Method, apparatus and computer program

The core network function assesses the trustworthiness of network access nodes to provide appropriate mobility restriction information, addressing privacy and operational challenges in communication networks by ensuring secure and efficient access control for user equipment.

WO2026032977A1PCT designated stage Publication Date: 2026-02-12NOKIA TECHNOLOGIES OY
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/072501
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-08
Filing Date
2025-08-05
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

Existing communication networks face privacy concerns and operational challenges when handling mobility restriction information for user equipment (UE) in untrusted network access nodes, particularly femto nodes, due to incomplete or restricted mobility restriction lists being sent to these nodes, leading to potential privacy issues and ineffective access control.

Method used

A core network function determines the trustworthiness of network access nodes and provides appropriate degrees of mobility restriction information based on predefined criteria, ensuring complete or restricted mobility information is sent only to trusted nodes, thereby addressing privacy concerns and enabling effective access control.

Benefits of technology

This approach ensures secure and efficient mobility management by providing the necessary mobility restriction information only to trusted nodes, maintaining privacy and ensuring seamless handover operations in communication networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025072501_12022026_PF_FP_ABST
    Figure EP2025072501_12022026_PF_FP_ABST
Patent Text Reader

Abstract

There is provided a method, apparatus, and computer program for causing the following to be performed by an apparatus: receiving, at a core network function from a first network access node, a request for access information for configuring the first network access node to provide a service to a user equipment; determining a degree of mobility restriction information to provide to the first network access node based on whether the first network access node fulfils one or more criterion for receiving incomplete mobility restriction information for the user equipment; and providing, to the first network access node, access information that comprises the determined degree of mobility restriction information.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD, APPARATUS AND COMPUTER PROGRAMTECHNICAL FIELD

[0001] Various example embodiments of this disclosure relate to a method, apparatus, system and computer program and in particular but not exclusively to controlling the provision of mobility information of a user equipment.BACKGROUND

[0002] A communication network can be seen as a facility that enables communications between two or more communication devices, or provides communication devices access to a data network. A mobile or wireless communication network is one example of a communication network. A communication device may be provided with a service by an application server.

[0003] Such communication networks operate in according with standards such as those provided by 3GPP (Third Generation Partnership Project) or ETSI (European Telecommunications Standards Institute). Examples of standards are the so-called 5G (5th Generation) standards and 6G (6th Generation) standards provided by 3GPP.SUMMARY

[0004] Some example embodiments of this disclosure will be described with respect to certain aspects. These aspects are not intended to indicate key or essential features of the embodiments of this disclosure, nor are they intended to be used to limit the scope of thereof. Other features, aspects, and elements will be readily apparent to a person skilled in the art in view of this disclosure.

[0005] According to a first aspect, there is provided an apparatus comprising means for performing: receiving, at a core network function from a first network access node, a request for access information for configuring the first network access node to provide a service to a user equipment; determining a degree of mobility restriction information to provide to the first network access node based on whether the first network access node fulfils one or more criterion for receiving incomplete mobility restriction information for the user equipment; and providing, to the first network access node, access information that comprises the determined degree of mobility restriction information.

[0006] According to a second aspect, there is provided an apparatus comprising: at least one processor; and at least one memory comprising code that, when executed by the at least one processor, causes the apparatus to perform: receiving, at a core network function from a first network access node, a request for access information for configuring the first network access node to provide a service to a user equipment; determining a degree of mobility restriction information to provide to the first network access node based on whether the first network access node fulfils one or more criterion for receiving incomplete mobility restriction information for the user equipment; and providing, to the first network access node, access information that comprises the determined degree of mobility restriction information.

[0007] According to a third aspect, there is provided a method for an apparatus, the method comprising: receiving, at a core network function from a first network access node, a request for access information for configuring the first network access node to provide a service to a user equipment; determining a degree of mobility restriction information to provide to the first network access node based on whether the first network access node fulfils one or more criterion for receiving incomplete mobility restriction information for the user equipment; and providing, to the first network access node, access information that comprises the determined degree of mobility restriction information.

[0008] According to a fourth aspect, there is provided an apparatus comprising: receiving circuitry for receiving, at a core network function from a first network access node, a request for access information for configuring the first network access node to provide a service to a user equipment; determining circuitry for determining a degree of mobility restriction information to provide to the first network access node based on whether the first network access node fulfils one or more criterion for receiving incomplete mobility restriction information for the user equipment; and providing circuitry for providing, to the first network access node, access information that comprises the determined degree of mobility restriction information.

[0009] The following may apply to any (e.g., one or more including all) of the above first to fourth aspects.

[0010] The apparatus may be caused to perform: obtaining, from the first network access node, a request for the core network function to determine whether the user equipment can be handed over to a target network access node; determining whether the user equipment can be handed over to the target network access node bycomparing mobility restriction information of the user equipment to mobility restriction information of the target network access node; and providing, the first network access node, the result of the determination of whether the user equipment can be handed over to the target network access node.

[0011] The criterion may comprise at least one of a list of access node identifiers for which the access information comprises at least one of no mobility restriction information or a restricted version of the mobility restriction information or a list of access node categories for which the access information comprises at least one of no mobility restriction information or a restricted version of the mobility restriction information.

[0012] According to a fifth aspect, there is provided an apparatus comprising means for performing: providing, to a core network function, a request for access information for configuring a first network access node to provide a service to a user equipment; and obtaining, based on the request, access information comprising a degree of mobility restriction information that is dependent on the first network access node.

[0013] According to a sixth aspect, there is provided an apparatus comprising: at least one processor; and at least one memory comprising code that, when executed by the at least one processor, causes the apparatus to perform: providing, to a core network function, a request for access information for configuring a first network access node to provide a service to a user equipment; and obtaining, based on the request, access information comprising a degree of mobility restriction information that is dependent on the first network access node.

[0014] According to a seventh aspect, there is provided a method for an apparatus, the method comprising: providing, to a core network function, a request for access information for configuring a first network access node to provide a service to a user equipment; and obtaining, based on the request, access information comprising a degree of mobility restriction information that is dependent on the first network access node.

[0015] According to an eighth aspect, there is provided an apparatus comprising: providing circuitry for providing, to a core network function, a request for access information for configuring a first network access node to provide a service to a user equipment; and obtaining, based on the request, access information comprising a degree of mobility restriction information that is dependent on the first network access node.

[0016] The following may apply to any (e.g., one or more including all) of the above fifth to eighth aspects.

[0017] The apparatus may be caused to perform: identifying a handover opportunity to handover the user equipment from the first network access node to a target network access node; determining that the obtained mobility restriction information is incomplete; and based on the determining that the mobility restriction information is incomplete, providing, to the core network function, before triggering the handover, a request for the core network function to determine whether the user equipment can be handed over to the target network access node.

[0018] The apparatus may be caused to perform: obtaining, from the core network function, an indication of whether the user equipment can be handed over to the target network access node based on said request; and either initiating handover to the target network access node or removing the target network access node as a candidate handover network access node based on the obtained indication of whether the user equipment can be handed over.

[0019] The indication may indicate that the user equipment can be handed over and the apparatus initiates handover by signalling, to the target network access node, a handover request, wherein the handover request may comprise the obtained degree of mobility restriction information.

[0020] The determining that the mobility restriction information is incomplete may comprises determining that the mobility restriction information either does not comprise a mobility restriction information or comprises a restricted version of the mobility restriction information.

[0021] The restricted version of the mobility restriction information may not comprise any closed access group subscription information of the user equipment.The target access node may comprise a femto node configured to operate in a closed access mode or in a hybrid access mode.

[0022] The following may apply to any (e.g., one or more including all) of the above first to eighth aspects.

[0023] The request for access information may comprise at least one of an identifier of the first network access node or an identifier of a category of the first network access node, and wherein the degree of mobility restriction information may be dependent on the at least one of identifier of the first network access node or the identifier of the category of first network access node comprised in the request for access.

[0024] The degree of mobility restriction information comprised in the access information may comprise: no mobility restriction list; a mobility restriction list; or a restricted version of the mobility restriction list.

[0025] The restricted version of the mobility restriction list may not comprise closed access group information for the user equipment.

[0026] The request for access information may be an Next Generation Application Protocol, NGAP, Initial User Equipment, UE, Message message.

[0027] The first network access node may comprise a femto node.

[0028] The first network access node may comprise a femto node configured to operate in a closed access mode or a hybrid access mode.

[0029] According to a ninth aspect, there is provided an apparatus comprising means for performing: obtaining, at a target network access node from another network node, a handover request for handing over a user equipment from a source network access node to the target network access node; determining that the handover request comprises incomplete mobility restriction information for the user equipment; and based on the determining that the mobility restriction information is incomplete, providing, to a core network function, a request for the core network function to determine whether the user equipment can be handed over to the target network access node.

[0030] According to a tenth aspect, there is provided an apparatus comprising: at least one processor; and at least one memory comprising code that, when executed by the at least one processor, causes the apparatus to perform: obtaining, at a target network access node from another network node, a handover request for handing over a user equipment from a source network access node to the target network access node; determining that the handover request comprises incomplete mobility restriction information for the user equipment; and based on the determining that the mobility restriction information is incomplete, providing, to a core network function, a request for the core network function to determine whether the user equipment can be handed over to the target network access node.

[0031] According to an eleventh aspect, there is provided a method for an apparatus, the method comprising: obtaining, at a target network access node from another network node, a handover request for handing over a user equipment from a source network access node to the target network access node; determining that the handover request comprises incomplete mobility restriction information for the userequipment; and based on the determining that the mobility restriction information is incomplete, providing, to a core network function, a request for the core network function to determine whether the user equipment can be handed over to the target network access node.

[0032] According to a twelfth aspect, there is provided an apparatus comprising: obtaining circuitry for obtaining, at a target network access node from another network node, a handover request for handing over a user equipment from a source network access node to the target network access node; determining that the handover request comprises incomplete mobility restriction information for the user equipment; and providing circuitry for, based on the determining that the mobility restriction information is incomplete, providing, to a core network function, a request for the core network function to determine whether the user equipment can be handed over to the target network access node.

[0033] The following may apply to any (e.g., one or more including all) of the above ninth to twelfth aspects.

[0034] The apparatus may be caused to perform: obtaining, from the core network function, an indication of whether the user equipment can be handed over to the target network access node based on said request; and based on the indication, either providing, to the another network node, an acceptance of the handover request, or providing, to the another network node, a refusal of the handover request.

[0035] The another network node may comprise at least one of the core network function or the source network access node.

[0036] The determining that the handover request comprises incomplete mobility restriction information for the user equipment may comprise determining that the handover request either does not comprise a mobility restriction information or comprises a restricted version of the mobility restriction information.

[0037] The restricted version of the mobility restriction information may not comprise any closed access group subscription information of the user equipment.

[0038] The target network access node is may be a femto node.

[0039] The target network access node may be a femto node configured to operate in a closed access mode or in a hybrid access mode.

[0040] The source network access node may be a femto node.

[0041] The source network access node may be a femto node configured to operate in a closed access mode or in hybrid access mode.

[0042] According to an aspect, there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the method according to any of the preceding aspects.

[0043] In the above, many different example embodiments have been described. It should be appreciated that further example embodiments may be provided by the combination of any two or more of the example embodiments described above.DESCRIPTION OF FIGURES

[0044] Some example embodiments will now be described, by way of non-limiting and illustrative example only, with reference to the accompanying Figures in which:

[0045] Figures 1A and 1 B shows a representation of a communication system;

[0046] Figure 2 shows a representation of an apparatus for the communication system of Figures 1 A and 1 B according to some example embodiments;

[0047] Figure 3 shows a representation of an apparatus according to some example embodiments;

[0048] Figures 4 to 6 illustrate example signalling;

[0049] Figures 7 to 9 illustrate methods that may be performed by example apparatus; and

[0050] Figures 10 to 12 illustrate example signalling in 3GPP.DETAILED DESCRIPTION

[0051] The present application relates to addressing privacy concerns in a network with respect to a user equipment’s (UE’s) mobility restriction information.

[0052] In more detail, the following describes a core network function (e.g., an access function, an access and mobility function (AMF), a network repository function (NRF), a unified data management (UDM), etc.) that can determine a degree of mobility restriction information of a user equipment to provision at a network access node based on (e.g., depending on) how trusted that network access node is.

[0053] The core network function may evaluate how trustworthy a network access node is based on at least one criterion. Therefore, the following describes a core network function that can determine a degree of mobility restriction information of a UE to provision at a network access node based on whether that network access node fulfils at least one criterion.

[0054] For example, the core network function may be configured to treat network access nodes of a first type (e.g., femto nodes) as being untrusted for receiving complete mobility restriction information for a UE, and to treat all other types of network access nodes as being trusted for receiving complete mobility restriction information. Consequently, in an example, the core network function may be configured to determine whether a network access node is a first type (e.g., fulfils a criterion of being configured as a first type of network access node), and provisions a degree of mobility restriction information at the network access node based on that determination. It is understood that a one or more (e.g., a plurality) of types of network access nodes may be preconfigured in the core network function as being untrusted for receiving complete mobility restriction information for a UE.

[0055] Analogously, the core network function may be preconfigured to treat one or more (e.g., a plurality) of types of network access nodes of a second type as being trusted for receiving complete mobility restriction information for a UE. In this case, only those types of network access nodes that are preconfigured as being trusted may be provided with complete mobility restriction information. Stated differently, only those network access nodes that are determined to fulfil a criterion of being the second type of network access node are provided with complete mobility restriction information for a UE.

[0056] As another example, the core network function may be preconfigured with a list of network access node identifiers that identify which network access nodes are trusted for receiving mobility restriction information for a UE, and / or be preconfigured with a list of network access node identifiers that identify which network access nodes are not trusted for receiving mobility restriction information for a UE. In such a case, determining whether the at least one criterion is fulfilled may comprise determining whether a network access node’s identifier is comprised on such a list.

[0057] There may also be different degrees to which mobility restriction information for a UE is provided. For example, the core network function may be configured to provide: no mobility restriction information, complete mobility restriction information, or a restricted version of the mobility restriction information, where the restricted version is restricted relative to the complete mobility restriction information so that the restricted version comprises some, but not all, of the complete mobility restriction information. The restricted version of the mobility restriction information may not comprise closed access group information of the UE.

[0058] In operation, the core network function may receive a request for access for a UE to receive a service through a network access node, perform an evaluation as to the degree of mobility restriction information to be provided (e.g., based on whether the at least one network access node fulfils at least one criterion), and provide access information to the network access node for enabling the UE to receive the service, wherein the access information comprises the determined degree of mobility restriction information of the UE (e.g., full, none, or restricted). The network access node may use the provided access information to provide a service to the UE through the network access node.

[0059] As the network access node may comprise incomplete mobility restriction information for the UE (e.g., a restricted version of a mobility restriction information or no mobility restriction information), the network access node may request that the core network function assist in mobility operations (such as, for example, handover, dual connectivity, multi-Transmission Reception Point (mTRP), etc.) by determining whether the UE’s mobility restriction information indicates that the UE is allowed to access one or more cells.

[0060] Although these concepts will be illustrated more fully below, the following provides an example of a communication environment in which the presently described techniques may be deployed. It is understood that this communication environment is not limiting, and is merely being used to provide at least one example for describing where such techniques may be deployed.

[0061] Stated differently, in the following various example embodiments are explained with reference to communication devices capable of communication with a communication system. Before explaining in detail the example embodiments of the methods and apparatuses of this disclosure, a 5thgeneration communication system (5GS), an access network and a core network (5GC) thereof, and communication devices are briefly explained with reference to Figures 1 A, 1 B, 2 and 3.

[0062] Figure 1A shows a schematic representation of a 5G communication system (5GS). The 5GS may comprise a user equipment (UE), an access network such as a 5G radio access network (5G-RAN) or next generation radio access network (NG- RAN), a 5G core network (5GC), and one or more application functions. An application function may be deployed in the 5GS as trusted application function or may be deployed or host on one or more application servers of the data network. Suchapplication functions are untrusted application functions. The 5GS connects the UE to a data network the access network and the 5GC (e.g., a UPF of the 5GC).

[0063] The 5G-RAN may comprise one or more network access nodes (e.g., radio access nodes), such as gNodeB (gNB). A gNB may include one or more gNodeB distributed units connected to one or more gNodeB centralized units. The 5G-RAN may be as illustrated below in Figure 1 B.

[0064] The 5GC may comprise the following network functions: Network Slice Selection Function (NSSF); Network Exposure Function; Network Repository Function (NRF); Policy Control Function (PCF); Unified Data Management (UDM); Application Function (AF); Authentication Server Function (AUSF); an Access and Mobility Management Function (AMF); and Session Management Function (SMF), and a user plane function (UPF). Figure 1A also shows the various interfaces (N1 , N2 etc.) that may be implemented between the various elements of the system.

[0065] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example rather than limitation, a terminal device may also be referred to as a communication device, user equipment (UE), a Subscriber Station (SS), a Portable Subscriber Station, a mobile device, a Mobile Station (MS), or an Access Terminal (AT). The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA), portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), USB dongles, smart devices, wireless customer-premises equipment (CPE), a machine-type communications (MTC) device, an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a data consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. The terminal device may also correspond to a Mobile Termination (MT) part of an Integrated Access and Backhaul (IAB) node (e.g., a relay node). In the following description, the terms“terminal device”, “communication device”, “terminal”, “user device”, “user equipment” and “UE” may be used interchangeably.

[0066] As used herein, the term “network device” is used interchangeably with “network access node”, and refers to a node in a communication network via which a terminal device accesses the network and receives services therefrom. The network device may refer to a base station (BS) or an access point (AP), for example, a node B (NodeB or NB), an evolved NodeB (eNodeB or eNB), an NR NB (also referred to as a gNB), a Remote Radio Unit (RRU), a radio header (RH), a remote radio head (RRH), a relay, an Integrated Access and Backhaul node, a low power node such as a femto, a pico, a non-terrestrial network (NTN) or non-ground network device such as a satellite network device, a low earth orbit (LEO) satellite and a geosynchronous earth orbit (GEO) satellite, an aircraft network device, and so forth, depending on the applied terminology and technology. In some example embodiments, radio access network (RAN) split architecture comprises a Centralized Unit (CU) and a Distributed Unit (DU) at an IAB donor node. An IAB node comprises a Mobile Terminal (IAB-MT) part that behaves like a UE toward the parent node, and a DU part of an IAB node behaves like a base station toward the next-hop IAB node.

[0067] In some example embodiments, a link from the network device 120 to the user device 110 or 115 is referred to as a DL, while a link from the user device 110 or 115 to the network device 120 is referred to as a UL. Links are also referred to herein as “channels”. In DL, the network device 120 is a Tx device (or a transmitter), and the user device 110 or 115 is a Rx device (or a receiver). In UL, the user device 110 or 115 is a Tx device (or a transmitter), and the network device 120 is a Rx device (or a receiver). A link between the user device 110 and another user device (not shown) is referred to as a sidelink (SL). In SL, one of the user devices is a Tx device (or a transmitter), and the other of the user devices is a Rx device (or a receiver).

[0068] Communications in the communication environment 100 may be implemented according to any proper communication protocol(s), comprising, but not limited to, cellular communication protocols of the first generation (1 G), the second generation (2G), the third generation (3G), the fourth generation (4G), the fifth generation (5G), the sixth generation (6G), and the like, wireless local network communication protocols such as Institute for Electrical and Electronics Engineers (IEEE) 802.11 and the like, and / or any other protocols currently known or to be developed in the future. Moreover, the communication may utilize any proper wireless communication technology,comprising but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple (OFDM), Discrete Fourier Transform spread OFDM (DFT-s-OFDM) and / or any other technologies currently known or to be developed in the future.

[0069] Of the above-mentioned communication protocols, at least some of these define cells provided by network access nodes that are configured to only provide services to a limited number of and / or type of terminal. For clarity and brevity in the following, the following may use the terms “cell” and “network access node” interchangeably.

[0070] For example, 4G defines closed subscriber group (CSG) methods for femto nodes while 5G defines closed access group (CAG) methods for network access nodes of non-public networks (NPNs). As CSG and CAG are similar concepts, only CAG will be discussed herein with reference to network access nodes of NPNs. However, it is understood that the presently described techniques may be applied both to CSG as well as to any other type of deployment in which a network access node is configured to not provide access to one or more UE or is configured to provide access to only a limited group of UEs.

[0071] CAG methods were originally introduced in the context of public network integrated non-public networks (PNI-NPNs) for preventing UE(s) that are not allowed to access an NPN via the associated cell(s) from automatically selecting and accessing the associated cell(s) configured in CAG mode. CAG-based access control was introduced in 3GPP Release-16. The existing 5G concept of PNI-NPN and of CAG cells is described in TS 23.501 clause 5.30.3.1 , and TS 38.300 clause 16.7. Further, the existing 5G concept of PNI-NPN and of CAG cells is described in TS 23.501 clause 5.30.3.1. CAG information changes in the home PLMN are described in TS 23.502 clause 4.2.4.2. Further references regarding CAG specification are TS 24.501 .

[0072] In general, an NPN is a network that is intended for the non-public (or private) use, although it is understood that an operator of an NPN may lease use of the NPN to other operators. While there are many possible configurations of NPNs, 3GPP defines two major categories of NPNs: Standalone Non-Public Network (SNPN) and Public network integrated NPN (PNI-NPN).

[0073] An SNPN may be considered as an NPN that does not rely on network functions provided by a Public Land Mobile Network (PLMN). In contrast, a PNI-NPN may be considered as an NPN that is deployed with the support of a PLMN. For example, a PNI-NPN may be deployed as a private slice (e.g., as a dedicated network slice by the PLMN for the sole use of the owner). As another example, the PNI-NPN may be comprised of part of a network deployed by a PLMN and parts of a network deployed by the owner.

[0074] A network access node in an NPN may be configured to operate in any of three different access modes: an open access mode, a closed access mode, and a hybrid access mode. In the open access mode, non-subscribing UEs are unconditionally allowed to access a network access node’s resources along with the network access node’s subscribing UEs. In the closed access mode, only a network access node’s subscribing UEs are allowed to access the network access node’s resources. In the hybrid access mode, in addition to allowing the network access node’s subscribing UEs to access the network access node’s resources, the network access node’s also allows a limited number of non-subscribing UEs to use a limited number of the network access node’s resources.

[0075] A network access node of an NPN (also referred to as an NPN network access node herein) maintains a list of CAG identifiers that are allowed to access specific services via the NPN network access node. The list of CAG identifiers comprises one or more identifiers of CAGs that are authorized to access the network service through that network access node. The list of CAG identifiers may be cell-specific. For example, a CAG identifier may correspond to one or more specific services (e.g., all or less than all) that are accessible for CAG group members through a specific cell. The network operator creates and manages this access control list of CAG identifiers. The access control list of CAG identifiers is stored in the network's database and is updated by the network operator as needed. The access control list of CAG identifiers can be configured to allow or deny access to specific network services for each CAG identifier on the access control list of CAG identifiers.

[0076] In order to access services via an NPN network access node of a CAG, a terminal having a subscription to a specific CAG is configured with the CAG identifier corresponding to that CAG. A UE’s CAG membership(s) is configured in the user subscription data in the network (which forms part of the UE’s context information) and on the terminal. The collection of CAG identifiers maintained at the UE thatcorresponds to the UE’s CAG memberships is referred to herein as a “UE allowed CAG list”.

[0077] In more detail, when a UE tries to connect to a NPN cell of a CAG (e.g., when the UE believes itself to be configured with a CAG identifier corresponding to a transmitted CAG identifier), the network (e.g., an access and mobility function) checks whether the UE is allowed to do so, based on the subscription data for that terminal. This may be performed by the access and mobility function comparing the CAG identifiers of the NPN cell to the UE allowed CAG list maintained in the UE’s context information that is stored at, or otherwise accessible to, the access and mobility function. When at least one CAG identifier is common to both the CAG identifiers of the NPN cell and the UE allowed CAG list, the access and mobility function provides the UE context (including a mobility restriction list (see below) that comprises the UE allowed CAG list) to the NPN cell. The NPN cell may later use this UE allowed CAG list when later making a mobility decision.

[0078] When a UE is roaming, access control may be performed in the visited network (e.g., in a visited PLMN (VPLMN)) based on CAG IDs configured in the VPLMN. The UE may be provisioned with the allowed visited CAG cell access information for accessing the visited network as part of its UE allowed CAG list.

[0079] Reference in the below is made to mobility restrictions and mobility restriction lists. The following provides an overview of some of these concepts.

[0080] Mobility restriction functionality provides restrictions to mobility handling or service access of a UE. The mobility restriction information and / or functionality is provided by a UE, a network access node, and at least one core network function.

[0081] A UE’s mobility restriction information comprises information that identifies at least one network access node and / or cell provided by a network access node that the UE is authorised to access at least one service through. Stated differently, a UE’s mobility restriction information comprises information indicating at least one network access node and / or at least one cell via which the UE has a subscription to receive a service.

[0082] When the UE is in a connection management- (CM-) CONNECTED state with a network (e.g., a network according to any of Figures 1A to 1 B), the core network provides mobility restriction information of the UE to the radio access network within a Mobility Restriction List (MRL). In general, the MRL information element (IE) may be considered as defining roaming or access restrictions for subsequent mobility actionfor which a network access node (e.g., a next generation radio access network (NG- RAN)) provides information about the target of the mobility action towards a UE. Example mobility actions may comprise, for example, handover, and / or secondary cell group (SCG) selection during a dual connectivity operation. The network access node behaviour upon receiving this IE is specified in TS 23.501.

[0083] The MRL may comprise mobility restrictions, including restrictions that are based on (e.g., dependent on) one or more of radio access technology (RAT) restriction, Forbidden Area, Service Area Restrictions, Core Network type restriction and Closed Access Group information.

[0084] With respect to the CAG information in an MRL, a UE that supports CAG may be pre-configured or (re)configured with at least one of a) to c) of the following CAG information, included in the subscription as part of the Mobility Restrictions: a) an Allowed CAG list (e.g., a list of CAG Identifiers the UE is allowed to access); and b) each entry of the Allowed CAG list may be associated with time validity information containing one or more time periods; and c) a CAG-only indication whether the UE is only allowed to access 5GS via CAG cells.

[0085] Figure 2 illustrates an example of a control apparatus 200 for controlling a function of the access network (e.g., a 5G-RAN or the NG-RAN illustrated in Figures 1A and 1 B) illustrated on Figures 1A and 1 B. The control apparatus 200 may comprise at least one random access memory (RAM) 211 a, at least on read only memory (ROM) 211 b, at least one processor 212, 213 and a network interface 214. The at least one processor 212, 213 may be coupled to the RAM 211a and the ROM 211 b. The at least one processor 212, 213 may be configured to execute an appropriate software code 215. Execution of the software code 215 may for example may cause the apparatus to perform operations for controlling a function of the access network. The software code 215 may be stored in the ROM 211 b. The control apparatus 200 may be interconnected with another control apparatus 200 for controlling another function of the 5G-RAN or the NG-RAN. In some example embodiments, each function of the 5G- RAN or the NG-RAN is deployed or hosted on a control apparatus 200. In alternative example embodiments, two or more functions of the 5G-RAN or the NG-RAN may share a control apparatus.

[0086] Figure 3 illustrates an example of a communication device 300, such as the UE illustrated on Figures 1A and 1 B. The communication device 300 may be provided by any device capable of sending and receiving radio signals. Non-limiting examples of a communication device 300 comprise a user equipment, a mobile station (MS) or mobile device such as a mobile phone or what is known as a ’smart phone’, a computer provided with a wireless interface card or other wireless interface facility (e.g., USB dongle), a personal data assistant (PDA) or a tablet provided with wireless communication capabilities, a machine-type communications (MTC) device, an Internet of things (loT) type communication device or any combinations of these or the like. The communication device 300 may comprise a transceiver for transmitting and / or receiving, for example, wireless signals carrying communications, for example radio signals. The communications may be one or more of voice, electronic mail (email), text messages, multimedia data, machine data and so on.

[0087] The communication device 300 may receive wireless signals (e.g., radio signals) over an air or radio interface 307 via appropriate apparatus for receiving and may transmit wireless signals via appropriate apparatus for transmitting radio signals. In Figure 3 transceiver is designated schematically by block 306. The transceiver 306 may comprise, for example, a radio part and associated antenna arrangement. The antenna arrangement may be arranged internally or externally to the mobile device and may comprise one or more antenna elements. The antenna arrangement may be a multi-input multi-output (MIMO) antenna.

[0088] The communication device 300 may be provided with at least one processor 301 , memory 302 comprising at least one memory ROM 302a, at least one RAM 302b and other possible components 303 for use in software and hardware aided execution of tasks it is designed to perform, including control of access to and communications with access networks (e.g., the 5G-RAN or NG-RAN illustrated in Figures 1A and 1 B) and other communication devices. The at least one processor 301 is coupled to the RAM 302b and the ROM 302a. The at least one processor 301 may be configured to execute an appropriate software code 308. The software code 308 may for example allow to perform one or more operations of the communication device. The software code 308 may be stored in the ROM 302a.

[0089] The processor, the ROM, and the RAM, the transceiver and other circuitry of the communication device (e.g., a modem) can be provided on a circuit board, in chipsets, or in a system on chip. The circuit board, chipsets or system on chip isdenoted by reference 304. The communication device 300 may optionally have a user interface such as keypad 305, touch sensitive screen or pad, combinations thereof or the like. Optionally one or more of a display, a speaker and a microphone may be provided depending on the type of communication device.

[0090] 3GPP plans to reuse the PNI-NPN deployment architecture for new radio (NR) femto nodes, including for access control of UEs to the femto nodes, in 5G and beyond. If the PNI-NPN solution is reused, this means that, as described above, a mobility restriction list (MRL) information element (IE) containing the UE Allowed CAG List for the connecting UE will be sent from an AMF to a femto node for use by the femto node when making mobility decisions.

[0091] However, this may be disadvantageous when the femto node is either untrusted, or is deployed in untrusted environments.

[0092] For example, a femto node may be deployed at some end user locations in untrusted environment. In such a case, the sending of the UE Allowed CAG List to a femto node could lead to a privacy issue.

[0093] However, not providing an untrusted femto node with the UE allowed CAG list may also lead to issues. This is illustrated in the following examples.

[0094] A first example considers outbound handovers from a source network access node to a private femto node using the current PNI-NPN deployment. Such a scenario would result in access control being performed at the source network access node. Stated differently, in this scenario, the source network access node would be configured to compare the UE Allowed CAG List with the list of CAG IDs supported by target cell. The source network access node should perform this comparison in order to avoid triggering handovers towards a femto node that will not admit the UE for access. However, if the source network access node is an untrusted femto node, the source network access node will not receive the UE Allowed CAG List due to privacy reasons, and so cannot perform the comparison.

[0095] A second example considers inbound handovers from a source network access node to a target network access node using the current PNI-NPN deployment. Such a scenario would result in the target network access node performing a second access control check at the target network access node (e.g., comparing the UE Allowed CAG List with the list of CAG IDs supported by target cell). However, if the target network access node is a closed femto node, the target femto node cannot perform this second inbound access control check as the target femto node does not receive the UEAllowed CAG List from AMF in the incoming Handover Request message due to the above-mentioned privacy reasons.

[0096] Analogous issues may apply in respect of other types of nodes (e.g., non-femto nodes) that are untrusted and / or that are in an untrusted environment.

[0097] The following aims to address one or more of the above-mentioned issues.

[0098] In general, the following proposes methods for use for complying with the access control requirements of a UE to access untrusted network access nodes without sending the UE Allowed CAG List to those untrusted network access nodes.

[0099] Stated differently, the following describes scenarios in which a core network function (such as an access and mobility function) is configured to provide access information to a network access node for enabling the network access node to provide a service to a UE through the network access node, where the access information comprises a level (e.g., a degree) of mobility restriction information that it determined based on how trustworthy the network access node is considered to be to the core network function.

[0100] As in the case above, the following will refer to femto nodes when referring to untrusted network access nodes. However, it is understood that this is merely for clarity and brevity, and that the presently described techniques may be applied to any other type of network access node that is untrusted and / or that is in an untrusted environment. It is further understood that while not all femto nodes are untrusted, the following will use the term “femto node” to represent those network access nodes that are untrusted (e.g., that are not under network operator control).

[0101] The core network function may evaluate how trustworthy a network access node is based on at least one criterion. Therefore, the following describes a core network function that can determine a degree of mobility restriction information of a UE to provision at a network access node based on whether that network access node fulfils at least one criterion.

[0102] For example, the core network function may be configured to treat network access nodes of a first type (e.g., femto nodes) as being untrusted for receiving complete mobility restriction information for a UE, and to treat all other types of network access nodes as being trusted for receiving complete mobility restriction information. Consequently, in an example, the core network function may be configured to determine whether a network access node is of a first type (e.g., fulfils a criterion of being configured as a first type of network access node), and to provision a degree ofmobility restriction information at the network access node based on that determination. It is understood that a one or more (e.g., a plurality) of types of network access nodes may be preconfigured in the core network function as being untrusted for receiving complete mobility restriction information for a UE.

[0103] Analogously, the core network function may be preconfigured to treat one or more (e.g., a plurality) of types of network access nodes of a second type as being trusted for receiving complete mobility restriction information for a UE. In this case, only those types of network access nodes that are preconfigured as being trusted may be provided with complete mobility restriction information. Stated differently, only those network access nodes that are determined to fulfil a criterion of being the second type of network access node are provided with complete mobility restriction information for a UE.

[0104] As another example, the core network function may be preconfigured with a list of network access node identifiers that identify which network access nodes are trusted for receiving complete mobility restriction information for a UE, and / or be preconfigured with a list of network access node identifiers that identify which network access nodes are not trusted for receiving complete mobility restriction information for a UE. In such a case, determining whether the at least one criterion is fulfilled may comprise determining whether a network access node’s identifier is comprised in such a list.

[0105] There may also be different degrees to which mobility restriction information for a UE is provided. For example, the core network function may be configured to provide: no mobility restriction information, complete mobility restriction information, or a restricted version of the mobility restriction information (e.g., as described above). The restricted version of the mobility restriction information may not comprise closed access group information of the UE.

[0106] In operation, the core network function may receive a request for access for a UE to receive a service through a network access node, perform an evaluation as to the degree of mobility restriction information to be provided (e.g., based on whether the at least one network access node fulfils at least one criterion), and provide access information to the network access node for enabling the UE to receive the service, wherein the access information comprises the determined degree of mobility restriction information of the UE (e.g., full, none, or restricted). The network accessnode may use the provided access information to provide a service to the UE through the network access node.

[0107] As the network access node may comprise incomplete mobility restriction information for the UE (e.g., no mobility restriction information or the restricted version of the mobility restriction information), the network access node may request that the core network function assist in mobility operations (such as, for example, handover, dual connectivity, multi-Transmission Reception Point (mTRP), etc.) by determining whether the UE’s mobility restriction information indicates that the UE is allowed to access one or more cells.

[0108] Figures 4 to 6 consider how such principles may be deployed in example apparatus, before a more general overview of features of these examples is illustrated with respect to Figures 7 to 9.

[0109] Figure 4 illustrates signalling that may be performed between a UE 401 , a source network access node 402, and an AMF 403.

[0110] During 4001 , the UE 401 maintains a UE allowed CAG list (CAG1 , CAG2, CAG3). The UE allowed CAG list lists the CAGs to which the UE 401 is allowed access. The UE may be allowed access to those CAGs because the UE has a subscription to those CAGs listed in the UE allowed CAG list. The UE allowed CAG list may be maintained in UE context. The UE allowed CAG list may be maintained in UE context stored at both the UE 401 and at the AMF 403.

[0111] During 4002 the AMF 403 is configured (e.g., by the network operator) to abstain from sending the UE Allowed CAG List to the source network access node upon the AMF determining that the source network access node fulfils one or more criteria for being an untrusted node. For example, considering the case where femto nodes are defined as being untrusted nodes in the AMF 403, the AMF 403 may be configured to abstain from sending the UE allowed CAG list to the source network access node 402 when the AMF receives one or more of the following in a message from the source network access node: a femto node identifier, a femto node indicator, one or more specific CAG identifier(s), and / or a specific value of a network access node identifier. In some examples, the message from the source network access node is an NGAP Initial UE Message message.

[0112] During 4003, the UE 401 transmits a connection request to the source network access node.

[0113] During 4004, based on receiving the service request of 4003, the source network access node 402 signals a Next Generation Application Protocol (NGAP) INITIAL UE MESSAGE message to the AMF 403.

[0114] The NGAP initial UE Message message is currently defined in 3GPP specifications (see, for example, TS 38.413). In general, a network access node initiates a procedure to obtain access information for a UE from an AMF by sending an NGAP INITIAL UE MESSAGE message to the AMF. The network access node allocates a unique radio access network UE identifier (e.g., a radio access network UE NGAP ID) to be used for the UE , and include this UE identifier in the NGAP INITIAL UE MESSAGE message. Although there are a plurality of fields that may be comprised in the NGAP INITIAL UE MESSAGE message, only a few are discussed below for brevity: the non-access stratum protocol data unit (NAS-PDU), and the PNI-NPN information.

[0115] The NAS-PDU IE contains a UE AMF message that is transferred without interpretation in the NG-RAN node. The NAS-PDU originated from the UE when the UE requested a service during 4003.

[0116] If PNI-NPN related information within the NPN Access Information IE is received in the INITIAL UE MESSAGE message, the AMF shall, if supported, consider that the included (e.g., a list of CAG identifiers that identify CAGs maintained by the source network access node) information is associated to the cell via which the UE has sent the first NAS message, and to the PLMN Identity which is indicated within a tracking area indicator (TAI) IE of the Initial UE message, and use the included information as specified in TS 23.501 .

[0117] In addition to fields such as, for example, the NAS PDU and the PNI-NPN related information, the signalling of 4004 may further comprise a network access node identifier (e.g., a gNB identifier) of the source network access node and / or a femto indicator that indicates that the source network access node is a femto node. It is particularly useful to include identifying information of the source network access node in the NGAP INITIAL UE MESSAGE message as this means that the information will be provided to the AMF 403 regardless of whether the NGAP INITIAL UE MESSAGE message is passed to the AMF 403 via a proxy function (e.g., via a proxy femto gateway). Stated differently, by comprising the identity and / or type information for the source network access node as part of a request for a UE context, the AMF403 may be able to extract the identity and / or type information from the received request.

[0118] During 4005, the AMF 403 performs access control by comparing the List of CAG IDs received during 4004 with the UE Allowed CAG ID list.

[0119] During 4006, assuming the access control check of 4005 is successful, the AMF 403 determines to send the NGAP Context Setup Request to the source network access node and further makes a determination regarding whether to comprise a restricted version of the RL in the context setup request, where the restricted version of the MRL is a reduction of an original MRL to exclude those CAG IDs comprised on the UE Allowed CAG List), or whether to not comprise any MRL in the context setup request. The restricted version of the MRL may alternatively be labelled as a “limited MRL”, a “limited version of the MRL”, “a reduced MRL”, or “a reduced version of the MRL”, and it is understood that these terms may be used interchangeably throughout the present description. The restricted version of the MRL comprises some, although not all of the mobility restriction information comprised in the original MRL.

[0120] The determination regarding whether to comprise a restricted version of the MRL in the context setup request and / or to not comprise any MRL in the context setup request may be made based on a determination as to whether the source network access node is trusted or untrusted. When the source network access node is determined to be trusted, the AMF is configured to provide a complete MRL to the source network access node. When the source network access node is determined to be untrusted, then the AMF is configured to provide either a restricted version of the MRL (e.g., excluding the UE allowed CAG list) to the source network access node, or no MRL at all.

[0121] The network operator may set any type of criteria for determining whether a source network access node (such as the source network access node) is trusted or not.

[0122] For example, an AMF may be configured to comprise a database that lists trusted network access nodes. In such a case, the AMF may compare the received network access node identifier in the NGAP INITIAL UE MESSAGE message to the identifiers of trusted network access nodes listed in the database. If the network access identifier comprised in the NGAP INITIAL UE MESSAGE message is not listed in the database, the source network access node may be determined to be untrusted. In another example, the AMF is configured to comprise a database that lists untrustednetwork access nodes. In such a case, the AMF may compare the received network access node identifier in the NGAP INITIAL UE MESSAGE message to the identifiers of untrusted network access nodes listed in the database. If the network access identifier comprised in the NGAP INITIAL UE MESSAGE message is not listed in the database, the source network access node may be determined to be trusted.

[0123] As another example, the AMF may be configured to classify certain categories of network access nodes as untrusted. For example, in the present example, an AMF may be configured to classify all femto nodes as being untrusted.

[0124] It is further understood that such criteria may be combined. For example, an AMF may be configured to classify a femto node as being untrusted unless that femto node’s identifier is comprised on a database of trusted network access nodes and / or trusted femto nodes.

[0125] In the present example of Figure 4, the AMF 403 is configured to classify all femto nodes as being an untrusted network access node.

[0126] The following lists some factors that may be used by an AMF to determine whether a network access node is a femto node (e.g., whether the network access node is untrusted according to one or more of the following factors or criteria):Whether at least one CAG identifier is received in the NGAP INITIAL UE MESSAGE message: For example, if a CAG identifier is received in the NGAP INITIAL UE MESSAGE message, then the AMF may determine that the requesting entity is a femto node.Whether one or more particular values of CAG identifiers have been received in the NGAP INITIAL UE MESSAGE message: For example, certain CAG identifiers may correspond to only femto nodes. The AMF may be configured with a list of such CAG identifiers (e.g., during 4002), and use such a list to identify a femto node.Whether a femto indicator is comprised in the NGAP INITIAL UE MESSAGE message: For example, the femto indicator comprises an enumerated value that indicates (e.g., explicitly indicates) whether the source network access node is a femto node.Whether a gNB Identifier was received in the NGAP INITIAL UE MESSAGE message and whether the AMF was configured during 4002 to send an incomplete MRL (e.g., a restricted version of the MRL or no MRL) without the UE Allowed CAG List or no MRL at all for this gNB Identifier.Whether both a femto indicator and a network access node identifier are comprised in the NGAP INITIAL UE MESSAGE message and whether the AMF has been configured during 4002 to send a restricted version of the MRL without the UE Allowed CAG List or no MRL at all if the femto indicator is received together with this network access node identifier: For example, the network may use the configuration of 4002 (including any lists of trusted and / or untrusted network access nodes) to determine whether a specific source network access node is untrusted and / or to what degree (e.g., partially trusted (in which a MRL excluding the UE allowed CAG list is provided) or untrusted (in which no MRL is provided to the UE)).

[0127] When the latter determination of 4006 determines that the source network access node is untrusted (e.g., the at least one criterion is fulfilled), then the method proceeds to 4007.

[0128] During 4007A, the AMF 403 responds to the signalling of 4004. This signalling comprises an NGAP Initial Context setup request. This signalling does not comprise any MRL, or comprises a restricted version of the MRL (e.g., excluding the UE allowed CAG list).

[0129] When the latter determination of 4006 determines that the source network access node is trusted (e.g., the at least one criterion is not fulfilled), the method proceeds to 4007B.

[0130] During 4007B, the AMF 403 responds to the signalling of 4004. This signalling comprises an NGAP Initial Context setup request. This signalling comprises a complete MRL (e.g., an MRL that comprises the UE allowed CAG list).

[0131] Figure 5 illustrates another (second) example.

[0132] In this second example, the UE Allowed CAG List of a UE is not present in the source network access node (e.g., either a restricted version of the MRL or no MRL is received), and the source network access node decides to handover this UE to target network access node.

[0133] Figure 5 illustrates signalling that may be performed between a UE 501 , a source network access node 502, and an AMF 503.

[0134] During 5001 , the UE 501 maintains an allocated UE allowed CAG list (CAG1 , CAG2, CAG3). This may be as described above in 4001 .

[0135] During 5002, the AMF is configured with, for a plurality of network access nodes, a list of CAG IDs corresponding to a particular network access node identifier. This configuring may be performed by a network operator.

[0136] During 5003, the UE 501 is in a radio resource control connected state (e.g., RRC_CONNECTED) and / or CM_CONNECTED state with the source network access node 502. The source network access node has received either a restricted version of the MRL or no MRL (e.g., as per the signalling of Figure 4). The source network access node 502 is therefore unaware of the U E Allowed CAG List of this UE.

[0137] During 5004, the UE 501 provides at least one measurement result to the source network access node 502. The at least one measurement result may indicate a strength of a signal received at the UE from target network access node (e.g., from a target network access node). The at least one measurement result may indicate a strength of a signal received at the UE from the source network access node 502. The at least one measurement result may be comprised in a single report (e.g., during signalling provided at only a first time) or in multiple reports (e.g., during signalling provided during at least a first time and a second time).

[0138] During 5005, the source network access node identifies (e.g. based on 5004) that it would be beneficial to trigger a handover of this UE to the target network access node. This identification may be performed based on the at least one measurement report received during 5004.

[0139] Prior to triggering any handover to the target network access node, the source network access node 502 determines whether the target network access node is configured to accept the UE 501 for receiving services via that target network access node. This is represented by steps 5006 to 5008, which are performed prior to the handover decision being completed. The signalling of 5006 to 5008 are in contrast to prior systems in which the source network access node performs on its own (i.e. without signalling to the AMF) the check of whether the target network access node is configured to accept the UE for receiving services.

[0140] During 5006, the source network access node 502 signals the AMF 503. This signalling may comprise a request for the AMF 503 to perform a mobility restriction check. Stated differently, this signalling may request that the AMF determines whether the target network access node is configured to accept the UE 501 . The signalling of 5006 may comprise a UE identifier (e.g. the NGAP connection identifier mentioned above) and an identifier of the target network access node (e.g., an identifier of the target network access node). One particular advantage to signal this identifier of the target network node is when the target network access node is a femto which is connected to AMF via a proxy (e.g., a femto gateway).

[0141] During 5007, the AMF 503 uses the received UE identifier to retrieve mobility information for the UE 502 (e.g., the mobility restriction list, which comprises the UE allowed CAG list). The AMF 503 then evaluates whether there are any CAGs listed on the UE allowed CAG list and on the list of CAG identifiers supported by the target access node (e.g., configured during 5002) that are common to both lists.

[0142] When there is at least one common CAG identifier shared by these two lists, the AMF 503 signals the source network access node during 5008 to indicate that handover of the UE 501 to the target network access node may proceed. When there are no common CAG identifiers between these two lists, the AMF signals the source network access node 502 during 5008 to indicate that handover of the UE 501 to the target network access node should not proceed. The signalling of 5008 may be labelled as a Mobility Verification Response message.

[0143] During 5009, the source network access node 502 performs an action based on the signalling of 5008. For example, when the signalling of 5008 indicates that handover of the UE 501 to the target network access node may proceed, the source network access node 502 triggers signalling for initiating the handover of the UE 501 from the source network access node 502 to the target network access node during 5009. As an example, when the signalling of 5008 indicates that the handover of the UE 501 to the target network access node should not proceed, the source network access node 502 does not perform any signalling for initiating the handover of the UE 501 from the source network access node 502 to the target network access node.

[0144] Figure 6 illustrates an example in which the target network access node of Figure 5 performs checks during handover regarding whether to accept the handover of the UE from the source network access node to the target network access node based on mobility restrictions of the UE. In this example of Figure 6, the target network access node is an untrusted network access node by the AMF.

[0145] Figure 6 illustrates signalling that may be performed between a UE 601 , a target network access node 602, an AMF 603, and a source network access node 604.

[0146] During 6001 , the UE is configured with a UE allowed CAG list (e.g, CAG1 , CAG2, CAG3). This may be as described above in connection to 4001 and / or 5001 .

[0147] During 6002, the AMF 603 is configured with a list of CAG identifiers supported by (e.g., corresponding to) an identifier of the target network access node 602. This configuration may be performed by a network operator (e.g., via an operations and management function).

[0148] At least one of 6003A or 6003B may be performed.

[0149] During 6003A, the target network access node 602 receives a handover request from the AMF 603 for a handover of the UE 601 from the source network access node 604. The handover request either comprises no MRL, or a restricted version of the MRL list (e.g., an MRL that does not comprise any UE allowed CAG list).

[0150] During 6003B, the target network access node 602 receives a handover request from the source network access node 604 for a handover of the UE 601 from the source network access node 604. The handover request either comprises no MRL, or a restricted version of the MRL list (e.g., an MRL that does not comprise any UE allowed CAG list).

[0151] Before accepting the incoming handover, the target network access node determines to perform mobility verification in an analogous manner to that performed by the source network access node of Figure 5. This is represented by the signalling of 6004 to 6006.

[0152] During 6004, the target network access node 602 signals the AMF 603. This signalling may comprise a Mobility Verification Request message. The mobility verification request message may comprise a UE identifier of the UE (e.g. the NGAP connection identifier) and an identifier of the target network node. One particular advantage to signal this identifier of the target network node is when the target network access node is a femto node that is connected to the AMF via a proxy (e.g. a femto gateway).

[0153] During 6005, the AMF 603 determines or uses the received UE identifier to retrieve mobility information for the UE 601 (e.g., the mobility restriction list, which comprises the UE allowed CAG list). The AMF 603 then evaluates whether there are any CAGs listed on the UE allowed CAG list and on the list of CAG identifiers supported by the target network access node (e.g., configured during 6002) that are common to both lists.

[0154] When there is at least one common CAG identifier shared by these two lists, the AMF 603 signals the target network access node during 6006 to indicate that handover of the UE 601 to the target network access node may proceed. When there are no common CAG identifiers between these two lists, the AMF signals the target network access node 602 during 6006 to indicate that handover of the UE 601 to thetarget network access node should not proceed. The signalling of 6006 may be labelled as a Mobility Verification Response message.

[0155] During 6007, the target network access node 602 performs an action based on the signalling of 6006. For example, when the signalling of 6006 indicates that handover of the UE 601 to the target network access node may proceed, the target network access node 602 signals back to the A F 603 and / or to the source network access node during 6008 that it accepts the handover. As another example, when the signalling of 6006 indicates that the handover of the UE 601 to the target network access node should not proceed, the target network access node 602 signals back to the AMF 603 and / or to the source network access node 604 during 6008 that it rejects the handover.

[0156] When the target network access node is a closed cell femto, the target network access node may be configured to only proceed with the handover when the received access control result is positive. In contrast, when the target network access node is a hybrid femto cell, the target network access node may prioritize this UE when the received access control result is positive.

[0157] Although Figure 6 is described in the context of handover, it is understood that analogous procedures may be performed for other mobility-related operations, such as dual connectivity operations and / or multi-transmission reception point (mTRP) operations. In each case, the target network access node may receive an indication that access for a UE through the target network access node is being requested (e.g., for dual connectivity and / or mTRP), and determine that the target network access node comprises incomplete mobility restriction information for that UE (e.g., the received indication and / or request does not comprise complete mobility restriction information for that UE: it may instead comprise incomplete mobility restriction information, such as no mobility restriction information for the UE or a restricted version of the UE’s mobility restriction information).

[0158] Based on this determination, the target network access node requests that a core network function (such as an AMF) determines whether the UE’s mobility restriction information indicates that access can be provided to the UE through the target network node for one or more services,. The target network access node either proceeds with the requested access or does not proceed with the requested access based on the determination performed by the AMF.

[0159] Figures 7 to 9 illustrate methods that may be performed by apparatus described herein.

[0160] Figures 7 to 9 illustrate methods that may be respectively performed by apparatus illustrated in the above. It is therefore understood that at least some of the features mentioned below may be better understood with reference to the above examples and explanation, particularly where the same terminology is used. It is further understood that terms used in Figures 7 to 9 may be understood with reference to each other.

[0161] Figure 7 illustrates a method that may be performed by an apparatus. The apparatus may comprise a core network function. The core network function may comprise the functionality of at least one of: an access function, an AMF, a UDM, a network function, or an NRF.

[0162] During 701 , the apparatus receives, from a first network access node, a request for access information for configuring the first network access node to provide a service to a user equipment. Stated differently, during 701 , the apparatus receives, from a first network access node, a request for access information for enabling the first network access node to provide a service to a user equipment. The first network access node may correspond to the first network access node to Figure 8.

[0163] During 702, the apparatus determines a degree of mobility restriction information to provide to the first network access node based on whether the first network access node fulfils one or more criterion for receiving incomplete mobility restriction information for the user equipment (e.g., one or more criterion for receiving either no mobility restriction information for the UE or a restricted version of the mobility restriction information for the UE).

[0164] For example, the apparatus may comprise one or more criterion that, when fulfilled, causes the apparatus to determine that full (e.g., complete) mobility restriction information is to be provided to the first network access node and, when not fulfilled, causes the apparatus to determine that a restricted version of the mobility restriction information or no mobility restriction information is to be provided to the first network access node.

[0165] As another example, the apparatus may comprise one or more criterion that, when fulfilled, causes the apparatus to determine that a restricted version of the mobility restriction information or no mobility restriction information is to be provided to the first network access node and, when not fulfilled, causes the apparatus todetermine that that full mobility restriction information is to be provided to the first network access node. The restricted version of the mobility restriction information and the no mobility restriction information may collectively be referred to as “incomplete mobility restriction information”, as they each contain less mobility restriction information than the complete mobility restriction information (e.g., the original MRL mentioned above)

[0166] The mobility restriction information may comprise mobility restriction information comprised in UE context data that is accessible to the apparatus of Figure 7. For example, the mobility restriction information may comprise mobility restriction information comprised in a UE’s subscription.

[0167] The mobility restriction information may comprise an indication of one or more CAG IDs supported by one or more network access nodes through which a UE is allowed to access one or more services (e.g., because the UE has a subscription to access those one or more services through that one or more cells and / or one or more network access nodes).

[0168] The mobility restriction information may comprise an indication of one or more cells and / or one or more network access nodes through which a UE is not allowed to access one or more services (e.g., because the UE does not have a subscription to access those one or more services through that one or more cells and / or one or more network access nodes).

[0169] The mobility restriction information may comprise the above-mentioned MRL. The mobility restriction information may comprise a UE allowed CAG list.

[0170] During 703, the apparatus provides, to the first network access node, access information that comprises the determined degree of mobility restriction information.

[0171] The apparatus may further be involved during later mobility-related operations.

[0172] For example, the apparatus may obtain, from the first network access node, a request for the core network function to determine whether the user equipment can be handed over to a target network access node. Based on this, the apparatus may determine whether the user equipment can be handed over to the target network access node by comparing mobility restriction information of the user equipment to mobility restriction information of the target network access node, and provide, the first network access node, the result of the determination of whether the user equipment can be handed over to the target network access node. The handover request may be specific for handover operations, or may be more general (e.g., the request may simplyrequest whether a UE can access the target network access apparatus for a specific service).

[0173] Analogously, the apparatus may be used to determine whether a target network access node can be used to provide dual connectivity-based access to the UE and / or operate as an mTRP-type of deployment. The only difference in these examples relative to the preceding paragraph is that the requests are either for these specific purposes (e.g., request for dual connectivity, request for MTRP check, etc.), or they simply request whether a UE can access the target network access apparatus for a specific service.

[0174] The criterion may comprise at least one of a list of access node identifiers for which the access information is to comprise at least one of no mobility restriction information or a restricted version of mobility restriction information, or a list of access node categories for which the access information is to comprise at least one of no mobility restriction information or a restricted version of the mobility restriction information. In some examples, the criterion may in contrast comprise at least one of a list of access node identifiers for which the access information is to comprise complete mobility restriction or a list of access node categories for which the access information is to comprise complete mobility restriction.

[0175] The request for access information may be a Next Generation Application Protocol, NGAP, Initial User Equipment, UE, Message message.

[0176] The request for access information may comprise at least one of an identifier of the first network access node or an identifier of a category of the first network access node, and wherein the degree of mobility restriction information is dependent on the at least one of identifier of the first network access node or the identifier of the category of first network access node comprised in the request for access. Stated differently, when the request for access information comprises at least one of an identifier of the first network access node or an identifier of a category of the first network access node, then these identifier(s) may be used to determine whether the at least one criterion is fulfilled.

[0177] As mentioned above, the at least one of an identifier of the first network access node or an identifier of a category of the first network access node may be comprised as an information element(s) inside the Next Generation Application Protocol, NGAP, Initial User Equipment, UE, Message message. This may be useful where the NGAPInitial UE message message is routed through at least one proxy in order to continue to identify the first network access node.

[0178] The degree of mobility restriction information comprised in the access information may comprise: no mobility restriction list; a mobility restriction list; or an restricted version of the mobility restriction list. The restricted version of the mobility list may comprise some, but not all, of the mobility restriction list. For example, the mobility restriction list may not comprise closed access group information for the user equipment.

[0179] The apparatus of Figure 7 may provide a handover request to a target network node, such as the target network node of Figure 9. The handover request may comprise a restricted version of the mobility restriction list and / or no mobility restriction list.

[0180] Figure 8 illustrates a method that may be performed by an apparatus. The apparatus may be comprised in functionality of a first network access node (such as the first network access node described in connection with Figure 8). The first network access node may be a network access node as described in connection with Figures 1A, 1 B, and 2. The first network access node may comprise a femto node. The first network access node may comprise a gNB. The first network access node may comprise a femto node configured to operate in a closed access mode or a hybrid access mode.

[0181] During 801 , the apparatus provides, to a core network function, a request for access information for configuring a first network access node to provide a service to a user equipment. The core network function may comprise the functionality of the apparatus of Figure 7. The request for access information may be as described above in connection with Figure 7.

[0182] During 802, the apparatus obtains, based on the request, access information comprising a degree of mobility restriction information that is dependent on the first network access node. The access information of 802 may be as described above in relation to Figure 7.

[0183] The apparatus of Figure 8 may use the access information to provide a service to the user equipment through the first network access node.

[0184] The apparatus of Figure 8 may perform at least one mobility operation in relation to a target network access node.

[0185] For example, the apparatus of Figure 8 may identify a handover opportunity to handover the user equipment from the first network access node to a target network access node, determine that the obtained mobility restriction information is incomplete, and based on the determining that the mobility restriction information is incomplete, providing, to the core network function, before triggering the handover, a request for the core network function to determine whether the user equipment can be handed over to the target network access node.

[0186] The apparatus may determine that the obtained mobility restriction information of 802 is incomplete by determining that at least one field is absent compared to expected mobility restriction fields. For example, the apparatus may determine that the obtained mobility restriction information is incomplete because a CAG list for the UE (e.g., UE allowed CAG list) is missing from the obtained mobility restriction information. As another example, the apparatus may determine that the obtained mobility restriction information is incomplete because no mobility restriction information was present in the access information obtained during 802.

[0187] The apparatus may obtain, from the core network function, an indication of whether the user equipment can be handed over to the target network access node based on said request, and either initiate handover to the target network access node (e.g., when the indication indicates that target network access node can be used for handover of the UE) or remove the target network access node as a candidate handover network access node (e.g., when the indication indicates that the target network node cannot be used for handover). When the indication indicates that the user equipment can be handed over, the apparatus may initiate handover by signalling, to the target network access node, a handover request, wherein the handover request comprises the obtained degree of mobility restriction information.

[0188] Analogously, the apparatus may use the core network function to determine whether a target network access node can be used to provide dual connectivity-based access to the UE and / or operate as an mTRP-type of deployment. The only difference in these examples relative to the preceding paragraphs is that the identified opportunities are for these specific purposes (e.g., identify an opportunity for dual connectivity, request for MTRP check, etc.), and that “handover” is replaced by these specific use cases.

[0189] In all of these use cases, the target access node may comprise a femto node configured to operate in a closed access mode or in a hybrid access mode.

[0190] Figure 9 illustrates a method that may be performed by an apparatus. The apparatus may be comprised in a target network access node The target network access node may be as described above in relation to Figures 7 and 8. The target network access node may be a network access node as described in connection with Figures 1 A, 1 B, and 2. The target network access node may comprise a femto node. The target network access node may comprise a gNB. The target network access node may comprise a femto node configured to operate in a closed access mode or a hybrid access mode.

[0191] During 901 , the apparatus obtains, from another network node, a handover request for handing over a user equipment from a source network access node to the apparatus. The source network access node may be the first network access node described above in relation to Figure 8. The another network node comprises at least one of the core network function of Figure 7 or the source network access node (e.g., the first network access node of Figure 8).

[0192] During 902, the apparatus determines that the handover request comprises incomplete mobility restriction information (e.g., no MRL or a restricted version of the MRL) for the user equipment.

[0193] During 903, based on the determining that the mobility restriction information is incomplete, providing, to a core network function, a request for the core network function to determine whether the user equipment can be handed over to the apparatus.

[0194] The apparatus may determine that the obtained mobility restriction information of 902 is incomplete by determining that at least one field is absent compared to expected mobility restriction fields. For example, the apparatus may determine that the obtained mobility restriction information is incomplete because a CAG list for the UE (e.g., UE allowed CAG list) is missing from the obtained mobility restriction information. As another example, the apparatus may determine that the obtained mobility restriction information is incomplete because no mobility restriction information was present in the handover request obtained during 901 .

[0195] The apparatus may obtain, from the core network function, an indication of whether the user equipment can be handed over to the apparatus based on said request, and based on the indication, either provide, to the another network node, an acceptance of the handover request, or provide, to the another network node, a refusal of the handover request. For example, when the indication indicates that the handovermay proceed and the apparatus is able to comply with any other requirements and / or constraints comprised in the handover request, then the apparatus may proceed with handover (and may, for example, send a handover accept message to the another network node). Otherwise, when at least one of the indication indicates that the handover may not proceed or the apparatus is unable to comply with any other requirements and / or constraints comprised in the handover request, then the apparatus does not proceed with handover (and may, for example, send a handover reject message to the another network node).

[0196] The above-described methods may be represented in 3GPP systems in any of a plurality of different ways. The following considers the type of language that may be used to represent at least one of the above-mentioned principles in 3GPP. It is understood that at least some of the presently described functionality may find functional correspondence with at least one of the features described above.

[0197] The following assumes:• The AMF is optionally pre-configured femto indication and / or gNB ID;• During service request procedure, a femto sends gNB ID or femto indicator to the AMF; and• The AMF decides to send restricted MRL (MRL without allowed CAG ID list) or no MRL based CAG IDs received from home gNB (gNB) and / or femto indicator and / or optional configuration done at AMF.

[0198] Figure 10 shows the message sequence where Restricted MRL or no MRL delivery at context setup.

[0199] With respect to Figure 10:• UE has been allocated UE Allowed CAG List (CAG1 , CAG2, CAG3). The operator may configure the AMF to not send the UE Allowed CAG List to the RAN node in the NGAP Context Setup upon receiving in the NGAP Initial UE Message a femto indicator, and / or particular values of CAG IDs and / or particular values of gNB IDs.• Upon service trigger from the UE (e.g. Service Request) the gNB includes in the NGAP Initial UE Message in addition to the NAS PDU the list of CAG IDs, and may newly include the gNB ID (gNB identifier) and / or a femto indicator if it is an NR femto.• the AMF performs access control by checking the received List of CAG IDs with the UE Allowed CAG ID list.• If the access control check at AMF is successful, the AMF decides to send the NGAP Context Setup Request to the gNB and newly makes a determination of whether to include a reduced MRL (i.e. mobility restriction list without the UE Allowed CAG List) or no MRL at all based on the following criteria:(i) At least one CAG ID is received in the NGAP Initial UE Message(ii) One or more particular values of CAG IDs have been received in the NGAP Initial UE Message as per configuration.(iii) A femto Indicator is received in the NGAP Initial UE Message(iv) A gNB Identifier was received in the NGAP Initial UE Message and the AMF has been configured to send a reduced MRL without the UE Allowed CAG List or no MRL at all for this gNB Identifier.(v) Both a femto indicator and a gNB Identifier are received in the NGAP Initial UE Message and the AMF has been configured to send a reduced MRL without the UE Allowed CAG List or no MRL at all if the femto indicator is received together with this gNB Identifier.• One of the above-mentioned criteria was met and therefore the AMF sends the NGAP Initial Context setup either with reduced MRL or with no MRL.

[0200] Figure 11 illustrates the message flow, where the UE Allowed CAG List of a UE is not present in the source femto (i.e. reduced MRL or no MRL received) and the source femto decides to handover this UE to a target closed NR femto.

[0201] With respect to Figure 11 :• The UE has been allocated UE Allowed CAG List (CAG1 , CAG2, CAG3). The operator may configure the AMF with the list of CAG IDs corresponding to a particular gNB ID.• UE is in the connected state (RRC_CONNECTED & CM_CONNECTED) in the source femto. The source femto has received reduced MRL or no MRL as per logic of example embodiment 1 and therefore doesn’t know the UE Allowed CAG List of this UE.• the source NR femto decides to trigger an handover of this UE to a target closed NR femto (e.g. due to received measurement reports from the UE).• The source femto newly triggers before the handover an NGAP procedure (e.g. Mobility Verification Request message) to the AMF including a UE identifier (e.g. the NGAP connection identifier) and the target gNB ID.• The AMF has been configured or has earlier received by some message from gNB the list of CAG IDs supported by this particular target gNB ID and the AMF performs access control for the UE i.e. comparing this list of CAG IDs supported by the target gNB with the UE Allowed CAG List of the UE.• The AMF further gives the result of the access control check to the source NR femto in the Mobility Verification Response message.• The source NR femto does not trigger the handover if the received access control result from AMF is negative.• The source NR femto triggers the handover if the received access control result from AMF is positive.

[0202] Figure 12 illustrates the message flow, where the UE Allowed CAG List is not present in the target NR femto.

[0203] With respect to Figure 12:The UE has been allocated UE Allowed CAG List (CAG1 , CAG2, CAG3). The operator may configure the AMF with the list of CAG IDs corresponding to a particular gNB ID.• The target femto receives a request for inbound handover (NGAP or XNAP Handover Request) from AMF or source femto for a UE and this Handover Request message includes no MRL or reduced MRL without UE Allowed CAG List.• The target femto newly triggers before accepting the handover an NGAP procedure (e.g. Mobility Verification Request message) to the AMF including a UE identifier (e.g. the NGAP connection identifier) and the target gNB ID.• The AMF has been configured or has earlier received by some message from gNB the list of CAG IDs supported by this particular target gNB ID and the AMF performs access control for the UE i.e. comparing this list of CAG IDs supported by the target gNB with the UE Allowed CAG List of the UE.• The AMF further gives the result of the access control check to the target NR femto in the Mobility Verification Response message.• The target NR femto (if closed femto) does not accept the handover (i.e. sends back handover failure may be with new failure cause e.g. “HgNB / femto AccessDenied” or any existing failure cause) if the received access control result is negative from the AMF.• The source NR femto (if Closed femto) accepts the handover (i.e. sends back handover request acknowledge) if the received access control result is positive from the AMF.

[0204] In case target femto is hybrid, the target femto takes also into account the result of the access control verification; if positive it can priotize the UE otherwise not.

[0205] It is understood in the above the term “obtaining” is used interchangeably with “receiving”. It is further understood that the term “providing” is used interchangeably with “transmitting”.

[0206] It is understood that references in the above to various network functions (e.g., to an AMF, an SMF, etc.) may comprise apparatus that perform at least some of the functionality associated with those network functions. Further, an apparatus comprising a network function may comprise a virtual network function instance of that network function.

[0207] It should be understood that the apparatuses may comprise or be coupled to other units or modules etc., such as radio parts or radio heads, used in or for transmission and / or reception. Although the apparatuses have been described as one entity, different modules and memory may be implemented in one or more physical or logical entities.

[0208] It is noted that whilst some example embodiments have been described in relation to 5G networks, similar principles can be applied in relation to other networks and communication systems. Therefore, although certain example embodiments were described above by way of example with reference to certain example architectures for wireless networks, technologies and standards, example embodiments may be applied to any other suitable forms of communication systems than those illustrated and described herein.

[0209] It is also noted herein that while the above describes example embodiments, there are several variations and modifications which may be made to the disclosed solution without departing from the scope of this disclosure.

[0210] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.

[0211] In general, the various example embodiments may be implemented in hardware or special purpose circuitry, software, logic or any combination thereof. Some aspects of the disclosure may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although the disclosure is not limited thereto. While various aspects of the disclosure may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.

[0212] As used herein, the term “circuitry” may refer to one or more or all of the following:(a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and(b) combinations of hardware circuits and software, such as (as applicable):(i) a combination of analog and / or digital hardware circuit(s) with software / firmware and(ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and(c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.”

[0213] This definition of circuitry applies to all uses of this term herein, including in any claims. As a further example, as used herein, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0214] The various example embodiments of this disclosure may be implemented by computer software executable by a data processor of the mobile device, such as inthe processor entity, or by hardware, or by a combination of software and hardware. Computer software or program, also called program product, including software routines, applets and / or macros, may be stored in any apparatus-readable data storage medium and they comprise program instructions to perform particular tasks. A computer program product may comprise one or more computer-executable components which, when the program is run, are configured to carry out one or more of the various example embodiments of this disclosure. The one or more computerexecutable components may be at least one software code or portions of it.

[0215] Further in this regard it should be noted that any blocks of the logic flow as in the Figures may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. The software may be stored on such physical media as memory chips, or memory blocks implemented within the processor, magnetic media such as hard disk or floppy disks, and optical media such as for example DVD and the data variants thereof, CD. The physical media is a non-transitory media.

[0216] The term “non-transitory,” as used herein, is a limitation of the medium itself (i.e. , tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).

[0217] The memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The data processors may be of any type suitable to the local technical environment, and may comprise one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), application specific integrated circuits (ASIC), FPGA, gate level circuits and processors based on multi core processor architecture, as non-limiting examples.

[0218] Various example embodiments of the disclosure may be practiced in various components such as integrated circuit modules. The design of integrated circuits is by and large a highly automated process. Complex and powerful software tools are available for converting a logic level design into a semiconductor circuit design ready to be etched and formed on a semiconductor substrate.

[0219] The scope of protection sought for various example embodiments of the disclosure is set out by the independent claims. The example embodiments andfeatures thereof, if any, described in this disclosure that do not fall under the scope of the independent claims are to be interpreted as examples useful for understanding various example embodiments of the disclosure.

[0220] The foregoing description has provided, by way of non-limiting and illustrative examples, a full and informative description of the various example embodiments of this disclosure. However, various modifications and adaptations may become apparent to those skilled in the relevant arts in view of the foregoing description, when read in conjunction with the accompanying drawings and the claims. However, all such and similar modifications of the teachings will still fall within the various example embodiments of the disclosure as set forth in the claims. By way of non-limiting and illustrative example, there is a further example embodiment comprising a combination of one or more example embodiments with any of the other example embodiments previously discussed.

Claims

Claims1 ) An apparatus comprising means for performing: receiving, at a core network function from a first network access node, a request for access information for configuring the first network access node to provide a service to a user equipment; determining a degree of mobility restriction information to provide to the first network access node based on whether the first network access node fulfils one or more criterion for receiving incomplete mobility restriction information for the user equipment; and providing, to the first network access node, access information that comprises the determined degree of mobility restriction information.2) An apparatus as claimed in claim 1 , further comprising means for: obtaining, from the first network access node, a request for the core network function to determine whether the user equipment can be handed over to a target network access node; determining whether the user equipment can be handed over to the target network access node by comparing mobility restriction information of the user equipment to mobility restriction information of the target network access node; and providing, the first network access node, the result of the determination of whether the user equipment can be handed over to the target network access node.3) An apparatus as claimed in any preceding claim, wherein the criterion comprises at least one of a list of access node identifiers for which the access information comprises at least one of no mobility restriction information or a restricted version of the mobility restriction information or a list of access node categories for which the access information comprises at least one of no mobility restriction information or a restricted version of the mobility restriction information.424) An apparatus comprising means for performing: providing, to a core network function, a request for access information for configuring a first network access node to provide a service to a user equipment; and obtaining, based on the request, access information comprising a degree of mobility restriction information that is dependent on the first network access node.5) An apparatus as claimed in claim 4, further comprising means for: identifying a handover opportunity to handover the user equipment from the first network access node to a target network access node; determining that the obtained mobility restriction information is incomplete; and based on the determining that the mobility restriction information is incomplete, providing, to the core network function, before triggering the handover, a request for the core network function to determine whether the user equipment can be handed over to the target network access node.6) An apparatus as claimed in claim 5, further comprising means for: obtaining, from the core network function, an indication of whether the user equipment can be handed over to the target network access node based on said request; and either initiating handover to the target network access node or removing the target network access node as a candidate handover network access node based on the obtained indication of whether the user equipment can be handed over.7) An apparatus as claimed in claim 6, wherein the indication indicates that the user equipment can be handed over and the apparatus initiates handover by signalling, to the target network access node, a handover request, wherein the handover request comprises the obtained degree of mobility restriction information.8) An apparatus as claimed in any of claims 5 to 7, wherein the target access node comprises a femto node configured to operate in a closed access mode or in a hybrid access mode.9) An apparatus as claimed in any of claims 5 to 8, wherein means for determining that the mobility restriction information is incomplete comprises means for determining that the mobility restriction information either does not comprise a mobility restriction information or comprises a restricted version of the mobility restriction information.10)An apparatus as claimed in claim 9, wherein the restricted version of the mobility restriction information does not comprise any closed access group subscription information of the user equipment.11 )An apparatus as claimed in any preceding claim, wherein the request for access information comprises at least one of an identifier of the first network access node or an identifier of a category of the first network access node, and wherein the degree of mobility restriction information is dependent on the at least one of identifier of the first network access node or the identifier of the category of first network access node comprised in the request for access.12)An apparatus as claimed in any preceding claim, wherein the degree of mobility restriction information comprised in the access information comprises: no mobility restriction list; a mobility restriction list; or a restricted version of the mobility restriction list.13)An apparatus as claimed in claim 12, wherein the restricted version of the mobility restriction list does not comprise closed access group information for the user equipment.14)An apparatus as claimed in any preceding claim, wherein the request for access information is a Next Generation Application Protocol, NGAP, Initial User Equipment, UE, Message message.15)An apparatus as claimed in any preceding claim, wherein the first network access node comprises a femto node.16)An apparatus as claimed in claim 15, wherein the first network access node comprises a femto node configured to operate in a closed access mode or a hybrid access mode.17)An apparatus comprising means for performing: obtaining, at a target network access node from another network node, a handover request for handing over a user equipment from a source network access node to the target network access node; determining that the handover request comprises incomplete mobility restriction information for the user equipment; and based on the determining that the mobility restriction information is incomplete, providing, to a core network function, a request for the core network function to determine whether the user equipment can be handed over to the target network access node.18)An apparatus as claimed in claim 17, further comprising means for: obtaining, from the core network function, an indication of whether the user equipment can be handed over to the target network access node based on said request; and based on the indication, either providing, to the another network node, an acceptance of the handover request, or providing, to the another network node, a refusal of the handover request.19)An apparatus as claimed in any of claims 17 to 18, wherein the another network node comprises at least one of the core network function or the source network access node.20)An apparatus as claimed in any of claims 17 to 19, wherein the means for determining that the handover request comprises incomplete mobility restriction information for the user equipment comprises means for determining that thehandover request either does not comprise a mobility restriction information or comprises a restricted version of the mobility restriction information.21 )An apparatus as claimed in claim 20, wherein the restricted version of the mobility restriction information does not comprise any closed access group subscription information of the user equipment.22)An apparatus as claimed in any of claims 17 to 21 wherein the target network access node is a femto node.23) An apparatus as claimed in any of claims 17 to 22 wherein the target network access node is a femto node configured to operate in a closed access mode or in a hybrid access mode.24)An apparatus as claimed in any of claims 17 to 23 wherein the source network access node is a femto node.25)An apparatus as claimed in claim 24 wherein the source network access node is a femto node configured to operate in a closed access mode or in hybrid access mode.26)A method for an apparatus, the method comprising: receiving, at a core network function from a first network access node, a request for access information for configuring the first network access node to provide a service to a user equipment; determining a degree of mobility restriction information to provide to the first network access node based on whether the first network access node fulfils one or more criterion for receiving incomplete mobility restriction information for the user equipment; and providing, to the first network access node, access information that comprises the determined degree of mobility restriction information.27)A method for an apparatus, the method comprising:providing, to a core network function, a request for access information for configuring a first network access node to provide a service to a user equipment; and obtaining, based on the request, access information comprising a degree of mobility restriction information that is dependent on the first network access node. )A method for an apparatus, the method comprising: obtaining, at a target network access node from another network node, a handover request for handing over a user equipment from a source network access node to the target network access node; determining that the handover request comprises incomplete mobility restriction information for the user equipment; and based on the determining that the mobility restriction information is incomplete, providing, to a core network function, a request for the core network function to determine whether the user equipment can be handed over to the target network access node. )A computer program comprising instructions which, when the program is executed by a computer comprised in an apparatus, cause the apparatus to carry out: receiving, at a core network function from a first network access node, a request for access information for configuring the first network access node to provide a service to a user equipment; determining a degree of mobility restriction information to provide to the first network access node based on whether the first network access node fulfils one or more criterion for receiving incomplete mobility restriction information for the user equipment; and providing, to the first network access node, access information that comprises the determined degree of mobility restriction information. )A computer program comprising instructions which, when the program is executed by a computer comprised in an apparatus, cause the apparatus to carry out:providing, to a core network function, a request for access information for configuring a first network access node to provide a service to a user equipment; and obtaining, based on the request, access information comprising a degree of mobility restriction information that is dependent on the first network access node. )A computer program comprising instructions which, when the program is executed by a computer comprised in an apparatus, cause the apparatus to carry out: obtaining, at a target network access node from another network node, a handover request for handing over a user equipment from a source network access node to the target network access node; determining that the handover request comprises incomplete mobility restriction information for the user equipment; and based on the determining that the mobility restriction information is incomplete, providing, to a core network function, a request for the core network function to determine whether the user equipment can be handed over to the target network access node.

Citation Information

Patent Citations

  • Handover control based on closed subscriber group subscription information

    US20100157944A1