Method, apparatus and computer program
By using confidentiality-protected RAT identifications via non-access stratum signaling, the system ensures secure connections by preventing UE from connecting to decommissioned RATs, addressing vulnerabilities in core networks.
Patent Information
- Application Number
- PCT/EP2025/052018
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-12
- Filing Date
- 2025-01-28
- Publication Date
- 2025-08-21
AI Technical Summary
Existing communication systems face challenges in maintaining security when user equipment (UE) connects to core networks that support older, decommissioned radio access technologies (RATs like 2G and 3G) with weaker security mechanisms, leading to vulnerabilities and potential attacks.
The system provides UE with confidentiality and integrity-protected identification of unsupported RATs via non-access stratum signaling, enabling it to determine whether to switch to a different access network node or maintain connectivity based on the identified RATs, ensuring secure connections.
This approach enhances security by preventing UE from connecting to decommissioned RATs, thereby reducing vulnerabilities and maintaining minimum security levels in core networks.
Smart Images

Figure EP2025052018_21082025_PF_FP_ABST
Abstract
Description
METHOD, APPARATUS AND COMPUTER PROGRAMFIELD
[0001] The present application relates to an apparatus, method, and computer program for causing operations relating to signalling an identification of at least one radio access technology not supported by a core network.BACKGROUND
[0002] A communication system can be seen as a facility that enables communication sessions between two or more entities such as user terminals, base stations and / or other nodes by providing carriers between the various entities involved in the communications session. A communication system can be provided for example by means of a communication network and one or more compatible communication devices. The communication sessions may comprise, for example, communication of data for carrying communications such as voice, video, electronic mail (email), text message, multimedia and / or content data and so on. Non-limiting examples of services provided comprise two-way or multi-way calls, data communication or multimedia services and access to a data network system, such as the Internet.
[0003] The communication system and associated devices typically operate in accordance with a given standard or specification which sets out what the various entities associated with the system are permitted to do and how that should be achieved. Communication protocols and / or parameters which shall be used for the connection are also typically defined. One example of a communications system is UTRAN (Universal Mobile Telecommunications Service terrestrial radio access network (e.g., 3G radio)). Other examples of communication systems are the longterm evolution (LTE) of the Universal Mobile Telecommunications System (UMTS) radio-access technology and so-called 5G or New Radio (NR) networks. NR is being standardized by the 3rd Generation Partnership Project (3GPP).SUMMARY
[0004] According to a first aspect, there is provided an apparatus for a user equipment, the apparatus comprising means for performing: receiving, from an access and mobility management function of a visited core network via a first access network node of a first network, an identification of at least one radio access technology not supported by a home core network; and using the received identification for selectingan access network node for connecting to at least one of the visited core network or home core network.
[0005] According to a second aspect, there is provided an apparatus for a user equipment, the apparatus comprising: at least one processor; and at least one memory comprising code that, when executed by the at least one processor, causes the apparatus to perform: receiving, from an access and mobility management function of a visited core network via a first access network node of a first network, an identification of at least one radio access technology not supported by a home core network; and using the received identification for selecting an access network node for connecting to at least one of the visited core network or home core network.
[0006] According to a third aspect, there is provided a method for an apparatus for a user equipment, the method comprising: receiving, from an access and mobility management function of a visited core network via a first access network node of a first network, an identification of at least one radio access technology not supported by a home core network; and using the received identification for selecting an access network node for connecting to at least one of the visited core network or home core network.
[0007] According to a fourth aspect, there is provided an apparatus for a user equipment, the apparatus comprising: receiving circuitry for receiving, from an access and mobility management function of a visited core network via a first access network node of a first network, an identification of at least one radio access technology not supported by a home core network; and using circuitry for using the received identification for selecting an access network node for connecting to at least one of the visited core network or home core network.
[0008] The following may apply in respect of any (e.g., all) of the above first to fourth aspects.
[0009] The receiving the identification may comprise receiving the identification via a registration accept message.
[0010] The using the received identification for selecting an access network node for connecting to the core network may comprise: determining that the first network is not providing connectivity services to the visited core access network using the identified at least one radio access technology; and maintaining connectivity to the visited core network via the first access network node.
[0011] The using the received identification for selecting an access network node for connecting to the core network may comprise: determining that the first network is providing connectivity services to the visited core access network using the identified at least one radio access technology; and switching from the first access network node to the visited core access network via a second access network node, wherein the first and second access network nodes are different access network nodes.
[0012] The apparatus may further be caused to perform: selecting the second access network node for receiving core network access based on a determination that the second access network node is operating in accordance with a radio access technology that was not identified in the received identification from the access and mobility management function.
[0013] The switching may comprise: releasing a radio resource connection with the first access network node; and establishing a radio resource connection with the second access network node.
[0014] The apparatus may further be caused to perform: receiving, from a third access network node, an indication to connect to the core network through the third access network node; and determining whether to connect to the core network through the third network node based on the received identification and a determined radio access technology provided by the third access network node.
[0015] According to a fifth aspect, there is provided an apparatus for a unified data management function of a home core network function, the apparatus comprising means for performing: transmitting, to a user equipment via an access and mobility management function of a visited core network, an identification of at least one radio access technology not supported by the home core network.
[0016] According to a sixth aspect, there is provided an apparatus for a unified data management function of a home core network function, the apparatus comprising: at least one processor; and at least one memory comprising code that, when executed by the at least one processor, causes the apparatus to perform: transmitting, to a user equipment via an access and mobility management function of a visited core network, an identification of at least one radio access technology not supported by the home core network.
[0017] According to a seventh aspect, there is provided a method for an apparatus for a unified data management function of a home core network function, the method comprising: transmitting, to a user equipment via an access and mobility managementfunction of a visited core network, an identification of at least one radio access technology not supported by the home core network.
[0018] According to an eighth aspect, there is provided an apparatus for a unified data management function of a home core network function, the apparatus comprising: transmitting circuitry for transmitting, to a user equipment via an access and mobility management function of a visited core network, an identification of at least one radio access technology not supported by the home core network.
[0019] The following may apply in respect of any (e.g., all) of the above fifth to eighth aspects.
[0020] The transmitting the identification may comprise transmitting the identification via signalling that is confidentiality protected and integrity protected by an access network node.
[0021] The transmitting the identification comprises may comprise transmitting the identification via non-access stratum signalling.
[0022] According to a ninth aspect, there is provided an apparatus for an access and mobility function of a visited core network, the apparatus comprising means for performing: receiving, from a unified data management of a home core network, an identification of at least one radio access technology that is not supported by the home core network; and transmitting, to a user equipment via a first access network node, the received identification.
[0023] According to a tenth aspect, there is provided an apparatus for an access and mobility function of a visited core network, the apparatus comprising: at least one processor; and at least one memory comprising code that, when executed by the at least one processor, causes the apparatus to perform: receiving, from a unified data management of a home core network, an identification of at least one radio access technology that is not supported by the home core network; and transmitting, to a user equipment via a first access network node, the received identification.
[0024] According to an eleventh aspect, there is provided a method for an apparatus for an access and mobility function of a visited core network, the method comprising: receiving, from a unified data management of a home core network, an identification of at least one radio access technology that is not supported by the home core network; and transmitting, to a user equipment via a first access network node, the received identification.
[0025] According to a twelfth aspect, there is provided an apparatus for an access and mobility function of a visited core network, the apparatus comprising: receiving circuitry for receiving, from a unified data management of a home core network, an identification of at least one radio access technology that is not supported by the home core network; and transmitting circuitry for transmitting, to a user equipment via a first access network node, the received identification.
[0026] The following may apply in respect of any (e.g., all) of the above first to twelfth aspects.
[0027] The received identification may be comprised in a registration response message.
[0028] The received identification may be comprised in a signalling of a steering of roaming service operation and / or in signalling of a user parameter update service operation.
[0029] The identified radio access technology may comprise at least one of: 2G, 3G, 4G and / or 5G.
[0030] The identification of at least one radio access technology not supported by the home core network may identify at least one radio access technology having a security mechanism that is not compliant with a security mechanism of the home core network.
[0031] According to a thirteenth aspect, there is provided an apparatus for a user equipment, the apparatus comprising means for performing: receiving, from a core network function of a core network via a first access network node of a first network, an identification of at least one radio access technology not supported by the core network; and using the received identification for selecting an access network node for connecting to the core network.
[0032] According to a fourteenth aspect, there is provided an apparatus for a user equipment, the apparatus comprising: at least one processor; and at least one memory comprising code that, when executed by the at least one processor, causes the apparatus to perform: receiving, from a core network function of a core network via a first access network node of a first network, an identification of at least one radio access technology not supported by the core network; and using the received identification for selecting an access network node for connecting to the core network.
[0033] According to a fifteenth aspect, there is provided a method for an apparatus for a user equipment, the method comprising: receiving, from a core network function of a core network via a first access network node of a first network, an identification of atleast one radio access technology not supported by the core network; and using the received identification for selecting an access network node for connecting to the core network.
[0034] According to a sixteenth aspect, there is provided an apparatus for a user equipment, the apparatus comprising: receiving circuitry for receiving, from a core network function of a core network via a first access network node of a first network, an identification of at least one radio access technology not supported by the core network; and using circuitry for using the received identification for selecting an access network node for connecting to the core network.
[0035] The following may apply in respect of any (e.g., all) of the above thirteenth to sixteenth aspects.
[0036] The receiving the identification may comprise receiving the identification via signalling that is confidentiality protected and integrity protected by the first access network node.
[0037] The receiving the identification may comprise receiving the identification via non-access stratum signalling.
[0038] The using the received identification for selecting an access network node for connecting to the core network may comprise: determining that the first network is not providing connectivity services to the core access network using the identified at least one radio access technology; and maintaining connectivity to the core network via the first access network node.
[0039] The using the received identification for selecting an access network node for connecting to the core network may comprise: determining that the first network is providing connectivity services to the core access network using the identified at least one radio access technology; and switching from the first access network node to a second access network node for connecting to the core network, wherein the first and second access network nodes are different access network nodes.
[0040] The apparatus may further be caused to perform: selecting the second access network node for connecting to the core network based on a determination that the second access network node is operating in accordance with a radio access technology that was not identified in the received identification from the core network function.
[0041] The switching may comprise: releasing a radio resource connection with the first access network node; and establishing a radio resource connection with the second access network node.
[0042] The apparatus may be further caused to perform: receiving, from a third access network node, an indication to connect to the core network through the third access network node; and determining whether to connect to the core network through the third access network node based on the received identification and a determined radio access technology provided by the third access network node.
[0043] The apparatus may further be caused to perform: determining to switch from a current access network node to another access network node for connecting to the core network; and using the received identification to select the another network node.
[0044] According to a seventeenth aspect, there is provided an apparatus for a core network function, the apparatus comprising means for performing: transmitting, to a user equipment via a first access network node, an identification of at least one radio access technology not supported by the core network.
[0045] According to an eighteenth aspect, there is provided an apparatus for a core network function, the apparatus comprising: at least one processor; and at least one memory comprising code that, when executed by the at least one processor, causes the apparatus to perform: transmitting, to a user equipment via a first access network node, an identification of at least one radio access technology not supported by the core network.
[0046] According to a nineteenth aspect, there is provided a method for an apparatus for a core network function, the method comprising: transmitting, to a user equipment via a first access network node, an identification of at least one radio access technology not supported by the core network.
[0047] According to a twentieth aspect, there is provided an apparatus for a core network function, the apparatus comprising: transmitting circuitry for transmitting, to a user equipment via a first access network node, an identification of at least one radio access technology not supported by the core network.
[0048] The following may apply in respect of any (e.g., all) of the above seventeenth to twentieth aspects.
[0049] The transmitting the identification may comprise transmitting the identification via signalling that is confidentiality protected and integrity protected by the first access network node.
[0050] The transmitting the identification may comprise transmitting the identification via non-access stratum signalling.
[0051] The following may apply in respect of any (e.g., all) of the above thirteenth to twentieth aspects.
[0052] The identification may be comprised in a registration response message.
[0053] The identification may be comprised in a signalling of a steering on roaming service operation and / or in signalling of a user parameter update service operation.
[0054] The identified radio access technology may comprise comprises at least one of: 2G, 3G, 4G and / or 5G.
[0055] The identification of at least one radio access technology not supported by the core network may identify at least one radio access technology having a security mechanism that is not compliant with a security mechanism of the core network.
[0056] The core network function may comprise a core network function of at least one of a home public land mobile network or a visited public land mobile network.
[0057] According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the method according to any of the preceding aspects.
[0058] In the above, many different embodiments have been described. It should be appreciated that further embodiments may be provided by the combination of any two or more of the embodiments described above.DESCRIPTION OF FIGURES
[0059] Embodiments will now be described, by way of example only, with reference to the accompanying Figures in which:
[0060] Figures 1 A to 1 B show representations of a network system according to some example embodiments;
[0061] Figure 2 shows a representation of a control apparatus according to some example embodiments;
[0062] Figure 3 shows a representation of an apparatus according to some example embodiments;
[0063] Figures 4 to 5 illustrate example signalling;
[0064] Figure 6 illustrates example information fields; and
[0065] Figures 7 to 11 illustrate example operations that may be performed by apparatus described herein.DETAILED DESCRIPTION
[0066] The following describes operations that may be performed in relation to helping to maintain a minimum level of security for a user equipment (UE) that is communicating with a network via a cell operating according to a radio access technology (e.g., 2G, 3G, 4G, 5G, 6G, etc.) provided by an access network node.
[0067] In more detail, 3GPP Rel-15 introduced an assumption that a public land mobile network (PLMN) 5G radio access technology (RAT) will not co-exist with 2G RATs, and that the 5G PLMN RAT will integrate with 3G RAT for limited use cases (e.g., the 5G PLMN may support 3G RATs for, for example, voice calls, such as single radio voice calls).
[0068] However this assumption that 2G RAT and / or some 3G RAT will not co-exist with 5G is not always true in reality as, in many networks, 2G RAT and / or 3G RAT do co-exist with 5G PLMNs. The coexistence of 2G RAT and / or 3G RAT is also not explicitly prohibited in 3GPP standards, which has led to regions where cells of varying RAT type all connect to a same core network operated by a network operator.
[0069] Despite this possible coexistence, several network operators have made steps to “decommission” access network nodes from such older RATs (e.g., 2G, 3G) so that operators of the 5G PLMNs can provide services using newer radio access technologies. Stated differently, several network operators have introduced restrictions and / or bans prohibiting older RATs from being used to provide connectivity services to a network. This may help to maintain a minimum-security level by the network operators for signalling information between a user equipment and the network via an access network node.
[0070] In light of such decommissioning, it is no longer appropriate to allow a UE supporting 2G or 3G RAT networks to continue selecting such networks for connecting to a 5G core. Further, due to weaker security mechanism protection in these previous generation technologies, if UEs are tricked into selecting such networks, then those UEs will be vulnerable to many known attacks pertaining to 2G and 3G.
[0071] To address at least one of the above-mentioned issues, the following describes mechanisms for enabling a core network function of a network to identify, to a user equipment connecting to the core network via an access network node, of at least oneradio access technology (RAT) that is not supported by the core network. For example, a network operator may have defined that the at least one RAT is not compliant with a minimum-security level to be applied by the core network.
[0072] The user equipment may be provided with identification(s) of the at least one RAT using signaling that is confidentiality protected (e.g., unreadable and / or cyphered) and / or integrity protected (e.g., unmodifiable) by the access network node. This may be performed, for example, using non-access stratum signaling. Examples provided below illustrate such non-access stratum signaling using procedures such as steering of roaming and user parameter update service operations. However, it is understood that the presently described techniques are not limited to the signaling of these two service operations.
[0073] The user equipment may use the identification of the at least one RAT to determine whether the user equipment should switch from the access network node the user equipment is currently using to connect to the core network to another access network node. Stated differently, the user equipment may determine whether the access network node is using an RAT corresponding to the identified at least one RAT. When the access network node is using an RAT corresponding to the identified at least one RAT, the user equipment may disconnect from the access node (e.g., release a radio resource control connection with the access node). The user equipment may further select the another access network node based on the identified at least one RAT such that the another access network node does not deploy the at least one RAT. When the access network node is not using an RAT corresponding to the identified at least one RAT, the user equipment may maintain a connection (e.g., maintain a radio resource control connection) to the core network via the access network node.
[0074] For both of these cases (e.g., maintaining a radio resource control connection and releasing a radio resource control connection), the user equipment may further maintain (e.g., store) identification(s) of the at least one RAT and use the maintained identification(s) for performing cell selection during a later mobility procedure.
[0075] Some examples of how this may be performed are provided further below with reference to 5G terminology.
[0076] As an aside, although the above decommissioning scenario is discussed in terms of 2G and 3G RAT networks being decommissioned for use in providing connectivity services to a 5GC, the same principles apply in respect of any “older” RAT network being decommissioned by a more recent PLMN operator. For example, whenthe more recent PLMN operator comprises a 6G network operator, the “older” RAT network being decommissioned may comprise at least one of: a 2G RAT network, a 3G RAT network, a 4G RAT network, or a 5G network. As another example, when the more recent PLMN operator comprises a 7G network operator, the “older” RAT network being decommissioned may comprise at least one of: a 2G RAT network, a 3G RAT network, a 4G RAT network, a 5G network, or a 6G network.
[0077] It is further understood that although this scenario is discussed in terms of 3GPP networks, that the “older” RAT network being decommissioned may comprise at least one of a non-3GPP RAT network or a 3GPP RAT network.
[0078] Before explaining in detail the exemplifying embodiments, certain general principles of a wireless communication system, access systems thereof, and mobile communication devices are briefly explained with reference to Figures 1A, 1 B, 2 and 3 to assist in understanding the technology underlying the described examples.
[0079] Figure 1 A shows a schematic representation of a 5G system (5GS) configured to communicate with a terminal (e.g., a user equipment (UE)). The 5GS may be a 5G radio access network (5GRAN) or next generation radio access network (NG-RAN), a 5G core network (5GC), one or more application function (AF) and one or more data networks (DN).
[0080] The 5G-RAN may comprise one or more gNodeB (GNB) or one or more gNodeB (GNB) distributed unit functions connected to one or more gNodeB (GNB) centralized unit functions. This is illustrated in more detail below, with reference to Figure 1 B.
[0081] The 5GC may comprise the following entities: Network Slice Selection Function (NSSF); Network Exposure Function; Network Repository Function (NRF); Policy Control Function (PCF); Unified Data Management (UDM); Application Function (AF); Authentication Server Function (AUSF); an Access and Mobility Management Function (AMF); and Session Management Function (SMF). Figure 1 also shows the various interfaces (N1 , N2 etc.) that may be implemented between the various elements of the system.
[0082] Figure 1 B illustrates an example communication environment in which example embodiments of the present disclosure can be implemented.
[0083] Figure 1 B shows an example communication environment 100 in which example embodiments of the present disclosure can be implemented.
[0084] In the communication environment 100, a plurality of communication devices, comprising user devices 110 and 115 (also referred to herein as a “terminal” or “terminal device”) and a network device 120 (also referred to herein as a “access network node”), can communicate with each other. The network device 120 may serve a coverage area, called a cell 125. The user device 110 may have access to a communication network via the cell 125. In some example embodiments, both the user device 110 and the network device 120 may be configured to implement a beamforming technique and communicate with each other via a plurality of beams.
[0085] Communications in the communication environment 100 may be implemented according to any proper communication protocol(s), comprising, but not limited to, cellular communication protocols of the first generation (1 G), the second generation (2G), the third generation (3G), the fourth generation (4G), the fifth generation (5G), the sixth generation (6G), and the like, wireless local network communication protocols such as Institute for Electrical and Electronics Engineers (IEEE) 802.11 and the like, and / or any other protocols currently known or to be developed in the future. Moreover, the communication may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple (OFDM), Discrete Fourier Transform spread OFDM (DFT-s-OFDM) and / or any other technologies currently known or to be developed in the future.
[0086] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example rather than limitation, a terminal device may also be referred to as a communication device, user equipment (UE), a Subscriber Station (SS), a Portable Subscriber Station, a mobile device, a Mobile Station (MS), or an Access Terminal (AT). The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA), portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), USB dongles, smart devices, wireless customer-premises equipment (CPE), amachine-type communications (MTC) device, an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. The terminal device may also correspond to a Mobile Termination (MT) part of an IAB node (e.g., a relay node). In the following description, the terms “terminal device”, “communication device”, “terminal”, “user device”, “user equipment” and “UE” may be used interchangeably.
[0087] As used herein, the term “network device” is used interchangeably with “access network node”, and refers to a node in a communication network via which a terminal device accesses the network and receives services therefrom. The network device may refer to a base station (BS) or an access point (AP), for example, a node B (NodeB or NB), an evolved NodeB (eNodeB or eNB), an NR NB (also referred to as a gNB), a Remote Radio Unit (RRU), a radio header (RH), a remote radio head (RRH), a relay, an Integrated Access and Backhaul (IAB) node, a low power node such as a femto, a pico, a non-terrestrial network (NTN) or non-ground network device such as a satellite network device, a low earth orbit (LEO) satellite and a geosynchronous earth orbit (GEO) satellite, an aircraft network device, and so forth, depending on the applied terminology and technology. In some example embodiments, radio access network (RAN) split architecture comprises a Centralized Unit (CU) and a Distributed Unit (DU) at an IAB donor node. An IAB node comprises a Mobile Terminal (IAB-MT) part that behaves like a UE toward the parent node, and a DU part of an IAB node behaves like a base station toward the next-hop IAB node.
[0088] In some example embodiments, a link from the network device 120 to the user device 110 or 115 is referred to as a DL, while a link from the user device 110 or 115 to the network device 120 is referred to as a UL. Links are also referred to herein as “channels”. In DL, the network device 120 is a Tx device (or a transmitter), and the user device 110 or 115 is a Rx device (or a receiver). In UL, the user device 110 or 115 is a Tx device (or a transmitter), and the network device 120 is a Rx device (or a receiver). A link between the user device 110 and another user device (not shown) is referred to as a sidelink (SL). In SL, one of the user devices is a Tx device (or a transmitter), and the other of the user devices is a Rx device (or a receiver).
[0089] Figure 2 illustrates an example of a control apparatus 200 for causing a network device 120 ((such as the network device described in Figure 1A and / or Figure 1 B) and / or a network function (such as the network function described in Figure 1 A and / or 1 B)) to perform its operations. The control apparatus may comprise at least one random access memory (RAM) 211 a, at least on read only memory (ROM) 211 b, at least one processor 212, 213 and an input / output interface 214. The at least one processor 212, 213 may be coupled to the RAM 211a and the ROM 211 b. The at least one processor 212, 213 may be configured to execute an appropriate software code 215. The software code 215 may for example allow to perform one or more steps to perform one or more of the present aspects. The software code 215 may be stored in the ROM 211 b. The control apparatus 200 may be interconnected with another control apparatus 200 controlling another function of the network device. In some embodiments, each function of the network device comprises a control apparatus 200. In some exemplary embodiments, the apparatus 200 may be implemented at the network device 120 or may be the network device 120.
[0090] Figure 3 illustrates an example of a terminal 300, such as the user device 110, 115 illustrated on Figure 1A and / or Figure 1 B. The terminal 300 may be provided by any device capable of sending and receiving radio signals, such as the user device described herein. The terminal 300 may provide, for example, communication of data for carrying communications. The communications may be one or more of voice, electronic mail (email), text message, multimedia, data, machine data and so on.
[0091] The terminal 300 may receive signals over an air or radio interface 307 via appropriate apparatus for receiving and may transmit signals via appropriate apparatus for transmitting radio signals. In Figure 3 transceiver apparatus is designated schematically by block 306. The transceiver apparatus 306 may be provided for example by means of a radio part and associated antenna arrangement. The antenna arrangement may be arranged internally or externally to the mobile device.
[0092] The terminal 300 may be provided with at least one processor 301 , at least one memory ROM 302a, at least one RAM 302b and other possible components 303 for use in software and hardware aided execution of tasks it is designed to perform, including control of access to and communications with access systems (such as a network access system provided by the network device described above in relation to Figures 1 and 2) and other communication devices. The at least one processor 301 iscoupled to the RAM 302b and the ROM 302a. The at least one processor 301 may be configured to execute an appropriate software code 308. The software code 308 may for example allow to perform one or more of the present aspects. The software code 308 may be stored in the ROM 302a.
[0093] The processor, storage and other relevant control apparatus can be provided on an appropriate circuit board and / or in chipsets. This feature is denoted by reference 304. The device may optionally have a user interface such as key pad 305, touch sensitive screen or pad, combinations thereof or the like. Optionally one or more of a display, a speaker and a microphone may be provided depending on the type of the device.
[0094] In some exemplary embodiments, the terminal 300 may be an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause a user device 110, 115 to perform examples or embodiments described in this document.
[0095] As mentioned above, the following proposes that a core network entity (e.g., a core network function) provides a UE with an identification of at least one RAT decommissioned by the network operator of the core network entity for addressing at least one of the above-mentioned issues. The UE may use this identification for selecting whether to switch from a current RAT access network node to another RAT access network node. The UE may further use this identification for selecting the another RAT access network node when such a switch is to be made, and / or more generally when the UE is caused to perform a mobility operation from the current RAT access network node.
[0096] For conciseness, the following will refer to an access network node configured to provide connectivity services to a UE via a decommissioned RAT as a “false” access network node, and will refer to an access network node configured to provide connectivity services to a UE via a non-decommissioned RAT as a “good” access network node.
[0097] The identification of the at least one RAT decommissioned by the network operator of the core network entity may be provided to the UE via a good access network node and / or via a false access network node.
[0098] For example, the identification of the at least one RAT decommissioned by the network operator of the core network entity may be provided to the UE via a good access network node. In such a case, the UE may determine that the UE is currentlyconnected to the core network via a good access network node, and simply store the identification of the at least one RAT decommissioned by the network operator for a future mobility operation (e.g., handover and / or multi-carrier operations).
[0099] Stated differently, the UE may determine that the UE is currently connected to the core network via a good access network node and maintain the UE’s radio resource control (RRC) connection to the core network via the good access network node (e.g., the UE does not disconnect from the good access network node based on the received identification of the at least one RAT decommissioned by the network operator). The UE may use the received identification of the at least one RAT decommissioned by the network operator for selecting at least one cell for connecting to the core network during a later mobility operation.
[0100] As mentioned above, the identification of the at least one RAT decommissioned by the network operator of the core network entity may be provided to the UE via a false access network node. In such a case, the UE may determine that the UE is currently connected to the core network via a false access network node, and initiate (e.g., trigger) a mobility operation to be performed to access the core network via another access network node. The UE may use the identification of the at least one RAT decommissioned by the network operator for selecting the another access network node. The UE may further store the identification of the at least one RAT decommissioned by the network operator for another (future) mobility operation (e.g., handover and / or multi-carrier operations).
[0101] Stated differently, the UE may determine that the UE is currently connected to the core network via a false access network node and disconnect from the false access network node (e.g., release a radio resource connection with the false access network node) based on the received identification of the at least one RAT decommissioned by the network operator. The UE may use the received identification of the at least one RAT decommissioned by the network operator for selecting at least one cell for connecting to the core network subsequent to this disconnection. The UE may further store the identification of the at least one RAT decommissioned by the network operator for another (future) mobility operation (e.g., handover and / or multi-carrier operations).
[0102] In both of these example options, the UE may store the identification of the at least one RAT decommissioned by the network operator for a future mobility operation (e.g., for selecting a cell as part of the future mobility operation). The UE may storethe identification(s) in a priority list, where the priority list is used to ensure that the UE does not attach to decommissioned RATs.
[0103] The way in which the identification of the at least one RAT decommissioned by the network operator may be signalled to (or otherwise understood by) the UE may be performed using at least one of a size, format, and / or structure of master information blocks (MIB(s)), or a size, format, and / or structure of System Information Block(s) (SIB(s)) received by the UE. When a “false” access network node is using 2G or 3G RAT, the MIBs and SIBs received at the UE from that false access network node will not match the 4G and / or 5G format, structure and sizes that are expected to be received at the UE. From this, the UE may determine whether the access node to which the UE is currently maintaining a radio resource control connection with (e.g., with which the UE is currently receiving connectivity services from) is a false access network node or a good access network node.
[0104] Further, a system information block, such as SIB4 and / or SIB5, may provide a UE with neighbour cell information, such as respective RAT type(s) supported by neighbouring cells. The UE may further use such information comprised in such system information blocks for determining whether an access network node is a false access network node (and so should not be selected by the UE for switching to from a current access network node) or is a good access network node (and so may be selected by the UE for switching to from a current access network node).
[0105] As SIBs are not secure, the information comprised therein can be modified by false access network node. It may therefore not be sufficient for the UE to rely only on SIB / MIB information for identifying those false access network nodes. In order to ensure that a false access network node does not use manipulated SIB / MIB information to get a UE attached to a decommissioned RAT, a UE may give a higher weight to the received decommissioned RAT information compared to the information the UE receives from SIB / MIB. When the UE receives contradictory information from different sources, UE can still decide to search for a RAT which is not decommissioned.
[0106] In order to bolster the security of such a network configuration, the core network function may cause the identification of the at least one RAT decommissioned by the network operator to be provided to the UE in signalling that cannot be decoded by the access network node (e.g., the identification of the at least one RAT decommissioned by the network operator may be signalled using non-access stratum signalling).
[0107] The use of such signalling may be useful, for example, in situations where the access network node to which the UE is currently connected is untrusted and / or is considered to be a security risk as the access network node cannot successfully modify the identification of the at least one RAT decommissioned by the network operator to insert and / or remove at least one RAT from the at least one RAT decommissioned by the network operator.
[0108] Stated differently, when a UE attempts to attach to a serving network, the serving network provides information about decommissioned RATs to the UEs included in the response for the attach request using a first secure NAS message sent from an AMF to the UE to ensure that any false access network node is not able to modify this information. The NAS security context established between the UE and the core network to which the UE is attaching may thus help to ensure that this information is not tampered with even when a false access network node is acting as man-in-the- middle.
[0109] As another example, when a UE is in an IDLE mode, when the UE receives a radio resource control redirect (RRC_Redirect) message, the UE checks the decommissioned RAT list to ensure that the redirection is not for an access network node operating according to an RAT on the decommissioned RAT list. When the access node of the RRC_Redirect message does operate according to an RAT on the decommissioned RAT list, the UE can ignore or reject the redirection message.
[0110] Potential features of the above-mentioned methods are illustrated with respect to the examples of Figures 4 to 11 .
[0111] A first example method is illustrated with respect to Figure 4.
[0112] Figure 4 illustrates signalling that may be performed between a UE 401 , a “false” access network node 402, a “good” access network node 403, and a core network function 404. The access network nodes 402, 403 may comprise, for example, any node in an access network that provides connectivity services to a core network to a UE. The access network node may comprise, for example, a gNB, femto node, etc. The “false” access network node 402 may comprise an access network node that operates using a non-up-to-date communication protocol (e.g., 2G and / or 3G and / or 4G) having weaker security procedures relative to the “good” access network node 403 (e.g., which operates using 5G and / or 6G and / or beyond).
[0113] 4001 to 4004 relate to a UE selecting an access network node for providing connectivity services to a core network.
[0114] During 4001 , the UE 401 is powered on.
[0115] During 4002, the UE performs a cell detection and / or selection method. This cell detection and / or selection method may detect a plurality of cells (e.g., a plurality of coverage regions provided by at least one access network node), including a cell provided by the false access network node 402. The plurality of cells may be detected by receiving information broadcast by at least one of the cells.
[0116] During 4003, the UE 401 determines to connect to the core network via the false access network node 402. Consequent to this determination of 4003, during 4004 the UE 401 performs a random-access channel procedure for initiating a connection for connectivity services with the false access network node 402. It is understood that although the UE 401 may have alternatively discovered and / or determined to connect via the good access network node 403 during 4003 and 4004, that larger security issues arise when the false access network node 402 is selected for providing connectivity services, and so this example is being considered.
[0117] 4005 to 4008 are performed after a successful RACH procedure has been performed during 4001 to 4004.
[0118] During 4005, the false access network node 402 signals the UE 401. This signalling may comprise a radio resource control (RRC) connection setup signalling message. Stated differently, the signalling may comprise an RRC connection setup configuration for use by the UE 401 for connecting with the false access network node 402.
[0119] During 4006, the UE 401 signals the false access network node 402. This signalling may comprise an indication that the RRC connection setup configuration in the signalling of 4005 has been complied with. Stated differently, this signalling may comprise an RRC connection setup complete signalling message. The signalling may comprise a non-access stratum (NAS) registration request.
[0120] During 4007, the false access network node 402 signals the core network function 404. This signalling may comprise the NAS registration request of 4006.
[0121] During 4008, the UE 401 , the false access network node 402, and the core network function 403 exchange signalling for completing NAS registration authentication, and NAS security context establishment procedures between the UE 401 and the core network function 403. It is assumed that the UE primary authentication and NAS security context establishment completes successfully with an access and mobility management function (AMF) of the core network during 4008.
[0122] During 4009, the core network function 404 signals the UE 401. This signalling comprises an indication that the NAS registration procedures of 4008 have been completed. This signalling may further comprise information about decommissioned radio access technologies (RATs), such as an indication of those RATs whose security mechanisms do not meet a minimum standard set by a network operator of the core network. As this information about decommissioned RATs is sent over a secure NAS connection, this information cannot be tampered with without the UE 401 being able to identify the tampering (e.g., when a cyclic redundancy check performed by the UE 401 is later failed), or read by the false access network node. Stated differently, the information about decommissioned RATs may be signalled using signalling that renders the information about decommissioned RATs as confidentiality protected and integrity protected.
[0123] It is understood that although the false access network node 402 may still drop and / or tamper this signalling of 4009, such an interference with the signalling of 4009 would corrupt the NAS completion message to the extent that the UE 401 would be able to determine that NAS has not been successfully completed, and would consequently be caused to perform a new cell reselection procedure. Such tampering may be considered as a temporary denial of service. When the UE cannot receive the information about decommissioned RATs during 4009 (e.g., because it has been tampered with), the UE can connect to another access network node using analogous signalling to 4003 to 4009 to receive this decommissioned RAT information from the another access network node.
[0124] During 4010, the UE 401 uses the information about decommissioned RATs comprised in the signalling of 4009 to update the UE’s cell search and reselection criteria, such that access network nodes that operate in accordance with a decommissioned RAT indicated in the information are not selected by the UE 401 for providing connectivity services to the core network node.
[0125] During 4011 , the UE 401 determines whether the RAT of the cell to which the UE 401 is currently connected corresponds to a decommissioned RAT indicated in the information of 4009.
[0126] When the determination of 4011 results in a determination that the RAT of the cell to which the UE 401 is currently connected does not correspond to the to a decommissioned RAT indicated in the information of 4009, the UE 401 proceeds with receiving connectivity services to the core network via the false access network node.
[0127] When the determination of 4011 results in a determination that the RAT of the cell to which the UE 401 is currently connected corresponds to the to a decommissioned RAT indicated in the information of 4009, the method proceeds to 4012.
[0128] During 4012, the UE 401 signals the false network node 402. This signalling may comprise signalling for causing the RRC connection established during 4005 to 4006 to be released. For example, the signalling of 4012 may comprise an RRC Connection Release message.
[0129] The signalling of 4012 may comprise an indication of why the RRC connection is being released. For example, the signalling of 4012 may comprise an indication that the reason why the RRC connection is being released is because of an error, and / or because of a security issue, and / or for some unknown reason. The UE 401 may further remove the cell to which the UE 401 is currently connected from the UE’s ceil priority list.
[0130] During 4013, the UE 401 performs a cell search and / or cell selection procedure (e.g., such as 4002 to 4003) except where the cell selection is performed to avoid those cells operating using the indicated decommissioned RATs. This may be performed using the updated cell priority list of 4012.
[0131] Having selected a new cell during 4013 (e.g., a cell provided by the good access network node 403), the UE 401 performs a random-access channel access procedure with the good access network node 403 during 4014.
[0132] During 4015, the UE 401 establishes a NAS security context with the core network function 404 via the good access network node 403.
[0133] During 4016, the UE 401 and the cell provided by the good access network node 403 establish an access stratum security context.
[0134] The UE 401 may subsequently move to an RRC IDLE mode during 4017.
[0135] At some point during the UE’s operation, a false access network node 402 may signal the UE 401 an RRC redirection (such as, for example, during 4018). This RRC redirection signalling may be configured to request that the UE 401 signals the core network function 404 via the false access network node 402.
[0136] The UE 401 may be configured to be able to not comply with such an RRC redirection message as comprised in 4018 when the UE 401 determines that the RRC redirection message was signalled by a cell using a decommissioned RAT. This lackof compliance is represented by 4019. In some examples, the UE 401 may respond to the signalling of 4018 with an error message (not shown).
[0137] In the example of Figure 4, because the decommissioned RATs information is sent on top of NAS Registration complete message, any UE would receive the information about decommissioned RATs every time that UE connects to the core network. Whether or not the decommissioned RAT information is comprised in the NAS signalling may (and / or what type of decommissioned RAT information is comprised in the NAS signalling may vary for different tracking areas.
[0138] For example, network operators may configure this information about decommissioned RATs in core network. The information configured may be dependent upon the areas where specific RATs are decommissioned. This configuration can be in UDM and / or AMFs. Configurations in UDM may not be able to cover all tracking area-specific decommissioning information.
[0139] The cell (re)selection information can also be used during handovers to ensure that UEs do not connect to BTSs providing services for RATs which the operator had decommissioned in that area.
[0140] The above example of Figure 4 illustrates that NAS signalling may be used for providing the decommission RAT information to the user equipment. There are a range of different procedures that may be used for this. Two of these procedures may be, for example, steering of roaming (SoR) service operations, and user parameter update (UPU) service operations.
[0141] The SoR service operation example is illustrated with respect to Figure 5, and uses terminology corresponding to service operations described in 3GPP TS 23.502, clause 4.
[0142] In more detail, Figure 5 illustrates a method for signalling decommissioned RAT information from a home public land mobile network (HPLMN) to a visited PLMN (VPLMN). In this example of Figure 5, the decommissioned RAT information (which indicates at least one RAT that has been decommissioned by the HPLMN) is signalled with information regarding steering. The signalling of the decommissioned RAT information and steering information may be performed using signalling that cannot be read and / or modified by the access network node that is connecting the UE to the VPLMN. For example, the signalling of the decommissioned RAT and steering information using control plane-based signalling.
[0143] Figure 5 illustrates signalling that may be performed between a UE 501 , a visited public land mobile network (VPLMN) AMF 502, a home public land mobile network (HPLMN) AUSF 503, and a HPLMN UDM 504.
[0144] During 5001 , the UE 501 signals a registration request to the VPLMN AMF 502.
[0145] 5002 to 5006 relate to registration procedures defined in clause 4.2.2.2.2 of 3GPP TS 23.502.
[0146] During 5002, the UE 501 , VPLMN AMF 502, HPLMN AUSF 503, and HPLMN UDM 504 exchange signalling for performing a primary authentication procedure.
[0147] During 5003, the UE 501 and VPLMN AMF 502 exchange signalling for NAS Security Mode Command (SMC) procedure.
[0148] During 5004, the VPLMN AMF 502 signals the HPLMN UDM 504. This signalling may comprise a registration request for registering the UE’s connectivity access via the VPLMN AMF 502 with the HPLMN UDM 504. This signalling operation may comprise an Nudm_UECM_Registration message.
[0149] During 5005, the HPLMN UDM 504 signals the VPLMN AMF 502. This signal may comprise a response to the signalling of 5004 to confirm that the connectivity access of 5004 has been registered at the UDM. This signalling operation may comprise an Nudm_UECM_Registration_Response message.
[0150] During 5006, the VPLMN AMF 502 signals the HPLMN UDM 504. This signalling may request access and mobility subscription information corresponding to the UE’s subscription. This signalling may comprise an Nudm_SDM_Get service operation message.
[0151] During 5007, the HPLMN UDM 504 determines to send Steering of Roaming (SoR) Information to the VPLMN AMF 502.
[0152] Further during 5007, the HPLMN determines to obtain a list of preferred PLMN- access technology combinations and optional additional SoR information. For example, the HPLMN... (e.g. the steering of roaming connected mode control information (SOR-CMCI) and the "Store the SOR-CMCI in the ME" indicator), or a secured packet list as described in TS 23.122. Additional SoR information (e.g. SOR- CMCI and the "Store the SOR-CMCI in the ME" indicator) can only be added when the AMF supports SoR transparent container.
[0153] It is understood that the HPLMN UDM may determine that the UE is configured to not expect to receive Steering of Roaming Information at initial registration and may further determine that no change of the "Operator Controlled PLMN Selector withAccess Technology" and the “decommissioned RATs information” list stored in the UE is needed. In such a case (e.g., based on such determinations), then the HPLMN UDM may not piggyback Steering of Roaming Information in the Nudm_SDM_Get response mentioned below, and hence the following steps are not performed. The following operations may thus relate to the case when the HPLMN UDM determines that the UE is configured to expect Steering of Roaming information.
[0154] 5008 to 5009 relate to the protection of the steering information being sent to the UE 501 from the HPLMN UDM 504. To do this, the HPLMN UDM requests that the HPLMN AUSF provides a security service to the HPLMN UDM that causes the steering information from being read by the VPLMN. Stated differently, 5008 to 5009 relate to protecting the Steering Information List from being tampered with or removed by the VPLMN.
[0155] During 5008, the HPLMN UDM 504 signals the HPLMN AUSF 503. The HPLMN AUSF 503 may be selected by the HPLMN UDM 504 based on a determination performed by the HPLMN UDM 504 that the HPLMN AUSF 503 is currently storing an authentication key for the UE 501 . This signalling may comprise a request to obtain security information (such as an encryption key) for encrypting communications for signalling steering information to the terminal. This signalling may be performed as part of an Nausf_SoRProtection service operation. The signalling of 5008 may comprise a subscriber identifier of the UE 501 (e.g., a subscription permanent identifier (SUPI)). The signalling of 5008 may comprise a steering information list.
[0156] The signalling of 5008 may comprise an indication that the UE 501 will be requested to provide an acknowledgement signal to the steering information provided to be provided to the UE 501 from the HPLMN UDM 504. Stated differently, the HPLMN UDM may be configured to determine that the UE is to acknowledge the successful receipt of the steering information list, of the received Steering of Roaming Information, then the HPLMN UDM accordingly sets an “ACK” Indication (labelled as an expected “SoR-XMAC-IUE” indication in 3GPP) in the Nausf_SoRProtection service operation message to signal that the HPLMN UDM is requesting security protection for the steering information list from the VPLMN.
[0157] During 5009, the HPLMN AUSF 503 signals the HPLMN UDM 504. This signalling may comprise a response to the signalling of 5008. This signalling may comprise an Nausf_SoRProtection Response service operation. This signalling may comprise a CounterSOR that is maintained for the lifetime of an authentication key(KAUSF) that is used for authentication processes between the UE 501 and the network. CounterSOR is intialised when KAUSF is stored, and used for deriving SOR-MAC-IUE at the UE for SoR signalling acknowledgement (as described further below). This signalling may comprise an SoR-XMAC-IUE value that has been encrypted using SoR-MAC-IAUSF methods.
[0158] During 5010, the HPLMN UDM 504 signals the VPLMN 502. This signalling may comprise the response comprised in the signalling of 5009. For example, the signalling may comprise at least one of the SoR-MAC-IAUSF, or the counterSOR. The signalling may comprise an indication that an acknowledgement to the SoR-MAC- IAUSF is requested from UE 501. The signalling of 5010 may comprise the steering list. The steering list may comprise an identification of the decommissioned RATs. The signalling of 5010 may comprise an Nudm_SDM_GET_Response service operation.
[0159] Stated differently, the signalling of 5010 may comprise an SoR transparent container with the “decommissioned RATs information”, SoR-MAC-IAUSF, and CounterSoR within the Access and Mobility Subscription data. When the UDM requests an acknowledgement for this signalling in 5010, the UDM temporarily stores the expected SoR-XMAC-IUE corresponding to the SoR-MAC-IAUSF. For example, an SoR transparent contained (currently defined in Figure 9.11.3.51.2A of TS 23.502) may comprise a “PLMN ID and access technology list” field. This “PLMN ID and access technology list” field may be modified relative to current such fields to comprise information identifying at least one decommissioned RAT. Such a modified PLMN ID and access technology list field is illustrated in Figure 6.
[0160] As an alternative to identifying the decommissioned RATs in the signalling of 5010, the signalling may comprise individual information elements comprising a list of preferred PLMN and access technology pair combinations or secured packet (if provided), SoR-MAC-IAUSF and CounterSoR within the Access and Mobility Subscription data.
[0161] During 5011 , the VPLMN AMF 502 signals the UE 501. This signalling may comprise a registration accept message. This signalling may comprise a steering on roaming (SoR) header. This signalling may comprise the steering list comprising the “decommissioned RATs information”, SoR-MAC-IAUSF, and CounterSoR within the Access and Mobility Subscription data.
[0162] Stated differently, when the SoR transparent container is received from the UDM during 5010, the VPLMN AMF includes the received SoR transparent containerin the Registration Accept message that the VPLMN AMF sends to the UE 501 . When the list of preferred PLMN and access technology pair combinations are received from the UDM instead of the identification of the decommissioned RATs, the VPLMN AMF may construct the SOR header based on the ACK Indication and the list of preferred PLMN / access technology combinations with the “decommissioned RATs information” or secured packet (if provided) received from the UDM and include it in the SOR transparent container. The vPLMN shall also include SoR-MAC-IAUSF and CounterSoR (both also received from the UDM) in the constructed SoR transparent container, and conveys the constructed SoR transparent container to the UE in a Registration Accept message.
[0163] The purpose of the SOR transparent container information element in the REGISTRATION ACCEPT message is to provide the list of preferred PLMN / access technology combinations (or HPLMN indication that 'no change of the "Operator Controlled PLMN Selector with Access Technology" list stored in the UE is needed and thus no list of preferred PLMN / access technology combinations is provided'), or a secured packet (see 3GPP TS 23.122 annex C) and optional indication of an acknowledgement request, SOR-CMCI, request the storage of the received SOR- CMCI in the ME, and SOR-SNPN-SI (or subscribed SNPN or HPLMN indication that 'no change of the SOR-SNPN-SI stored in the UE is needed and thus no SOR-SNPN- SI is provided'). The purpose of the SOR transparent container information element in the REGISTRATION COMPLETE message is to indicate to the UE that acknowledgement of successful reception of the SOR transparent container information element in the REGISTRATION ACCEPT message is requested, as well as to indicate the mobile equipment support of SOR-CMCI and the mobile equipment support of SOR-SNPN-SI.
[0164] When used in NAS transport procedures, the contents of the SOR transparent container information element are comprised in the payload container information element of a downlink NAS TRANSPORT message, and are used to provide the list of preferred PLMN / access technology combinations and an optional indication of an acknowledgement request, SOR-CMCI, request the storage of the received SOR- CMCI in the ME, and SOR-SNPN-SI. The contents of the SOR transparent container information element in the Payload container IE of the UL NAS TRANSPORT message are used to indicate the UE acknowledgement of successful reception of the SORtransparent container IE in the DL NAS TRANSPORT message as well as to indicate the ME support of SOR-CMCI and the ME support of SOR-SNPN-SI.
[0165] During 5012, on receiving the Registration Accept message with the SoR transparent container from the AMF during 5011 , the UE calculates a “SoR-MAC- IAUSF” value in the same way as the AUSF (as specified in Annex A.17 of TS 33.501 ) on the SoR transparent container, including the CounterSoR and the SoR header, and verifies whether the calculated SoR-MAC-IAUSF matches the SoR-MAC-IAUSF value received in the Registration Accept message. Based on the SoR-MAC-IAUSF verification outcome, the behaviour of the UE is specified in TS 23.122. The received “decommissioned RATs information” is stored at the UE (e.g., at the universal subscriber identity module (USIM) and / or at the Mobile Equipment(ME)).
[0166] As in the present example the UDM has requested an acknowledgement from the UE and the UE verified that the SoR transparent container received during 5012 has been provided by the HPLMN, then during 5013 the UE 501 sends a Registration Complete message to the PLMN AMF 502. In more detail, the UE 501 generates an SoR-MAC-IUE (as specified in Annex A.18) and includes the generated SoR-MAC- IUE in a SOR transparent container in the Registration Complete message that is sent to the VPLMN AMF 502.
[0167] During 5014, the VPLMN AMF 502 signals the HPLMN UDM 503. This signalling may comprise an Nudm_SDM_lnfo request message to the UDM. When a transparent container comprising the SoR-MAC-IUE was received in the Registration Complete message and the VPLMN AMF 502 supports SoR transparent container, the VPLMN AMF 502 includes the received SoR transparent container of 5013 in an SoR transparent container in the Nudm_SDM_lnfo request message. When the VPLMN AMF 502 does not support SoR transparent container, the VPLMN AMF 502 comprises the received SoR-MAC-IUE in the received SoR transparent container in the Nudm_SDM_lnfo request message.
[0168] During 5015, the HPLMN UDM 504 compares the received SoR-MAC-IUE in the signalling of 5014 with the expected SoR-XMAC-IUE that the UDM stored temporarily during 5010.
[0169] As mentioned above, SoR service operations are only one example of how decommissioned RAT information may be signalled to a UE using protected signalling. Another example way of signalling decommissioned RAT information is to use userparameter update service operations, such as defined in 3GPP TS 33.501 , section 6.15 (where SoR service operations are further described in TS 33.501 Section 6.14).
[0170] At least some of the above-mentioned examples are illustrated below with reference to Figures 7 to 11. It is therefore understood that the above may provide non-limiting examples for how the following described features may be implemented in example systems. It is further understood that the above examples may provide context for understanding how certain features described below may be implemented in example systems.
[0171] Figures 7 to 8 illustrate a first example of apparatus that may communicate with each other.
[0172] Figure 7 illustrates operations that may be performed by an apparatus for a user equipment. The user equipment may be as described above with reference to Figure 3.
[0173] During 701 , the apparatus receives, from a core network function of a core network via a first access network node of a first network, an identification of at least one radio access technology not supported by the core network. The core network function may comprise the core network function of Figure 8.
[0174] During 702, the apparatus uses the received identification for selecting an access network node for connecting to the core network.
[0175] As mentioned above, the apparatus may use various methods for determining a current radio access technology of an access network node (e.g., the first access node or another network node). These may include, for example, receiving system information blocks and / or master information blocks broadcast by access network nodes indicating RAT parameters of the broadcasting access network node, and / or receiving information from an access network node indicating (e.g., identifying) RAT parameters of at least one neighbouring access network node. The apparatus may use the received RAT parameters for determining a corresponding RAT deployed for an access network node.
[0176] The selecting an access network node in 702 may comprise selecting the first access network node, or another network node.
[0177] For example, when the first access network node is a "good" access network node, the selecting an access node during 702 may correspond to determining to continue with the first (e.g., the "good") access network node.
[0178] Stated differently, the using the received identification for selecting an access network node for connecting to the core network may comprise: determining that the first network is not providing connectivity services to the core access network using the identified at least one radio access technology; and maintaining connectivity to the core network via the first access network node.
[0079] Further, when the first access network node is a "false" access network node the selecting an access node during 702 may correspond to releasing a current RRC connection with the first access node, and selecting another access network node for connecting to the core network (e.g., using the received identification to select the another access network node by excluding those access network nodes that deploy at least one of said at least one radio access technologies not supported by the core network).
[0180] Stated differently, the using the received identification for selecting an access network node for connecting to the core network may comprise: determining that the first network is providing connectivity services to the core access network using the identified at least one radio access technology; and switching (e.g., performing a mobility operation, such as handover) from the first access network node to a second access network node for connecting to the core network, wherein the first and second access network nodes are different access network nodes. The apparatus may select the second access network node for connecting to the core network based on a determination that the second access network node is operating in accordance with a radio access technology that was not identified in the received identification from the core network function. Further, the switching may comprise: releasing a radio resource connection with the first access network node; and establishing a radio resource connection with the second access network node.
[0181] For both of these examples, the UE may perform a new selection operation based on the signalled decommissioned RAT information received during 701 (e.g., using a UE’s updated priority list, as described above).
[0182] Stated differently, the apparatus may determine to switch from a current access network node to another access network node for connecting to the core network; and use the received identification to select the another network node.
[0183] In all of the above examples, the receiving the identification may comprise receiving the identification via signalling that is confidentiality protected (e.g.,(cyphered or unreadable) and integrity protected (e.g., unmodifiable) by the first access network node.
[0184] In all of the above examples, the receiving the identification may comprise receiving the identification via non-access stratum signalling. The non-access stratum signalling may comprise an SoR service operation and / or a user parameter update service operation.
[0185] As described above, the UE may further receive a redirection request from a third access network node for causing the UE to signal the core network through the third access network node instead of through a current access network node. The UE may be able to ignore this redirection request when the UE determines that the third access network node is operating using a radio access technology corresponding to one of the identified radio access technologies of 701 . When it is determined that the third access network node is not operating using a radio access technology corresponding to the identified radio access technologies of 701 , the UE may obey the redirection (e.g., be caused to signal the core network through the third access network node instead of through the current access network node).
[0186] Stated differently, the UE may receive, from a third access network node, an indication to connect to the core network through the third access network node; and determining whether to connect to the core network through the third network node based on the received identification and a determined radio access technology provided by the third access network node.
[0187] Figure 8 illustrates operations that may be performed by an apparatus for a core network function. The core network function may comprise, for example an access and mobility management function and / or a unified data management function, and / or some other core network function. The core network function may correspond to the core network function of Figure 7. The functionality of the apparatus of the core network function may be caused by apparatus described in relation to Figure 2.
[0188] During 801 , the apparatus transmits, to a user equipment via a first access network node, an identification of at least one radio access technology not supported by the core network. The user equipment may correspond to the user equipment of Figure 7.
[0189] The transmitting the identification may comprise transmitting the identification via signalling that is confidentiality protected and integrity protected by the first access network node.
[0190] The transmitting the identification may comprise transmitting the identification via non-access stratum signalling.
[0191] In any (e.g., all and / or either) of the examples of Figures 7 and 8, the identification may be comprised in a registration response message.
[0192] In any (e.g., all and / or either) of the examples of Figures 7 and 8, the identification may be comprised in a signalling of a steering on roaming service operation and / or in signalling of a user parameter update service operation.
[0193] In any (e.g., all and / or either) of the examples of Figures 7 and 8, the identified radio access technology may comprise at least one of: 2G, 3G, 4G and / or 5G.
[0194] In any (e.g., all and / or either) of the examples of Figures 7 and 8, the identification of at least one radio access technology not supported by the core network may identify at least one radio access technology having a security mechanism that is not compliant with a security mechanism of the core network. A network operator may have configured identifiers of the at least one radio access technology that identifies said at least one radio access technology.
[0195] In any (e.g., all and / or either) of the examples of Figures 7 and 8, the core network function may comprise a core network function of at least one of a home public land mobile network or a visited public land mobile network.
[0196] Figures 9 to 11 illustrate a second example of interacting apparatus.
[0197] Figure 9 illustrates operations that may be performed by illustrates operations that may be performed by an apparatus for a user equipment. The user equipment may be as described above with reference to Figure 3.
[0198] During 901 , the apparatus receives, from an access and mobility management function of a visited core network via a first access network node of a first network, an identification of at least one radio access technology not supported by a home core network. The access and mobility management function may correspond to the access and mobility management function described below in relation to Figure 11.
[0199] During 902, the apparatus uses the received identification for selecting an access network node for connecting to at least one of the visited core network or home core network.
[0200] As mentioned above, the apparatus may use various methods for determining a current radio access technology of an access network node (e.g., the first access node or another network node). These may include, for example, receiving system information blocks and / or master information blocks broadcast by access networknodes indicating RAT parameters of the broadcasting access network node, and / or receiving information from an access network node indicating (e.g., identifying) RAT parameters of at least one neighbouring access network node. The apparatus may use the received RAT parameters for determining a corresponding RAT deployed for an access network node.
[0201] The receiving the identification may comprise receiving the identification via a registration accept message.
[0202] The selecting an access network node in 902 may comprise selecting the first access network node, or another network node.
[0203] For example, when the first access network node is a "good" access network node, the selecting an access node during 702 may correspond to determining to continue with the first (e.g., the "good") access network node.
[0204] Stated differently, the using the received identification for selecting an access network node for connecting to the core network may comprise: determining that the first network is not providing connectivity services to the visited core access network using the identified at least one radio access technology; and maintaining connectivity to the visited core network via the first access network node.
[0205] Further, when the first access network node is a "false" access network node the selecting an access node during 702 may correspond to releasing a current RRC connection with the first access node, and selecting another access network node for connecting to the core network (e.g., using the received identification to select the another access network node by excluding those access network nodes that deploy at least one of said at least one radio access technologies not supported by the core network).
[0206] Stated differently, the using the received identification for selecting an access network node for connecting to the core network may comprise: determining that the first network is providing connectivity services to the visited core access network using the identified at least one radio access technology; and switching (e.g., performing a mobility operation, such as handover) from the first access network node to a second access network node for connecting to the visited core network, wherein the first and second access network nodes are different access network nodes. The apparatus may select the second access network node for connecting to the visited core network based on a determination that the second access network node is operating in accordance with a radio access technology that was not identified in the receivedidentification from the core network function. Further, the switching may comprise: releasing a radio resource connection with the first access network node; and establishing a radio resource connection with the second access network node.
[0207] For both of these examples, the UE may perform a new selection operation based on the signalled decommissioned RAT information received during 701 (e.g., using a UE’s updated priority list, as described above).
[0208] Stated differently, the apparatus may determine to switch from a current access network node to another access network node for connecting to the core network; and use the received identification to select the another network node.
[0209] In all of the above examples, the receiving the identification may comprise receiving the identification via signalling that is confidentiality protected (e.g., (cyphered or unreadable) and integrity protected (e.g., unmodifiable) by the first access network node.
[0210] In all of the above examples, the receiving the identification may comprise receiving the identification via non-access stratum signalling. The non-access stratum signalling may comprise an SoR service operation and / or a user parameter update service operation.
[0211] As described above, the UE may further receive a redirection request from a third access network node for causing the UE to signal the core network through the third access network node instead of through a current access network node. The UE may be able to ignore this redirection request when the UE determines that the third access network node is operating using a radio access technology corresponding to one of the identified radio access technologies of 701 . When it is determined that the third access network node is not operating using a radio access technology corresponding to the identified radio access technologies of 701 , the UE may obey the redirection (e.g., be caused to signal the core network through the third access network node instead of through the current access network node).
[0212] Stated differently, the UE may receive, from a third access network node, an indication to connect to the core network through the third access network node; and determining whether to connect to the visited core network (or to another core network) through the third network node based on the received identification and a determined radio access technology provided by the third access network node.
[0213] Figure 10 illustrates operations that may be performed by an apparatus for a unified data management function of a home core network function. The unified datamanagement function may be the unified data management function described below in relation to Figure 11 . The functionality of the apparatus of the UDM may be caused by apparatus described in relation to Figure 2.
[0214] During 1001 , the apparatus transmits, to a user equipment via an access and mobility management function of a visited core network, an identification of at least one radio access technology not supported by the home core network. The user equipment may correspond to the user equipment of Figure 9. The access and mobility management function may correspond to the access and mobility management function of Figure 11 .
[0215] The transmitting the identification may comprise transmitting the identification via signalling that is confidentiality protected and integrity protected by an access network node.
[0216] The transmitting the identification may comprise transmitting the identification via non-access stratum signalling.
[0217] Figure 11 illustrates operations that may be performed by an apparatus of an access and mobility function of a visited core network. The AMF of Figure 11 may correspond to the AMF of Figure 9 and / or Figure 10. The functionality of the apparatus of the AMF may be caused by apparatus described in relation to Figure 2.
[0218] During 1101 , the apparatus receives, from a unified data management of a home core network (e.g., from the apparatus of Figure 10), an identification of at least one radio access technology that is not supported by the home core network.
[0219] During 1102, the apparatus may transmit, to a user equipment (e.g., the user equipment of Figure 9) via a first access network node, the received identification.
[0220] The transmitting the identification may comprise transmitting the identification via signalling that is confidentiality protected and integrity protected by the first access network node.
[0221] The transmitting the identification may comprise transmitting the identification via non-access stratum signalling.
[0222] In any (e.g., all and / or either) of the examples of Figures 9 to 11 , the identification may be comprised in a registration response message.
[0223] In any (e.g., all and / or either) of the examples of Figures 9 to 11 , the identification may be comprised in a signalling of a steering on roaming service operation and / or in signalling of a user parameter update service operation.
[0224] In any (e.g., all and / or either) of the examples of Figures 9 to 11 , the identified radio access technology may comprise at least one of: 2G, 3G, 4G and / or 5G.
[0225] In any (e.g., all and / or either) of the examples of Figures 9 to 11 , the identification of at least one radio access technology not supported by the core network may identify at least one radio access technology having a security mechanism that is not compliant with a security mechanism of the core network. A network operator may have configured identifiers of the at least one radio access technology that identifies said at least one radio access technology.
[0226] It should be understood that the apparatuses may comprise or be coupled to other units or modules etc., such as radio parts or radio heads, used in or for transmission and / or reception. Although the apparatuses have been described as one entity, different modules and memory may be implemented in one or more physical or logical entities.
[0227] It is noted that whilst some embodiments have been described in relation to 5G networks, similar principles can be applied in relation to other networks and communication systems. Therefore, although certain embodiments were described above by way of example with reference to certain example architectures for wireless networks, technologies and standards, embodiments may be applied to any other suitable forms of communication systems than those illustrated and described herein. In particular, an as mentioned above, is understood in the following that, where references are made to 5G alone, that this is not limited to only 5G. Instead, these references may comprise 5G and / or beyond 5G. For example, it is understood that references to 5G networks, and / or 5G network entities comprises references to 6G networks, and / or 6G network entities.
[0228] It is also noted herein that while the above describes example embodiments, there are several variations and modifications which may be made to the disclosed solution without departing from the scope of the present invention.
[0229] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0230] In general, the various embodiments may be implemented in hardware or special purpose circuitry, software, logic or any combination thereof. Some aspects of the disclosure may be implemented in hardware, while other aspects may beimplemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although the disclosure is not limited thereto. While various aspects of the disclosure may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
[0231] As used in this application, the term “circuitry” may refer to one or more or all of the following:(a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and(b) combinations of hardware circuits and software, such as (as applicable):(c) a combination of analog and / or digital hardware circuit(s) with software / firmware and(d) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and(e) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[0232] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0233] The embodiments of this disclosure may be implemented by computer software executable by a data processor of the mobile device, such as in the processor entity, or by hardware, or by a combination of software and hardware. Computer software orprogram, also called program product, including software routines, applets and / or macros, may be stored in any apparatus-readable data storage medium and they comprise program instructions to perform particular tasks. A computer program product may comprise one or more computer-executable components which, when the program is run, are configured to carry out embodiments. The one or more computer-executable components may be at least one software code or portions of it.
[0234] Further in this regard it should be noted that any blocks of the logic flow as in the Figures may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. The software may be stored on such physical media as memory chips, or memory blocks implemented within the processor, magnetic media such as hard disk or floppy disks, and optical media such as for example DVD and the data variants thereof, CD. The physical media is a non-transitory media.
[0235] The term “non-transitory,” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal ) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).
[0236] The memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The data processors may be of any type suitable to the local technical environment, and may comprise one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), application specific integrated circuits (ASIC), FPGA, gate level circuits and processors based on multi core processor architecture, as non-limiting examples.
[0237] Embodiments of the disclosure may be practiced in various components such as integrated circuit modules. The design of integrated circuits is by and large a highly automated process. Complex and powerful software tools are available for converting a logic level design into a semiconductor circuit design ready to be etched and formed on a semiconductor substrate.
[0238] The scope of protection sought for various embodiments of the disclosure is set out by the independent claims. The embodiments and features, if any, described in this specification that do not fall under the scope of the independent claims are to beinterpreted as examples useful for understanding various embodiments of the disclosure.
[0239] The foregoing description has provided by way of non-limiting examples a full and informative description of the exemplary embodiment of this disclosure. However, various modifications and adaptations may become apparent to those skilled in the relevant arts in view of the foregoing description, when read in conjunction with the accompanying drawings and the appended claims. However, all such and similar modifications of the teachings of this disclosure will still fall within the scope of this invention as defined in the appended claims. Indeed, there is a further embodiment comprising a combination of one or more embodiments with any of the other embodiments previously discussed.
Claims
CLAIMS1 ) An apparatus for a user equipment, the apparatus comprising means for performing: receiving, from a core network function of a core network via a first access network node of a first network, an identification of at least one radio access technology not supported by the core network; and using the received identification for selecting an access network node for connecting to the core network.2) An apparatus as claimed in claim 1 , wherein the means for receiving the identification comprises means for receiving the identification via signalling that is confidentiality protected and integrity protected by the first access network node.3) An apparatus as claimed in any preceding claim, wherein the means for receiving the identification comprises means for receiving the identification via non-access stratum signalling.4) An apparatus as claimed in any preceding claim, wherein the means for using the received identification for selecting an access network node for connecting to the core network comprises means for: determining that the first network is not providing connectivity services to the core access network using the identified at least one radio access technology; and maintaining connectivity to the core network via the first access network node.5) An apparatus as claimed in any preceding claim, wherein the means for using the received identification for selecting an access network node for connecting to the core network comprises means for:determining that the first network is providing connectivity services to the core access network using the identified at least one radio access technology; and switching from the first access network node to a second access network node for connecting to the core network, wherein the first and second access network nodes are different access network nodes.6) An apparatus as claimed in claim 5, the apparatus further comprising means for performing: selecting the second access network node for connecting to the core network based on a determination that the second access network node is operating in accordance with a radio access technology that was not identified in the received identification from the core network function.7) An apparatus as claimed in any of claims 5 to 6, wherein the means for switching comprises means for: releasing a radio resource connection with the first access network node; and establishing a radio resource connection with the second access network node.8) An apparatus as claimed in any preceding claim, further comprising means for performing: receiving, from a third access network node, an indication to connect to the core network through the third access network node; and determining whether to connect to the core network through the third access network node based on the received identification and a determined radio access technology provided by the third access network node.9) An apparatus as claimed in any preceding claim, further comprising means for performing: determining to switch from a current access network node to another access network node for connecting to the core network; and using the received identification to select the another network node.10)An apparatus for a core network function, the apparatus comprising means for performing: transmitting, to a user equipment via a first access network node, an identification of at least one radio access technology not supported by the core network.11 )An apparatus as claimed in claim 10, wherein the means for transmitting the identification comprises means for transmitting the identification via signalling that is confidentiality protected and integrity protected by the first access network node.12)An apparatus as claimed in any of claims 10 to 11 , wherein the means for transmitting the identification comprises means for transmitting the identification via non-access stratum signalling.13)An apparatus as claimed in any preceding claim, wherein the identification is comprised in a registration response message.14)An apparatus as claimed in any preceding claim, wherein the identification is comprised in a signalling of a steering on roaming service operation and / or in signalling of a user parameter update service operation.15)An apparatus as claimed in any preceding claim, wherein the identified radio access technology comprises at least one of: 2G, 3G, 4G and / or 5G.)An apparatus as claimed in any preceding claim, wherein the identification of at least one radio access technology not supported by the core network identifies at least one radio access technology having a security mechanism that is not compliant with a security mechanism of the core network. )An apparatus as claimed in any preceding claim, wherein the core network function comprises a core network function of at least one of a home public land mobile network or a visited public land mobile network. )A method for an apparatus for a user equipment, the method comprising: receiving, from a core network function of a core network via a first access network node of a first network, an identification of at least one radio access technology not supported by the core network; and using the received identification for selecting an access network node for connecting to the core network. )A method for an apparatus for a core network function, the method comprising: transmitting, to a user equipment via a first access network node, an identification of at least one radio access technology not supported by the core network. )A computer program comprising instructions which, when the program is executed by a computer of a user equipment, cause the computer to carry out comprising: receiving, from a core network function of a core network via a first access network node of a first network, an identification of at least one radio access technology not supported by the core network; and using the received identification for selecting an access network node for connecting to the core network.)A computer program comprising instructions which, when the program is executed by a computer of a core network function, cause the computer to carry out: transmitting, to a user equipment via a first access network node, an identification of at least one radio access technology not supported by the core network.
Citation Information
Patent Citations
Method and apparatus for roaming restrictions of forbidden radio access networks in a wireless system
US20140038592A1
Slice-aware PLMN selection
US20210282084A1
Radio-access-technology-specific access restrictions
US20220194493A1