User equipment location reporting via non-access stratum signaling

NB-IoT UEs in non-terrestrial networks use NAS signaling for secure and accurate location reporting, addressing privacy and accuracy issues, thereby improving radio resource management and regulatory compliance.

WO2025178696A1PCT designated stage Publication Date: 2025-08-28APPLE INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/US2025/011765
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-19
Filing Date
2025-01-16
Publication Date
2025-08-28

AI Technical Summary

Technical Problem

Current wireless communication networks lack secure and accurate UE location reporting mechanisms for NB-IoT devices in non-terrestrial networks, which impacts radio resource management and mobility management efficiency due to privacy concerns and low location estimation accuracy.

Method used

UEs report their location using Non-Access Stratum (NAS) signaling, with security activated, by transmitting UE capability information and location reports through messages like the security mode complete message, TAU request, and other control plane messages, ensuring privacy and improved location accuracy.

Benefits of technology

Enhances UE location reporting accuracy and security, enabling efficient radio resource management and compliance with regulatory standards in NB-IoT NTN UEs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2025011765_28082025_PF_FP_ABST
    Figure US2025011765_28082025_PF_FP_ABST
Patent Text Reader

Abstract

Techniques described herein include solutions for User Equipment (UE) location reporting via non-access stratum (NAS) signaling. A UE may transmit UE capability information indicating a capability of the UE to report its location via NAS signaling. Subsequently, the UE may receive a security mode command message to establish NAS signaling security, where the security mode command message includes a request for the location of the UE. In response to the request, the UE may transmit a message indicating the location of the UE.
Need to check novelty before this filing date? Find Prior Art

Description

USER EQUIPMENT LOCATION REPORTING VIA NON-ACCESS STRATUM SIGNALINGREFERENCE TO RELATED APPLICATIONS

[0001] This Application claims the benefit of U.S. Provisional Application No. 63 / 555,126 filed on February 19, 2024, the contents of which are hereby incorporated by reference in their entirety.FIELD

[0002] This disclosure relates to wireless communication networks including techniques for reporting user equipment (UE) location within wireless networks.BACKGROUND

[0003] Wireless communication networks may include user equipments (UEs), base stations, and / or other types of wireless devices capable of communicating with one another. During operation, a UE may report its location to a network, which may be used by the network to manage radio resources.BRIEF DESCRIPTION OF THE DRAWINGS

[0004] The following detailed description refers to the accompanying drawings. Like reference numbers in different drawings may identify the same or similar features, elements, operations, etc. Additionally, the present disclosure is not limited to the following description as other implementations may be utilized, and structural or logical changes made, without departing from the scope of the present disclosure.

[0005] Fig. 1 is a block diagram illustrating a non-terrestrial network (NTN) including a user equipment (UE) configured to perform location reporting using non-access stratum (NAS) signaling in accordance with some aspects of the present disclosure.

[0006] Figs. 2-4 are schematic diagrams illustrating signaling between a UE and a mobility management entity (MME) for UE location reporting in accordance with some aspects of the present disclosure.

[0007] Fig. 5 is a schematic diagram illustrating a UE location request information element (IE) in accordance with some aspects of the present disclosure.

[0008] Fig. 6 is a schematic diagram illustrating a UE location IE in accordance with some aspects of the present disclosure.

[0009] Fig. 7 is a process flow for a UE to report its location in accordance with some aspects of the present disclosure.

[0010] Fig. 8 is a process flow for a base station to receive location reporting from a UE in accordance with some aspects of the present disclosure.

[0011] Fig. 9 is a block diagram illustrating a wireless network including a UE configured to perform location reporting using NAS signaling in accordance with some aspects of the present disclosure.

[0012] Fig. 10 is a block diagram illustrating a device that can be employed to perform UE location reporting in accordance with some aspects of the present disclosure.

[0013] Fig. 11 is a block diagram illustrating baseband circuitry that can be employed to perform UE location reporting in accordance with some aspects of the present disclosure.DETAILED DESCRIPTION

[0014] The following detailed description refers to the accompanying drawings. Like reference numbers in different drawings may identify the same or similar features, elements, operations, etc. Additionally, the present disclosure is not limited to the following description as other implementations may be utilized, and structural or logical changes made, without departing from the scope of the present disclosure.

[0015] A user equipment (UE) may be configured to communicate using various communication schemes optimized for different use cases. One development of wireless communication is towards machine type communications (MTC) providing limited bandwidth and low data rate service to simple and / or cheap devices with very low power budgets. For example, the Third Generation Partnership Project (3GPP) standardized two different approaches of this kind: enhanced MTC (eMTC) and narrowband Internet of Things (NB-IoT). The latter more aggressively addresses the extremely low cost market with less than 200 KHZ of spectrum. Both eMTC and NB-IoT are optimized for lower complexity / power, deeper coverage, and higher device density, while seamlessly coexisting with regular mobile broadband.

[0016] Meanwhile, the focus on non-terrestrial networks (NTN) is growing. NTN refer to networks, or segments of networks, using an airborne or spaceborne vehicle for transmission. NTN enables delivering services in areas lacking network infrastructure or availability like during natural disasters. Satellite links can provide coverage for isolated or moving platforms such as aircrafts, ships, oil platforms, and trains, and support MTC communications discussed above.

[0017] A NTN may utilize a location of a UE when communicating with the UE for purposes such as following regulatory compliance, radio resource management (RRM), mobility management, etc. For example, depending on a jurisdiction the UE is located in, the network may follow different regulations when communicating with the UE. For RRM, the network may utilize knowledge of the distribution (e.g., location) of UEs within the network to efficiently allocate radio resources across the UEs. The UE location may also be used for mobility management, for example, when determining when to perform handover procedures, etc.

[0018] Communication schemes such as eMTC utilize access stratum (AS) signaling to report UE location. However, NB-IoT UEs are not required to have established AS security during operation. For example, an NB-IoT UE may transmit small amounts of data directly over the control plane, without the use of AS security. When considering AS based UE location reporting, the lack of AS security in NB-IoT poses a risk to user privacy. Currently, UE location reporting is not specified for NB-IoT NTN UEs. In order to provide efficient RRM and mobility management for NB-IoT NTN UEs and follow regulatory standards, enabling secure location reporting for such UEs is desired.

[0019] Accordingly, the present disclosure provides techniques for reporting UE location via non-access stratum (NAS) signaling. In some aspects, a UE transmits UE capability information to a network (e.g., via a base station) indicating a capability of the UE to report its location via NAS signaling. Then, the network transmits a UE location request to the UE based on the UE capability information. In response to the UE location request, the UE transmits a UE location report to the network indicating the location of the UE. The UE location report may be transmitted using NAS layer signaling, with NAS security activated. For example, the UE location report is included in a security mode complete message. The UE may also transmit one or more additional messages to the network to provide the UEs updated location (e.g., when the UE has moved), such as a tracking area update (TAU) request message, an extended service request message, a control plane service request message, or a packet data network (PDN) connectivity request message.

[0020] Fig. 1 illustrates an example NTN 100 including a UE 101 configured to perform location reporting. The UE 101 may be configured to communicate with a non-terrestrial base station 130-1 and / or a core network (CN) 120, for example, using NAS signaling.

[0021] In some aspects, the UE 101 is configured to communicate using NB-IoT within the NTN 100 (e.g., communicate with the non-terrestrial base station 130-1). In some examples, the non-terrestrial base station 130-1 comprises a satellite, which is configured tocommunicate with the UEs 101 using wide beams. For example, the beams may be in the range of hundreds of kilometers (kms). In such examples, the location of the UE 101 may be estimated using the beams, but with low accuracy due to the wide beam size.

[0022] The network may utilize a UEs location for RRM, such as mapping the UE to a cell (e.g., geographical area), determining which frequencies to use in the cell, etc. Furthermore, the network may utilize knowledge of the locations (e.g., UE distribution) of the UEs 101 when allocating radio resources. The low accuracy of the UE location estimation due to the wide beam size negatively impacts RRM efficiency. Similarly, mobility management efficiency is negatively impacted. In scenarios where NTN cell coverage overlaps two regulatory areas (e.g., cross-country borders), the poor UE location accuracy may be insufficient for the network to determine which regulations (e.g., between countries) to follow when communicating with the UE. To increase the accuracy of the UEs location that is known by the network, UE location reporting can be used.

[0023] Accordingly, in some aspects, the UE 101 is configured to report its location to the CN 120 (e.g., via the non-terrestrial base station 130-1). For example, the UE 101 reports its location to the CN 120 using NAS signaling. The UE 101 may determine its location using a Global Navigation Satellite System (GNSS) or the like. For example, the GNSS may include the non-terrestrial base stations 130-1, or other satellites (not shown). In the illustrated example, the UE 101 transmits UE capability information to the CN 120 via the non-terrestrial base station 130-1. For example, the non-terrestrial base station 130-1 acts as an intermediate entity, forwarding signals between the UE 101 and the CN 120. The UE capability information indicates whether the UE is capable of reporting its location via NAS signaling. Then, the CN 120 transmits (e.g., via non-terrestrial base station 130-1) a UE location request to the UE 101. In response to the UE location request, the UE 101 transmits a UE location report to the CN 120 (e.g., via non-terrestrial base station 130-1) indicating the UEs location. The CN 120 may comprise a mobility management function (e.g., a mobility management entity (MME)) used to manage mobility functions of the UE 101 including handover, etc. Further details are described below with reference to the following figures.

[0024] Figs. 2-4 illustrates various examples of signaling between the UE 101 and the MME 122 for reporting a location of the UE 101. Alternatively, the signaling may be exchanged between the UE 101 and the non-terrestrial base station 130-1. For example, the non- terrestrial base station 130-1 may forward signaling between the UE 101 and the MME 122. With reference to following figures, the signaling will generally be described as occurring between the UE 101 and the MME 122 to simplify description. However, it will beunderstood that similar signaling between the UE 101 and the non- terrestrial base station may also occur, where the non-terrestrial base station 130-1 acts as an intermediate entity by relaying signals between the UE 101 and the MME 122.

[0025] In some aspects, some or all of the signaling of Fig. 2 is transmitted as NAS layer signaling. By using NAS signaling for UE location reporting, the UE location reporting can be performed by UEs with support for control plane (CP) cellular internet of things (CIoT) evolved packet system (EPS) optimization only. For example, CP CIoT EPS optimized UEs may transmit data over the CP without the use of AS security.

[0026] In the example of Fig. 2, at act 202, the UE 101 transmits UE capability information to the MME 122 (e.g., via non-terrestrial base station 130-1). The UE capability information indicates whether the UE is capable of reporting its location to the MME 122 via NAS signaling. In some examples, the UE capability information is included in a UE network capability information element (IE). For example, the indication whether the UE is capable of reporting its location via NAS signaling includes a 1 -bit indication (e.g., a UE NB-IoT NTN Location Reporting Capability (NNLR) bit) in the UE network capability IE. In some examples, a NNLR bit value of 1 indicates that UE location reporting is supported, and a NNLR bit value of 0 indicates that UE location reporting is not supported. In some examples, the UE network capability IE is a type 4 IE with a minimum length of 4 octets and a maximum length of 15 octets.

[0027] In some aspects, a type 4 IE is in the format of length and value (LV) or type, length, and value (TLV). The length may be indicated by a length indicator (LI) containing one octet. The value part may contain zero, one, or up to 255 octets. In the TLV example, the type may be indicated by an IE identifier (IEI) having one octet length. The LI may precede the value part, and the type (if present) may precede the LI.

[0028] At act 204, the MME 122 determines whether to request the UEs location. For example, the MME 122 determines whether to request the location based on the UE capability information (e.g., based on whether the UE is capable of reporting its location). Additionally or alternatively, the determination may be based on whether security ciphering is configured, and / or a capability of the network to receive / process the location information. For example, if a security cipher is not configured (e.g., null security cipher) the MME 122 may determine to not request the location of the UE, since reporting UE location may raise privacy / security concerns for the user. Therefore, in some examples the MME 122 only determines to request the UEs location if it detects a security cipher other than null.Additionally or alternatively, the MME 122 may determine not to request the location of the UE if the MME 122 is unable to receive and / or process the UE location information.

[0029] At act 206, the MME 122 transmits a UE location request to the UE 101 (e.g., via 130-1), for example, in response to the determination at act 204. In some examples, the UE location request is included in a UE location request IE. For example, the UE location request includes a 1 -bit indication in the UE location request IE.

[0030] At act 208, the UE 101 transmits UE location information to the MME 122 (e.g., via 130-1 ). In some examples, the UE location information is included in a UE location IE, which may include information such as a latitude and a longitude corresponding to the location of the UE. In some aspects, the base station 130-1 and / or the MME 122 forward the UEs location information to an evolved serving mobile location center (E-SMLC), which may process the UE location information. For example, upon receiving the UE location information, the E-SMLC responds with a country code and / or a region code corresponding to the UEs location. The country and / or region codes may be used by the base station 130-1 and / or the MME 122 to serve the UE (e.g., in compliance with local regulations for the country / region the UE is located in).

[0031] In some aspects, the UE location request procedure of Fig. 2 is integrated with a connection establishment (e.g., attach) procedure, as described with reference to Figs. 3-4. For example, the IES from the UE location request procedure are carried by the messages already exchanged during the attach procedure, which allows the UE to efficiently perform location reporting by minimizing the signaling exchanged between the UE 101 and the base station 130-1.

[0032] Fig. 3 illustrates an example variation of the signaling flow of Fig. 2. In the example of Fig. 3, the UE capability information is included in an attach request message, the UE location request is included in a security mode command message, and the UE location information is included in a security mode complete message. For example, such messaging may be part of an attach request procedure for NB-IoT communication.

[0033] At act 302, the UE 101 transmits an attach request message to the MME 122 (e.g., via 130-1). For example, the UE 101 sends the attach request message to the base station 130-1, which may forward the attach request to the MME 122. In some examples, the attach request message is a NAS layer message used by the UE 101 to establish a connection with the MME 122. The attach request message includes UE capability information (e.g., UE network capability IE) indicating the UEs capability to report its location via NAS signaling, for example, as described with reference to Fig. 2.

[0034] At act 304, the MME 122 determines whether to request the UEs location (e.g., similar to act 204). The MME 122 may determine whether to request the UEs location based on one or more of: the UE capability information, a security ciphering configuration, or a capability of the base station 130-1 or the MME 122 to process the UE location information, as previously described. For example, the MME 122 and the UE 101 exchange one or more authentication messages as part of an authentication exchange. Based on the authentication exchange, the MME 122 may determine whether security ciphering is configured.

[0035] At act 306, the MME 122 transmits a security mode command message to the UE 101 (e.g., via 130-1). In some examples, the security mode command message is used to establish NAS signaling security between the UE 101 and the MME 122. Upon receipt of the security mode command message, the UE 101 checks whether the UE can provide a suitable response to this command. For example, the UE 101 determines whether it is capable of providing the level of security specified in the security mode command message. The security mode command message includes the request for the UEs location (e.g., UE location request IE), for example, as described with reference to Fig. 2.

[0036] At act 308, the UE 101 transmits a security mode complete message to the MME 122 (e.g., via 130-1) in response to the security mode command message. In some examples, the security mode complete message is ciphered according to the NAS ciphering algorithm specified by the security mode command message. The security mode complete message includes the UEs location information (e.g., UE location IE), as described with reference to Fig. 2. By first establishing NAS security using the security mode command message, user privacy can be protected when including the UE location information in the security mode complete message.

[0037] The signaling flow illustrated by Fig. 4 resembles the signaling flow of Fig. 3, but differs in that Fig. 4 further includes acts 402 and 404.

[0038] At act 402, the UE 101 makes a determination to provide its updated location to the network. For example, the UE 101 may choose to provide its updated location when it detects that its location has changed since the last location report (e.g., since act 308).

[0039] At act 404, the UE 101 transmits an additional message to the MME 122 (e.g., via 130-1) including the UEs updated location information. Similar to act 308, the UE location information may be included in a UE location IE of the additional message. The additional message may be a message such as a TAU request message, an extended service request message, a control plane service request message, or a PDN connectivity request message. Insome examples, the additional message is ciphered (e.g., according to the established NAS security at act 306) to protect the privacy of the UE 101 when transmitting UE location data.

[0040] In some examples, when the UE 101 determines to provide its updated location at act 402, the updated UE location information is queued for transmission. For example, the determination at act 402 does not cause the UE 101 to immediately provide its updated location, but rather causes the UE 101 to provide its updated location upon transmission of the next candidate message. The candidate message may be one or more of: a TAU request message, an extended service request message, a control plane service request message, or a PDN connectivity request message. In some examples, when the message is a TAU request message, the TAU request message further include the UE network capability IE (e.g., indicating UE capability to report its location via NAS), as described throughout the present disclosure.

[0041] As an example, the UE 101 may periodically transmit a TAU request message to the MME 122 (e.g., via 130-1) according to a TAU timer. At act 402, the UE determines to provide its updated location, and queues the updated location information for transmission. Upon expiration of the TAU timer, the UE transmits a TAU request message to the MME 122 at act 404, which includes the updated UE location information. Alternatively, if the UE were to transmit another candidate message type before expiration of the TAU timer, the UE location information would be included in the other candidate message. For example, the UE could transmit an extended service request (e.g., to initiate circuit switched (CS) fallback), a control plane service request (e.g., when the UE is using EPS services with CIoT EPS optimization), or a PDN connectivity request message (e.g., to establish a PDN connection).

[0042] Thus, the additional message at act 404 may be transmitted by the UE 101 for additional purposes other than reporting the UEs location. For example, if the additional message is a TAU request message, the UE 101 transmits the TAU request message for the purpose of updating its tracking area, which allows the UE to provide its updated location while minimizing the required signaling.

[0043] Acts 402 and 404 may be repeated by the UE to continue providing updated UE location information. For example, the UE 101 may repeat act 402 to determine whether to provide updated location information (e.g., based on whether the UE has moved).

[0044] Fig. 5 illustrates an example of a UE location request IE 500. The UE location request IE 500 may be the UE location request IE as described with reference to Figs. 2-4, and throughout the present disclosure.

[0045] As shown, the UE location request IE 500 may include three octets each comprising 8 bits. In some examples, the UE location request IE 500 is a type 4 IE. A first octet 502 includes a UE NB-IoT NTN location request IEI, which may be used to identify the IE 500. A second octet 504 includes a length of the UE NB-IoT NTN location request contents. In some aspects, a third octet 506 includes the UE NB-IoT NTN location request contents, for example, which includes a UE NB-IoT NTN location request (UNNLR) bit. For example, the IE 500 is in TLV format, where the first octet 502 contains the type, the second octet 504 contains the LI, and the third octet 504 contains the value.

[0046] The UE NB-IoT NTN location request contents (e.g., third octet 506) may include information related to the UE location request. For example, the UE NB-IoT NTN location request contents includes the UNNLR bit, which may be used to indicate a request for the UEs location. In some aspects, a value of 1 indicates that UE location reporting is requested, and a value of 0 indicates that UE location reporting is not requested. As shown, the third octet 506 may further include 7 spare bits. In one aspect, the UNNLR bit is located in bit 1 of the third octet 506. In other aspects, the UNNLR bit may be located in other locations (i.e. , bit 2 to bit 8) of the third octet 506, such as bit 2 to bit 8. The UNNLR may also be indicated in combination with other location request information in multiple combined bits in the third octet 506 or one or more other octets of the UE location request IE 500.

[0047] In some examples, the length of the UE NB-IoT NTN location request contents may be n octets, where n equals to 1, 2, 3, 4, ...., up to 255. Accordingly, in such examples, the UE location request IE 500 may include further octets in addition to the third octet 506.

[0048] In the present examples, the UNNLR bit is included in the UE location request IE 500. However, in alternative examples, the UNNLR may be included in a different IE and function in a similar manner (e.g., communicate a request for the location of an NB-IoT NTN UE).

[0049] Fig. 6 illustrates an example of a UE location IE 600. The UE location IE 600 may be the UE location IE as described with reference to Figs. 2-4 and throughout the present disclosure.

[0050] As shown, the UE location IE 600 may include eight octets each comprising 8 bits. In some examples, the UE location IE 600 is a type 4 IE. A first octet 602 includes a UE coarse location IEI, which may be used to identify the IE 600. A second octet 604 includes a length of the UE coarse location contents. Third-fifth octets 608 are used to indicate the latitude of the UEs location in degrees. Sixth-eighth octets 610 are used to indicate thelongitude of the UEs location in degrees. For example, the IE 600 is in TLV format, where the first octet 602 contains the type, the second octet 604 contains the LI, and the third-eighth octets contain the value.

[0051] In some aspects, a sign of the latitude is indicated by a latitude sign bit 606, where a different bit value (e.g., 0, 1) correspond to “north” or “south”. In the illustrated example, the latitude sign bit 606 is illustrated as the first bit of the third octet, however, alternative

[0052] In some aspects, a second bit of the third octet (e.g., the bit following the latitude sign bit 606) corresponds to a most significant bit of the latitude, and a last bit of the fifth octet corresponds to a least significant bit of the latitude. In some examples, one or more of the least significant bits are set to a value of 0 to achieve a specific location granularity (e.g., 2 kilometers (km)). The number of bits set to a value of 0 to achieve the specific location granularity may depend on UE implementation. A similar methodology may be applied to the longitude, the first bit of the sixth octet being the most significant bit, and the last bit of the eighth octet being the least significant bit.

[0053] Fig. 7 is a process flow for a UE (e.g., UE 101) to report its location in accordance with some aspects of the present disclosure.

[0054] At act 710, the UE transmits (e.g., to an MME via a non-terrestrial base station) UE capability information indicating a capability of the UE to report a location of the UE via NAS signaling. For example, the UE capability information may be transmitted in the form of a UE network capability IE, as previously described. The UE network capability IE may be included, for example, in an attach request message.

[0055] At act 720, the UE receives a security mode command message (e.g., from the non-terrestrial base station / MME) to establish NAS signaling security. The security mode command message includes a request for the location of the UE. For example, the request for the location of the UE may be in the form of a UE location request IE, as previously described.

[0056] At act 730, in response to the request for the location of the UE, the UE transmits a message (e.g., to the non-terrestrial base station / MME) including the location of the UE. For example, the UE determines its location using GNSS or the like. The location of the UE may be included in a UE location IE, as previously described. In one example, the message is a security mode complete message. The UE may also provide updates of its location in one or more additional messages, such as a TAU request message, an extended service request message, a control plane service request message, and / or a PDN connectivity requestmessage, as previously described.

[0057] Fig. 8 is a process flow for an MME to receive location reporting from a UE in accordance with some aspects of the present disclosure. In some examples, the MME communicates with the UE via a base station (e.g., non-terrestrial base station 130-1), as previously described.

[0058] At act 810, the MME receives UE capability information (e.g., from a UE) indicating a capability of the UE to report a location of the UE via NAS signaling. For example, the UE capability information may be in the form of a UE network capability IE, as previously described. The UE network capability IE may be included, for example, in an attach request message.

[0059] At act 820, the MME transmits a security mode command message (e.g., to the UE) to establish NAS signaling security. The security mode command message includes a request for the location of the UE. For example, the request for the location of the UE may be in the form of a UE location request IE, as previously described.

[0060] At act 830, the MME receives a message (e.g., from the UE) including the location of the UE. For example, the location of the UE is included in a UE location IE, as previously described. The message may be a security mode complete message, a TAU request message, an extended service request message, a control plane service request message, and / or a PDN connectivity request message.

[0061] Fig. 9 illustrates an example architecture of a network system 900 in accordance with various aspects. The network system 900 includes a UE 101 , which may represent one or more UEs (referred to collectively as “UEs 101” and individually as “UE 101”). The UE 101 is configured to connect, for example, communicatively couple, with an NTN. As shown, the NTN includes non-terrestrial base stations (e.g., satellites) 130-1, 130-2. The UE 101 may communicate with the non-terrestrial base stations 130-1, 130-2 using connections 932 and 933 for uplink and downlink respectively. The non-terrestrial base stations 130-1, 130-2 may communicate with a radio access network (RAN) 910 using connections 934-1 and 934-2 respectively, and with each other using connection 936 or through the RAN 910 using connections 934-1 and 934-2. The RAN 910 may be part of a terrestrial network (TN) and may comprise one or more terrestrial base stations 911-1, 911-2, which may communicate with the UE using connections 902 and 904 for downlink and uplink respectively. The RAN 910 may be configured to communicate with CN 120. In some aspects, customers may connect through both terrestrial links (e.g., 902, 904) and satellite links (e.g., 932, 933), the terrestrial links handling low-latency traffic and the satellite ones carrying high-latencytraffic. Mobile operators can also use satellite links to cover the edge of their networks. In one deployment scenario of NTN, a satellite referred to as a transparent satellite may act as a relay station to link UEs with a ground-based BS and the core network by implementing a transparent payload. In another deployment scenario, a satellite referred to as a regenerative satellite may have onboard processing capability to perform the functions of a BS by implementing a regenerative payload between UEs and the ground-based core network. Though the term “satellite” is used for non-terrestrial equipment of the NTN hereafter, examples of other non-terrestrial equipment include aerial vehicles, A2G (air to ground) system, HAPS (high altitude platform station, such as airplane, helicopter, drones, etc.), and the like.

[0062] In the present example, the UEs 101 are illustrated as smartphones, but can comprise any mobile or non-mobile computing device, such as consumer electronics devices, cellular phones, smartphones, feature phones, tablet computers, wearable computer devices, personal digital assistants (PDAs), pagers, wireless handsets, desktop computers, laptop computers, in-vehicle infotainment (IVI), in-car entertainment (ICE) devices, an Instrument Cluster (1C), head-up display (HUD) devices, onboard diagnostic (OBD) devices, dashtop mobile equipment (DME), mobile data terminals (MDTs), Electronic Engine Management System (EEMS), electronic / engine control units (ECUs), electronic / engine control modules (ECMs), embedded systems, microcontrollers, control modules, engine management systems (EMS), networked or “smart” appliances, Machine Type Communication (MTC) devices, Machine to Machine (M2M), Internet of Things (loT) devices, and / or the like.

[0063] In some aspects, the RAN 910 can be an evolved-UMTS Terrestrial RAN (E- UTRAN), a next generation (NG) RAN or a 5G RAN, or a legacy RAN, such as a UTRAN or GERAN. As used herein, the term “E-UTRAN” or the like can refer to a RAN 910 that operates in an LTE or 4G system, and the term “NG RAN” or the like can refer to a RAN 910 that operates in an NR or 5G system.

[0064] In some aspects, the CN 120 can be a 4GC (referred to as “4GC 120” or the like). The CN 120 includes an MME 122, a serving gateway (S-GW) 924, a packet data network (PDN) gateway (P-GW) 926, and a home subscriber server (HSS) 928. The MME 122 may be used to manage the mobility functions of the UE 101, such as tracking area management, handover, attach / detach, paging, etc. Furthermore, the S-GW 924 may route data packets for the UE 101, and the P-GW 926 may provide connectivity from the UE to external packet data networks. The HSS 928 may be a database containing user related and subscription related information.

[0065] Although the present example involves the use of a 4G system, the techniques described herein may also be extended to future or past generation systems, such as 5thgeneration (5G) systems, 6thgeneration (6G) systems, 3rdgeneration (3G) systems, etc. Accordingly, although an MME 122 is used in the present example, an alternative mobility management function may be used in place of the MME 122 in other examples. For example, an access and mobility function (AMF) may be used in place of the MME 122 in a 5G system.

[0066] The systems and devices of the network 900 may operate in accordance with 3G, 4G, 5G, 6G communication standards of 3GPP or the like. Additionally, or alternatively, one or more of the systems and devices of example network 900 may operate in accordance with other communication standards and protocols, such as institute of electrical and electronics engineers (IEEE) standards (e.g., wireless metropolitan area network (WMAN), worldwide interoperability for microwave access (WiMAX), etc.), and more.

[0067] Fig. 10 is a diagram illustrating example components of a device 1000 that can be employed in accordance with some aspects of the present disclosure. In some aspects, the device 1000 can include application circuitry 1002, baseband circuitry 1004, Radio Frequency (RF) circuitry 1006, front-end module (FEM) circuitry 1008, one or more antennas 1010, and power management circuitry (PMC) 1012 coupled together at least as shown. The components of the illustrated device 1000 can be included in a UE or a RAN node such as the UE 101, the non-terrestrial base stations 130-1, 130-2, or the base stations 911-1, 911-2 as described, for example, with reference to Figs. 1-4, Fig. 9, and throughout the present disclosure. The UE 101 and the non-terrestrial base station 130-1 (or 130-2) may be configured for UE location reporting using NAS signaling, as described throughout the present disclosure. In some implementations, the device 1000 can include fewer elements (e.g., a RAN node may not utilize application circuitry 1002 and instead include a processor / controller to process IP data received from a CN, which may be a 5GC or an Evolved Packet Core (EPC)). In some implementations, the device 1000 can include additional elements such as, for example, memory / storage, display, camera, sensor (including one or more temperature sensors, such as a single temperature sensor, a plurality of temperature sensors at different locations in device 1000, etc.), or input / output (VO) interface. In other implementations, the components described below can be included in more than one device (e.g., said circuitries can be separately included in more than one device for Cloud- RAN (C-RAN) implementations).

[0068] The application circuitry 1002 can include one or more application processors.For example, the application circuitry 1002 can include circuitry such as, but not limited to, one or more single-core or multi-core processors. The processor(s) can include any combination of general-purpose processors and dedicated processors (e.g., graphics processors, application processors, etc.). The processors can be coupled with or can include memory / storage and can be configured to execute instructions stored in the memory / storage to enable various applications or operating systems to run on the device 1000. In some implementations, processors of application circuitry 1002 can process IP data packets received from an EPC.

[0069] The baseband circuitry 1004 can include circuitry such as, but not limited to, one or more single-core or multi-core processors. The baseband circuitry 1004 can include one or more baseband processors or control logic to process baseband signals received from a receive signal path of the RF circuitry 1006 and to generate baseband signals for a transmit signal path of the RF circuitry 1006. Baseband circuitry 1004 can interface with the application circuitry 1002 for generation and processing of the baseband signals and for controlling operations of the RF circuitry 1006. For example, in some implementations, the baseband circuitry 1004 can include a 3G baseband processor 1004A, a 4G baseband processor 1004B, a 5G baseband processor 1004C, or other baseband processor(s) 1004D for other existing generations, generations in development or to be developed in the future (e.g., 2G, 6G, etc.).

[0070] The baseband circuitry 1004 (e.g., one or more of baseband processors 1004A-D) can handle various radio control functions that enable communication with one or more radio networks via the RF circuitry 1006. In other implementations, some or all of the functionality of baseband processors 1004A-D can be included in modules stored in the memory 1004G and executed via a Central Processing Unit (CPU) 1004E. The radio control functions can include, but are not limited to, signal modulation / demodulation, encoding / decoding, radio frequency shifting, etc. In some implementations, the baseband circuitry 1004 can include one or more audio digital signal processor(s) (DSP) 1004F.

[0071] RF circuitry 1006 can enable communication with wireless networks using modulated electromagnetic radiation through a non-solid medium. In various implementations, the RF circuitry 1006 can include switches, filters, amplifiers, etc. to facilitate the communication with the wireless network. RF circuitry 1006 can include a receive signal path which can include circuitry to down-convert RF signals received from the FEM circuitry 1008 and provide baseband signals to the baseband circuitry 1004. RF circuitry 1006 can also include a transmit signal path which can include circuitry to up-convert baseband signals provided by the baseband circuitry 1004 and provide RF output signals to the FEM circuitry 1008 for transmission.

[0072] In some implementations, the receive signal path of the RF circuitry 1006 can include mixer circuitry 1006A, amplifier circuitry 1006B and filter circuitry 1006C. In some implementations, the transmit signal path of the RF circuitry 1006 can include filter circuitry 1006C and mixer circuitry 1006A. RF circuitry 1006 can also include synthesizer circuitry 1006D for synthesizing a frequency for use by the mixer circuitry 1006 A of the receive signal path and the transmit signal path.

[0073] Fig. 11 illustrates a diagram illustrating example interfaces of baseband circuitry that can be employed in accordance with some aspects. As discussed above, the baseband circuitry 1004 of Fig. 10 can comprise processors 1004A-1004E and a memory 1004G utilized by said processors. Each of the processors 1004A-1004E can include a memory interface, 1104A-1104E, respectively, to send / receive data to / from the memory 1004G. The baseband circuitry 1004, or the one or more baseband processors or control logic of the baseband circuitry 1004, may stand alone as the UE 101, the non- terrestrial base station 130- 1 (or 130-2), or the base station 91 1-1 (or 911-2) and perform signaling and operation in the meaning as described throughout this disclosure.

[0074] The baseband circuitry 1004 can further include one or more interfaces to communicatively couple to other circuitries / devices, such as a memory interface 1112 (e.g., an interface to send / receive data to / from memory external to the baseband circuitry 1004), an application circuitry interface 11 14 (e.g., an interface to send / receive data to / from the application circuitry 1002 of Fig. 10), an RF circuitry interface 1116 (e.g., an interface to send / receive data to / from RF circuitry 1006 of Fig. 10), a wireless hardware connectivity interface 1118 (e.g., an interface to send / receive data to / from Near Field Communication (NFC) components, Bluetooth® components (e.g., Bluetooth® Low Energy), Wi-Fi® components, and other communication components), and a power management interface 1120 (e.g., an interface to send / receive power or control signals to / from the PMC 1012).

[0075] Examples herein can include subject matter such as a method, means for performing acts or blocks of the method, at least one machine-readable medium including executable instructions that, when performed by a machine (e.g., a processor (e.g., processor , etc.) with memory, an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or the like) cause the machine to perform acts of the method or of an apparatus or system for concurrent communication using multiple communication technologies according to implementations and examples described.

[0076] Example 1 is a baseband circuit, comprising one or more processors, when executing instructions stored in a memory coupled to the one or more processors, configured to perform operations comprising: encoding User Equipment (UE) capability information indicating a capability of the UE to report a location of the UE via non-access stratum (NAS) signaling, performing a security mode procedure, comprising decoding a SECURITY MODE COMMAND message to establish NAS signaling security, wherein the SECURITY MODE COMMAND message includes a request for the location of the UE, and encoding a message indicating the location of the UE in response to the request.

[0077] Example 2 comprises the subject matter of any variation of example 1, wherein the message is a SECURITY MODE COMPLETE message, and wherein the operations comprise encoding the SECURITY MODE COMPLETE message in response to decoding the SECURITY MODE COMMAND message.

[0078] Example 3 comprises the subject matter of any variation of example 1, wherein the security mode procedure is part of an attach procedure, a tracking area update (TAU) procedure, or a service request procedure.

[0079] Example 4 comprises the subject matter of any variation of example 1, wherein the operations further comprise: in response to NAS signaling security being established, encoding an additional message indicating an updated location of the UE.

[0080] Example 5 comprises the subject matter of any variation of example 1, wherein the additional message is one of: a tracking area update (TAU) REQUEST message, an EXTENDED SERVICE REQUEST message, a CONTROL PLANE SERVICE REQUEST message, or a packet data network (PDN) CONNECTIVITY REQUEST message.

[0081] Example 6 comprises the subject matter of any variation of example 1, wherein the security mode command message includes a UE location request information element (IE), and wherein the request for the location of the UE is indicated by the UE location request IE.

[0082] Example 7 comprises the subject matter of any variation of example 6, wherein the request for the location of the UE includes a single UE NB-IoT NTN location reporting request (UNNLR) bit.

[0083] Example 8 comprises the subject matter of any variation of example 1, wherein the UE capability information is included in a UE network capability information element (IE).

[0084] Example 9 comprises the subject matter of any variation of example 8, wherein the indication of the capability of the UE to report the location of the UE includes a 1 -bitindication in the UE Network Capability IE.

[0085] Example 10 comprises the subject matter of any variation of example 1, wherein the message comprises a UE location information element (IE) indicating the location of the UE.

[0086] Example 11 comprises the subject matter of any variation of example 1, wherein the security mode command message is received from a mobility management entity (MME).

[0087] Example 12 comprises the subject matter of any variation of example 1, wherein the UE capability information is included in an ATTACH REQUEST message.

[0088] Example 13 comprises the subject matter of any variation of example 1, wherein the operations further comprise encoding the location of the UE in response to a security cipher being configured.

[0089] Example 14 comprises the subject matter of any variation of example 1, wherein the UE capability information, the security mode command message, and the message indicating the location of the UE are communicated using narrowband internet of things (NB- loT) signaling.

[0090] Example 15 is a baseband circuit, comprising one or more processors, when executing instructions stored in a memory coupled to the one or more processors, configured to perform operations comprising: decoding User Equipment (UE) capability information indicating a capability of a UE to report a location of the UE via non-access stratum (NAS) signaling, performing a security mode procedure, comprising: encoding a security mode command message to establish NAS signaling security, wherein the security mode command message includes a request for the location of the UE, and decoding a message indicating the location of the UE.

[0091] Example 16 comprises the subject matter of any variation of example 15, wherein the message is a security mode complete message.

[0092] Example 17 comprises the subject matter of any variation of example 15, wherein the security mode procedure is part of an attach procedure, a tracking area update (TAU) procedure, or a service request procedure.

[0093] Example 18 comprises the subject matter of any variation of example 15, wherein the operations further comprise: decoding an additional message indicating an updated location of the UE.

[0094] Example 19 comprises the subject matter of any variation of example 18, wherein the additional message is one of: a tracking area update (TAU) REQUEST message, an EXTENDED SERVICE REQUEST message, a CONTROL PLANE SERVICE REQUESTmessage, or a packet data network (PDN) CONNECTIVITY REQUEST message.

[0095] Example 20 comprises the subject matter of any variation of example 15, wherein the security mode command message includes a UE location request information element (IE), and wherein the request for the location of the UE is indicated by the UE location request IE.

[0096] Example 21 comprises the subject matter of any variation of example 20, wherein the request for the location of the UE includes a 1 -bit indication in the UE location request IE.

[0097] Example 22 comprises the subject matter of any variation of example 15, wherein the UE capability information is included in a UE network capability information element (IE).

[0098] Example 23 comprises the subject matter of any variation of example 22, wherein the indication of the capability of the UE to report the location of the UE includes a 1 -bit indication in the UE Network Capability IE.

[0099] Example 24 comprises the subject matter of any variation of example 15, wherein the message comprises a UE location information element (IE) indicating the location of the UE.

[0100] Example 25 comprises the subject matter of any variation of example 15, wherein the UE capability information is included in an attach request message.

[0101] Example 26 comprises the subject matter of any variation of example 15, wherein the UE capability information, the security mode command message, and the message indicating the location of the UE are communicated using narrowband internet of things (NB- loT) signaling.

[0102] Example 27 is a method for a Mobility Management Entity (MME), comprising: receiving User Equipment (UE) capability information indicating a capability of a UE to report a location of the UE via non-access stratum (NAS) signaling, performing a security mode procedure, comprising: transmitting a security mode command message to establish NAS signaling security, wherein the security mode command message includes a request for the location of the UE, and receiving a message indicating the location of the UE.

[0103] Example 28 comprises the subject matter of any variation of example 27, wherein the message is a security mode complete message.

[0104] Example 29 comprises the subject matter of any variation of example 27, wherein the security mode procedure is part of an attach procedure, a tracking area update (TAU)procedure, or a service request procedure.

[0105] Example 30 comprises the subject matter of any variation of example 27, further comprising: receiving an additional message indicating an updated location of the UE.

[0106] Example 31 comprises the subject matter of any variation of example 30, wherein the additional message is one of: a tracking area update (TAU) REQUEST message, an EXTENDED SERVICE REQUEST message, a CONTROL PLANE SERVICE REQUEST message, or a packet data network (PDN) CONNECTIVITY REQUEST message.

[0107] Example 32 comprises the subject matter of any variation of example 27, wherein the security mode command message includes a UE location request information element (IE), and wherein the request for the location of the UE is indicated by the UE location request IE.

[0108] Example 33 comprises the subject matter of any variation of example 32, wherein the request for the location of the UE includes a 1 -bit indication in the UE location request IE.

[0109] Example 34 comprises the subject matter of any variation of example 27, wherein the UE capability information is included in a UE network capability information element (IE).

[0110] Example 35 comprises the subject matter of any variation of example 34, wherein the indication of the capability of the UE to report the location of the UE includes a 1 -bit indication in the UE Network Capability IE.

[0111] Example 36 comprises the subject matter of any variation of example 27, wherein the message comprises a UE location information element (IE) indicating the location of the UE.

[0112] Example 37 comprises the subject matter of any variation of example 27, wherein the UE capability information is included in an attach request message.

[0113] Example 38 comprises the subject matter of any variation of example 27, wherein the UE capability information, the security mode command message, and the message indicating the location of the UE are communicated using narrowband internet of things (NB- loT) signaling.

[0114] The above description of illustrated examples, implementations, aspects, etc., of the subject disclosure, including what is described in the Abstract, is not intended to be exhaustive or to limit the disclosed aspects to the precise forms disclosed. While specific examples, implementations, aspects, etc., are described herein for illustrative purposes, various modifications are possible that are considered within the scope of such examples,implementations, aspects, etc., as those skilled in the relevant art can recognize.

[0115] In this regard, while the disclosed subject matter has been described in connection with various examples, implementations, aspects, etc., and corresponding Figures, where applicable, it is to be understood that other similar aspects can be used or modifications and additions can be made to the disclosed subject matter for performing the same, similar, alternative, or substitute function of the subject matter without deviating therefrom.Therefore, the disclosed subject matter should not be limited to any single example, implementation, or aspect described herein, but rather should be construed in breadth and scope in accordance with the appended claims below.

[0116] In particular regard to the various functions performed by the above described components or structures (assemblies, devices, circuits, systems, etc.), the terms (including a reference to a “means”) used to describe such components are intended to correspond, unless otherwise indicated, to any component or structure which performs the specified function of the described component (e.g., that is functionally equivalent), even though not structurally equivalent to the disclosed structure which performs the function in the herein illustrated exemplary implementations. In addition, while a particular feature may have been disclosed with respect to only one of several implementations, such feature may be combined with one or more other features of the other implementations as may be desired and advantageous for any given or particular application.

[0117] As used herein, the term “or” is intended to mean an inclusive “or” rather than an exclusive “or”. That is, unless specified otherwise, or clear from context, “X employs A or B” is intended to mean any of the natural inclusive permutations. That is, if X employs A; X employs B; or X employs both A and B, then “X employs A or B” is satisfied under any of the foregoing instances. In addition, the articles “a” and “an” as used in this application and the appended claims should generally be construed to mean “one or more” unless specified otherwise or clear from context to be directed to a singular form. Furthermore, to the extent that the terms “including”, “includes”, “having”, “has”, “with”, or variants thereof are used in either the detailed description and the claims, such terms are intended to be inclusive in a manner similar to the term “comprising.” Additionally, in situations wherein one or more numbered items are discussed (e.g., a “first X”, a “second X”, etc.), in general the one or more numbered items can be distinct, or they can be the same, although in some situations the context may indicate that they are distinct or that they are the same.

[0118] It is well understood that the use of personally identifiable information should follow privacy policies and practices that are generally recognized as meeting or exceedingindustry or governmental requirements for maintaining the privacy of users. In particular, personally identifiable information data should be managed and handled so as to minimize risks of unintentional or unauthorized access or use, and the nature of authorized use should be clearly indicated to users.

Claims

CLAIMSWhat is claimed is:

1. A baseband circuit comprising one or more processors configured to, when executing instructions stored in a memory coupled to the one or more processors, perform operations comprising: providing, to a radio frequency (RF) interface for transmission, User Equipment (UE) capability information indicating a capability of the UE to report a location of the UE via non-access stratum (NAS) signaling; performing a security mode procedure, comprising: receiving a SECURITY MODE COMMAND message to establish NAS signaling security, wherein the SECURITY MODE COMMAND message includes a request for the location of the UE; and providing, to the RF interface for transmission, a message indicating the location of the UE in response to the request.

2. The baseband circuit of claim 1, wherein the message is a SECURITY MODE COMPLETE message, and wherein the operations comprise providing the SECURITY MODE COMPLETE message in response to receiving the SECURITY MODE COMMAND message.

3. The baseband circuit of claim 1, wherein the security mode procedure is part of an attach procedure, a tracking area update (TAU) procedure, or a service request procedure.

4. The baseband circuit of claim 1, wherein the operations further comprise: in response to NAS signaling security being established, encoding an additional message indicating an updated location of the UE, wherein the additional message is one of: a tracking area update (TAU) REQUEST message, an EXTENDED SERVICE REQUEST message, a CONTROL PLANE SERVICE REQUEST message, or a packet data network (PDN) CONNECTIVITY REQUEST message.

5. The baseband circuit of claim 1, wherein the SECURITY MODE COMMAND message includes a UE location request information element (IE), and wherein the request for thelocation of the UE a single UE NB-IoT NTN location reporting request (UNNLR) bit in the UE location request IE.

6. The baseband circuit of claim 1 , wherein the indication of the capability of the UE to report the location of the UE includes a 1 -bit indication in a UE Network Capability information element (IE).

7. The baseband circuit of claim 1 , wherein the security mode command message is received from a mobility management entity (MME).

8. The baseband circuit of claim 1, wherein the UE capability information is included in an ATTACH REQUEST message.

9. The baseband circuit of claim 1 , wherein the operations further comprise providing the location of the UE in response to a security cipher being configured.

10. The baseband circuit of claim 1, wherein the UE capability information, the security mode command message, and the message indicating the location of the UE are communicated using narrowband internet of things (NB-IoT) signaling.

11. A baseband circuit comprising one or more processors configured to, when executing instructions stored in a memory coupled to the one or more processors, perform operations comprising: receiving User Equipment (UE) capability information indicating a capability of a UE to report a location of the UE via non-access stratum (NAS) signaling; performing a security mode procedure, comprising: providing, to a radio frequency (RF) interface for transmission, a SECURITY MODE COMMAND message to establish NAS signaling security, wherein the SECURITY MODE COMMAND message includes a request for the location of the UE; and receiving a message indicating the location of the UE.

12. The baseband circuit of claim 11, wherein the message is a SECURITY MODE COMPLETE message.

13. The baseband circuit of claim 11, wherein the security mode procedure is part of an attach procedure, a tracking area update (TAU) procedure, or a service request procedure.

14. The baseband circuit of claim 11, wherein the UE capability information, the SECURITY MODE COMMAND message, and the message indicating the location of the UE are communicated using narrowband internet of things (NB-IoT) signaling.

15. A method for a Mobility Management Entity (MME), comprising: receiving User Equipment (UE) capability information indicating a capability of a UE to report a location of the UE via non-access stratum (NAS) signaling; performing a security mode procedure, comprising: transmitting a SECURITY MODE COMMAND message to establish NAS signaling security, wherein the SECURITY MODE COMMAND message includes a request for the location of the UE; and receiving a message indicating the location of the UE.

16. The method of claim 15, wherein the message is a SECURITY MODE COMPLETE message.

17. The method of claim 15, wherein the security mode procedure is part of an attach procedure, a tracking area update (TAU) procedure, or a service request procedure.

18. The method of claim 15, wherein the SECURITY MODE COMMAND message includes a UE location request information element (IE), and wherein the request for the location of the UE is indicated by the UE location request IE.

19. The method of claim 15, wherein the UE capability information is included in an ATTACH REQUEST message.

20. The method of claim 15, wherein the UE capability information, the SECURITY MODE COMMAND message, and the message indicating the location of the UE are communicated using narrowband internet of things (NB-IoT) signaling.