Policy Control Function (PCF) Method and PCF
The UPF method verifies UE session data against URSP rules to enforce policy compliance, preventing unauthorized application usage and ensuring secure traffic routing in UEs, addressing the lack of such mechanisms in 3GPP standards.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-03-17
- Publication Date
- 2026-04-07
AI Technical Summary
Current 3GPP standards lack mechanisms to address the implementation and enforcement of User Equipment (UE) Route Selection Policy (URSP) rules, leading to potential misuse of unauthorized applications in User Equipment (UE).
A User Plane Function (UPF) method verifies whether user data for a UE session matches UE Route Selection Policy (URSP) rules by receiving and analyzing UE ID, Data Network Name (DNN), and Single-Network Slice Selection Assistance Information (S-NSSAI) from a core network node, and transmits the verification result to the core network node.
Enforces policy compliance by preventing unauthorized applications from being used in UEs, ensuring secure and controlled routing of application traffic based on predefined policies.
Smart Images

Figure 0007841612000001 
Figure 0007841612000002 
Figure 0007841612000003
Abstract
Description
Technical Field
[0001] This disclosure relates to a method of a User Plane Function (UPF) and the UPF.
Background Art
[0002] In the SA2#149e plenary session, Non-Patent Document 2 describes the recognition of the 5GC regarding the implementation of URSP in research items related to an important issue, namely, the improvement of 5G UE policies. This agreed-upon important issue includes the following research items. - Whether or not a UE can implement a URSP rule and route application traffic to a PDU session based on the URSP rule provisioned by the 5GC, or whether and how the 5GC can be made to recognize such a case. - Whether there is any action that the 5GS can take after the 5GC recognizes whether a UE implements a URSP rule for a specific application traffic. If so, what action should the 5GC take?
Prior Art Documents
Non-Patent Documents
[0003]
Non-Patent Document 1
Non-Patent Document 2
Non-Patent Document 3
[0004] Current 3GPP standards lack any mechanisms or procedures to address the important issues mentioned above.
[0005] This disclosure provides a solution to this important issue. For example, this disclosure provides a mechanism or procedure relating to this important issue. [Means for solving the problem]
[0006] In aspects of this disclosure, a User Plane Function (UPF) method receives from a core network node at least one of the following: User Equipment ID (UE ID), Data Network Name (DNN), Single-Network Slice Selection Assistance Information (S-NSSAI), and information related to UE Route Selection Policy (URSP) rules. The method verifies whether the user data for a User Equipment (UE) session using the DNN and S-NSSAI matches the information related to the UE Route Selection Policy (URSP) rules. The method transmits the result of the verification to the core network node.
[0007] In aspects of the present disclosure, a User Plane Function (UPF) includes memory and at least one processor, the at least one processor configured to access the memory and to receive at least one of the following from a core network node: User Equipment ID (UE ID), Data Network Name (DNN), Single-Network Slice Selection Assistance Information (S-NSSAI), and UE Route Selection Policy (URSP) rule-related information; to verify whether user data for a User Equipment (UE) session using the DNN and S-NSSAI matches the information related to the UE Route Selection Policy (URSP) rule; and to transmit the result of the verification to the core network node. [Brief explanation of the drawing]
[0008] [Figure 1] Figure 1 is a signaling diagram of a first example of the first embodiment (UE policy confirmed by AMF). [Figure 2] Figure 2 is a signaling diagram of a second example of the first embodiment (UE policy confirmed by SMF). [Figure 3] Figure 3 is a signaling diagram of a third example of the first embodiment (UE policy verified by UPF). [Figure 4] Figure 4 is a signaling diagram of the fourth example of the first embodiment (UE policy (UE trigger) confirmed by AMF for an existing PDU session). [Figure 5]FIG. 5 is a signaling diagram of the fifth example of the first aspect (UE policy (AMF trigger) confirmed by the AMF for an existing PDU session). [Figure 6] FIG. 6 is a diagram showing the system overview. [Figure 7] FIG. 7 is a block diagram showing a user equipment (UE). [Figure 8] FIG. 8 is a block diagram showing a (R) AN node. [Figure 9] FIG. 9 is a diagram showing the system overview of a (R) AN node based on the O-RAN architecture. [Figure 10] FIG. 10 is a block diagram showing a radio unit (RU). [Figure 11] FIG. 11 is a block diagram showing a distributed unit (DU). [Figure 12] FIG. 12 is a block diagram showing a centralized unit (CU). [Figure 13] FIG. 13 is a block diagram showing an access and mobility management function (AMF). [Figure 14] FIG. 14 is a block diagram showing a session management function (SMF). [Figure 15] FIG. 15 is a block diagram showing a user plane function (UPF). [Figure 16] FIG. 16 is a block diagram showing a policy control function (PCF). [Figure 17] FIG. 17 is a block diagram showing an authentication server function (AUSF). [Figure 18]FIG. 18 is a block diagram showing Unified Data Management (UDM). [Figure 19] FIG. 19 shows verification of URSP implementation of a UE by a network.
Embodiments for Carrying Out the Invention
[0009] <Abbreviations> For the purposes of this specification, the abbreviations given in Non-Patent Document 1 and the following ones apply. The abbreviations defined in this specification take precedence over the definitions of the same abbreviations in Non-Patent Document 1, if any.
[0010] 4G-GUTI 4G Globally Unique Temporary UE Identity 5GC 5G Core Network 5GLAN 5G Local Area Network 5GS 5G System 5G-AN 5G Access Network 5G-AN PDB 5G Access Network Packet Delay Budget 5G-EIR 5G-Equipment Identity Register 5G-GUTI 5G Globally Unique Temporary Identifier 5G-BRG 5G Broadband Residential Gateway 5G-CRG 5G Cable Residential Gateway 5G GM 5G Grand Master 5G-RG 5G Residential Gateway 5G-S-TMSI 5G S-Temporary Mobile Subscription Identifier 5G VN 5G Virtual Network 5QI 5G QoS Identifier AF Application Function AMF Access and Mobility Management Function AMF-G Geographically selected Access and Mobility Management Function AMF-NG Non-Geographically selected Access and Mobility Management Function ANDSF Access Network Discovery and Selection Function AS Access Stratum ATSSS Access Traffic Steering, Switching, Splitting ATSSS-LL ATSSS Low-Layer AUSF Authentication Server Function AUTN Authentication token BCCH Broadcast Control Channel BMCA Best Master Clock Algorithm BSF Binding Support Function CAG Closed Access Group CAPIF Common API Framework for 3GPP northbound APIs CHF Charging Function CN PDB Core Network Packet Delay Budget CP Control Plane DAPS Dual Active Protocol Stacks DL Downlink DN Data Network DNAI DN Access Identifier DNN Data Network Name DRX Discontinuous Reception DS-TT Device-side TSN translator ePDG evolved Packet Data Gateway EBI EPS Bearer Identity EPS Evolved Packet System EUI Extended Unique Identifier FAR Forwarding Action Rule FN-BRG Fixed Network Broadband RG FN-CRG Fixed Network Cable RG FN-RG Fixed Network RG FQDN Fully Qualified Domain Name GFBR Guaranteed Flow Bit Rate GMLC Gateway Mobile Location Centre GPSI Generic Public Subscription Identifier GUAMI Globally Unique AMF Identifier GUTI Globally Unique Temporary UE Identity HPLMN Home Public Land Mobile Network HR Home Routed (roaming) IAB Integrated access and backhaul IMEI / TAC IMEI Type Allocation Code IPUPS Inter PLMN UP Security I-SMF Intermediate SMF I-UPF Intermediate UPF LADN Local Area Data Network LBO Local Break Out (roaming) LMF Location Management Function LoA Level of Automation LPP LTE Positioning Protocol LRF Location Retrieval Function MCC Mobile country code MCX Mission Critical Service MDBV Maximum Data Burst Volume MFBR Maximum Flow Bit Rate MICO Mobile Initiated Connection Only MITM Man In the Middle MNC Mobile Network Code MPS Multimedia Priority Service MPTCP Multi-Path TCP Protocol N3IWF Non-3GPP InterWorking Function N3GPP Non-3GPP access N5CW Non-5G-Capable over WLAN NAI Network Access Identifier NAS Non-Access-Stratum NEF Network Exposure Function NF Network Function NGAP Next Generation Application Protocol NID Network identifier NPN Non-Public Network NR New Radio NRF Network Repository Function NSI ID Network Slice Instance Identifier NSSAA Network Slice-Specific Authentication and Authorization NSSAAF Network Slice-Specific Authentication and Authorization Function NSSAI Network Slice Selection Assistance Information NSSF Network Slice Selection Function NSSP Network Slice Selection Policy NSSRG Network Slice Simultaneous Registration Group NW-TT Network-side TSN translator NWDAF Network Data Analytics Function PCF Policy Control Function PCO Protocol Configuration Options PDB Packet Delay Budget PDR Packet Detection Rule PDU Protocol Data Unit PEI Permanent Equipment Identifier PER Packet Error Rate PFD Packet Flow Description PLMN Public Land Mobile Network PNI-NPN Public Network Integrated Non-Public Network PPD Paging Policy Differentiation PPF Paging Proceed Flag PPI Paging Policy Indicator PSA PDU Session Anchor PTP Precision Time Protocol QFI QoS Flow Identifier QoE Quality of Experience RACS Radio Capabilities Signalling optimisation (R)AN (Radio) Access Network RAT Radio Access Technology RG Residential Gateway RIM Remote Interference Management RQA Reflective QoS Attribute RQI Reflective QoS Indication RSN Redundancy Sequence Number SA NR Standalone New Radio SBA Service Based Architecture SBI Service Based Interface SCP Service Communication Proxy SD Slice Differentiator SEAF Security Anchor Functionality SEPP Security Edge Protection Proxy SMF Session Management Function SMSF Short Message Service Function SN Sequence Number SN name Serving Network Name. SNPN Stand-alone Non-Public Network S-NSSAI Single Network Slice Selection Assistance Information SSC Session and Service Continuity SSCMSP Session and Service Continuity Mode Selection Policy SST Slice / Service Type SUCI Subscription Concealed Identifier SUPI Subscription Permanent Identifier SV Software Version TMSI Temporary Mobile Subscriber Identity TNAN Trusted Non-3GPP Access Network TNAP Trusted Non-3GPP Access Point TNGF Trusted Non-3GPP Gateway Function TNL Transport Network Layer TNLA Transport Network Layer Association TSC Time Sensitive Communication TSCAI TSC Assistance Information TSN Time Sensitive Networking TSN GM TSN Grand Master TSP Traffic Steering Policy TT TSN Translator TWIF Trusted WLAN Interworking Function UCMF UE radio Capability Management Function UDM Unified Data Management UDR Unified Data Repository UDSF Unstructured Data Storage Function UE User Equipment UL Uplink UL CL Uplink Classifier UPF User Plane Function UPSI UE Policy Section Identifier URLLC Ultra Reliable Low Latency Communication URRP-AMF UE Reachability Request Parameter for AMF URSP UE Route Selection Policy VID VLAN Identifier VLAN Virtual Local Area Network VPLMN Visited Public Land Mobile Network W-5GAN Wireline 5G Access Network W-5GBAN Wireline BBF Access Network W-5GCAN Wireline 5G Cable Access Network W-AGF Wireline Access Gateway Function
[0011] <Definition> For the purposes of this specification, the terms and definitions given in Non-Patent Document 1, as well as the following, shall apply. In the event that a term is used herein, the definition of that term in Non-Patent Document 1 shall take precedence over that definition.
[0012] <General Overview> Those skilled in the art will understand that the elements in the figures are simplified and do not necessarily have to be drawn to scale. Furthermore, with respect to the structure of the device, one or more components of the device may be represented in the figures by ordinary symbols, and the figures may show only certain details appropriate for understanding aspects of this disclosure, so as not to obscure figures with details that would be readily apparent to those skilled in the art who benefit from the description herein.
[0013] To facilitate understanding of the principles of this disclosure, we will refer here to the embodiments shown in the figures and use specific terminology to describe those principles. Nevertheless, it will be understood that this is not intended to limit the scope of this disclosure. Such modifications and further alterations to the shown systems, as well as such further applications of the principles of this disclosure that a person skilled in the art would ordinarily conceive, should be construed as being within the scope of this disclosure.
[0014] The terms “equipped with,” “possessing,” or any other variations thereof are intended to cover non-exclusive inclusion, so that a process or method comprising a list of steps may include not only those steps but also other steps that are not explicitly enumerated or that are inherent in such a process or method. Similarly, one or more devices, entities, subsystems, elements, structures, or components beginning with “equipped with” does not, unless further restricted, exclude the existence of other devices, subsystems, elements, structures, components, additional devices, additional subsystems, additional elements, additional structures, or additional components. Throughout this specification, where the phrases “in another aspect,” “in another aspect,” and similar terms appear, they may, but may not necessarily, refer to the same aspect.
[0015] Unless otherwise specified, all technical and scientific terms used herein have the same meaning as those generally understood by those skilled in the art to which this disclosure pertains. The systems, methods, and examples provided herein are illustrative and not intended to limit the scope of this disclosure.
[0016] In the following specification and claims, numerous terms are to be defined as having the following meanings: The singular forms "a," "an," and "the" include plural references unless specifically defined in the context.
[0017] Since data is meaningful information and represents values resulting from parameters, the information used herein is associated with data and insights. Furthermore, insights mean an understanding of abstract or concrete concepts. Note that the exemplary system presented here is simplified for the sake of facilitating the explanation of the subject matter of this disclosure and is not intended to limit the scope of this disclosure. Other devices, systems, and configurations may be used in addition to or instead of the system to implement the embodiments disclosed herein, and all such embodiments are assumed to be within the scope of this disclosure.
[0018] Each of the embodiments, and the elements included in each of the embodiments described below, can be implemented independently or in combination with each other. These embodiments include novel features that are distinct from each other. Therefore, these embodiments contribute to achieving objectives or solving different problems, and contribute to obtaining different advantages.
[0019] An exemplary object of this disclosure is to provide a method and apparatus that can solve the above-mentioned problems.
[0020] For example, the Policy Control Function (PCF) provides the UE with a policy for PDU session selection, namely a UE Route Selection Policy (URSP). This policy is used by the UE to determine how to route outgoing traffic from applications within the UE. For example, regarding existing PDU sessions, the UE examines the URSP rules in the UE policy information to determine whether the existing PDU session is reusable.
[0021] However, for example, the current 3GPP specifications (or 3GPP standards) do not contain any solutions that can prevent unapproved applications from being used in UEs.
[0022] A communication device method according to an exemplary aspect of this disclosure receives a policy concerning user equipment (UE). The method receives information from the UE related to an application in the UE. The method verifies whether the information is consistent with the policy. If the information is not consistent with the policy, the method sends a rejection message.
[0023] A user equipment (UE) method according to an exemplary embodiment of the present disclosure transmits a first message, which contains first information relating to an application in the UE. After transmitting the first message, the method receives a second message, which contains second information indicating that the application is rejected. Upon receiving the second message, the method ceases using the application.
[0024] A communication device method according to an exemplary embodiment of the present disclosure receives information indicating that a policy regarding user equipment (UE) and the UE's data need to be verified. After receiving the information, the method verifies whether the data is consistent with the policy. If the data is not consistent with the policy, the method deactivates the communications associated with the data.
[0025] A communication device method according to an exemplary aspect of this disclosure receives a policy for user equipment (UE). The method receives a service request message, which includes an application identifier in the UE. The method checks whether the identifier matches the policy. If the identifier matches the policy, the method sends an approval message. If the identifier does not match the policy, the method sends a rejection message.
[0026] A user equipment (UE) method according to an exemplary embodiment of the present disclosure involves the UE sending a service request message if it has an established PDU session. The service request message includes an identifier for an application in the UE. After sending the service request message, the method receives a first message. If the first message is an acknowledgment message, the method sends data. If the first message is a rejection message, the method stops using the application.
[0027] A communication device method according to an exemplary aspect of the present disclosure receives a policy concerning user equipment (UE). The method sends a request to transmit an application identifier in the UE. The method receives the identifier. The method verifies whether the identifier is consistent with the policy. After verifying whether the identifier is consistent with the policy, the method sends a message. The message includes at least one of information indicating permitted applications and information indicating prohibited applications.
[0028] A user equipment (UE) method according to an exemplary aspect of the present disclosure receives a request to transmit an application identifier in the UE. The method transmits the identifier. After transmitting the identifier, the method receives a message. The message includes at least one of information indicating an authorized application and information indicating an unauthorized application. After receiving the message, the method ceases using the unauthorized application.
[0029] A communication device according to an exemplary aspect of this disclosure includes memory and at least one hardware processor connected to the memory. The at least one hardware processor is configured to receive policies about user equipment (UE). The at least one hardware processor is configured to receive information from the UE related to applications in the UE. The at least one hardware processor is configured to check whether the information is consistent with a policy. The at least one hardware processor is configured to send a rejection message if the information is not consistent with a policy.
[0030] An exemplary user equipment (UE) according to the present disclosure includes memory and at least one hardware processor connected to the memory. The at least one hardware processor is configured to send a first message, which includes first information relating to an application in the UE. After sending the first message, the at least one hardware processor is configured to receive a second message, which includes second information indicating that the application is rejected. If the at least one hardware processor receives the second message, it is configured to stop using the application.
[0031] An exemplary communication device according to the present disclosure includes memory and at least one hardware processor connected to the memory. The at least one hardware processor is configured to receive a policy about user equipment (UE) and information indicating that verification of the UE's data is required. After receiving the information, the at least one hardware processor is configured to verify whether the data is consistent with the policy. If the data is not consistent with the policy, the at least one hardware processor is configured to deactivate the communications associated with the data.
[0032] A communication device according to an exemplary aspect of this disclosure includes memory and at least one hardware processor connected to the memory. The at least one hardware processor is configured to receive policies about user equipment (UE). The at least one hardware processor is configured to receive service request messages. The service request messages include an application identifier in the UE. The at least one hardware processor is configured to check whether the identifier is consistent with a policy. If the identifier is consistent with a policy, the at least one hardware processor is configured to send an approval message. If the identifier is not consistent with a policy, the at least one hardware processor is configured to send a rejection message.
[0033] An exemplary user equipment (UE) in this disclosure includes memory and at least one hardware processor connected to the memory. The at least one hardware processor is configured to send a service request message if the UE has an established PDU session. The service request message includes an identifier for an application in the UE. After sending the service request message, the at least one hardware processor is configured to receive a first message. If the first message is an acknowledgment message, the at least one hardware processor is configured to send data. If the first message is a rejection message, the at least one hardware processor is configured to stop using the application.
[0034] A communication device according to an exemplary aspect of this disclosure includes memory and at least one hardware processor connected to the memory. The at least one hardware processor is configured to receive policies about user equipment (UE). The at least one hardware processor is configured to send requests to transmit application identifiers in the UE. The at least one hardware processor is configured to receive identifiers. The at least one hardware processor is configured to verify whether the identifiers are consistent with the policy. After verifying whether the identifiers are consistent with the policy, the at least one hardware processor is configured to send a message. The message includes at least one of information indicating permitted applications and information indicating prohibited applications.
[0035] An exemplary user equipment (UE) according to the present disclosure includes memory and at least one hardware processor connected to the memory. The at least one hardware processor is configured to receive a request to transmit an application identifier in the UE. The at least one hardware processor is configured to transmit the identifier. After transmitting the identifier, the at least one hardware processor is configured to receive a message. The message includes at least one of information indicating an authorized application and information indicating an unauthorized application. After receiving the message, the at least one hardware processor is configured to stop using the unauthorized application.
[0036] A method of a first device according to an exemplary aspect of this disclosure receives policy information relating to a communication terminal from a second device. The method receives information about an application relating to the communication terminal from the communication terminal. The method verifies whether the information about the application relating to the communication terminal is consistent with the policy information relating to the communication terminal. If the information about the application relating to the communication terminal is not consistent with the policy information relating to the communication terminal, the method sends information relating to rejection to the communication terminal.
[0037] A method of a third device according to an exemplary aspect of the present disclosure stores policy information relating to a communication terminal from a second device. The method receives information about an application relating to the communication terminal from the communication terminal. The method checks whether the information about the application relating to the communication terminal is consistent with the policy information relating to the communication terminal. If the information about the application relating to the communication terminal is not consistent with the policy information relating to the communication terminal, the method transmits information relating to rejection to the first device.
[0038] A method of a fourth device according to an exemplary aspect of the present disclosure stores policy information relating to a communication terminal from a second device. The method receives application information relating to the communication terminal from a third device for session management. The method receives information from the third device for session management indicating that verification of data relating to the communication terminal is required. Based on the information indicating that verification of data relating to the communication terminal is required, the method verifies whether the application information relating to the communication terminal is consistent with policy information relating to the communication terminal. If the application information relating to the communication terminal is not consistent with policy information relating to the communication terminal, the method transmits information relating to rejection.
[0039] A communication terminal method relating to an exemplary aspect of the present disclosure includes sending a service request message to a first device, the first device storing policy information about the communication terminal from a second device, the first device checking whether the information about the application about the communication terminal is consistent with policy information about the communication terminal, and if the information about the application about the communication terminal is not consistent with policy information about the communication terminal, the first device sending information related to rejection to the communication terminal.
[0040] A communication terminal method relating to an exemplary aspect of the present disclosure includes sending a service request message to a first device, the first device storing policy information about the communication terminal from a second device, the first device verifying whether the information about the application about the communication terminal is consistent with policy information about the communication terminal, and if the information about the application about the communication terminal is consistent with policy information about the communication terminal, the first device sending information related to approval to the communication terminal.
[0041] A method of a first device according to an exemplary aspect of this disclosure stores policy information relating to a communication terminal from a second device. The method receives a service request message from the communication terminal containing information about an application relating to the communication terminal. The method verifies whether the information about the application relating to the communication terminal is consistent with policy information relating to the communication terminal. If the information about the application relating to the communication terminal is not consistent with the policy information relating to the communication terminal, the method sends information relating to the rejection to the communication terminal.
[0042] A method of a first device according to an exemplary aspect of the present disclosure stores policy information relating to a communication terminal from a second device. The method receives a service request message from the communication terminal containing information about an application relating to the communication terminal. The method verifies whether the information about the application relating to the communication terminal is consistent with policy information relating to the communication terminal. If the information about the application relating to the communication terminal is consistent with the policy information relating to the communication terminal, the method transmits information relating to approval to the communication terminal.
[0043] A method of a first device according to an exemplary aspect of the present disclosure stores policy information relating to a communication terminal from a second device. The method sends a request message to the communication terminal regarding information about an application relating to the communication terminal. The method receives information about an application relating to the communication terminal from the communication terminal. The method verifies whether the information about the application relating to the communication terminal is consistent with policy information relating to the communication terminal. If the information about the application relating to the communication terminal is not consistent with policy information relating to the communication terminal, the method sends information relating to the rejection to the communication terminal.
[0044] A method of a first device according to an exemplary aspect of the present disclosure stores policy information relating to a communication terminal from a second device. The method sends a request message to the communication terminal regarding information about an application relating to the communication terminal. The method receives information about an application relating to the communication terminal from the communication terminal. The method verifies whether the information about the application relating to the communication terminal is consistent with policy information relating to the communication terminal. If the information about the application relating to the communication terminal is consistent with policy information relating to the communication terminal, the method sends information relating to approval to the communication terminal.
[0045] <First aspect> This embodiment discloses, for example, a method for network verification regarding whether the UE correctly applies URSP rules provisioned by the core network.
[0046] <First example of the first aspect> A first example of the first aspect discloses how PCF73 sends a UE policy to AMF70 when AMF70 establishes a UE policy association with PCF73. AMF70 then checks the request PDU session from UE3 to see if the request from UE3 is consistent with the latest UE policy provisioned to UE3 by PCF73.
[0047] A detailed process of the first example of the first embodiment is described below with reference to Figure 1.
[0048] Step 1: UE3 performs the registration procedure as defined in Section 4.2.2.2.2 of Non-Patent Document 4.
[0049] Step 2: During or after the registration procedure, UE policy establishment by the PCF procedure is performed by PCF73. This process may be carried out in accordance with 4.16.11 of Non-Patent Literature 4.
[0050] Step 3: PCF73 decides to update the UE policy or a portion of the UE policy, for example, the UE policy rules that have been updated since the last UE update related to the UE policy. For example, PCF73 may decide to update the UE policy based on the local configuration in PCF73. For example, if a new UE policy is created and the previous UE policy needs to be updated by the new UE policy, PCF73 may decide to update the UE policy. The new UE policy may be created by PCF73.
[0051] Step 4: PCF73 sends a Namf_Communication_N1N2MessageTransfer message or any other existing or new message to AMF70 via the interface between PCF73 and AMF70, and PCF73 includes the UE ID, UE policy container, and UE policy as separate parameters in the message. The UE policy may contain the same data as the data in the UE policy container. The UE ID may be an identifier for UE3. At least one of the UE policy container and the UE policy may be referred to as UE policy information or UE policy rule. If PCF73 decides to update the UE policy or part of the UE policy, PCF73 may send a Namf_Communication_N1N2MessageTransfer message. PCF73 may periodically send Namf_Communication_N1N2MessageTransfer messages.
[0052] Step 5: If AMF70 receives a Namf_Communication_N1N2MessageTransfer message from PCF73 in Step 4, or any other message from PCF73 conveying UE policy information, AMF70 stores or updates the UE context with the UE policy received from PCF73. The UE policy may include NSSP, DNN selection, Time Window and Location criteria, as defined in the URSP rules in Non-Patent Document 5, as well as other information.
[0053] Step 6: Upon receiving the Namf_Communication_N1N2MessageTransfer message from PCF73 in Step 4, AMF70 sends a UE configuration update command message containing the UE policy container to UE3. The UE policy container in Step 6 may be the same as the one received in Step 4. Step 5 may be performed after Step 6.
[0054] Step 7: At some point, UE3 sends a UL NAS transport message, a service request message, or any other NAS message to AMF70, which includes a PDU session ID, an App_Id, a DNN, an S-NSSAI, and a NAS container containing a PDU session establishment request to establish a PDU session, in order to establish a new PDU session, reuse an already established PDU session, or modify an already established PDU session. In this disclosure, the App_Id may be used to identify an application running in the OS of UE3. In this disclosure, the App_Id may be used to identify an application running in UE3. In this disclosure, the DNN and S-NSSAI in the UL NAS transport message may be a DNN and S-NSSAI requested for use by UE3 or an application in UE3.
[0055] Step 8: Upon receiving a UL NAS transport message from UE3, AMF70 checks whether at least one of the information provided by UE3, such as App_Id, S-NSSAI, DNN, and other information, is consistent with or matches a UE policy rule stored in the UE context for UE3 within AMF70. The UE policy rule stored in the UE context for UE3 within AMF70 may be the UE policy stored in Step 4.
[0056] If AMF70 is checking whether at least one of the App_Id provided by UE3 is consistent with a UE policy, AMF70 may check the UE policy or URSP rule corresponding to the PDU session ID received in step 7.
[0057] Step 9: If AMF70 finds that at least one of the parameters received in the UL NAS transport message or any other NAS message is inconsistent with the UE policy rules for UE3 (for example, if the received application identifier (i.e., App_Id) does not match any root descriptor rule defined in the NSSP corresponding to the application identifier, or if the received App_Id does not match any application identifier in the URSP rule, or if the received App_Id does not match any application identifier in the "Application Descriptor" of the URSP rule), AMF70 sends a DL NAS transport message or any other NAS message to UE3, and AMF70 includes a reject cause parameter in the message. Otherwise (for example, if AMF70 finds that at least one of the parameters received in the UL NAS transport message or any other NAS message is inconsistent with the UE policy rules for UE3), AMF70 continues the PDU session establishment procedure in accordance with Section 4.3.2.2.1 of TS23.502. If a PDU session establishment request is rejected, or if AMF70 finds that at least one of the parameters received in the UL NAS transport message or any other NAS message is inconsistent with the UE policy rules for UE3, the rejection cause parameter in the NAS message to UE3, the DL NAS transport message, or any other NAS message may have one or more values from the rejection causes listed below. These may be 5GMM causes. The rejection cause may correspond to the App_Id received from UE3 in step 7.
[0058] -In accordance with the URSP rules in the UE context for UE3 in AMF70, an unauthorized S-NSSAI, an application in an unauthorized S-NSSAI (i.e., an application with an App_Id is not an authorized service in that S-NSSAI), or any other indication of the reason for denial, to indicate to UE3 that an application in UE3 requesting a service in a particular S-NSSAI is not an authorized service in that S-NSSAI. If UE3 receives the reason for denial "unauthorized S-NSSAI", UE3 will not allow the denied application in UE3 to start another service in the S-NSSAI where the service was denied. Alternatively, if UE3 receives the denial cause "Unauthorized S-NSSAI", UE3 will not allow the denied application in UE3 to start another service in the S-NSSAI where the service was denied until the S-NSSAI selection rule (e.g., NSSP) in the UE3 policy is updated and the updated S-NSSAI selection policy (e.g., NSSP) allows the application to trigger a service in that S-NSSAI. AMF70 may also include an application-specific S-NSSAI backoff timer (e.g., App_Id, S-NSSAI, backoff timer, or any other indication of a backoff timer applicable only to a specific application in a particular S-NSSAI) in the DL NAS transport message. In this case, UE3 will remember the received application-specific S-NSSAI backoff timer and will not allow a service from the denied application in the S-NSSAI for the duration of the backoff timer for that application in the S-NSSAI. The backoff timer may be referred to as the backoff timer value in this disclosure.
[0059] -In accordance with the URSP rules in the UE context for UE3 in AMF70, an unauthorized DNN, an application in an unauthorized DNN (i.e., an application with an App_Id is not an authorized service from the DNN), or any other indication of the denial cause to indicate to UE3 that an application in UE3 requesting a service in a particular DNN is not an authorized service in that DNN. When UE3 receives the denial cause "Unauthorized DNN", UE3 will not allow the denied application in UE3 to start another service in the DNN where the service was denied. Alternatively, when UE3 receives the denial cause "Unauthorized DNN", UE3 will not allow the denied application in UE3 to start another service in the DNN where the service was denied until the DNN selector policy in the UE policy in UE3 (e.g., "DNN Selection" in the "Route Selection Descriptor" of the URSP rule) is updated and the updated DNN selector policy allows the application to trigger a service in that DNN. The AMF70 may also include an application-specific DNN backoff timer (e.g., App_Id, DNN, backoff timer, or any other indication of a backoff timer applicable only to a specific application in a particular DNN) in the DL NAS transport message. In this case, the UE3 remembers the received application-specific DNN backoff timer and does not allow service from the denied application in that DNN for the duration of the DNN backoff timer.
[0060] -In accordance with the URSP rules in the UE context for UE3 in AMF70, any other indication regarding an S-NSSAI outside the time window (i.e., an application with App_Id is not currently a permitted service in the S-NSSAI) or a reason for denial to indicate to UE3 that an application in UE3 requesting a service in a particular S-NSSAI is not currently a permitted service in that S-NSSAI (i.e., the service is requested outside the permitted time window for the service in the S-NSSAI). If UE3 receives the reason for denial "S-NSSAI outside the permitted time window", UE3 will not allow the denied application in UE3 to start another service in the S-NSSAI where the service was denied. Alternatively, if UE3 receives the rejection cause "S-NSSAI outside the permitted time window," UE3 will not allow the rejected application in UE3 to start another service in the S-NSSAI where the service was denied until the S-NSSAI selective time window rule in the UE policy in UE3 (e.g., "Time Window" in the "Root Select Descriptor" of the URSP rule or the "Root Select Descriptor" for the S-NSSAI in the URSP rule) is updated, and the updated S-NSSAI selective time window policy then allows the application to trigger a service in that S-NSSAI. AMF70 may also include an application-specific S-NSSAI backoff timer (e.g., App_Id, S-NSSAI, backoff timer, or any other indication of a backoff timer applicable only to a specific application in a particular S-NSSAI) in the DL NAS transport message. In this case, UE3 stores the S-NSSAI backoff timer for each received application, and UE3 does not allow service from the rejected application in S-NSSAI for the duration of the backoff timer for that application in S-NSSAI.The AMF70 can calculate a value for the S-NSSAI backoff timer so that the S-NSSAI backoff timer for a rejected application expires within the permitted time window for that S-NSSAI.
[0061] -In accordance with the URSP rules in the UE context for UE3 in AMF70, any other indication regarding a DNN outside the time window (i.e., an application with App_Id is not currently a permitted service in the DNN) or a reason for denial to indicate to UE3 that an application in UE3 requesting a service in a particular DNN is not currently a permitted service in that DNN (i.e., the service is being requested outside the permitted time window for services in the DNN). If UE3 receives the reason for denial "DNN outside the permitted time window", UE3 will not allow the denied application in UE3 to start another service in the DNN where the service was denied. Alternatively, if UE3 receives the denial cause “DNN outside the permitted time window”, UE3 will not allow the denied application in UE3 to initiate another service in the DNN where the service was denied until the DNN selection time window rule in the UE policy in UE3 (e.g., “Time Window” in the “Root Selection Descriptor” of the URSP rule or the “Root Selection Descriptor” for the DNN in the URSP rule) is updated, and the updated DNN selection time window policy then allows the application to trigger a service in that DNN. AMF70 may also include an application-specific DNN backoff timer in the DL NAS transport message (e.g., App_Id, DNN, backoff timer, or any other indication of a backoff timer applicable only to a specific application in a particular DNN). In this case, UE3 will remember the received application-specific DNN backoff timer and will not allow a service from the denied application in the DNN for the duration of the backoff timer for that application in the DNN. The AMF70 can calculate a value for the DNN backoff timer so that the DNN backoff timer for a rejected application expires within the permitted time window for that DNN.
[0062] -In accordance with the URSP rules in the UE context for UE3 in AMF70, any other indication regarding an out-of-location S-NSSAI (i.e., an application with App_Id is not an authorized service for S-NSSAI at this location or area) or a reason for denial to indicate to UE3 that an application in UE3 requesting a service at a particular S-NSSAI is not an authorized service at that S-NSSAI at its current location (i.e., the service is requested out of the authorized location for the service in the S-NSSAI). If UE3 receives the reason for denial "out-of-location S-NSSAI", UE3 will not allow the denied application in UE3 to initiate another service at the S-NSSAI where the service was denied. Alternatively, if UE3 receives the rejection reason “Out of Location S-NSSAI”, UE3 will not allow the rejected application in UE3 to start another service in the S-NSSAI where the service was rejected until UE3 re-selects a different cell, UE3 moves to a different Tracking Area (TA), a different Registration Area (RA), or a different PLMN, or the S-NSSAI selection location rule in the UE policy in UE3 (for example, the “Root Selection Descriptor” in the URSP rule or the “Location Criteria” in the “Root Selection Descriptor” for the S-NSSAI in the URSP rule) is updated, and the updated S-NSSAI selection location policy then allows the application to trigger a service in that S-NSSAI. The AMF70 may also include application-specific S-NSSAI backoff timers in DL NAS transport messages (e.g., App_Id_S-NSSAI, backoff timer, or any other indication of a backoff timer applicable only to a specific application in a particular S-NSSAI).In this case, unless the UE re-selects a different cell, or the UE moves to a different TA, a different RA, or a different PLMN, UE3 will remember the S-NSSAI backoff timer for each received application, and UE3 will not allow service from the rejected application in S-NSSAI for the duration of the backoff timer for that application in S-NSSAI.
[0063] -In accordance with the URSP rules in the UE context for UE3 in AMF70, any other indication of an out-of-location DNN (i.e., an application with App_Id is not a permitted service in the DNN at this location or area) or a reason for denial to indicate to UE3 that an application in UE3 requesting a service in a particular DNN is not a permitted service in that DNN at its current location or area (i.e., the service is requested out of the permitted location for the service in the DNN). If UE3 receives the reason for denial "out-of-location DNN", UE3 will not allow the denied application in UE3 to initiate another service in the DNN where the service was denied. Alternatively, if UE3 receives the rejection cause "Out of Location DNN", UE3 will not allow the rejected application in UE3 to start another service in the DNN where the service was denied until UE3 re-selects a different cell, moves to a different Tracking Area (TA), a different Registration Area (RA), or a different PLMN, or updates the DNN selection location rule in the UE policy in UE3 (e.g., the "Route Selection Descriptor" in the URSP rule or the "Location Criteria" in the "Route Selection Descriptor" for the DNN in the URSP rule) and the updated DNN selection location policy allows the application to trigger a service in that DNN. AMF70 may also include an application-specific DNN backoff timer (e.g., App_Id, DNN, backoff timer, or any other indication of a backoff timer applicable only to a specific application in a particular DNN) in the DL NAS transport message. In this case, unless the UE re-selects a different cell, or moves to a different TA, another RA, or another PLMN, UE3 remembers the DNN backoff timer for each received application, and UE3 does not allow service from a rejected application in the DNN for the duration of the backoff timer for that application in the DNN.
[0064] The reason for rejection can be described as information indicating that the application identified by the App_Id is being rejected.
[0065] The rejection reason can be described as information indicating that an application in UE3 has been rejected.
[0066] For example, if UE3 receives a rejection reason, UE3 may stop using the application identified by the App_Id sent in step 7.
[0067] For example, if UE3 receives a rejection reason, UE3 may stop using the application.
[0068] The reason for rejection may be described as information requesting that the use of the application identified by the App_Id sent in step 7 be stopped.
[0069] The reason for rejection could be described as information requesting that the application cease using UE3.
[0070] For example, AMF70 may check whether the current time coincides with the "time window" in the "route selection descriptor" defined in the URSP rule. If AMF70 determines that the current time does not coincide with the "time window" (for example, if AMF70 determines that the current time is not within the period or time window defined by the "time window"), AMF70 may send a DL NAS transport message containing a rejection cause set to "S-NSSAI outside time window" or "DNN outside time window".
[0071] When the AMF70 checks the "time window," it uses the time data provided by the Network Time Protocol (NTP), as defined in Non-Patent Document 6, as the current time.
[0072] For example, AMF70 may check whether the current location of UE3 matches the "location criterion" in the "route selection descriptor" defined in the URSP rule. If AMF70 determines that the current location of UE3 does not match the "location criterion" (for example, if AMF70 determines that the current location of UE3 does not match the location or area defined by the "location criterion," or that the current location of UE3 is not included in the location or area defined by the "location criterion"), AMF70 may send a DL NAS transport message containing a rejection cause set to "S-NSSAI out of location" or "DNN out of location."
[0073] When AMF70 determines the location of UE3 (for example, the location of UE3), AMF70 uses the user location information in the INITIAL UE message from RAN5 when the UL NAS transport message is transmitted from RAN5 to AMF70, in accordance with Non-Patent Document 7.
[0074] For example, AMF70 may check whether the S-NSSAI received in step 7 matches the S-NSSAI in "Network Slice Selection". If AMF70 determines that the S-NSSAI received in step 7 does not match the S-NSSAI in "Network Slice Selection", AMF70 may send a DL NAS transport message containing a rejection cause set to "Unauthorized S-NSSAI" or "Application in Unauthorized S-NSSAI".
[0075] For example, AMF70 may check whether the DNN received in step 7 matches the DNN in the URSP rule (for example, the "DNN selection" in the "route selection descriptor" defined in the URSP rule). If AMF70 determines that the DNN received in step 7 does not match the DNN in the URSP rule, AMF70 may send a DL NAS transport message containing a rejection cause set to "unauthorized DNN" or "application in unauthorized DNN".
[0076] The AMF70 may check whether at least one of the following matches the corresponding parameter in the URSP rule as described above: App_Id, DNN, S-NSSAI, current time, and current UE3 location. If the AMF70 determines that at least one of the following does not match the corresponding parameter in the URSP rule, the AMF70 may send a DL NAS transport message containing the rejection reason as described above.
[0077] According to a first example of the first embodiment, for example, 5GC (e.g., AMF) can recognize whether or not the UE enforces the URSP rule. In addition, according to a first example of the first embodiment, for example, actions that 5GS (e.g., AMF) can take after 5GC recognizes whether the UE enforces the URSP rule can be provided. Furthermore, according to a first example of the first embodiment, for example, a solution can be provided that can prevent unauthorized applications in the UE.
[0078] For example, a first device corresponding to AMF70 receives policy information about a communication terminal from a second device corresponding to PCF73. The first device receives application information about the communication terminal from the communication terminal corresponding to UE3. The first device checks whether the application information about the communication terminal is consistent with the policy information about the communication terminal. If the application information about the communication terminal is not consistent with the policy information about the communication terminal, the first device sends information related to rejection to the communication terminal.
[0079] <Modified form 1 of the first example of the first aspect> In step 2, PCF73 may send the UE policy to AMF70 by an Npcf_UEPolicyControl creation response message. The UE policy may be the same as the UE policy that PCF73 provides to UE3 in the UE policy container during the UE configuration update procedure for transparent UE policy delivery procedures as defined in section 4.2.4.3 of Non-Patent Literature 4.
[0080] <Modified form 2 of the first example of the first embodiment> In step 7, the UL NAS transport message may be replaced with a service request message. In this case, the UL NAS transport message in step 7 is replaced with a service request message.
[0081] In addition, the DL NAS transport message in step 9 is replaced with a denial-of-service message.
[0082] Service request messages may contain the same information as UL NAS transport messages.
[0083] Denial of Service messages may contain the same information as DL NAS transport messages.
[0084] <Modified form 3 of the first example of the first embodiment> In step 4, instead of including the entire UE policy in the message to AMF70, PCF73 may include only the UE policy for UE3 related to the PDU session establishment parameters provided to AMF70 by UE3 in step 7 in the message to AMF70.
[0085] Therefore, PCF73 may include in its message to AMF70 the following: S-NSSAI selection policy for UE3 (e.g., NSSP), DNN selection policy for UE3 (e.g., "DNN selection" in the "Route selection descriptor"), Time windows parameter for UE3 that defines the time window in which services in S-NSSAI or DNN are permitted (e.g., "Time window" in the "Route selection descriptor"), and Location parameter for UE3 that defines the location in which services or access in S-NSSAI or DNN are permitted (e.g., "Location criteria" in the "Route selection descriptor"). The DNN selection policy may be referred to as a DNN selection rule. The Time windows parameter may be referred to as a permitted Time windows parameter. The Location parameter may be referred to as a permitted Location. The Location parameter may be represented as cell identifier information, a list of cell identifier information, Tracking Area (TA) identifier information, a list of TA identifier information, or registration area identifier information. The AMF70 stores or updates these parameters provided by the PCF73 within the UE context in the AMF70. In step 8, the AMF70 verifies whether at least one of the S-NSSAI and DNN provided by the UE3 for the application having the App_Id parameter in the NAS message to the AMF70 in step 7 matches at least one of the S-NSSAI selection rule, DNN selection rule, allowed time window, and allowed position for the application having the App_ID from the UE context in the AMF70. If at least one of these rules does not match, the AMF70 rejects the NAS message from the UE3 using a rejection cause as described in step 9 in Figure 1.
[0086] For example, PCF73 may obtain information about PDU sessions that UE3 may establish from other network nodes. For example, PCF73 may store information about PDU sessions that UE3 may have established in advance. Information about PDU sessions that UE3 may establish may include an S-NSSAI selection policy (NSSP) for UE3, a DNN selection policy for UE3, a time window parameter for UE3 that defines the time window in which services in S-NSSAI or DNN are permitted, and a location parameter for UE3 that defines the location in which services or access in S-NSSAI or DNN are permitted. Based on the information about PDU sessions that UE3 may establish, PCF73 may determine the content of the message in step 4.
[0087] <Second example of the first aspect> A second example of the first aspect discloses how PCF73 sends a UE policy to SMF71 via AMF70 when PDU session establishment is requested by UE3. SMF71 then verifies the requested PDU session from UE3 in relation to whether the request from UE3 is consistent with the UE policy.
[0088] A detailed process of a second example of the first embodiment is described below with reference to Figure 2.
[0089] Step 1 is the same as steps 1-6 in the first example of the first embodiment.
[0090] Step 2: The UE policy, including the URSP, is provided to AMF70 by PCF73 as specified in steps 4 and 5 of the first example of the first aspect. If AMF70 has already received the UE policy from PCF73 in step 1, step 2 may be skipped.
[0091] Step 3: At some point, UE3 sends a UL NAS transport message, a service request message, or any other NAS message to AMF70, which includes the PDU session ID, App_Id, DNN, S-NSSAI, and a NAS container containing a PDU session establishment request to establish a PDU session, in order to establish a new PDU session, reuse an already established PDU session, or modify an already established PDU session.
[0092] Step 4: Upon receiving the UL NAS transport message from UE3, AMF70 sends an Nsmf_PDUSession_CreateSMContext request message to SMF71 containing the PDU session ID, App_Id, DNN, S-NSSAI, UE policy, and an SM NAS container containing the PDU session establishment request message. The Nsmf_PDUSession_CreateSMContext request message may contain location information. The UE policy parameter (or UE policy) is entered by AMF70 from the UE context of UE3. The UE policy may be one received from PCF73 in Step 1 or Step 2. Location information is entered by AMF70 from user location information received in the INITIAL UE message from RAN5. Location information may indicate the current location of UE3. AMF70 may use user location information in the INITIAL UE MESSAGE from RAN5 as location information when the UL NAS transport message is transmitted from RAN5 to AMF70, according to Non-Patent Literature 7.
[0093] Step 5: Upon receiving the Nsmf_PDUSession_CreateSMContext request message from AMF70, SMF71 verifies whether at least one of the information provided by AMF70, such as App_Id, S-NSSAI, DNN, and other information, is consistent with the UE policy received from AMF70 (for example, SMF71 verifies whether the received application identifier (i.e., App_Id) matches any root descriptor rule defined in the NSSP corresponding to the application identifier, whether the received App_Id matches any application identifier in the URSP rule, or whether the received App_Id matches any application identifier in the "application descriptor" of the URSP rule).
[0094] If SMF71 is checking whether at least one of the App_Id provided by AMF70 is consistent with the UE policy, SMF71 may check the UE policy or URSP rule corresponding to the PDU session ID received in step 4.
[0095] Step 6: If SMF71 finds that at least one of the parameters received in the Nsmf_PDUSession_CreateSMContext request message is inconsistent with the UE policy (for example, if the received application identity (i.e., the received App_Id) does not match any root descriptor rule defined in the NSSP corresponding to the application identity, or if the received App_Id does not match any application identity in the URSP rule, or if the received App_Id does not match any application identity in the "application descriptor" of the URSP rule), SMF71 sends an Nsmf_PDUSession_CreateSMContext response message to AMF70 that includes a cause parameter. Otherwise (for example, if SMF71 finds that at least one of the parameters received in the Nsmf_PDUSession_CreateSMContext request message is inconsistent with the UE policy), SMF71 continues the PDU session establishment procedure in accordance with Section 4.3.2.2.1 of TS23.502. If the PDU session establishment request is rejected by SMF71, or if SMF71 finds that at least one of the parameters received in the Nsmf_PDUSession_CreateSMContext request message is inconsistent with the UE policy, the cause parameter included in the Nsmf_PDUSession_CreateSMContext response message to AMF70 may have one or more values from the causes listed below. These can be any SM cause. The cause parameter may correspond to the App_Id received from UE3 in step 3.
[0096] -In accordance with the URSP rules in SMF71, an unauthorized S-NSSAI, an application in an unauthorized S-NSSAI (i.e., an application with an App_Id is not an authorized service in that S-NSSAI), or any other indication of the denial cause to indicate to UE3 that an application in UE3 requesting a service in a particular S-NSSAI is not an authorized service in that S-NSSAI. When UE3 receives the denial cause "Unauthorized S-NSSAI", UE3 will not allow the denied application in UE3 to start another service in the S-NSSAI where the service was denied. Alternatively, when UE3 receives the denial cause "Unauthorized S-NSSAI", UE3 will not allow the denied application in UE3 to start another service in the S-NSSAI where the service was denied until the S-NSSAI selection rule in UE3's UE policy (e.g., NSSP) is updated and the updated S-NSSAI selection policy (e.g., NSSP) allows the application to trigger a service in that S-NSSAI. SMF71 may also include an application-specific S-NSSAI backoff timer (e.g., App_Id, S-NSSAI, backoff timer, or any other indication of a backoff timer applicable only to a specific application in a particular S-NSSAI) in the Nsmf_PDUSession_CreateSMContext response message. In this case, UE3 will remember the received application-specific S-NSSAI backoff timer and will not allow service from the denied application in the S-NSSAI for the duration of the backoff timer for that application in the S-NSSAI.
[0097] -In accordance with the URSP rules in SMF71, an unauthorized DNN, an application in an unauthorized DNN (i.e., an application with an App_Id is not an authorized service from the DNN), or any other indication of the denial cause to indicate to UE3 that an application in UE3 requesting a service in a particular DNN is not an authorized service in that DNN. When UE3 receives the denial cause "Unauthorized DNN", UE3 will not allow the denied application in UE3 to start another service in the DNN where the service was denied. Alternatively, when UE3 receives the denial cause "Unauthorized DNN", UE3 will not allow the denied application in UE3 to start another service in the DNN where the service was denied until the DNN selector policy in the UE3 policy (e.g., "DNN select" in the "Root select descriptor" of the URSP rule) is updated and the updated DNN selector policy allows the application to trigger a service in that DNN. SMF71 may also include an application-specific DNN backoff timer (e.g., App_Id, DNN, backoff timer, or any other indication of a backoff timer applicable only to a specific application in a particular DNN) in the Nsmf_PDUSession_CreateSMContext response message. In this case, UE3 remembers the received application-specific DNN backoff timer and does not allow services from the denied application in that DNN for the duration of the DNN backoff timer.
[0098] - Any other indication regarding an S-NSSAI outside the time window (i.e., an application with App_Id is not currently a permitted service in the S-NSSAI) or a reason for denial, in accordance with the URSP rules in SMF71, to indicate to UE3 that an application in UE3 requesting a service in a particular S-NSSAI is not currently a permitted service in that S-NSSAI (i.e., the service is requested outside the permitted time window for services in the S-NSSAI). If UE3 receives the reason for denial "S-NSSAI outside the permitted time window", UE3 will not allow the denied application in UE3 to start another service in the S-NSSAI where the service was denied. Alternatively, if UE3 receives the rejection cause "S-NSSAI outside the permitted time window," UE3 will not allow the rejected application in UE3 to start another service in the S-NSSAI where the service was denied until the S-NSSAI selective time window rule in the UE policy in UE3 (e.g., "Time Window" in the "Root Select Descriptor" of the URSP rule or the "Root Select Descriptor" for the S-NSSAI in the URSP rule) is updated, and the updated S-NSSAI selective time window policy then allows the application to trigger a service in that S-NSSAI. SMF71 may also include an application-specific S-NSSAI backoff timer (e.g., App_Id, DNN, backoff timer, or any other indication of a backoff timer applicable only to a specific application in a particular S-NSSAI) in the Nsmf_PDUSession_CreateSMContext response message. In this case, UE3 stores the S-NSSAI backoff timer for each received application, and UE3 does not allow service from the rejected application in S-NSSAI for the duration of the backoff timer for that application in S-NSSAI.The SMF71 can calculate a value for the S-NSSAI backoff timer so that the S-NSSAI backoff timer for a rejected application expires within the permitted time window for that S-NSSAI.
[0099] - Any other indication of a DNN outside the time window (i.e., an application with App_Id is not currently a permitted service in the DNN) or a reason for denial, in accordance with the URSP rules in SMF71, to indicate to UE3 that an application in UE3 requesting a service in a particular DNN is not currently a permitted service in that DNN (i.e., the service is being requested outside the permitted time window for services in the DNN). If UE3 receives the reason for denial "DNN outside the permitted time window", UE3 will not allow the denied application in UE3 to start another service in the DNN where the service was denied. Alternatively, if UE3 receives the denial cause “DNN outside the permitted time window”, UE3 will not allow the denied application in UE3 to initiate another service in the DNN where the service was denied until the DNN selection time window rule in the UE policy in UE3 (e.g., “Route Selection Descriptor” in the URSP rule or “Time Window” in the “Route Selection Descriptor” for the DNN in the URSP rule) is updated, and the updated DNN selection time window policy then allows the application to trigger a service in that DNN. SMF71 may also include an application-specific DNN backoff timer (e.g., App_Id, DNN, Backoff Timer, or any other indication of a backoff timer applicable only to a specific application in a particular DNN) in the Nsmf_PDUSession_CreateSMContext response message. In this case, UE3 will remember the received application-specific DNN backoff timer and will not allow a service from the denied application in the DNN for the duration of the backoff timer for that application in the DNN. The SMF71 can calculate a value for the DNN backoff timer so that the DNN backoff timer for a rejected application expires within the permitted time window for that DNN.
[0100] - Any other indication of an out-of-place S-NSSAI (i.e., an application with App_Id is not an authorized service for the S-NSSAI at this location) or a reason for denial, in accordance with the URSP rules in SMF71, to indicate to UE3 that an application in UE3 requesting a service at a particular S-NSSAI is not an authorized service at that S-NSSAI at its current location (i.e., the service is requested out of the authorized location for the service in the S-NSSAI). When UE3 receives the reason for denial "out-of-place S-NSSAI", UE3 does not allow the denied application in UE3 to initiate another service at the S-NSSAI where the service was denied. Alternatively, if UE3 receives the rejection reason “Out of Location S-NSSAI”, UE3 will not allow the rejected application in UE3 to start another service in the S-NSSAI where the service was rejected until UE3 re-selects a different cell, UE3 moves to a different Tracking Area (TA), a different Registration Area (RA), or a different PLMN, or the S-NSSAI selection location rule in the UE policy in UE3 (for example, the “Root Selection Descriptor” in the URSP rule or the “Location Criteria” in the “Root Selection Descriptor” for the S-NSSAI in the URSP rule) is updated, and the updated S-NSSAI selection location policy then allows the application to trigger a service in that S-NSSAI. SMF71 may also include application-specific S-NSSAI backoff timers (e.g., App_Id, DNN, backoff timer, or any other indication of a backoff timer applicable only to a specific application in a particular S-NSSAI) in the Nsmf_PDUSession_CreateSMContext response message.In this case, unless the UE re-selects a different cell, or the UE moves to a different TA, a different RA, or a different PLMN, UE3 will remember the S-NSSAI backoff timer for each received application, and UE3 will not allow service from the rejected application in S-NSSAI for the duration of the backoff timer for that application (in S-NSSAI).
[0101] - Any other indication of an out-of-location DNN (i.e., an application with App_Id is not a service permitted in the DNN at this location) or a rejection cause to indicate to UE3 that an application in UE3 requesting a service in a particular DNN is not a permitted service in that DNN at its current location (i.e., the service is requested out of the permitted location for the service in the DNN), in accordance with the URSP rules in SMF71. When UE3 receives the rejection cause "Out-of-location DNN", UE3 does not allow the rejected application in UE3 to initiate another service in the DNN where the service was denied. Alternatively, if UE3 receives the rejection reason “Out of Location DNN”, UE3 will not allow the rejected application in UE3 to start another service in the DNN where the service was denied until UE3 re-selects a different cell, UE3 moves to a different Tracking Area (TA), a different Registration Area (RA), or a different PLMN, or the DNN selection location rule in the UE policy in UE3 (e.g., the “Route Selection Descriptor” in the URSP rule or the “Location Criteria” in the “Route Selection Descriptor” for the DNN in the URSP rule) is updated, and the updated DNN selection location policy then allows the application to trigger a service in that DNN. SMF71 may also include an application-specific DNN backoff timer (e.g., App_Id, DNN, backoff timer, or any other indication of a backoff timer applicable only to a specific application in a particular DNN) in the Nsmf_PDUSession_CreateSMContext response message. In this case, unless the UE re-selects a different cell, or the UE moves to a different TA, a different RA, or a different PLMN, UE3 remembers the DNN backoff timer for each received application, and UE3 does not allow service from the rejected application (in the DNN) for the duration of the backoff timer for that application in the DNN.
[0102] For example, SMF71 may check whether the current time coincides with the "time window" in the "route selection descriptor" defined in the URSP rule. If SMF71 determines that the current time does not coincide with the "time window" (for example, if SMF71 determines that the current time is not within the period or time window defined by the "time window"), SMF71 may send a DL NAS transport message containing a rejection cause set to "S-NSSAI outside the time window" or "DNN outside the time window".
[0103] When SMF71 checks the "time window," it uses the time data provided by the Network Time Protocol (NTP), as defined in Non-Patent Document 6, as the current time.
[0104] For example, SMF71 may check whether the current location of UE3 matches the "location criterion" in the "route selection descriptor" defined in the URSP rule. If SMF71 determines that the current location of UE3 does not match the "location criterion" (for example, if SMF71 determines that the current location of UE3 does not match the location or area defined by the "location criterion," or that the current location of UE3 is not included in the location or area defined by the "location criterion"), SMF71 may send a DL NAS transport message containing a rejection cause set to "S-NSSAI out of location" or "DNN out of location."
[0105] When SMF71 checks the location of UE3 (for example, the location of US3), SMF71 uses the user location information received from AMF70 in the Nsmf_PDUSession_CreateSMContext request message.
[0106] Step 7: Upon receiving the Nsmf_PDUSession_CreateSMContext response message from SMF71, AMF70 sends a DL NAS transport message to UE3 containing an SM NAS container with a PDU session rejection message that has a causal parameter. If UE3 receives the causal parameter, UE3 may take action based on the causal parameter as mentioned in Step 6.
[0107] SMF71 may check whether at least one of the App_Id, DNN, S-NSSAI, current time, and current UE3 location matches the corresponding parameter in the URSP rule, similar to AMF70 in the first example of the first embodiment. If SMF71 determines that at least one of the App_Id, DNN, S-NSSAI, current time, and current UE3 location does not match the corresponding parameter in the URSP rule, SMF71 may send a rejection reason via AMF70 as described above.
[0108] For example, a third device corresponding to SMF71 stores policy information about a communication terminal from the second device. For example, the communication terminal corresponds to UE3. For example, the second device corresponds to PCF73. The third device receives application information about the communication terminal from the communication terminal. The third device checks whether the application information about the communication terminal is consistent with the policy information about the communication terminal. If the application information about the communication terminal is not consistent with the policy information about the communication terminal, the third device sends information related to rejection to the first device corresponding to AMF70.
[0109] According to a second example of the first embodiment, for example, 5GC (e.g., SMF) can recognize whether or not the UE enforces the URSP rule. In addition, according to a second example of the first embodiment, for example, actions that 5GS (e.g., SMF) can take after 5GC recognizes whether the UE enforces the URSP rule can be provided. Furthermore, according to a second example of the first embodiment, for example, a solution can be provided that can prevent unauthorized applications in the UE.
[0110] <Modified form 1 of the second example of the first embodiment> If SMF71 receives an Nsmf_PDUSession_CreateSMContext request message from AMF70 in step 4, SMF71 may obtain UE policy information from PCF73 via the Npcf_UEPolicyControl service provided by PCF73. In this case, the following steps are taken between SMF71 and PCF73.
[0111] -SMF71 sends an Npcf_UEPolicyControl_Create message containing the user ID to PCF73. The user ID may be UE3 identification information. The user ID may be SUPI. The user ID may be UE3 SUPI.
[0112] -PCF73 finds the UE policy rule based on the received user ID (for example, PCF73 finds the UE policy for UE3) and sends an Npcf_UEPolicyControl_UpdateNotify message containing the UE policy to SMF71. The UE policy may be represented by a UE policy association ID.
[0113] If the Nsmf_PDUSession_CreateSMContext request message does not include a UE policy, SMF71 may send an Npcf_UEPolicyControl_Create message to PCF73.
[0114] Regardless of whether the Nsmf_PDUSession_CreateSMContext request message contains a UE policy, SMF71 may send an Npcf_UEPolicyControl_Create message to PCF73.
[0115] <Modified form 2 of the second example of the first embodiment> In step 3, the UL NAS transport message may be replaced with a service request message. In this case, the UL NAS transport message in step 3 is replaced with a service request message.
[0116] In addition, the DL NAS transport message in step 7 is replaced with a denial-of-service message.
[0117] Service request messages may contain the same information as UL NAS transport messages.
[0118] Denial of Service messages may contain the same information as DL NAS transport messages.
[0119] <Third example of the first aspect> A third example of the first aspect discloses how PCF73 transmits a UE policy to UPF72 via AMF70 and SMF71 when PDU session establishment is requested by UE3. UPF72 then verifies the uplink user data from UE3 to determine whether the user data from UE3 is consistent with the UE policy.
[0120] A detailed process of a third example of the first embodiment is described below with reference to Figure 3.
[0121] Step 1 is the same as the sequence of steps 1-6 in the first example of the first embodiment.
[0122] Step 2: The UE policy, including the URSP, is provided to AMF70 by PCF73 as specified in steps 4 and 5 of the first example of the first aspect. If AMF70 has already received the UE policy from PCF73 in step 1, step 2 may be skipped.
[0123] Step 3: At some point, UE3 sends a UL NAS transport message, a service request message, or any other NAS message to AMF70, which includes the PDU session ID, App_Id, DNN, S-NSSAI, and a NAS container containing a PDU session establishment request to establish a PDU session, in order to establish a new PDU session, reuse an already established PDU session, or modify an already established PDU session.
[0124] Step 4: Upon receiving the UL NAS transport message from UE3, AMF70 sends an Nsmf_PDUSession_CreateSMContext request message to SMF71 containing the PDU session ID, App_Id, DNN, S-NSSAI, the "URSP observation needed" parameter, the UE policy, and an SM NAS container containing the PDU session establishment request message. The UE policy parameter is entered by AMF70 from the UE context of UE3. The UE policy may be one received from PCF73 in Step 1 or Step 2. The "URSP observation needed" parameter is entered or created by AMF70 to indicate to SMF71 that user data verification at UPF72 is required. The "URSP observation needed" parameter may be described as information indicating that verification of data in UE3 or data related to UE3 is required.
[0125] Step 5: Upon receiving the Nsmf_PDUSession_CreateSMContext request message from AMF70, SMF71 sends an N4 session establishment request message to UPF72, which includes the "required URSP observation" parameters and UE policy. The "required URSP observation" parameters and UE policy may be entered by copying them from the parameters received in the Nsmf_PDUSession_CreateSMContext request message from AMF70. The "required URSP observation" parameters and UE policy may be those received in the Nsmf_PDUSession_CreateSMContext request message from AMF70.
[0126] Step 6: UPF72 sends an N4 session establishment response message to SMF71. If UPF72 receives an N4 session establishment request message from SMF71, UPF72 may send an N4 session establishment response message.
[0127] Step 7: The PDU session establishment procedure continues from step 11 of section 4.3.2.2.1 in Non-Patent Document 4.
[0128] Step 8: UPF72 receives uplink user data from UE3 via RAN5. The uplink user data may include the App_ID.
[0129] Step 9: Upon receiving uplink user data from UE3 via RAN5, UPF72 verifies whether the received uplink user data is consistent with the UE policy received from PCF73 via AMF70 and SMF71 (for example, whether the received application identifier (i.e., App_Id) does not match any root descriptor rule defined in the NSSP corresponding to the application identifier, whether the received App_Id matches any application identifier in the URSP rule, or whether the received App_Id matches any application identifier in the "Application Descriptor" of the URSP rule).
[0130] Step 10: If UPF72 finds that the received uplink user data is inconsistent with the UE policy (for example, if the received application identifier (i.e., App_Id) does not match any route descriptor rule defined in the NSSP corresponding to the application identifier, or if the received App_Id does not match any application identifier in the URSP rule, or if the received App_Id does not match any application identifier in the "Application Descriptor" of the URSP rule), UPF72 requests SMF71 to initiate selective deactivation of CN initiation for UP connections of existing PDU session procedures, as described in Section 4.3.7 of Non-Patent Literature 4. UPF72 may provide SMF71 with a cause value (or cause parameter) and request that it set it as the SM cause value. For example, UPF72 may send a cause value to SMF71. If SMF71 receives a cause value, SMF71 may send the cause value to UE3. For example, SMF71 may send a cause value to UE3 using DL NAS transport messages. If UE3 receives the cause value, UE3 may stop sending uplink user data to UPF72.
[0131] Requesting SMF71 to initiate selective deactivation of CN initiation for UP connections in existing PDU session procedures can be described as deactivating data-related communications in UE3.
[0132] For example, if UPF72 finds that the received uplink user data is consistent with the UE policy, UPF72 may process the received uplink user data for communication with UE3. For example, if UPF72 finds that the received uplink user data is consistent with the UE policy, the user data exchange (e.g., the exchange of uplink user data) may not be interrupted or may be processed appropriately.
[0133] The causal parameter may have one or more values from the causes listed below. These can be any SM cause. - IP descriptors do not match. - The destination IP address is outside the range defined in the IP descriptors. - The IPv6 prefix is outside the range defined in the IP descriptors. - The port number is outside the range defined in the IP descriptor. - The protocol ID is outside the range defined in the IP descriptors. - The FQDN does not match the ones defined in the domain descriptors. - Out of time windows
[0134] For example, UPF72 may check whether the current time (e.g., the current time when UPF72 receives or confirms uplink user data; information indicating that the current time may be included in the uplink user data) matches the "time window" in the "route selection descriptor" defined in the URSP rule. If UPF72 determines that the current time does not match the "time window" (e.g., UPF72 determines that the current time is not within the period or time window defined by the "time window"), UPF72 may request SMF71 to initiate selective deactivation of CN initiation for UP connections of existing PDU session procedures. In addition, UPF72 may send a cause parameter set to "outside time window" to SMF71, and SMF71 may send the cause parameter to UE3.
[0135] When UPF72 checks the "time window," it may use time data provided by the Network Time Protocol (NTP), as defined in Non-Patent Document 6, as the current time.
[0136] For example, uplink user data may include at least one of the following: information about an IP address (e.g., destination IP address, IPv6 prefix, port number, protocol ID) and information about a domain name (e.g., FQDN).
[0137] For example, UPF72 may check whether at least one of the following—information about an IP address and information about a domain name—matches the corresponding information in a URSP rule. For example, UPF72 may check at least one of the following:
[0138] - Whether the destination IP address of the uplink user data matches the "IP descriptor" in the URSP rule.
[0139] - Whether the IPv6 prefix of the uplink user data matches the "IP descriptor" in the URSP rule, or whether the IPv6 prefix of the uplink user data is within the range defined by the "IP descriptor" in the URSP rule.
[0140] - Whether the port number of the uplink user data matches the "IP descriptor" in the URSP rule, or whether the port number of the uplink user data is within the range defined by the "IP descriptor" in the URSP rule.
[0141] - Whether the protocol ID of the uplink user data matches the "IP descriptor" in the URSP rule, or whether the protocol ID of the uplink user data is within the range defined by the "IP descriptor" in the URSP rule, and
[0142] - Whether the FQDN of the uplink user data matches the FQDN defined by the "domain descriptor" in the URSP rule.
[0143] If UPF72 determines that the destination IP address of the uplink user data does not match the "IP descriptor" in the URSP rule, UPF72 may request SMF71 to initiate selective deactivation of CN initiation for UP connections in existing PDU session procedures. In addition, UPF72 may send a cause parameter set to "IP descriptors does not match" or "destination IP address is outside the range defined by the IP descriptor," and SMF71 may send the cause parameter to UE3.
[0144] If UPF72 determines that the IPv6 prefix of the uplink user data does not match the "IP descriptor" in the URSP rule, or that the IPv6 prefix of the uplink user data falls outside the range defined by the "IP descriptor" in the URSP rule, UPF72 may request SMF71 to initiate selective deactivation of CN initiation for UP connections in existing PDU session procedures. In addition, UPF72 may send a cause parameter set to "IP descriptor mismatch" or "IPv6 prefix outside the range defined by IP descriptor" to SMF71, which may send the cause parameter to UE3.
[0145] If UPF72 determines that the port number of the uplink user data does not match the "IP descriptor" in the URSP rule, or that the port number of the uplink user data falls outside the range defined by the "IP descriptor" in the URSP rule, UPF72 may request SMF71 to initiate selective deactivation of CN initiation for UP connections in existing PDU session procedures. In addition, UPF72 may send a cause parameter set to "IP descriptor mismatch" or "port number outside the range defined by IP descriptor" to SMF71, which may send the cause parameter to UE3.
[0146] If UPF72 determines that the protocol ID of the uplink user data does not match the "IP descriptor" in the URSP rule, or that the protocol ID of the uplink user data falls outside the range defined by the "IP descriptor" in the URSP rule, UPF72 may request SMF71 to initiate selective deactivation of CN initiation for UP connections in existing PDU session procedures. In addition, UPF72 may send a cause parameter set to "IP descriptor mismatch" or "protocol ID outside the range defined by IP descriptor" to SMF71, which may send the cause parameter to UE3.
[0147] If UPF72 determines that the FQDN of the uplink user data does not match the FQDN defined by the "domain descriptor" in the URSP rule, UPF72 may request SMF71 to initiate selective deactivation of CN initiation for UP connections in existing PDU session procedures. In addition, UPF72 may send a cause parameter set to "FQDN does not match what is defined in the domain descriptor" to SMF71, and SMF71 may send the cause parameter to UE3.
[0148] UPF72 may check whether at least one of the following information matches the corresponding parameter in the URSP rule as described above: App_Id, current time, IP address information, and domain name information. If UPF72 determines that at least one of the following information does not match the corresponding parameter in the URSP rule, UPF72 may send cause parameters requesting SMF71 to initiate selective deactivation of CN initiation for UP connections of existing PDU session procedures as described above.
[0149] According to a third example of the first embodiment, for example, 5GC (e.g., UPF) can recognize whether or not the UE enforces URSP rules. In addition, according to a third example of the first embodiment, for example, actions that 5GS (e.g., UPF) can take after 5GC recognizes whether the UE enforces URSP rules can be provided. Furthermore, according to a third example of the first embodiment, for example, a solution can be provided that can prevent unauthorized applications in the UE from routing traffic through existing PDU sessions.
[0150] For example, a fourth device corresponding to UPF72 stores policy information about a communication terminal from a second device. For example, the communication terminal corresponds to UE3. For example, the second device corresponds to PCF73. The fourth device receives application information about the communication terminal from a third device. For example, the third device corresponds to SMF71. The fourth device receives information from the third device indicating that verification of data related to the communication terminal is required. Based on the information indicating that verification of data related to the communication terminal is required, the fourth device checks whether the application information about the communication terminal is consistent with the policy information about the communication terminal. If the application information about the communication terminal is not consistent with the policy information about the communication terminal, the fourth device sends information related to rejection.
[0151] <Modified form 1 of the third example of the first embodiment> In step 8, UPF72 can determine the user location in relation to whether the UE3 is in an authorized location as defined by the URSP rules. To enable location verification by UPF72, whenever RAN5 sends GTP-U data to UPF72, RAN5 enters the cell ID to which the UE3 is connected in the RAN container or NR RAN container in the GTP-U header. UPF72 checks the cell ID in the GTP-U in relation to whether the received cell ID is within an authorized location or area as defined by the URSP rules.
[0152] If UPF72 finds that the received cell ID falls outside the range defined by the URSP rule (for example, if UPF72 determines that the received cell ID does not match the cell ID indicated by the URSP rule, or if UPF72 determines that the location indicated by the received cell ID does not match the location or area indicated by the URSP rule), UPF72 requests SMF71 to initiate selective deactivation of CN initiation for UP connections of existing PDU session procedures, as described in Section 4.3.7 of Non-Patent Literature 4. UPF72 may provide SMF71 with a cause value and request that it be set as the SM cause value.
[0153] The causal parameters may be as follows. These may be SM causes.
[0154] - Out of Location
[0155] UPF72 can convert locations indicated by URSP rules into cell IDs. UPF72 can convert received cell IDs into location information that can be used for location verification. UPF72 can perform conversions based on local configurations or operator policies stored in UPF72. UPF72 can receive information for conversion from other network nodes. UPF72 can pre-store information for conversion.
[0156] <Fourth example of the first aspect> A fourth example of the first embodiment discloses how UE3 sends a request for service message to AMF70 when UE3's NAS layer 362 receives uplink data from a new application in UE3, even though UE3 is CM connected and a PDU session indicated by UE3 has already been activated.
[0157] When AMF70 receives a service request message from UE3 that includes an application identifier (e.g., App_Id), AMF70 verifies the application identifier to determine if it is consistent with the UE policy downloaded from PCF73 regarding the use of the PDU session.
[0158] A detailed process of the fourth example of the first embodiment is described below with reference to Figure 4.
[0159] Step 1: The UE policy, including the URSP rule, is provided to AMF70 by PCF73 as specified in steps 4 and 5 of the first example of the first aspect. The UE policy, including the URSP rule, may be provided to AMF70 by PCF73 as specified in steps 3-5 of the first example of the first aspect. AMF70 may provide the UE policy to UE3 as specified in step 6 of the first example of the first aspect.
[0160] Step 2: A PDU session (PDU session ID #1 is assigned to this PDU session) is established for APP1 36301, and DRB is established for APP1 36301. That is, UE3 is in a CM connection state. A PDU session can be established for APP1 36301 with S-NSSAI. APP1 36301 is the application in UE3.
[0161] Step 3: At some point, APP2 36302 sends uplink data with the APP_id of APP2 36302 to NAS layer 362. APP2 36302 is the application in UE3.
[0162] Note that the NAS layer 362 may be one of the functions of the communication control module 362 in the schematic block diagram for UE3.
[0163] Step 4: NAS layer 362 checks the URSP rules in UE3 to see if the App_Id received from APP2 36302 matches an existing PDU session (PDU session ID #1) used for APP2 36302. For example, NAS layer 362 may check if a URSP rule exists that corresponds to the received App_Id. For example, NAS layer 362 may check if a URSP rule exists that contains a traffic descriptor corresponding to the received App_Id. If NAS layer 362 finds a URSP rule that corresponds to the received App_Id, NAS layer 362 selects a route selection descriptor within the found URSP rule. NAS layer 362 then determines whether the existing PDU session (PDU session ID #1) matches the components in the selected route selection descriptor. For example, NAS layer 362 may determine whether the information about the existing PDU session (PDU session ID #1) matches the information about the PDU session in the selected route selection descriptor. If they match (for example, if an existing PDU session (PDU session ID #1) matches a component in the selected root selection descriptor), the NAS layer 362 proceeds with the following steps in the fourth example of the first embodiment. Otherwise, the NAS layer 362 may initiate the PDU session establishment procedure for the UE request to establish a new PDU session for APP2 36302 as described in section 4.3.2.2 of Non-Patent Literature 4.
[0164] Step 5: NAS layer 362 in UE3 sends a service request message to AMF70 containing PDU session ID #1 (PDU session identification information 1) and App_Id (application identification information) of APP2 36302.
[0165] Step 6: Upon receiving a service request message from UE3, AMF70 verifies whether the App_Id provided by UE3 is consistent with the UE policy in UE3's UE context (for example, AMF70 verifies whether the received application identity (i.e., the received App_Id) matches any root descriptor rule defined in the NSSP corresponding to the application identity, whether the received App_Id matches any application identity in the URSP rule, or whether the received App_Id matches any application identity in the "application descriptor" of the URSP rule).
[0166] When AMF70 checks whether the App_Id provided by UE3 is consistent with the UE policy, AMF70 may check the UE policy or URSP rule corresponding to PDU session ID #1.
[0167] If it is consistent with the UE policy (for example, if the received application identifier (i.e., the received App_Id) matches one of the root descriptor rules defined in the NSSP corresponding to the application identifier, or if the received App_Id matches one of the application identifiers in the URSP rule, or if the received App_Id matches one of the application identifiers in the "Application Descriptor" of the URSP rule), then steps 7a and 8a are performed; otherwise (for example, if the received application identifier (i.e., the received App_Id) does not match any of the root descriptor rules defined in the NSSP corresponding to the application identifier, or if the received App_Id does not match any of the application identifiers in the URSP rule, or if the received App_Id does not match any of the application identifiers in the "Application Descriptor" of the URSP rule), then steps 7b and 8b are performed.
[0168] Step 7a: AMF sends a service authorization message to UE3.
[0169] Step 8a: Upon receiving the service authorization message, NAS layer 362 forwards the uplink data received from APP2 36302 in step 3 to UPF72 via the RAN.
[0170] Following step 8a, subsequent uplink data from APP2 36302 is forwarded by NAS layer 362 via RAN to UPF72 using the PDU session identified by PDU session ID #1. Similarly, downlink data from UPF72 via RAN is forwarded by NAS layer 362 to APP2 36302 if the downlink data is destined for APP2 36302.
[0171] Step 7b: AMF70 sends a denial-of-service message to UE3. The denial-of-service message includes an SM cause value set to "App_Id is not allowed," indicating that PDU session ID #1 cannot be used by APP2 36302, which is shown as App_Id in the service request message in Step 5.
[0172] Step 8b: Upon receiving a denial-of-service message containing an SM cause value, NAS layer 362 discards the uplink data received from APP2 36302 in step 3 and sends a message to APP2 36302 indicating that the App_Id defined in step 3 is invalid.
[0173] Upon receiving a message from NAS layer 362, APP2 36302 stops sending uplink data to NAS layer 362 and starts a scanning program (e.g., a virus check program). At least one of abandoning uplink data and stopping the transmission of uplink data may be referred to as ceasing use of APP2 36302.
[0174] According to a fourth example of the first embodiment, for example, 5GC (e.g., AMF) can recognize whether or not the UE enforces URSP rules. In addition, according to a fourth example of the first embodiment, for example, actions that 5GS (e.g., AMF) can take after 5GC recognizes whether the UE enforces URSP rules can be provided. Furthermore, according to a fourth example of the first embodiment, for example, a solution can be provided that can prevent unauthorized applications in the UE from routing traffic through existing PDU sessions.
[0175] For example, a communication terminal that supports UE3 sends a service request message to the first device containing information about the application for the communication terminal. For example, the first device supports AMF70. The first device stores policy information about the communication terminal from the second device. For example, the second device supports PCF73. The first device checks whether the information about the application for the communication terminal is consistent with the policy information for the communication terminal. If the information about the application for the communication terminal is not consistent with the policy information for the communication terminal, the first device sends information related to rejection to the communication terminal.
[0176] For example, a communication terminal that supports UE3 sends a service request message to the first device containing information about the application of the communication terminal. For example, the first device supports AMF70. The first device stores policy information about the communication terminal from the second device. For example, the second device supports PCF73. The first device checks whether the information about the application of the communication terminal is consistent with the policy information about the communication terminal. If the information about the application of the communication terminal is consistent with the policy information about the communication terminal, the first device sends information related to authorization to the communication terminal.
[0177] For example, the first device corresponding to AMF70 stores policy information about the communication terminal from the second device. For example, the communication terminal corresponds to UE3. For example, the second device corresponds to PCF73. The first device receives a service request message from the communication terminal that contains information about the application for the communication terminal. The first device checks whether the information about the application for the communication terminal is consistent with the policy information for the communication terminal. If the information about the application for the communication terminal is not consistent with the policy information for the communication terminal, the first device sends information related to rejection to the communication terminal.
[0178] For example, the first device, which corresponds to AMF70, stores policy information about the communication terminal from the second device. For example, the communication terminal corresponds to UE3. For example, the second device corresponds to PCF73. The first device receives a service request message from the communication terminal that contains information about the application for the communication terminal. The first device checks whether the information about the application for the communication terminal is consistent with the policy information for the communication terminal. If the information about the application for the communication terminal is consistent with the policy information for the communication terminal, the first device sends information related to authorization to the communication terminal.
[0179] <Fifth example of the first aspect> A fifth example of the first aspect discloses how AMF70 sends a first NAS message to UE3 requesting a list of application identifiers associated with a given PDU session. When AMF70 receives a second NAS message containing the list of application identifiers associated with a PDU session, AMF70 checks each application to see if its use of the PDU session is consistent with the UE policy downloaded from PCF73.
[0180] A detailed process of the fifth example of the first embodiment is described below with reference to Figure 5.
[0181] Step 1: The UE policy, including the URSP rule, is provided to AMF70 by PCF73 as specified in steps 4 and 5 of the first example of the first aspect. The UE policy, including the URSP rule, may be provided to AMF70 by PCF73 as specified in steps 3-5 of the first example of the first aspect.
[0182] Step 2: A PDU session (PDU session ID #1 is assigned to this PDU session) is established for APP1 36301, and DRB is established for APP1 36301. That is, UE3 is in a CM connection state. A PDU session can be established for APP1 36301 with S-NSSAI. APP1 36301 is the application in UE3.
[0183] Step 3: At some point, APP2 36302 will start using a PDU session identified by PDU session ID #1, based on the URSP rules in UE3. APP2 36302 is an application in UE3.
[0184] In this example, the PDU session identified by PDU session ID #1 is used by two applications, APP1 36301 and APP2 36302.
[0185] Step 4: The AMF70 sends a first NAS message to the UE3 containing a flag and a PDU session ID. The flag indicates that a list of applications using the PDU session is requested. If the PDU session ID is not specified or explicitly indicated by another parameter, the first NAS message may apply to all PDU sessions established in the UE3. The flag may be referred to as an APP ID request.
[0186] For example, the first NAS message could be a DL NAS transport message, an identification request message, a notification message, a 5GMM status message, or another existing NAS message or a new NAS message.
[0187] The triggers for the AMF70 to send the first NAS message can be listed as follows: - Regular activation. For example, once a day for each PDU session. -When user data traffic monitored by UPF72 is abnormal, AMF70 receives a notification from SMF71 or UPF72 indicating that UE3 needs to check on the use of PDU sessions. An example of abnormal traffic to monitor is too much data in a short period of time. -When the use of a PDU session is suspicious in UE behavior, AMF70 receives a notification from another node, for example NWDAF76, indicating that UE3 needs to check the use of the PDU session.
[0188] Step 5: Upon receiving the first NAS message, UE3 sends a second NAS message to AMF70 containing a list of App_Ids and PDU session IDs. The list of App_Ids indicates that the applications identified by the App_Ids use the PDU sessions indicated by the PDU session IDs. If the PDU session IDs are not specified or are not explicitly indicated by other parameters in the first NAS message, the second NAS message includes a list of parameters, where the parameters include a list of App_Ids and PDU session IDs.
[0189] For example, the second NAS message could be a UL NAS transport message, an identification response message, a notification response message, a 5GMM status message, or another existing NAS message or a new NAS message.
[0190] For example, if a PDU session identified by PDU session ID #1 is used by two applications in UE3, such as APP1 36301 and APP2 36302, and UE3 receives a first NAS message containing a flag and PDU session ID #1, UE3 may send a second NAS message containing a list of App_Ids and the PDU session ID. In this case, the list may include the App_Id of APP1 36301, the App_Id of APP2 36302, and PDU session ID #1. The list may indicate that PDU session ID #1 (or the PDU session identified by PDU session ID #1) is used by APP1 36301 identified by App_Id1 and APP2 36302 identified by App_Id2.
[0191] Step 6: Upon receiving a second NAS message from UE3, AMF70 verifies whether the App_Id provided by UE3 is consistent with the UE policy in UE3's UE context (for example, AMF70 verifies whether the received application identity (i.e., the received App_Id) matches any root descriptor rule defined in the NSSP corresponding to the application identity, or whether the received App_Id matches any application identity in the "Application Descriptor" of the URSP rule).
[0192] If AMF70 is checking whether the App_Id provided by UE3 is consistent with the UE policy, AMF70 may check the UE policy or URSP rule corresponding to the PDU session ID received in step 5.
[0193] If it does not align with the UE policy (for example, if the received application identifier (i.e., the received App_Id) does not match any root descriptor rule defined in the NSSP corresponding to the application identifier, or if the received App_Id does not match any application identifier in the URSP rule, or if the received App_Id does not match any application identifier in the "Application Descriptor" of the URSP rule), then steps 7 and 8 are performed; otherwise (for example, if the received application identifier (i.e., the received App_Id) matches one of the root descriptor rules defined in the NSSP corresponding to the application identifier, or if the received App_Id matches one of the application identifiers in the URSP rule, or if the received App_Id matches one of the application identifiers in the "Application Descriptor" of the URSP rule), then AMF70 does nothing.
[0194] If AMF70 receives two or more App_Ids, AMF70 may determine whether each of the App_Ids matches a URSP rule. If at least one of the App_Ids does not match a URSP rule, steps 7 and 8 may be performed.
[0195] Step 7: The AMF70 sends a third NAS message to the UE3 containing a list of allowed APP_Ids, a list of unallowed APP_Ids, and the PDU session ID. If the PDU session ID is not specified or is not explicitly indicated by another parameter in the first NAS message, the third NAS message contains a list of parameters, where the parameters include the list of allowed APP_Ids, the list of unallowed APP_Ids, and the PDU session ID.
[0196] For example, the third NAS message could be a DL NAS transport message, an identification request message, a notification message, a 5GMM status message, or another existing NAS message or a new NAS message.
[0197] For example, consider a scenario where a PDU session identified by PDU session ID #1 is used by two applications in UE3, such as APP1 36301 and APP2 36302. In this example, if App_Id1 of APP1 36301 matches the URSP rule, and App_Id2 of APP2 36302 does not match the URSP rule, the third NAS message may include a list of permitted APP_Ids, including App_Id1; a list of unauthorized APP_Ids, including App_Id2; and PDU session ID #1. If App_Id1 and App_Id2 match the URSP rule, the third NAS message may include a list of permitted APP_Ids, including App_Id1 and App_Id2; and PDU session ID #1. If App_Id1 and App_Id2 do not match the URSP rules, the third NAS message may include a list of unauthorized APP_Ids, including App_Id1 and App_Id2, and PDU session ID #1.
[0198] Step 8: Upon receiving the third NAS message, NAS layer 362 functions as follows:
[0199] If the third NAS message contains a list of unauthorized APP_Ids, NAS layer 362 generates a Termination of Service message and sends it to the application identified by the App_Id included in the list of unauthorized APP_Ids. The Termination of Service message may indicate that the PDU session being used is inappropriate.
[0200] For example, if the third NAS message contains a list of unauthorized APP_Ids, including App_Id2 of APP2 36302, NAS layer 362 may send a termination of service message to APP2 36302.
[0201] When APP2 36302 receives a service termination message from NAS layer 362, it stops sending uplink data to NAS layer 362 and starts a scanning program (e.g., a virus check program).
[0202] If the third NAS message indicates that multiple applications will be terminated (for example, if the list of unauthorized APP_Ids in the third NAS message contains multiple App_Ids), NAS layer 362 will send multiple termination of service notification messages to each application based on the parameters received in the third NAS message (e.g., App_Id).
[0203] At least one of the following actions may be referred to as ceasing the use of APP2 36302: ceasing the generation of a service termination message, ceasing the transmission of a service termination message, and ceasing the transmission of uplink data.
[0204] If an application does not receive a service termination message, it may continue to send uplink data to NAS layer 362.
[0205] When NAS layer 362 receives a list of permitted APP_Ids, it may generate a service continuation message and send it to the application identified by the App_Id included in the list of permitted APP_Ids. The service continuation message may indicate that the PDU session being used is valid.
[0206] Upon receiving a service continuation message from NAS layer 362, the application may continue sending uplink data to NAS layer 362.
[0207] According to a fifth example of the first embodiment, for example, 5GC (e.g., AMF) can recognize whether or not the UE enforces URSP rules. In addition, according to a fifth example of the first embodiment, for example, actions that 5GS (e.g., AMF) can take after 5GC recognizes whether the UE enforces URSP rules can be provided. Furthermore, according to a fifth example of the first embodiment, for example, a solution can be provided that can prevent unauthorized applications in the UE from routing traffic through existing PDU sessions.
[0208] For example, a first device corresponding to AMF70 stores policy information about a communication terminal from a second device. For example, the communication terminal corresponds to UE3. For example, the second device corresponds to PCF72. The first device sends a request message to the communication terminal about application information for the communication terminal. The first device receives application information for the communication terminal from the communication terminal. The first device checks whether the application information for the communication terminal is consistent with the policy information for the communication terminal. If the application information for the communication terminal is not consistent with the policy information for the communication terminal, the first device sends information related to rejection to the communication terminal.
[0209] For example, the first device corresponding to AMF70 stores policy information regarding the communication terminal from the second device. For example, the communication terminal corresponds to UE3. For example, the second device corresponds to PCF72. The first device transmits a request message to the communication terminal regarding information about the application for the communication terminal. The first device receives information about the application for the communication terminal from the communication terminal. The first device checks whether the information about the application for the communication terminal is consistent with the policy information regarding the communication terminal. If the information about the application for the communication terminal is consistent with the policy information regarding the communication terminal, the first device transmits information related to approval to the communication terminal.
[0210] <Variant 1 of the fifth example of the first aspect> In one example, steps 4 to 7 are similarly executed by SMF71 or UPF72. For example, as defined in one of the above aspects, UPF72 or SMF71 may determine whether the data (e.g., App_Id) transmitted in the PDU session matches the URSP rule received by UPF72 or SMF71.
[0211] <System overview> FIG. 6 schematically shows a telecommunication system 1 for mobile (cellular or wireless) to which the above aspect is applicable.
[0212] The telecommunication system 1 represents a system overview enabling end-to-end communication. For example, UE3 (or user equipment, "mobile device" 3) communicates with other UE3 or service servers in the data network 20 via the respective (R)AN node 5 and core network 7.
[0213] (R)AN Node 5 supports any radio access, including non-3GPP RATs such as 5G radio access technology (RAT), E-UTRA radio access technology, Beyond5G RAT, 6G RAT, and wireless local area network (WLAN) technology as defined by the Institute of Electrical and Electronics Engineers (IEEE).
[0214] (R)AN node 5 may be separated into a Radio Unit (RU), a Distributed Unit (DU), and a Centralized Unit (CU). In some embodiments, each of the units may be connected to each other to form (R)AN node 5 by employing an architecture as defined by the Open RAN (O-RAN) Alliance, and the above units shall be referred to as O-RU, O-DU, and O-CU, respectively.
[0215] (R)AN node 5 may be separated into control plane functions and user plane functions. Furthermore, multiple user plane functions may be assigned to support communications. In some embodiments, user traffic may be distributed across multiple user plane functions, and the user traffic in each user plane function is aggregated at both UE3 and (R)AN node 5. This separation architecture may be called "dual connectivity" or "multi-connectivity".
[0216] (R)AN node 5 may also support communications using satellite access. In some embodiments, (R)AN node 5 may support both satellite and ground access.
[0217] In addition, (R)AN node 5 may also be referred to as an access node for non-wireless access. Non-wireless access includes fixed network access as defined by the Broadband Forum (BBF) and optical access as defined by the Innovative Optical and Wireless Network (IOWN).
[0218] The core network 7 may include logical nodes (or "functions") that support communication in the telecommunications system 1. For example, the core network 7 may be a 5G Core Network (5GC) that includes, in particular, control plane functions and user plane functions. Each function in a logical node may be considered a network function. Network functions may be provided to other nodes by adapting a Service Based Architecture (SBA).
[0219] Network functions can be deployed as distributed, redundant, stateless, and extensible, providing services from several locations and offering several execution instances at each location, by adapting network virtualization technologies such as those defined by the European Telecommunications Standards Institute, Network Functions Virtualization (ETSI NFV).
[0220] Core network 7 may support a Non-Public Network (NPN). The NPN may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0221] As is well known, when a UE3 is moving around the geographic area covered by the telecommunications system 1, the UE3 may move in and out of the area (i.e., radio cell) serviced by the (R)AN node 5. To maintain tracking of the UE3 and facilitate movement between various (R)AN node 5, the core network 7 includes at least one access and mobility management function (AMF) 70. The AMF 70 communicates with the (R)AN node 5 connected to the core network 7. In some core networks, a mobility management entity (MME) or mobility management node for Beyond 5G, or a mobility management node for 6G, may be used instead of the AMF 70.
[0222] The core network 7 also includes, in particular, a Session Management Function (SMF) 71, a User Plane Function (UPF) 72, a Policy Control Function (PCF) 73, an Authentication Server Function (AUSF) 74, a Unified Data Management (UDM) 75, and a Network Data Analytics Function (NWDAF) 76. When UE3 roams to the Visited Public Land Mobile Network (VPLMN), the UE3's Home Public Land Mobile Network (HPLMN) provides the roaming-out UE3 with the UDM 75, as well as at least some of the functions of SMF 71, UPF 72, and PCF 73.
[0223] UE3 and each Serving(R)AN node 5 are connected via appropriate air interfaces (e.g., so-called "Uu" interfaces and / or equivalents). Neighboring(R)AN nodes 5 are connected to each other via appropriate(R)AN node 5-to-(R)AN node interfaces (such as so-called "Xn" interfaces and / or equivalents). Each(R)AN node 5 is also connected to nodes in the core network 7 (such as so-called core network nodes) via appropriate interfaces (such as so-called "N2" / "N3" interfaces and / or equivalents). Connection from the core network 7 is also provided to the data network 20. The data network 20 may be the internet, a public network, an external network, a private network, or the internal network of the PLMN. If the data network 20 is provided by a PLMN operator or a Mobile Virtual Network Operator (MVNO), IP Multimedia Subsystem (IMS) services may be provided by that data network 20. UE3 can be connected to the data network 20 using IPv4, IPv6, IPv4v6, Ethernet, or unstructured data types.
[0224] The "Uu" interface may include the control plane of the Uu interface and the user plane of the Uu interface.
[0225] The user plane of the Uu interface is responsible for transmitting user traffic between UE3 and Serving(R)AN node 5. The user plane of the Uu interface may have a hierarchical structure with SDAP, PDCP, RLC, and MAC sublayers via physical connections.
[0226] The Uu interface control plane is responsible for establishing, modifying, and releasing connections between UE3 and Serving(R)AN node 5. The Uu interface control plane may have a hierarchical structure with RRC, PDCP, RLC, and MAC sublayers based on physical connections.
[0227] For example, the following message is communicated at the RRC layer to support AS signaling.
[0228] - RRC setup request message: This message is sent from UE3 to (R)AN node 5. In addition to the parameters disclosed in this aspect of disclosure, the following parameters may also be included in the RRC setup request message. --Establishment Cause and ue-Identity. The ue-Identity may have a value of ng-5G-S-TMSI-Part1 or a random value.
[0229] - RRC setup message: This message is sent from (R)AN node 5 to UE3. In addition to the parameters disclosed in this aspect of disclosure, the following parameters may also be included in the RRC setup message. --Master Cell Group and Radio Bearer Config
[0230] - RRC setup complete message: This message is sent from UE3 to (R)AN node 5. In addition to the parameters disclosed in this disclosure, the following parameters may also be included in the RRC setup complete message. --guami type, iab-node indication, idle measurement available, mobility state, ng-5G-S-TMSI-part 2, registered AMF, selected PLMN identity
[0231] UE3 and AMF70 are connected via an appropriate interface (e.g., the so-called N1 interface and / or the like). The N1 interface serves to provide communication between UE3 and AMF70 to support NAS signaling. The N1 interface can be established in 3GPP access and non-3GPP access. For example, the following messages are communicated over the N1 interface.
[0232] - Registration request message: This message is sent from UE3 to AMF70. In addition to the parameters disclosed by the aspects of the present disclosure, the following parameters may be included together in the registration request message. --5GS registration type, ngKSI, 5GS mobile identity, Non-current native NAS key set identifier, 5GMM capability, UE security capability, Requested NSSAI, Last visited registered TAI, S1 UE network capability, Uplink data status, PDU session status, MICO indication, UE status, Additional GUTI, Allowed PDU session status, UE's usage setting, Requested DRX parameters, EPS NAS message container, LADN indication, Payload container type, Payload Container, Network slicing indication, 5GS update type, Mobile station classmark 2, Supported codecs, NAS message container, EPS bearer context status, Requested extended DRX parameters, T3324 value, UE radio capability ID.ID), Requested mapped NSSAI, Additional information requested, Requested WUS assistance information, N5GC indication, and Requested NB-N1 mode DRX parameters.
[0233] -Registration approval message: This message is sent from AMF70 to UE3. In addition to the parameters disclosed in this manner, the following parameters may also be included in the registration approval message. --5GS registration result, 5G-GUTI, Equivalent PLMNs, TAI list, Allowed NSSAI, Rejected NSSAI, Configured NSSAI, 5GS network feature support, PDU session status, PDU session reactivation result, PDU session reactivation result error cause, LADN information, MICO indication, Network slicing indication, Service area list, T3512 value, Non-3GPP de-registration timer value, T3502 value, Emergency number list list), Extended emergency number list, SOR transparent container, EAP message, NSSAI inclusion mode, Operator-defined access category definitions, Negotiated DRX parameters, Non-3GPP NW policies, EPS bearer context status, Negotiated extended DRX parameters, T3447 value, T3448 valueThe following are listed: value, T3324 value, UE radio capability ID, UE radio capability ID deletion indication, Pending NSSAI, Ciphering key data, CAG information list, Truncated 5G-S-TMSI configuration, Negotiated WUS assistance information, Negotiated NB-N1 mode DRX parameters, and Extended rejected NSSAI.
[0234] -Registration completion message: This message is sent from UE3 to AMF70. In addition to the parameters disclosed in this manner, the following parameters may also be included in the registration completion message. --SOR transparent container.
[0235] - Authentication request message: This message is sent from AMF70 to UE3. In addition to the parameters disclosed in this aspect of disclosure, the following parameters may also be included in the authentication request message. --ngKSI, ABBA, authentication parameter RAND (5G authentication challenge), authentication parameter AUTN (5G authentication challenge), and EAP message.
[0236] - Authentication response message: This message is sent from UE3 to AMF70. In addition to the parameters disclosed in this aspect of disclosure, the following parameters may also be present in the authentication response message. --Authentication response message identity, authentication response parameter, and EAP message.
[0237] - Authentication result message: This message is sent from AMF70 to UE3. In addition to the parameters disclosed in this disclosure, the following parameters may also be present in the authentication result message. --ngKSI, EAP message, and ABBA.
[0238] - Authentication failure message: This message is sent from UE3 to AMF70. In addition to the parameters disclosed in this disclosure, the following parameters may also be present in the authentication failure message. --Authentication failure message identity, 5GMM cause, and authentication failure parameter.
[0239] - Authentication denial message: This message is sent from AMF70 to UE3. In addition to the parameters disclosed in this aspect of disclosure, the following parameters may also be present in the authentication denial message. --EAP message.
[0240] - Service request message: This message is sent from UE3 to AMF70. In addition to the parameters disclosed in this aspect of disclosure, the following parameters may also be present in the service request message. --ngKSI, Service type, 5G-S-TMSI, Uplink data status, PDU session status, Allowed PDU session status, NAS message container.
[0241] - Service authorization message: This message is sent from AMF70 to UE3. In addition to the parameters disclosed in this manner, the following parameters may also be present in the service authorization message. --PDU session status, PDU session reactivation result, PDU session reactivation result error cause, EAP message, and T3448 value.
[0242] - Denial of Service Message: This message is sent from AMF70 to UE3. In addition to the parameters disclosed in this manner, the following parameters may also be present in the denial of service message. --5GMM cause, PDU session status, T3346 value, EAP message, T3448 value, and CAG information list.
[0243] -Configuration update command message: This message is sent from AMF70 to UE3. In addition to the parameters disclosed in this aspect of disclosure, the following parameters may also be present in the configuration update command message. --Configuration update indication, 5G-GUTI, TAI list, Allowed NSSAI, Service area list, Full name for network, Short name for network, Local time zone, Universal time and local time zone, Network daylight saving time, LADN information, MICO indication, Network slicing indication, Configured NSSAI, Rejected NSSAI, Operator-defined access category definitions, SMS indication, T3447 value, CAG information list, UE radio capability ID, UE radio capability ID deletion indication (indication), 5GS registration result, Truncated 5G-S-TMSI configuration, Additional configuration indication, and Extended rejected NSSAI.
[0244] -Configuration update complete message: This message is sent from UE3 to AMF70. In addition to the parameters disclosed in this disclosure, the following parameters may also be present in the configuration update complete message. --Configuration update complete message identity.
[0245] <User Equipment (UE)> Figure 7 is a block diagram showing the main components of UE3 (Mobile Device 3). As shown, UE3 includes a transceiver circuit 31, which is operable to transmit signals to and receive signals from connected nodes via one or more antennas 32. Furthermore, UE3 may include a user interface 34 for inputting or outputting information externally. Although not necessarily shown in the figure, UE3 may have all the usual functions of a conventional mobile device, which may be provided by any one or any combination of hardware, software, and firmware, as needed. For example, the software may be pre-installed in memory and / or downloaded via a telecommunications network or from a removable data storage device (RMD). The controller 33 controls the operation of UE3 according to the software stored in memory 36. The software includes, in particular, an operating system 361, an application 363, and a communication control module 362 having at least a transceiver control module 3621. Application 363 is an application that provides services to users of UE3 and / or machine-type services. Application 363 generates uplink data packets and transmits these uplink data packets via antenna 32 by communicating with communication control module 362. Conversely, if downlink data packets received by antenna 32 are destined for application 363, application 363 receives the downlink data packets from communication control module 362. One or more applications 363 may reside in memory 36. Application 363 may include APP1 (Application 1) 36301 and APP2 (Application 2) 36302.The communication control module 362 (using its transceiver control module 3621) is responsible for processing (generating / transmitting / receiving) signaling and uplink / downlink data packets between the UE3 and other nodes such as the (R)AN node 5 and AMF70. Such signaling may include appropriately formatted signaling messages (e.g., registration request messages and associated response messages) relating to access and mobility management procedures (for the UE3). The controller 33 interacts with one or more Universal Subscriber Identity Modules (USIMs) 35. If there are multiple USIMs 35, the controller 33 may activate only one USIM 35 or multiple USIMs 35 simultaneously.
[0246] UE3 can support, for example, Non-Public Networks (NPNs). An NPN can be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0247] UE3 may be, for example, items of equipment for production or manufacturing, and / or items of energy-related machinery (e.g., boilers, engines, turbines, solar panels, wind turbines, hydroelectric generators, thermal power generators, nuclear power generators, batteries, nuclear systems and / or related equipment, heavy electrical machinery, pumps including vacuum pumps, compressors, fans, blowers, hydraulic equipment, pneumatic equipment, metalworking machinery, manipulators, robots and / or their application systems, tools, molds or dies, rolls, conveying equipment, lifting equipment, material handling equipment, textile machinery, sewing machinery, printing machinery and / or related machinery, paperwork machinery, chemical machinery, mining machinery and / or construction machinery and / or related equipment, machinery and / or equipment for agriculture, forestry and / or fishing, safety and / or environmental protection equipment, tractors, precision bearings, chains, gears, power transmission equipment, lubrication equipment, valves, pipe fittings, and / or application systems for any of the aforementioned equipment or machinery).
[0248] UE3 can be, for example, transportation equipment items (e.g., vehicles, automobiles, motorcycles, bicycles, trains, buses, carts, rickshaws, ships and other vessels, aircraft, rockets, satellites, drones, balloons and other transportation equipment).
[0249] UE3 can be, for example, an item of information and communication equipment (e.g., electronic computers and related equipment, communication and related equipment, electronic components, and other information and communication equipment).
[0250] UE3 may include, for example, refrigeration machines, refrigeration machine applications, items of commercial and / or service industry equipment, vending machines, automated service machines, office machines or equipment, consumer electronics and electronic devices (e.g., consumer electronic devices such as audio equipment, video equipment, loudspeakers, radios, televisions, microwave ovens, rice cookers, coffee machines, dishwashers, washing machines, dryers, electronic fans or related appliances, vacuum cleaners, etc.).
[0251] UE3 may be, for example, an electrical application system or device (e.g., an electrical application system or device such as an X-ray system, particle accelerator, radioisotope device, sound wave device, electromagnetic application device, power application device, etc.).
[0252] UE3 may include, for example, electronic lamps, lighting fixtures, measuring instruments, analyzers, testers, or surveying or detection equipment (such as smoke detectors, human alarm sensors, motion sensors, wireless tags, etc.), wristwatches or wall clocks, laboratory equipment, optical devices, medical equipment and / or systems, weapons, cutlery items, hand tools, or similar items.
[0253] UE3 could be, for example, a wireless-equipped personal digital assistant or related device (such as a wireless card or module designed to be attached to or inserted into another electronic device, e.g., a personal computer, an electrical measuring instrument).
[0254] UE3 may be part of a device or system that uses various wired and / or wireless communication technologies to provide the applications, services, and solutions described below in relation to the Internet of Things (IoT).
[0255] An Internet of Things (IoT) device (or "Thing") may include appropriate electronics, software, sensors, network connectivity, and / or similar, so that it can collect and exchange data with each other and with other communication devices. IoT devices may include automated devices that follow software instructions stored in internal memory. IoT devices may operate without requiring human supervision or interaction. IoT devices may also remain stationary and / or stopped for extended periods. IoT devices may be implemented as part of (generally) fixed equipment. IoT devices may also be incorporated into non-fixed equipment (e.g., vehicles) or attached to animals or people being monitored / tracked.
[0256] Regardless of whether such communication devices are controlled by human input or by software instructions stored in memory, it will be understood that IoT technology can be implemented on any communication device that can connect to a communication network for sending / receiving data.
[0257] It will be understood that IoT devices are sometimes also referred to as Machine-Type Communication (MTC) devices, Machine-to-Machine (M2M) communication devices, or Narrow Band IoT UEs (NB-IoT UEs). It will be understood that UE3 can support one or more IoT or MTC applications.
[0258] UE3 can be a smartphone or a wearable device (e.g., smart glasses, a smartwatch, a smart ring, or a hearable device).
[0259] UE3 can be a car, connected car, autonomous vehicle, vehicle device, motorcycle, or Vehicle to Everything (V2X) communication module (e.g., vehicle-to-vehicle communication module, vehicle-to-infrastructure communication module, vehicle-to-person communication module, and vehicle-to-network communication module).
[0260] <(R)AN node> Figure 8 is a block diagram showing the main components of an exemplary (R)AN node 5, for example, a base station ("eNB" in LTE, "gNB" in 5G, a base station for Beyond 5G, a base station for 6G). As shown, the (R)AN node 5 includes a transceiver circuit 51 which is operable to transmit signals to and receive signals from connected UEs 3 via one or more antennas 52, and to transmit signals to and receive signals from other network nodes via a network interface 53 (directly or indirectly). A controller 54 controls the operation of the (R)AN node 5 according to software stored in memory 55. For example, the software may be pre-installed in memory and / or downloaded via a telecommunications network or from a removable data storage device (RMD). The software includes, in particular, an operating system 551 and a communication control module 552 having at least a transceiver control module 5521.
[0261] The communication control module 552 (using its transceiver control sub-module) is responsible for processing (generating / sending / receiving) signaling between the (R)AN node 5 and other nodes such as the UE 3, another (R)AN node 5, the AMF 70, and the UPF 72, either directly or indirectly. The signaling may include, for example, properly formatted signaling messages (such as RRC connection establishment messages and other RRC messages), NG Application Protocol (NGAP) messages (i.e., messages based on the N2 reference point), Xn Application Protocol (XnAP) messages (i.e., messages based on the Xn reference point), etc., regarding the radio connection and connection to the core network 7 for a particular UE 3, especially regarding connection establishment and maintenance. Such signaling may also include, in the case of transmission, for example, broadcast information (such as master information and system information).
[0262] When implemented, the controller 54 is also configured (by software or hardware) to handle related tasks such as UE mobility estimation and / or movement trajectory estimation.
[0263] The (R)AN node 5 may support a Non-Public Network (NPN). The NPN may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN). The Master Node (MN) 501 and the Secondary Node (SN) 502 may have the same components as the (R)AN node 5.
[0264] <System Overview of the (R)AN Node 5 Based on the O-RAN Architecture> Figure 9 schematically shows an (R)AN node 5 based on an O-RAN architecture to which the (R)AN node 5 configuration can be applied.
[0265] A (R)AN node 5 based on the O-RAN architecture represents a system overview in which the (R)AN node is separated into a Radio Unit (RU) 60, a Distributed Unit (DU) 61, and a Centralized Unit (CU) 62. In some embodiments, each unit may be combined. For example, RU 60 may be integrated / coupled with DU 61 as an integration / coupling unit, and DU 61 may be integrated / coupled with CU 62 as another integration / coupling unit. Any function in the description of a unit (e.g., one of RU 60, DU 61, and CU 62) may be implemented in the above integration / coupling unit. Furthermore, CU 62 may be separated into two functional units, such as a Control plane (CP) and a User plane (UP). CU CP has control plane functionality in (R)AN node 5. CU UP has user plane functionality in (R)AN node 5. Each CU CP is connected to a CU UP via an appropriate interface (such as the so-called "E1" interface and / or similar).
[0266] UE3 and each serving RU60 are connected via appropriate air interfaces (e.g., so-called "Uu" interfaces and / or similar). Each RU60 is connected to DU61 via appropriate interfaces (such as so-called "fronthaul," "open fronthaul," "F1" interfaces, and / or similar). Each DU61 is connected to CU62 via appropriate interfaces (such as so-called "midhaul," "open midhaul," "E2" interfaces, and / or similar). Each CU62 is also connected to nodes in the core network 7 (such as so-called core network nodes) via appropriate interfaces (such as so-called "backhaul," "open backhaul," "N2" / "N3" interfaces, and / or similar). In addition, the user plane portion of DU61 may also be connected to core network node 7 via appropriate interfaces (such as so-called "N3" interfaces and / or similar).
[0267] Depending on the functions separated between RU60, DU61, and CU62, each unit provides a portion of the functions provided by (R)AN node 5. For example, RU60 may provide the function to communicate with UE3 on the air interface, DU61 may provide the function to support the MAC and RLC layers, and CU62 may provide the function to support the PDCP, SDAP, and RRC layers.
[0268] <Radio Unit (RU)> Figure 10 is a block diagram showing the main components of the RU portion of an exemplary RU60, for example, a base station (eNB in LTE, gNB in 5G, base station for Beyond 5G, base station for 6G). As shown, the RU60 includes a transceiver circuit 601 which is operable to transmit signals to and receive signals from connected UE3 via one or more antennas 602, and transmit signals to and receive signals from other network nodes or network units via the network interface 603 (directly or indirectly). The controller 604 controls the operation of the RU60 according to software stored in memory 605. For example, the software may be pre-installed in memory and / or downloaded via a telecommunications network or from a removable data storage device (RMD). The software includes, in particular, an operating system 6051 and a communication control module 6052 having at least a transceiver control module 60521.
[0269] The communication control module 6052 (using its transceiver control submodule) is responsible for processing (generating / transmitting / receiving) signaling between RU60 and other nodes or units such as UE3, another RU60, and DU61 (for example, directly or indirectly). The signaling may include appropriately formatted signaling messages relating to the radio connection and connectivity with RU60 (for a particular UE3), particularly concerning the MAC and RLC layers.
[0270] The controller 604, once implemented, is also configured (by software or hardware) to handle related tasks such as UE mobility estimation and / or movement trajectory estimation.
[0271] The RU60 may support Non-Public Networks (NPNs). An NPN can be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0272] As described above, RU60 can be integrated / coupled to DU61 as an integration / coupling unit. Any functions described in the description of RU60 can be implemented in the above integration / coupling unit.
[0273] <Distributed Unit (DU)> Figure 11 is a block diagram showing the main components of the DU portion of an exemplary DU61, for example, a base station ("eNB" in LTE, "gNB" in 5G, a base station for Beyond 5G, a base station for 6G). As shown, the device includes a transceiver circuit 611, which is operable to transmit signals to and receive signals from other nodes or units (including RU60) via a network interface 612. A controller 613 controls the operation of the DU61 according to software stored in memory 614. For example, the software may be pre-installed in memory 614 and / or downloaded via a telecommunications network or from a removable data storage device (RMD). The software includes, in particular, an operating system 6141 and a communication control module 6142 having at least a transceiver control module 61421. The communication control module 6142 is responsible for processing (generating / transmitting / receiving) signaling between DU61 and other nodes or units such as RU60 and other nodes and units, using its transceiver control module 61421.
[0274] DU61 may support Non-Public Networks (NPNs). An NPN can be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0275] As described above, RU60 can be integrated / coupled to DU61 or CU62 as an integration / coupling unit. Any function described in the description of DU61 can be implemented in one of the above integration / coupling units.
[0276] <Centralized Unit (CU)> Figure 12 is a block diagram showing the main components of the CU portion of an exemplary CU62, for example, a base station ("eNB" in LTE, "gNB" in 5G, a base station for Beyond 5G, a base station for 6G). As shown, the device includes a transceiver circuit 621, which is operable to transmit signals to and receive signals from other nodes or units (including DU61) via a network interface 622. A controller 623 controls the operation of the CU62 according to software stored in memory 624. For example, the software may be pre-installed in memory 624 and / or downloaded via a telecommunications network or from a removable data storage device (RMD). The software includes, in particular, an operating system 6241 and a communication control module 6242 having at least a transceiver control module 62421. The communication control module 6242 (using its transceiver control module 62421) is responsible for processing (generating / transmitting / receiving) signaling between CU62 and other nodes or units such as DU61 and other nodes and units.
[0277] CU62 may support Non-Public Networks (NPNs). An NPN can be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0278] As described above, CU62 can be integrated / coupled to DU61 as an integration / coupling unit. Any functions described for CU62 can be implemented in the above-mentioned integration / coupling unit.
[0279] <amf> Figure 13 is a block diagram showing the main components of the AMF70. As shown, the device includes a transceiver circuit 701, which is operable to transmit signals to and receive signals from other nodes (including UE3, RAN5, and SMF71) via a network interface 702. A controller 703 controls the operation of the AMF70 according to software stored in memory 704. For example, the software may be pre-installed in memory 704 and / or downloaded via a telecommunications network or from a removable data storage device (RMD). The software includes, in particular, an operating system 7041 and a communication control module 7042 having at least a transceiver control module 70421. The communication control module 7042 is responsible for processing (generating / transmitting / receiving) signaling between the AMF 70 and other nodes, such as UE3 (e.g., via (R)AN node 5) and other core network nodes, including the core network node in HPLMN of UE3 when UE3 is roaming in. Such signaling may include appropriately formatted signaling messages (e.g., registration request messages and associated response messages) relating to access and mobility management procedures (for UE3).
[0280] The AMF70 may support Non-Public Networks (NPNs). An NPN can be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN). The AMF7001 and AMF7002 may have the same components as the AMF70.
[0281] <smf> Figure 14 is a block diagram showing the main components of the SMF71. As shown, the device includes a transceiver circuit 711, which is operable to transmit signals to and receive signals from other nodes (including AMF70 and UPF72) via a network interface 712. A controller 713 controls the operation of the SMF71 according to software stored in memory 714. For example, the software may be pre-installed in memory 714 and / or downloaded via a telecommunications network or from a removable data storage device (RMD). The software includes, in particular, an operating system 7141 and a communication control module 7142 having at least a transceiver control module 71421. The communication control module 7142 is responsible for handling (generating / transmitting / receiving) signaling between the SMF 71 and other nodes, such as the UPF 72 and other core network nodes, including the core network node in the HPLMN of the UE3 when the UE3 is roaming in. Such signaling may include, for example, appropriately formatted signaling messages (e.g., Hypertext Transfer Protocol (HTTP) RESTful methods based on a service-based interface) relating to session management procedures (for the UE3).
[0282] SMF71 may support Non-Public Networks (NPNs). An NPN can be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0283] <upf> Figure 15 is a block diagram showing the main components of UPF72. As shown, the device includes a transceiver circuit 721, which is operable to transmit signals to and receive signals from other nodes (including SMF71) via a network interface 722. A controller 723 controls the operation of UPF72 according to software stored in memory 724. For example, the software may be pre-installed in memory 724 and / or downloaded via a telecommunications network or from a removable data storage device (e.g., a removable memory device (RMD)). The software includes, in particular, an operating system 7241 and a communication control module 7242 having at least a transceiver control module 72421. The communication control module 7242 is responsible for handling (generating / transmitting / receiving) signaling between UPF72 and other nodes, such as SMF71 and other core network nodes, including the core network node in the HPLMN of UE3 when UE3 is roaming in. Such signaling may include, for example, appropriately formatted signaling messages (e.g., GPRS Tunneling Protocol (GTP) for the user plane) relating to user data processing (about UE3).
[0284] UPF72 may support Non-Public Networks (NPNs). An NPN can be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0285] A juxtaposed gNB-CU-UP and UPF, or a communication device that performs the functions of a juxtaposed gNB-CU-UP and UPF, or a communication device that performs the functions of a gNB-CU-UP and a UPF, may have the same components as the UPF72.
[0286] <pcf> Figure 16 is a block diagram showing the main components of PCF73. As shown, the device includes a transceiver circuit 731, which is operable to transmit signals to and receive signals from other nodes (including AMF70) via a network interface 732. A controller 733 controls the operation of PCF73 according to software stored in memory 734. For example, the software may be pre-installed in memory 734 and / or downloaded via a telecommunications network or from a removable data storage device (e.g., a removable memory device (RMD)). The software includes, in particular, an operating system 7341 and a communication control module 7342 having at least a transceiver control module 73421. The communication control module 7342 (using its transceiver control module 73421) is responsible for handling (generating / transmitting / receiving) signaling between the PCF73 and other nodes, such as the AMF70 and other core network nodes, including the core network node in the HPLMN of the UE3 when the UE3 is roaming in. Such signaling may include, for example, appropriately formatted signaling messages (e.g., HTTP RESTful methods based on a service-based interface) relating to policy management procedures (about the UE3).
[0287] PCF73 may support Non-Public Networks (NPNs). An NPN can be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN). PCF7301 and PCF7302 may have the same components as PCF73.
[0288] <ausf> Figure 17 is a block diagram showing the main components of AUSF74. As shown, the device includes a transceiver circuit 741, which is operable to transmit signals to and receive signals from other nodes (including UDM75) via a network interface 742. A controller 743 controls the operation of AUSF74 according to software stored in memory 744. For example, the software may be pre-installed in memory 744 and / or downloaded via a telecommunications network or from a removable data storage device (e.g., a removable memory device (RMD)). The software includes, in particular, an operating system 7441 and a communication control module 7442 having at least a transceiver control module 74421. The communication control module 7442 (using its transceiver control module 74421) is responsible for handling (generating / transmitting / receiving) signaling between AUSF74 and other nodes, such as AMF70 and other core network nodes, including the core network node in the HPLMN of UE3 when UE3 is roaming in. Such signaling may include, for example, appropriately formatted signaling messages (e.g., HTTP RESTful methods based on service-based interfaces) relating to policy management procedures (about UE3).
[0289] AUSF74 may support Non-Public Networks (NPNs). An NPN can be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0290] <udm> Figure 18 is a block diagram showing the main components of the UDM 75. As shown, the device includes a transceiver circuit 751, which is operable to transmit signals to and receive signals from other nodes (including the AMF 70) via a network interface 752. A controller 753 controls the operation of the UDM 75 according to software stored in memory 754. For example, the software may be pre-installed in memory 754 and / or downloaded via a telecommunications network or from a removable data storage device (RMD). The software includes, in particular, an operating system 7541 and a communication control module 7542 having at least a transceiver control module 75421. The communication control module 7542 (using its transceiver control module 75421) is responsible for handling (generating / transmitting / receiving) signaling between the UDM 75 and other nodes, such as the AMF 70 and other core network nodes, including the core network node in the VPLMN of the UE3 when the UE3 is roaming out. Such signaling may include, for example, appropriately formatted signaling messages (e.g., HTTP RESTful methods based on a service-based interface) relating to mobility management procedures (about the UE3).
[0291] The UDM75 may support Non-Public Networks (NPNs). An NPN can be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).
[0292] Exemplary aspects of the above disclosure may be described as follows, but are not limited to the following:
[0293] 1 background This contribution proposes a solution to key issue #2, namely, the 5GC's perception of URSP implementation.
[0294] 6.X Solution #X: Verifying UE URSP implementation via network 6.X.1 Description Editor's Note: This section describes the principles of the solution and the assumptions of the corresponding architecture.
[0295] This solution addresses critical issue #2, namely the following requirements based on the 5GC's recognition of URSP implementation.
[0296] - Can the UE enforce URSP rules and route application traffic to PDU sessions based on URSP rules provisioned by 5GC, or if so, make 5GC aware of this, and how can 5GC be made aware of it?
[0297] - Is there any action that 5GC can take after it recognizes whether the UE enforces URSP rules for specific application traffic? If so, what action should 5GC take?
[0298] This solution enables UE implementation to correctly adhere to URSP rules regarding traffic matching. The solution introduces application identification parameters provisioned to the PCF by the UE during the PDU session establishment procedure. To verify whether the UE correctly implements the traffic matching rules in URSP for applications requesting services, the PCF performs a URSP validity check. If the PCF finds that the UE is not correctly adhering to the URSP rules, the PDU session is rejected for a new reason indicating non-compliance with either general or specific URSP rules. The PCF may also optionally trigger a UE policy update procedure to refresh the URSP rules in the UE with the latest version of the URSP rules.
[0299] 6.X.2 Procedure Editor's Note: This section outlines high-level procedures and information flows for the solution.
[0300] Figure 6.X.2: Verification of UE implementation via network (see Figure 19)
[0301] 1. An application in the UE requests a service. The UE initiates a PDU session establishment request message, which includes the UE_ID, PDU session ID, S-NSSAI, and DNN. The UE selects the S-NSSAI and DNN based on the URSP rules applicable to the application requesting the service. The UE also includes the application's App_ID in the PDU session establishment request message.
[0302] 2. SMF selection by AMF.
[0303] 3. The AMF executes an Nsmf_PDUSession_CreateSMContext_Request message to the SMF if no association exists with the SMF, or an Nsmf_PDUSession_UpdateSMContext_Request message if the AMF is already associated with the SMF. Along with the UE_ID, S-NSSAI, DNN, and user location parameters, the AMF also forwards the App_ID received by the UE to the SMF.
[0304] 4. Continue the PDU session establishment procedure according to steps 4-7a of section 4.3.2.2.1 of TS23.502.
[0305] 5. The SMF initiates the SM policy association establishment procedure, sending the Npcf_SMPpolicy_Control_Create message to the PCF, which includes the UE_ID, S-NSSAI, DNN, user location, and App_ID parameters in the Npcf_SMPpolicy_Control_Create message.
[0306] 6. The PCF performs URSP validity checks for the UE. The PCF retrieves the latest version of the URSP rules stored for the UE and verifies whether the UE correctly adheres to the S-NSSAI selection rules, DNN selector rules, time window criteria, and position criteria.
[0307] 7. If the URSP validity check by the PCF indicates that the UE is not correctly following one or more of the traffic matching rules in the latest version of URSP, the PCF returns a Failure parameter in its Npcf_SMPpolicy_Control_Create response to the SMF. The PCF may also include a more specific rejection reason, such as the cause of the failure, e.g., non-compliance with a URSP rule, or identifying the specific URSP rule that the UE is not following.
[0308] 8. SMF forwards the reason for rejection to AMF in the Nsmf_PDUSession_CreateSMContext_Response message.
[0309] 9. The AMF rejects the PDU session establishment request from the UE, and the AMF includes a rejection reason that the URSP rules are not followed, or a more specific rejection reason that indicates which URSP rules are not followed (e.g., not following the S-NSSAI selection rule, not following the DNN selection rule, not following the time window criterion, or not following the position criterion).
[0310] 10. If the URSP validity check by the PCF fails in step 6, the PCF may assume that the UE does not have the latest URSP rules, and therefore the PCF may trigger the UE policy update procedure in accordance with Section 4.2.4.3 of TS23.502 to refresh the UE with the latest URSP rules.
[0311] 11. UE policy update in accordance with Section 4.2.4.3 of TS23.502
[0312] 6.X.3 Impact on Services, Entities, and Interfaces Editor's note: This clause describes the impact on existing 3GPP nodes and functional elements.
[0313] UE, AMF, SMF - New App_ID parameter and new PDU session establishment rejection cause.
[0314] PCF - New APP ID parameter and URSP validity verification function.
[0315] <Corrections and Alterations> Detailed embodiments are described above. Those skilled in the art will understand that numerous modifications and substitutions can be made to the above embodiments, still benefiting from the disclosure as embodied herein. Numerous such substitutions and modifications are described herein merely as examples.
[0316] In the above description, the UE3 and network device are described as having a number of separate modules (such as communication control modules) for ease of understanding. These modules may thus be provided, for example, in a system designed from the outset to take the features of the invention into consideration, for other applications, for example, in an existing system that has been modified to implement the disclosure, but these modules may not be recognizable as separate entities, as they may be built within an overall operating system or code. These modules may also be implemented in software, hardware, firmware, or a combination thereof.
[0317] Each controller may include, but is not limited to, one or more hardware-implemented computer processors, microprocessors, central processing units (CPUs), arithmetic logic units (ALUs), input / output (IO) circuits, internal memory / cache (for programs and / or data), processing registers, communication buses (e.g., control buses, data buses, and / or address buses), direct memory access (DMA) functions, hardware or software-implemented counters, pointers and / or timers, and / or similar.
[0318] In the above embodiments, numerous software modules have been described. Those skilled in the art will understand that the software modules may be provided in compiled or uncompiled form and may be supplied to the UE3 and network devices as signals on a computer network or on a recording medium. Furthermore, some or all of the functions performed by the software may be performed using one or more dedicated hardware circuits. However, the use of software modules is preferred for updating the functions of the UE3 and network devices in order to facilitate updates to the UE3 and network devices.
[0319] In the above embodiment, 3GPP wireless communication (wireless access) technology is used. However, any other wireless communication technology (e.g., WLAN, Wi-Fi, WiMAX, Bluetooth, etc.) and other fixed-line communication technology (e.g., BBF access, cable access, optical access, etc.) may also be used in accordance with the above embodiment.
[0320] User device items may include, for example, communication devices such as mobile phones, smartphones, personal digital assistants, laptop / tablet computers, web browsers, e-book readers, and / or similar devices. Such mobile (and generally fixed) devices are typically operated by a user, but it is also possible to connect so-called "Internet of Things (IoT)" devices and similar machine-type communication (MTC) devices to a network. For simplicity, this application refers to mobile devices (or UEs) in the description, but it will be understood that the technologies described may be implemented on any (mobile and / or generally fixed) communication devices that can connect to a communication network to transmit / receive data, whether such communication devices are controlled by human input or by software instructions stored in memory.
[0321] Various other modifications are obvious to those skilled in the art, and therefore no further details are provided here.
[0322] As those skilled in the art will understand, this disclosure can be embodied as a method and a system. Accordingly, this disclosure may take the form of a complete hardware embodiment, a software embodiment, or an embodiment combining software and hardware aspects.
[0323] It will be understood that each block in a block diagram can be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general-purpose computer, a dedicated computer, or other programmable data processing device to generate a machine, and as a result, instructions executed through the processor of the computer or other programmable data processing device generate means for implementing the functions / actions specified in the blocks or blocks(s) of the flowchart and / or block diagram. A general-purpose processor may be a microprocessor, but alternatively, the processor may be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented as a computing device, e.g., multiple microprocessors, one or more microprocessors, or any other combination of such configurations.
[0324] Methods or algorithms described in connection with the examples disclosed herein may be directly embodied in hardware, software modules executed by a processor, or a combination of both. The software modules may reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disks, removable disks, CD-ROMs, or any other form of storage medium known in the art. The storage medium may be connected to the processor so that the processor can read information from and write information to the storage medium. Alternatively, the storage medium may be integrated into the processor. The processor and storage medium may reside in an ASIC.
[0325] The prior description relating to the examples of this disclosure is provided to enable any person skilled in the art to make or use the disclosure. Various modifications to such examples will be readily apparent to a person skilled in the art, and the general principles set forth herein may be applied to other examples without departing from the spirit or scope of this disclosure. Accordingly, this disclosure is not intended to be limited to the examples shown herein, but should be given the broadest scope consistent with the principles and novel features disclosed herein.
[0326] While this disclosure has been described in detail with reference to exemplary embodiments thereof, this disclosure is not limited to such embodiments. Those skilled in the art will understand that various modifications in form and detail are possible without departing from the intent and scope of this disclosure as defined herein. For example, the embodiments described above are not limited to 5GS, and are applicable to other communication systems (e.g., 6G systems, Beyond 5G systems).
[0327] <Note> All or part of the exemplary aspects of the above disclosure may be described as follows, but are not limited to the following appendices.
[0328] Note 1. We received a policy regarding user equipment (UE). Information related to the application in the aforementioned UE is received from the UE, Verify whether the aforementioned information is consistent with the aforementioned policy. If the aforementioned information is inconsistent with the aforementioned policy, a rejection message will be sent. Methods for communication devices.
[0329] Note 2. A method for user equipment (UE), wherein the method is Send the first message, The first message includes first information relating to the application in the UE, After sending the first message, and receiving the second message, The aforementioned second message contains the second piece of information, The second piece of information indicates that the application is rejected. If the second message is received, the use of the application is stopped. method.
[0330] Note 3. Upon receiving information regarding the policy concerning user equipment (UE) and indicating that verification of the data of said UE is required, After receiving the aforementioned information, we verify whether the data is consistent with the policy. If the aforementioned data is inconsistent with the aforementioned policy, the communications related to the aforementioned data will be deactivated. Methods for communication devices.
[0331] Note 4. We received a policy regarding user equipment (UE). Upon receiving a service request message, The service request message includes an identifier for the application in the UE, Check whether the identifier is consistent with the policy, If the identifier is consistent with the policy, an approval message is sent. If the identifier does not conform to the policy, a rejection message will be sent. Methods for communication devices.
[0332] Note 5. A method for user equipment (UE), wherein the method is If the UE has an established PDU session, it sends a service request message. The service request message includes an identifier for the application in the UE, After sending the aforementioned service request message, the first message is received. If the first message is an approval message, send the data. If the first message is a rejection message, stop using the application. method.
[0333] Note 6. We received a policy regarding user equipment (UE). Send a request to transmit the application identifier in the aforementioned UE, Upon receiving the aforementioned identifier, Check whether the identifier is consistent with the policy, After verifying whether the identifier is consistent with the policy, send the message. The message includes at least one of the following: information indicating permitted applications and information indicating prohibited applications. Methods for communication devices.
[0334] Note 7. A method for user equipment (UE), wherein the method is Upon receiving a request to transmit the application identifier in the aforementioned UE, Send the aforementioned identifier, After sending the aforementioned identifier, receive a message, The message includes at least one of the following: information indicating permitted applications and information indicating prohibited applications. After receiving the aforementioned message, stop using the unauthorized application. method.
[0335] Note 8. Means for receiving policies regarding user equipment (UE), A means for receiving information related to the application in the aforementioned UE from the aforementioned UE, A means for verifying whether the aforementioned information is consistent with the aforementioned policy, If the aforementioned information is inconsistent with the aforementioned policy, means for sending a rejection message, A communication device equipped with the following features.
[0336] Note 9. User equipment (UE), A means for sending a first message, The first message includes means, which include first information relating to the application in the UE, A means for receiving a second message after sending the first message, The aforementioned second message contains the second piece of information, The second piece of information includes means for indicating that the application is rejected, When the second message is received, means for stopping the use of the application, A UE equipped with
[0337] Note 10. A means for receiving information regarding policies concerning user equipment (UE) and information indicating that verification of the UE's data is required, After receiving the aforementioned information, means for verifying whether the data is consistent with the aforementioned policy, If the aforementioned data is inconsistent with the aforementioned policy, means for deactivating communications related to the aforementioned data, A communication device equipped with the following features.
[0338] Note 11. Means for receiving policies regarding user equipment (UE), A means for receiving a service request message, The service request message includes means, which include an application identifier in the UE, A means for verifying whether the identifier is consistent with the policy, If the identifier is consistent with the policy, means for sending an approval message, If the identifier is inconsistent with the policy, means for sending a rejection message, A communication device equipped with the following features.
[0339] Note 12. User equipment (UE), If the UE has an established PDU session, means for sending a service request message, The service request message includes means, which include an application identifier in the UE, After sending the aforementioned service request message, means for receiving the first message, If the first message is an approval message, means for sending data, If the first message is a rejection message, means for stopping the use of the application, A UE equipped with
[0340] Note 13. Means for receiving policies regarding user equipment (UE), Means for sending a request to transmit an application identifier in the aforementioned UE, means for receiving the identifier, A means for verifying whether the identifier is consistent with the policy, A means for sending a message after confirming whether the identifier is consistent with the policy, The message includes means that include at least one of information indicating an allowed application and information indicating an unallowed application. A communication device equipped with the following features.
[0341] Note 14. User equipment (UE), A means for receiving a request to transmit an application identifier in the aforementioned UE, Means for transmitting the identifier, A means for receiving a message after transmitting the identifier, The message includes means that include at least one of information indicating an allowed application and information indicating an unallowed application. After receiving the aforementioned message, means to stop the use of the unauthorized application, A UE equipped with
[0342] Note 15 The second device receives policy information regarding the communication terminal. The communication terminal receives information regarding the application for the communication terminal from the aforementioned communication terminal. The system checks whether the information regarding the application for the communication terminal is consistent with the policy information regarding the communication terminal. If the information regarding the application for the communication terminal does not match the policy information regarding the communication terminal, information related to rejection is sent to the communication terminal. Method of the first apparatus.
[0343] Note 16 The second device stores policy information regarding the communication terminal, The communication terminal receives information regarding the application for the communication terminal from the aforementioned communication terminal. The system checks whether the information regarding the application for the communication terminal is consistent with the policy information regarding the communication terminal. If the information relating to the application for the communication terminal does not match the policy information relating to the communication terminal, information related to rejection is transmitted to the first device. The method of the third apparatus.
[0344] Note 17. The second device stores policy information regarding the communication terminal, The third device for session management receives information regarding the application of the communication terminal. The third device for session management receives information indicating that verification of data related to the communication terminal is required. Based on the information indicating that verification of data related to the communication terminal is required, it is checked whether the information regarding the application for the communication terminal is consistent with the policy information regarding the communication terminal (UE). If the information relating to the application for the communication terminal does not match the policy information relating to the communication terminal, information related to rejection is transmitted. The method of the fourth apparatus.
[0345] Note 18. A method for communication terminals, A service request message containing information about the application for the aforementioned communication terminal is sent to the first device. The first device stores policy information regarding the communication terminal from the second device. The first device verifies whether the information relating to the application for the communication terminal is consistent with the policy information relating to the communication terminal. If the information relating to the application for the communication terminal does not match the policy information relating to the communication terminal, the first device transmits information relating to rejection to the communication terminal. method.
[0346] Note 19. A method for communication terminals, A service request message containing information about the application for the aforementioned communication terminal is sent to the first device. The first device stores policy information regarding the communication terminal from the second device. The first device verifies whether the information relating to the application for the communication terminal is consistent with the policy information relating to the communication terminal. If the information relating to the application for the communication terminal is consistent with the policy information relating to the communication terminal, the first device transmits information related to approval to the communication terminal. method.
[0347] Note 20. The second device stores policy information regarding the communication terminal, A service request message containing information about the application for the aforementioned communication terminal is received from the aforementioned communication terminal. The system checks whether the information regarding the application for the communication terminal is consistent with the policy information regarding the communication terminal. If the information regarding the application for the communication terminal does not match the policy information regarding the communication terminal, information related to rejection is sent to the communication terminal. Method of the first apparatus.
[0348] Note 21. A method for the first apparatus, The second device stores policy information regarding the communication terminal, A service request message containing information about the application for the aforementioned communication terminal is received from the aforementioned communication terminal. The system checks whether the information regarding the application for the communication terminal is consistent with the policy information regarding the communication terminal. If the information relating to the application for the communication terminal is consistent with the policy information relating to the communication terminal, the approval-related information is transmitted to the communication terminal. Method of the first apparatus.
[0349] Note 22. The second device stores policy information regarding the communication terminal, A request message regarding application information for the aforementioned communication terminal is sent to the aforementioned communication terminal. The communication terminal receives the information relating to the application for the communication terminal from the communication terminal. The system checks whether the information regarding the application for the communication terminal is consistent with the policy information for the communication terminal. If the information relating to the application for the communication terminal does not match the policy information relating to the communication terminal, information related to rejection is sent to the communication terminal. Method of the first apparatus.
[0350] Note 23. The second device stores policy information regarding the communication terminal, A request message regarding application information for the aforementioned communication terminal is sent to the aforementioned communication terminal. The communication terminal receives the information relating to the application for the communication terminal from the communication terminal. The system checks whether the information regarding the application for the communication terminal is consistent with the policy information for the communication terminal. If the information relating to the application for the communication terminal is consistent with the policy information relating to the communication terminal, the information related to approval is transmitted to the communication terminal. Method of the first apparatus.
[0351] <Note 2> Note 1. The core network node receives at least one of the following: User Equipment ID (UE ID), Data Network Name (DNN), Single-Network Slice Selection Assistance Information (S-NSSAI), and information related to UE Route Selection Policy (URSP) rules. The system verifies whether the user data for a User Equipment (UE) that uses a User Equipment (UE) session together with the aforementioned DNN and S-NSSAI matches the information related to the UE Route Selection Policy (URSP) rules. The result of the above verification is transmitted to the core network node. Methods for implementing User Plane Functions (UPFs).
[0352] Note 2. The information related to the aforementioned URSP includes time information and location information. The method described in Appendix 1.
[0353] Note 3. The information related to the URSP is used by the UPF to determine whether the destination address of the user data matches the descriptor in the URSP rule. The method described in Appendix 1.
[0354] Note 4. The information related to the URSP is used by the UPF to determine whether the port number of the user data matches the descriptor in the URSP rule. The method described in Appendix 1.
[0355] Note 5. The information related to the URSP is used by the UPF to determine whether the protocol of the user data matches the descriptor in the URSP rule. The method described in Appendix 1.
[0356] Note 6. Memory and At least one processor configured to access the aforementioned memory, Equipped with, The aforementioned at least one processor is The core network node receives at least one of the following: User Equipment ID (UE ID), Data Network Name (DNN), Single-Network Slice Selection Assistance Information (S-NSSAI), and information related to UE Route Selection Policy (URSP) rules. The system verifies whether the user data for a User Equipment (UE) that uses a User Equipment (UE) session together with the aforementioned DNN and S-NSSAI matches the information related to the UE Route Selection Policy (URSP) rules. The results of the above verification are configured to be transmitted to the core network node. User Plane Function (UPF).
[0357] Note 7. The information related to the aforementioned URSP includes time information and location information. User Plane Function (UPF) as described in Appendix 6.
[0358] Note 8. The information related to the URSP is used by the UPF to determine whether the destination address of the user data matches the descriptor in the URSP rule. User Plane Function (UPF) as described in Appendix 6.
[0359] Note 9. The information related to the URSP is used by the UPF to determine whether the port number of the user data matches the descriptor in the URSP rule. User Plane Function (UPF) as described in Appendix 6.
[0360] Note 10. The information related to the URSP is used by the UPF to determine whether the protocol of the user data matches the descriptor in the URSP rule. User Plane Function (UPF) as described in Appendix 6.
[0361] Although the present invention has been described above with reference to embodiments (and examples), the present invention is not limited to the above embodiments (and examples). Various modifications to the structure and details of the present invention can be made, as can be understood by those skilled in the art within the scope of the present invention.
[0362] This application claims priority based on Indian Provisional Patent Application No. 202211016661, filed on 24 March 2022, and incorporates all of its disclosures herein. [Explanation of symbols]
[0363] 1. Telecommunications Systems 3 UE 5 (R)AN Node 7 Core Network 20 Data Networks 31 Transceiver Circuit 32 Antennas 33 Controllers 34 User Interface 35 USIM 36 memory 51 Transceiver Circuit 52 Antennas 53 Network Interfaces 54 Controllers 55 memory 60 RU 61 DU 62 CU 70 AMF 71 SMF 72 UPF 73 PCF 74 AUSF 75 UDM 76 NWDAF 361 Operating Systems 362 Communication control module 363 Applications 551 Operating Systems 552 Communication control module 601 Transceiver Circuit 602 Antenna 603 Network Interface 604 Controller 605 memory 611 Transceiver Circuit 612 Network Interfaces 613 Controller 614 memory 621 Transceiver Circuit 622 Network Interfaces 623 Controller 624 memory 701 Transceiver Circuit 702 Network Interface 703 Controller 704 memory 711 Transceiver Circuit 712 Network Interfaces 713 Controller 714 memory 721 Transceiver Circuit 722 Network Interfaces 723 Controller 724 memory 731 Transceiver Circuit 732 Network Interfaces 733 Controller 734 memory 741 Transceiver Circuit 742 Network Interfaces 743 Controller 744 memory 751 Transceiver Circuit 752 Network Interfaces 753 Controller 754 memory 3621 Transceiver Control Module 5521 Transceiver Control Module 6051 Operating System 6052 Communication Control Module 6141 Operating Systems 6142 Communication control module 6241 Operating Systems 6242 Communication control module 7041 Operating System 7042 Communication control module 7141 Operating Systems 7142 Communication control module 7241 Operating Systems 7242 Communication control module 7341 Operating Systems 7342 Communication control module 7441 Operating Systems 7442 Communication control module 7541 Operating Systems 7542 Communication control module 36301 APP1 36302 APP2 60521 Transceiver Control Module 61421 Transceiver Control Module 62421 Transceiver Control Module 70421 Transceiver Control Module 71421 Transceiver Control Module 72421 Transceiver Control Module 73421 Transceiver Control Module 74421 Transceiver Control Module 75421 Transceiver Control Module< / udm> < / ausf> < / pcf> < / upf> < / smf> < / amf>
Claims
1. The Session Management Function (SMF) receives at least one of the Data Network Name (DNN) and Single-Network Slice Selection Assistance Information (S-NSSAI), as well as information about the User Equipment (UE) application. Based on the information regarding the UE's application, it is determined whether at least one of the DNN and the S-NSSAI conforms to the UE Route Selection Policy rule (URSP rule). A method for implementing a Policy Control Function (PCF).
2. A UE Route Selection Policy rule (URSP rule) used to associate an application of a User Equipment (UE) with a Protocol Data Unit Session (PDU session) is transmitted to the UE. The method according to claim 1.
3. If the aforementioned URSP rule is not the latest URSP rule, update the URSP rule based on information about the application. The method according to claim 1.
4. If at least one of the DNN and the S-NSSAI does not conform to the URSP rule, update the URSP rule in the User Equipment (UE). The method according to claim 1.
5. The aforementioned reception and confirmation are related to the Protocol Data Unit Session Establishment (PDU session establishment) procedure. The method according to claim 1.
6. Receives information regarding URSP rule enforcement from User Equipment (UE). The method according to claim 3.
7. The DNN and the S-NSSAI are transmitted from the User Equipment (UE). The method according to claim 3.
8. Based on the information regarding the aforementioned application, the information regarding the implementation of the URSP rule is confirmed. The method according to claim 6.
9. A means for receiving at least one of the Data Network Name (DNN) and Single-Network Slice Selection Assistance Information (S-NSSAI) from the Session Management Function (SMF), and information regarding the application of the User Equipment (UE), A means for determining whether at least one of the DNN and the S-NSSAI conforms to the UE Route Selection Policy rule (URSP rule) based on information regarding the UE's application, A policy control function (PCF) that includes the following features.
10. A UE Route Selection Policy rule (URSP rule) used to associate an application of a User Equipment (UE) with a Protocol Data Unit Session (PDU session) is transmitted to the UE. The PCF according to claim 9.
11. If the aforementioned URSP rule is not the latest URSP rule, means for updating the URSP rule based on information about the application. The PCF according to claim 9, further comprising
12. If at least one of the DNN and the S-NSSAI does not conform to the URSP rule, means for updating the URSP rule in User Equipment (UE) The PCF according to claim 9, further comprising
13. The receiving means and the confirming means are related to the Protocol Data Unit Session Establishment (PDU session establishment) procedure. The PCF according to claim 9.
14. Means for receiving information regarding URSP rule enforcement from User Equipment (UE). The PCF according to claim 11, further comprising:
15. The DNN and the S-NSSAI are transmitted from the User Equipment (UE). The PCF according to claim 11.
16. Means for confirming information regarding the implementation of the URSP rule based on the information regarding the application. The PCF according to claim 14, further comprising:
Citation Information
Patent Citations
Communication method, device and system
CN112954768A
Communication method, device, and system
EP3958643A1
Method and apparatus for session management on applying UE policy in wireless communication system
KR1020210120768A
Handling of routing rules for a 5g rg
WO2022008103A1