Methods and network node for handling a connection establishment procedure

By categorizing RRC Connection Request messages based on UE registration status and managing load thresholds for each category, the network node effectively mitigates congestion and DoS attacks, ensuring legitimate UEs can access the network.

WO2025122038A1PCT designated stage expired Publication Date: 2025-06-12TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/SE2023/051225
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-06
Publication Date
2025-06-12

AI Technical Summary

Technical Problem

Wireless communication networks face congestion and Denial of Service (DoS) attacks due to a high number of RRC Connection Request messages from UEs that do not have a previous connection with the network.

Method used

A method and network node configuration that categorize connection request messages based on the registration status of the UE's ID in the network. Messages from registered UEs are handled separately from those from unregistered UEs, allowing or rejecting connections based on load thresholds for each category.

Benefits of technology

This approach alleviates cell congestion and prevents DoS attacks by selectively blocking connection requests from unregistered UEs while allowing those from registered UEs, thereby maintaining network access for legitimate devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SE2023051225_12062025_PF_FP_ABST
    Figure SE2023051225_12062025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed is a method performed by a network node (130) of a wireless communication network (100) for handling a connection establishment procedure. The method comprises determining whether a wireless device ID received in a connection request message from the wireless device (140) is registered as a wireless device ID in the network, thus belonging to a first category, or whether the wireless device ID is not registered in the network, thus belonging to a second category. When the connection request message is determined to belong to the first category and based on a load of connection request messages of the first category, either reject the connection request message or setup a connection with the wireless device. When the connection request message is determined to belong to the second category and based on a load of connection request messages of the second category, either reject the connection request message or setup a connection with the wireless device.
Need to check novelty before this filing date? Find Prior Art

Description

METHODS AND NETWORK NODE FOR HANDLING A CONNECTION ESTABLISHMENT PROCEDURETECHNICAL FIELD

[0001] The present disclosure relates generally to methods and network nodes of a wireless communication network for handling a connection establishment procedure, for example a Radio Resource Control (RRC) connection establishment procedure. The present disclosure further relates to computer programs and carriers corresponding to the above methods and nodes.BACKGROUND

[0002] In order to handle connections of wireless devices to wireless communication networks, communication protocols are standardized, by e.g., 3GPP, and used by the wireless devices and nodes of the wireless communication networks for communication. A connection establishment procedure is a procedure for establishing a connection for a wireless device with the wireless communication network so that the wireless device can communicate with the wireless communication network. RRC Connection Establishment is a procedure defined in 3GPP TS 36.331 standard, Radio Resource Control (RRC) Protocol specification for 4thGeneration wireless networks (4G), see e.g., 3GPP TS 36.331 , V17.6.0, chapter 5.3.3, dated September 2023 [ref 1],

[0003] Fig. 1 , which is taken from [ref. 1] chapter 5.3.3.1 , shows messages of an RRC Connection Establishment procedure communicated when connection establishment is successful. When the wireless device, which in 4G is called User Equipment (UE) 40, wants to establish a connection with the wireless communication network, which in 4G is called Evolved Universal Mobile Telecommunications System (UMTS) Terrestrial Radio Access Network (EUTRAN) 30, the UE 40 sends 1 .1 an RRC Connection Request to a network node of the EUTRAN 30. The RRC Connection Request comprises UE identity (ID) and establishment cause. When the EUTRAN 30 finds that it can provide a connection to the UE 40, the EUTRAN 30 responds by sending 1 .2 an RRC Connection Setup including communication resources for the connection to the UE40. As a response to the received RRC Connection Setup, the UE 40 prepares itself for the RRC Connection and responds by sending 1 .3 an RRC Connection Setup Complete to the ELITRAN 30.

[0004] Fig. 2, which also is taken from [ref. 1] chapter 5.3.3.1 , shows messages of an RRC Connection Establishment procedure communicated when connection establishment is rejected. In such a case, the ELITRAN 30 responds to the received RRC Connection Request 1.1 by sending 1.4 an RRC Connection Reject to the UE 40.

[0005] The purpose of the RRC Connection Establishment procedure in 4G is to establish an RRC Connection, to resume a suspended RRC Connection, to move the UE from an inactive state called RRCJNACTIVE to an active state called RRC_CONNECTED or to perform Early Data Transmission (EDT).

[0006] The UE 140 initiates the RRC Connection Establishment procedure when upper communication layers request establishment or resume of an RRC connection while the UE is in RRCJDLE state or when upper layers request resume of an RRC connection or RRC layer requests resume of an RRC connection for, e.g., a RAN-based Notification Area Update (RNAU) or reception of RAN paging while the UE is in RRCJNACTIVE state.

[0007] A similar RRC connection establishment procedure is defined for 5thGeneration (5G), also called New Radio (NR), in 3GPP TS 38.331 , V17.6.0, chapter 5.3.3, dated September 2023 [Ref. 2], The names of messages in 5G are slightly different to the names in 4G. E.g., first message in the RRC Connection establishment procedure, which was called RRC Connection Request in 4G is called RRC Setup Request in 5G, but the concept / mechanisms are more or less the same in 4G and 5G.

[0008] Upon initiating the RRC Connection Establishment procedure, the UE is instructed to start a timer called T300, and the UE is instructed not to start a new RRC Connection Establishment procedure until the T300 timer expires. Hereby itis avoided that the same UE repeatedly sends an RRC Connection Request thereby overloading the network node.

[0009] Despite this measure, it may happen that a high number of RRC Connection requests are sent from UEs in one and the same cell, which may result in that the load of the network node handling the cell increases, which may cause congestion for handling such requests. In order to avoid such overload problems, 4G and probably also 5G have implemented another load protection mechanism that uses an algorithm that protects the cell from having to handle too many RRC Connection Request messages in too short time. It limits the number of RRC Connection Requests that are allowed to be processed within a certain time. If more RRC Connection Requests are received in one time window than a number predefined by this algorithm, the RRC Connection Requests above that number are rejected without being processed. Hereby, cell congestion is avoided.

[0010] Recently, wireless communication networks in some markets have experienced UEs that repeatedly send RRC Connection Request messages 1.1 and do not respond to any RRC Connection Setup messages 1 .2 received from the network in return. This problem refers to UEs that do not have any previous connection with the network, i.e. , UEs that are, or appears to be, a part of a Random-Access procedure. This causes problems for "normal" UEs, depleting their access resources.

[0011] Malicious use of this problem, i.e., initiating transmission of a high number of RRC Connection Setup messages to a network node, can lead to a successful Denial of Service (DoS) attack on the network node, which results in cell congestion. Hereby, no UE can access the cell, neither UEs that do not have any previous connection with the network, nor UEs that have had a connection but now are in e.g., Inactive state or idle state. This problem was described in “Touching the Untouchables: Dynamic Security Analysis of the LTE Control Plane”, by K. Hongil et al, Proceedings of the 40th IEEE Symposium on Security and Privacy, San Francisco, USA, 2019, Volume 1 , pages 1153-1168.

[0012] Consequently, there is a need for an improved connection establishment procedure that alleviates the effects of this problem.SUMMARY

[0013] It is an object of embodiments of the invention to address at least some of the problems and issues outlined above. It is an object of embodiments of the invention to provide an improved connection establishment procedure. It is another object of embodiments to provide an RRC connection establishment procedure that alleviates the problem of cell congestion due to DoS attacks by RRC Connection Requests from UEs, or alleged UEs, that do not have any previous connection with the communication network. It is possible to achieve at least of one of these objects by using methods and network nodes as defined in the attached independent claims.

[0014] According to one aspect, a method is provided that is performed by a network node of a wireless communication network for handling a connection establishment procedure. The method comprises receiving, from a wireless device, a connection request message comprising an ID of the wireless device. The method further comprises determining whether the ID of the wireless device is registered as a wireless device ID in the network, the connection request message thus belonging to a first category, or whether the ID of the wireless device is not registered as a wireless device ID in the network, the connection request message thus belonging to a second category. The method further comprises, when the connection request message is determined to belong to the first category and based on a load of connection request messages of the first category, either rejecting the connection request message or initiating setup of a connection with the wireless device, and, when the connection request message is determined to belong to the second category and based on a load of connection request messages of the second category, either rejecting the connection request message or initiating setup of a connection with the wireless device

[0015] According to another aspect, a network node is provided that is configured to operate in a wireless communication network and configured forhandling a connection establishment procedure. The network node comprises a processing circuitry and a memory. Said memory contains instructions executable by said processing circuitry, whereby the network node is operative for receiving, from a wireless device, a connection request message comprising an ID of the wireless device, and determining whether the ID of the wireless device is registered as a wireless device ID in the network, the connection request message thus belonging to a first category, or whether the ID of the wireless device is not registered as a wireless device ID in the network, the connection request message thus belonging to a second category. The network node is further operative for, when the connection request message is determined to belong to the first category and based on a load of connection request messages of the first category, either rejecting the connection request message or initiating setup of a connection with the wireless device, and when the connection request message is determined to belong to the second category and based on a load of connection request messages of the second category, either rejecting the connection request message or initiating setup of a connection with the wireless device.

[0016] According to other aspects, computer programs and carriers are also provided, the details of which will be described in the claims and the detailed description.

[0017] Further possible features and benefits of this solution will become apparent from the detailed description below.BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The solution will now be described in more detail by means of exemplary embodiments and with reference to the accompanying drawings, in which:

[0019] Fig. 1 is a signaling diagram illustrating an RRC Connection establishment procedure according to prior art, where the connection establishment is successful.

[0020] Fig. 2 is a signaling diagram illustrating an RRC Connection establishment procedure according to prior art, where the connection establishment is rejected.

[0021] Fig. 3 is a schematic diagram of a wireless communication network in which the present invention may be used.

[0022] Fig. 4 is a flow chart illustrating a method performed by a network node, according to possible embodiments.

[0023] Fig. 5 is a flow chart illustrating a method performed by a network node, according to other possible embodiments.

[0024] Fig. 6 is a flow chart illustrating a method performed by a network node, according to other possible embodiments.

[0025] Fig. 7 is a schematic diagram illustrating sorting and handling of incoming RRC Connection requests depending on their individual category.

[0026] Fig. 8 is a flow chart illustrating a method performed by a network node, according to possible embodiments.

[0027] Fig. 9 is a flow chart illustrating a method of dynamically configuring size of buckets, according to embodiments.

[0028] Fig. 10 is a block diagram illustrating a network node in more detail, according to further possible embodiments.DETAILED DESCRIPTION

[0029] Fig. 3 shows a wireless communication network 100 comprising a radio access network (RAN) node aka network node 130 that is in, or is adapted for, wireless communication with a wireless communication device aka wireless device 140. The network node 130 provides radio access in a cell 150 covering a geographical area. The network node 130 is in its turn connected to other nodes in the wireless communication network 100, such as nodes of a RAN and a core network 160.

[0030] The wireless communication network 100 may be any kind of wireless communication network that can provide radio access to wireless devices.Example of such wireless communication networks are networks based on Global System for Mobile communication (GSM), Enhanced Data Rates for GSM Evolution (EDGE), Universal Mobile Telecommunications System (UMTS), Code Division Multiple Access 2000 (CDMA 2000), Long Term Evolution (LTE), LTE Advanced, Wireless Local Area Networks (WLAN), Worldwide Interoperability for Microwave Access (WiMAX), WiMAX Advanced, as well as fifth generation (5G) wireless communication networks based on technology such as New Radio (NR), and any possible future sixth generation (6G) wireless communication network.

[0031] The network node 130 may be any kind of network node that can provide wireless access to a wireless device 140 alone or in combination with another network node. Examples of network nodes 130 are a base station (BS), a radio BS, a base transceiver station, a BS controller, a network controller, a Node B (NB), an evolved Node B (eNB), a gNodeB (gNB), a Multi-cell / multicast Coordination Entity, a relay node, an access point (AP), a radio AP, a remote radio unit (RRU), a remote radio head (RRH) and a multi-standard BS (MSR BS).

[0032] The wireless device 140 may be any type of device capable of wirelessly communicating with a network node 130 using radio signals. For example, the wireless device 140 may be a User Equipment (UE), a machine type UE or a UE capable of machine to machine (M2M) communication, a sensor, a tablet, a mobile terminal, a smart phone, a laptop embedded equipped (LEE), a laptop mounted equipment (LME), a USB dongle, a Customer Premises Equipment (CPE), an Internet of Things (loT) device, etc.

[0033] Embodiments of the invention is built upon the idea of determining whether wireless devices sending a connection request message have a previous connection with the network or not based on the device identities (ID) appended to the connection request messages, and then treat the wireless devices that were determined to have a previous connection separately from the wireless devices not having a previous connection. Wireless devices whichdevice IDs in the connection request messages are not registered in the network are wireless devices that do not have any previous connection with the network, e.g., devices or alleged devices that try to access the network via a Random- Access procedure. Wireless devices which device IDs are registered in the network are wireless devices that already have or recently have had a connection to the wireless communication network, e.g., wireless devices that are in Idle mode or Inactive mode or are registered in a Tracking Area (TA) of the current cell. Hereby, in case there is a DoS attack from (alleged) wireless devices, which device IDs are not registered in the network, connection request messages from wireless devices which device IDs are not registered are blocked, but it can still be possible to allow connection request messages from wireless devices, which device IDs are already registered in the network. Thus, an improved connection establishment procedure is achieved. Especially, a connection establishment procedure is achieved that alleviates the problem of cell congestion due to DoS attacks by RRC Connection Requests from alleged UEs, which do not have any previous connection with the communication network.

[0034] In the known procedure referred to in figs. 1 and 2 from [Ref. 1], the UE shall include the UE ID in the RRC Connection Request message 1.1. The same is applicable in 5G, see [Ref. 2] section 6.2.2. The UE ID is to be included as follows: If upper layers provide a Serving Temporary Mobile Subscriber Identity (S- TMSI), the UE ID in the RRC Connection Request message is to be set to the value of the S-TMSI. If upper layers do not provide any S-TMSI, the UE shall draw a random value in the range of 0 to 240-1 in 4G and 239-1 in 5G and set the UE ID in the RRC Connection Request message to this value. Note that the upper layers provide an S-TMSI if the UE is registered in the Tracking Area (TA) of the current cell when the UE is to send the RRC Connection Request. According to an embodiment of the invention, those different types of UE IDs are used to categorize the UEs in any of two categories, one category for UEs which RRC Connection Request message includes S-TMSI and another category for UEs which RRC Connection Request message includes a random number. Whether to allow or reject the connection request is then determined separately for the two categories. UEs that have an S-TMSI included in the RRC Connection Request1.1 are UEs which device IDs are registered in the network. UEs that have a random number included as device ID in the RRC Connection Request 1.1 are UEs which device IDs are not registered in the network.

[0035] Fig. 4, in conjunction with fig. 3, describes a method performed by a network node 130 of a wireless communication network 100 for handling a connection establishment procedure. The method comprises receiving 202, from a wireless device 140, a connection request message comprising an ID of the wireless device. The method further comprises determining 204 whether the ID of the wireless device 140 is registered as a wireless device ID in the network, the connection request message thus belonging to a first category, or whether the ID of the wireless device 140 is not registered as a wireless device ID in the network, the connection request message thus belonging to a second category 100. The method further comprises, when the connection request message is determined 204 to belong to the first category and based on a load of connection request messages of the first category, either rejecting 206 the connection request message or initiating 208 setup of a connection with the wireless device, and, when the connection request message is determined 204 to belong to the second category and based on a load of connection request messages of the second category, either rejecting 210 the connection request message or initiating 212 setup of a connection with the wireless device.

[0036] By such a method it is possible to handle connection request messages received from wireless devices already having a device ID registered in the network separately from connection request messages received from wireless devices not having a device ID registered in the network. Thus, if load of connection request messages in one of the categories is too high for initiating setup of a connection for any more wireless devices of that category, the connection request messages belonging to that category can be discarded, but if at the same time, load of connection request messages of the other category reveals that there is still space for a wireless device, a setup of a connection can be initiated for wireless devices which connection request messages belongs to that other category. Hereby, in case of a DoS attack by connection requests fromalleged UEs, accessing the network without having a previous connection to the network, e.g., accessing the network via Random Access, Connection Requests from such wireless devices that have an ID not registered in the network can be denied. However, at the same time Connection Requests from wireless devices having an ID already registered in the network can still be allowed, as long as the load of connection request messages for this category of devices is not too high.

[0037] An example of a wireless device ID registered in the network is an S- TMSI. Consequently, when a connection request message is received that comprises a wireless device ID registered in the network, e.g., an S-TMSI, the request message is determined to belong to a first category of connection request messages. An example of a wireless device ID not registered in the network is a random number. Consequently, when a connection request message is received that comprises a wireless device ID not registered in the network, for example, a random number, the request message is determined to belong to a second category of connection request messages.

[0038] The load of connection request messages of the first and second category, respectively, may be a number of connection request messages received over a defined time period, which may be a current ongoing time period, or a certain time period that has recently ended or that ends at the very moment. Alternatively, the load of connection request messages of the first and second category, respectively, may be a size of a processing queue of connection request messages of the respective category. The rejecting of the connection request message of the first / second category may be performed so that when the load of connection request messages of that category is above a threshold, all incoming connection request messages of that category are rejected as long as the load is above the threshold, or, alternatively, only a percentage of the connection request messages of that category are rejected as long as the load is above the threshold.

[0039] According to an embodiment, the connection establishment procedure is an RRC connection establishment procedure. Further, the connection requestmessage is an RRC Connection Request message as defined in 4G or an RRC Setup Request message as defined in 5G.

[0040] According to an embodiment, when the connection request message is determined 204 to belong to the first category, the either rejecting 206 of the connection request message or the initiating 208 setup of a connection with the wireless device is performed based on the load of connection request messages of the first category in relation to a first load threshold. In other words, the load of connection request messages of the first category is compared to a first load threshold, which is a threshold that sets the allowed load of connection request messages of the first category.

[0041] According to an alternative of the above embodiment, when the connection request message is determined 204 to belong to the first category, the connection request message is rejected 206 when the load of connection request messages of the first category is above or same as the first load threshold and the connection setup is initiated 208 for the wireless device when the load of connection request messages of the first category is below the first load threshold.

[0042] According to another alternative, when the connection request message is determined 204 to belong to the first category and when the load of connection request messages of the first category is below the first load threshold, increasing 207 the load of connection request messages of the first category with 1.

[0043] According to an embodiment, when the connection request message is determined 204 to belong to the second category, the either rejecting 210 of the connection request message or the initiating 212 of setup of a connection with the wireless device is performed based on the load of connection request messages of the second category in relation to a second load threshold. In other words, the load of connection request messages of the second category is compared to a second load threshold, which is a threshold that sets the allowed load of connection request messages of the second category.

[0044] According to an alternative of the above embodiment, when the connection request message is determined 204 to belong to the second category, the connection request message is rejected 210 when the load of connection request messages of the second category is above or same as the second load threshold and the connection setup is initiated 212 for the wireless device when the load of connection request messages of the second category is below the second load threshold.

[0045] According to another alternative, when the connection request message is determined 204 to belong to the second category and when the load of connection request messages of the second category is below the second load threshold, increasing 211 the load of connection request messages of the second category with 1 .

[0046] According to another embodiment, the first load threshold and the second load threshold are adjustable. Hereby, it is possible to change the first and second load thresholds, depending e.g., on capacity changes in the network or on previous loads. Adjustable thresholds make the method more flexible. According to an embodiment, a total load threshold may be set as the sum of the first load threshold and the second load threshold. The total load threshold may be a set, non-adjustable threshold. Then the first and second thresholds are adjustable in as much as if the first threshold is increased, the second threshold has to be decreased with the same value, in order not to exceed the total load threshold. According to another embodiment, the total load threshold is a set non-adjustable value, but it can be set to a higher value than the sum of the first and second load thresholds. Then the first threshold can be increased without decreasing the second load threshold, as long as the sum of the first and second load threshold does not exceed the total load threshold.

[0047] According to yet another embodiment, the first load threshold and the second load threshold are adjustable based on previous load of connection request messages of the first category and previous load of connection request messages of the second category, the respective previous loads being determinedbased on a previous time period that ended before the connection request message was received 202, preferably the time period immediately before the connection request message was received. By such a method, the first and second load threshold can be adapted to what the loads of the respective categories were in previous time periods, which makes the method quite flexible and adaptable to current load situations. The length of the time period may be set by a timer, e.g., a timer of an overload protection algorithm.

[0048] According to yet another embodiment, which is shown in fig. 5, the method further comprises, before the receiving 202 of the connection request message, determining 222 that the previous load of connection request messages of the first category is below the first load threshold and that the previous load of connection request messages of the second category is above the second load threshold, decreasing 224 the first load threshold and increasing 226 the second load threshold.

[0049] According to an alternative of the above embodiment, the decreasing 224 of the first load threshold and the increasing 226 of the second load threshold is only performed when the first load threshold after the decrease will be above a defined minimum and / or when the second load threshold after the increase will be below a defined maximum.

[0050] According to yet another embodiment, which is shown in fig. 6, the method further comprises, before the receiving 202 of the connection request message, determining 232 that the previous load of connection request messages of the first category is above the first load threshold and that the previous load of connection request messages of the second category is below the second load threshold, increasing 234 the first load threshold and decreasing 236 the second load threshold.

[0051] According to an alternative of the above embodiment, the increasing 234 of the first load threshold and the decreasing 236 of the second load threshold is only performed when the second load threshold after the decrease will be above adefined minimum and / or when the first load threshold after the increase will be below a defined maximum.

[0052] According to another embodiment, a sum of the first load threshold and the second load threshold equals a total number of allowed connection request messages within a defined time period.

[0053] As discussed, legacy algorithms for handling RRC connection request messages limit the total number of RRC connection request messages of a cell to be processed by the cell's network node within a certain time window / period. If more RRC connection request messages are received than a set threshold within the time window, RRC connection request messages above the threshold are rejected. According to an embodiment, in addition to this legacy algorithm, instead of handling all RRC connection request messages as one category, i.e. , in one universal “bucket”, two buckets / categories are used: A first bucket / category for RRC connection request messages received from UEs which have a S-TMSI as UE ID in the RRC connection request message, below called an “S-TMSI ID bucket”, and a second bucket / category for RRC connection request messages received from UEs which have a random number as UE ID in the RRC connection request message, below called a “Random ID bucket”.

[0054] Fig. 7 is an illustration of handling of incoming RRC Connection request messages, called “RRC” in the figure. Over time, RRCs 302 - 326 are received from above in the figure and are treated as they over time move down in the figure. There are two categories of RRCs, a first RRC category called RRC1 302, 304, 308, 318, 322, 324, 326, which are RRCs to which an S-TMSI UE ID is appended, and a second RRC category called RRC2 306, 310, 312, 3145, 316, 320, which are RRCs to which a random UE ID is appended. As the RRCs are received by the network node 130 they are treated by a determining unit 330, e.g., a processor, that based on the UE ID of the RRC determines whether the RRC belongs to the first or the second category. When it is determined that the RRC belongs to the first category, i.e., has an S-TMSI appended to it, the RRC1 is led to an S-TMSI ID bucket 334. If the S-TMSI bucket 334 is full, e.g., if theload of the S-TMSI ID bucket 334 is above a threshold, the incoming RRC1 is discarded, as is illustrated by RRC 1 318. If there is still space in the S-TMSI bucket 334, the incoming RRC1 is processed and a set-up of a connection with the UE having the S-TMSI of the RRC1 is initiated, as is illustrated by RRC1 322, 324 and 326. When it is determined that the RRC belongs to the second category, i.e. , has a random UE ID appended to it, the RRC2 is led to a Random ID bucket 332. If the Random ID bucket 332 is full, e.g., if the load of the Random ID bucket 332 is above a threshold, the incoming RRC2 is discarded, as is illustrated by RRC2 314 and 316. If there is still space in the Random ID bucket 332, the incoming RRC2 is processed and a set-up of a connection with the UE having the Random ID of the RRC2 is initiated, as is illustrated by RRC2 320.

[0055] According to an embodiment, the sum of size of the Random ID bucket 332 and size of the S-TMSI ID bucket 334 is the same as the size of an original legacy bucket, when there is only one bucket for all RRCs. For example, sum of a load threshold of the Random ID bucket 332 and load threshold of the S-TMSI ID bucket 334 is the same as load threshold of the legacy bucket. Respective size for each of the Random ID bucket 332 and the S-TMSI ID bucket 334 may be defined as relative size, i.e., as a percentage of total bucket size:S-TMSI ID bucket size + Random ID bucket size = 100 % maximum number of requests that can be handled

[0056] Fig. 8 shows a flow chart of an algorithm for treating incoming RRC Connection requests at a network node. An RRC Connection request comprising a UE ID is received 402. The UE ID may be an S-TMSI or a random value. Then it is determined 404 whether the UE ID of the RRC Connection request is an S-TMSI or not. If the UE ID is an S-TMSI, the algorithm proceeds to step 406 where it is determined whether the S-TMSI ID bucket is full. If the S-TMSI ID bucket is full, the RRC Connection request is rejected 410. If the S-TMSI ID bucket is not full, an RRC Connection setup is initiated 412 with the UE to which the S-TMSI of the RRC Connection request belonged. When it is determined at step 404 that the UE ID of the RRC Connection request is not a S-TMSI, in other words, it is a randomvalue, the algorithm proceeds to step 408 where it is determined whether the Random ID bucket is full. If the Random ID bucket is full, the RRC Connection request is rejected 414. If the Random ID bucket is not full, an RRC Connection setup is initiated 412 with the UE to which the Random value ID of the RRC Connection request belonged.

[0057] According to an embodiment, the sizes of the respective S-TMSI ID bucket 332 and the Random ID bucket 334 may be configured dynamically. In other words, the sizes of the respective bucket 332, 334 may be changed over time. According to one advantageous embodiment, the size of the respective bucket may be changed depending on number of incoming RRC connection requests in each of the two categories in one or more previous time windows, before the current time window. In other words, the size of the S-TMSI ID bucket 334 and the size of the Random ID bucket 332 may be changed based on statistics on how many RRC Connection requests in each of the two categories that were received in one or more previous time windows. For example, in case the number of received RRC connection requests of the first category in the previous time window made the S-TMSI bucket full but the number of received RRC Connection requests of the second category in the previous time window did not make the Random ID bucket full, the size of the S-TMSI ID bucket 334 may be increased and the size of the Random ID bucket 332 may be decreased.

[0058] According to an embodiment, one or more of the following parameters are to be configured for dynamic configuring of the buckets sizes: minimum and maximum possible size for the S-TMSI ID bucket, for example measured as % of overall bucket size, maximum number of RRC Connection requests that can be handled and adjustment step for each time period. According to an embodiment, the size of the S-TMSI ID bucket and the size of the Random ID bucket are adjusted after every time window, based on incoming number of RRC Connection requests in each category in previous time window.

[0059] Fig. 9 is a flow chart illustrating an embodiment of an algorithm for dynamically configuring the sizes of the S-TMSI ID bucket and the Random IDbucket. When a time window expires 502, it is checked 504 whether number of received RRC Connection Requests with S-TMSI (RRC1 ) in the time window was smaller than current size of the S-TMSI ID bucket. If yes at check 504, it is also checked 506 whether number of received RRC Connection Requests with Random UE ID (RRC2) in the time window was larger than current size of the Random ID bucket. If no at check 506, there is no further action in this time window. If yes at check 506, it is also checked 508 whether current size of the S- TMSI ID bucket, decreased by the predefined adjustment step, is still larger than predefined minimum possible size of the S-TMSI ID bucket. If no at check 508, there is no further action in this time window. If yes at check 508, the size of the S- TMSI ID bucket is decreased 510 with the predefined adjustment step, while the size of the Random ID bucket is calculated by subtracting 512 the S-TMSI bucket from the total bucket size. If no at check 504, it is also checked 514 whether the number of received RRC Connection Requests with Random UE ID (RRC2) in the time window was smaller than the current size of the Random ID bucket. If no at check 514, there is no further action in this time window. If yes at check 514, it is also checked 516 whether the current size of the S-TMSI ID bucket, increased by the predefined adjustment step, is smaller than or equal to a predefined maximum possible size of the S-TMSI ID bucket. If no at check 516, there is no further action in this time window. If yes at check 516, the size of the S-TMSI ID bucket is increased 518 with the predefined adjustment step, while the size of the Random ID bucket is calculated by subtracting 520 the S-TMSI bucket from the total bucket size. Reference 522 defines that a new time window can start.

[0060] Fig. 10, in conjunction with fig. 3, shows a network node 130 configured to operate in a wireless communication network 100, and configured for handling a connection establishment procedure. The network node 130 comprises a processing circuitry 603 and a memory 604. Said memory contains instructions executable by said processing circuitry, whereby the network node 600 is operative for receiving, from a wireless device 140, a connection request message comprising an ID of the wireless device, and determining whether the ID of the wireless device 140 is registered as a wireless device ID in the network, the connection request message thus belonging to a first category, or whether the IDof the wireless device 140 is not registered as a wireless device ID in the network, the connection request message thus belonging to a second category 100. The network node 130 is further operative for, when the connection request message is determined to belong to the first category and based on a load of connection request messages of the first category, either rejecting the connection request message or initiating setup of a connection with the wireless device, and when the connection request message is determined to belong to the second category and based on a load of connection request messages of the second category, either rejecting the connection request message or initiating setup of a connection with the wireless device.

[0061] According to an embodiment, when the connection request message is determined to belong to the first category, the network node is operative for performing the either rejecting of the connection request message or the initiating setup of a connection with the wireless device based on the load of connection request messages of the first category in relation to a first load threshold.

[0062] According to another embodiment, when the connection request message is determined to belong to the first category, the network node 130 is operative for rejecting the connection request message when the load of connection request messages of the first category is above or same as the first load threshold and operative for initiating the connection setup for the wireless device when the load of connection request messages of the first category is below the first load threshold.

[0063] According to another embodiment, when the connection request message is determined to belong to the first category and when the load of connection request messages of the first category is below the first load threshold, the network node 130 is operative for increasing the load of connection request messages of the first category with 1 .

[0064] According to yet another embodiment, when the connection request message is determined to belong to the second category, the network node 130 is operative for performing the either rejecting of the connection request message orinitiating setup of a connection with the wireless device based on the load of connection request messages of the second category in relation to a second load threshold.

[0065] According to yet another embodiment, when the connection request message is determined to belong to the second category, the network node 130 is operative for rejecting the connection request message when the load of connection request messages of the second category is above or same as the second load threshold and operative for initiating connection setup for the wireless device when the load of connection request messages of the second category is below the second load threshold.

[0066] According to yet another embodiment, when the connection request message is determined to belong to the second category and when the load of connection request messages of the second category is below the second load threshold, the network node 130 is operative for increasing the load of connection request messages of the second category with 1 .

[0067] According to yet another embodiment, the network node 130 is operative for adjusting the first load threshold and the second load threshold.

[0068] According to still another embodiment, the network node 130 is operative for adjusting the first load threshold and the second load threshold based on previous load of connection request messages of the first category and previous load of connection request messages of the second category, the respective previous loads being determined based on a previous time period that ended before the connection request message was received.

[0069] According to still another embodiment, the network node 130 is operative for, before the receiving of the connection request message, determining that the previous load of connection request messages of the first category is below the first load threshold and that the previous load of connection request messages of the second category is above the second load threshold, decreasing the first load threshold and increasing the second load threshold.

[0070] According to another embodiment, the network node 130 is operative for only performing the decreasing of the first load threshold and the increasing of the second load threshold when the first load threshold after the decrease will be above a defined minimum and / or when the second load threshold after the increase will be below a defined maximum.

[0071] According to another embodiment, the network node 130 is further operative for, before the receiving of the connection request message, determining that the previous load of connection request messages of the first category is above the first load threshold and that the previous load of connection request messages of the second category is below the second load threshold, increasing the first load threshold and decreasing the second load threshold.

[0072] According to yet another embodiment, the network node 130 is operative for only performing the increasing of the first load threshold and the decreasing of the second load threshold when the second load threshold after the decrease will be above a defined minimum and / or when the first load threshold after the increase will be below a defined maximum.

[0073] According to yet another embodiment, a sum of the first load threshold and the second load threshold equals a total number of allowed connection request messages within a defined time period.

[0074] According to other embodiments, the network node 130 may further comprise a communication unit 602, which may be considered to comprise conventional means for wireless communication with the wireless device 140, such as a transceiver for wireless transmission and reception of signals in the communication network. The communication unit 602 may also comprise conventional means for communication with other network nodes of the wireless communication network 100, such as the RAN nodes and CN nodes 160 shown in fig. 3. The instructions executable by said processing circuitry 603 may be arranged as a computer program 605 stored e.g., in said memory 604. The processing circuitry 603 and the memory 604 may be arranged in a subarrangement 601 . The sub-arrangement 601 may be a micro-processor andadequate software and storage therefore, a Programmable Logic Device, PLD, or other electronic component(s) / processing circuit(s) configured to perform the methods mentioned above. The processing circuitry 603 may comprise one or more programmable processor, application-specific integrated circuits, field programmable gate arrays or combinations of these adapted to execute instructions.

[0075] The computer program 605 may be arranged such that when its instructions are run in the processing circuitry 603, the instructions cause the network node 130 to perform the steps described in any of the described embodiments of the network node 130 and its method. The computer program 605 may be carried by a computer program product connectable to the processing circuitry 603. The computer program product may be the memory 604, or at least arranged in the memory. The computer program product may be called a computer-readable storage medium. The memory 604 may be realized as for example a Random-access memory (RAM), Read-Only Memory (ROM) or an Electrical Erasable Programmable ROM (EEPROM). In some embodiments, a carrier may contain the computer program 605. The carrier may be one of an electronic signal, an optical signal, an electromagnetic signal, a magnetic signal, an electric signal, a radio signal, a microwave signal, or computer readable storage medium. The computer-readable storage medium may be e.g., a CD, DVD or flash memory, from which the program could be downloaded into the memory 604. Alternatively, the computer program 605 may be stored on a server or any other entity to which the network node 130 has access via the communication unit 602. The computer program 605 may then be downloaded from the server into the memory 604.

[0076] Although the description above contains a plurality of specificities, these should not be construed as limiting the scope of the concept described herein but as merely providing illustrations of some exemplifying embodiments of the described concept. It will be appreciated that the scope of the presently described concept fully encompasses other embodiments which may become obvious to those skilled in the art, and that the scope of the presently described concept isaccordingly not to be limited. Reference to an element in the singular is not intended to mean "one and only one" unless explicitly so stated, but rather "one or more." All structural and functional equivalents to the elements of the abovedescribed embodiments that are known to those of ordinary skill in the art are expressly incorporated herein by reference and are intended to be encompassed hereby. Moreover, it is not necessary for an apparatus or method to address each and every problem sought to be solved by the presently described concept, for it to be encompassed hereby. In the exemplary figures, a broken line generally signifies that the feature within the broken line is optional.

Claims

CLAIMS1 . A method performed by a network node (130) of a wireless communication network (100) for handling a connection establishment procedure, the method comprising: receiving (202), from a wireless device (140), a connection request message comprising an ID of the wireless device, determining (204) whether the ID of the wireless device (140) is registered as a wireless device ID in the network, the connection request message thus belonging to a first category, or whether the ID of the wireless device (140) is not registered as a wireless device ID in the network, the connection request message thus belonging to a second category (100), and when the connection request message is determined (204) to belong to the first category and based on a load of connection request messages of the first category, either rejecting (206) the connection request message or initiating (208) setup of a connection with the wireless device, and when the connection request message is determined (204) to belong to the second category and based on a load of connection request messages of the second category, either rejecting (210) the connection request message or initiating (212) setup of a connection with the wireless device.

2. Method according to claim 1 , wherein when the connection request message is determined (204) to belong to the first category, the either rejecting (206) of the connection request message or the initiating (208) setup of a connection with the wireless device is performed based on the load of connection request messages of the first category in relation to a first load threshold.

3. Method according to claim 2, wherein when the connection request message is determined (204) to belong to the first category, the connection request message is rejected (206) when the load of connection request messages of the first category is above or same as the first load threshold and the connection setup is initiated (208) for the wireless device when the load of connection request messages of the first category is below the first load threshold.

4. Method according to claim 3, wherein when the connection request message is determined (204) to belong to the first category and when the load of connection request messages of the first category is below the first load threshold, increasing (207) the load of connection request messages of the first category with 1.

5. Method according to any of the preceding claims, wherein when the connection request message is determined (204) to belong to the second category, the either rejecting (210) of the connection request message or initiating (212) setup of a connection with the wireless device is performed based on the load of connection request messages of the second category in relation to a second load threshold.

6. Method according to claim 5, wherein when the connection request message is determined (204) to belong to the second category, the connection request message is rejected (210) when the load of connection request messages of the second category is above or same as the second load threshold and the connection setup is initiated (212) for the wireless device when the load of connection request messages of the second category is below the second load threshold.

7. Method according to claim 6, wherein when the connection request message is determined (204) to belong to the second category and when the load of connection request messages of the second category is below the second load threshold, increasing (211 ) the load of connection request messages of the second category with 1 .

8. Method according to claim 2, 3 or 4 in combination with claim 5, 6 or 7, wherein the first load threshold and the second load threshold are adjustable.

9. Method according to claim 8, wherein the first load threshold and the second load threshold are adjustable based on previous load of connection request messages of the first category and previous load of connection request messages of the second category, the respective previous loads being determinedbased on a previous time period that ended before the connection request message was received (202).

10. Method according to claim 9, further comprising, before the receiving (202) of the connection request message, determining (222) that the previous load of connection request messages of the first category is below the first load threshold and that the previous load of connection request messages of the second category is above the second load threshold, decreasing (224) the first load threshold and increasing (226) the second load threshold.11 . Method according to claim 10, wherein the decreasing (224) of the first load threshold and the increasing (226) of the second load threshold is only performed when the first load threshold after the decrease will be above a defined minimum and / or when the second load threshold after the increase will be below a defined maximum.

12. Method according to claim 9, further comprising, before the receiving (202) of the connection request message, determining (232) that the previous load of connection request messages of the first category is above the first load threshold and that the previous load of connection request messages of the second category is below the second load threshold, increasing (234) the first load threshold and decreasing (226) the second load threshold.

13. Method according to claim 12, wherein the increasing (234) of the first load threshold and the decreasing (236) of the second load threshold is only performed when the second load threshold after the decrease will be above a defined minimum and / or when the first load threshold after the increase will be below a defined maximum.

14. Method according to claim 2, 3 or 4 in combination with claim 5, 6 or 7, wherein a sum of the first load threshold and the second load threshold equals a total number of allowed connection request messages within a defined time period.

15. A network node (130) configured to operate in a wireless communication network (100), and configured for handling a connection establishment procedure, the network node (130) comprising a processing circuitry (603) and a memory (604), said memory containing instructions executable by said processing circuitry, whereby the network node (130) is operative for: receiving, from a wireless device (140), a connection request message comprising an ID of the wireless device, determining whether the ID of the wireless device (140) is registered as a wireless device ID in the network, the connection request message thus belonging to a first category, or whether the ID of the wireless device (140) is not registered as a wireless device ID in the network, the connection request message thus belonging to a second category (100), and when the connection request message is determined to belong to the first category and based on a load of connection request messages of the first category, either rejecting the connection request message or initiating setup of a connection with the wireless device, and when the connection request message is determined to belong to the second category and based on a load of connection request messages of the second category, either rejecting the connection request message or initiating setup of a connection with the wireless device.

16. Network node (130) according to claim 15, wherein when the connection request message is determined to belong to the first category, the network node is operative for performing the either rejecting of the connection request message or the initiating setup of a connection with the wireless device based on the load of connection request messages of the first category in relation to a first load threshold.

17. Network node (130) according to claim 16, wherein when the connection request message is determined to belong to the first category, the network node (130) is operative for rejecting the connection request message when the load of connection request messages of the first category is above or same as the first load threshold and operative for initiating the connection setup for the wireless device when the load of connection request messages of the first category is below the first load threshold.

18. Network node (130) according to claim 17, wherein when the connection request message is determined to belong to the first category and when the load of connection request messages of the first category is below the first load threshold, the network node (130) is operative for increasing the load of connection request messages of the first category with 1 .

19. Network node (130) according to any of claims 15-18, wherein when the connection request message is determined to belong to the second category, the network node (130) is operative for performing the either rejecting of the connection request message or initiating setup of a connection with the wireless device based on the load of connection request messages of the second category in relation to a second load threshold.

20. Network node (130) according to claim 19, wherein when the connection request message is determined to belong to the second category, the network node (130) is operative for rejecting the connection request message when the load of connection request messages of the second category is above or same as the second load threshold and operative for initiating connection setup for the wireless device when the load of connection request messages of the second category is below the second load threshold.21 . Network node (130) according to claim 20, wherein when the connection request message is determined to belong to the second category and when the load of connection request messages of the second category is below the second load threshold, the network node (130) is operative for increasing the load of connection request messages of the second category with 1 .

22. Network node (130) according to claim 16, 17 or 18 in combination with claim 19, 20 or 21 , operative for adjusting the first load threshold and the second load threshold.

23. Network node (130) according to claim 22, operative for adjusting the first load threshold and the second load threshold based on previous load of connection request messages of the first category and previous load of connection request messages of the second category, the respective previous loads being determined based on a previous time period that ended before the connection request message was received.

24. Network node (130) according to claim 23, operative for, before the receiving of the connection request message, determining that the previous load of connection request messages of the first category is below the first load threshold and that the previous load of connection request messages of the second category is above the second load threshold, decreasing the first load threshold and increasing the second load threshold.

25. Network node (130) according to claim 24, operative for only performing the decreasing of the first load threshold and the increasing of the second load threshold when the first load threshold after the decrease will be above a defined minimum and / or when the second load threshold after the increase will be below a defined maximum.

26. Network node (130) according to claim 23, further being operative for, before the receiving of the connection request message, determining that the previous load of connection request messages of the first category is above the first load threshold and that the previous load of connection request messages of the second category is below the second load threshold, increasing the first load threshold and decreasing the second load threshold.

27. Network node (130) according to claim 26, operative for only performing the increasing of the first load threshold and the decreasing of the second load threshold when the second load threshold after the decrease will be above a defined minimum and / or when the first load threshold after the increase will be below a defined maximum.

28. Network node (130) according to claim 16, 17 or 18 in combination with claim 19, 20 or 21 , wherein a sum of the first load threshold and the second load threshold equals a total number of allowed connection request messages within a defined time period.

29. A computer program (605) comprising instructions, which, when executed by at least one processing circuitry of a network node (130) of a wireless communication network, configured for handling a connection establishment procedure, causes the network node (130) to perform the following steps: receiving, from a wireless device (140), a connection request message comprising an ID of the wireless device, determining whether the ID of the wireless device (140) is registered as a wireless device ID in the network, the connection request message thus belonging to a first category, or whether the ID of the wireless device (140) is not registered as a wireless device ID in the network, the connection request message thus belonging to a second category (100), and when the connection request message is determined to belong to the first category and based on a load of connection request messages of the first category, either rejecting the connection request message or initiating setup of a connection with the wireless device, and when the connection request message is determined to belong to the second category and based on a load of connection request messages of the second category, either rejecting the connection request message or initiating setup of a connection with the wireless device.

30. A carrier containing the computer program (605) according to claim 29, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, an electric signal or a computer readable storage medium.

Citation Information

Patent Citations

  • Radio resource control method, radio station device, recording medium containing radio station control program, and radio communication system

    EP2259636A1

  • Access control method and device

    EP2665310A1

  • Communicationpacket switched network for presenting Anonymous Communication Rejection and Communication Barring service, apparatus thereof and method thereof

    KR1020120038647A

  • Method and radio base station in a wireless communication network

    WO2012105877A1

  • Network congestion control

    WO2023278414A1