Wireless communication system for first responder network

A wireless communication system for first responders enhances network reliability and coverage during MCIs by authorizing devices and using relay nodes and drones to overcome network disruptions.

JP7862416B2Active Publication Date: 2026-05-19KONINKLIJKE PHILIPS NV
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
KONINKLIJKE PHILIPS NV
Filing Date
2022-02-10
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing communication networks, including dedicated networks for emergency services, are often unreliable during mass casualty incidents (MCIs) due to overloading or intentional disruption, leading to communication breakdowns that hinder effective response efforts.

Method used

A wireless communication system is established using access devices that connect to a network controller, receive geographic area information, and invite wireless devices to register with a core network, ensuring secure and reliable communication by authorizing devices and extending network coverage through relay nodes and drones.

Benefits of technology

The system ensures faster response times and reliable communication coverage for first responders and injured persons by securing network access and expanding coverage, even in areas with disrupted infrastructure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007862416000001
    Figure 0007862416000001
  • Figure 0007862416000002
    Figure 0007862416000002
  • Figure 0007862416000003
    Figure 0007862416000003
Patent Text Reader

Abstract

A first responder network is a network used by first responders to communicate among devices typically used by first response officers. MCI refers to an incident in which emergency medical services are overwhelmed by the number and severity of injuries. To ensure faster response times within MCI areas, a wireless communication system for the first responder network is proposed that can securely register various wireless devices. Existing wireless devices belonging to both triage officers and victims within the MCI area can automatically register with the first responder network to enhance coverage within the MCI area. Expansion of the wireless infrastructure of the first responder network can be enabled by securely registering heterogeneous central nodes (e.g., base stations) on demand.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the establishment of a first responder network in a wireless network environment, such as, but not limited to, a cellular network with an indirect network connection for a remote communication device.

Background Art

[0002] Natural disasters such as earthquakes, hurricanes, tsunamis, landslides, forest fires, and tropical storms can cause many damages and may result in losses to human life. Other non-natural disasters such as building fires, some forest fires, building collapses, and terrorist attacks can similarly cause damages and losses to life. In some cases, the amount of damage and / or loss to life resulting from a disaster can be reduced through improvement of the response system.

[0003] A mass casualty incident (MCI) represents an incident where emergency medical services may be overwhelmed by the number and severity of the casualties. Triage is a process applied when there are more casualties requiring assistance than there are available medical personnel. Examples of these situations are mass transportation accidents and terrorism.

[0004] Currently, the tools used by care providers during an MCI event are relatively low-tech, i.e., paper-based systems. Digital technologies have been proposed to improve triage speed, provide a better overview of the MCI event situation, and transform the current static paper-based information into dynamic digital information. By doing so, the planning of clinical and non-clinical operations in an MCI event can be improved, and real-time patient monitoring can be developed by incorporating vital sign sensors.

[0005] Nevertheless, the use of digital technologies requires communication coverage for exchanging data between locally present wireless communication devices in the field, either in a peer-to-peer manner (e.g., a mesh network) or a server-client manner (e.g., via a serving Wi-Fi access point). [Overview of the project] [Problems that the invention aims to solve]

[0006] One problem that often occurs during MCI events is the overloading of normal telecommunications networks. To prevent emergency medical services from becoming unable to communicate, countries have set up dedicated communication networks for this purpose, such as the US First Response Network Authority's FirstNet and the Netherlands' C2000. Unfortunately, even these networks are often reported to be unreliable.

[0007] Another problem is that during an MCI event caused by a criminal (e.g., terrorism), the criminal could intentionally overload and shut down publicly available telecommunications networks. Alternatively, a natural MCI event (e.g., a tsunami) could disrupt the public infrastructure of normal telecommunications networks by damaging, for example, cellular base stations and backhaul links.

[0008] The objective of this invention is to enable improvements in service provision within MCI areas. [Means for solving the problem]

[0009] This objective is achieved by the apparatus described in claim 1, by the access device described in claim 8, by the wireless communication system described in claim 9, by the method described in claim 17, and by the computer program described in claim 18.

[0010] According to a first aspect relating to a communication link access device end, an apparatus is provided for supporting the establishment of a wireless communication network (for example, for use by a first responder), and the apparatus is - To connect to a wireless network controller device and establish wireless connectivity to wireless communication devices within a target geographic area, - Receiving information about the target geographical area, - Receiving information from the network controller device about the network configuration for setting up a communication channel with wireless communication devices, - Inviting wireless communication devices within the target geographic area to register via a communication channel to the core network operated by the network controller device or other communication channels. It was configured to perform the following actions.

[0011] The first aspect relates to an access device (such as a drone), in which case information about the target geographic region / space (e.g., a two-dimensional (2D) area or three-dimensional (3D) volume (indicated by a set of 2D / 3D coordinates) containing a group of injured persons, or the best landmark location for positioning the access device within the MCI area) may be received directly from the network controller device or via other access devices and / or a separate positioning server. The network controller device may also provide or compute this information for the access device using a third-party positioning application programming interface (API), for example, through the network exposure function (NEF) of the network controller device. In one example, an access device that has not yet received information about the target geographic region may receive this information directly from a third-party API / NEF via another (e.g., non-3GPP®) communication method (e.g., Wi-Fi) upon request from the network controller device. This is advantageous in that access devices that have lost their connection to the network controller device at a distance can still be rediscovered within the target geographic area.

[0012] Therefore, information about the target geographic region within the MCI area is received directly from the network controller device, or via other wireless communication devices, access devices, or a separate positioning server. Details necessary for access devices to calculate information about the target geographic region (such as SLAM sensor data and signal quality information) are transmitted from access devices and wireless communication devices within the MCI area to the network controller device.

[0013] Information about the network configuration for setting up a communication channel with wireless communication devices includes and / or can be used to configure access devices to be authorized to invite wireless communication devices to specific slices / frequencies of the network within the MCI area. Network configuration information includes, for example, the authorization that access devices can use to invite wireless communication devices or additional access devices within the area to connect to the core network, network / slice-specific settings (frequency, authorized devices, services provided, Restricted Local Operator Service (RLOS), roaming steering, emergency / non-emergency slice instructions, etc.), and certificates (e.g., private keys) required to authorize first responder wireless communication devices.

[0014] A pre-authorized wireless communication device responds to an invitation by establishing a secure channel using a certificate (e.g., a public key) pre-stored in the wireless communication device to connect to the wireless communication network and / or a specific network slice via an access device. In one example, a wireless communication device that can prove its authenticity is permitted to connect to a "first responder" slice. A device that cannot prove its authenticity is steered to connect to a "non-first responder" slice.

[0015] According to a second aspect relating to the access device end of a communication link, a method is provided for supporting the establishment of a wireless communication network (for a first responder), and the method is - To connect to a network controller device of a wireless communication network and to establish wireless connections to wireless communication devices within a target geographic area, - Receiving information about the target geographical area, - Receiving information from the network controller device about the network configuration for setting up a communication channel with wireless communication devices, - Inviting wireless communication devices within the target geographic area to register via a communication channel to the core network operated by the network controller device or other communication channels. It holds.

[0016] According to a third aspect, an access device is provided for making a wireless connection to a wireless communication device in a wireless communication network (for a first responder), the access device comprising the apparatus of the first aspect.

[0017] According to a fourth aspect, a wireless communication system is provided comprising a network controller device, one or more wireless communication devices, and a third-aspect access device connected to the network controller device.

[0018] Finally, according to the fifth aspect, a computer program product is provided which, when executed on a computer device, comprises coding means for producing the steps of the method of the third or fourth aspect described above.

[0019] Therefore, to ensure faster response times, for example, within MCI or other emergency areas, a wireless communication system can be provided for a first responder network or other public and private wireless (emergency) networks, enabling the secure registration of various wireless devices. In the case of an MCI event, existing wireless devices belonging to both triage officers and injured persons within the MCI area can be automatically registered with the first responder network to enhance coverage within the MCI area. Furthermore, the wireless communication network can be authorized to grant access devices the authority to send invitations to wireless communication devices to connect to the wireless communication network.

[0020] According to the first option, combined with any of the first to fifth aspects described above, a detected wireless communication device that is a designated wireless communication device of the first responder is prevented from connecting to another wireless network (e.g., a different operator's public network) during an MCI or other emergency event (e.g., by receiving a corresponding priority access list, or by roaming steering information, or by temporarily disabling roaming steering based on an order), and / or a detected wireless communication device that is not a designated wireless communication device of the first responder is prevented from registering with the wireless first responder network (e.g., by receiving corresponding access control or allow / deny slice information). This makes it possible to control the number of wireless communication devices allowed to communicate (e.g., within an MCI or other emergency area) and their communication range to ensure sufficient service capacity. As a further option, only a limited set of services (e.g., only voice services and / or limited data services) may be allowed as part of the default slice, so that bystanders cannot flood the network with video streaming of the event.

[0021] Furthermore, a wireless communication device that is normally permitted to connect to another wireless network (e.g., a public network of a different operator) can temporarily update the roaming steering information by, for example, removing a preferred non-public network or giving a higher priority to the wireless first responder network, or similarly, update the priority list of the preferred non-public network to be controlled to connect to the first responder network. For this purpose, a security certificate indicating an emergency or MCI event is attached to or signed on the roaming steering or the priority list of the non-public network information. As a further option, a policy for connecting to the network (e.g., the minimum signal strength for connection) is updated. When leaving the MCI area, the old roaming steering / non-public network priority list is restored. This can be implemented by temporarily backing up the old roaming steering / non-public network priority list, or by giving only a temporary higher priority to the wireless first responder network based on an expiration timer so that a higher priority network is removed when the expiration timer expires.

[0022] Note that information about the target geographical area is received in the device of the first aspect. In one specific example, the target geographical area is an area smaller than the coverage area of the access device.

[0023] According to the first option, or a second option combined with any of the first to fifth aspects described above, the total number of access devices required within the target geographical area and the locations of the access devices within the target area are predicted based on measurement parameters received from the access devices, and the access devices are deployed or removed based on the prediction results. Therefore, it is possible to ensure the coverage required for sufficient service capacity within the target geographical area.

[0024] According to the first or second option, or a third option which may be combined with any of the first to fifth embodiments described above, the detected wireless communication device is checked to determine whether it is a designated wireless communication device of the first responder by verifying the identification information linked to the user of the detected wireless communication device or the identification information linked to a pre-registered first responder device. This allows communications within the MCI or emergency area to be restricted to selected wireless communication devices in order to ensure sufficient service capacity. As a further option, the first responder device may be registered to a separate slice and / or separate frequency of the first responder network, separate from those of the injured and / or spectators.

[0025] According to any of the first to third options, or a fourth option that can be combined with any of the first to fifth aspects described above, one or more additional access devices can be authorized and registered (i.e., connected) to a wireless communication network (for the first responder) either directly or via an access device that was previously already connected, for example, by exchanging a security certificate related to an emergency or a security certificate indicating the first responder during registration. When the access device is mobile (e.g., a drone with built-in base station functionality), each of these access devices receives coordinates from a network controller device and moves towards its respective coordinates. Furthermore, base station devices belonging to a Public Land Mobile Network (PLMN) operating within the same or a partially overlapping area are requested / invited (either via a (signaling an emergency) signal transmitted by an access device of the wireless first responder network or via a back-end connection between the network controller device of the wireless first responder network and the PLMN), and then authorized and registered to operate as an additional access device of the first responder network. This measure ensures that communication by emergency services can be provided by the wireless first responder network, for example, by providing sufficient coverage within an MCI or emergency area.

[0026] According to any of the first to fourth options, or a fifth option which can be combined with any of the first to fifth embodiments described above, for example, identity information of a wireless communication device belonging to a person in an MCI or emergency area is retrieved, and the person is identified by matching the identity information of the wireless communication device with user information stored on the cellular device platform, or the person's wireless communication device is registered with the wireless communication network (for the first responder) to triangulate the person's location. This makes it possible to identify and / or locate the person in the MCI or emergency area.

[0027] According to any of the first to fifth options, or a sixth option which may be combined with any of the first to fifth aspects described above, the invitation to register is limited to at least one of a predetermined group and / or type of wireless communication devices in a wireless communication network, a network service, and a network slice. This makes it possible to limit the wireless devices used in an MCI or emergency area to a specific group or type, service, or network slice in order to ensure reliable and effective service delivery in the MCI or emergency area.

[0028] According to any of the first to sixth options, or a seventh option which can be combined with any of the first to fifth embodiments described above, access devices deployed in a target geographic area (e.g., MCI or emergency area) are equipped with relay node functionality that can be activated by a network controller device. This measure has the advantage that the network controller device can activate relay node functionality to enhance the coverage area of ​​the first responder network within the MCI or emergency area, for example, through a multi-hop chain of access devices. Additionally, wireless communications devices connected to the access devices are activated to act as relay nodes to extend the coverage of the wireless communications network.

[0029] According to any of the first to seventh options, or an eighth option which can be combined with any of the first to fifth embodiments described above, measurements are performed by the deployed access devices in the target geographic area of ​​the access devices (e.g., the MCI or emergency area), and the corresponding measurement parameters are transmitted to a network controller device for predicting the total number of access devices required within the MCI or emergency area. This ensures that a sufficient number of access devices are deployed within the MCI or emergency area to ensure reliable and effective service delivery within the MCI or emergency area. Such measurements may also be performed by other wireless devices, for example, in areas where access devices do not provide coverage and only relay connections are available.

[0030] According to any of the first to eighth options, or a ninth option which may be combined with any of the first to fifth embodiments described above, a first responder database is provided for pre-registering wireless communication devices associated with each first responder, and a central identity server is provided which is configured to access the first responder database and derive first responder user information associated with the pre-registered wireless communication devices. Thus, the device identification information of a discovered wireless communication device can be used to check whether the discovered wireless communication device belongs to a pre-registered first responder authorized to use the first responder network for communication.

[0031] According to any of the first to ninth options, or a tenth option which may be combined with any of the first to fifth embodiments described above, the device of the first embodiment is further configured to include information about an emergency (e.g., special information elements) in an invitation signal or message which is transmitted to a wireless communication device and further includes a certificate (e.g., a digital certificate signed by a first responder organization or government) indicating the urgency of the request.

[0032] According to any of the first to tenth options, or an eleventh option which can be combined with any of the first to fifth embodiments described above, the system of the fourth embodiment is configured to perform device authentication via a connection between a network controller device and an external device that is not registered with the wireless communication network (for the first responder). This makes it possible to register an unregistered wireless communication device with the wireless communication network without expending significant effort on pre-registration.

[0033] In one example of the eleventh option, the network controller device of the system in the fourth aspect is configured to connect to an external device via a limited-range local connection and to the core network of the wireless communications network (for the first responder) in order to enable the external device to function as an authenticator and / or subscriber owner registry for an inbound roaming device.

[0034] In another example of the eleventh option, the network controller device of the system in the fourth aspect is configured to allow external devices to verify that incoming roaming devices belong to the same network, facility, or group.

[0035] In a further example of the 11th option, the network controller device of the system in the fourth embodiment is configured to provide authentication and / or identification information to an external device (e.g., a drone or other wireless robotic device, or a mobile server device, for example, located in a fire truck of another fire brigade), so that the core network function of the external device can perform local network registration.

[0036] According to any of the first to eleventh options, or a twelfth option which can be combined with any of the first to eighth embodiments described above, the system of the seventh embodiment is configured to exchange information between the wireless communication network (for the first responder) and another wireless communication network (e.g., a PLMN operated by a public network operator) to obtain location information for user identification, or to request access devices on another wireless communication network to temporarily join the first responder network.

[0037] According to any of the first to twelfth options, or a thirteenth option which may be combined with any of the first to fifth embodiments described above, the system of the fourth embodiment is configured to identify and track legitimate network privileges and transactions in the wireless communication network and / or subscriber database, for example, to perform appropriate deregistration of all access devices and wireless communication devices, to restore the devices to their previous state, and to record what has happened (for example, for training purposes or in case of liability, i.e., as a black box).

[0038] It should be noted that the above-mentioned devices are executed based on individual hardware circuit equipment, which involves the arrangement of individual hardware components, integrated chips, or chip modules, or on signal processing devices or chips controlled by software routines or programs stored in memory, written to computer-readable media, or downloaded from a network such as the Internet.

[0039] It should be understood that the apparatus described in claim 1, the access device described in claim 8, the wireless communication system described in claim 9, the method described in claim 17, and the computer program described in claim 18 have similar and / or identical preferred embodiments, particularly as defined in the dependent claims.

[0040] It should be understood that preferred embodiments of the present invention may also be any combination of each independent and dependent claim or the embodiments described above.

[0041] These and other aspects of the present invention will become apparent from the embodiments described below, and will become clearer by referring to the embodiments. [Brief explanation of the drawing]

[0042] [Figure 1] This figure schematically illustrates an MCI scenario in which the present invention can be implemented. [Figure 2] This diagram schematically illustrates the architecture of the first responder network in various embodiments. [Figure 3] This diagram schematically shows block diagrams of network controller devices in various embodiments. [Figure 4] This diagram schematically shows block diagrams of access devices according to various embodiments. [Figure 5] This diagram schematically shows the flowchart of the first responder network deployment procedure according to various embodiments. [Figure 6] This diagram schematically shows the flowcharts of the first responder network location confirmation and mapping procedures according to various embodiments. [Modes for carrying out the invention]

[0043] Embodiments of the present invention are described herein based on a network infrastructure, for example, targeting a first responder, comprising an end-to-end wireless system deployed in an MCI event or other event (e.g., a forest fire or emergency in a remote area without reliable network coverage, or a temporary event including a large crowd requiring an alternative network for personnel) where personnel (e.g., emergency) require the network infrastructure to communicate. While embodiments of the present invention are described based on a first responder network, the present invention and its techniques are not limited to a first responder network and are applicable to any cellular public land mobile network (PLMN) or any cellular or non-cellular non-public network (NPN).

[0044] The system can be deployed on demand based on location dynamics and details of the MCI event (e.g., whether the MCI event is a terrorist attack, auxiliary or highway accident, natural disaster, or infectious outbreak), each with its own requirements depending on the number of victims and the area surrounding the incident. Medical service vehicles such as ambulances and fire trucks can be fitted with antennas for wireless communication technologies such as (but not limited to) direct satellite links, Wi-Fi, Bluetooth, Long Range (LoRa), and cellular base stations with similar technologies.

[0045] Throughout this disclosure, “First Response Person” is intended to be the person who will be the first to arrive at an emergency scene and provide assistance in the event of an MCI event such as an accident, natural disaster, or terrorist attack. First Response Persons include law enforcement officers, paramedics, emergency medical technicians (EMTs), and firefighters. Depending on the area, emergency department personnel may also be required to designate themselves as First Response Persons to respond to disaster and crisis situations. Furthermore, “First Response Person Network” is intended to be a dedicated network for use by First Response Persons to support First Response Person services in an MCI area. A First Response Person Network is typically a dedicated / standalone non-public network, but it can also be a network that shares infrastructure with a public network or incorporates public network capabilities.

[0046] Reasons for not using existing communication networks may include overload (typically, when something happens, people begin to use communication systems to obtain and disseminate information), network unavailability (especially when considering large-scale and catastrophic MCIs such as earthquakes, plane crashes in residential areas or metro stations, where communication systems may simply be destroyed or signals may be unreachable to such locations), and the unlawful intention of criminals in MCI events to disrupt known and public network services (e.g., shutting down specific radio frequency ranges during terrorist attacks).

[0047] As already mentioned above, there are several first responder networks, such as FirstNet, which is deployed in all 50 states of the United States. These types of first responder networks typically operate on a dedicated non-public radio frequency (RF) spectrum to reduce interference from the general public during MCI events, but it is impossible to deploy them automatically and operate them independently without using existing cellular infrastructure.

[0048] As an alternative, non-commercial networks such as amateur radio are frequently used during disasters. However, such networks are not very reliable for high-bandwidth, low-latency communication. Moreover, users need additional hardware to enjoy amateur radio communication.

[0049] Furthermore, Cell on Wings (COW) has been proposed, in which drones are used to automatically deploy a pre-configured network infrastructure using direct satellite links. However, such COW systems still require a significant amount of pre-configured, specific network information that is only appropriate for areas without cellular coverage and that cannot be dynamically configured based on the unique characteristics of MCI events.

[0050] Figure 1 schematically shows an MCI scenario in which the present invention can be implemented.

[0051] More specifically, the MCI scenario in Figure 1 relates to a crashed aircraft 15 with first responders (e.g., triage officers) 110 and triaged injured persons (i.e., victims or patients) 120, 130.

[0052] In various embodiments, emergency vehicles such as fire trucks 10 and ambulances or medical service vehicles 13 are fitted with their own first responder network infrastructure, including dedicated backhaul communication equipment (e.g., satellite antennas), which can be automatically deployed with a minimal configuration to function effectively as a standalone wireless first responder network, particularly capable of serving the MCI area. The wireless first responder network has its own limited range to prevent interference with other public networks outside the MCI area.

[0053] In certain situations where MCI events occur over a wide area, emergency vehicles 10 and 13 are still unable to provide adequate coverage. In Figure 1, triaged patients 120 and 130, located within the dashed circles around emergency vehicles 10 and 13, are within the range of two first-line responder networks established by emergency vehicles 10 and 13. However, emergency vehicles 10 and 13 are unable to cover the entire MCI area because they cannot reach certain locations.

[0054] Other examples of insufficient coverage include subway (metro) accidents, accidents near or in the vicinity of mountains, swamps, or coastlines.

[0055] To support and / or extend the coverage area of ​​an established first responder network, various devices present in the MCI area (e.g., user equipment (UE) of the injured or first responder (e.g., triage officer), smartwatches, cellular medical devices, and other wireless communication devices) function as relays in the first responder network.

[0056] Furthermore, the infrastructure of the wireless first-party network is expandable by adding base station devices that are not known to the deployed wireless first-party network, which can be deployed as part of the deployed first-party network (for example, equipped on drones by different first-party services).

[0057] Furthermore, unmanned, remotely controlled or autonomous robots, such as drones and / or motorized rovers, already have a wide range of applications, including military use, racing, light shows, video and photography for package delivery, inspection of underwater communication lines, and possibly combating insect outbreaks like locusts in Africa. Such unmanned robots are cost-effective and potentially programmable to be remotely controlled or fully automated to navigate unprecedented locations such as MCI areas.

[0058] As shown in Figure 1, the drone 12 or other autonomous robot can be used to monitor and expand the MCI area of ​​the emergency vehicles 10, 13. Network expansion can be achieved by deploying the drone 12 as a relay node, each having its own coverage area (a circle drawn with dots around the drone 12). As shown in Figure 1, one of the lower drones 12 is in the coverage area to the left of the emergency vehicles 10, 13 in Figure 1, and acts as a relay node in the first responder network, while one of the upper drones 12 is in the coverage area of ​​the lower drone 12 (the relay node).

[0059] As an addition or alternative, existing and available cellular devices (e.g., mobile phones) or other wireless devices (not shown in Figure 1) may be improvised and / or automatically reused to enhance the coverage area of ​​the first responder network.

[0060] Figure 2 schematically shows the architecture of the first responder network 200 in various embodiments based on a wireless communication system (e.g., a public land mobile network (PLMN) or a non-public network (NPN)).

[0061] In Figure 2, the network controller device (device A) 20 is configured to operate a core network for a standalone first responder network 200 to provide temporary networking to first responders and injured persons in MCI events, and is optionally connected to other core networks of one or more mobile operators. The network controller device (device A) 20 comprises a network controller module or function 202, an identity service module or function 204, a simultaneous localization and mapping (SLAM) module or function 206, a location service (LCS) or location database, and other core network modules / functions (such as Access and Mobility Function (AMF), Mobility Management Entity (MME), Unified Data Management function (UDM) or Home Subscriber server (HSS), Authentication Server Function (AUSF)). The functions of these modules / functions are combined; for example, the SLAM module / function 206 is combined with the Location Services (LCS), or the Identity Services module or function 204 is a separate identity manager / database combined with, for example, AUSF or UDM, but is AUSF combined with UDM, or simply functions as AUSF, an authentication / authorization / billing AAA server, or an equivalent.

[0062] Nevertheless, it should be noted that in all embodiments, the core network is distributed across multiple devices and does not need to be a single device.

[0063] Furthermore, one or more base stations or access devices (device B) 22 are connected to device A 20 and have the ability to wirelessly connect to wireless communication devices 24 (device UE) within its coverage area. The device identity of one or more device UEs 24 (e.g., subscription concealed identity (SUCI) in a 5G network) can be concealed by a secure certificate (e.g., private key) of the device UE 24's home PLMN.

[0064] Device A20 can automatically connect to a central identity server (CIS) 26 to communicate subscriber details such as the First Responder's Device Identification Number (DID) (e.g., IMSI) and retrieve user information linked to the target device UE24. Such a central identity server (CIS) 26 is located outside the core network of the First Responder network 200 and is deployed, for example, as an external AAA server or RADIUS server, or as an AUSF on another network (e.g., the home network of the target device UE24).

[0065] Additionally, a first responder database (FRDB) 28 is provided, which can be used to pre-register at least some of the device UE24s with their respective first responders and / or unique network slices for verification purposes. Such a first responder database (FRDB) 28 is, for example, an Active Directory server or UDM on another network (e.g., the home network of the target device UE24).

[0066] For example, in order to enable authentication of device UE24 by the first responder network 200 through the Identity Service Module / Function 204 and / or the Central Identity Server 26, and / or by the first responder database and / or the device's home network, device UE24 has a secure device identity (devID) or user identity (userID) (e.g., International Mobile Equipment Identity (IMEI)) (e.g., digital passport) that is unique to device UE24 or the user and stored in secure memory, and can be linked to the device's user via network-related information (e.g., International Mobile Subscription Identity (IMSI) stored in the Subscriber Identification Information Module 242 (e.g., as described in the GSMA SGP.21-RSP architecture)). In the case of NPN, for example, TLS / certificate / PKI-based certificates, as described in TS33.501, are available, and / or the concept of a default certificate, as described in 3GPP® specification TR23.700-07, is available.

[0067] CIS26 is configured to access the first responder database 28 and derive user information (e.g., first responder ID (FRID)) of registered first responders associated with device UE24.

[0068] In one embodiment, device A20 invites device UE24 or triggers / requests device UE24 to connect with first responder network 200 after deconcealing the concealed device identity (e.g., to derive the subscription permanent identifier (SUPI) from the SUCI) by requesting the home PLMN of device UE24 (e.g., in the Subscriber Identifier Deconcealment Function (SIDF) in a 5G network via NEF). For this purpose, first responder network 200 is required to provide a certificate (e.g., a digital certificate signed by first responder agency or government) via, for example, AUSF, which allows first responder network 200 to prove to the home PLMN of device UE24 that first responder network 200 is involved in an emergency and therefore it is important to provide device / user identity information for device UE24 (e.g., based on the SUCI provided to the home PLMN by the responder network) and / or for device UE24 to connect with first responder network and set up the necessary communications. As an alternative, when device UE24 registers with the First Responder Network, if device UE24 is permitted, or if it is possible to permit / enable, to register with the First Responder Network without requesting the deconcealment of the SUPI, the First Responder Network will request this from device UE24's home PLMN. As an alternative, the First Responder Network will need to provide the Home PLMN of device UE24 with an emergency certificate as described above (for example, if a roaming agreement is not in effect).As an alternative, when device UE24 registers with the First Responder Network, the First Responder Network requests that device UE24's Home PLMN provide user identity-related information (e.g., subscription information, name, phone number, emergency contact, and electronic health record information for subscriptions linked to each SUPI), and / or location information for device UE24, regardless of whether device UE24 requests further permission to register with the First Responder Network. As an alternative, the First Responder Network must provide the Home PLMN of device UE24 with an emergency certificate, as described above. Communication from the First Responder Network 200 to the Home PLMN to make the above requests and for the Home PLMN to provide the responses will be conducted over a secure channel, regardless of whether a roaming agreement exists in the emergency scenario.

[0069] For this purpose, device A20 or another device in the first responder network must connect to the NEF of device UE24's home PLMN and present an emergency certificate, which, after being verified as authentic by the home PLMN (e.g., by contacting the respective certificate authorities that signed the certificate), is available during the security handshake to set up a secure connection (e.g., an IPSec tunnel) between the first responder network and the home PLMN. Alternatively, device A or another device in the first responder network could register with the home network as a UE, for example, request a PDU session, provide the emergency certificate through the PDU session, use the emergency certificate to set up a secure connection, enable the first responder network (e.g., its AUSF) to request the home PLMN to deconceal the device identity, and / or enable device UE24 to register with the first responder network. The registration would be of the type "emergency request" or "disaster roaming," as defined in TS23.501. Alternatively, device A20 or another device in the first responder network may need to connect to a Public Safety Answering Point (PSAP) and provide the PSAP with the SUCI of device UE24, information about device UE24's home PLMN, and / or an emergency certificate. Such a PSAP can then have emergency access to each home PLMN of device UE24 (e.g., via NEF) and thus request the home PLMN of device UE24 to deconceal the device identity and / or allow device UE24 to register with the first responder network and return this response to the first responder network. The PSAP may also request the home PLMN to set up a secure connection between the home PLMN and the first responder network, either directly (e.g., via a TCP / IP connection over the Internet) or through the PSAP.Through a secure channel, the Home PLMN provides information about the signals, messages, or certificates available to the First Responder in its invitation, triggering or requesting Device UE24 to enable connection to the First Responder network. The Home PLMN updates the steering of roaming information or Device UE24's non-public network preference list by adding the First Responder network identity (provided by the First Responder network through the secure connection) and / or updates other policy information of Device UE24 to enable the First Responder network to connect with Device UE24. The Home PLMN also deregisters Device UE24.

[0070] For example, to enable automated billing, tracking, or identification of injured persons, and to facilitate the simple and automatic registration of wireless communication devices within an MCI area for MCI events, device B22 is configured to receive information or volume about a target geographic area (e.g., from a network controller device (device A) 20) and allow wireless communication devices within this target geographic area to be automatically registered via device B22 to the core network operated by device A20. This can be achieved by an invitation or connection trigger / request, which is an emergency signal or message transmitted by an access device of the first responder network 200. In one example, this could be a Public Warning System (PWS) signal, an SMS / IMS message, a System Information Block (SIB) or Radio Resource Control (RRC) message, a Non-Access Layer (NAS) message, or a preamble containing flags or information elements. In one example, the First Responder Network includes a flag / attribute (e.g., a Boolean "Emergency Use Request") with a value to instruct it to broadcast that it supports disaster roaming (like TS23.501) and to request / invite devices to connect, and / or a flag / attribute with the identity (e.g., SUCI) of a specific device UE24 that will register with the First Responder Network. The signal / message or one of its informational elements may be signed or include several security certificates (e.g., a digital certificate signed by a First Responder Organization or Government) indicating an emergency or MCI event.Sending an invitation or connection trigger / request is accomplished by sending an emergency instruction (and / or emergency certificate) during the setup of a call to device UE24, by dialing a special number related to the phone number of device UE24, by sending a USIM application / service command or (secret) dial code to device UE24, or by sending a broadcast message with a predetermined payload or an SMS with a special code (e.g., via a multicast / broadcast service framework).

[0071] Instead of, or in addition to, an invitation or connection trigger / request to connect to a wireless communication network provided by device B22 and / or device A20, the invitation or connection trigger / request includes instructions to initiate communication via a sidelink, set up a sidelink connection to another wireless communication device (e.g., a shared patient monitor that collects data from a group of victims), or trigger a handover from one access device to another, or from one wireless communication network to another.

[0072] Additionally, an invitation or connection trigger / request may include a minimum / maximum distance (e.g., to access device B22, or to a specific coordinate or reference point / device (e.g., a location reference unit as described in R2-2106920)), or a set of coordinates (absolute (e.g., geographic coordinates) or relative to a reference point / device (e.g., a location reference unit as described in R2-2106920)) indicating the target area / volume to which the device is invited / triggered to connect, or a tracking area identifier and / or dimensions of the tracking area (e.g., a set of coordinates), or a restricted area identifier and / or dimensions of the restricted area (e.g., a set of coordinates). Instead of, or in addition to, an invitation or connection trigger / request, information about one or more target areas to which a device is allowed / not allowed to connect, such as a set of coordinates indicating the dimensions of the tracking area and relevant tracking identifiers, may be securely provided to device UE24 in advance (e.g., by PCF). Then, when device UE24 detects access device B22 (e.g., receives a connection trigger / request), it can estimate the location of access device B22 and force a connection to access device B22, whether allowed or not. A device outside the designated target area / volume does not need to respond if its location is not within the target area / volume, or, alternatively, device B22 (possibly together with device A20) may select which devices are in or out of the target area / volume (e.g., which devices to register with device B22 and which not to register).As an addition or alternative, device B22 may allow a device (e.g., device UE24) to register with device B22 and allow the device to initiate registration with the First Responder Network (e.g., by forwarding messages received from the device to device A20), at which point the First Responder Network (e.g., by the AMF / AUSF of the First Responder Network's core network operated by device A20) selects which devices are located within the target area / volume (e.g., which devices are registered with the First Responder Network 200 and which are not). For this purpose, device B22 or device A20 may contact a location service / database to retrieve location information for each device UE24, or use location / location measurement information (e.g., timing of sounding reference signals or location reference signals) provided by each device UE24 or device B22. Device A or Device B also obtains the location of each device UE24 by connecting to a public safety response point, which must or can contact a location service that provides up-to-date information about the location of each device.

[0073] In embodiments implemented in combination with any other embodiment or independently, there is a target geographic area of ​​a base station or access device (device B) 22 for triggering / requesting an invitation, and / or for device B22 and / or device A20 to select devices that are in or not in the target area / volume (and therefore permitted / not permitted to register with the first responder network). The target geographic area is smaller than the coverage area of ​​a single base station or access device. In other words, device B22 is configured to receive information about dimensions (e.g., a set of coordinates that are absolute (e.g., geographic coordinates) or relative to a reference point / device (e.g., a location reference unit as described in R2-2106920)), and / or a minimum / maximum distance (set) to, for example, one or more access devices B22, or to one or more unique coordinates, or to one or more reference points / devices (e.g., a location reference unit as described in R2-2106920) of a target geographic area that is a subregion of the coverage area of ​​one or more devices B22, and / or to invite or trigger / request one or more devices UE24 within the coverage area of ​​device B22 to register with the core network operated by device A20 via each device B22. Device B22 extracts or calculates distance or location from a set of devices within its coverage area (and potentially in cooperation with other devices and / or location services in the core network) by transmitting and receiving their respective location signals (e.g., location reference signals, round-trip time measurement signals).Alternatively, device B22 or device A20 may contact a location service or database (which may also be provided by another network service / server, such as Network Data Analysis Function (NWDAF), which provides data about the device (e.g., capabilities, type, identity), device location within a specific area, and / or the most recent / previously known location of the device, based on previous data collection and measurement, for example, operated by device 20 or by the PLMN to which device UE24 is connected) to retrieve a set of devices within the target area / volume, and based on this information, send an invitation or connection trigger / request to each set of devices only. For this purpose, the invitation or connection trigger / request may include the device identity information of the target device, or device B22 (and possibly together with device A20) or device A20 may select devices that match or do not match their respective identities. Instead of sending an invitation or connection trigger / request, device A20 or B22 allows device UE24 to register with the network, and then estimates the location of device UE24 by exchanging location estimation signals during or after registration, or by exchanging location information (e.g., between device UE24 and device A20 or B22) (or by device UE24 providing location / location measurements (e.g., sounding reference signal or location reference signal timing) during the registration procedure), after which the network aborts the connection setup procedure or unregisters / disconnects the UE if the estimated location is not within a configured target area.Alternatively, after the initial registration and / or PDU session setup of device UE24, device A20 or B22 retrieves the estimated location of device UE24 by contacting a location service or database operated by, for example, device 20 and / or first responder network 200, or by a PLMN to which device UE24 is connected (and from which device UE24 transmits its location estimation signal measurement or its location information, and / or which can determine the location of device UE24). This requires authorization from device UE24's home network operator to determine the location of device UE24 and / or access the location service, and therefore requires device A20 or device B22 to provide an emergency certificate / certificate as described above. Instead of contacting a location service or location database (which may be operated by the home network operator of device UE24), device A20 or B22 may also send a message to the location service or location database containing target area information and, in some cases, an identifier received from device UE24 (e.g., Subscriber Concealment Identifier (SUCI)), to which the location service or location database will respond with a message that contains information on whether the UE is currently within its respective target area, but does not reveal any additional identity information about device UE24 (such as an International Mobile Subscriber Identification Number (IMSI) or Subscriber Permanent Identifier (SUPI)) in order to maintain the privacy of device UE24 to the network operated by device A20.

[0074] Alternatively, the first responder network has a roaming agreement with device UE24's home network and provides home-routed roaming to device UE24's home network, for example, as in TS23.501. In this case, device UE24 registers with its home network (via the roaming connection provided by the first responder network) and therefore uses the location services of this network. The first responder network provides information about the target area to device UE24's home network, for example, by having the AMF add information about the target area to a home-routed registration request forwarded from device UE24 to device UE24's home network, or by providing this information through the NEF between the first responder network and device UE24's home network, for example. The home network of device UE24 determines, based on the provided target area information, whether device UE24 is permitted to register with the first responder network (for example, by checking whether device UE24's location is within the target area using the location service of device UE24's home network). If not permitted, device UE24's home network either cancels the registration process or deregisters the device.

[0075] As an addition or alternative, device B22 may have multiple antennas and transmit synchronization signals or invitation or connection triggers / requests only on specific beams or specific synchronous signal blocks (SSBs). The signals / messages may also be broadcast in all directions on all beams, but may include an index to a specific SSB, for example, to allow device UE24 to respond or not respond based on the index. Alternatively, device UE24 may transmit an SSB / beam index and / or other beamforming-related information (e.g., channel status information, signal direction, or other measurements) to device B22, which then uses this to determine whether device UE22 is within a specific coverage area corresponding to the SSB index. Based on configured target area information (for example, received via an NEF), one or more beams are adjusted to narrow in order to target a smaller coverage area (for example, by applying different OFDM encodings to reduce spatial diversity, adjusting antenna array configurations, applying different transmission power patterns to antenna areas, changing antenna positions, moving panels / reflectors, etc.). Additionally, device A20 or device B22 is connected to other access devices / base stations, thereby allowing the devices to exchange messages to provide synchronized beam sets from multiple base stations (for example, by using multipoint coordinated transmission / reception (CoMP)) to greatly improve the signal within the configured target area (so that each beam can use weaker signal strength, and therefore individual beams are not as strong in other coverage areas, making service to UEs outside the configured target area much worse or possibly unusable). The area covered by the beams is likely to be circular or spherical in nature. The target areas that can be configured (for example, via an NEF) are limited to such shapes.To apply beamforming to other configured shapes, device A20 or device B22 performs several shape matching operations to cover as much of the configured target area as possible using multiple overlapping beams (from one or more access devices), for example by algorithmically determining various combinations of overlapping beams and / or beam configurations, measuring the expected percentage of overlap with the configured target area for each combination / configuration, and / or estimating the area outside the target area that would be similarly covered by the beams (considering various beam configurations), and comparing these percentages and / or estimates to determine the best configuration / assembly of overlapping beams, thereby minimizing coverage outside the configured target area.

[0076] Please note that an invitation or connection trigger / request may include information about (additional) emergency phone numbers to allow the device UE24 to set up an (unauthenticated) emergency call simultaneously with receiving an invitation or connection trigger / request to a designated emergency phone number.

[0077] Invitations or connection triggers / requests are limited to or targeted to specific groups of device UE24 (e.g., those operated by the first responder) and / or specific types of device UE24 (e.g., those with specific capabilities, such as side-link communication or access to the Global Positioning System (GPS)).

[0078] In addition, if, during an MCI event (for example, due to a network failure in the home network), communication with the home PLMN may not be established within a specified time, device A20 may use the device identity (e.g., a Permanent Equipment Identifier (PEI) or International Mobile Equipment Identification Number (IMEI) obtained directly from device UE24 via a pre-installed user application over a secure out-of-band communication such as Wi-Fi) and / or the unconcealed subscriber identity (e.g., a Globally Unique Temporary Identity (GUTI)) obtained from device UE24 without a security context in an emergency scenario (e.g., RRC setup of the 5G network as specified in 3GPP® TS33.501 Security Architecture and Procedures for 5G Systems) (e.g., during the setup of an emergency connection between the first responder network 200 and device UE24) (e.g., GSMA-SGP.22) The network certificate (e.g., SIM profile) for the first responder network 200 is provided to device UE24 via a generic subscriber identification module (SIM) provisioning server (such as the one specified in the route discovery service specified in the RSP technical specification).Alternatively, device A20 may initiate the setup of a connection to the first responder network via a UE-network repeater (e.g., an emergency connection) by the first responder UE providing the public key of the first responder network (e.g., through discovery messages or other sidelink messages) and / or by the first responder UE connecting via sidelink / PC5 to a ProSe application / service provided by device UE24 for such purposes (e.g., for this particular application / service (e.g., ProSe configuration service or ProSe emergency service), using PC5 direct communication between the first responder UE and device UE24 as specified in TS23.304) and / or by initiating the setup of a connection to the first responder network via a UE-network repeater (e.g., an emergency connection). As a UE-network relay to device UE24, the first responder UE provides access (e.g., via a control plane connection (e.g., via NAS / RRC messages), or via a restricted local operator services (RLOS) user plane connection to device UE24, or via a sidelink connection between a device connected to the first responder network (e.g., a UE carried by the first responder) and device UE24, thereby downloading / providing security certificates (e.g., TLS certificates). Subsequently, device A20 provides (additional) security certificates and, if applicable, further policy information to enable device UE24 to register and use all services of the first responder network.

[0079] In embodiments implemented in combination with any other embodiment or independently, the first responder network may be permitted to do so (for example, by representing a PLMN operator class, as specified in the description of functional stage 2 of 3GPP® TS23.271 Location Services (LCS)) if device B22 of the first responder network 200 can prove to device UE24 or the home network of device UE24 that the first responder network is permitted to do so (for example, by representing a PLMN operator class, as specified in the description of functional stage 2 of 3GPP® TS23.271 Location Services (LCS)). For example, device UE24 may have special permissions set for such a situation so that even the government cannot have access in any case. Device UE24 stores permissions for the device or for services / applications on the device, for example, by setting to grant Android permissions (e.g., android.permission.emergency-location or android.permission.location-override (which do not yet exist)) (e.g., granted / authorized when the device or service / application was installed / configured, or explicitly set by the device user). Such permissions are linked to passwords, keys, or other certificates that must be provided to the device to verify / grant / allow such permissions.The user of device UE24 also agrees in advance to provide such special permissions by storing acceptance of special permissions in the Integrated Data Manager (UDM), Integrated Data Repository (UDR), and Home Subscriber Server (HSS) of the device UE24's home PLMN, and acceptance of special permissions is verified by the first responder by connecting to the respective Integrated Data Manager (UDM), Integrated Data Repository (UDR), and Home Subscriber Server (HSS), for example, through NEF or indirectly through a Public Safety Response Point (PSAP), which have the ability to access the respective permission data or revoke the respective permissions. In such a scenario, the user or their friends / family (who have been added to the information in the Subscriber Database (HSS) or are listed as emergency contacts on the respective mobile phone's SIM card, non-volatile storage, or wearable connected to the mobile phone) will receive a notification to "unlock" the device, discard the device's location privacy indicator settings, or discard the security lock on the device UE24 or SIM card in order to accept an incoming invitation or connection trigger / request or an incoming SIM profile, or to grant them the authority to perform these actions on behalf of the injured person. Alternatively, device A20 in the first responder network 200 may provide a new location service profile (for example, as specified in 3GPP® TS23.273 5G System (5GS) Location Service (LCS)) when establishing a network connection with one or more access devices B22 or device UE24 within the MCI area.

[0080] Alternatively, the first responder may be authorized to unlock device UE24 (for example, based on special privileges granted to the first responder's wireless communication device by network controller device A20), after which the first responder's identity (e.g., the subscriber concealment identity SUCI of the first responder's wireless communication device) is recorded on device UE24 or device A20 to later check whether this was a legitimate action. Alternatively, the first responder's device UE24 may be authorized to provide a new location service profile to one or more device UE24 (e.g., by device 20), or to discard location privacy settings to enable ranging between the first responder device and one or more device UE24 (e.g., via NEF as specified by 3GPP® TS23.273 5G System (5GS) Location Service (LCS), or via secure out-of-band communication such as NFC), or to enable location sharing services for device UE24 (e.g., by setting the location privacy index LPI to allow for a specified time).

[0081] Furthermore, invitations or connection triggers / requests are limited to device UE24s (e.g., first responders) that have access to a specific network slice (e.g., available network resources) by including a specific slice identifier (S-NSSAI) as part of the invitation signal / message or connection trigger / request, for example. Also, the victim's device UE24s are assigned to different network slices, for example, depending on the severity of the victim's injuries. Groups of device UE24s are invited or triggered / requested to connect based, for example, on special informational elements in signaling information or special RRC messages from device B22. Thus, multiple network slices are deployed that deliver the same characteristics to different groups of device UE24s. Inviting or triggering / requesting a device UE24 to connect to a specific network slice is also achievable, for example, by adding the network slice to the authorized network slice selection assistance information (NSSAI) list for specific device UE24s within a group of device UE24s, device UE24s within a specific geographic region, and / or device UE24s with an explicit invitation or connection trigger / request. In one example, the network slice is limited to a specific geographic area smaller than the coverage or tracking area of ​​a single device B22. Additionally or alternatively, device UE24 is configured with preferred non-public network roaming steering information / list, which, following the PLMN / NPN information, also includes information on which (preferred) network slice / NSSAI to connect to. Thus, for the first responder network 200, device UE24 is provided with the identity of the first responder network and the (preferred) network slice / NSSAI to connect to at the time of registration.Based on this information, whenever device UE24 registers with the first responder network 200, device UE24 will automatically request the configured (preferred) network slice / NSSAI at the time of registration with the first responder network.

[0082] Network controller device A20 needs to securely, but authoritatively, invite or trigger / request device UE24 to connect to the first responder network 200 in the MCI area via device B22. In addition to explicit invitation or connection trigger / request messages transmitted from device B22 (i.e., sent to device UE24 without prior confirmation from the home PLMN), invitation or connection trigger / requests are also implicit (i.e., sent to device UE24 with prior confirmation from the home PLMN), which distinguishes the following scenarios:

[0083] a) Device UE24 is within the coverage area of ​​an existing network infrastructure where the first responder network 200 is connected to a PLMN with which it has a roaming agreement. In this scenario, the first responder network 200 may be given a higher priority in the roaming steering information or the non-public network preference list, and therefore the invitation or connection trigger / request is implicit, and the device UE24 involved will automatically connect to such a network as soon as it discovers the respective first responder network 200. In this case, device B22 (possibly in cooperation with device B20) selects devices outside the designated target area by determining distance / location (e.g., through triangulation / trilateration of different signals received by one or more access devices), by comparing the location information (e.g., GPS coordinates) of such device UE24, or by one of the other methods described above. The location of device UE24 is estimated before the UE completes the registration procedure and / or PDU session setup procedure (including authentication) by performing location estimation (e.g., TDOA measurement, signal strength information, SSB index / pattern, e-CID time difference value) using, for example, a pre-registration message (e.g., location estimation signal), or by the UE transmitting (encrypted) location information (including location estimation signal measurement (e.g., arrival time of location reference signal)) to the network by the UE, based on, for example, the same home network public key or a similar / derived key used to encrypt SUCI (e.g., as in TS33.501), or a different public key published through, for example, system information (SI) provided by the access device, or an emergency certificate, for example, based on, for example, the network's public key.The location estimation of device UE24 is also performed after the UE has (partially) completed the registration procedure and / or PDU session setup procedure, by exchanging location estimation signals (for example, directly from device UE10) or location information (or, for example, by device 20 and / or by the first responder network, or by retrieving the location information of device UE24 from a location service or database operated by a PLMN to which device UE24 is connected, and to which device UE24 transmits its location estimation signal measurement or its location information, and / or which is capable of determining the location of device UE24), and thereafter, if the estimated location is not within the configured target area, the network will abort the connection setup procedure or unregister / disconnect the UE. In a particular example, device UE24 uses home-routed roaming via the first responder network 200 to device UE24's home network, and therefore registers with device UE24's home network, and therefore uses the location service of device UE24's home network. The first responder network provides information about the target area to the home network of device UE24, for example, by having the AMF add target area information to a home-routed registration request forwarded from device UE24 to device UE24's home network, or by providing this information, for example, through the NEF between the first responder network and device UE24's home network. The home network of device UE24 determines, based on the provided target area information, whether device UE24 is permitted to register with the first responder network (for example, by checking whether device UE24's location is within the target area using its location service). If not permitted, the home network of device UE24 either terminates the registration process or deregisters the device.

[0084] In embodiments implemented in combination with or independently of any other embodiment, the above-described mechanism for estimating the location of device UE24 [i.e., by performing location estimation (e.g., TDOA measurement, signal strength information, SSB index / pattern, e-CID time difference value) using a pre-registration message (e.g., location estimation signal), or by having the UE transmit (encrypted) location information (e.g., encrypted using the network's public key or emergency certificate) to the network, or by exchanging location estimation signals or location information to estimate the location of device UE24 after the UE has (partially) completed the registration procedure and / or PDU session setup procedure, or by estimating the location of device UE24 before the UE has completed the registration procedure and / or PDU session setup procedure] is applied for geofencing, for example, during the registration of the UE to the network.Such geofencing allows access devices, location services, or other network entities to verify / ensure that a UE does not attempt to register from an unauthorized / prohibited area, based on information about the area (e.g., a set of coordinates / distances) and information about the estimated location of the UE, and if a UE attempts to register from an unauthorized / prohibited area, for example, by rejecting registration or deregistering the UE, or to verify / ensure that the UE registers with the access device in the correct country / area (e.g., by ensuring that the UE registers with satellites from a specified country and / or with PLMNs operating within a specific country), and to reject registration if a UE accesses the network from an incorrect country / area, for example, if a UE accesses the network from an incorrect country. It is possible to deregister a UE, or verify / ensure that it is authorized to use a specific licensed frequency band, and if it is not authorized to use this frequency band, to send a message to the UE and / or the access device to which the UE is connected, along with information / triggers to switch to a different frequency band; or to verify / ensure that the UE is registered with the correct network covering a specific area / location, and if not, to reject the connection attempt and / or to force the UE to roam / register with another network covering this specific area / location (for example, by providing the identity of another network in a rejection / error / (re)configuration message); or to verify / ensure that public alert signals are sent only to the UE.

[0085] b) Device UE24 is within the coverage area of ​​an existing network infrastructure, connected to a PLMN that does not have a roaming agreement (for example, because a new first responder network 200 always starts as a fresh network). In this scenario, the network controller device A20 of the first responder network 200 captures the concealed device identity (e.g., SUCI) or globally unique temporary identifier (e.g., GUTI) of device UE24 via device B22. Initial and transient radio resource allocations (e.g., PDCCH in a 5G network) without security context (e.g., RRC setup phase in a 5G network) can be established between device B22 and device UE24 (e.g., as specified by the 3GPP® TS38.331 Radio Resource Control (RRC) protocol specification) to enable the exchange of these transient network identifiers without security context. The functions in the network controller device A20 (e.g., the 5G access and mobility function AMF) can be used to identify the home PLMN of device UE24 by decoding a temporary identifier (e.g., obtaining MCC and MNC information from SUCI), and to establish a temporary roaming agreement for the duration of the MCI event at a specific location of the MCI event. The temporary roaming agreement is established if the first responder network 200 can prove its integrity to the home PLMN based on a trusted hardware route (e.g., a trusted GSMA route) established by a trusted platform recognized by the network operator, or if the first responder network 200 can prove that an emergency is occurring (e.g., through a digital certificate signed by the first responder agency or government).Communication between the first responder network 200 and the remote provisioning platform is established only if the first responder network 200 can demonstrate its integrity through a trusted route established on a trusted platform recognized by the network operator (e.g., a GSMA route for trust and security domains, as described in the GSMA SGP.22-RSP technical specification).

[0086] c) Device UE24 is not provided with any network certificates (e.g., a (new) mobile phone without a network subscriber identification module (SIM) profile). In this scenario, device UE24 is provided with a network certificate for the first responder network 200 via a generic provisioning server (e.g., as specified in the route discovery service specified in the GSMA-SGP.22 RSP technical specification) using an out-of-band (e.g., Wi-Fi) communication link established between device B22 and device UE24, either directly or via another device UE24 (e.g., a first responder UE connected to device UE24 via a sidelink).

[0087] Furthermore, in all of the above scenarios, or in independent embodiments, an implicit invitation or connection trigger / request can be sent to these devices, for example, by making contact with an active PLMN within a given MCI area (for example, by device 20 after these devices have been discovered by device UE22 (for example, by receiving some signals from device UE24 within the target geographic area of ​​the MCI area). In such a case, a lawfully regulated device B22 of the first responder network 200 can scan for PLMNs within the MCI area and request each of these PLMNs (for permission) to trigger roaming control plane steering (for example, as specified in GSMA IR.73 Roaming Steering Implementation Guidelines, version 5.0), or to trigger device UE24 to move into private network connection mode by setting up a secure channel between the first responder network 200 and the respective PLMN using the method described above. The home PLMN of device UE24 within the MCI area may temporarily set the first responder network 200 as the highest priority network for a specified period after the occurrence of an MCI event. Alternatively, the functions of the network controller device A20 of the first responder network 200 may communicate with the functions of the home PLMN network within the target MCI area (e.g., the access and mobility functions AMF in a 5G system) via a secure and integrated channel (e.g., the network exposure function NEF in a 5G system, or one of the other aforementioned methods for setting up a secure channel between the first responder network 200 and each PLMN) to distribute roaming steering information (e.g., a list of PLMN identities including the identity and priority of the first responder network) and / or a priority list of non-public networks to all device UE24 connected to a particular home PLMN.

[0088] In addition, in all of the above scenarios, or in independent embodiments, an explicit invitation or connection trigger / request may be sent by device B22 to device UE24 in the target geographic area of ​​the MCI area (e.g., when there are no available homes and / or preferred PLMNs in the target geographic area of ​​the MCI area). In such cases, specific and lawfully regulated broadcast information about the MCI event (e.g., a system information block SIB, as specified by the 3GPP® TS38.331 Radio Resource Control (RRC) protocol specification) may be sent as a signaling message during the initial random access radio setup phase (e.g., the 5G system's signaling radio bearer 1 SRB1 and RRC setup) or as part of information (e.g., system information) broadcast by device B22 in the first responder network 200. Such signaling messages (e.g., broadcasted system information messages), or the payload / information elements of such signaling messages, are securely signed / encrypted (e.g., using a mechanism such as that described in TR33.809) by using a key used for emergency / MCI events (e.g., a pre-configured pre-shared key on device UE24) and / or by using a key provided with a digitally signed certificate by, for example, a first responder organization or government, or by using a key derived from one of such keys / certificates. The signaling message includes an identifier of the key used (if multiple keys exist for similar purposes (e.g., for emergencies)) and information about the nonce / salt used to derive the certificate to verify / decrypt the signed signaling message, so that device UE24 can decrypt the signaling message and / or verify that the signaling message is authentic.Alternatively, the signaling message may include a unique string (e.g., part of a human-readable name or part of a network or cell identifier) ​​that is recognizable / preconfigurable by device UE24 to represent a first responder network, emergency network, or other network that is available / should be available / should be available in an emergency, in a specific geographic area, or, for example, when other known networks are unavailable, and / or the signaling message may include a public key (e.g., as part of a digitally signed certificate) and / or a key identifier (e.g., a pre-shared (public) key) and / or an address (e.g., a URL) from which key material can be retrieved, so that device UE24 can use such a key during network authentication (e.g., after retrieving key material from its storage or a given address), so that the network can prove to the device that the network possesses the matching / private key. In the case of a digitally signed certificate, device UE24 verifies whether the digitally signed certificate was signed by a trusted certificate authority by checking whether the digitally signed certificate corresponds to / links to a trusted root certificate stored / pre-configured on device UE24.

[0089] Alternatively or additionally, device UE24 may contact a server (e.g., an authentication server operated by its home PLMN, certification authority, device manufacturer, or other trusted organization) via a data connection, for example, through the home PLMN to which device UE24 is connected, or through a Wi-Fi network to which device UE24 is connected (either directly connected to the Internet or connected to a data network of a mobile carrier network via a non-3GPP® Interworking Function (N3IWF)), or through an emergency / RLOS connection (e.g., via a first responder network). When connecting to such an authentication server, device UE24 requests authentication for each network (e.g., the network from which device UE24 received the signaling message) and / or obtains permission to access each network and / or requests verification of the public key / certificate received from each network (e.g., to verify whether the certificate is still valid and has not been revoked) and / or verifies whether each network is trustworthy (e.g., not part of a blacklist) and / or requests decryption of the encrypted signaling message or encrypted payload within the signaling message. Contacting such an authentication server involves sending a message containing a copy of the signaling message or a subset of its contents (such as a public key), the identity of the network / cell from which the authentication server received the signaling message, and / or the identity of device UE24, and / or the certificate of device UE24.Alternatively, after receiving a signaling message (e.g., an invitation / request / system information block) from the First Responder Network, device UE24 may use its current connection to its home network (e.g., via a nearby base station) or set up a new connection to its home network, send a message (e.g., an RRC or NAS message) to its home network along with a copy / subset of the information received from the First Responder Network (e.g., via a signaling message), and have permission to connect to the First Responder Network requested and / or accepted by the home network. The home network sends a message to device UE24 to accept such a request / permission, and / or updates its roaming steering information, non-public network preference list, and / or device UE24's policy information (e.g., by adding the First Responder Network's identity to the roaming steering information or non-public network preference list) to enable device UE24 to connect to the First Responder Network. The home network will also unregister device UE24.

[0090] Signaling messages as described above are also indirectly received by device UE24 from the first responder network via a sidelink (e.g., via a ProSe UE-network relay that provides signaling information, including PLMN identity information, and information about the emergency (e.g., through emergency-specific relay service codes) during connection setup such as ProSe discovery information or TS23.304). Signaling messages are also received from the home network to which device UE24 is connected or from access devices operated by the home network, thereby the signaling messages include messages / information to request and / or authorize device UE24 to connect to the first responder network instead (e.g., via a roaming trigger, or by sending a message to device UE24, to (temporarily) discard the configuration of the roaming steering / non-public network preference list). The home network also triggers updates to the tracking area in order to trigger device UE24 to connect to the first responder network instead of device UE's home network, and / or (temporarily) configures device UE in the unauthorized / forbidden area so that the area (partially) covers the MCI area, and / or configures the access device to (temporarily) add device UE24 to the unauthorized / forbidden area. For this purpose, the first responder network provides device UE24's home network with information about the target geographic area (e.g., the MCI area). This also allows device UE24's home network to send a signaling message to device UE24, for example, if it is currently in the target geographic area. This signal or message is transmitted on a dedicated frequency band to indicate that it originates from the first responder network 200 and / or to indicate an emergency. Furthermore, the signal is transmitted on multiple different frequencies.For this purpose, device B22 receives network configuration information from network controller device 20 so that device UE24 can set up a communication channel. The network configuration information includes information for configuring access devices to invite or trigger / request device UE24 to connect to a specific slice / frequency of the network within the MCI area, and / or can be used to authorize access devices. The network configuration information includes, for example, the authority for access devices to invite or trigger / request wireless communication devices or additional access devices within the area to connect to the core network, network / slice-specific settings (bandwidth / frequency, authorized devices, services provided, restricted local operator services (RLOS), steering / priority list for roaming on non-public networks, emergency / non-emergency slice instructions, etc.), and certificates (e.g., private keys) required to authorize the first responder device UE24. The operating band / frequency that will be provided in the network configuration information is a special emergency band for MCI events or first responder networks. This is also one or more common frequency bands supported by many UEs, and / or well-known operators within the area. In order for a first responder network within an MCI area to determine whether it is permitted to transmit on a particular frequency, the first responder network must first scan the area for any existing PLMNs operating within the area, identify their MCC / MNC codes, identify the nearest base station, measure its signal strength, and connect with these PLMNs to request permission to send invitation or connection trigger / request signals on one or more frequency bands operated by the PLMNs.If the nearest base station is very far away, and / or a particular PLMN is not active in the area, or if a particular band cannot be measured as being in use, for example, because a base station in the area is destroyed or the signal is very weak, the network controller provides the respective frequencies as part of the network configuration information and authorizes / authorizes access device B22 to use these frequency bands to send invitation or connection trigger / request signals. An invitation to device UE24 may also be transmitted via an access device B22 different from the access device B22 (e.g., a Wi-Fi access point) that device UE24 will connect to the first responder network (e.g., a cellular base station) (through a Wi-Fi beacon or probe response message, or, for example, an information element in a paging message from a non-3GPP® interworking function that device UE24 connects to via the Wi-Fi access point).

[0091] Furthermore, invitations are limited to or targeted at specific groups of victims and their corresponding device UE24s, grouped based on victim characteristics including, but not limited to, movement, location, and severity of injury. For this purpose, a location management service or other location estimation function (e.g., on device A20 or device B22) can detect the movement of UEs based on observations of the location of a set of device UE24s within the MCI area over a specific period of time. For example, a victim with a severe leg injury may not be able to move around the MCI area, meaning that the victim's device UE24 has not moved for an extended period. On the other hand, an uninjured victim may be walking around the MCI area, meaning that the victim's device UE24 has moved. Device B22 of the first responder network scans the area to identify such characteristics of device UE24s within the MCI area and groups them based on derived characteristics of the victims, such as moving and non-moving groups of device UEs. Generally, the non-moving group of victims may require priority triage because they are considered to be more severely injured. Additionally, before assigning device UE24 to such a cluster / group, device A20 or device B22 excludes the first responder device from the cluster / group (for example, by distinguishing the first responder device from other devices based on its registration or capabilities) and excludes devices belonging to other clusters / groups (for example, clusters of areas that group people, such as those designating victims or bystanders in a specific triage area).

[0092] Based on this clustering, device B22 first sends an invitation or connection trigger / request only to the non-mobile device UE24 within the MCI area, as it is very certain that the victim of the corresponding non-mobile device UE24 is severely injured and requires immediate triage.

[0093] More generally, several device UE24s are grouped into clusters based on the tarp triage status, the spatial location of the device UE24s, and other characteristics of devices in a cluster and / or device UEs at the center of a cluster (including, but not limited to, dimensions in the horizontal and vertical planes (e.g., area or tarp size), the number of associated devices, positional accuracy, location of the cluster and devices within the cluster, and the distance from the center of the cluster to the device UE24s). A cluster is typically represented by a set / group of devices that have a common set of characteristics (e.g., communication / device / user characteristics) and / or are within a defined area or within a certain maximum distance from each other.

[0094] The characteristics for recognizing / forming clusters are also distinguishable features (sets) of a set of devices that are available / not applicable to other devices. For example, devices are clustered depending on whether the device is moving around (which indicates that the injuries of the person carrying the device are not very severe) or not moving for a certain period of time (which indicates that the injuries of the person carrying the device are more severe).

[0095] Alternatively, device 20 in the first responder network recognizes the center of a cluster / group through its communication characteristics (e.g., high bandwidth, low latency, QoS requirements). Additionally, device 20 detects / infers which devices will belong to a particular cluster / group if all devices have similar communication characteristics (e.g., same QoS, similar traffic patterns, same bandwidth or operating within the same slice or closed access group, supporting the same capabilities, or all connected to each other via D2D / sidelink communication, or operating with similar (application-controlled) group / multicast communication).

[0096] Such clusters / groups of devices can be recognized / formed in device A based on triage applications or information provided / collected via device B or via a third-party positioning server, for example, by network analysis functions (such as NWDAF), or based on the distance measured between multiple UEs and the cluster / group, or based on the communication characteristics of devices within a particular cluster / group.

[0097] Device A sends information about a cluster / group of wireless communication devices to Device B, and Device B invites / triggers / requests each of these devices in such a cluster / group to join the wireless communication network.

[0098] For this purpose, device B operates or connects to a first device for supporting the establishment of a wireless communication network (200), and the device - Connect to the network controller device A (20) of the wireless communication network (200) and establish a wireless connection to the wireless communication device (24) within the target geographic area. - Receiving information about a cluster / group of wireless communication devices (24) (or at least a subset of a cluster / group of wireless communication devices whose determined location is within a target geographic area / coverage area), wherein the information received includes (but is not limited to) device identifiers, locations, and / or common characteristics of the wireless communication devices within the cluster / group. - Receiving information from the network controller device (20) about the network configuration for setting up a communication channel with the wireless communication device (24), - To invite or trigger wireless communication devices (24) of a cluster / group of wireless communication devices to register or unregister via a communication channel or other communication channel to the core network operated by the network controller device (20) and It was configured to perform the following actions.

[0099] Device A20 (or another device in the first responder network) includes or connects to a second device for determining clusters / groups of wireless communication devices in a wireless network (e.g., first responder network 200), the device receiving or learning at least one of resource usage data, location or distance measurement information, device characteristics, communication characteristics, measurement data, user characteristics of multiple wireless communication devices (e.g., device UE24), and assigning a minimum number of wireless communication devices to determine clusters / groups of wireless communication devices. • Distance between wireless communication devices, • The distance between the wireless communication device and the anchor device (e.g., device B22), • The distance between the wireless communication device and the location of the wireless communication device in the target geographic region or related to the target geographic region. • Communication pattern information, and • Overlap in communication characteristics, device characteristics, and user characteristics Calculate at least one of the following: • The calculated distance between at least a minimum number of wireless communication devices is between the minimum distance measurement threshold and the maximum distance measurement threshold. • The calculated distance between at least a minimum number of wireless communication devices and anchor devices is between the minimum distance measurement threshold and the maximum distance measurement threshold. • The calculated distance between at least a minimum number of wireless communication devices and the target geographic area is between the minimum distance measurement threshold and the maximum distance measurement threshold. • At least a minimum number of wireless communication devices have the same communication pattern, or thereby the time variation is between the minimum time variation threshold and the maximum time variation threshold, and • At least a minimum number of wireless communication devices share the same communication characteristics, device characteristics, and user characteristics. It is configured to determine a cluster / group of wireless communication devices based on at least one of the following.

[0100] The above-described apparatus for supporting the establishment of a wireless network, or for determining clusters / groups of mobile devices in a wireless network, includes identifying mobile wireless devices (e.g., device UE24) within a cluster / group, monitoring the location of identified devices within a cluster / group to detect movement of identified devices between different clusters / groups, and / or associating a cluster / group with an identified device, or monitoring at least one communication characteristic of an identified device within a cluster / group to determine a change in the associated cluster / group of an identified device, and / or, - Triggering the unregistration of identified devices from the network or slice. - Triggering a handover to a different access device, or a connection to a device via a side link. - Assigning devices to different clusters / groups of devices, - Sending different invitation messages to devices, - Changing QoS, or adapting resource allocation for a device. - Changing the set of slices allowed for the device, - Changing the communication parameters of the access device, - Triggering the sending of messages (e.g., via NEF, SMS) that include an alert that a specific victim or wireless communication device has moved to a different tarp or outside the area (e.g., to a hospital). The system is further configured to perform one or more of the following actions. These actions are triggered when an identified device moves beyond a configured threshold distance from the center of a cluster / group or from another device within the cluster / group, and / or moves below a configured threshold distance from the center of another cluster / group or from another device. These actions are also triggered when the current access device (anchor node, e.g., device B22) is unable to achieve QoS for devices within the cluster / group or a specific target geographical area at its current location.

[0101] Any of the above devices, the first and second devices, and a set of wireless communication devices (e.g., device UE24) form a system, the wireless communication devices transmit at least one of resource usage data, location or distance measurement information, device characteristics, communication characteristics, measurement data, and user characteristics to the second device, the first device receives information about a cluster or group of wireless communication devices (24), sets up a communication channel with the wireless communication devices (24), and invites or triggers the wireless communication devices (24) of the cluster or group of wireless communication devices to register or unregister via the communication channel or other communication channels to the core network operated by the network controller device (20).

[0102] Upon registration, the unique identifier (e.g., 5G-GUTI) of the wireless communication device UE24 received by device B22 in the first responder network 200 can be used to derive / retrieve subscriber information and device identifiers and to authenticate the wireless communication device.

[0103] A robotic device, drone, vehicle, or other mobile device acting as an access device is configured to receive information from device 20 so that it can authenticate and / or identify itself as a first responder device and have the ability to locally perform the corresponding core network functions (e.g., AMF / MME, AUSF, UDM / HSS), and as a result, can perform the task of locally registering with the network (for example, for a wireless communication device within the coverage area of ​​an access device operated by a mobile device) if it goes out of coverage and loses connection to device A20. This approach is similar to connecting an external device (from another emergency department) to device A20 to authenticate the wireless communication device, rather than having device A20 perform authentication on its own. The UDM / HSS operated by such devices includes only a subset of (pre-registered) subscribers available in the UDM / HSS of the first responder network, and / or only a subset of (pre-registered) subscribers authorized to register with the first responder network (e.g., through a roaming connection to the UDM / HSS operated by the home PLMN of the wireless communications device).

[0104] As another or additional option that can be added to or implemented independently of any other embodiment, if a wireless communication device is not known to or pre-registered with the Unified Data Management Function (UDM) or Home Subscriber Server (HSS) of the First Responder Network 200, and the First Responder Network 200 is not known to or available to a home network with which it has a roaming agreement, the First Responder Network 200 authenticates the device and derives the device's identity and subscriber information by contacting an external device that is temporarily connected to the First Responder Network 200 at the time of an MCI event and operates an AUSF / UDM / HSS (or a copy thereof) of another network (e.g., from a First Responder Department in a neighboring region), and by redirecting the authentication request to the external device.

[0105] In one example, a wireless communication device carried by personnel from a different region (e.g., a fire brigade in a neighboring region) can be considered an inbound roaming device to the first responder network 200. Typically, the visiting network can connect to the home network of this inbound roaming device to verify its access rights and other information. In the case of an MCI event involving a temporary non-public network, this occurs when the backend infrastructure is down. One of the devices (e.g., UE, mobile base station / drone, or specially dedicated devices carried by personnel from different regions) connects to the network controller (i.e., wirelessly or wireline) to (temporarily) assume the role of authenticator (e.g., Authentication Server Function (AUSF)) and subscriber owner registry (e.g., UDM, HSS) for these inbound roaming devices, and is connectable to the core network of device A20 of the first responder network 200 (e.g., via SCEF / NEF or SBA framework, with appropriate certificates). This device has duplicate versions of these components from the home network and / or includes a (pre-registered) subset of subscribers available in the UDM / HSS of each home network (e.g., the network for personnel from different regions).

[0106] In other words, device A20 incorporates or connects to equipment for supporting the establishment of a wireless communication network (200), and the equipment, - To enable the external device to function as an authenticator and / or subscriber owner registry for a set of wireless communication devices (24), and / or to connect to the core network of the wireless communication network (200) via a limited-range local connection. It was configured to perform the following actions.

[0107] For this purpose, an external device (operated / owned by a different operator or network) enables the operation of an internal interface or protocol and / or the setup of a connection to the network controller device A20 via a limited-range local connection, and connects to another core network (in this case, the wireless communications network 200) so that the external device can function as an authenticator and / or subscriber owner registry for a set of wireless communications devices (24).

[0108] Such external devices and such network controller devices A20, which incorporate or are connected to devices for supporting the establishment of a wireless communication network, are used in a wireless communication system comprising one or more wireless communication devices (24), an access device (22) connected to a network controller device (20), and such external devices, the system being configured to perform device authentication of the wireless communication devices (24) via a link between the network controller device (20) and the external devices (operated / owned by different operators or different networks).

[0109] This connection is essentially temporary; all information related to the registered device (e.g., related to AUSF / UDM / UDR) is removed before unconnecting, and any specific security certificates are renewed before connecting to another network. Such connectivity is achieved by the external device connecting to the network operated by the network controller device (20) by performing a mobile registration procedure via an access device (22) (which allows the external device to use EAP-AKA with SIM-based certificates), or by initiating an unauthenticated emergency connection to the network operated by the network controller device (20), or by setting up a disaster roaming connection such as TS23.501, or by setting up a connection to a network exposure function (NEF) such as TS23.501 of the network operated by the network controller device (20), or by setting up a service-based interface (SBI) connection such as TS33.501 (for example, between the AMF of the network operated by the network controller device (20) and the UDM / AUSF operated by the external device), and / or by providing the address of the AAA server to the network controller device (20) which configures its AUSF or network slice and SNPN authentication and authorization function (NSSAAF) to use such an external AAA server for authentication. To securely set up the connection, the external device and the network controller device 20 perform a security handshake, for example, by using a pre-shared / pre-configured certificate, or by using an emergency / disaster roaming certificate, or by providing / proving ownership of a special key or certificate (e.g., digitally signed by a certification authority for emergency medical personnel or by a government) during the connection.

[0110] Furthermore, the first responder's devices are capable of supporting side-link communication (e.g., ProSe D2D communication), and therefore can set up temporary / mesh-type networks. In such situations, it is wise to assign sets of devices to first responders in different specific regions or different first responder networks, which are usually known to each other and can form temporary / mesh-type networks, and to have them all participate in a distributed ledger. As a result, devices in this ledger can prove that incoming roaming devices belong to the first responder equipment in this same network / region.

[0111] As an alternative or addition, devices can each run a group application, thereby each device in a particular group having the same core group key, and by this key, each of these devices can check whether another device (i.e., an inbound roaming device to the First Responder Network 200) belongs to this same group by verifying whether a temporary key, hash / nonce, authentication code, signature, or other data was signed with a key derived from this group key. As a result, such groups of devices (i.e., such groups of devices having the same group key or running the same distributed ledger) can all be added to the First Responder Network 200 at once, or alternatively, if one device in a group of devices (from different regional First Responder divisions / networks) is properly authenticated, authorized, and registered with the network, this device can act as an authenticator for other devices from the same group that are trying to register. This single registered device must first undergo several additional authentication, authorization, and verification steps, for example, by possessing a special key or certificate (e.g., digitally signed by a certification authority for emergency responders) during registration to prove that the wireless communication device belongs to the primary responder.

[0112] Alternatively or additionally, the first responder network may perform additional verification checks based on the capabilities of the wireless communication device, for example, by checking whether the wireless communication device has certain unique capabilities common to first responder devices that are not typically the case for ordinary consumer devices (such as support for Bandwidth 14 (Firstnet), high-power operation, and ProSe relay support).

[0113] As an alternative, the first responder network 200 would contact a network-trusted third-party portal (e.g., an identity information server operated by a government, GSMA, or other organization) capable of securely processing user data and device data.

[0114] Device and user information obtained from the user data resolution server is used to register devices or to securely provide the network certificate of the first responder network 200 (e.g., subscriber identification module SIM profile) via a remote provisioning platform (e.g., as described in the GSMA SGP.21-RSP architecture). Communication between the first responder network 200 and the remote provisioning platform is established only if the first responder network 200 can prove its integrity through a trusted route (e.g., a trusted GSMA route) established using a trusted platform recognized by the network operator.

[0115] Furthermore, the invitation or connection trigger / request signal / message sent to the device UE24 includes information about the cause of the urgent establishment. This information is provided in a special or dedicated information element (IE) or in the preamble portion of the invitation or connection trigger / request message.

[0116] To achieve the required communication links, device B22 supports, in particular, a single-hop relay link 22S and / or a multi-hop relay link 22M to device UE24, and / or a base station relay link 22R.

[0117] The target geographic region can focus on areas specific to triage (e.g., areas with the highest concentration of injured people, areas with fewer seriously injured people, etc.) or is linked to a set of spatial formation requirements for identifying cluster formation (e.g., when multiple devices UE24 are within a configurable radius around specified relative coordinates, specified device UE24, centroid, baseline, etc.). In one example, information about potential target areas (e.g., areas with a high concentration of potentially injured people) can be provided, for example, by one or more devices B22 or by separate devices via network exposure (NEF) and application (AF) functions. In another example, a LiDAR camera is used to find mobile phones and / or traces of people's heat, thus locating clusters of devices. Furthermore, victim / injured triage-specific areas are identified by different colored triage tarps (e.g., indicating the severity of the injury, respectively). The location (and color) of these tarps is determined via a camera or other color detector operating on a drone or other access device (e.g., a mobile base station), a camera on an ambulance or fire truck, or a security camera available on site, or provided to the network by a first responder (e.g., via NEF or directly via a data connection with SLAM functionality). As another or additional option that can be added to or implemented independently of any other embodiment, the tarps may be provided with a wireless device (possibly including a GPS module) that can register with the network to enable automatic location determination. In this ability, or through matching the identity of the wireless device, the color of its corners and its size / shape / metric / relative position can be determined. Alternatively, the tarps may be equipped with location markers (e.g., Bluetooth iBeacon®) that broadcast their location, size, etc.

[0118] As another or additional option, which can be added to or implemented independently of any other embodiment, the tarp is digitally recreated by device B or any other device, which is capable and connected to or not connected to the first responder network within the MCI area, so that the boundaries and dimensions of the tarp are drawn with visible optical markers (e.g., using a laser projector). Depending on the number of injured persons physically present within the digital tarp, the dimensions of the tarp can be automatically increased or decreased by device A20 of the first responder network or via a third-party service. Additionally, if the physical tarps are positioned such that the boundaries of the tarps overlap each other, the actual ranging distance of device UE24 located at the center of the tarp can be reduced by the device, either directly, via device B, or via a third-party ranging service. A first responder operating from a remote location within the MCI area can digitally recreate the MCI area, including the tarp, devices, MCI environment, and characteristics including, but not limited to, the location, communication patterns, and movements of the first responder, victim, and onlookers, based on information obtained by the respective UE24 devices of first responders physically present within the MCI area. Even such remote first responders can monitor the victim's health status through robust patient monitoring, either directly connected to the victim or shared among multiple victims, depending on the severity of the injury and the victim's triage status.

[0119] Additionally, first responders within an MCI area may be assisted by drones or robotic devices capable of performing tasks including, but not limited to, transporting victims, medications, and / or tools to tarps or designated locations within and around the MCI area; beacons for various functions including, but not limited to, road guides or road finders for first responders, victims, and onlookers; cluster formation; victim identification and tracking; asset positioning; and medication transport. In one example, such a beacon drone could assist first responders in moving victims to a specific tarp based on relative positioning between different tarp locations when multiple tarps are in the vicinity.

[0120] In addition, if an urgent or restricted Local Operator Service (RLOS) connection is required by the home PLMN of device UE24 or by national regulations concerning mobile networks within the MCI area, an initial connection to a first responder network 200 with restricted service access can be established using device UE24 (for example, as specified in 3GPP® TS22.011 Service Accessibility Continuity of Service provision). Device 20 is configured with special privileges to update or discard PLMN selection procedures to enable roaming of device UE24 within the first responder network 200 (for example, as specified in 3GPP® TS22.011 Service Accessibility Roaming Steering Information), or similarly to update a preferred list of non-public networks, as in TS23.501. Device UE24 is currently connected to the First Responder Network 200 as a roaming device after successfully completing a roaming authentication procedure (for example, as specified under Service Access Authority in 3GPP® TS33.501 Security Architecture and Procedure for 5G Systems). This is based on special cooperation between the Emergency or RLOS operator and the mobile operator of Device UE24, or on national regulations to identify, authorize, and permit Device A20 of the First Responder Network 200 to establish limited services using Device UE24 at MCI locations.This can be indicated (for example, by including a unique certificate or key identifier of a pre-configured key, or by including a securely signed information element of system information or securely signed system information (for example, as described in TR33.809)), thereby using a key for an emergency / MCI event (for example, a pre-configured pre-shared key in device UE24) and / or using a key provided with a digitally signed certificate by, for example, a first responder organization or government, or using a key derived from one of such keys / certificates in one of the network broadcast information blocks (for example, a system information block (SIB) as specified in the 3GPP® TS38.331 Radio Resource Control (RRC) protocol specification) of the first responder network 200, while implicitly and explicitly sending invitations or connection triggers / requests to device UE24 at the MCI location.

[0121] Once the wireless communication devices of first responders and injured persons within the MCI area are connected to the first responder network 200, the connection can be readily used to communicate relationship information between first responder personnel and injured persons (groups) to, for example, keep them informed of what happened, provide instructions on what to do next, or enable victims to state when they begin to feel unwell. To do this, the First Responder can remotely configure and control victim device UE24 or groups of device UE24 belonging to a specific class of victim (e.g., severely injured, lightly injured) (for example, by using device 20, or access device 22, or a First Responder UE connected to a First Responder network operated by / accessible through device 20 and / or access device 22), and as a result, an audio / video / data call may be automatically answered or initiated from the First Responder's specific device UE24, especially when the victim is unable to operate the device UE24, by sending emergency instructions (and / or emergency certificates) during the setup of a call to the device UE24, for example by calling a special number related to the phone number of the device UE24, or by sending USIM application / service commands or (secret) dial codes to the device UE24, or by sending public alarm signals or broadcast messages, or SMS with special codes (e.g., via a multicast / broadcast service framework). Alternatively, the device UE can be configured to answer all incoming audio / video / data calls initiated by the first responder and to block all other calls for a specified period of time.Alternatively, if device UE24 supports push-to-talk functionality, messages may be transmitted via one or more frequencies, or by transmitting one or more messages supported by one or more push-to-talk systems (e.g., mission-critical push-to-talk as defined in 3GPP® TS24.379).

[0122] Alternatively, the First Responder may use Device 20, or Access Device 22, or a First Responder UE connected to a First Responder network operated by / accessible through Device 20 and / or Access Device 22, to set up a sidelink / PC5 to ProSe applications / services provided by Device UE24 for such purposes (e.g., ProSe applications / services that enable the establishment of an automatically accepted connection to Device UE24 (without showing any pop-up / user confirmation dialog), and / or ProSe applications / services for configuring the device by sending configuration messages (e.g., to discard certain restrictions / policies or to prevent notification pop-ups on Device UE24 that require authorization through user action), and / or ProSe applications / services for retrieving the device's location, and / or a ProSe application for requesting Device UE24 to set up a connection to the First Responder network). For example, this is achieved by using PC5 direct communication, as specified in TS23.304, between device 20, access device 22, or first responder UE and device UE 24 for this particular application / service (e.g., ProSe configuration service or ProSe emergency service).

[0123] In one example, device UE24 is configured with special permissions to revoke / reconfigure other permissions / restrictions / policies or block pop-ups, along with a password, key, or other certificate that may be provided to the device (e.g., through one of the methods described above for establishing a connection and / or after such a connection has been established) in order to verify / enable / authorize such special permissions. Alternatively, device UE24 is configured with a password, key, or other certificate that can revoke / reconfigure a set of permissions / restrictions / policies. In another example, the user of device UE24 also pre-consents permissions to revoke / reconfigure other permissions / restrictions / policies or block pop-ups under certain conditions (such as an emergency / MCI event) by storing acceptance of such special permissions in, for example, the Integrated Data Manager (UDM), Integrated Data Repository (UDR), or Home Subscriber Server (HSS) of device UE24's home network. The first responder uses device 20 or access device 22, or requests information that will allow the first responder UE to verify whether such special permissions are granted or enabled, or requests to verify that such special permissions are granted or enabled, or requests to be granted the authority to access such permissions, or to be granted the authority to connect to device UE 24 based on these permissions, or to be granted the authority to allow device UE 24 to connect to / through the first responder network, access device, or first responder UE.Such requests for information, verification, or authorization may be made, for example, through a roaming connection (e.g., between the NEF or the AMF of the First Responder Network and the UDM in the home network of device UE24), or through a connection with a Public Safety Response Point (PSAP), by connecting to the respective Integrated Data Manager (UDM), Integrated Data Repository (UDR), Home Subscriber Server (HSS), during the connection setup with device UE24, or when device UE24 registers a connection with the First Responder Network, access device, or First Responder UE / During setup, the PSAP may have access to the respective permission data, or the ability to revoke / grant permissions on behalf of or in cooperation with the device UE24's home network, or the PSAP may allow the first responder network to set up a connection to the device UE24's home network via the PSAP (e.g., to connect to its UDM), thereby allowing the PSAP to act as a relay / bridge between the two networks to enable information exchange. In another scenario, additional information about the device UE24's users (e.g., the name, phone number, and emergency contact number of the subscriber of the subscription linked to the device UE24) may be retrieved from the UDM / UDR / HSS.Using telephone numbers and / or emergency contact information (added to the information in the UDM / UDR / HSS, or listed as emergency contacts on the SIM card, non-volatile storage, or wearable connected to the device UE24 of each device UE24), the First Responder Network (or the device UE24's home network, or PSAP) may, by sending requests / notifications to the device UE24 or device linked to the emergency contact telephone number, "unlock" the device and discard certain permission / policy settings on the device UE24 (such as location privacy index settings), or discard a security lock on the device UE24 or SIM card, or accept an incoming invitation (e.g., to connect to the First Responder Network), a connection request (e.g., to retrieve device information such as the device's location), a location estimation request, a user identification request, or to retrieve a SIM profile, or to grant permission to perform these actions on behalf of the injured person. Such invitations are, for example, SMS messages that originate from pre-configured phone numbers (operated by, for example, government agencies, such as PSAPs) that have specific keywords or character codes / combinations or identity information, and include first responder network identity information and several emergency certificates.After confirming a request / notification to “unlock” device UE24 (for example, by responding to a message and / or by providing a certificate to unlock the device (for example, in a response message) and / or by a receiving device to send a message (e.g., an SMS message) to device UE24 that originates from a pre-configured phone number, such as the phone number of one of the emergency contacts stored on the device UE's SIM card, non-volatile storage, or a wearable device connected to device UE24, and / or by device UE24 initiating connection setup to the first responder network), the first responder network is granted access to information about device UE24, such as the location of device UE24, and / or device UE24 begins setting up a connection to the first responder network. As an addition or alternative, when device UE24 receives a notification to “unlock” the device and / or receives a specific message (e.g., an SMS containing specific keywords or character codes / combinations or identity information, and coming from a pre-configured phone number (e.g., operated by a government agency, such as PSAP)), device UE24 retrieves a list of emergency contacts (e.g., a set of phone numbers) from device UE's SIM card, non-volatile storage, or a wearable connected to device UE24, and automatically sends a message (e.g., an SMS) to these emergency contact phone numbers containing a request / notification to “unlock” device UE24.

[0124] Device A20 stores information about identified injured persons and devices associated with them (e.g., information about mobile phones and wearable monitoring devices, along with the injured person's identifier, phone number, personal data, emergency contact information, severity of the injured person's injury, triage color, received electronic patient records, and the injured person's current location) in a database, enabling easy filtering, providing an overview of specific severity levels for all injured persons, and facilitating contact with injured persons as a group or individually.

[0125] One or more device UE24 comprises a subscriber identification module 242 associated with a mobile carrier subscription (e.g., a universal integrated circuit card (UICC) including a subscriber identification module (SIM) card or a universal mobile telecommunications system (UMTS) SIM (USIM) card), a radio module 244 for wireless communication, and at least one user application (app) 246. The device UE24 is configured to support a sidelink communication link 24SL between these.

[0126] As an additional option, if device UE24 is still connected to an existing PLMN operating within the same MCI area, the first responder network 200 (e.g., device A20) may send messages (e.g., via a data connection) to a specific emergency application running on device UE24, either directly or routed via the home PLMN, enabling device UE24 to set up an emergency call (or RLOS) connection to the first responder network 200 and / or to provide location information to the first responder network 200 via the home PLMN, via an application server (e.g., on the internet or operated by the home PLMN).

[0127] Device A20 is configured to receive device identity information from one or more device UE24 and to determine the user identity associated with the device identity of device UE24, for example, based on mobile carrier subscription information, or, in some cases, in addition to the device identity information, user identity information provided by device UE24 (e.g., digitally signed identity card, name / email / contact address, fingerprint scan) (e.g., digitally signed identity card, name / email / contact address, fingerprint scan). As mentioned above, information about user identity is also requested from or provided by device UE24's home network, for example, when device UE24 registers with a first responder network, thereby prompting the first responder network to request device UE24's home PLMN to provide user identity-related information (e.g., subscription information, name of subscriber, telephone number, emergency contact), and / or device UE24's location information. For this purpose, the first responder network must provide an emergency certificate (e.g., a digital certificate signed by the first responder agency or government), which, using the emergency certificate, can prove to the home PLMN of device UE24 that the first responder network is involved in an emergency and that it is important to provide the device identity information of device UE24 (e.g., based on the SUCI provided by the responder network to the home PLMN, which in return provides user identity information or location information about device UE24). Alternatively, the first responder network may request information about the user identity information and / or location information of device UE24 via the home network's NEF of the home PLMN. Similarly, the first responder network must provide an emergency certificate to enable such requests and the secure exchange of user identity information or location information via the NEF.Optionally, at least some of the devices UE24 (e.g., identified and pre-connected to the default network connection but not matched to the network settings of a particular first responder) are not distributed to the first responder when the first responder arrives in the MCI area. Therefore, there is no mapping to a particular person in the mobile operator's subscriber database. In such cases, the device UE24 can be manually linked to the first responder by retrieving details from the FRDB28 via device A20 by securely and confidentially entering user information into the device UE24 (e.g., manually scanning a government-issued first responder ID card, or scanning biometrics including but not limited to facial, fingerprint, and iris data). The information retrieved from the FRDB28 is available to device 20 to match the device UE24 to a particular first responder, depending on the role of that particular first responder in the MCI area. Network settings are provided using UE configuration update or UE parameter update procedures, or by using a remote provisioning server (e.g., as specified in the route discovery service specified in the GSMA-SGP.22 RSP technical specification).

[0128] As an alternative, the fully connected device UE24 of the first responder A can identify the first responder B on a connected FRDB server based on user identity information securely and confidentially collected on the first responder A's device UE24. This allows the network configuration and settings of the first responder B (e.g., subscriber information module SIM profile) to be securely retrieved and downloaded to the unconnected UE24 via an out-of-band channel (e.g., NFC or peer-to-peer Wi-Fi, Bluetooth connection).

[0129] The first responder network 200 is therefore established by devices A20, B22, and UE24 (as described in the 3GPP® specification as a 2G / 3G / 4G or 5G network, including, but not limited to, non-3GPP® access to unlicensed wireless spectrum such as Wi-Fi, Bluetooth, industrial, scientific, and medical (ISM) bands, or similar). The infrastructure of the first responder network 200 conforms to the specifications of the corresponding technology on which the network chooses to operate its devices A20, B22, and UE24.

[0130] Furthermore, all device UE24 deployed by a first responder within the first responder network 200 are typically capable of operating in one of their ISM bands, while the deployment of private mobile user devices (i.e., BYOD ("bring your own device")) within the MCI area is limited to the wireless technology available on the user device.

[0131] Therefore, the proposed first responder network 200 enables the automatic identification and registration (embedding) of a first responder's pre-registered device UE24 (e.g., a cellular device) to the first responder network available within the MCI area from the network side (i.e., device A20). Furthermore, deployed device UE24 can be prevented from connecting to public networks during MCI events, and unauthorized devices can be prevented from registering with the first responder network 200. If pre-registered, device UE24 can be pre-provided with the necessary configuration steering-of-roaming information, or similarly, a preferred list and certificates for non-public networks, to facilitate registration with the first responder network 200.

[0132] Furthermore, the proposed first responder network 200 enables the automatic registration of unregistered devices either directly by verifying user-linked identities (e.g., through cellular device platforms such as the Global Systems for Mobile Communications Association (GSMA) IMEI platform) or by pre-registering first responder devices within deployed infrastructure (e.g., FRDB28 of the core network) from the network side. Where certificates are not required, the first responder network 200 can provide some form of emergency or RLOS connection instead of fully registering and authenticating unregistered devices.

[0133] As described above, wireless communication devices carried by personnel from different regions (e.g., firefighters from a neighboring region) can be considered inbound roaming devices, or the first responder's devices can support sidelink communication and thus set up temporary / mesh-type networks, or each wireless communication device can perform group applications and thus all be added to the first responder network 200 at once, or one of a group of devices can function as an authenticator for other devices from the same group that are trying to register, or additional verification checks can be added based on the capabilities of the wireless communication devices.

[0134] In addition, the proposed first responder network 200 (e.g., device A20) allows for the automatic authorization and registration of base station devices (e.g., device B22) from various emergency services (e.g., fire departments, health ministries, and police departments), as well as other public and non-public network operators. The base station devices may also be IAB devices (e.g., as specified in TS38.174 Integrated Access and Backhaul Radio Transmission and Reception), in which case the access device B22 of the first responder network may function as an IAB donor to initiate the establishment of a first radio link with an IAB device (e.g., via S1 / NG interface security and integrated with IPSec using trusted hardware routes within the IAB device). Additionally, IAB devices may be equipped with an ID, private / public key pair, and manufacturer's certificate, which are necessary to establish a link between devices B22 (e.g., an X2 / Xn link) via a special service (e.g., an X2AP global procedure, as specified in 3GPP® TS36.423 X2 Application Protocol (X2AP)) at device A20 in the first responder network 200.

[0135] Furthermore, the proposed first responder network 200 (e.g., device A20) enables the automatic extraction of capabilities from base station devices (e.g., device B22) that will be registered with the first responder network 200.

[0136] Additionally, the proposed first responder network 200 (e.g., device A20) enables the automatic retrieval of identity information of a device UE24 (e.g., a wearable device) belonging to the injured person during the initial wireless setup phase (e.g., 5G_GUTI as specified in 3GPP® TS33.501 Security Architecture and Procedure for 5G Systems). The functionality in device A20 of the first responder network 200 (e.g., Access and Mobile Functions (AMF) as specified in 3GPP® TS23.501 System Architecture for 5G Systems) can be communicated to a similar function of the home PLMN (of device UE24) to securely retrieve the user context of device UE24 (e.g., subscriber information) and the device identity of device UE24 (e.g., IMEI). The injured person can be identified by matching the device ID to user information stored in a common cellular device platform (e.g., the GSMA IMEI platform), or by different network operators of the relevant device UE24, or by administrative agencies. The AMF of the first responder network 200 can communicate with the AMF / UDM / HSS of the home network (of the device UE24) to derive / transfer the context of the device UE24 (i.e., to provide such context information to the first responder network 200), including the Permanent Device Identifier (PEI), which is IMEI in 5G / 3GPP®.

[0137] In one example, wearable monitoring devices are provided to a patient or victim by a first responder. These monitoring devices are already pre-configured for the first responder network 200 and are automatically attached. However, these monitoring devices are not yet linked to a specific person (or only to a temporary / anonymous person identifier, such as John Doe1). In this case, some automatic identity matching with the nearest mobile phone or other wireless communication device can be performed, for example, by measuring the distance between the monitoring device and the mobile phone, or by measuring the distance between the first responder's wireless communication device and the mobile phone (so that the first responder's mobile phone is used to link the two devices together). Once the mobile phone is registered and the identity of the patient or victim can be determined (for example, using one of the mechanisms described above), it is also clear to whom the output of the monitoring device belongs. As an alternative or addition, a photograph of the injured or victim may be uploaded (e.g., to the monitoring device, the first responder's mobile phone, and / or network) to link the monitoring device to a specific injured or victim. The color of the triage tarp or label provided to the victim may also be uploaded to indicate the severity of the patient's injury. This information (e.g., the color of the triage label) and / or the location of the device may be broadcast periodically to enable easy tracking of the injured or victim. As an alternative, a copy of the injured or victim's emergency information in their mobile phone (e.g., locally stored on the mobile phone, or the identity of their Electronic Health Report (EHR)) may be read via Near Field Communication (NFC) or provided verbally or visually to the first responder's monitoring device or mobile phone, which may then upload this information to the network.Note that NFC in the monitoring device or the first responder's mobile device can also be used to provide the patient's or victim's mobile phone with a network certificate, enabling the patient's or victim's mobile phone to connect to the first responder network 200.

[0138] Additionally, if a person is moved to a different triage area (for example, if their condition becomes more severe), the wireless communication device for that person (e.g., a mobile phone, wearable monitor, or location tag) is updated to broadcast a different color. The relocation of a person is also detected by a drone or access device camera, or through location services (i.e., if the injured person's location now points to a different geographic area, for example, covered by a tarp of a different color). The wireless communication device is re-invited or triggered / requested to connect to the first responder network 200 and requested or updated to attach to a different slice (e.g., if more resources are needed for monitoring devices for more critically ill patients, or if additional monitoring devices, such as a 12-lead ECG, need to be attached to the injured person).

[0139] Figure 3 schematically shows block diagrams of network controller devices (i.e., device A) according to various embodiments.

[0140] Device A is installed in the first emergency vehicle to arrive at the first responder's location for an MCI event (e.g., a medical vehicle, fire truck, or unmanned aerial vehicle (UAV)) and includes a power supply (PS) unit 34 connected to the emergency vehicle's uninterrupted power supply.

[0141] Device A further comprises a transceiver (TRX) 31 for wireless transmission and reception with the first responder network 200, and at least one controller (RAN CTRL) 32 configured to provide the network controller function 202 shown in Figure 2, and to provide the capabilities of a radio access network (RAN), for example, equivalent to a base station of a cellular network. The controller 32 is configured to set up an integrated, protected, and secure communication channel for communication connectivity with Device B, Device UE, the central identity server, the first responder database, and other services outside the described system, and to provide the identity service function 204 shown in Figure 2.

[0142] Furthermore, device A is likely to be a base station device or other network access device coupled with core network functionality, and further comprises a backhaul communication module 35 that provides a direct satellite link as backhaul communication to enable Internet access and data routing to the backbone network. Other means of backhaul communication, such as optical wireless communication (OWC), may be further or alternatively deployed in device A. In one example, device A can be configured to provide a standalone end-to-end wireless system (e.g., a cellular network with the necessary hardware and software for a base station, a core network, and a backhaul network for providing Internet and data routing) via off-the-grid connectivity (e.g., deployed as a small cell system with a non-public network) or via an existing telecommunications grid (e.g., an existing mobile network operator (MNO) backbone). Furthermore, device A includes a Simultaneous Localization and Mapping (SLAM) module 33 (corresponding to the SLAM function 206 in Figure 2) which has sensors and a computer system (e.g., Radar, Lidar subsystems, etc.) for determining the MCI area and the number and type of devices to be deployed within the MCI area.

[0143] Figure 4 schematically shows block diagrams of access devices (i.e., Device B) in various embodiments. These are unmanned robotic devices, including but not limited to drones and rovers, or access devices mounted on, for example, an ambulance.

[0144] Device B includes a transceiver (TRX) 31 for wireless transmission and reception to and from a first-party network (for example, functioning as a gNB or Wi-Fi access point), and a relay function (RLF) 42 that provides relay node capabilities (for example, as described in 3GPP® TS24.334 V16.0.0 (2020-07): "Technical Specification Group Core Network and Terminals; Proximity-services (ProSe) User Equipment (UE) to ProSe function protocol aspects") or 3GPP® TS38.174 V16.3.0: "Technical Specification Group Radio Access Network; NR Integrated access and backhaul radio transmission and reception"), which can be controlled by Device A in a specific location limited to the MCI area.

[0145] Furthermore, device B includes a controller (CTRL) 43 configured to provide the ability to access the wireless first-party network provided by device A. The controller 43 is further configured to set up an integrated, protected, and secure communication channel for communication connectivity between device A and device UE.

[0146] In addition, device B is also equipped with an exclusive wireless system (XWS) 44 (e.g., Wi-Fi, Bluetooth, LoRa, etc.) in addition to the radio access capabilities necessary to access the first responder network provided by device A. In one example, the exclusive wireless system 44 can be used for separate sidelink communication links both from device B to device A and between devices B, as well as to enable more precise positioning (for example, by further transmitting signals from these other radio access capabilities to a hybrid positioning module in a location service operated by network 200).

[0147] Figure 5 schematically shows flowcharts of the first responder network deployment procedure (for example, in device A) according to various embodiments.

[0148] At the initial initiation of device A within the MCI area, a predetermined number of devices B (and / or other devices, such as drones dedicated to mapping tasks that do not provide cellular access) are deployed in the field to survey and map the MCI area, and to calculate the severity and scale of the MCI area, for example, in the SLAM module 33 in Figure 3 (step S510). In step S520, the deployed devices B, communicated to the device via a wireless link, are deployed on device A, or on a cloud communicated via device A, and update the measurement parameters of device B (e.g., total area in square meters, structural anchor points, number of victims, etc.) to a local SLAM service controlled by the SLAM function 206 in Figure 2 or the SLAM module 33 in Figure 3. In step S530, the SLAM service predicts the total number of devices B and their locations required in the field to fully cover the MCI area, with or without human supervision. The procedure in step S530 is supported by the use of a machine learning model.

[0149] Based on the results of the SLAM service, device B is deployed or removed from the field based on a predicted estimate of the number of first responders required to handle a particular MCI event.

[0150] More specifically, in step S530, the SLAM service estimates landmarks in a given geographic region based on sensor measurements obtained from sensors of device B22 and / or other devices dedicated to the mapping task. A landmark is a uniquely identifiable surface / object whose characteristics are estimated by the sensor. For example, the concrete wall of a high-rise building can be a landmark. The dimensions and refractive properties of such a landmark can be estimated, for example, by using a laser scanner or other optical measuring device present in at least some of the deployed device B22 and / or other devices dedicated to the mapping task.

[0151] While determining landmark boundaries using sensors from device B22 and / or other devices dedicated to the mapping task, the SLAM service in device A20 constructs a virtual 3D map of the MCI area using sensor data acquired from sensors from device B22 and / or other devices dedicated to the mapping task.

[0152] In addition to location and mapping measurements, the wireless radio provided on device B22 simultaneously measures wireless link quality parameters of the radio signal (including, but not limited to, received signal strength, channel status information, and reference signal received power) between device A20 and device B22 at its current location, and between device B22 and device UE24, which is attached to device B22 covering the MCI area (and its location). The SLAM service or other network function (such as NWDAF) on device A20 receives this wireless link quality information from each of the devices B22 at a configurable sampling rate to determine white spots of radio signals within the target geographic area.

[0153] Sensor measurements and wireless link quality parameters between device A20 and device B22 and / or other measuring devices can be used to predict the precise location of access points (i.e., device B22) to ensure adequate and reliable coverage of the wireless system of the first responder network 200. Based on this precise prediction of device B's placement, device A20 deploys additional access devices B22 and / or relay devices to enhance coverage of white spot areas of the wireless link between device A20 and device UE24 in the field. If there are redundant devices B22 in locations with good link quality, such redundant devices B22 can be removed (e.g., withdrawn from the location).

[0154] In MCI areas, the environment can change dynamically due to the catastrophic nature of events. Large buildings may collapse and become rubble, and large pieces of rubble may fill open spaces. The rubble in open spaces, including new metals, can change the environment to be both more favorable and less unfavorable for wireless communications. In such a constantly changing environment, the SLAM service will receive continuous measurement parameters from the sensors and wireless radios of device B22 and / or other devices dedicated to mapping tasks throughout the entire duration of the triage process in the MCI area, updating the SLAM service and ensuring high reliability and sufficient coverage for wireless connectivity.

[0155] Alternatively, the SLAM service can use an existing map of the target geographic area (e.g., OpenStreetMap) as a starting point for determining the number of Device B22s, and update the existing map with measurement data acquired from Device B22 and / or other devices dedicated to the mapping task. Machine learning models can be used to predict both small environmental changes (e.g., a collapsed compound wall) and large environmental changes (e.g., a collapsed multi-story building) based on sensor data, and to determine anchor points (Device B22 and / or other devices dedicated to the mapping task) based on new landmarks acquired from the SLAM service.

[0156] Alternatively, when there are no major landmarks in the MCI area (e.g., a plane crash into a meadow without buildings), wireless link quality measurements can be used as an indicator of the distance between device B22 and device A20, or as distance-dependent measurements. In one example, the sensor on device B22 can be used for a rough distance estimation between device A20 and device B22, and wireless link quality is mapped as distance between device A20 and device B22.

[0157] Finally, in step S540, device A20 registers device UE24, which was discovered and invited or triggered / requested by device B22, to connect to the first responder network 200, for example, if the discovered device UE24 is a predetermined / pre-registered first responder wireless communication device. To achieve this, device A20 uses the device identity information received from the discovered device UE24 to determine the user identity associated with the received device identity information of the discovered device UE24 and checks whether the user is a registered first responder or whether the discovered device UE24 is a registered first responder device. Alternatively, as described above, wireless communication devices carried by personnel from different regions (e.g., firefighters from a neighboring region) may be considered inbound roaming devices, or the first responder's devices may be capable of supporting sidelink communication and thus able to set up a temporary / mesh-type network, or the wireless communication devices may each be capable of running group applications and thus all be able to be added to the first responder network 200 at once, or one of the devices in a group may be able to act as an authenticator for other devices from the same group that are trying to register, or additional verification checks may be added based on the capabilities of the wireless communication devices.

[0158] Furthermore, device B22 is used to detect signals from the injured or victim's device UE24 (e.g., a mobile phone) (e.g., under rubble).

[0159] Figure 6 schematically shows flowcharts of the first responder network location confirmation and mapping procedure in various embodiments (for example, in device B).

[0160] In step S610, based on the initial determination of device A, device B is deployed to the target field of the MCI area. Then, in step S620, the deployed device B performs measurements to derive measurement parameters within the target field of the MCI area (e.g., total area in square meters, structural anchor points, number of victims, etc.).

[0161] Next, in step S630, the acquired or updated measurement parameters are transmitted to device A. Furthermore, the deployed device B invites or triggers / requests device UE in the target field to register with the core network operated by device A.

[0162] In the optional step S640, deployed device B, which is communication-coupled to device A, is controlled by the device to function as a relay base station (for example, as described in 3GPP® TS36.216 “Evolved Universal Terrestrial Radio Access (E-UTRA); Physical layer for relaying operation” or 3GPP® TS38.174 “Integrated Access and Backhaul (IAB) radio transmission and reception”), and the relay base station can relay messages received from device UE (for example, by extracting data from the received signal, applying noise correction techniques, and retransmitting a new, “clean” signal within its own coverage zone) so that the device’s signal coverage can be extended across the entire field of the MCI area without overloading the resources of device A.

[0163] Device B is configured to automatically switch its relay function on or off by constantly monitoring the load capacity of the first responder network 200, for example, and to work in cooperation with Device A to optimize the network topology.

[0164] Alternatively, an authorized network controller (either an automated software function or a human) can interact with device A (for example, as specified in 3GPP® TS29.522: "Network Exposure Function Northbound APIs") to manually discard the network topology and alternately switch the relay function of device B.

[0165] Next, in an optional subsequent step (not shown in Figure 6), the first responder network (operated by, for example, device A) performs device identification, user identification, positioning, device counting, provision of emergency communication services, or other actions for / alternatively for device UEs registered with the first responder network (through device B).

[0166] In one example, to identify a specific first responder as the user UE of a device, user A, who is likely to be a pre-registered first responder, arrives at the MCI area with the device UE, and the device UE has device identification information (devID) and an IMSI linked to a specific user in a centralized server (for example, as specified in the route discovery service specified in the GSMA-SGP.22 RSP technical specification). This centralized server is communicated to a first responder database (see FRDB28 in Figure 2), and as a result, when device A identifies the device identification information and IMSI of the device UE, the IMSI can be used to verify the first responder in the first responder database by biometric identification information, including but not limited to, the user's face, fingerprints, and / or iris data captured in the device UE.

[0167] Alternatively, a Personal Identification Number (PIN) code can be used to identify the user in the First Responder database. In yet another alternative, after verification of the First Responder's device UE registration, a user interface (UI) prompt is triggered on the device UE by the First Responder database, allowing the user to identify themselves through their own selection of verification method. If the user and device UE are successfully identified, device A can automatically register (install) the device UE in the First Responder network.

[0168] Another alternative for identifying the user on the device may be to use a government-issued radio frequency ID card (e.g., an NFC-based first-person ID) on the device.

[0169] Alternatively, device A restricts the device UE to ignore other mobile network operators within the MCI area and is strictly connectable only to services provided by the device for a period predetermined for a specific MCI event or set by the SLAM service on the device when surveying the MCI area.

[0170] In yet another example, after the initiation of the First Responder Network on Device A, First Responder A can register (install) another unregistered Device UE of First Responder B, which is registered in the First Responder database, by first registering itself with the First Responder Network via Device A and authorizing First Responder B's Device UE to register for the network services provided by Device A. Subsequently, the Device Identification Information (devID) of First Responder A's Device UE is captured in the First Responder database along with First Responder B's registration details so that a record of legitimate authorization is available to a given MCI event.

[0171] If, after arriving at the MCI field, First Responder B is injured in an MCI event, First Responder B changes their designation on-site, First Responder B's device UE is handed over to another First Responder, or First Responder B must leave the MCI area for unprecedented reasons, First Responder B's device UE is deregistered from the First Responder database as a First Responder, either directly by First Responder B's device UE or via another First Responder's device UE present in the MCI area. The device identification information (devID) of the First Responder's device UE that deregisters First Responder B from the First Responder database is then further captured in the First Responder database along with the details of the deregistration.

[0172] In yet another example, device B is shared by different emergency services (e.g., medical, fire, and police drones) that will be used in an MCI event as a heterogeneous access device in the first responder network. Device A can identify and authorize heterogeneous device B to securely retrieve from heterogeneous device B its capabilities (e.g., battery, radio resources, antenna) or services in an exclusive emergency services network that has information about heterogeneous device B's capabilities. This information is available to the device while planning the deployment of access devices within the MCI area.

[0173] In another example of identifying a patient / victim as a device user UE, the patient's registered device UE, which is likely a powered-on wearable device or mobile phone, has an intact radio frequency (RF) module (e.g., a 3GPP® radio module) with an IMSI stored in a subscriber identification module (e.g., eSIM). The IMSI is identified by device B or device A (e.g., by using an IMSI scanner and initiating a scan for the IMSI near device B), or is derived from a temporary identifier (e.g., 5G GUTI) assigned to device UE24 by the home PLMN or by the first responder network (operated by device A) to request that the UDM or UDM of device UE24's home PLMN deconceal the SUCI received from device UE24 at registration. Upon identifying the presence of the patient's device UE nearby, device A or device B connects (possibly automatically) to a central identity server to communicate subscriber details (e.g., IMSI) and retrieve information about the person linked to the device UE. Device A is connected to a service provider (e.g., a mobile network operator), registers (installs) the injured person's device UE on the first responder network, and can, for example, use its location service and / or device B to automatically triangulate the injured person's location, or request the location of device UE24 from the location service of device UE24's home network.

[0174] Alternatively, the identity service running on device A, in coordination with a similar identity service at the patient's device UE's network provider (e.g., home PLMN) (for example, by the first responder network setting up a connection to the device UE's home PLMN's UDM via NEF and requesting the home PLMN to provide user identity information related to the device identity (e.g., SUCI) provided by the device UE during registration), retrieves relevant patient or user information details, including but not limited to the subscriber name of the subscription related to the IMSI / SUPI, emergency contact details, or the electronic medical record identity (EMR ID) of the user who owned / operated the device UE (i.e., victim / patient). This identity service has secure access to the IMSI details (e.g., as specified in the GlobalPlatform card specification v2.2) from the subscriber identification module stored in the patient's device UE. The device on the first responder network then securely transports the subscriber details to the patient's device UE's network provider over an integrity-protected communication channel.

[0175] In yet another example, when device B or device A identifies device UE nearby, it can simultaneously register device UE with the first responder network, or possibly before registration (installation), detect the presence of vital sign sensors on device UE by a pre-specified device class identifier for devices classified as vital sign devices (e.g., smartwatches with integrated vital sign sensors such as heart rate sensors or similar) (e.g., by capturing the device class of device UE). If device B is the UE itself (e.g., from the first responder), this can be done through discovery, or during or after setting up a sidelink connection, through a sidelink interface (e.g., PC5 of ProSe) that provides a list of device B's capabilities, device class, or unique ProSe services. Device B can also set up a sidelink (e.g., PC5) connection to device UE to communicate directly with the victim's device, for example, to retrieve vital sign information.

[0176] Upon detecting the presence of a device UE equipped with a vital sign sensor, device B, in cooperation with device A, enables a virtual subnet under the first responder network, allowing the isolated patient's device UE to register (embed) in the virtual private subnet by being provided with a network certificate from the first responder network. Upon successful registration, the first responder network's network services can access the device UE to enable network-specific services on the device UE, including but not limited to location verification and device power management, as well as application-specific services, including but not limited to retrieving data from the vital sign sensor and installing network-optimized applications for first responder operations.

[0177] Alternatively, device A can communicate with the patient's device UE's network service provider (e.g., home PLMN) to enable the device UE to roam the first responder network and perform network and application-specific services. The device UE's PLMN provides an interface or application programming interface (API) via the NEF, enabling the first responder network to send such requests for a specific device UE and under specific authority and / or privileges.

[0178] In yet another example, an intact vital signs-enabled device (UE) of an injured or ill person can be used to track the person's health status after it has been connected to a first responder network.

[0179] When the presence of a vital signs-integrated device UE (e.g., a smartwatch) is detected, the prioritization service on device B is used to give the device UE a higher priority than non-integrated device UEs (e.g., smartphones) that can be registered in the first responder network. As a result, once the device UE is registered, device B can securely retrieve the latest vital signs from the patient's device UE in an optimized balance within the first responder network.

[0180] In yet another example, devices A and B operate multiple network slices, each with its own unique performance characteristics.

[0181] In summary, a wireless communication system for first responder networks has been described that can securely enroll (embed) various wireless devices to ensure faster response times in MCI fields. Existing wireless devices belonging to both triage officers and victims in MCI fields can be automatically enrolled in the first responder network for automated tracking, identification, and location of first responders and injured persons, emergency communication between first responders and injured persons, and enhanced coverage in MCI fields. The expansion of the first responder network's wireless infrastructure can be enabled by securely enrolling heterogeneous central nodes (e.g., base stations) on demand.

[0182] Although the present invention has been illustrated and described in detail in the drawings and the foregoing description, such illustrations and descriptions should be considered illustrative or exemplary and not limiting. The present invention is not limited to the embodiments disclosed. It is applicable to various types of device UE, such as mobile phones, vital sign monitoring / remote measurement devices, smartwatches, detectors, or other types of portable devices. The term geographical area as used throughout this description is used synonymously with any spatial area or volume determined by a set of coordinates (absolute or relative to a reference point / device) or a set of minimum / maximum distances to a reference point / device. Geographical areas are outdoor and indoor.

[0183] Wireless communication devices (device UEs) can be various types of devices, such as mobile phones, vehicles (for vehicle-to-vehicle (V2V) communication or more commonly, vehicle-to-infrastructure (V2X) communication), V2X devices, IoT hubs, IoT devices including low-power medical sensors for health monitoring, medical (emergency) diagnostic and treatment devices for hospitals or first responders, and virtual reality (VR) headsets.

[0184] Device A is any network access device that provides a geographical service area (such as a base station, node B (eNB, eNodeB, gNB, gNodeB, ng-eNB, etc.), access point, or similar, or, for example, a PC / portable / server device that provides network control or core network functions).

[0185] Furthermore, at least some of the embodiments described above are based on 5G New Radio (5G NR) radio access technology. Specifically, the relay function enables multi-hop indirect network connectivity for remote communication devices, specifically achieving improved coverage for communication devices within the first responder network and improved low-power operation for IoT communication devices.

[0186] Furthermore, the present invention is applicable to medical applications or connected healthcare in which multiple wireless (e.g., 4G / 5G) connected sensor or actuator nodes participate, where wireless (e.g., 4G / 5G) connected devices occasionally utilize or generate continuous data streaming at a specific average data rate, such as video, ultrasound, X-ray, computed tomography (CT) imaging devices, real-time patient sensors, and audio or voice or video streaming devices used by medical personnel; in general IoT applications including wireless, mobile, or fixed; in sensor or actuator nodes (e.g., smart cities, logistics, agriculture, etc.); in emergency services and critical communication applications; in V2X systems; in systems for improved coverage for 5G cellular networks using high frequency (e.g., mmWave) RF; and in any other application area of ​​5G communications in which relay is used.

[0187] Other variations of the embodiments disclosed are understandable and implementable by those skilled in the art in practicing the claimed invention, based on a review of the drawings, this disclosure, and the appended claims. In the claims, the word “equipped with” does not exclude other elements or steps, and singular elements do not exclude plural elements. A single processor or other unit enables the functionality of several of the items enumerated in the claims. The mere fact that certain measures are enumerated in mutually different dependent claims does not indicate that combinations of these measures cannot be used advantageously. The foregoing description details certain embodiments of the invention. Nevertheless, it will be recognized that no matter how much the foregoing appears in detail in this text, the invention is practiced in many ways and is therefore not limited to the embodiments disclosed. It should be noted that the use of certain technical terms when describing certain features or aspects of the invention should not be taken to suggest that the technical terms have been redefined herein to include any inherent characteristics of the feature or aspect of the invention to which the term relates.

[0188] A single unit or device performs the functions of several items enumerated in the claims. The mere fact that certain measures are enumerated in different dependent claims does not indicate that combinations of these measures cannot be used advantageously.

[0189] The operations described, such as those shown in Figures 5 and 6, can be implemented as program code means of a computer program and / or as dedicated hardware for the relevant communication or access device, respectively. The computer program is stored and / or distributed on appropriate media such as optical storage media or solid-state media, supplied together with or as part of other hardware, but may also be distributed in other forms, such as via the Internet or other wired or wireless telecommunications systems.

Claims

1. A device for supporting the establishment of a wireless communication network, wherein the device is To connect to the network controller device of the aforementioned wireless communication network and to establish wireless connections to wireless communication devices within the target geographic area, Receiving information about the aforementioned target geographical area, Receiving information from the network controller device regarding the network configuration for setting up a communication channel with the wireless communication device, The wireless communication device located within the target geographic area is invited or triggered to register with the core network operated by the network controller device via the communication channel or other communication channels. The device comprises a relay node function that can be activated by the network controller device.

2. The apparatus according to claim 1, wherein the apparatus restricts triggers or registration invitations to at least one of a predetermined group and / or type of wireless communication devices of the wireless communication network, network services, and network slices.

3. A device for supporting the establishment of a wireless communication network, wherein the device comprises: To connect to the network controller device of the aforementioned wireless communication network and to establish wireless connections to wireless communication devices within the target geographic area, Receiving information about the aforementioned target geographical area, Receiving information from the network controller device regarding the network configuration for setting up a communication channel with the wireless communication device, The wireless communication device located within the target geographic area is invited or triggered to register with the core network operated by the network controller device via the communication channel or other communication channels. The device receives information about the target geographic region, wherein the target geographic region is smaller than the coverage area of ​​the access device.

4. A device for supporting the establishment of a wireless communication network, wherein the device comprises: To connect to the network controller device of the aforementioned wireless communication network and to establish wireless connections to wireless communication devices within the target geographic area, Receiving information about the aforementioned target geographical area, Receiving information from the network controller device regarding the network configuration for setting up a communication channel with the wireless communication device, The wireless communication device located within the target geographic area is invited or triggered to register with the core network operated by the network controller device via the communication channel or other communication channels. A device that performs measurements within the target geographic area and transmits corresponding measurement parameters to the network controller device for predicting the total number of access devices, relay devices, or wireless communication devices required in a Mass Injury (MCI) or emergency area.

5. The apparatus according to claim 1, wherein the invitation signal or message transmitted to the wireless communication device includes information about an emergency.

6. A device for supporting the establishment of a wireless communication network, wherein the device comprises: To connect to the network controller device of the aforementioned wireless communication network and to establish wireless connections to wireless communication devices within the target geographic area, Receiving information about the aforementioned target geographical area, Receiving information from the network controller device regarding the network configuration for setting up a communication channel with the wireless communication device, The wireless communication device located within the target geographic area is invited or triggered to register with the core network operated by the network controller device via the communication channel or other communication channels. A device that retrieves identity information of the wireless communication device and identifies the user of the wireless communication device by matching the identity information of the wireless communication device with user information stored on a cellular device platform.

7. One or more wireless communication devices, A wireless communication system comprising: an access device connected to a network controller device for making wireless connections to wireless communication devices in a wireless communication network, The access device includes equipment for supporting the establishment of the wireless communication network. The device connects to the network controller device and establishes a wireless connection to the wireless communication device within the target geographic area. Receiving information about the aforementioned target geographical area, Receiving information from the network controller device regarding the network configuration for setting up a communication channel with the wireless communication device, The wireless communication device located within the target geographic area is invited or triggered to register with the core network operated by the network controller device via the communication channel or other communication channels. A wireless communication system that performs device authentication through a connection between the network controller device and an external device not registered in the wireless communication network.

8. The wireless communication system according to claim 7, wherein the network controller device connects to the external device via a limited-range local connection to connect to the core network of the wireless communication network, so that the external device can function as an authenticator and / or subscriber owner registry for inbound roaming devices.

9. The wireless communication system according to claim 7, wherein the network controller device enables the external device to verify that an incoming roaming device belongs to the same network, facility, or group.

10. One or more wireless communication devices, A wireless communication system comprising: an access device connected to a network controller device for making wireless connections to wireless communication devices in a wireless communication network, The access device includes equipment for supporting the establishment of the wireless communication network. The device connects to the network controller device and establishes a wireless connection to the wireless communication device within the target geographic area. Receiving information about the aforementioned target geographical area, Receiving information from the network controller device regarding the network configuration for setting up a communication channel with the wireless communication device, The wireless communication device located within the target geographic area is invited or triggered to register with the core network operated by the network controller device via the communication channel or other communication channels. The network controller device is a wireless communication system that provides authentication and / or identification information to the external device so that the core network function of the external device can provide a local network registration function.

11. The wireless communication system according to claim 7, wherein the external device is a drone or a mobile server device.

12. One or more wireless communication devices, A wireless communication system comprising: an access device connected to a network controller device for making wireless connections to wireless communication devices in a wireless communication network, The access device includes equipment for supporting the establishment of the wireless communication network. The device connects to the network controller device and establishes a wireless connection to the wireless communication device within the target geographic area. Receiving information about the aforementioned target geographical area, Receiving information from the network controller device regarding the network configuration for setting up a communication channel with the wireless communication device, The wireless communication device located within the target geographic area is invited or triggered to register with the core network operated by the network controller device via the communication channel or other communication channels. A wireless communication system that, for user identification purposes, exchanges information between the wireless communication network and another wireless communication network to obtain location information, requests the wireless communication device to connect to the wireless communication network, or requests an access device of the other wireless communication network to temporarily join the wireless communication network.

13. One or more wireless communication devices, A wireless communication system comprising: an access device connected to a network controller device for making wireless connections to wireless communication devices in a wireless communication network, The access device includes equipment for supporting the establishment of the wireless communication network. The device connects to the network controller device and establishes a wireless connection to the wireless communication device within the target geographic area. Receiving information about the aforementioned target geographical area, Receiving information from the network controller device regarding the network configuration for setting up a communication channel with the wireless communication device, The wireless communication device located within the target geographic area is invited or triggered to register with the core network operated by the network controller device via the communication channel or other communication channels. A wireless communication system for identifying and tracking legitimate network authorizations and transactions in the wireless communication network and / or subscriber database.

14. A method for supporting the establishment of a wireless communication network, wherein the method is The device connects to the network controller device of the wireless communication network and establishes a wireless connection to wireless communication devices within the target geographic area. The device receives information about the target geographic region, The device receives information from the network controller device regarding a network configuration for setting up a communication channel with the wireless communication device. The device includes the step of inviting or triggering the wireless communication device located within the target geographic area to register with the core network operated by the network controller device, A method wherein the apparatus includes a relay node function that can be activated by the network controller device.

15. A computer program, when executed on a computer device, comprising coding means for causing the computer device to perform the steps of the method described in claim 14.