so-called core network nodes) via appropriate interfaces (such as the so-called "N2" / "N3" interfaces). The core network 7 also provides a connection to a data network 20. The data network 20 may be the Internet, a public network, an external network, a private network, or an internal network of a PLMN. If the data network 20 is provided by a PLMN operator or a mobile virtual network operator (MVNO), IP Multimedia Subsystem (IMS) services may be provided by that data network 20. The UE 3 may connect to the data network 20 using IPv4, IPv6, IPv4v6, Ethernet, or an unstructured data type.
[0165] The "Uu" interface can include a control plane of the Uu interface and a user plane of the Uu interface.
[0166] The user plane of the Uu interface is responsible for carrying user traffic between the UE 3 and the serving (R)AN node 5. The user plane of the Uu interface may have a layered structure with SDAP, PDCP, RLC, and MAC sublayers over the physical connection.
[0167] The control plane of the Uu interface is responsible for establishing, modifying and releasing the connection between the UE 3 and the serving (R)AN node 5. The control plane of the Uu interface may have a hierarchical structure with RRC, PDCP, RLC and MAC sublayers over the physical connection.
[0168] For example, the following messages are communicated via the RRC layer to support AS signaling:
[0169] RRC Setup Request message: This message is sent from the UE 3 to the (R)AN node 5. In addition to the parameters disclosed by aspects of the present disclosure, the following parameters may also be included in the RRC Setup Request message: --establishmentCause and ue-Identity, where ue-Identity may have the value of ng-5G-S-TMSI-Part1 or randomValue.
[0170] RRC Setup message: This message is sent from the (R)AN node 5 to the UE 3. The RRC Setup message may include the following parameters together in addition to the parameters disclosed by aspects of the present disclosure: --masterCellGroup and radioBearerConfig
[0171] RRC Setup Complete message: This message is sent from the UE 3 to the (R)AN node 5. The RRC Setup Complete message may include the following parameters together in addition to the parameters disclosed by aspects of the present disclosure: --guami-Type, iab-NodeIndication, idleMeasAvailable, mobilityState, ng-5G-S-TMSI-Part2, registeredAMF, selectedPLMN-Identity
[0172] The UE 3 and the AMF 70 are connected via an appropriate interface (such as the so-called N1 interface). The N1 interface is responsible for providing communication between the UE 3 and the AMF 70 to support NAS signaling. The N1 interface can be established over 3GPP access and over non-3GPP access. For example, the following messages are communicated over the N1 interface:
[0173] Registration Request message: This message is sent from the UE 3 to the AMF 70. The Registration Request message may include the following parameters together with the parameters disclosed by the aspects of the present disclosure: --5GS registration type, ngKSI, 5GS mobile identity, Non-current native NAS key set identifier, 5GMM capability, UE security capability, Requested NSSAI, Last visited registered TAI, S1 UE network capability, Uplink data status, PDU session status, MICO indication, UE status, Additional GUTI, Allowed PDU session status, UE's usage setting, Requested DRX parameters, EPS NAS message container, LADN indication, Payload container type, Payload container container, Network slicing indication, 5GS update type, Mobile station classmark 2, Supported codecs, NAS message container, EPS bearer context status, Requested extended DRX parameters, T3324 valuevalue, UE radio capability ID, Requested mapped NSSAI, Additional information requested, Requested WUS Assistance Information, N5GC indication, and Requested NB-N1 mode DRX parameters.
[0174] Registration Accept message: This message is sent from the AMF 70 to the UE 3. The registration accept message may include the following parameters in addition to the parameters disclosed in the aspects of the present disclosure. --5GS registration result, 5G-GUTI, Equivalent PLMNs, TAI list, Allowed NSSAI, Rejected NSSAI, Configured NSSAI, 5GS network feature support, PDU session status, PDU session reactivation result, PDU session reactivation result error cause, LADN information, MICO indication, Network slicing indication, Service area list, T3512 value, Non-3GPP de-registration timer value, T3502 value, Emergency number list number list, Extended Emergency number list, SOR transparent container, EAP message, NSSAI inclusion mode, Operator-defined access category definitions, Negotiated DRX parameters, Non-3GPP NW policies, EPS bearer context status, Negotiated extended DRX parametersparameters, T3447 value, T3448 value, T3324 value, UE radio capability ID, UE radio capability ID deletion indication, Pending NSSAI, Ciphering key data, CAG information list, Truncated 5G-S-TMSI configuration, Negotiated WUS Assistance Information, Negotiated NB-N1 mode DRX parameters, and Extended rejected NSSAI).
[0175] Registration Complete message: This message is sent from the UE 3 to the AMF 70. The Registration Complete message may include the following parameters together with the parameters disclosed by the aspects of the present disclosure:
[0176] --SOR transparent container. Authentication Request message: This message is sent from the AMF 70 to the UE 3. The Authentication Request message may include the following parameters together with the parameters disclosed by the aspects of the present disclosure: --ngKSI, ABBA, Authentication parameter RAND (5G authentication challenge), Authentication parameter AUTN (5G authentication challenge), and EAP message.
[0177] Authentication Response message: This message is sent from the UE 3 to the AMF 70. In addition to the parameters disclosed by the aspects of the present disclosure, the following parameters may be input together in the authentication response message: Authentication Response message identity, Authentication response parameter, and EAP message.
[0178] Authentication Result message: This message is sent from the AMF 70 to the UE 3. In addition to the parameters disclosed by the aspects of the present disclosure, the following parameters may be input together in the Authentication Result message: --ngKSI, EAP message, and ABBA. Authentication Failure message: This message is sent from the UE 3 to the AMF 70. In addition to the parameters disclosed by the aspects of the present disclosure, the following parameters may be input together in the authentication failure message:
[0179] --Authentication Failure message identity, 5GMM cause, and Authentication failure parameter.
[0180] Authentication Reject message: This message is sent from the AMF 70 to the UE 3. In addition to the parameters disclosed by the aspects of the present disclosure, the following parameters may be input together in the authentication reject message: --EAP message.
[0181] Service Request message: This message is sent from the UE 3 to the AMF 70. In addition to the parameters disclosed by the aspects of the present disclosure, the following parameters may be input together in the Service Request message: --ngKSI, Service type, 5G-S-TMSI, Uplink data status, PDU session status, Allowed PDU session status, NAS message container.
[0182] Service Accept message: This message is sent from the AMF 70 to the UE 3. In addition to the parameters disclosed by the aspects of the present disclosure, the following parameters may be entered together in the service accept message: --PDU session status, PDU session reactivation result, PDU session reactivation result error cause, EAP message, and T3448 value.
[0183] Service Reject message: This message is sent from the AMF 70 to the UE 3. In addition to the parameters disclosed by the aspects of the present disclosure, the following parameters may be input together in the service reject message: --5GMM cause, PDU session status, T3346 value, EAP message, T3448 value, and CAG information list.
[0184] Configuration Update Command message: This message is sent from the AMF 70 to the UE 3. In addition to the parameters disclosed by aspects of the present disclosure, the following parameters may be entered together in the Configuration Update Command message: --Configuration update indication, 5G-GUTI, TAI list, Allowed NSSAI, Service area list, Full name for network, Short name for network, Local time zone, Universal time and local time zone, Network daylight saving time, LADN information, MICO indication, Network slicing indication, Configured NSSAI, Rejected NSSAI, Operator-defined access category definitions, SMS indication, T3447 value, CAG information list, UE radio capability ID, UE radio capability ID deletion indication indication, 5GS registration result, Truncated 5G-S-TMSI configuration, Additional configuration indication, and Extended rejected NSSAI.
[0185] Configuration Update Complete message: This message is sent from the UE 3 to the AMF 70. In addition to the parameters disclosed by the aspects of the present disclosure, the following parameters may be entered together in the Configuration Update Complete message: --Configuration update complete message identity.
[0186] <User Equipment (UE)> FIG. 6 is a block diagram illustrating the main components of a mobile device 3 (UE 3). As shown, the UE 3 includes a transceiver circuit 31 operable to transmit signals to and receive signals from connected nodes via one or more antennas 32. The UE 3 may also include a user interface 34 for inputting and outputting information from the outside. Although not necessarily shown, the UE 3 may include all of the usual functions of a conventional mobile device, which may be provided by any one or any combination of hardware, software, and firmware, as needed. The software may be pre-installed in memory and / or downloaded via a communication network or from a removable data storage device (RMD). The controller 33 controls the operation of the UE 3 in accordance with software stored in the memory 36. The software includes, among other things, an operating system 361 and a communication control module 362 having at least a transceiver control module 3621. The communications control module 362 (using the transceiver control module 3621) is responsible for signaling and handling (generating / sending / receiving) uplink / downlink data packets between the UE 3 and other nodes, such as the (R)AN node 5 and the AMF 10. Such signaling may include, for example, appropriately formatted signaling messages (e.g., registration request messages and associated response messages) related to access and mobility management procedures (for the UE 3). The controller 33 interacts with one or more Universal Subscriber Identity Modules (USIMs) 35. If equipped with multiple USIMs 35, the controller 33 may activate only one USIM 35 or may activate multiple USIMs 35 simultaneously.
[0187] The UE 3 may, for example, support a Non-Public Network (NPN), which may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0188] UE3 may be, for example, an item of production or manufacturing equipment and / or an item of energy-related machinery (e.g., plant or machinery such as boilers, engines, turbines, solar panels, wind turbines, hydroelectric generators, thermal generators, nuclear power plants, batteries, nuclear systems and / or related equipment, heavy electrical machinery, pumps including vacuum pumps, compressors, fans, blowers, hydraulic equipment, pneumatic equipment, metalworking machinery, manipulators, robots and / or application systems thereof, tools, moulds or dies, rolls, conveying equipment, lifting equipment, material handling equipment, textile machinery, sewing machines, printing and / or related machinery, paper processing machinery, chemical machinery, mining and / or construction machinery and / or related equipment, agricultural, forestry and / or fishing machinery and / or implements, safety and / or environmental protection equipment, tractors, precision bearings, chains, gears, power transmission equipment, lubrication equipment, valves, pipe fittings, and / or application systems of the aforementioned plant or machinery, etc.).
[0189] UE3 may be, for example, an item of transportation equipment (e.g., railway vehicles, automobiles, motorcycles, bicycles, trains, buses, carts, rickshaws, ships and other water vehicles, aircraft, rockets, satellites, drones, balloons, etc.).
[0190] The UE 3 may be, for example, an information and communication device (for example, an information and communication device such as an electronic computer and related device, a communication and related device, or an electronic component).
[0191] The UE3 may be, for example, a refrigerator, a refrigerator application product, trade and / or service industry equipment, a vending machine, an automatic service machine, an office machine or equipment, a household appliance and an electronic device (e.g., a household appliance such as an audio device, a video device, a loud speaker, a radio, a television, a microwave oven, a rice cooker, a coffee machine, a dishwasher, a washing machine, a dryer, an electronic fan or related equipment, a vacuum cleaner, etc.).
[0192] The UE 3 may be, for example, an electrical application system or device (eg, an electrical application system or device such as an X-ray system, a particle accelerator, a radioisotope device, an acoustic device, an electromagnetic application device, or a power application device).
[0193] UE3 may be, for example, a light, lighting fixture, measuring instrument, analyzer, tester, or measuring instrument or detector (e.g., a smoke alarm, motion sensor, radio tag, or other measuring or detecting instrument), clock, laboratory equipment, optical equipment, medical equipment and / or system, weapon, blade, hand tool, etc.
[0194] The UE 3 may be, for example, a wirelessly equipped personal digital assistant or related equipment (such as a wireless card or module designed to be connected to or inserted into another electronic device (e.g., a personal computer, an electrical measuring instrument)).
[0195] The UE 3 may be part of a device or system that utilizes various wired and / or wireless communication technologies to provide the applications, services, and solutions described below regarding the "Internet of Things" (IoT).
[0196] Internet of Things devices (or "things") may be equipped with appropriate electronics, software, sensors, network connectivity, etc., which enable them to collect data and exchange data with each other and with other communicating devices. IoT devices may consist of automated machines that follow software instructions stored in their internal memory. IoT devices may operate without the need for human supervision or interaction. IoT devices may remain stationary or inactive for long periods of time. IoT devices may be implemented as part of (typically) fixed equipment. IoT devices may be embedded in non-fixed equipment (such as vehicles) or attached to animals or people being monitored / tracked.
[0197] It will be understood that IoT technologies may be implemented on any communication device that can connect to a communication network to send and receive data, regardless of whether such communication device is controlled by human input or by software instructions stored in memory.
[0198] It will be appreciated that an IoT device may also be referred to as a machine-type communication (MTC) device, a machine-to-machine (M2M) communication device, or a narrowband IoT UE (NB-IoT UE). It will be appreciated that a UE 3 may support one or more IoT or MTC applications.
[0199] The UE 3 may be a smartphone or a wearable device (e.g., smart glasses, a smart watch, a smart ring, or a hearable device).
[0200] The UE3 may be an automobile, a connected car, an autonomous vehicle, a vehicle device, a motorcycle, or a V2X (Vehicle to Everything) communication module (e.g., a vehicle-to-vehicle communication module, a vehicle-to-infrastructure communication module, a vehicle-to-people communication module, or a vehicle-to-network communication module).
[0201] <(R)AN node> FIG. 7 is a block diagram illustrating the main components of an exemplary (R)AN node 5, e.g., a base station (e.g., an LTE "eNB," a 5G "gNB," a 5G or later base station, or a 6G base station). As shown, the (R)AN node 5 includes transceiver circuitry 51 operable to transmit signals to and receive signals from connected UEs 3 via one or more antennas 52 and 53, and to transmit and receive signals (directly or indirectly) with other network nodes via a network interface 53. A controller 54 controls the operation of the (R)AN node 5 in accordance with software stored in memory 55. The software may be pre-installed in memory and / or downloaded over a communications network or from a removable data storage device (RMD). The software includes, among other things, an operating system 551 and a communications control module 552 having at least a transceiver control module 5521.
[0202] The communications control module 552 (using a transceiver control sub-module) handles (e.g., directly or indirectly) the processing (generation / transmission / reception) of signaling between the (R)AN node 5 and other nodes, such as a UE 3, another (R)AN node 5, an AMF 70, a UPF 72, etc. The signaling may include, for example, appropriately formatted signaling messages related to the radio connection and connection with the core network 7 (for a particular UE 3), in particular, related to establishing and maintaining the connection (e.g., RRC connection establishment and other RRC messages), NG Application Protocol (NGAP) messages (i.e., messages over the N2 reference point), and Xn Application Protocol (XnAP) messages (messages over the Xn reference point). Such signaling may also include, for example, broadcast information (e.g., master information and system information) in the case of transmission.
[0203] The controller 54 is also configured (either by software or hardware) to handle related tasks such as UE mobility estimation and / or movement trajectory estimation when implemented.
[0204] (R)AN node 5 may support a non-public network (NPN). The NPN may be a stand-alone non-public network (SNPN) or a public network integrated NPN (PNI-NPN).
[0205] <System overview of (R)AN node 5 based on the O-RAN architecture> FIG. 8 schematically shows (R)AN node 5 based on the O-RAN architecture to which the aspects of (R)AN node 5 are applicable.
[0206] (R)AN node 5 based on the O-RAN architecture represents a system overview in which the (R)AN node is divided into a radio unit (RU) 60, a distributed unit (DU) 61, and a central unit (CU) 62. In some aspects, the units can be combined. For example, RU 60 can be integrated / combined with DU 61 as an integrated / combined unit, and DU 61 can be integrated / combined with CU 62 as another integrated / combined unit. Any function in the description of a unit (e.g., one of RU 60, DU 61, and CU 62) can be implemented in the above integrated / combined unit. Further, CU 62 can be separated into two functional units such as a CU control plane (CP) and a CU user plane (UP). The CU CP has a control plane function within (R)AN node 5. The CU UP has a user plane function within (R)AN node 5. Each CU CP is connected to the CU UP via an appropriate interface (such as the so-called "E1" interface).
[0207] The UEs 3 and their respective serving RUs 60 are connected via an appropriate air interface (such as the so-called "Uu" interface). Each RU 60 is connected to a DU 61 via an appropriate interface (such as the so-called "Front haul," "Open Front haul," or "F1" interface). Each DU 61 is connected to a CU 62 via an appropriate interface (such as the so-called "Mid haul," "Open Mid haul," or "E2" interface). Each CU 62 is also connected to nodes in the core network 7 (such as so-called core network nodes) via an appropriate interface (such as the so-called "Back haul," "Open Back haul," or "N2" / "N3" interface). Furthermore, the user plane part of the DU 61 may also be connected to the core network nodes 7 via an appropriate interface (such as the so-called "N3" interface).
[0208] Depending on the functionality divided among the RU 60, DU 61, and CU 62, each unit provides a portion of the functionality provided by the (R)AN node 5. For example, the RU 60 may provide functionality for communicating with the UE 3 over the air interface, the DU 61 may provide functionality for supporting the MAC and RLC layers, and the CU 62 may provide functionality for supporting the PDCP, SDAP, and RRC layers.
[0209] <Radio Unit (RU)> FIG. 9 is a block diagram illustrating the main components of an exemplary RU 60, e.g., the RU portion of a base station (e.g., an LTE "eNB," a 5G "gNB," a 5G or later base station, or a 6G base station). As shown, the RU 60 includes one or more antennas 602 and transceiver circuitry 601 operable to transmit signals to and receive signals from connected UEs 3 via the one or more antennas 602, and to transmit and receive signals to and from other network nodes or units (directly or indirectly) via a network interface 603. A controller 604 controls the operation of the RU 60 in accordance with software stored in memory 605. The software may be pre-installed in the memory and / or downloaded via a communications network or from a removable data storage device (RMD). The software includes, among other things, an operating system 6051 and a communications control module 6052 having at least a transceiver control module 60521.
[0210] The communications control module 6052 (using a transceiver control sub-module) handles (e.g., directly or indirectly) the handling (generation / transmission / reception) of signaling between the RU 60 and other nodes, such as a UE 3, another RU 60, a DU 61, etc. The signaling may include, for example, appropriately formatted signaling messages related to the radio connection and connection (for a particular UE 3) with the RU 60, particularly the MAC and RLC layers.
[0211] The controller 604, if implemented, is also configured (by software or hardware) to handle related tasks such as UE mobility estimation and / or motion trajectory estimation.
[0212] The RU 60 may support a Non-Public Network (NPN), which may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0213] As mentioned above, the RU 60 can be integrated / combined with the DU 61 as an integrated / combined unit. Any of the functions described for the RU 60 can be implemented in the integrated / combined unit.
[0214] Distributed Unit (DU) FIG. 10 is a block diagram illustrating the main components of an exemplary DU 61, e.g., the DU portion of a base station (eNB for LTE, gNB for 5G, 5G or later base station, 6G base station). As shown, the device includes a transceiver circuit 611 operable to transmit and receive signals to and from other nodes or units (including the RU 60) via a network interface 612. A controller 613 controls the operation of the DU 61 in accordance with software stored in memory 614. The software may be pre-installed in the memory 614 and / or downloaded via a communications network or from a removable data storage device (RMD). The software includes, among other things, an operating system 6141 and a communications control module 6142 having at least a transceiver control module 61421. The communications control module 6142 (using its transceiver control module 61421) handles the processing (generation / transmission / reception) of signaling between the DU 61 and other nodes and units, such as the RU 60 and other nodes and units.
[0215] The DU 61 may support a Non-Public Network (NPN), which may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0216] As mentioned above, the RU 60 can be integrated / combined with the DU 61 as an integrated / combined unit. Any of the functions described for the DU 61 can be implemented in the integrated / combined unit.
[0217] <Centralized Unit (CU)> FIG. 11 is a block diagram illustrating the main components of an exemplary CU 62, e.g., the CU portion of a base station (eNB for LTE, gNB for 5G, 5G or later base station, 6G base station). As shown, the device includes a transceiver circuit 621 operable to transmit and receive signals to and from other nodes or units (including the DU 61) via a network interface 622. A controller 623 controls the operation of the CU 62 in accordance with software stored in memory 624. The software may be pre-installed in the memory 624 and / or downloaded via a communications network or from a removable data storage device (RMD). The software includes, among other things, an operating system 6241 and a communications control module 6242 having at least a transceiver control module 62421. The communications control module 6242 (using its transceiver control module 62421) handles the processing (generation / transmission / reception) of signaling between the CU 62 and other nodes and units, such as the DU 61 and other nodes and units.
[0218] CU 62 may support a Non-Public Network (NPN), which may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0219] As mentioned above, the CU 62 can be integrated / combined with the DU 61 as an integrated / combined unit. Any of the functions described for the CU 62 can be implemented in the integrated / combined unit.
[0220] <amf> 12 is a block diagram illustrating the main components of the AMF 70. As shown, the device includes a transceiver circuit 701 operable to transmit and receive signals to and from other nodes or units (including the UE 3) via a network interface 702. A controller 703 controls the operation of the AMF 70 in accordance with software stored in a memory 704. The software may be pre-installed in the memory 704 and / or downloaded via a communications network or from a removable data storage device (RMD). The software includes, among other things, an operating system 7041 and a communications control module 7042 having at least a transceiver control module 70421. The communications control module 7042 (using its transceiver control module 70421) handles the processing (generation / transmission / reception) of signaling between the AMF 70 and other nodes, such as the UE 3 (e.g., via the (R)AN node 5) as well as other core network nodes (including core network nodes in the UE 3's HPLMN if the UE 3 is roaming in). Such signaling may include, for example, appropriately formatted signaling messages related to access and mobility management procedures (for UE 3) (e.g., Registration Request messages and associated response messages).
[0221] The AMF 70 may support a Non-Public Network (NPN), which may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0222] <udm> 13 is a block diagram illustrating the major components of the UDM 75. As shown, the device includes a transceiver circuit 751 operable to transmit and receive signals to and from other nodes (including the AMF 70) via a network interface 752. A controller 753 controls the operation of the UDM 75 in accordance with software stored in memory 754. The software may be pre-installed in memory 754 and / or downloaded over a communications network or from a removable data storage device (RMD). The software includes, among other things, an operating system 7541 and a communications control module 7542 having at least a transceiver control module 75421. The communications control module 7542 (using its transceiver control module 75421) handles the processing (generation / sending / reception) of signaling between the UDM 75 and other nodes, such as the AMF 70 as well as other core network nodes (including core network nodes in the VPLMN of the UE 3 if the UE 3 is roaming out). Such signaling may include, for example, appropriately formatted signaling messages (e.g., Hypertext Transfer Protocol (HTTP) restful methods based on service-based interfaces) related to mobility management procedures (for the UE 3).
[0223] The UDM 75 may support a Non-Public Network (NPN), which may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0224] <Modifications and Alternatives> Detailed embodiments have been described above. As will be appreciated by those skilled in the art, many modifications and alternatives may be made to the above embodiments while still benefiting from the disclosure embodied herein. By way of example, some of these alternatives and modifications are now described.
[0225] In the above description, for ease of understanding, the UE 3 and network devices have been described as having a number of separate modules (e.g., a communications control module). While these modules may be provided in this manner for a particular application, for example, when an existing system is being modified to implement the disclosure, in other applications, such as a system designed from the beginning with the functionality of the invention in mind, these modules may be incorporated into the overall operating system or code, and these modules may not be recognizable as separate entities. These modules may be implemented in software, hardware, firmware, or a combination thereof.
[0226] Each controller may comprise any suitable form of processing circuitry, including, but not limited to, for example, one or more hardware-implemented computer processors, microprocessors, central processing units (CPUs), arithmetic logic units (ALUs), input / output (IO) circuitry, internal memory / cache (program and / or data), processing registers, communication buses (e.g., control buses, data buses, address buses, etc.), direct memory access (DMA) facilities, hardware or software implemented counters, pointers, and / or timers, and / or the like.
[0227] In the above embodiments, a number of software modules have been described. As will be appreciated by those skilled in the art, the software modules may be provided in compiled or uncompiled form and supplied to the UE 3 and network devices as signals over a computer network or on a recording medium. Furthermore, the functionality performed by some or all of this software may be performed using one or more dedicated hardware circuits. However, the use of software modules is preferred because they facilitate updating the functionality of the UE 3 and network devices.
[0228] In the above embodiments, 3GPP wireless communication (radio access) technologies are used, but other wireless communication technologies (e.g., WLAN, Wi-Fi, WiMAX, Bluetooth, etc.) and other fixed line communication technologies (e.g., BBF access, cable access, optical access, etc.) may also be used in accordance with the above embodiments.
[0229] Items of user equipment may include, for example, communication devices such as mobile phones, smartphones, user devices, personal digital assistants, laptop / tablet computers, web browsers, e-readers, etc. Such mobile (or generally fixed) devices are typically operated by a user, although so-called "Internet of Things" (IoT) devices and similar machine-type communication (MTC) devices may also be connected to the network. For simplicity, this application will refer to mobile devices (or UEs) in the description. However, it will be understood that the described techniques can be implemented on any communication device (mobile and / or generally fixed) that can connect to a communication network to transmit and receive data, regardless of whether such communication device is controlled by human input or by software instructions stored in memory.
[0230] Various other modifications will be apparent to those skilled in the art and will not be described in further detail here.
[0231] All or part of the exemplary aspects disclosed above can be expressed as follows, but are not limited thereto.
[0232] <4.2.2.2.2 Registration Overview> Figure 4.2.2.2.2-1: Registration procedure (see Figure 14)
[0233] 1. UE to (R)AN: AN message (AN parameters), Registration Request (Registration type, SUCI or 5G-GUTI or PEI, [last visited TAI (if available)], Security parameters, [Requested NSSAI], [Mapping Of Requested NSSAI], [Default Configured NSSAI Indication], [UE Radio Capability Update], [UE MM Core Network Capability], [PDU Session status], [List Of PDU Sessions To Be Activated], [Follow-on request], [MICO mode preference], [Requested Active Time], [Requested DRX parameters for E-UTRA and NR] NR), [Requested DRX parameters for NB-IoT], [Extended idle mode DRX parameters], [LADN DNN(s) or Indicator Of Requesting LADN information], [NAS message container], [Support for restriction of use of Enhanced Coverage], [Preferred Network Operation]Behavior), UE paging probability information, UE Policy Container (list of PSIs, indication of UE support for ANDSP and the operating system identifier), UE radio capability ID, Release Request indication, Paging Restriction Information, PEI, NSSRG handling support indication, PLMN with Disaster Condition).
[0234] NOTE 1: The UE policy container and its usage are defined in TS 23.503
[20] .
[0235] For NG-RAN, the AN parameters include, for example, 5G-S-TMSI or GUAMI, Selected PLMN ID (or PLMN ID and NID, see clause 5.30 of TS 23.501 [2]), and NSSAI information, and also include an Establishment cause. The Establishment cause provides the reason for requesting establishment of an RRC connection. Whether and how the UE includes NSSAI information as part of the AN parameters depends on the value of the Access Stratum Connection Establishment NSSAI Inclusion Mode parameter, as specified in clause 5.15.9 of TS 23.501 [2].
[0236] If the UE is an IAB node accessing 5GS, the AN parameters also include an IAB indication.
[0237] The registration type indicates whether the UE wants to perform an initial registration (i.e., the UE is in the RM-DEREGISTERED state), a mobility registration update (i.e., the UE is in the RM-REGISTERED state and initiates the registration procedure for mobility, or because the UE needs to update its capabilities or protocol parameters, or to request a change in the set of network slices it is authorized to use), a periodic registration update (i.e., the UE is in the RM-REGISTERED state and initiates the registration procedure due to expiration of the periodic registration update timer; see Section 4.2.2.2.1), an emergency registration (i.e., the UE is in a limited service state), or a disaster roaming registration.
[0238] If the UE uses E-UTRA, the UE indicates support for CIoT 5GS optimization related to AMF selection in the RRC connection establishment signaling associated with the registration request.
[0239] If the UE is performing initial registration or disaster roaming registration, the UE shall indicate the UE identity in the registration request message as follows, which are listed in order of decreasing priority for registration to a PLMN: i) If the UE has a valid EPS GUTI, the 5G-GUTI mapped from the EPS GUTI. ii) If available, the native 5G-GUTI assigned by the PLMN to which the UE is attempting to register; iii) If available, the native 5G-GUTI assigned by the equivalent PLMN to the PLMN the UE is attempting to register; iv) Native 5G-GUTI allocated by other PLMNs, if available. NOTE 2: This may also be a 5G-GUTI allocated via another access type. v) Otherwise, the UE shall include the SUCI in the registration request as defined in TS 33.501
[15] .
[0240] If the UE is registering with an SNPN, when the UE is performing initial registration, the UE indicates the UE identity in the registration request message as follows, listed in descending order of priority: i) If available, a native 5G-GUTI assigned by the same SNPN to which the UE is trying to register; ii) If available, the native 5G-GUTI assigned by any other SNPN together with the NID of the SNPN that assigned the 5G-GUTI; iii) Otherwise, the UE includes the SUCI in the registration request as defined in TS 33.501
[15] .
[0241] If the UE performing initial registration has both a valid EPS GUTI and a native 5G-GUTI, the UE shall also indicate the native 5G-GUTI as an additional GUTI. If multiple native 5G-GUTIs are available, the UE shall select a 5G-GUTI from items (ii) to (iv) in the above list in descending order of priority.
[0242] If the UE is sending a Registration Request message as an initial NAS message, the UE has a valid 5G NAS security context, and the UE needs to send non-cleartext IEs, the NAS message container is included. See clause 4.4.6 of TS 24.501
[25] . If the UE does not need to send non-cleartext IEs, the UE sends the Registration Request message without a NAS message container.
[0243] If the UE does not have a valid 5G NAS security context, the UE sends the Registration Request message without a NAS message container. The UE includes the entire Registration Request message (i.e., including the cleartext and non-cleartext IEs) in the NAS message container sent as part of the Security Mode Complete message in step 9b.
[0244] When the UE performs initial registration with native 5G-GUTI (i.e., when the UE is in RM-DEREGISTERED state), the UE indicates the related GUAMI information in the AN parameter. If the UE performs initial registration using SUCI, the UE does not indicate the GUAMI information in the AN parameter.
[0245] If the UE is performing initial registration or mobility registration and CIoT 5GS optimization is supported, the UE shall indicate its Preferred Network Behavior (see clause 5.31.2 of TS 23.501 [2]). If S1 mode is supported, the UE's EPC Preferred Network Behavior shall be included in the S1 UE network capabilities of the Registration Request message (see clause 8.2.6.1 of TS 24.501
[25] ).
[0246] In case of emergency registration, if the UE does not have a valid 5G-GUTI available, the SUCI is included. If the UE has neither a SUPI nor a valid 5G-GUTI, the PEI is included. In other cases, the 5G-GUTI is included, indicating the last serving AMF.
[0247] The UE may provide its usage settings based on its configuration as defined in clause 5.16.3.7 of TS23.501[2]. The UE shall provide the requested NSSAIs (as described in clause 5.15.5.2.1 of TS 23.501 [2], taking into account the NSSRG information constraints if the UE supports subscription-based restrictions to simultaneous registration of network slices as described in clause 5.15.12 of TS 23.501 [2]). In the case of an Initial Registration or Mobility registration update, the UE shall include the mapping of the requested NSSAIs (if available), which is the mapping of each S-NSSAI of the requested NSSAI to the HPLMN S-NSSAI, so that the network can be sure that the S-NSSAI in the requested NSSAI is allowed based on the Subscribed S-NSSAI. In the case of inter-PLMN mobility, the UE shall include the mapping of the requested NSSAIs to the HPLMN S-NSSAI, if available, so that the network can be sure that the S-NSSAI in the requested NSSAI is allowed based on the Subscribed S-NSSAI. In the case of inter-PLMN mobility, the UE shall include the mapping of the serving PLMN corresponding to the established PDU session as described in clause 5.15.5.2.1 of TS 23.501 [2]. If the S-NSSAI does not exist in the UE, the relevant HPLMN S-NSSAI associated with the established PDU session is provided in the mapping of the requested NSSAI.
[0248] If the UE is using a Default Configured NSSAI as defined in TS 23.501 [2], the UE shall include a Default Configured NSSAI indication.
[0249] If the UE supports allocation of WUS Assistance Information from the AMF, it may include UE paging probability information (see TS23.501[2]).
[0250] In the case of a mobility registration update, the UE includes in the list of PDU sessions to be activated those PDU sessions for which there is pending uplink data. When the UE includes in the list of PDU sessions to be activated, it indicates only those PDU sessions associated with the access to which the registration request relates. As defined in TS 24.501
[25] , the UE includes in the list of PDU sessions to be activated those always-on PDU sessions that are accepted by the network, even if those PDU sessions have no pending uplink data.
[0251] NOTE 3: The PDU session corresponding to the LADN is not included in the list of PDU sessions to be activated if the UE is outside the available area of the LADN.
[0252] The UE MM Core Network Function is provided by the UE and processed by the AMF as defined in clause 5.4.4a of TS 23.501 [2]. The UE includes in the UE MM Core Network Function an indication of whether it supports the request type flag "Handover" in the PDN connection request during the attach procedure as defined in clause 5.17.2.3.1 of TS 23.501 [2]. If the UE supports "Strictly Periodic Registration Timer Indication", the UE indicates the capability of "Strictly Periodic Registration Timer Indication" in the UE MM Core Network Capabilities. If the UE supports CAG, the UE indicates the capability of "CAG supported" in the UE MM Core Network Capabilities. If the UE operates more than one USIM and supports and intends to use one or more multi-USIM features, the UE shall indicate one or more multi-USIM specific features listed in clause 5.38 of TS 23.501 [2] in the UE MM Core Network Functions.
[0253] The UE can provide either the LADN DNN or an Indication of Requesting LADN Information as described in clause 5.6.5 of TS 23.501 [2].
[0254] If available, the last visited TAI is included to allow the AMF to generate the registration area for the UE.
[0255] The security parameters are used for authentication and integrity protection. See TS 33.501
[15] . The requested NSSAI indicates the Network Slice Selection Assistance Information (defined in clause 5.15 of TS 23.501 [2]). The PDU session status indicates the PDU session previously established in the UE. If the UE is connected to two AMFs belonging to different PLMNs via 3GPP and non-3GPP accesses, the PDU session status indicates the PDU session established in the current PLMN in the UE.
[0256] The Follow-on request is included if the UE has pending uplink signaling and the UE does not include a list of PDU sessions to be activated, or if the registration type indicates that the UE wants to perform an emergency registration. In the initial registration and mobility registration update, the UE provides UE Requested DRX parameters as defined in clause 5.4.5 of TS 23.501 [2]. The UE can request extended idle mode DRX by providing extended idle mode DRX parameters as defined in clause 5.31.7.2 of TS 23.501 [2].
[0257] The UE provides a UE Radio Capability Update indication as described in TS 23.501 [2].
[0258] The UE includes a preference for MICO mode and, optionally, a requested active time value if the UE wants to use MICO mode during active time.
[0259] The UE can indicate its Service Gap Control Capability at the UE MM Core Network Function, see clause 5.31.16 of TS 23.501 [2].
[0260] If the UE has a Service Gap Timer running in it, the UE shall not set the Follow-on Request Indicator or the Uplink Data Status in the Registration Request message, except for network access for barred priority services such as emergency services or exception reporting (see clause 5.31.16 of TS 23.501 [2]).
[0261] If the UE supports RACS and has been assigned a UE Radio Capability ID, the UE shall indicate the UE Radio Capability ID as defined in clause 5.4.4.1a of TS 23.501 [2] as a non-plaintext IE.
[0262] The PEI can be obtained from the UE during initial registration as described in section 4.2.2.2.1.
[0263] If the UE supports the subscription-based restrictions to simultaneous registration of network slices feature, the UE includes an NSSRG handling support indication according to clause 5.15.12 of TS 23.501 [2]. The AMF stores in the UE context whether the UE supports this feature.
[0264] For example, if a UE in MUSIM mode wants to enter CM-IDLE state immediately after performing mobility or periodic registration, the UE may include a release request indication and optionally provide paging restriction information.
[0265] If the UE is performing a disaster roaming registration, the UE may indicate the disaster situation to the PLMN if the UE does not have a valid 5G-GUTI indicating the PLMN in disaster condition, and the PLMN with Disaster Condition is not the UE's HPLMN, or the PLMN with Disaster Condition is the UE's HPLMN but the UE does not provide its SUCI.
[0266] 2. If the 5G-S-TMSI or GUAMI is not included, or if the 5G-S-TMSI or GUAMI does not indicate a valid AMF, the (R)AN shall select an AMF based on the (R)AT and requested NSSAI, if available.
[0267] The (R)AN selects the AMF as described in clause 6.3.5 of TS 23.501 [2]. If the UE is in CM-CONNECTED state, the (R)AN can forward the registration request message to the AMF based on the UE's N2 connection.
[0268] If the (R)AN cannot select a suitable AMF, it forwards the registration request to an AMF that is configured to perform AMF selection in the (R)AN.
[0269] 3. New AMF:N2 message from the (R)AN (with N2 parameters, Registration Request (described in step 1) and [LTE-M Indication]).
[0270] If NG-RAN is used, the N2 parameters include a UE context request indicating that a UE context should be established in the NG-RAN, including the selected PLMN ID (or PLMN ID and NID, see clause 5.30 of TS 23.501 [2]), location information, cell identity related to the cell the UE is camped on, and security information.
[0271] If NG-RAN is used, the N2 parameter also contains the establishment cause and, if an indication was received in the AN parameter in step 1, the IAB indication.
[0272] Mapping of the requested NSSAI will be provided only if available.
[0273] If the registration type indicated by the UE is periodic registration update, steps 4 to 19 may be omitted.
[0274] If the establishment cause is associated with a priority service (MPS, MCS, etc.), the AMF includes a Message Priority header indicating the priority information. Other NFs relay the priority information by including a Message Priority header in their service-based interfaces as specified in TS 29.500
[17] .
[0275] The RAT type used by the UE is determined (see section 4.2.2.2.1) and based on that the AMF decides whether the UE is performing inter-RAT mobility to or from NB-IoT. When the AMF receives an LTE-M indication, it considers the RAT type to be LTE-M and stores the LTE-M indication in the UE context.
[0276] If the UE includes a preferred network behavior, this defines the network behavior that the UE supports and is expected to be available in the network, as defined in clause 5.31.2 of TS 23.501 [2].
[0277] If the UE includes a preferred network operation and what the UE indicates it supports in its preferred network operation is not compatible with the network support, the AMF rejects the registration request with an appropriate cause value (e.g., a value that avoids retries with this PLMN).
[0278] If a Service Gap Timer is running in the UE context of the AMF for the UE and a Follow-on Request indication or an uplink data status is included in the registration request message, the AMF shall ignore the Follow-on Request indication and the uplink data status and shall not perform any action related to the status.
[0279] If the UE included the UE radio capability ID in step 1 and the AMF supports RACS, the AMF stores the radio capability ID in the UE context.
[0280] For NR satellite access, if the AMF can determine, based on the selected PLMN ID and ULI (including cell ID) received from the gNB, that the UE is attempting to register with a PLMN that is not authorized to operate at the UE's current location, the AMF shall reject the registration request indicating an appropriate cause value and, if known to the AMF, the country of the UE's location. Otherwise, if the AMF does not know the UE's location with sufficient accuracy to make a final decision, the AMF may proceed with the registration procedure and initiate a UE location procedure as specified in clause 6.10.1 of TS 23.273
[51] , preparing to deregister the UE if the information received from the LMF proves that the UE is registered with a PLMN that is not authorized to operate at the UE's location.
[0281] NOTE 4: It cannot be guaranteed that the location information is accurate enough for the AMF to identify the country in which the UE is located in all cases.
[0282] NOTE 5: Because multiple MCCs are used in some countries and some MCCs, such as 901, are allowed in multiple countries, the UE may register with a PLMN using a different MCC than the MCC returned to the UE.
[0283] Upon receiving a registration rejection from the country in which the UE is located, the UE shall attempt to register with a PLMN that is permitted to operate in the UE's location, as specified in TS 23.122
[22] .
[0284] For disaster roaming registration, the AMF determines whether disaster roaming service can be provided based on the ULI (including cell ID) received from the NG-RAN, the PLMN with a disaster situation derived from the UE's 5G-GUTI, derived from the UE's SUCI, or indicated by the UE, and local configuration. If the current location is not eligible for disaster roaming service or if disaster roaming service is not provided for the PLMN with a disaster situation derived from the UE's 5G-GUTI, derived from the UE's SUCI, or indicated by the UE, the AMF rejects the registration request with an appropriate cause value.
[0285] 4. [Conditional] From new AMF to old AMF: Namf_Communication_UEContextTransfer (full registration request), or from new AMF to UDSF: Nudsf_Unstructured Data Management_Query().
[0286] The new AMF determines the old AMF using the UE's 5G-GUTI. If the new AMF receives the NID in the registration request, it determines that the 5G-GUTI was assigned by the SNPN and uses the 5G-GUTI and the SNPN's NID to determine the old AMF.
[0287] (With UDSF): If the UE's 5G-GUTI is included in the registration request and the serving AMF has changed since the last registration procedure, if the new AMF and the old AMF are in the same AMF set and UDSF is deployed, the new AMF can use the Nudsf_UnstructuredDataManagement_Query service operation to obtain the stored UE's SUPI and UE context directly from the UDSF. If UDSF is not deployed, the new AMF can share the stored UE context via implementation-specific means. This also includes event subscription information by each NF consumer for a specific UE. In this case, the new AMF performs and verifies integrity protection using an integrity-protected complete Registration Request NAS message.
[0288] (Without UDSF implementation): If the UE's 5G-GUTI is included in the registration request and the serving AMF has changed since the last registration procedure, the new AMF may invoke the NAMF_Communication_UEContextTransfer service operation on the old AMF, including the access type along with the integrity-protected complete registration request NAS message, to request the UE's SUPI and UE context. For details about this service operation, see Section 5.2.2.2.2. In this case, if the context transfer service operation invocation corresponds to the requested UE, the old AMF verifies the integrity protection using the 5G-GUTI and the integrity-protected complete registration request NAS message, or the SUPI and an indication that the UE has been activated from the new AMF. The old AMF checks the integrity of the received complete registration request message using the 5G NAS security context associated with the access type. In this case, the UE uses a UL NAS COUNT that is set to zero if the UL NAS COUNT corresponding to the common 5G NAS security context and access type is not stored, and uses the stored UL NAS COUNT and NAS connection identifier corresponding to the access type. The old AMF also forwards event subscription information by each NF consumer for the UE to the new AMF. If the old AMF has not yet reported a non-zero MO Exception Data Counter to the (H-)SMF, the context response also includes the MO Exception Data Counter.
[0289] If the old AMF has a PDU session with a different access type (different from the access type indicated in this procedure) and the old AMF determines that there is no possibility to relocate the N2 interface to the new AMF, the old AMF returns the UE's SUPI, indicating that the registration request has been validated for integrity protection, but does not include the remaining UE context.
[0290] In the case of inter-PLMN mobility, the UE context information does not include the allowed NSSAI of the old PLMN, but includes the HPLMN S-NSSAI corresponding to the allowed NSSAI for each access type.
[0291] NOTE 6: The new AMF sets an indication that the UE is enabled according to step 9a if the new AMF successfully authenticates the UE after a previous integrity check failure in the old AMF.
[0292] NOTE 7: The NF consumer does not need to resubscribe to events in the new AMF after the UE has successfully registered with the new AMF.
[0293] If the new AMF has already received the UE context from the old AMF during the handover procedure, steps 4, 5 and 10 are skipped.
[0294] In case of emergency registration, if the UE identifies itself with a 5G-GUTI that is not known to the AMF, steps 4 and 5 are skipped and the AMF immediately requests a SUPI from the UE. If the UE identifies itself with a PEI, the SUPI request is skipped. The permission of emergency registration without a user identifier depends on local regulations.
[0295] 5. [Conditional] From the old AMF to the new AMF: Response to Namf_Communication_UEContextTransfer (SUPI, UE context in AMF (according to Table 5.2.2.2.2-1)), or from UDSF to the new AMF: Nudsf_Unstructured Data Management_Query (). The old AMF may start an implementation-specific (guard) timer for the UE context.
[0296] If the UDSF is queried in step 4, it responds to the new AMF with a Nudsf_Unstructured Data Management_Query call with the associated context including the established PDU session, and the old AMF includes information about the NGAP UE-TNLA binding, including SMF information DNN, S-NSSAI, PDU session ID, and active NGAP UE-TNLA binding to N3IWF / TNGF / W-AGF. If the old AMF is queried in step 4, it responds to the new AMF with a Nudsf_Communication_UEContextTransfer call by including the UE's SUPI and UE context.
[0297] If the old AMF holds information about an established PDU session and it is not an initial registration, the old AMF includes SMF information, DNN, S-NSSAI, and PDU session ID.
[0298] If the old AMF holds a UE context established via N3IWF, W-AGF, or TNGF, the old AMF includes the CM state via N3IWF, W-AGF, or TNGF. If the UE is in CM-CONNECTED state via N3IWF, W-AGF, or TNGF, the old AMF includes information about the NGAP UE-TNLA binding.
[0299] If the old AMF fails the integrity check of the registration request NAS message, the old AMF indicates an integrity check failure. If the new AMF is configured to allow emergency services for unauthenticated UEs, the new AMF operates as follows:
[0300] If the UE only has an emergency PDU session, the AMF skips the authentication and security procedures or accepts that authentication may fail and continues with the mobility registration update procedure, or
[0301] If the UE has both emergency and non-emergency PDU sessions and authentication fails, the AMF continues the mobility registration update procedure and deactivates all non-emergency PDU sessions as specified in section 4.3.4.2.
[0302] NOTE 8: The new AMF can determine whether a PDU session is used for emergency services by checking whether the DNN matches the emergency DNN.
[0303] If the old AMF holds information about the AM policy association and information about the UE policy association (i.e., the policy control request trigger for updating the UE policy defined in TS 23.503
[20] ), the old AMF includes information about the AM policy association, the UE policy association, and the PCF ID. In case of roaming, the V-PCF ID and the H-PCF ID are included.
[0304] If the old AMF was a consumer of the UE-related NWDAF service, the old AMF includes information about the active analysis subscription, i.e., subscription correlation ID, NWDAF identifier (i.e., instance ID or set ID), analysis ID, and associated analysis-specific data, in the Namf_Communication_UEContextTransfer response. The use of analysis information by the new AMF is specified in TS 23.288
[50] .
[0305] During inter-PLMN mobility, the handling of the UE radio capability ID in the new AMF is as defined in TS 23.501 [2].
[0306] NOTE 9: If the new AMF uses UDSF for context acquisition, the interaction between the old AMF, new AMF and UDSF due to UE signaling in the old AMF at the same time becomes an implementation issue.
[0307] 6. [Conditional] New AMF to UE: Identity Request ().
[0308] If the SUCI is not provided by the UE and not obtained from the old AMF, the Identity Request procedure is initiated by the AMF sending an Identity Request message to the UE requesting the SUCI.
[0309] 7. [Conditional] UE to new AMF: Identity Response ().
[0310] The UE responds with an Identity Response message containing the SUCI, which the UE derives using the HPLMN's provisioned public key as specified in TS33.501
[15] .
[0311] 8. The AMF may decide to initiate UE authentication by invoking the AUSF, in which case the AMF selects the AUSF based on the SUPI or SUCI as described in clause 6.3.4 of TS 23.501 [2].
[0312] If the AMF is configured to support unauthenticated SUPI Emergency Registration and the UE indicates a registration type of Emergency Registration, the AMF may skip authentication or accept that authentication may fail and continue with the registration procedure.
[0313] 9a. If authentication is required, the AMF requests authentication from the AUSF, and if the Tracing Requirements for the UE are available in the AMF, the AMF provides the tracing requirements in the request to the AUSF. Upon request from the AMF, the AUSF performs authentication of the UE. Authentication is performed as described in TS 33.501
[15] . The AUSF selects a UDM as described in clause 6.3.8 of TS 23.501 [2] and obtains authentication data from the UDM.
[0314] Editor's Note: In the case of disaster roaming registration, how the AUSF performs authentication of the UE is FFS.
[0315] Once the UE is authenticated, the AUSF provides the relevant security-related information to the AMF. If the AMF provides the SUCI to the AUSF, the AUSF returns the SUPI to the AMF only after successful authentication.
[0316] After successful authentication with the new AMF triggered by a failed integrity check with the old AMF in step 5, the new AMF invokes step 4 above again and indicates that the UE has been activated (i.e., through the reason parameter specified in clause 5.2.2.2.2).
[0317] 9b If no NAS security context exists, NAS security initiation is performed as described in TS 33.501
[15] . If the UE did not have a NAS security context in step 1, the UE includes the complete Registration Request message as defined in TS 24.501
[25] .
[0318] The AMF decides whether the registration request needs to be rerouted as described in Section 4.2.2.2.3, where Initial AMF refers to the AMF.
[0319] 9c. If the 5G-AN requests a UE context, the AMF initiates the NGAP procedure and provides the 5G-AN with the security context specified in TS38.413
[10] . If the AMF determines that EPS fallback is supported (e.g., based on the UE's capabilities, subscription data, and local policy supporting the request type flag "handover" in the PDN connection request during the attach procedure defined in clause 5.17.2.3.1 of TS23.501 [2]), the AMF sends an indication to the 5G-AN that "Redirection for EPS fallback for voice is possible" as specified in TS38.413
[10] . Otherwise, the AMF indicates that "Redirection for EPS fallback for voice is not possible." Additionally, if the trace requirements for the UE are available to the AMF, the AMF provides the trace requirements to the 5G-AN in the NGAP procedure.
[0320] 9d. The 5G-AN stores the security context and acknowledges it to the AMF. The 5G-AN uses the security context to protect messages exchanged with the UE as described in TS33.501
[15] .
[0321] 10. [Conditional] From new AMF to old AMF: Namf_Communication_RegistrationStatusUpdate (PDU session ID to be released, e.g., because slicing is not supported).
[0322] If the AMF is changed, the new AMF notifies the old AMF that the UE's registration to the new AMF is complete by calling the Namf_Communication_RegistrationStatusUpdate service operation.
[0323] If the authentication / security procedures fail, the registration is rejected and the new AMF invokes the Namf_Communication_RegistrationStatusUpdate service operation with a rejection indication to the old AMF. The old AMF continues as if the UE context transfer service operation had never been received.
[0324] If one or more S-NSSAIs used in the old registration area cannot be served in the target registration area, the new AMF determines which PDU sessions cannot be supported in the new registration area. The new AMF invokes the Namf_Communication_RegistrationStatusUpdate service operation with the rejected PDU session IDs for the old AMF. The new AMF then changes the PDU session status accordingly. The old AMF notifies the corresponding SMF to locally release the UE's SM context by invoking the Nsmf_PDUSession_ReleaseSMContext service operation.
[0325] If the new AMF receives information about the AM policy association and UE policy association in the UE context transfer in step 5 and decides based on local policy not to use the PCF identified by the PCF ID for the AM policy association and UE policy association, it notifies the old AMF that the AM policy association and UE policy association in the UE context will no longer be used, and then PCF selection is performed in step 15.
[0326] If the new AMF receives information about the UE-related analysis subscriptions in the UE context transfer in step 5, the new AMF may take over the analysis subscriptions from the old AMF. Otherwise, if the new AMF decides to create new analysis subscriptions instead, it may inform the old AMF about the analysis subscriptions (identified by the Subscription Correlation ID) that are no longer needed, and the old AMF may unsubscribe from the UE's NWDAF analysis subscriptions according to TS 23.288
[50] .
[0327] 11. [Conditional] New AMF to UE: Identity Request / Response (PEI).
[0328] If the PEI was not provided by the UE or was not obtained from the old AMF, the identity request procedure is initiated by the AMF sending an identity request message to the UE to obtain the PEI. The PEI is transmitted encrypted unless the UE performs emergency registration and cannot be authenticated.
[0329] In case of Emergency Registration, the UE may include the PEI in the registration request, in which case PEI acquisition is skipped.
[0330] As indicated in the UE MM Core Network Functions, if the UE supports RACS, the AMF uses the UE's PEI to obtain the IMEI / TAC for the purpose of RACS operation.
[0331] 12. Optionally, the new AMF initiates an ME identity check by calling the N5g-eir_EquipmentIdentityCheck_Get service operation (see Section 5.2.4.2.2).
[0332] PEI checks are performed as described in Section 4.7.
[0333] In the case of emergency registration, if the PEI is blocked, operator policy determines whether to continue or stop the emergency registration procedure.
[0334] 13. If step 14 is performed, the new AMF selects a UDM based on the SUPI, and then the UDM can select a UDR instance. See section 6.3.9 of TS23.501[2].
[0335] The AMF selects the UDM as described in clause 6.3.8 of TS 23.501 [2].
[0336] 14a-c. If the AMF has changed since the last registration procedure, or if the UE provides a SUPI that does not reference a valid context in the AMF, or if the UE registers with the same AMF that is already registered for non-3GPP access (i.e., the UE is registered via non-3GPP access and initiates this registration procedure to add 3GPP access), the new AMF registers with the UDM for the access to which it is registered using Nudm_UECM_Registration (and subscribes to be notified when the UDM deregisters this AMF). In this case, if the AMF does not have event exposure subscription information for this UE, the AMF notifies the UDM. Then, if the UDM has existing applicable event exposure subscriptions for events detected in the AMF for this UE or any of the groups to which this UE belongs (possibly obtained from the UDR), the UDM calls the Namf_EventExposure_Subscribe service to recreate the event exposure subscriptions.
[0337] The AMF shall provide the "Homogenous Support of IMS Voice over PS Sessions" indication (see clause 5.16.3.3 of TS 23.501 [2]) to the UDM. The "Homogenous Support of IMS Voice over PS Sessions" indication shall not be included unless the AMF has completed its evaluation of the support for "IMS Voice over PS Sessions" as specified in clause 5.16.3.2 of TS 23.501 [2].
[0338] During initial registration, if the AMF and UE support SRVCC from NG-RAN to UTRAN, the AMF provides the UE SRVCC capability to the UDM.
[0339] If the AMF determines that only the UE SRVCC capability has changed, the AMF sends the UE SRVCC capability to the UDM.
[0340] NOTE 10: At this step, the AMF may not have all the information necessary to determine the setting of the IMS Voice over PS Session Supported indication for this UE (see clause 5.16.3.2 of TS 23.501 [2]). Therefore, the AMF may send "Homogenous Support of IMS Voice over PS Sessions" later in this procedure.
[0341] If the AMF does not have the UE's subscription data, the AMF uses Nudm_SDM_Get to obtain the Access and Mobility Subscription data, SMF Selection Subscription data, the UE context in SMF data, and LCS mobile origination. If the AMF already has the UE's subscription data, but the SoR update indication in the UE context requires the AMF to obtain SoR information depending on the NAS registration type (Initial Registration or Emergency Registration) (see Annex C of TS23.122
[22] ), the AMF uses Nudm_SDM_Get to obtain the Steering of Roaming information. This requires that the UDM can obtain this information from the UDR via Nudr_DM_Query. After receiving a successful response, the AMF subscribes to be notified using Nudm_SDM_Subscribe when the requested data changes, and the UDM can subscribe to the UDR by Nudr_DM_Subscribe. If GPSI is available in the UE subscription data, the GPSI is provided to the AMF in the access and mobility subscription data from the UDM. The UDM can provide an indication that the subscription data for network slicing has been updated for the UE. If the UE is subscribed to MPS in the serving PLMN, the "MPS priority" is included in the access and mobility subscription data provided to the AMF. If the UE is subscribed to MCX in the serving PLMN, the "MCX priority" is included in the access and mobility subscription data provided to the AMF.The UDM also provides an IAB-Operation allowed Indication to the AMF as part of the access and mobility subscription data, which triggers the setup of a UE context in the NG-RAN or a modification of the UE context in the NG-RAN if the initial setup is in step 9c, including an indication that the IAB node is allowed.
[0342] Editor's Note: In the case of Disaster Roaming registrations, the method by which UDM provides AMF with subscription data applicable to Disaster Roaming services is FFS.
[0343] The new AMF provides the UDM with the access type to provide to the UE, and the access type is set to "3GPP access". The UDM stores the associated access type together with the serving AMF and does not delete any AMF identities associated with other access types. The UDM may store the information provided by Nudr_DM_Update during AMF registration in the UDR.
[0344] If the UE is registered to the old AMF for access and the old AMF and the new AMF are in the same PLMN, the new AMF sends a separate / independent Nudm_UECM_Registration to update the UDM with the access type set to the access used by the old AMF after the relocation of the old AMF is successfully completed.
[0345] The new AMF creates a UE context for the UE after obtaining the access and mobility subscription data from the UDM. The access and mobility subscription data includes whether the UE is allowed to include NSSAI in the 3GPP access RRC connection establishment in the clear. The access and mobility subscription data may include Enhanced Coverage Restricted information. If received from the UDM and the UE included support for Extended Coverage Usage Restriction in step 1, the AMF determines whether Extended Coverage is restricted for the UE as specified in clause 5.31.12 of TS 23.501 [2] and stores the updated Enhanced Coverage Restricted information in the UE context.
[0346] The Access and Mobility Subscription data may include NB-IoT UE Priority.
[0347] The subscription data may include a service gap time parameter. If received from the UDM, the AMF stores this service gap time in the UE context in the AMF for the UE.
[0348] In the case of an emergency registration where the UE is not successfully authenticated, the AMF does not register with the UDM.
[0349] The AMF enforces the mobility restrictions specified in clause 5.3.4.1.1 of TS 23.501 [2]. In case of emergency registration, the AMF does not check mobility restrictions, access restrictions, regional restrictions, or subscription restrictions. In case of emergency registration, the AMF ignores the failed registration response from the UDM and continues the registration procedure.
[0350] NOTE 11: The AMF may use the Nudm_SDM_Subscribe service operation with an Immediate Report Indication to trigger the UDM to immediately return the subscribed data instead of the Nudm_SDM_Get service operation if the corresponding functionality is supported by both the AMF and the UDM.
[0351] 14d. If the UDM stores the associated access type (e.g., 3GPP) with the serving AMF as shown in step 14a, the UDM initiates Nudm_UECM_DeregistrationNotification (see section 5.2.3.2.2) to the old AMF (if any) corresponding to the same (e.g., 3GPP) access. If the timer started in step 5 is not running, the old AMF may delete the UE context for the same access type. Otherwise, the AMF may delete the UE context for the same access type when the timer expires. If the serving NF deletion reason indicated by the UDM is initial registration, as described in section 4.2.2.3.2, the old AMF invokes the Nsmf_PDUSession_ReleaseSMContext(SM context ID) service operation to all SMFs associated with the UE to notify them that the UE has been deregistered from the old AMF for the same access type. The SMF releases the PDU session upon receiving this notification.
[0352] If the old AMF has established an AM policy association and a UE policy association with the PCF and the old AMF did not transfer the PCF ID to the new AMF (for example, the new AMF is in a different PLMN), the old AMF performs the AMF-initiated Policy Association Termination procedure as defined in subclause 4.16.3.2 and the AMF-initiated UE Policy Association Termination procedure as defined in subclause 4.16.13.1. In addition, if the old AMF transferred the PCF ID in the UE context but the new AMF indicates in step 10 that the AM policy association information and UE policy association information in the UE context will not be used, the old AMF performs the AMF-initiated Policy Association Termination procedure as defined in subclause 4.16.3.2 and the AMF-initiated UE Policy Association Termination procedure as defined in subclause 4.16.13.1.
[0353] If the old AMF has an N2 connection for the UE (e.g. because the UE was in RRC Inactive state but has now moved to E-UTRAN or to an area not served by the old AMF), the old AMF performs an AN release (see section 4.2.6) with a cause value indicating that the UE has already released the RRC connection in the NG-RAN locally.
[0354] If the UE context of the old AMF contains authorized NSSAIs including one or more S-NSSAIs that are subject to NSAC, upon receiving Nudm_UECM_DeregistrationNotification from the UDM, the old AMF shall send an Update Request message for each S-NSSAI that is subject to NSAC to the corresponding NSACF (see clause 4.2.11.2) with the Update Flag parameter set to decrease (see clause 4.2.11.2).
[0355] If in step 14a the AMF does not indicate that the event exposure subscription is unavailable, then at the end of the registration procedure the AMF may initiate the synchronization of event exposure subscriptions with the UDM.
[0356] NOTE 12: The AMF may initiate synchronization with the UDM even if the event is available based on local policy at any time in the UE context (e.g., as received from the old AMF). This can be done during subscription change related events.
[0357] 14e. [Conditional] If the old AMF does not have a UE context for another access type (i.e., non-3GPP access), the old AMF unsubscribes the UDM for subscription data using Nudm_SDM_unsubscribe.
[0358] 15. If the AMF decides to initiate PCF communication, the AMF operates as follows:
[0359] If the new AMF decides to use the (V-)PCF identified by the (V-)PCF ID included in the UE context from the old AMF in step 5, the AMF contacts the (V-)PCF identified by the (V-)PCF ID to obtain the policy. If the AMF decides to perform PCF discovery and selection, it selects a (V)-PCF and may select an H-PCF (in case of roaming scenarios) by V-NRF and H-NRF interaction as described in clause 6.3.7.1 and clause 4.3.2.2.3.3 of TS 23.501 [2].
[0360] 16. [Optional] The new AMF performs AM policy association establishment / modification. In case of emergency registration, this step is skipped.
[0361] If the new AMF selected a new (V-)PCF in step 15, the new AMF performs the establishment of an AM policy association with the selected (V-)PCF as defined in clause 4.16.1.2.
[0362] If a (V-)PCF identified by the (V-)PCF ID included in the UE context from the old AMF is used, the new AMF performs the AM policy association change using the (V-)PCF as defined in clause 4.16.2.1.2.
[0363] When the AMF notifies the PCF of mobility restrictions (e.g., the location of the UE) for adjustment, or when the PCF updates the mobility restrictions itself due to some conditions (e.g., the application in use, the date and time), the PCF provides the updated mobility restrictions to the AMF. If the subscription information includes tracing requirements, the AMF provides the tracing requirements to the PCF.
[0364] If the AMF supports DNN replacement, the AMF provides the PCF with the allowed NSSAI and, if available, a mapping of the allowed NSSAI.
[0365] If the PCF supports DNN substitution, the PCF provides the AMF with a trigger for DNN substitution.
[0366] 17. [Conditional] AMF to SMF: Nsmf_PDUSession_UpdateSMContext().
[0367] For an Emergency Registered UE (see TS23.501[2]), this step applies if the registration type is Mobility Registration Update.
[0368] AMF calls Nsmf_PDUSession_UpdateSMContext (see Section 5.2.8.2.6) in the following scenarios:
[0369] If the registration request in step 1 contains a list of PDU sessions to be activated, the AMF sends an Nsmf_PDUSession_UpdateSMContext Request request to the SMF associated with these PDU sessions to activate the user plane connections for these PDU sessions. Steps 5 and following steps described in subclause 4.2.3.2 are performed to complete the activation of the user plane connections without sending RRC Inactive Assistance Information and without sending an MM NAS Service Accept from the AMF to the (R)AN as described in step 12 of subclause 4.2.3.2. Once the user plane connections for the PDU sessions are activated, the AS layer of the UE notifies the NAS layer.
[0370] If in step 3 the AMF determines that the UE is performing inter-RAT mobility to or from NB-IoT, the AMF sends an Nsmf_PDUSession_UpdateSMContext request to the SMF associated with the UE's PDU sessions so that the SMF can update them according to the "PDU Session continuity at inter RAT mobility" subscription data. The steps from step 5 onwards described in subclause 4.2.3.2 are performed without sending an MM NAS Service Accept from the AMF to the (R)AN described in step 12 of subclause 4.2.3.2.
[0371] If the serving AMF changes, the new serving AMF notifies the SMFs of each PDU session that it has taken over responsibility for the signaling path to the UE, and the new serving AMF invokes the Nsmf_PDUSession_UpdateSMContext service operation using the SMF information received from the old AMF in step 5. It also indicates whether the PDU session should be reactivated.
[0372] NOTE 13: When a UE moves to another PLMN, the AMF of the serving PLMN can insert or change the V-SMF in the serving PLMN of the Home Routed PDU session. In this case, the same procedures described in subclause 4.23.3 apply to the V-SMF change as to the I-SMF change (i.e., by replacing the I-SMF with the V-SMF). If the same SMF is used during the change between PLMNs, session continuity can be supported depending on the operator's policy.
[0373] The steps from step 5 onwards described in section 4.2.3.2 are performed. If an intermediate UPF is inserted, deleted or modified for a PDU session that is not included in the "PDU Session(s) to be re-activated", this procedure is performed without interaction with N11 and N2 to update the N3 user plane between the (R)AN and the 5GC.
[0374] AMF invokes the Nsmf_PDUSession_ReleaseSMContext service operation to SMF in the following scenarios:
[0375] -If any PDU session status indicates that it has been released in the UE, the AMF invokes the Nsmf_PDUSession_ReleaseSMContext service operation to the SMF to release the network resources associated with the PDU session.
[0376] If the serving AMF has changed, the new AMF waits until step 18 is completed for all SMFs associated with the UE. Otherwise, steps 19 to 22 can continue in parallel with this step.
[0377] 18. [Conditional] If the new AMF and the old AMF are in the same PLMN, the new AMF sends a UE context modification request to the N3IWF / TNGF / W-AGF as specified in TS 29.413
[64] .
[0378] When an AMF is changed and the old AMF indicates that the UE is in CM-CONNECTED state via an N3IWF, W-AGF, or TNGF, and the new AMF and the old AMF are in the same PLMN, the new AMF creates an NGAP UE association to the N3IWF / TNGF / W-AGF to which the UE is connected, which automatically releases the existing NGAP UE association between the old AMF and the N3IWF / TNGF / W-AGF.
[0379] 19. The N3IWF / TNGF / W-AGF sends a UE Context Modification Response to the new AMF.
[0380] 19a. [Conditional] After the new AMF receives a response message from the N3IWF, W-AGF, or TNGF in step 19, the new AMF registers with the UDM using Nudm_UECM_Registration with the access type set to "non-3GPP access" as in step 14a. The UDM stores the associated access type with the serving AMF and does not delete any AMF identities associated with other access types. The UDM may store the information provided by Nudr_DM_Update during AMF registration in the UDR.
[0381] 19b. [Conditional] Once the UDM saves the associated access type (i.e., non-3GPP) with the serving AMF as indicated in step 19a, the UDM shall initiate a Nudm_UECM_DeregistrationNotification (see section 5.2.3.2.2) to the old AMF corresponding to the same (i.e., non-3GPP) access. The old AMF shall delete the UE context for the non-3GPP access.
[0382] 19c. Old AMF uses Nudm_SDM_unsubscribe to unsubscribe from UDM for subscription data.
[0383] 20a. Void
[0384] 21. New AMF to UE: Registration Accept (5G-GUTI, Registration Area, Mobility restrictions, PDU Session status, Allowed NSSAI, Mapping of Allowed NSSAI, Configured NSSAI for the Serving PLMN, Mapping of Configured NSSAI, NSSRG Information, Rejected S-NSSAIs, Pending NSSAI, Mapping of Pending NSSAI, Periodic Registration Update timer, Active Time, Strictly Periodic Registration Timer Indication, LADN Information, Accepted MICO Mode MICO mode], [IMS Voice over PS session supported Indication], [Emergency Service Support indicator], [Accepted DRX parameters for E-UTRA and NR], [Accepted DRX parameters for NB-IoT], [Extended idle mode DRX parameters], [Paging Time Window]Window), Network support of Interworking without N26, Access Stratum Connection Establishment NSSAI Inclusion Mode, Network Slicing Subscription Change Indication, Operator-defined access category definitions, List of equivalent PLMNs, Enhanced Coverage Restricted information, Supported Network Behavior, Service Gap Time, PLMN-assigned UE radio capability ID, PLMN-assigned UE radio capability ID deletion, WUS Assistance Information, Truncated 5G-S-TMSI Configuration, Connection Release Support Supported, Paging Cause Indication for Voice Service Supported, Paging Restriction Supported, and Reject Paging Request Supported.
[0385] If the requested NSSAI does not contain an S-NSSAI that maps to an S-NSSAI of the HPLMN that is subject to Network Slice-Specific Authentication and Authorization, and the AMF determines that the S-NSSAI cannot be provided in the allowed NSSAIs for the UE within the current UE tracking area, and no default S-NSSAIs that have not yet been involved in the current UE registration procedure are further considered, the AMF shall reject the UE registration and include in the rejection message a list of rejected S-NSSAIs, each with an appropriate rejection cause value.
[0386] The allowed NSSAIs for the access type for the UE are included in the N2 message carrying the registration accept message. The allowed NSSAIs include only S-NSSAIs that do not require network slice-specific authentication and authorization based on subscription information, regardless of access type, and S-NSSAIs for which network slice-specific authentication and authorization based on the UE context in the AMF have previously been successful. The pending NSSAI mapping maps each S-NSSAI of the serving PLMN's pending NSSAIs to an HPLMN S-NSSAI.
[0387] If the UE indicates support for network slice-specific authentication and authorization procedures in the UE MM Core Network Function in the registration request, the AMF includes in the pending NSSAI the S-NSSAIs that map to the S-NSSAIs of the HPLMNs whose subscription information indicates that they are subject to network slice-specific authentication and authorization, as described in Section 4.6.2.4 of TS 24.501
[25] . In such a case, the AMF triggers the network slice-specific authentication and authorization procedures specified in Section 4.2.9.2 in step 25, except for S-NSSAIs for which network slice-specific authentication and authorization has already been initiated for another access type of the same S-NSSAI based on the network policy. The UE does not attempt to re-register to an S-NSSAI included in the list of pending NSSAIs until the network slice-specific authentication and authorization procedures are completed, regardless of the access type.
[0388] If the UE does not indicate support for network slice-specific authentication and authorization procedures in the UE 5GMM Core Network Functions in the registration request and the requested NSSAI includes S-NSSAIs that map to HPLMN S-NSSAIs that are subject to network slice-specific authentication and authorization, the AMF shall include those S-NSSAIs in the requested NSSAI in the rejected S-NSSAI.
[0389] The following are reasons why an S-NSSAI cannot be provided to an Allowed NSSAI:
[0390] All S-NSSAIs within the requested NSSAI are subject to network slice-specific authentication and authorization, or
[0391] -The requested NSSAI is not provided or none of the S-NSSAIs in the requested NSSAI matches the Subscribed S-NSSAI, and all S-NSSAIs marked as default in the Subscribed S-NSSAI are subject to network slice-specific authentication and authorization.
[0392] The AMF shall provide an empty Authorized NSSAI. Upon receiving an empty Authorized NSSAI and a pending NSSAI, the UE remains registered with the PLMN but shall not attempt to use any services offered by the PLMN in any access, except for emergency services (see TS 24.501
[25] ), until the UE receives an Authorized NSSAI and awaits completion of network slice specific authentication and authorization procedures.
[0393] The AMF stores the NB-IoT Priority obtained in step 14 and associates it with the 5G-S-TMSI assigned to the UE.
[0394] If the registration request message received via 3GPP access does not contain paging restriction information, the AMF shall delete the paging restriction information stored for this UE and stop paging restriction accordingly.
[0395] If the Registration Request message received via 3GPP access contains a Release Request indication:
[0396] The AMF updates the UE context with the received paging restriction information and enforces it in the network triggered Service Request procedure as described in section 4.2.3.3.
[0397] The AMF does not establish user plane resources and triggers the AN release procedure as described in section 4.2.6 after the registration procedure is completed.
[0398] The AMF sends a registration accept message to the UE indicating that the registration request has been accepted. If the AMF assigns a new 5G-GUTI, the 5G-GUTI is included. When the AMF receives a registration request message of type "Initial Registration," "Mobility Registration Update," or "Disaster Roaming Registration" from the UE, the AMF includes the new 5G-GUTI in the registration accept message. When the AMF receives a registration request message of type "Periodic Registration Update" from the UE, the AMF includes the new 5G-GUTI in the registration accept message. If the UE is already in RM-REGISTERED state via another access within the same PLMN, the UE uses the 5G-GUTI received in the registration accept for both registrations. If the registration accept does not include a 5G-GUTI, the UE uses the 5G-GUTI assigned to the existing registration for the new registration as well. If the AMF assigns a new registration area, the AMF sends the registration area to the UE via the registration accept message. In case of disaster roaming registration, the AMF allocates a registration area limited to the area where the disaster situation exists as specified in clause 5.40 of TS 23.501 [2]. If the registration accept message does not include a registration area, the UE considers the old registration area valid. If mobility restrictions apply to the UE and the registration type is not emergency registration, the mobility restrictions are included. The AMF notifies the UE of the established PDU session in the PDU session status. The UE locally deletes internal resources related to PDU sessions that are not marked as established in the received PDU session status. If the AMF invokes the Nsmf_PDUSession_UpdateSMContext procedure for UP activation of the PDU session in step 18 and receives a rejection from the SMF, the AMF notifies the UE of the PDU session ID and the reason why the user plane resources were not activated.If the UE is connected to two AMFs belonging to different PLMNs via 3GPP and non-3GPP accesses, the UE locally deletes internal resources related to PDU sessions in the current PLMN that are not marked as established in the received PDU session status. If PDU session status information was included in the registration request, the AMF indicates the PDU session status to the UE.
[0399] If the RAT type is NB-IoT and the network is configured to use the Control plane Relocation Indication procedure, the AMF includes in the Registration Accept message a truncated 5G-S-TMSI configuration that a UE using control plane CIoT 5GS optimization will use to create a truncated 5G-S-TMSI, see clause 5.31.4.3 of TS 23.501 [2].
[0400] The allowed NSSAIs provided in the registration consent are valid in the registration area and apply to all PLMNs with tracking areas included in the registration area. The mapping of allowed NSSAIs is the mapping of each S-NSSAI of the allowed NSSAIs to the HPLMN S-NSSAI. The mapping of configured NSSAIs is the mapping of each S-NSSAI of the configured NSSAIs of the serving PLMN to the HPLMN S-NSSAI.
[0401] If the UE indicates support for the subscription-based restriction feature for simultaneous network slice registrations, the AMF shall include the NSSRG information defined in clause 5.15.12 of TS 23.501 [2], if available.
[0402] If the UE does not indicate support for the subscription-based restriction feature for concurrent network slice registrations, the UE's subscription information includes SRG information, and the AMF provides the UE with a configured NSSAI, the configured NSSAI includes the S-NSSAI according to clause 5.15.12 of TS 23.501 [2].
[0403] The AMF includes in the registration accept message the LADN information of the list of LADNs available in the registration area determined by the AMF for the UE as described in clause 5.6.5 of TS 23.501 [2]. The AMF may also include operator-defined access category definitions as described in TS 24.501
[25] to allow the UE to determine the applicable operator-specific access category definitions.
[0404] If the UE includes the MICO mode in the registration request, the AMF responds in the registration accept message whether to use the MICO mode. If the MICO mode is allowed for the UE, the AMF can include an Active Time value and / or a Strictly Periodic Registration Timer Indication in the registration accept message. As described in clause 5.31.7 of TS 23.501 [2], to enable UE power saving, the AMF determines the Periodic Registration Update timer value, the Active Time value, and the Strictly Periodic Registration Timer Indication based on local configuration, if available, the Expected UE Behavior, UE indicated preferences, UE capabilities, UE subscription information, and network policies, or a combination thereof. If the UE indicated the Strictly Periodic Registration Timer Indication capability in the Registration Request message as described in step 1, the AMF decides to apply the Strictly Periodic Registration Timer Indication to the UE. If the AMF provides the UE with a periodic registration update timer value together with the Strictly Periodic Registration Timer Indication, the UE and the AMF start the periodic registration update timer after this step as described in clause 5.31.7.5 of TS 23.501 [2].
[0405] In case of registration via 3GPP access, the AMF sets the IMS Voice over PS session supported indication as described in clause 5.16.3.2 of TS 23.501 [2]. To set the IMS Voice over PS Session supported indication, the AMF may need to perform the UE Capability Match Request procedure in clause 4.2.8a to check the compatibility of the UE and NG-RAN radio capabilities related to IMS Voice over PS. If the AMF does not receive the Voice Support Match Indicator from the NG-RAN on time, based on the implementation, the AMF may set the IMS Voice over PS Session supported indication and update it at a later stage.
[0406] In the case of registration in 3GPP access, if the AMF obtains or determines, according to local configuration, a target NSSAI and a corresponding RFSP index to enable the NG-RAN to redirect the UE to a cell supporting network slicing that is not available in the current TA, as described in clause 5.3.4.3.3 of TS23.501 [2], the AMF provides the target NSSAI and the corresponding RFSP index to the NG-RAN.
[0407] In case of registration via non-3GPP access, the AMF sets the IMS Voice over PS Session Support indication as described in clause 5.16.3.2a of TS 23.501 [2].
[0408] The Emergency Service Support Indication informs the UE that emergency services are supported, i.e., the UE can request an emergency service PDU session. If the AMF receives "MPS Priority" from the UDM as part of the access and mobility subscription data, based on operator policy, the "MPS Priority" is included in the registration accept message to the UE to inform the UE whether the configuration of Access Identity 1 is valid within the selected PLMN, as specified in TS 24.501
[25] . If the AMF receives "MCX Priority" from the UDM as part of the access and mobility subscription data, based on operator policy and the UE subscription to the MCX service, the "MCX Priority" is included in the registration accept message to the UE to inform the UE whether the configuration of Access Identity 2 is valid within the selected PLMN, as specified in TS 24.501
[25] . The accepted DRX parameters are defined in clause 5.4.5 of TS 23.501 [2]. The AMF includes the accepted DRX parameters for NB-IoT if the UE included the requested DRX parameters for NB-IoT in the registration request message. The AMF configures network support for interworking without the N26 parameter as described in clause 5.17.2.3.1 of TS 23.501 [2]. If the AMF accepts the use of extended idle mode DRX, the AMF includes the extended idle mode DRX parameters and the Paging Time Window as described in clause 5.31.7.2 of TS 23.501 [2].
[0409] If the UDM is intended to indicate to the UE that the subscription has changed, it includes a Network Slicing Subscription Change Indication. If the AMF includes a Network Slicing Subscription Change Indication, the UE shall locally clear all network slicing configurations for all PLMNs and, if applicable, update the current PLMN configuration based on the received information.
[0410] As specified in clause 5.15.9 of TS 23.501 [2], the Access Stratum Connection Establishment NSSAI inclusion mode is included to indicate to the UE which NSSAI, if any, to include in the Access Stratum Connection Establishment. The AMF can set values for operation modes a, b, and c defined in clause 5.15.9 of TS 23.501 [2] for 3GPP access only if this is indicated as allowed by including an NSSAI in the RRC Connection Establishment Authorization.
[0411] For a UE registered in a PLMN, the AMF may provide a list of equivalent PLMNs, which are processed as specified in TS 24.501
[25] . For a UE registered in an SNPN, the AMF does not provide the UE with a list of equivalent PLMNs.
[0412] If the UE included support for restricted use of enhanced coverage in step 1, the AMF sends the Enhanced Coverage Restricted information to the NG-RAN in the N2 message. The AMF also sends the Enhanced Coverage Restricted information to the UE in the Registration Accept message.
[0413] If the UE receives Enhanced Coverage Restricted information in the registration accept message, the UE stores this information and uses the value of the Enhanced Coverage Restricted information to determine whether to use the enhanced coverage function.
[0414] If the UE and the AMF negotiate to enable MICO mode and the AMF uses the Extended Connected Timer, the AMF provides the Extended Connected Time value to the NG-RAN in this step (see clause 5.31.7.3 of TS 23.501 [2]). The Extended Connected Time value indicates the minimum time the RAN must keep the UE in RRC-CONNECTED state, regardless of inactivity.
[0415] If the UE includes a preferred network behavior in its registration request, the AMF indicates the supported and accepted CIoT 5GS optimizations in the Supported Network Behavior information (see clause 5.31.2 of TS 23.501 [2]).
[0416] The AMF can steer the UE out of 5GC by rejecting the registration request. Before steering the UE out of 5GC, the AMF takes into account the Preferred and Supported Network Behavior (see clause 5.31.2 of TS 23.501 [2]) and the availability of EPC to the UE.
[0417] If the AMF accepts the MICO mode and is aware that there may be mobile terminated data or pending signaling, the AMF shall maintain the N2 connection for at least the extended connection time and provide the extended connection time value to the RAN as described in clause 5.31.7.3 of TS 23.501 [2].
[0418] If a service gap time is present in the subscription information (steps 14a-c) or the service gap time has been updated by the Subscriber Data Update Notification to AMF procedure (see section 4.5.1) and the UE has indicated UE Service Gap Control Capability, the AMF includes the service gap time.
[0419] If the UE receives a service gap time in the registration accept message, the UE stores this parameter and applies the service gap control (see clause 5.31.16 of TS 23.501 [2]).
[0420] If the network supports WUS grouping (see TS23.501[2]), the AMF sends WUS Assistance Information to the UE. If the UE provides UE paging probability information in step 1, the AMF takes it into account when determining the WUS Assistance Information.
[0421] If the UE and AMF support RACS as defined in clause 5.4.4.1a of TS 23.501 [2], the AMF shall configure the UE with the UE radio capability ID, and if the AMF already has a UE radio capability other than the NB-IoT radio capability for the UE, the AMF may provide the UE with the UE radio capability ID of the UE radio capability, which the UCMF returns to the AMF in the Nucmf_assign service operation for this UE. Alternatively, if the UE and AMF support RACS, the AMF may provide the UE with an indication to delete any PLMN-assigned UE Radio Capability ID in this PLMN (see clause 5.4.4.1a of TS 23.501 [2]).
[0422] If the UE is "CAG supported" and the AMF needs to update the UE's CAG information, the AMF may include the CAG information as part of the mobility restriction in the registration accept message.
[0423] If the UE indicates support for the Paging Cause Indication for Voice Service feature in the Registration Request message and the network supports and plans to apply the Paging Cause Indication for Voice Service feature for the UE, the AMF includes an indication that the UE supports the Paging Cause Indication for Voice Service feature in the N2 message carrying the Registration Accept message.
[0424] If the multi-USIM UE indicated support for one or more multi-USIM specific features in the UE 5GMM Core Network Capabilities in step 1, the AMF shall indicate to the multi-USIM UE whether one or more corresponding multi-USIM specific features listed in clause 5.38 of TS 23.501 [2] are supported, based on the network capabilities and configuration by the network (i.e., based on local network policy), by providing one or more of the following indications: Connection Release Supported, Paging Cause Indication for Voice Service Supported, Paging Restriction Supported, Reject Paging Request Supported. If the multi-USIM UE indicates support for the paging cause indication for voice service feature, the AMF supporting paging cause indication for voice service shall include an indication that the UE supports the paging cause indication for voice service feature in the N2 message. The AMF indicates only Paging Restriction Supported and either Connection Release Supported or Reject Paging Request Supported. The UE uses only the multi-USIM specific features that the AMF indicates are supported.
[0425] 21b. [Optional] The new AMF performs a UE Policy Association Establishment as defined in clause 4.16.11. In case of an emergency registration, this step is skipped.
[0426] The new AMF sends an Npcf_UEPolicyControl Create Request to the PCF. The PCF sends an Npcf_UEPolicyControl Create Response to the new AMF.
[0427] The PCF triggers the UE Configuration Update Procedure as defined in section 4.2.4.3.
[0428] 22. [Conditional] UE to new AMF: Registration Complete ().
[0429] In step 21, after receiving the [Configured NSSAI of Serving PLMN], [Configured NSSAI Mapping], [NSSRG Information], and either the Network Slicing Subscription Change Indication or CAG information, if the update is successful, the UE sends a registration complete message to the AMF.
[0430] The UE sends a registration complete message to the AMF to check whether a new 5G-GUTI has been assigned.
[0431] If a new 5G-GUTI is assigned, the UE passes the new 5G-GUTI to the lower layers of the 3GPP access when the lower layers (3GPP access or non-3GPP access) indicate to the RM layer of the UE that the registration complete message has been successfully transferred over the air interface.
[0432] NOTE 14: The above is necessary because the NG-RAN may use the RRC Inactive state and part of the 5G-GUTI is used to calculate the Paging Frame (see TS38.304
[44] and TS36.304
[43] ). It is assumed that the Registration Complete is delivered reliably to the AMF after the 5G-AN has confirmed its reception to the UE.
[0433] If the list of PDU sessions to be activated is not included in the registration request and the registration procedure was not started in the CM-CONNECTED state, the AMF shall release the signaling connection with the UE according to clause 4.2.6.
[0434] If a follow-on request is included in the registration request, the AMF does not release the signaling connection after the registration procedure is completed.
[0435] If the AMF is aware that some signaling is pending within the AMF or between the UE and the 5GC, the AMF will not release the signaling connection immediately after the registration procedure is completed.
[0436] If a PLMN-assigned UE radio capability ID is included in step 21, the AMF stores the PLMN-assigned UE radio capability ID in the UE context upon receiving the registration complete message.
[0437] If the UE receives a PLMN-assigned UE Radio Capability ID deletion indication in step 21, the UE deletes the PLMN-assigned UE Radio Capability ID for this PLMN.
[0438] 23. [Conditional] If the access and mobility subscription data provided by the UDM to the AMF in AMF to UDM:14b includes roaming steering information with an indication that the UDM requests the UE to acknowledge receipt of this information, the AMF provides the UE response to the UDM using Nudm_SDM_Info. For more information on handling of roaming steering information, see TS23.122
[22] .
[0439] 23a. In the case of registration via 3GPP access, if the AMF does not release the signaling connection, the AMF sends RRC Inactive Assistance Information to the NG-RAN.
[0440] In the case of registration via non-3GPP access, if the UE is also in CM-CONNECTED state in 3GPP access, the AMF sends RRC inactive assistance information to the NG-RAN.
[0441] The AMF also uses the Nudm_SDM_Info service operation to provide an acknowledgement to the UDM that the UE has received and acted upon the CAG information or Network Slicing Subscription Change Indication (see steps 21 and 22).
[0442] 24. [Conditional] AMF to UDM: After step 14a, in parallel with any of the previous steps, the AMF sends the "Homogeneous Support of IMS Voice over PS Sessions" indication to the UDM using Nudm_UECM_Update.
[0443] - If AMF is evaluating support for IMS Voice over PS Sessions, see clause 5.16.3.2 of TS 23.501 [2].
[0444] - If the AMF determines that it is necessary to update the Homogeneous Support of IMS Voice over PS Sessions, please refer to clause 5.16.3.3 of TS 23.501 [2].
[0445] 25. [Conditional] If the UE indicates support for network slice-specific authentication and authorization procedures in the UE MM Core Network Function in the Registration Request, and the S-NSSAI of the HPLMN is subject to network slice-specific authentication and authorization, the relevant procedures are performed in this step (see Section 4.2.9.1). Once the network slice-specific authentication and authorization procedures are completed for all S-NSSAIs, the AMF triggers a UE Configuration Update procedure to deliver the allowed NSSAIs, including the S-NSSAIs for which network slice-specific authentication and authorization were successful, and includes the rejected NSSAIs with an appropriate rejection cause value.
[0446] Due to pending network slice-specific authentication and authorization, the AMF removes the mobility restriction if the tracking area of the registration area was previously assigned as a non-authorized area.
[0447] The AMF stores in the UE context an indication of successful network slice-specific authentication and authorization for any S-NSSAI of the HPLMN that is subject to network slice-specific authentication and authorization.
[0448] Once the network slice specific authentication and authorization procedures are completed, if the AMF is unable to provide an S-NSSAI for the allowed NSSAIs of a UE that is already authenticated and authorized by the PLMN and is unable to further consider a default S-NSSAI, the AMF shall perform the Network-initiated Deregistration procedure described in clause 4.2.2.3.3 and include in the explicit deregistration request message a list of rejected S-NSSAIs, each with an appropriate rejection cause value.
[0449] Mobility related event notifications to NF consumers are triggered at the end of this procedure for the cases described in subclause 4.15.4.
[0450] <4.2.2.2.2 Registration Overview> Figure 4.2.2.2.2-1: Registration procedure (see Figure 15)
[0451] 1. UE to (R)AN: AN message (AN parameters), Registration Request (Registration type, SUCI or 5G-GUTI or PEI, [last visited TAI (if available)], Security parameters, [Requested NSSAI], [Mapping Of Requested NSSAI], [Default Configured NSSAI Indication], [UE Radio Capability Update], [UE MM Core Network Capability], [PDU Session status], [List Of PDU Sessions To Be Activated], [Follow-on request], [MICO mode preference], [Requested Active Time], [Requested DRX parameters for E-UTRA and NR] NR), [Requested DRX parameters for NB-IoT], [Extended idle mode DRX parameters], [LADN DNN(s) or Indicator Of Requesting LADN information], [NAS message container], [Support for restriction of use of Enhanced Coverage], [Preferred Network Operation]Behavior), UE paging probability information, UE Policy Container (list of PSIs, indication of UE support for ANDSP and the operating system identifier), UE radio capability ID, Release Request indication, Paging Restriction Information, PEI, NSSRG handling support indication, PLMN with Disaster Condition, NAS connection identifier).
[0452] NOTE 1: The UE Policy Container and its usage are defined in TS 23.503
[20] .
[0453] For NG-RAN, the AN parameters include, for example, 5G-S-TMSI or GUAMI, Selected PLMN ID (or PLMN ID and NID, see clause 5.30 of TS 23.501 [2]), and NSSAI information, and also include an Establishment cause. The Establishment cause provides the reason for requesting establishment of an RRC connection. Whether and how the UE includes NSSAI information as part of the AN parameters depends on the value of the Access Stratum Connection Establishment NSSAI Inclusion Mode parameter, as specified in clause 5.15.9 of TS 23.501 [2].
[0454] If the UE is an IAB node accessing 5GS, the AN parameters also include an IAB indication.
[0455] The registration type indicates whether the UE wants to perform an initial registration (i.e., the UE is in the RM-DEREGISTERED state), a mobility registration update (i.e., the UE is in the RM-REGISTERED state and initiates the registration procedure for mobility, or because the UE needs to update its capabilities or protocol parameters, or to request a change in the set of network slices it is authorized to use), a periodic registration update (i.e., the UE is in the RM-REGISTERED state and initiates the registration procedure due to expiration of the periodic registration update timer; see Section 4.2.2.2.1), an emergency registration (i.e., the UE is in a limited service state), or a disaster roaming registration.
[0456] If the UE uses E-UTRA, the UE indicates support for CIoT 5GS optimization related to AMF selection in the RRC connection establishment signaling associated with the registration request.
[0457] If the UE is performing initial registration or disaster roaming registration, the UE shall indicate the UE identity in the registration request message as follows, which are listed in order of decreasing priority for registration to a PLMN: i) If the UE has a valid EPS GUTI, the 5G-GUTI mapped from the EPS GUTI. ii) If available, the native 5G-GUTI assigned by the PLMN to which the UE is attempting to register; iii) If available, the native 5G-GUTI assigned by the equivalent PLMN to the PLMN the UE is attempting to register; iv) Native 5G-GUTI allocated by other PLMNs, if available. NOTE 2: This may also be a 5G-GUTI allocated via another access type. v) Otherwise, the UE shall include the SUCI in the registration request as defined in TS 33.501
[15] .
[0458] If the UE is registering with an SNPN, when the UE is performing initial registration, the UE indicates the UE identity in the registration request message as follows, listed in descending order of priority: i) If available, a native 5G-GUTI assigned by the same SNPN to which the UE is trying to register; ii) If available, the native 5G-GUTI assigned by any other SNPN together with the NID of the SNPN that assigned the 5G-GUTI; iii) Otherwise, the UE includes the SUCI in the registration request as defined in TS 33.501
[15] .
[0459] If the UE performing initial registration has both a valid EPS GUTI and a native 5G-GUTI, the UE shall also indicate the native 5G-GUTI as an additional GUTI. If multiple native 5G-GUTIs are available, the UE shall select a 5G-GUTI from items (ii) to (iv) in the above list in descending order of priority.
[0460] If the UE is sending a Registration Request message as an initial NAS message, the UE has a valid 5G NAS security context, and the UE needs to send non-cleartext IEs, the NAS message container is included. See clause 4.4.6 of TS 24.501
[25] . If the UE does not need to send non-cleartext IEs, the UE sends the Registration Request message without a NAS message container.
[0461] If the UE does not have a valid 5G NAS security context, the UE sends the Registration Request message without a NAS message container. The UE includes the entire Registration Request message (i.e., including the cleartext and non-cleartext IEs) in the NAS message container sent as part of the Security Mode Complete message in step 9b.
[0462] When the UE performs initial registration with native 5G-GUTI (i.e., when the UE is in RM-DEREGISTERED state), the UE indicates the related GUAMI information in the AN parameter. If the UE performs initial registration using SUCI, the UE does not indicate the GUAMI information in the AN parameter.
[0463] If the UE is performing initial registration or mobility registration and CIoT 5GS optimization is supported, the UE shall indicate its Preferred Network Behavior (see clause 5.31.2 of TS 23.501 [2]). If S1 mode is supported, the UE's EPC Preferred Network Behavior shall be included in the S1 UE network capabilities of the Registration Request message (see clause 8.2.6.1 of TS 24.501
[25] ).
[0464] In case of emergency registration, if the UE does not have a valid 5G-GUTI available, the SUCI is included. If the UE has neither a SUPI nor a valid 5G-GUTI, the PEI is included. In other cases, the 5G-GUTI is included, indicating the last serving AMF.
[0465] The UE may provide its usage settings based on its configuration as defined in clause 5.16.3.7 of TS23.501[2]. The UE shall provide the requested NSSAIs (as described in clause 5.15.5.2.1 of TS 23.501 [2], taking into account the NSSRG information constraints if the UE supports subscription-based restrictions to simultaneous registration of network slices as described in clause 5.15.12 of TS 23.501 [2]). In the case of an Initial Registration or Mobility registration update, the UE shall include the mapping of the requested NSSAIs (if available), which is the mapping of each S-NSSAI of the requested NSSAI to the HPLMN S-NSSAI, so that the network can be sure that the S-NSSAI in the requested NSSAI is allowed based on the Subscribed S-NSSAI. In the case of inter-PLMN mobility, the UE shall include the mapping of the requested NSSAIs to the HPLMN S-NSSAI, if available, so that the network can be sure that the S-NSSAI in the requested NSSAI is allowed based on the Subscribed S-NSSAI. In the case of inter-PLMN mobility, the UE shall include the mapping of the serving PLMN corresponding to the established PDU session as described in clause 5.15.5.2.1 of TS 23.501 [2]. If the S-NSSAI does not exist in the UE, the relevant HPLMN S-NSSAI associated with the established PDU session is provided in the mapping of the requested NSSAI.
[0466] If the UE is using a Default Configured NSSAI as defined in TS 23.501 [2], the UE shall include a Default Configured NSSAI indication.
[0467] If the UE supports allocation of WUS Assistance Information from the AMF, it may include UE paging probability information (see TS 23.501 [2]).
[0468] In the case of a mobility registration update, the UE includes in the list of PDU sessions to be activated those PDU sessions for which there is pending uplink data. When the UE includes in the list of PDU sessions to be activated, it indicates only those PDU sessions associated with the access to which the registration request relates. As defined in TS 24.501
[25] , the UE includes in the list of PDU sessions to be activated those always-on PDU sessions that are accepted by the network, even if those PDU sessions have no pending uplink data.
[0469] NOTE 3: The PDU session corresponding to the LADN is not included in the list of PDU sessions to be activated if the UE is outside the available area of the LADN.
[0470] The UE MM Core Network Function is provided by the UE and processed by the AMF as defined in clause 5.4.4a of TS 23.501 [2]. The UE includes in the UE MM Core Network Function an indication of whether it supports the request type flag "Handover" in the PDN connection request during the attach procedure as defined in clause 5.17.2.3.1 of TS 23.501 [2]. If the UE supports "Strictly Periodic Registration Timer Indication", the UE indicates the capability of "Strictly Periodic Registration Timer Indication" in the UE MM Core Network Capabilities. If the UE supports CAG, the UE indicates the capability of "CAG supported" in the UE MM Core Network Capabilities. If the UE operates more than one USIM and supports and intends to use one or more multi-USIM features, the UE shall indicate one or more multi-USIM specific features listed in clause 5.38 of TS 23.501 [2] in the UE MM Core Network Functions.
[0471] The UE can provide either the LADN DNN or an Indication of Requesting LADN information as described in clause 5.6.5 of TS 23.501 [2].
[0472] If available, the last visited TAI is included to allow the AMF to generate the registration area for the UE.
[0473] The security parameters are used for authentication and integrity protection. See TS 33.501
[15] . The requested NSSAI indicates the Network Slice Selection Assistance Information (defined in clause 5.15 of TS 23.501 [2]). The PDU session status indicates the PDU session previously established in the UE. If the UE is connected to two AMFs belonging to different PLMNs via 3GPP and non-3GPP accesses, the PDU session status indicates the PDU session established in the current PLMN in the UE.
[0474] The Follow-on request is included if the UE has pending uplink signaling and the UE does not include a list of PDU sessions to be activated, or if the registration type indicates that the UE wants to perform an emergency registration. In the initial registration and mobility registration update, the UE provides UE Requested DRX parameters as defined in clause 5.4.5 of TS 23.501 [2]. The UE can request extended idle mode DRX by providing extended idle mode DRX parameters as defined in clause 5.31.7.2 of TS 23.501 [2].
[0475] The UE provides the UE Radio Capability Update indication as described in TS 23.501 [2].
[0476] The UE includes a preference for MICO mode and, optionally, a requested active time value if the UE wants to use MICO mode during active time.
[0477] The UE can indicate Service Gap Control Capability at the UE MM Core Network Function, see clause 5.31.16 of TS 23.501 [2].
[0478] For a UE with a Service Gap Timer running in it, the UE shall not set the Follow-on Request indication or the uplink data status in the Registration Request message, except for network access for barred priority services such as emergency services or exception reporting (see clause 5.31.16 of TS 23.501 [2]).
[0479] If the UE supports RACS and has been assigned a UE Radio Capability ID, the UE shall indicate the UE Radio Capability ID as defined in clause 5.4.4.1a of TS 23.501 [2] as a non-plaintext IE.
[0480] The PEI can be obtained from the UE during initial registration as described in section 4.2.2.2.1.
[0481] If the UE supports the subscription-based restrictions to simultaneous registration of network slices feature, the UE includes an NSSRG handling support indication according to clause 5.15.12 of TS 23.501 [2]. The AMF stores in the UE context whether the UE supports this feature.
[0482] For example, if a UE in MUSIM mode wants to enter CM-IDLE state immediately after performing mobility or periodic registration, the UE may include a release request indication and optionally provide paging restriction information.
[0483] If the UE is performing a disaster roaming registration, the UE may indicate the disaster situation to the PLMN if the UE does not have a valid 5G-GUTI indicating the PLMN in disaster state, and the PLMN with the Disaster Condition is not the UE's HPLMN, or the PLMN with the Disaster Condition is the UE's HPLMN but the UE does not provide its SUCI.
[0484] If a 5G NAS security context corresponding to 3GPP access is used to protect the integrity of the registration request message, the UE includes a NAS connection identifier with the value set to 3GPP access. This information element may be sent as a cleartext IE.
[0485] 2. If the 5G-S-TMSI or GUAMI is not included, or if the 5G-S-TMSI or GUAMI does not indicate a valid AMF, the (R)AN shall select an AMF based on the (R)AT and the requested NSSAI, if available.
[0486] The (R)AN selects the AMF as described in clause 6.3.5 of TS 23.501 [2]. If the UE is in CM-CONNECTED state, the (R)AN can forward the registration request message to the AMF based on the UE's N2 connection.
[0487] If the (R)AN cannot select a suitable AMF, it forwards the registration request to an AMF that is configured to perform AMF selection in the (R)AN.
[0488] 3. New AMF:N2 message from the (R)AN (with N2 parameters, Registration Request (described in step 1) and [LTE-M Indication]).
[0489] If NG-RAN is used, the N2 parameters include a UE context request indicating that a UE context should be established in the NG-RAN, including the selected PLMN ID (or PLMN ID and NID, see clause 5.30 of TS 23.501 [2]), location information, cell identity related to the cell the UE is camped on, and security information.
[0490] If NG-RAN is used, the N2 parameter also contains the establishment cause and, if an indication was received in the AN parameter in step 1, the IAB indication.
[0491] Mapping of the requested NSSAI will be provided only if available.
[0492] If the registration type indicated by the UE is periodic registration update, steps 4 to 19 may be omitted.
[0493] If the establishment cause is associated with a priority service (MPS, MCS, etc.), the AMF includes a Message Priority header indicating the priority information. Other NFs relay the priority information by including a Message Priority header in their service-based interfaces as specified in TS 29.500
[17] .
[0494] The RAT type used by the UE is determined (see section 4.2.2.2.1) and based on that the AMF decides whether the UE is performing inter-RAT mobility to or from NB-IoT. When the AMF receives an LTE-M indication, it considers the RAT type to be LTE-M and stores the LTE-M indication in the UE context.
[0495] If the UE includes a preferred network behavior, this defines the network behavior that the UE supports and is expected to be available in the network, as defined in clause 5.31.2 of TS 23.501 [2].
[0496] If the UE includes a preferred network operation and what the UE indicates it supports in its preferred network operation is not compatible with the network support, the AMF rejects the registration request with an appropriate cause value (e.g., a value that avoids retries in this PLMN).
[0497] If a Service Gap Timer is running in the UE context of the AMF for the UE and a Follow-on Request indication or an uplink data status is included in the registration request message, the AMF shall ignore the Follow-on Request indication and the uplink data status and shall not perform any action related to the status.
[0498] If the UE included the UE radio capability ID in step 1 and the AMF supports RACS, the AMF stores the radio capability ID in the UE context.
[0499] For NR satellite access, if the AMF can determine, based on the selected PLMN ID and ULI (including cell ID) received from the gNB, that the UE is attempting to register with a PLMN that is not authorized to operate at the UE's current location, the AMF shall reject the registration request indicating an appropriate cause value and, if known to the AMF, the country of the UE's location. Otherwise, if, for example, the AMF does not know the UE's location with sufficient accuracy to make a final decision, the AMF may proceed with the registration procedure and initiate a UE location procedure as specified in clause 6.10.1 of TS 23.273
[51] , preparing to deregister the UE if the information received from the LMF proves that the UE is registered with a PLMN that is not authorized to operate at the UE's location.
[0500] NOTE 4: It cannot be guaranteed that the location information is accurate enough for the AMF to identify the country in which the UE is located in all cases.
[0501] NOTE 5: Because multiple MCCs are used in some countries and some MCCs, such as 901, are allowed in multiple countries, the UE may register with a PLMN using a different MCC than the MCC returned to the UE.
[0502] Upon receiving a registration rejection from the country in which the UE is located, the UE shall attempt to register with a PLMN that is permitted to operate in the UE's location, as specified in TS 23.122
[22] .
[0503] For disaster roaming registration, the AMF determines whether disaster roaming service can be provided based on the ULI (including cell ID) received from the NG-RAN, the PLMN with a disaster situation derived from the UE's 5G-GUTI, derived from the UE's SUCI, or indicated by the UE, and local configuration. If the current location is not eligible for disaster roaming service or if disaster roaming service is not provided for the PLMN with a disaster situation derived from the UE's 5G-GUTI, derived from the UE's SUCI, or indicated by the UE, the AMF rejects the registration request with an appropriate cause value.
[0504] 4. [Conditional] From new AMF to old AMF: Namf_Communication_UEContextTransfer (Full Registration Request, NAS Connection Identifier), or from new AMF to UDSF: Nudsf_Unstructured Data Management_Query().
[0505] The new AMF determines the old AMF using the UE's 5G-GUTI. If the new AMF receives the NID in the registration request, it determines that the 5G-GUTI was assigned by the SNPN and uses the 5G-GUTI and the SNPN's NID to determine the old AMF.
[0506] (With UDSF): If the UE's 5G-GUTI is included in the registration request and the serving AMF has changed since the last registration procedure, if the new AMF and the old AMF are in the same AMF set and UDSF is deployed, the new AMF can use the Nudsf_UnstructuredDataManagement_Query service operation to obtain the stored UE's SUPI and UE context directly from the UDSF. If UDSF is not deployed, the new AMF can share the stored UE context via implementation-specific means. This also includes event subscription information by each NF consumer for a specific UE. In this case, the new AMF performs and verifies integrity protection using an integrity-protected complete Registration Request NAS message.
[0507] (Without UDSF implementation): If the UE's 5G-GUTI is included in the registration request and the serving AMF has changed since the last registration procedure, the new AMF may invoke the Namf_Communication_UEContextTransfer service operation on the old AMF, including the access type, with an integrity-protected complete registration request NAS message, requesting the UE's SUPI and UE context. The old AMF may include the NAS connection identifier received in the complete registration request. For details about this service operation, see Section 5.2.2.2.2. In this case, if the context transfer service operation invocation corresponds to the requested UE, the old AMF verifies the integrity protection using the 5G-GUTI and the integrity-protected complete registration request NAS message, or the SUPI and an indication that the UE has been activated from the new AMF. The old AMF also forwards the event subscription information by each NF consumer for the UE to the new AMF. If the old AMF has not yet reported a non-zero MO Exception Data Counter to the (H-)SMF, the context response also includes the MO Exception Data Counter.
[0508] If the old AMF has a PDU session with a different access type (different from the access type indicated in this procedure) and the old AMF determines that there is no possibility to relocate the N2 interface to the new AMF, the old AMF returns the SUPI of the UE and indicates that the registration request is enabled for integrity protection, but does not include the remaining UE context.
[0509] In the case of inter-PLMN mobility, the UE context information does not include the allowed NSSAI of the old PLMN, but includes the HPLMN S-NSSAI corresponding to the allowed NSSAI for each access type.
[0510] NOTE 6: The new AMF sets an indication that the UE is enabled according to step 9a if the new AMF successfully authenticates the UE after a previous integrity check in the old AMF failed.
[0511] NOTE 7: The NF consumer does not need to resubscribe to events in the new AMF after the UE has successfully registered with the new AMF.
[0512] If the new AMF has already received the UE context from the old AMF during the handover procedure, steps 4, 5 and 10 are skipped.
[0513] In case of emergency registration, if the UE identifies itself with a 5G-GUTI that is not known to the AMF, steps 4 and 5 are skipped and the AMF immediately requests a SUPI from the UE. If the UE identifies itself with a PEI, the SUPI request is skipped. The permission of emergency registration without a user identifier depends on local regulations.
[0514] 5. [Conditional] From the old AMF to the new AMF: Response to Namf_Communication_UEContextTransfer (SUPI, UE context in AMF (according to Table 5.2.2.2.2-1)), or from UDSF to the new AMF: Nudsf_Unstructured Data Management_Query (). The old AMF may start an implementation-specific (guard) timer for the UE context.
[0515] If the UDSF is queried in step 4, it responds to the new AMF with a Nudsf_Unstructured Data Management_Query call with the associated context including the established PDU session, and the old AMF includes information about the NGAP UE-TNLA binding, including SMF information DNN, S-NSSAI, PDU session ID, and active NGAP UE-TNLA binding to N3IWF / TNGF / W-AGF. If the old AMF is queried in step 4, it responds to the new AMF with a Nudsf_Communication_UEContextTransfer call by including the UE's SUPI and UE context.
[0516] If the old AMF holds information about an established PDU session and it is not an initial registration, the old AMF includes SMF information, DNN, S-NSSAI, and PDU session ID.
[0517] If the old AMF holds a UE context established via N3IWF, W-AGF, or TNGF, the old AMF includes the CM state via N3IWF, W-AGF, or TNGF. If the UE is in CM-CONNECTED state via N3IWF, W-AGF, or TNGF, the old AMF includes information about the NGAP UE-TNLA binding.
[0518] The old AMF performs an integrity check of the complete registration request using the 5G NAS security context corresponding to the NAS connection identifier.
[0519] If the old AMF fails the integrity check of the registration request NAS message, the old AMF indicates an integrity check failure. If the new AMF is configured to allow emergency services for unauthenticated UEs, the new AMF operates as follows:
[0520] If the UE only has an emergency PDU session, the AMF skips the authentication and security procedures or accepts that authentication may fail and continues with the mobility registration update procedure, or
[0521] If the UE has both emergency and non-emergency PDU sessions and authentication fails, the AMF continues the mobility registration update procedure and deactivates all non-emergency PDU sessions as specified in section 4.3.4.2.
[0522] NOTE 8: The new AMF can determine whether a PDU session is used for emergency services by checking whether the DNN matches the emergency DNN.
[0523] If the old AMF holds information about the AM policy association and information about the UE policy association (i.e., the policy control request trigger for updating the UE policy defined in TS 23.503
[20] ), the old AMF includes information about the AM policy association, the UE policy association, and the PCF ID. In case of roaming, the V-PCF ID and the H-PCF ID are included.
[0524] If the old AMF was a consumer of the UE-related NWDAF service, the old AMF includes information about the active analysis subscription, i.e., subscription correlation ID, NWDAF identifier (i.e., instance ID or set ID), analysis ID, and associated analysis-specific data, in the Namf_Communication_UEContextTransfer response. The use of analysis information by the new AMF is specified in TS 23.288
[50] .
[0525] During inter-PLMN mobility, the handling of the UE radio capability ID in the new AMF is as defined in TS 23.501 [2].
[0526] NOTE 9: If the new AMF uses UDSF for context acquisition, the interaction between the old AMF, new AMF and UDSF due to UE signaling in the old AMF at the same time becomes an implementation issue.
[0527] 6. [Conditional] New AMF to UE: Identity Request ().
[0528] If the SUCI is not provided by the UE and not obtained from the old AMF, the Identity Request procedure is initiated by the AMF sending an Identity Request message to the UE requesting the SUCI.
[0529] 7. [Conditional] UE to new AMF: Identity Response ().
[0530] The UE responds with an Identity Response message containing the SUCI, which the UE derives using the HPLMN's provisioned public key as specified in TS33.501
[15] .
[0531] 8. The AMF may decide to initiate UE authentication by invoking the AUSF, in which case the AMF selects the AUSF based on the SUPI or SUCI as described in clause 6.3.4 of TS 23.501 [2].
[0532] If the AMF is configured to support unauthenticated SUPI Emergency Registration and the UE indicates a registration type of Emergency Registration, the AMF may skip authentication or accept that authentication may fail and continue with the registration procedure.
[0533] 9a. If authentication is required, the AMF requests authentication from the AUSF, and if the Tracing Requirements for the UE are available in the AMF, the AMF provides the tracing requirements in the request to the AUSF. Upon request from the AMF, the AUSF performs authentication of the UE. Authentication is performed as described in TS 33.501
[15] . The AUSF selects a UDM as described in clause 6.3.8 of TS 23.501 [2] and obtains authentication data from the UDM.
[0534] Editor's Note: In the case of disaster roaming registration, how the AUSF performs authentication of the UE is FFS.
[0535] Once the UE is authenticated, the AUSF provides the relevant security-related information to the AMF. If the AMF provides the SUCI to the AUSF, the AUSF returns the SUPI to the AMF only after successful authentication.
[0536] After successful authentication with the new AMF triggered by a failed integrity check with the old AMF in step 5, the new AMF invokes step 4 above again and indicates that the UE has been activated (i.e., through the reason parameter specified in clause 5.2.2.2.2).
[0537] 9b If no NAS security context exists, NAS security initiation is performed as described in TS 33.501
[15] . If the UE did not have a NAS security context in step 1, the UE includes the complete Registration Request message as defined in TS 24.501
[25] .
[0538] The AMF decides whether the registration request needs to be rerouted as described in Section 4.2.2.2.3, where Initial AMF refers to the AMF.
[0539] 9c. If the 5G-AN requests a UE context, the AMF initiates the NGAP procedure and provides the 5G-AN with the security context specified in TS38.413
[10] . If the AMF determines that EPS fallback is supported (e.g., based on the UE's capabilities, subscription data, and local policy supporting the request type flag "handover" in the PDN connection request during the attach procedure defined in clause 5.17.2.3.1 of TS23.501 [2]), the AMF sends an indication to the 5G-AN that "Redirection for EPS fallback for voice is possible" as specified in TS38.413
[10] . Otherwise, the AMF indicates that "Redirection for EPS fallback for voice is not possible." Additionally, if the trace requirements for the UE are available to the AMF, the AMF provides the trace requirements to the 5G-AN in the NGAP procedure.
[0540] 9d. The 5G-AN stores the security context and acknowledges it to the AMF. The 5G-AN uses the security context to protect messages exchanged with the UE as described in TS33.501
[15] .
[0541] 10. [Conditional] From new AMF to old AMF: Namf_Communication_RegistrationStatusUpdate (PDU session ID to be released, e.g., because slicing is not supported).
[0542] If the AMF is changed, the new AMF notifies the old AMF that the UE's registration to the new AMF is complete by calling the Namf_Communication_RegistrationStatusUpdate service operation.
[0543] If the authentication / security procedures fail, the registration is rejected and the new AMF invokes the Namf_Communication_RegistrationStatusUpdate service operation with a rejection indication to the old AMF. The old AMF continues as if the UE context transfer service operation had never been received.
[0544] If one or more S-NSSAIs used in the old registration area cannot be served in the target registration area, the new AMF determines which PDU sessions cannot be supported in the new registration area. The new AMF invokes the Namf_Communication_RegistrationStatusUpdate service operation with the rejected PDU session IDs for the old AMF. The new AMF then changes the PDU session status accordingly. The old AMF notifies the corresponding SMF to locally release the UE's SM context by invoking the Nsmf_PDUSession_ReleaseSMContext service operation.
[0545] If the new AMF receives information about the AM policy association and UE policy association in the UE context transfer in step 5 and decides based on local policy not to use the PCF identified by the PCF ID for the AM policy association and UE policy association, it notifies the old AMF that the AM policy association and UE policy association in the UE context will no longer be used, and then PCF selection is performed in step 15.
[0546] If the new AMF receives information about the UE-related analysis subscriptions in the UE context transfer in step 5, the new AMF may take over the analysis subscriptions from the old AMF. Otherwise, if the new AMF decides to create new analysis subscriptions instead, it may inform the old AMF about the analysis subscriptions (identified by the Subscription Correlation ID) that are no longer needed, and the old AMF may unsubscribe from the UE's NWDAF analysis subscriptions according to TS 23.288
[50] .
[0547] 11. [Conditional] New AMF to UE: Identity Request / Response (PEI).
[0548] If the PEI was not provided by the UE or was not obtained from the old AMF, the identity request procedure is initiated by the AMF sending an identity request message to the UE to obtain the PEI. The PEI is transmitted encrypted unless the UE performs emergency registration and cannot be authenticated.
[0549] In case of Emergency Registration, the UE may include the PEI in the registration request, in which case PEI acquisition is skipped.
[0550] As indicated in the UE MM Core Network Functions, if the UE supports RACS, the AMF uses the UE's PEI to obtain the IMEI / TAC for the purpose of RACS operation.
[0551] 12. Optionally, the new AMF initiates an ME identity check by calling the N5g-eir_EquipmentIdentityCheck_Get service operation (see Section 5.2.4.2.2).
[0552] PEI checks are performed as described in Section 4.7.
[0553] In the case of emergency registration, if the PEI is blocked, operator policy determines whether to continue or stop the emergency registration procedure.
[0554] 13. If step 14 is performed, the new AMF selects a UDM based on the SUPI, and then the UDM can select a UDR instance. See section 6.3.9 of TS23.501[2].
[0555] The AMF selects the UDM as described in clause 6.3.8 of TS 23.501 [2].
[0556] 14a-c. If the AMF has changed since the last registration procedure, or if the UE provides a SUPI that does not reference a valid context in the AMF, or if the UE registers with the same AMF that is already registered for non-3GPP access (i.e., the UE is registered via non-3GPP access and initiates this registration procedure to add 3GPP access), the new AMF registers with the UDM for the access to which it is registered using Nudm_UECM_Registration (and subscribes to be notified when the UDM deregisters this AMF). In this case, if the AMF does not have event exposure subscription information for this UE, the AMF notifies the UDM. Then, if the UDM has existing applicable event exposure subscriptions for events detected in the AMF for this UE or any of the groups to which this UE belongs (possibly obtained from the UDR), the UDM calls the Namf_EventExposure_Subscribe service to recreate the event exposure subscriptions.
[0557] The AMF shall provide the "Homogenous Support of IMS Voice over PS Sessions" indication (see clause 5.16.3.3 of TS 23.501 [2]) to the UDM. The "Homogenous Support of IMS Voice over PS Sessions" indication shall not be included unless the AMF has completed its evaluation of the support for "IMS Voice over PS Sessions" as specified in clause 5.16.3.2 of TS 23.501 [2].
[0558] During initial registration, if the AMF and UE support SRVCC from NG-RAN to UTRAN, the AMF provides the UE SRVCC capability to the UDM.
[0559] If the AMF determines that only the UE SRVCC capability has changed, the AMF sends the UE SRVCC capability to the UDM.
[0560] NOTE 10: At this step, the AMF may not have all the information necessary to determine the setting of the IMS Voice over PS Session Supported indication for this UE (see clause 5.16.3.2 of TS 23.501 [2]). Therefore, the AMF may send "Homogenous Support of IMS Voice over PS Sessions" later in this procedure.
[0561] If the AMF does not have the UE's subscription data, the AMF uses Nudm_SDM_Get to obtain the Access and Mobility Subscription data, SMF Selection Subscription data, the UE context in SMF data, and LCS mobile origination. If the AMF already has the UE's subscription data, but the SoR update indication in the UE context requires the AMF to obtain SoR information depending on the NAS registration type (Initial Registration or Emergency Registration) (see Annex C of TS23.122
[22] ), the AMF uses Nudm_SDM_Get to obtain the Steering of Roaming information. This requires that the UDM can obtain this information from the UDR via Nudr_DM_Query. After receiving a successful response, the AMF subscribes to be notified using Nudm_SDM_Subscribe when the requested data changes, and the UDM can subscribe to the UDR by Nudr_DM_Subscribe. If GPSI is available in the UE subscription data, the GPSI is provided to the AMF in the access and mobility subscription data from the UDM. The UDM can provide an indication that the subscription data for network slicing has been updated for the UE. If the UE is subscribed to MPS in the serving PLMN, the "MPS priority" is included in the access and mobility subscription data provided to the AMF. If the UE is subscribed to MCX in the serving PLMN, the "MCX priority" is included in the access and mobility subscription data provided to the AMF.The UDM also provides an IAB-Operation allowed Indication to the AMF as part of the access and mobility subscription data, which triggers the setup of a UE context in the NG-RAN or a modification of the UE context in the NG-RAN if the initial setup is in step 9c, including an indication that the IAB node is allowed.
[0562] Editor's Note: In the case of Disaster Roaming registrations, the method by which UDM provides AMF with subscription data applicable to Disaster Roaming services is FFS.
[0563] The new AMF provides the UDM with the access type to provide to the UE, and the access type is set to "3GPP access". The UDM stores the associated access type together with the serving AMF and does not delete any AMF identities associated with other access types. The UDM may store the information provided by Nudr_DM_Update during AMF registration in the UDR.
[0564] If the UE is registered to the old AMF for access and the old AMF and the new AMF are in the same PLMN, the new AMF sends a separate / independent Nudm_UECM_Registration to update the UDM with the access type set to the access used by the old AMF after the relocation of the old AMF is successfully completed.
[0565] The new AMF creates a UE context for the UE after obtaining the access and mobility subscription data from the UDM. The access and mobility subscription data includes whether the UE is allowed to include NSSAI in the 3GPP access RRC connection establishment in the clear. The access and mobility subscription data may include Enhanced Coverage Restricted information. If received from the UDM and the UE included support for Extended Coverage Usage Restriction in step 1, the AMF determines whether Extended Coverage is restricted for the UE as specified in clause 5.31.12 of TS 23.501 [2] and stores the updated Enhanced Coverage Restricted information in the UE context.
[0566] The Access and Mobility Subscription data may include NB-IoT UE Priority.
[0567] The subscription data may include a service gap time parameter. If received from the UDM, the AMF stores this service gap time in the UE context in the AMF for the UE.
[0568] In the case of an emergency registration where the UE is not successfully authenticated, the AMF does not register with the UDM.
[0569] The AMF enforces the mobility restrictions specified in clause 5.3.4.1.1 of TS 23.501 [2]. In case of emergency registration, the AMF does not check mobility restrictions, access restrictions, regional restrictions, or subscription restrictions. In case of emergency registration, the AMF ignores the failed registration response from the UDM and continues the registration procedure.
[0570] NOTE 11: The AMF may use the Nudm_SDM_Subscribe service operation with an Immediate Report Indication to trigger the UDM to immediately return the subscribed data instead of the Nudm_SDM_Get service operation if the corresponding functionality is supported by both the AMF and the UDM.
[0571] 14d. If the UDM stores the associated access type (e.g., 3GPP) with the serving AMF as shown in step 14a, the UDM initiates Nudm_UECM_DeregistrationNotification (see section 5.2.3.2.2) to the old AMF (if any) corresponding to the same (e.g., 3GPP) access. If the timer started in step 5 is not running, the old AMF may delete the UE context for the same access type. Otherwise, the AMF may delete the UE context for the same access type when the timer expires. If the serving NF deletion reason indicated by the UDM is initial registration, as described in section 4.2.2.3.2, the old AMF invokes the Nsmf_PDUSession_ReleaseSMContext(SM context ID) service operation to all SMFs associated with the UE to notify them that the UE has been deregistered from the old AMF for the same access type. The SMF releases the PDU session upon receiving this notification.
[0572] If the old AMF has established an AM policy association and a UE policy association with the PCF and the old AMF did not transfer the PCF ID to the new AMF (for example, the new AMF is in a different PLMN), the old AMF performs the AMF-initiated Policy Association Termination procedure as defined in subclause 4.16.3.2 and the AMF-initiated UE Policy Association Termination procedure as defined in subclause 4.16.13.1. In addition, if the old AMF transferred the PCF ID in the UE context but the new AMF indicates in step 10 that the AM policy association information and UE policy association information in the UE context will not be used, the old AMF performs the AMF-initiated Policy Association Termination procedure as defined in subclause 4.16.3.2 and the AMF-initiated UE Policy Association Termination procedure as defined in subclause 4.16.13.1.
[0573] If the old AMF has an N2 connection for the UE (e.g. because the UE was in RRC Inactive state but has now moved to E-UTRAN or to an area not served by the old AMF), the old AMF performs an AN release (see section 4.2.6) with a cause value indicating that the UE has already released the RRC connection in the NG-RAN locally.
[0574] If the UE context of the old AMF contains authorized NSSAIs including one or more S-NSSAIs that are subject to NSAC, upon receiving Nudm_UECM_DeregistrationNotification from the UDM, the old AMF shall send an Update Request message for each S-NSSAI that is subject to NSAC to the corresponding NSACF (see clause 4.2.11.2) with the Update Flag parameter set to decrease (see clause 4.2.11.2).
[0575] If in step 14a the AMF does not indicate that the event exposure subscription is unavailable, then at the end of the registration procedure the AMF may initiate the synchronization of event exposure subscriptions with the UDM.
[0576] NOTE 12: The AMF may initiate synchronization with the UDM even if the event is available based on local policy at any time in the UE context (e.g., as received from the old AMF). This can be done during subscription change related events.
[0577] 14e. [Conditional] If the old AMF does not have a UE context for another access type (i.e., non-3GPP access), the old AMF unsubscribes the UDM for subscription data using Nudm_SDM_unsubscribe.
[0578] 15. If the AMF decides to initiate PCF communication, the AMF operates as follows:
[0579] If the new AMF decides to use the (V-)PCF identified by the (V-)PCF ID included in the UE context from the old AMF in step 5, the AMF contacts the (V-)PCF identified by the (V-)PCF ID to obtain the policy. If the AMF decides to perform PCF discovery and selection, it selects a (V)-PCF and may select an H-PCF (in case of roaming scenarios) by V-NRF and H-NRF interaction as described in clause 6.3.7.1 and clause 4.3.2.2.3.3 of TS 23.501 [2].
[0580] 16. [Optional] The new AMF performs AM policy association establishment / modification. In case of emergency registration, this step is skipped.
[0581] If the new AMF selected a new (V-)PCF in step 15, the new AMF performs the establishment of an AM policy association with the selected (V-)PCF as defined in clause 4.16.1.2.
[0582] If a (V-)PCF identified by the (V-)PCF ID included in the UE context from the old AMF is used, the new AMF performs the AM policy association change using the (V-)PCF as defined in clause 4.16.2.1.2.
[0583] When the AMF notifies the PCF of mobility restrictions (e.g., the location of the UE) for adjustment, or when the PCF updates the mobility restrictions itself due to some conditions (e.g., the application in use, the date and time), the PCF provides the updated mobility restrictions to the AMF. If the subscription information includes tracing requirements, the AMF provides the tracing requirements to the PCF.
[0584] If the AMF supports DNN replacement, the AMF provides the PCF with the allowed NSSAI and, if available, a mapping of the allowed NSSAI.
[0585] If the PCF supports DNN substitution, the PCF provides the AMF with a trigger for DNN substitution.
[0586] 17. [Conditional] AMF to SMF: Nsmf_PDUSession_UpdateSMContext().
[0587] For an Emergency Registered UE (see TS23.501[2]), this step applies if the registration type is Mobility Registration Update.
[0588] AMF calls Nsmf_PDUSession_UpdateSMContext (see Section 5.2.8.2.6) in the following scenarios:
[0589] If the registration request in step 1 contains a list of PDU sessions to be activated, the AMF sends an Nsmf_PDUSession_UpdateSMContext Request request to the SMF associated with these PDU sessions to activate the user plane connections for these PDU sessions. Steps 5 and following steps described in subclause 4.2.3.2 are performed to complete the activation of the user plane connections without sending RRC Inactive Assistance Information and without sending an MM NAS Service Accept from the AMF to the (R)AN as described in step 12 of subclause 4.2.3.2. Once the user plane connections for the PDU sessions are activated, the AS layer of the UE notifies the NAS layer.
[0590] If in step 3 the AMF determines that the UE is performing inter-RAT mobility to or from NB-IoT, the AMF sends an Nsmf_PDUSession_UpdateSMContext request to the SMF associated with the UE's PDU sessions so that the SMF can update them according to the "PDU Session continuity at inter RAT mobility" subscription data. The steps from step 5 onwards described in subclause 4.2.3.2 are performed without sending an MM NAS Service Accept from the AMF to the (R)AN described in step 12 of subclause 4.2.3.2.
[0591] If the serving AMF changes, the new serving AMF notifies the SMFs of each PDU session that it has taken over responsibility for the signaling path to the UE, and the new serving AMF invokes the Nsmf_PDUSession_UpdateSMContext service operation using the SMF information received from the old AMF in step 5. It also indicates whether the PDU session should be reactivated.
[0592] NOTE 13: When a UE moves to another PLMN, the AMF of the serving PLMN can insert or change the V-SMF in the serving PLMN of the Home Routed PDU session. In this case, the same procedures described in subclause 4.23.3 apply to the V-SMF change as to the I-SMF change (i.e., by replacing the I-SMF with the V-SMF). If the same SMF is used during the change between PLMNs, session continuity can be supported depending on the operator's policy.
[0593] The steps from step 5 onwards described in section 4.2.3.2 are performed. If an intermediate UPF is inserted, deleted or modified for a PDU session that is not included in the "PDU Session(s) to be re-activated", this procedure is performed without interaction with N11 and N2 to update the N3 user plane between the (R)AN and the 5GC.
[0594] AMF invokes the Nsmf_PDUSession_ReleaseSMContext service operation to SMF in the following scenarios:
[0595] -If any PDU session status indicates that it has been released in the UE, the AMF invokes the Nsmf_PDUSession_ReleaseSMContext service operation to the SMF to release the network resources associated with the PDU session.
[0596] If the serving AMF has changed, the new AMF waits until step 18 is completed for all SMFs associated with the UE. Otherwise, steps 19 to 22 can continue in parallel with this step.
[0597] 18. [Conditional] If the new AMF and the old AMF are in the same PLMN, the new AMF sends a UE context modification request to the N3IWF / TNGF / W-AGF as specified in TS 29.413
[64] .
[0598] When an AMF is changed and the old AMF indicates that the UE is in CM-CONNECTED state via an N3IWF, W-AGF, or TNGF, and the new AMF and the old AMF are in the same PLMN, the new AMF creates an NGAP UE association to the N3IWF / TNGF / W-AGF to which the UE is connected, which automatically releases the existing NGAP UE association between the old AMF and the N3IWF / TNGF / W-AGF.
[0599] 19. The N3IWF / TNGF / W-AGF sends a UE Context Modification Response to the new AMF.
[0600] 19a. [Conditional] After the new AMF receives a response message from the N3IWF, W-AGF, or TNGF in step 19, the new AMF registers with the UDM using Nudm_UECM_Registration with the access type set to "non-3GPP access" as in step 14a. The UDM stores the associated access type with the serving AMF and does not delete any AMF identities associated with other access types. The UDM may store the information provided by Nudr_DM_Update during AMF registration in the UDR.
[0601] 19b. [Conditional] Once the UDM saves the associated access type (i.e., non-3GPP) with the serving AMF as indicated in step 19a, the UDM shall initiate a Nudm_UECM_DeregistrationNotification (see section 5.2.3.2.2) to the old AMF corresponding to the same (i.e., non-3GPP) access. The old AMF shall delete the UE context for the non-3GPP access.
[0602] 19c. Old AMF uses Nudm_SDM_unsubscribe to unsubscribe from UDM for subscription data.
[0603] 20a. Void
[0604] 21. New AMF to UE: Registration Accept (5G-GUTI, Registration Area, Mobility restrictions, PDU Session status, Allowed NSSAI, Mapping of Allowed NSSAI, Configured NSSAI for the Serving PLMN, Mapping of Configured NSSAI, NSSRG Information, Rejected S-NSSAIs, Pending NSSAI, Mapping of Pending NSSAI, Periodic Registration Update timer, Active Time, Strictly Periodic Registration Timer Indication, LADN Information, Accepted MICO Mode MICO mode], [IMS Voice over PS session supported Indication], [Emergency Service Support indicator], [Accepted DRX parameters for E-UTRA and NR], [Accepted DRX parameters for NB-IoT], [Extended idle mode DRX parameters], [Paging Time Window]Window), Network support of Interworking without N26, Access Stratum Connection Establishment NSSAI Inclusion Mode, Network Slicing Subscription Change Indication, Operator-defined access category definitions, List of equivalent PLMNs, Enhanced Coverage Restricted information, Supported Network Behavior, Service Gap Time, PLMN-assigned UE radio capability ID, PLMN-assigned UE radio capability ID deletion, WUS Assistance Information, Truncated 5G-S-TMSI Configuration, Connection Release Support Supported, Paging Cause Indication for Voice Service Supported, Paging Restriction Supported, and Reject Paging Request Supported.
[0605] If the requested NSSAI does not contain an S-NSSAI that maps to an S-NSSAI of the HPLMN that is subject to Network Slice-Specific Authentication and Authorization, and the AMF determines that the S-NSSAI cannot be provided in the allowed NSSAIs for the UE within the current UE tracking area, and no default S-NSSAIs that have not yet been involved in the current UE registration procedure are further considered, the AMF shall reject the UE registration and include in the rejection message a list of rejected S-NSSAIs, each with an appropriate rejection cause value.
[0606] The allowed NSSAIs for the access type for the UE are included in the N2 message carrying the registration accept message. The allowed NSSAIs include only S-NSSAIs that do not require network slice-specific authentication and authorization based on subscription information, regardless of access type, and S-NSSAIs for which network slice-specific authentication and authorization based on the UE context in the AMF have previously been successful. The pending NSSAI mapping maps each S-NSSAI of the serving PLMN's pending NSSAIs to an HPLMN S-NSSAI.
[0607] If the UE indicates support for network slice-specific authentication and authorization procedures in the UE MM Core Network Function in the registration request, the AMF includes in the pending NSSAI the S-NSSAIs that map to the S-NSSAIs of the HPLMNs whose subscription information indicates that they are subject to network slice-specific authentication and authorization, as described in Section 4.6.2.4 of TS 24.501
[25] . In such a case, the AMF triggers the network slice-specific authentication and authorization procedures specified in Section 4.2.9.2 in step 25, except for S-NSSAIs for which network slice-specific authentication and authorization has already been initiated for another access type of the same S-NSSAI based on the network policy. The UE does not attempt to re-register to an S-NSSAI included in the list of pending NSSAIs until the network slice-specific authentication and authorization procedures are completed, regardless of the access type.
[0608] If the UE does not indicate support for network slice-specific authentication and authorization procedures in the UE 5GMM Core Network Functions in the registration request and the requested NSSAI includes S-NSSAIs that map to HPLMN S-NSSAIs that are subject to network slice-specific authentication and authorization, the AMF shall include those S-NSSAIs in the requested NSSAI in the rejected S-NSSAI.
[0609] The following are reasons why an S-NSSAI cannot be provided to an Allowed NSSAI:
[0610] All S-NSSAIs within the requested NSSAI are subject to network slice-specific authentication and authorization, or
[0611] -The requested NSSAI is not provided or none of the S-NSSAIs in the requested NSSAI matches the Subscribed S-NSSAI, and all S-NSSAIs marked as default in the Subscribed S-NSSAI are subject to network slice-specific authentication and authorization.
[0612] The AMF shall provide an empty Authorized NSSAI. Upon receiving an empty Authorized NSSAI and a pending NSSAI, the UE is registered with the PLMN but shall not attempt to use any services offered by the PLMN upon access, except for emergency services (see TS 24.501
[25] ), until the UE receives an Authorized NSSAI, pending completion of network slice-specific authentication and authorization procedures.
[0613] The AMF stores the NB-IoT Priority obtained in step 14 and associates it with the 5G-S-TMSI assigned to the UE.
[0614] If the registration request message received via 3GPP access does not contain paging restriction information, the AMF shall delete the paging restriction information stored for this UE and stop paging restriction accordingly.
[0615] If the Registration Request message received via 3GPP access contains a Release Request indication:
[0616] The AMF updates the UE context with the received paging restriction information and enforces it in the network triggered Service Request procedure as described in section 4.2.3.3.
[0617] The AMF does not establish user plane resources and triggers the AN release procedure as described in section 4.2.6 after the registration procedure is completed.
[0618] The AMF sends a registration accept message to the UE indicating that the registration request has been accepted. If the AMF assigns a new 5G-GUTI, the 5G-GUTI is included. When the AMF receives a registration request message of type "Initial Registration," "Mobility Registration Update," or "Disaster Roaming Registration" from the UE, the AMF includes the new 5G-GUTI in the registration accept message. When the AMF receives a registration request message of type "Periodic Registration Update" from the UE, the AMF includes the new 5G-GUTI in the registration accept message. If the UE is already in RM-REGISTERED state via another access within the same PLMN, the UE uses the 5G-GUTI received in the registration accept for both registrations. If the registration accept does not include a 5G-GUTI, the UE uses the 5G-GUTI assigned to the existing registration for the new registration as well. If the AMF assigns a new registration area, the AMF sends the registration area to the UE via the registration accept message. In case of disaster roaming registration, the AMF allocates a registration area limited to the area where the disaster situation exists as specified in clause 5.40 of TS 23.501 [2]. If the registration accept message does not include a registration area, the UE considers the old registration area valid. If mobility restrictions apply to the UE and the registration type is not emergency registration, the mobility restrictions are included. The AMF notifies the UE of the established PDU session in the PDU session status. The UE locally deletes internal resources related to PDU sessions that are not marked as established in the received PDU session status. If the AMF invokes the Nsmf_PDUSession_UpdateSMContext procedure for UP activation of the PDU session in step 18 and receives a rejection from the SMF, the AMF notifies the UE of the PDU session ID and the reason why the user plane resources were not activated.If the UE is connected to two AMFs belonging to different PLMNs via 3GPP and non-3GPP accesses, the UE locally deletes internal resources related to PDU sessions in the current PLMN that are not marked as established in the received PDU session status. If PDU session status information was included in the registration request, the AMF indicates the PDU session status to the UE.
[0619] If the RAT type is NB-IoT and the network is configured to use the Control plane Relocation Indication procedure, the AMF includes in the Registration Accept message a truncated 5G-S-TMSI configuration that a UE using control plane CIoT 5GS optimization will use to create a truncated 5G-S-TMSI, see clause 5.31.4.3 of TS 23.501 [2].
[0620] The allowed NSSAIs provided in the registration consent are valid in the registration area and apply to all PLMNs with tracking areas included in the registration area. The mapping of allowed NSSAIs is the mapping of each S-NSSAI of the allowed NSSAIs to the HPLMN S-NSSAI. The mapping of configured NSSAIs is the mapping of each S-NSSAI of the configured NSSAIs of the serving PLMN to the HPLMN S-NSSAI.
[0621] If the UE indicates support for the subscription-based restriction feature for simultaneous network slice registrations, the AMF shall include the NSSRG information defined in clause 5.15.12 of TS 23.501 [2], if available.
[0622] If the UE does not indicate support for the subscription-based restriction feature for concurrent network slice registrations, the UE's subscription information includes SRG information, and the AMF provides the UE with a configured NSSAI, the configured NSSAI includes the S-NSSAI according to clause 5.15.12 of TS 23.501 [2].
[0623] The AMF includes in the registration accept message the LADN information of the list of LADNs available in the registration area determined by the AMF for the UE as described in clause 5.6.5 of TS 23.501 [2]. The AMF may also include operator-defined access category definitions as described in TS 24.501
[25] to allow the UE to determine the applicable operator-specific access category definitions.
[0624] If the UE includes the MICO mode in the registration request, the AMF responds in the registration accept message whether to use the MICO mode. If the MICO mode is allowed for the UE, the AMF can include an Active Time value and / or a Strictly Periodic Registration Timer Indication in the registration accept message. As described in clause 5.31.7 of TS 23.501 [2], to enable UE power saving, the AMF determines the Periodic Registration Update timer value, the Active Time value, and the Strictly Periodic Registration Timer Indication based on local configuration, if available, the Expected UE Behavior, UE indicated preferences, UE capabilities, UE subscription information, and network policies, or a combination thereof. If the UE indicated the Strictly Periodic Registration Timer Indication capability in the Registration Request message as described in step 1, the AMF decides to apply the Strictly Periodic Registration Timer Indication to the UE. If the AMF provides the UE with a periodic registration update timer value together with the Strictly Periodic Registration Timer Indication, the UE and the AMF start the periodic registration update timer after this step as described in clause 5.31.7.5 of TS 23.501 [2].
[0625] In case of registration via 3GPP access, the AMF sets the IMS Voice over PS session supported indication as described in clause 5.16.3.2 of TS 23.501 [2]. To set the IMS Voice over PS Session supported indication, the AMF may need to perform the UE Capability Match Request procedure in clause 4.2.8a to check the compatibility of the UE and NG-RAN radio capabilities related to IMS Voice over PS. If the AMF does not receive the Voice Support Match Indicator from the NG-RAN on time, based on the implementation, the AMF may set the IMS Voice over PS Session supported indication and update it at a later stage.
[0626] In the case of registration in 3GPP access, if the AMF obtains or determines, according to local configuration, a target NSSAI and a corresponding RFSP index to enable the NG-RAN to redirect the UE to a cell supporting network slicing that is not available in the current TA, as described in clause 5.3.4.3.3 of TS23.501 [2], the AMF provides the target NSSAI and the corresponding RFSP index to the NG-RAN.
[0627] In case of registration via non-3GPP access, the AMF sets the IMS Voice over PS Session Support indication as described in clause 5.16.3.2a of TS 23.501 [2].
[0628] The Emergency Service Support Indication informs the UE that emergency services are supported, i.e., the UE can request an emergency service PDU session. If the AMF receives "MPS Priority" from the UDM as part of the access and mobility subscription data, based on operator policy, the "MPS Priority" is included in the registration accept message to the UE to inform the UE whether the configuration of Access Identity 1 is valid within the selected PLMN, as specified in TS 24.501
[25] . If the AMF receives "MCX Priority" from the UDM as part of the access and mobility subscription data, based on operator policy and the UE subscription to the MCX service, the "MCX Priority" is included in the registration accept message to the UE to inform the UE whether the configuration of Access Identity 2 is valid within the selected PLMN, as specified in TS 24.501
[25] . The accepted DRX parameters are defined in clause 5.4.5 of TS 23.501 [2]. The AMF includes the accepted DRX parameters for NB-IoT if the UE included the requested DRX parameters for NB-IoT in the registration request message. The AMF configures network support for interworking without the N26 parameter as described in clause 5.17.2.3.1 of TS 23.501 [2]. If the AMF accepts the use of extended idle mode DRX, the AMF includes the extended idle mode DRX parameters and the Paging Time Window as described in clause 5.31.7.2 of TS 23.501 [2].
[0629] If the UDM is intended to indicate to the UE that the subscription has changed, it includes a Network Slicing Subscription Change Indication. If the AMF includes a Network Slicing Subscription Change Indication, the UE shall locally clear all network slicing configurations for all PLMNs and, if applicable, update the current PLMN configuration based on the received information.
[0630] As specified in clause 5.15.9 of TS 23.501 [2], the Access Stratum Connection Establishment NSSAI inclusion mode is included to indicate to the UE which NSSAI, if any, to include in the Access Stratum Connection Establishment. The AMF can set values for operation modes a, b, and c defined in clause 5.15.9 of TS 23.501 [2] for 3GPP access only if this is indicated as allowed by including an NSSAI in the RRC Connection Establishment Authorization.
[0631] For a UE registered in a PLMN, the AMF may provide a list of equivalent PLMNs, which are processed as specified in TS 24.501
[25] . For a UE registered in an SNPN, the AMF does not provide the UE with a list of equivalent PLMNs.
[0632] If the UE included support for restricted use of enhanced coverage in step 1, the AMF sends the Enhanced Coverage Restricted information to the NG-RAN in the N2 message. The AMF also sends the Enhanced Coverage Restricted information to the UE in the Registration Accept message.
[0633] If the UE receives Enhanced Coverage Restricted information in the registration accept message, the UE stores this information and uses the value of the Enhanced Coverage Restricted information to determine whether to use the enhanced coverage function.
[0634] If the UE and the AMF negotiate to enable MICO mode and the AMF uses the Extended Connected Timer, the AMF provides the Extended Connected Time value to the NG-RAN in this step (see clause 5.31.7.3 of TS 23.501 [2]). The Extended Connected Time value indicates the minimum time the RAN must keep the UE in RRC-CONNECTED state, regardless of inactivity.
[0635] If the UE includes a preferred network behavior in its registration request, the AMF indicates the supported and accepted CIoT 5GS optimizations in the Supported Network Behavior information (see clause 5.31.2 of TS 23.501 [2]).
[0636] The AMF can steer the UE out of 5GC by rejecting the registration request. Before steering the UE out of 5GC, the AMF takes into account the Preferred and Supported Network Behavior (see clause 5.31.2 of TS 23.501 [2]) and the availability of EPC to the UE.
[0637] If the AMF accepts the MICO mode and is aware that there may be mobile terminated data or pending signaling, the AMF shall maintain the N2 connection for at least the extended connection time and provide the extended connection time value to the RAN as described in clause 5.31.7.3 of TS 23.501 [2].
[0638] If a service gap time is present in the subscription information (steps 14a-c) or the service gap time has been updated by the Subscriber Data Update Notification to AMF procedure (see section 4.5.1) and the UE has indicated UE Service Gap Control Capability, the AMF includes the service gap time.
[0639] If the UE receives a service gap time in the registration accept message, the UE stores this parameter and applies the service gap control (see clause 5.31.16 of TS 23.501 [2]).
[0640] If the network supports WUS grouping (see TS23.501[2]), the AMF sends WUS Assistance Information to the UE. If the UE provides UE paging probability information in step 1, the AMF takes it into account when determining the WUS Assistance Information.
[0641] If the UE and AMF support RACS as defined in clause 5.4.4.1a of TS 23.501 [2], the AMF shall configure the UE with the UE radio capability ID, and if the AMF already has a UE radio capability other than the NB-IoT radio capability for the UE, the AMF may provide the UE with the UE radio capability ID of the UE radio capability, which the UCMF returns to the AMF in the Nucmf_assign service operation for this UE. Alternatively, if the UE and AMF support RACS, the AMF may provide the UE with an indication to delete any PLMN-assigned UE Radio Capability ID in this PLMN (see clause 5.4.4.1a of TS 23.501 [2]).
[0642] If the UE is "CAG supported" and the AMF needs to update the UE's CAG information, the AMF may include the CAG information as part of the mobility restriction in the registration accept message.
[0643] If the UE indicates support for the Paging Cause Indication for Voice Service feature in the Registration Request message and the network supports and plans to apply the Paging Cause Indication for Voice Service feature for the UE, the AMF includes an indication that the UE supports the Paging Cause Indication for Voice Service feature in the N2 message carrying the Registration Accept message.
[0644] If the multi-USIM UE indicated support for one or more multi-USIM specific features in the UE 5GMM Core Network Capabilities in step 1, the AMF shall indicate to the multi-USIM UE whether one or more corresponding multi-USIM specific features listed in clause 5.38 of TS 23.501 [2] are supported, based on the network capabilities and configuration by the network (i.e., based on local network policy), by providing one or more of the following indications: Connection Release Supported, Paging Cause Indication for Voice Service Supported, Paging Restriction Supported, Reject Paging Request Supported. If the multi-USIM UE indicates support for the paging cause indication for voice service feature, the AMF supporting paging cause indication for voice service shall include an indication that the UE supports the paging cause indication for voice service feature in the N2 message. The AMF indicates only Paging Restriction Supported and either Connection Release Supported or Reject Paging Request Supported. The UE shall only use multi-USIM specific features that the AMF indicates are supported.
[0645] 21b. [Optional] The new AMF performs a UE Policy Association Establishment as defined in clause 4.16.11. In case of an emergency registration, this step is skipped.
[0646] The new AMF sends an Npcf_UEPolicyControl Create Request to the PCF. The PCF sends an Npcf_UEPolicyControl Create Response to the new AMF.
[0647] The PCF triggers the UE Configuration Update Procedure as defined in section 4.2.4.3.
[0648] 22. [Conditional] UE to new AMF: Registration Complete ().
[0649] In step 21, after receiving the [Configured NSSAI of Serving PLMN], [Configured NSSAI Mapping], [NSSRG Information], and either the Network Slicing Subscription Change Indication or CAG information, if the update is successful, the UE sends a registration complete message to the AMF.
[0650] The UE sends a registration complete message to the AMF to check whether a new 5G-GUTI has been assigned.
[0651] If a new 5G-GUTI is assigned, the UE passes the new 5G-GUTI to the lower layers of the 3GPP access when the lower layers (3GPP access or non-3GPP access) indicate to the RM layer of the UE that the registration complete message has been successfully transferred over the air interface.
[0652] NOTE 14: The above is necessary because the NG-RAN may use the RRC Inactive state and part of the 5G-GUTI is used to calculate the Paging Frame (see TS38.304
[44] and TS36.304
[43] ). It is assumed that the Registration Complete is delivered reliably to the AMF after the 5G-AN has confirmed its reception to the UE.
[0653] If the list of PDU sessions to be activated is not included in the registration request and the registration procedure was not started in the CM-CONNECTED state, the AMF shall release the signaling connection with the UE according to clause 4.2.6.
[0654] If a follow-on request is included in the registration request, the AMF does not release the signaling connection after the registration procedure is completed.
[0655] If the AMF is aware that some signaling is pending within the AMF or between the UE and the 5GC, the AMF will not release the signaling connection immediately after the registration procedure is completed.
[0656] If a PLMN-assigned UE radio capability ID is included in step 21, the AMF stores the PLMN-assigned UE radio capability ID in the UE context upon receiving the registration complete message.
[0657] If the UE receives a PLMN-assigned UE Radio Capability ID deletion indication in step 21, the UE deletes the PLMN-assigned UE Radio Capability ID for this PLMN.
[0658] 23. [Conditional] If the access and mobility subscription data provided by the UDM to the AMF in AMF to UDM:14b includes roaming steering information with an indication that the UDM requests the UE to acknowledge receipt of this information, the AMF provides the UE response to the UDM using Nudm_SDM_Info. For more information on handling of roaming steering information, see TS23.122
[22] .
[0659] 23a. In the case of registration via 3GPP access, if the AMF does not release the signaling connection, the AMF sends RRC Inactive Assistance Information to the NG-RAN.
[0660] In the case of registration via non-3GPP access, if the UE is also in CM-CONNECTED state in 3GPP access, the AMF sends RRC inactive assistance information to the NG-RAN.
[0661] The AMF also uses the Nudm_SDM_Info service operation to provide an acknowledgement to the UDM that the UE has received and acted upon the CAG information or Network Slicing Subscription Change Indication (see steps 21 and 22).
[0662] 24. [Conditional] AMF to UDM: After step 14a, in parallel with any of the previous steps, the AMF sends the "Homogeneous Support of IMS Voice over PS Sessions" indication to the UDM using Nudm_UECM_Update.
[0663] - If AMF is evaluating support for IMS Voice over PS Sessions, see clause 5.16.3.2 of TS 23.501 [2].
[0664] - If the AMF determines that it is necessary to update the Homogeneous Support of IMS Voice over PS Sessions, please refer to clause 5.16.3.3 of TS 23.501 [2].
[0665] 25. [Conditional] If the UE indicates support for network slice-specific authentication and authorization procedures in the UE MM Core Network Function in the Registration Request, and the S-NSSAI of the HPLMN is subject to network slice-specific authentication and authorization, the relevant procedures are performed in this step (see Section 4.2.9.1). Once the network slice-specific authentication and authorization procedures are completed for all S-NSSAIs, the AMF triggers a UE Configuration Update procedure to deliver the allowed NSSAIs, including the S-NSSAIs for which network slice-specific authentication and authorization were successful, and includes the rejected NSSAIs with an appropriate rejection cause value.
[0666] Due to pending network slice-specific authentication and authorization, the AMF removes the mobility restriction if the tracking area of the registration area was previously assigned as a non-authorized area.
[0667] The AMF stores in the UE context an indication of successful network slice-specific authentication and authorization for any S-NSSAI of the HPLMN that is subject to network slice-specific authentication and authorization.
[0668] Once the network slice specific authentication and authorization procedures are completed, if the AMF is unable to provide an S-NSSAI among the allowed NSSAIs of a UE that is already authenticated and authorized by the PLMN and is unable to further consider a default S-NSSAI, the AMF shall perform the Network-initiated Deregistration procedure described in clause 4.2.2.3.3 and include in the explicit deregistration request message a list of rejected S-NSSAIs, each with an appropriate rejection cause value.
[0669] Mobility related event notifications to NF consumers are triggered at the end of this procedure for the cases described in subclause 4.15.4.
[0670] <4.2.2.2.3 Registration via AMF Reassignment> When an AMF receives a registration request, the AMF may need to reroute the registration request to another AMF, for example if the initial AMF is not the appropriate AMF to serve the UE. The registration via AMF reallocation procedure described in Figure 4.2.2.2.3-1 is used to reroute the UE's NAS messages to the target AMF during the registration procedure.
[0671] Figure 4.2.2.2.3-1: Registration with AMF reassignment procedure (see Figure 16)
[0672] The initial AMF and target AMF register their functions with the NRF.
[0673] 1. Steps 1 and 2 in Figure 4.2.2.2.2-1 occur, and the (R)AN sends a registration request message to the initial AMF within the initial UE message.
[0674] 2. If the AMF requires SUPI and / or UE subscription information to decide whether to reroute the registration request, or if the registration request was not sent integrity protected, or if integrity protection is indicated as failed, the AMF performs steps 4 to 9a or 9b of Figure 4.2.2.2.2-1.
[0675] 3a. [Conditional] If the initial AMF requires the UE's subscription information to decide whether to reroute the registration request and the UE's slice selection subscription information was not provided by the old AMF, the AMF selects the UDM as described in clause 6.3.8 of TS 23.501 [2].
[0676] 3b. Initial AMF to UDM: Nudm_SDM_Get(SUPI, Slice Selection Subscription data).
[0677] The initial AMF requests the UE's slice selection subscription data from the UDM by invoking the Nudm_SDM_Get (see section 5.2.3.3.1) service operation. The UDM can obtain this information from the UDR by Nudr_DM_Query(SUPI, Slice Selection Subscription data).
[0678] 3c. UDM to initial AMF: Response to Nudm_SDM_Get. AMF obtains slice selection subscription data including Subscribed S-NSSAI.
[0679] The UDM responds to the initial AMF with slice selection data.
[0680] Editor's note: In the case of disaster roaming registration, the FFS is the method by which the UDM provides the AMF with slice selection subscription data applicable to disaster roaming services.
[0681] 4a. [Conditional] Initial AMF to NSSF: Nnssf_NSSelection_Get(Requested NSSAI, [Mapping Of Requested NSSAI], Subscribed S-NSSAI(s) with the default S-NSSAI indication, [NSSRG Information], TAI, Allowed NSSAI for the other access type (if any), [Mapping of Allowed NSSAI], PLMN ID of SUPI).
[0682] If slice selection is required (see clause 5.15.5.2.1 of TS 23.501 [2]), for example, if the initial AMF cannot provide service for all S-NSSAIs of the requested NSSAI that are allowed by the subscription information, the initial AMF invokes the Nnssf_NSSelection_Get service operation from the NSSF by including the requested NSSAI, optionally the mapping of the requested NSSAI, the Subscribed S-NSSAI with the default S-NSSAI indication, [NSSRG Information], allowed NSSAIs of other access types (if any), the mapping of the allowed NSSAI, the PLMN ID of the SUPI, and the TAI of the UE.
[0683] If available, the AMF shall include NSSRG information on the S-NSSAI of the HPLMN as defined in clause 5.15.12 of TS 23.501 [2], including whether the UE has indicated support for the subscription-based restrictions to simultaneous registration of network slices and whether the UDM has indicated that all Subscribed S-NSSAIs are provided to non-supporting UEs.
[0684] 4b. [Conditional] NSSF to Initial AMF: Response to Nnssf_NSSelection_Get (AMF Set or list of AMF addresses, Allowed NSSAI for the first access type, [Mapping of Allowed NSSAI], [Allowed NSSAI for the second access type], [Mapping of Allowed NSSAI], [NSI ID], [NRF], [List of rejected (S-NSSAI(s), cause value(s))], [Configured NSSAI for the Serving PLMN], [Mapping of Configured NSSAI]).
[0685] The NSSF performs the steps specified in point (B) of clause 5.15.5.2.1 of TS 23.501 [2]. The NSSF returns to the initial AMF the allowed NSSAIs for the first access type, optionally the mapping of the allowed NSSAIs, the allowed NSSAIs for the second access type (if any), optionally the mapping of the allowed NSSAIs, and the target AMF set or a list of candidate AMFs based on the configuration. The NSSF may return the NSI ID associated with the network slice instance corresponding to the specific S-NSSAI. The NSSF may also return the NRF used to select an NF / service within the selected network slice instance. Information regarding the rejection cause of an S-NSSAI not included in the allowed NSSAI may also be returned. The NSSF may return the configured NSSAIs of the serving PLMN and, possibly, the associated mapping of the configured NSSAIs. If NSSRG information was included in the request, the NSSF provides the configured NSSAIs as described in clause 5.15.12 of TS 23.501 [2].
[0686] NOTE 1: The NRF returned by the NSSF, if any, may belong to any level of NRF (see clause 6.2.6 of TS 23.501 [2]) according to the operator's deployment decision.
[0687] 5. [Conditional] Initial AMF to old AMF: Namf_Communication_RegistrationStatusUpdate (failure cause).
[0688] If a different AMF is selected, the initial AMF sends a reject indication to the old AMF, indicating that the UE registration procedure was not fully completed by the initial AMF. The old AMF continues as if Namf_Communication_UEContextTransfer had never been received.
[0689] 6a. [Conditional] Initial AMF to NRF: Nnrf_NFDiscovery_Request(NF Type, AMF Set).
[0690] If the initial AMF does not store the target AMF address locally and the initial AMF intends to use direct reroute to the target AMF, or if the AMF address needs to be included in the reroute message via the (NG-R)AN, the initial AMF invokes the Nnrf_NFDiscovery_Request service operation from the NRF to find a suitable target AMF with the NF capabilities required to provide service to the UE. The NF type is set to AMF. The AMF set is included in the Nnrf_NFDiscovery_Request.
[0691] 6b. [Conditional] Response from NRF to AMF: Nnrf_NFDiscovery_Request (AMF pointer, AMF address, and a list of plus additional selection rules and NF capabilities).
[0692] The NRF responds with a list of potential target AMF(s). The NRF may also provide details of the services offered by the candidate AMFs, along with notification endpoints (if available) for each type of notification service that the selected AMF has registered with the NRF. Alternatively, a list of potential target AMFs, their capabilities and optionally additional selection rules may be provided. Based on information about the registered NFs and the required capabilities, the target AMF is selected by the initial AMF.
[0693] If a security association has been established between the UE and the initial AMF, to avoid registration failure, the initial AMF forwards the NAS message to the target AMF by performing step 7(A).
[0694] NOTE 2: When the initial AMF forwards the NAS message to the target AMF via the (R)AN, the security context in the initial AMF is not forwarded to the target AMF. In this case, the security context in the UE and the target AMF are not synchronized, so the UE rejects the NAS message sent from the target AMF.
[0695] Note 3: If AMF reassignment is performed in step 7(A), network slice isolation cannot be completely maintained.
[0696] If the initial AMF is not part of the target AMF set and cannot obtain a list of candidate AMFs by querying the NRF using the target AMF set (e.g., an NRF pre-configured locally on the AMF does not provide the requested information, a query to an appropriate NRF provided by the NSSF was not successful, or the initial AMF recognizes that the initial AMF is not authorized as a serving AMF), the initial AMF performs step 7(B) and forwards the NAS message to the target AMF via the (R)AN, unless a security association has been established between the UE and the initial AMF. The authorized NSSAI and AMF set are included to allow the (R)AN to select the target AMF, as described in clause 6.3.5 of TS 23.501 [2].
[0697] 7(A). If the initial AMF decides to forward the NAS message directly to the target AMF based on local policy and subscription information, the initial AMF invokes Namf_Communication_N1MessageNotify to the target AMF to transmit the rerouted NAS message. The Namf_Communication_N1MessageNotify service operation includes AN access information (e.g., information that allows the (R)AN to identify the N2 terminating point, the CAG identifier of the CAG cell) and the full Registration Request message, as well as the UE's SUPI, information elements indicating that the UE is enabled, and the MM context, if available. If the initial AMF obtained information from the NSSF as described in step 4b, that information is included, except for the AMF set or list of AMF addresses. Then, the target AMF updates the (R)AN with the UE's newly updated N2 terminating point in the first message from the target AMF to the RAN in step 8.
[0698] 7(B). If the initial AMF decides based on local policy and subscription information to forward the NAS message to the target AMF via the (R)AN unless the target AMF is identified in the list of candidate AMFs returned from the NSSF, the initial AMF sends a Reroute NAS message to the (R)AN (step 7a). The Reroute NAS message includes information about the target AMF and a full Registration Request message. If the old AMF successfully checked the integrity of the Registration Request message or the authentication procedure was successfully performed in step 2, and the initial AMF received an MM context or a SUPI without an MM context from the old AMF in step 2, the initial AMF includes the SUPI and an information element indicating that the UE is enabled if the initial AMF obtained the information as described in step 4b. If the initial AMF obtained the information as described in step 4b, the information is included. The (R)AN sends an Initial UE message indicating Reroute by Slicing to the target AMF, including the information from step 4b provided by the NSSF (step 7b). The (R)AN includes the SUPI in the reroute NAS message for the initial NAS message, an information element indicating that the UE is enabled, and any other received information elements.
[0699] 8. If the target AMF receives an information element indicating the SUPI and the UE is validated, the target AMF sends the SUPI and the information element indicating the UE is validated to the old AMF in a Namf_Communication_UEContextTransfer message. Upon receiving a Namf_Communication_UEContextTransfer message containing an information element indicating the SUPI and the UE is validated, the old AMF sends the UE context to the target AMF in a Namf_Communication_UEContextTransfer response message without performing an integrity check. If the target AMF does not receive an information element indicating the SUPI and the UE is validated, after receiving the registration request message sent in step 7(A)a or step 7(B)b, the target AMF continues the registration procedure from steps 4 to 22 in Figure 4.2.2.2.2-1 (the target AMF corresponds to the new AMF), which includes the UE context obtained from the old AMF. If a 5G security context is received from the initial AMF, the target AMF continues to use that context instead of the 5G security context obtained from the old AMF. If the initial AMF decides to forward a NAS message to the target AMF (step 7(A)), the first message from the target AMF to the (R)AN (either an initial context setup request or a downlink NAS transport) includes the AMF name of the initial AMF and the target AMF UE NGAP ID.
[0700] As will be appreciated by those skilled in the art, the present disclosure may be embodied as a method and a system, and thus may take the form of an entirely hardware embodiment, a software embodiment, or an embodiment combining software and hardware aspects.
[0701] It will be understood that each block of the block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus to produce a machine, and the instructions, executed by the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowchart and / or block diagram blocks. A general-purpose processor may be a microprocessor, but alternatively, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as, for example, a combination of computing devices, such as multiple microprocessors, one or more microprocessors, or any other such configuration.
[0702] The methods or algorithms described in connection with the examples disclosed herein may be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. The software module may reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. The storage medium may be coupled to the processor such that the processor can read information from, and write information to, the storage medium. Alternatively, the storage medium may be integral to the processor. The processor and the storage medium may reside in an ASIC.
[0703] The previous description of the disclosed examples is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these examples will be readily apparent to those skilled in the art. The general principles defined herein may be applied to other examples without departing from the spirit or scope of the present disclosure. Thus, the present disclosure is not intended to be limited to the examples shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0704] Although the present disclosure has been particularly shown and described with reference to exemplary embodiments thereof, the present disclosure is not limited to these embodiments. Those skilled in the art will understand that various changes in form and details can be made without departing from the spirit and scope of the present disclosure as defined by this document. For example, the above embodiments are not limited to 5GS, but can also be applied to communication systems other than 5GS (e.g., 6G systems, Beyond 5G systems).
[0705] All or part of the embodiments disclosed above can be described as follows, but are not limited to these.
[0706] Clause 1. A method of a non-geographically selected Access and Mobility Management Function (AMF) device, the method comprising: Receives Namf_Communication_UEContextTransfer messages from geographically selected AMF devices This includes: The Namf_Communication_UEContextTransfer message includes a registration request message and information indicating an access type set to 3rd Generation Partnership Project (3GPP) access; The method comprises: If the Namf_Communication_UEContextTransfer message contains the information, perform an integrity check of the Registration Request message based on a Non-Access-Stratum (NAS) security context for non-3GPP access. A method comprising:
[0707] Appendix 2. The method of Appendix 1, further comprising: If the non-geographically selected AMF device passes the integrity check, it sends a Namf_Communication_UEContextTransfer response message to the geographically selected AMF. A method comprising:
[0708] Clause 3. A method of a geographically selected Access and Mobility Management Function (AMF) device, the method comprising: Receives a registration request message This includes: the registration request message includes information indicating that the registration request message is integrity protected based on a Non-Access-Stratum (NAS) security context for non-3rd Generation Partnership Project (non-3GPP) access; and The method comprises: Sending a Namf_Communication_UEContextTransfer message to a non-geographically selected AMF device This includes: The Namf_Communication_UEContextTransfer message includes the information A method characterized by:
[0709] Clause 4. A method of a geographically selected Access and Mobility Management Function (AMF) device, the method comprising: Receives a registration request message This includes: the registration request message includes: first information indicating that the registration request message is integrity protected based on a Non-Access-Stratum (NAS) security context for non-3rd Generation Partnership Project (non-3GPP) access; and second information indicating whether registration via 3GPP access or the non-3GPP access is preferred; The method comprises: Sends a Namf_Communication_UEContextTransfer message to a non-geographically selected AMF device. receiving a Namf_Communication_UEContextTransfer response message from the non-geographically selected AMF device; This includes: The Namf_Communication_UEContextTransfer response message includes third information indicating that a user equipment (UE) context related to a non-3GPP access cannot be transferred or that a non-3GPP InterWorking Function (N3IWF) can only establish a connection with the non-geographically selected AMF device; The method comprises: sending a registration accept message if the second information indicates that registration via the 3GPP access is preferred; This includes: The registration accept message includes fourth information indicating that the geographically selected AMF device cannot simultaneously register the UE for the 3GPP access and the non-3GPP access; The method comprises: sending a registration reject message if the second information indicates that registration via the non-3GPP access is preferred; This includes: The registration rejection message includes the fourth information. A method characterized by:
[0710] Supplementary Note 5. A method for a user equipment (UE), the method comprising: Start the registration process, Send a registration request message This includes: The registration request message includes first information indicating that the registration request message is integrity protected based on a Non-Access-Stratum (NAS) security context for non-3rd Generation Partnership Project (non-3GPP) access. A method characterized by:
[0711] Appendix 6. The method according to Appendix 5, comprising: The registration request message includes second information indicating whether registration via 3GPP access or registration via non-3GPP access is preferred. A method characterized by:
[0712] Appendix 7. The method of Appendix 6, further comprising: receiving a registration accept message if the second information indicates that registration via the 3GPP access is preferred; This includes: The registration accept message includes third information indicating that a geographically selected AMF device cannot simultaneously register a UE for the 3GPP access and the non-3GPP access; The method comprises: receiving a registration rejection message if the second information indicates that registration via the non-3GPP access is preferred; This includes: The registration rejection message includes third information: A method characterized by:
[0713] Clause 8. A method of a non-geographically selected access and mobility management function (AMF) device, the method comprising: Receives Namf_Communication_UEContextTransfer messages from geographically selected AMF devices This includes: The Namf_Communication_UEContextTransfer message includes a registration request message and information indicating an access type set to 3rd Generation Partnership Project (3GPP) access; T...
Claims
1. 1. A method for a user equipment (UE), the method comprising: Initiating a registration procedure for the UE, which has been registered with a non-geographically selected Access and Mobility Management Function (AMF) device, to newly register with a geographically selected AMF device; Sending a registration request message to the geographically selected AMF device. This includes: the registration request message includes a first 5G Globally Unique Temporary Identifier (5G-GUTI), a first Non-Access-Stratum (NAS) container, a second 5G-GUTI, and a second NAS container; The second 5G-GUTI and the second NAS container were used when the UE registered with the non-geographically selected AMF device before the registration procedure was initiated, the first NAS container includes a first integrity-protected registration request message; the first integrity-protected registration request message is a registration request message integrity-protected based on a first NAS security context; the second NAS container includes a second integrity-protected registration request message; The second integrity-protected registration request message is a registration request message that is integrity-protected based on a second NAS security context. A method characterized by:
2. 1. A method for a geographically selected Access and Mobility Management Function (AMF) device, the method comprising: Receiving a registration request message from a user equipment (UE) This includes: the registration request message includes a first 5G Globally Unique Temporary Identifier (5G-GUTI), a first Non-Access-Stratum (NAS) container, a second 5G-GUTI, and a second NAS container; The second 5G-GUTI and the second NAS container were used when the UE registered with a non-geographically selected AMF device before the registration procedure was initiated, the first NAS container includes a first integrity-protected registration request message whose integrity is protected based on a first NAS security context; the second NAS container includes a second integrity-protected registration request message whose integrity is protected based on a second NAS security context; The method comprises: Send the first Namf_Communication_UEContextTransfer message This includes: The first Namf_Communication_UEContextTransfer message includes the first 5G-GUTI and the first integrity-protected registration request message; The method comprises: Receive a first Namf_Communication_UEContextTransfer response message. This includes: The first Namf_Communication_UEContextTransfer response message includes a first user equipment (UE) context associated with the first 5G-GUTI; The method comprises: Send a second Namf_Communication_UEContextTransfer message to the non-geographically selected AMF device. This includes: The second Namf_Communication_UEContextTransfer message includes the second 5G-GUTI and the second integrity-protected registration request message; The method comprises: Receive a second Namf_Communication_UEContextTransfer response message. This includes: The second Namf_Communication_UEContextTransfer response message includes a second UE context associated with a second 5G-GUTI. A method characterized by:
3. A user equipment (UE), means for initiating a registration procedure when the UE, which has been registered in a non-geographically selected Access and Mobility Management Function (AMF) device, newly registers with a geographically selected AMF device; means for sending a registration request message to the geographically selected AMF device; Equipped with the registration request message includes a first 5G Globally Unique Temporary Identifier (5G-GUTI), a first Non-Access-Stratum (NAS) container, a second 5G-GUTI, and a second NAS container; The second 5G-GUTI and the second NAS container were used when the UE registered with the non-geographically selected AMF device before the registration procedure was initiated, the first NAS container includes a first integrity-protected registration request message; the first integrity-protected registration request message is a registration request message integrity-protected based on a first NAS security context; the second NAS container includes a second integrity-protected registration request message; The second integrity-protected registration request message is a registration request message that is integrity-protected based on a second NAS security context. A user device characterized in that:
4. A geographically selected Access and Mobility Management Function (AMF) device, comprising: Means for receiving a registration request message from a user equipment (UE) Equipped with the registration request message includes a first 5G Globally Unique Temporary Identifier (5G-GUTI), a first Non-Access-Stratum (NAS) container, a second 5G-GUTI, and a second NAS container; The second 5G-GUTI and the second NAS container were used when the UE registered with a non-geographically selected AMF device before the registration procedure was initiated, the first NAS container includes a first integrity-protected registration request message whose integrity is protected based on a first NAS security context; the second NAS container includes a second integrity-protected registration request message whose integrity is protected based on a second NAS security context; The device comprises: means for sending a first Namf_Communication_UEContextTransfer message; Equipped with The first Namf_Communication_UEContextTransfer message includes the first 5G-GUTI and the first integrity-protected registration request message; The device comprises: means for receiving a first Namf_Communication_UEContextTransfer response message; Equipped with The first Namf_Communication_UEContextTransfer response message includes a first user equipment (UE) context associated with the first 5G-GUTI; The device comprises: means for sending a second Namf_Communication_UEContextTransfer message to the non-geographically selected AMF device; Equipped with The second Namf_Communication_UEContextTransfer message includes the second 5G-GUTI and the second integrity-protected registration request message; The device comprises: means for receiving a second Namf_Communication_UEContextTransfer response message; Equipped with The second Namf_Communication_UEContextTransfer response message includes a second UE context associated with the second 5G-GUTI. An apparatus characterized in that
Citation Information
Patent Citations
GUTI reallocation for mt-edt
WO2021156347A1