Method performed by user equipment, method performed by core network device, user equipment and core network device

The UE and core network methods address NAS integrity protection challenges in satellite operations by sending specific messages and handling reject messages with appropriate codes and timers, ensuring secure communication in satellite networks.

WO2026094955A1PCT designated stage Publication Date: 2026-05-07NEC CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
NEC CORP
Filing Date
2025-10-29
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

The 3GPP specifications are unclear on how to perform NAS integrity protection when the MME-SAT, contacted by the UE for Store and Forward Satellite Operation, cannot obtain the security context due to an unavailable feeder link, and how the MME-SAT checks the integrity of uplink NAS messages without having the UE security context.

Method used

The UE and core network device methods involve sending and receiving NAS request messages with specific parameters, such as GUTI and S&F capability, and determining feeder link availability to handle NAS integrity protection and reject messages with appropriate cause codes and timers, ensuring secure communication during satellite operations.

Benefits of technology

This approach enables secure and efficient communication in satellite networks by managing NAS integrity protection and feeder link availability, allowing seamless operation of Store and Forward Satellite Operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025037970_07052026_PF_FP_ABST
    Figure JP2025037970_07052026_PF_FP_ABST
Patent Text Reader

Abstract

An aspect of this disclosure includes a method of a User Equipment (UE) and Core Network (CN). The method includes a CIoT (Cellular Internet of Things) data, MTC (Machine-Type Communication) data and an SMS message delivery using a Store and Forward Satellite operation in 3GPP system.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD PERFORMED BY USER EQUIPMENT, METHOD PERFORMED BY CORE NETWORK DEVICE, USER EQUIPMENT AND CORE NETWORK DEVICE

[0001] The present disclosure relates to a method of a User Equipment (UE) and a method of a core network communication apparatus and etc.

[0002] The Store and Forward Satellite Operation is suitable for delay-tolerant communication services (e.g. CIoT, MTC and SMS).

[0003] The Store and Forward Satellite Operation is realized by an architecture where the MME is split into two parts, an MME part on-board of satellite (MME-SAT in this disclosure) and an MME part in Ground (MME-GND in this disclosure). This architecture was introduced by a 3GPP document in S2-2410989 [2] and S2-2410927 [3].

[0004] All downlink signals and data to the UE for the Delay-tolerant communication services are stored in the MME-GND if the feeder link is not available and forwarded it to the UE if it becomes available.

[0005] In addition, all downlink signals and data to the UE for the Delay-tolerant communication services are stored in the MME-SAT if the service link is not available and forwarded it to the UE if it becomes available.

[0006] Similarly, all uplink signals and data to the core network communication apparatus for the Delay-tolerant communication services are stored in the MME-SAT if the feeder link is not available and forwarded it to the core network communication apparatus if it becomes available.

[0007] NPL 1: [1] 3GPP TR 21.905: "Vocabulary for 3GPP Specifications". V18.0.0 (2024-03) NPL 2: [2] S2-2410989: https: / / www.3gpp.org / ftp / tsg_sa / WG2_Arch / TSGS2_165_Hyderabad_2024-10 / Docs / S2-2410989.zip NPL 3: [3] S2-2410927: https: / / www.3gpp.org / ftp / tsg_sa / WG2_Arch / TSGS2_165_Hyderabad_2024-10 / Docs / S2-2410927.zip NPL 4: [4] 3GPP TS 23.401: "Evolved Universal Terrestrial Radio Access Network (E-UTRAN) access". V19.1.0 (2024-09) NPL 5: [5] 3GPP TS 23.272: "Circuit Switched (CS) fallback in Evolved Packet System (EPS) Stage 2". V19.0.0 (2024-09) NPL 6: [6] 3GPP TS 33.401: "3GPP System Architecture Evolution (SAE) Security architecture". V18.2.0 (2024-09) NPL 7: [7] 3GPP TS 23.003: "Numbering, addressing and identification". V19.0.0 (2024-09) NPL 8: [8] 3GPP TS 24.301: "Non-Access-Stratum (NAS) protocol for Evolved Packet System (EPS) Stage 3". V19.0.0 (2024-09) NPL 9: [9] 3GPP TS 38.321 "Medium Access Control (MAC) protocol specification", V18.3.0 (2024-09)

[0008] In general, the Store and Forward Satellite Operation is a complex mechanism as compared to the 3GPP system in a Terrestrial Networks (TNs).

[0009] The architecture for the Store and Forward Satellite Operation, singling sequence, suspending and resuming mechanism are carefully inspected.

[0010] Inventors of this disclosure found some issues in 3GPP specification to support the Store and Forward Satellite Operation.

[0011] For example, it is unclear in 3GPP standard how an NAS Integrity protection is performed when security contexts are installed in both a UE and any MME in the PLMN but the MME-SAT, being contacted by the UE for the Store and Forward Satellite Operation, cannot get the security context from the MME in the PLMN due to no feeder link is available. In this case, it seems that a downlink NAS message from the MME-SAT to the UE cannot be integrity protected as no security context available in the MME-SAT. It is also not clear when the UE sends uplink NAS message with security protection e.g. integrity protected or ciphered NAS message then how does the MME-SAT checks the integrity of the protected NAS message or decipher the NAS message when the MME-SAT doesn't have a UE security context is unknown.

[0012] The disclosure has a method performed by a user equipment (UE), the method comprising receiving, from a Radio Access Network (RAN) corresponding to a first satellite, system information comprising information related to whether the RAN supports a store and forward operation sending, to a core network device corresponding to the first satellite, a first Non-Access-Stratum (NAS) request message with NAS integrity protection, the first NAS message comprising a Globally Unique Temporary UE Identity (GUTI) and a capability related to the store and forward operation; increasing an Uplink NAS count after sending the first NAS request message; and receiving, from the core network device corresponding to the first satellite, a first NAS reject message without NAS integrity protection, the first NAS reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation, wherein the method comprises determining, based on a first condition, whether to decrease the Uplink NAS count after receiving the first NAS reject message.

[0013] The disclosure has a method performed by a core network device corresponding to a first satellite, the method comprising receiving, from a user equipment (UE), a first Non-Access-Stratum (NAS) request message with NAS integrity protection, the first NAS message comprising a Globally Unique Temporary UE Identity (GUTI) and a capability related to the store and forward operation determining whether a feeder link for the core network device is available; and sending, to the UE, a first NAS reject message without NAS integrity protection based on the determination that the feeder link is not available, the first NAS reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation.

[0014] The disclosure has a method performed by a user equipment (UE), the method comprising receiving, from a Radio Access Network (RAN) corresponding to a first satellite, system information comprising information related to whether the RAN supports a store and forward operation and a status related to a feeder link for the RAN sending, to a core network device corresponding to the first satellite, an Attach Request message comprising EPS mobile identity and a first data; and receiving, from the core network device corresponding to the first satellite, an Attach Reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation.

[0015] The disclosure has a method performed by a core network device corresponding to the first satellite, the method comprising receiving, from a user equipment (UE), an Attach Request message comprising EPS mobile identity and a first data determining whether a feeder link for the core network device is available; and sending, to the UE, an Attach Reject message based on the determination that the feeder link is not available, the Attach Reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation.

[0016] The disclosure has a user equipment (UE) comprising one or more memories storing instructions; and one or more processors configured to process the instructions to control the UE to receive, from a Radio Access Network (RAN) corresponding to a first satellite, system information comprising information related to whether the RAN supports a store and forward operation send, to a core network device corresponding to the first satellite, a first Non-Access-Stratum (NAS) request message with NAS integrity protection, the first NAS message comprising a Globally Unique Temporary UE Identity (GUTI) and a capability related to the store and forward operation increase an Uplink NAS count after sending the first NAS request message; and receive, from the core network device corresponding to the first satellite, a first NAS reject message without NAS integrity protection, the first NAS reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation, wherein the one or more processors are configured to process the instructions to control the UE to determine, based on a first condition, whether to decrease the Uplink NAS count after receiving the first NAS reject message.

[0017] The disclosure has a core network device corresponding to a first satellite, the core network device comprising one or more memories storing instructions; and one or more processors configured to process the instructions to control the core network device to receive, from a user equipment (UE), a first Non-Access-Stratum (NAS) request message with NAS integrity protection, the first NAS message comprising a Globally Unique Temporary UE Identity (GUTI) and a capability related to the store and forward operation determine whether a feeder link for the core network device is available; and send, to the UE, a first NAS reject message without NAS integrity protection based on the determination that the feeder link is not available, the first NAS reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation.

[0018] The disclosure has a user equipment (UE) comprising one or more memories storing instructions; and one or more processors configured to process the instructions to control the UE to receive, from a Radio Access Network (RAN) corresponding to a first satellite, system information comprising information related to whether the RAN supports a store and forward operation and a status related to a feeder link for the RAN send, to a core network device corresponding to the first satellite, an Attach Request message comprising EPS mobile identity and a first data; and receive, from the core network device corresponding to the first satellite, an Attach Reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation.

[0019] The disclosure has a core network device corresponding to the first satellite, the core network device comprising one or more memories storing instructions; and one or more processors configured to process the instructions to control the core network device to receive, from a user equipment (UE), an Attach Request message comprising EPS mobile identity and a first data determine whether a feeder link for the core network device is available; and send, to the UE, an Attach Reject message based on the determination that the feeder link is not available, the Attach Reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation.

[0020] Fig. 1 is a diagram illustrating an architecture.Fig. 2 is a diagram illustrating an architecture.Fig. 3 is an example signaling diagram of this disclosure.Fig. 4 is an example signaling diagram of this disclosure.Fig. 5 is a diagram illustrating an architecture.Fig. 6 is an example signaling diagram of this disclosure.Fig. 7 is an example signaling diagram of this disclosure.Fig. 8 is an example signaling diagram of this disclosure.Fig. 9 is an example signaling diagram of this disclosure.Fig. 10 is a diagram illustrating an architecture.Fig. 11 is an example signaling diagram of this disclosure.Fig. 12 is an example signaling diagram of this disclosure.Fig. 13 is an example signaling diagram of this disclosure.Fig. 14 is an example signaling diagram of this disclosure.Fig. 15 is a diagram illustrating a system overview.Fig. 16 is a block diagram illustrating a UE.Fig. 17 is a block diagram illustrating an (R)AN node.Fig. 18 is a block diagram illustrating an MME.Fig. 19 is a block diagram illustrating an S-GW.Fig. 20 is a block diagram illustrating a P-GW.Fig. 21 is a block diagram illustrating a PCRF.Fig. 22 is a block diagram illustrating an HSS.Fig. 23 is a block diagram illustrating a SCEF.Fig. 24 is a block diagram illustrating an SGSN.Fig. 25 is a block diagram illustrating a GGSN.Fig. 26 is a block diagram illustrating an MSC / VLR.Fig. 27 is a block diagram illustrating an SMS-GMSC.Fig. 28 is a block diagram illustrating an SC.Fig. 29 is a block diagram illustrating an OAM.Fig. 30 is a block diagram illustrating an AF.Fig. 31 is a block diagram illustrating an SCS / AS.

[0021] <Abbreviations>   For the purposes of the present document, the abbreviations given in 3GPP TR 21.905 [1] and the following apply. An abbreviation defined in the present document takes precedence over the definition of the same abbreviation, if any, in 3GPP TR 21.905 [1]. 4G-GUTI  4G Globally Unique Temporary UE Identity 5GC  5G Core Network 5GLAN  5G Local Area Network 5G HE AV  5G Home Environment Authentication Vector 5G SE AV  5G Serving Environment Authentication Vector 5GS  5G System 5G-AN  5G Access Network 5G-AN PDB  5G Access Network Packet Delay Budget 5G-EIR  5G-Equipment Identity Register 5G-GUTI  5G Globally Unique Temporary Identifier 5G-BRG  5G Broadband Residential Gateway 5G-CRG  5G Cable Residential Gateway 5G GM  5G Grand Master 5G-RG  5G Residential Gateway 5G-S-TMSI  5G S-Temporary Mobile Subscription Identifier 5G VN  5G Virtual Network 5QI  5G QoS Identifier AAnF  AKMA Anchor Function ABBA  Anti-Bidding down Between Architectures AF  Application Function A-KID  AKMA Key Identifier AKMA  Authentication and Key Management for Applications AMBR  Aggregated Maximum Bit Rate AMF  Access and Mobility Management Function AMF-G  Geographically selected Access and Mobility Management Function AMF-NG  Non-Geographically selected Access and Mobility Management Function ANDSF  Access Network Discovery and Selection Function AP  Authentication Proxy APN  Access Point Name AR  Augmented Reality ARFCN  Absolute radio-frequency channel number AS  Access Stratum ASN  Abstract Syntax Notation A-TID  AKMA Temporary UE Identifier ATSSS  Access Traffic Steering, Switching, Splitting ATSSS-LL  ATSSS Low-Layer AuC  Authentication Centre AUSF  Authentication Server Function AUTN  Authentication token BCCH  Broadcast Control Channel BMCA  Best Master Clock Algorithm BSF  Binding Support Function CAG  Closed Access Group CAPIF  Common API Framework for 3GPP northbound APIs CDR  Charging Data Record CHF  Charging Function CIoT  Cellular Internet-of-Things CN PDB  Core Network Packet Delay Budget CP  Control Plane CS  Circuit switched CS domain  Circuit switched domain CSG  Closed Subscriber Group DAPS  Dual Active Protocol Stacks DL  Downlink DN  Data Network DNAI  DN Access Identifier DNN  Data Network Name DRX  Discontinuous Reception DSATSSS  Dual Steer Access Traffic Steering, Switching, Splitting DSATSSS-LL  Dual Steer Access Traffic Steering, Switching, Splitting- Low-Layer DSMA  Dual Steer Multi Access DS-TT  Device-side TSN translator ePDG  evolved Packet Data Gateway EBI  EPS Bearer Identity ECGI  E-UTRAN Cell Global Identifier EPS  Evolved Packet System ESM  Energy Saving Management EUI  Extended Unique Identifier FAR  Forwarding Action Rule FN-BRG  Fixed Network Broadband RG FN-CRG  Fixed Network Cable RG FN-RG  Fixed Network RG FQDN  Fully Qualified Domain Name GCI  Global Cable Identifier GEO  Geostationary Earth Orbit GFBR  Guaranteed Flow Bit Rate GMLC  Gateway Mobile Location Centre GNSS  Global Navigation Satellite System G-PDU  GTP encapsulated user Plane Data Unit GPS  Global Positioning System GPSI  Generic Public Subscription Identifier GSO  Geosynchronous Orbit GUAMI  Globally Unique AMF Identifier GUTI  Globally Unique Temporary UE Identity HAPS  High Altitude Platform Station HPLMN  Home Public Land Mobile Network HR  Home Routed (roaming) HSS  Home Subscriber Server IAB  Integrated access and backhaul IEC  International Electrotechnical Commission IMEI / TAC  IMEI Type Allocation Code IMSI  International Mobile Subscriber Identity IPsec  Internet Protocol Security IPUPS  Inter PLMN UP Security I-SMF  Intermediate SMF ISO  International Organization for Standardization I-UPF  Intermediate UPF KAF  AKMA Application Key KAKMA  AKMA Anchor Key LADN  Local Area Data Network LBO  Local Break Out (roaming) LCS  Location Service LEO  Low Earth Orbit LMF  Location Management Function LoA  Level of Automation LPP  LTE Positioning Protocol LRF  Location Retrieval Function LSB  Least Significant Bit MA  Multi Access MCC  Mobile country code MCX  Mission Critical Service MDBV  Maximum Data Burst Volume ME  Mobile Equipment MFBR  Maximum Flow Bit Rate MIB  Master Information Block MICO  Mobile Initiated Connection Only MINT  Minimization of service interruption MITM  Man In the Middle MME  Mobility Management Entity MN  Master Node MNC  Mobile Network Code MNO  Mobile Network Operator MO  Mobile Originated MOCN  Multiple Operator Core Network MPS  Multimedia Priority Service MPTCP  Multi-Path TCP Protocol MR  Mixed Reality MSB  Most Significant Bit MSC / VLR  Mobile Switching Centre / Visitors Location Register MT  Mobile Termination, Mobile Terminating, Mobile terminated N3IWF  Non-3GPP InterWorking Function N3GPP  Non-3GPP access N5CW  Non-5G-Capable over WLAN NAI  Network Access Identifier NAS  Non-Access-Stratum NCGI  NR Cell Global Identity NCI  NR Cell Identity NEF  Network Exposure Function NF  Network Function NGAP  Next Generation Application Protocol NGSO  Non-Geosynchronous Orbit NID  Network identifier NMEA  National Marine Electronics Association NPN  Non-Public Network NR  New Radio NSAG  Network Slice Access Stratum Group NRF  Network Repository Function NSAC  Network Slice Admission Control NSACF  Network Slice Admission Control Function NSI ID  Network Slice Instance Identifier NSSAA  Network Slice-Specific Authentication and Authorization NSSAAF  Network Slice-Specific Authentication and Authorization Function NSSAI  Network Slice Selection Assistance Information NSSF  Network Slice Selection Function NSSP  Network Slice Selection Policy NSSRG  Network Slice Simultaneous Registration Group NTN  Non-Terrestrial Networks NW-TT  Network-side TSN translator NWDAF  Network Data Analytics Function OAM  Operations, Administration, and Maintenance PCF  Policy Control Function PCO  Protocol Configuration Options PCRF  Policy and Charging Rules Function PDB  Packet Delay Budget PDN  Packet Data Network PDR  Packet Detection Rule PDU  Protocol Data Unit PEI  Permanent Equipment Identifier PER  Packet Error Rate PFD  Packet Flow Description PLMN  Public Land Mobile Network PNI-NPN  Public Network Integrated Non-Public Network PPD  Paging Policy Differentiation PPF  Paging Proceed Flag PPI  Paging Policy Indicator ProSe  Proximity based Services PS  Packet switched PSA  PDU Session Anchor PS domain  Packet switched domain PTP  Precision Time Protocol QFI  QoS Flow Identifier QoE  Quality of Experience QoS  Quality of Service RACS  Radio Capabilities Signaling optimization (R)AN  (Radio) Access Network RAT  Radio Access Technology RFID  Radio Frequency Identification RG  Residential Gateway RID  Routing Indicator RIM  Remote Interference Management RQA  Reflective QoS Attribute RQI  Reflective QoS Indication RRC  Radio Resource Control RSC  Relay Service Code RSD  Route Selection Descriptor RSN  Redundancy Sequence Number RSRP  Reference Signal Received Power RSRQ  Reference Signal Received Quality RTT  Round-Trip Time RVAS  Roaming Value Added Service SA NR  Standalone New Radio SBA  Service Based Architecture SBI  Service Based Interface SC  Service Center SCP  Service Communication Proxy S-CSCF  Server - Call Session Control Function SD  Slice Differentiator SEAF  Security Anchor Functionality SENSE  Signal Level Enhanced Network Selection SEPP  Security Edge Protection Proxy SGW  Serving Gateway SIB  System Information Block SINR  Signal to Interference plus Noise Ratio SLA  Service Level Agreement SMF  Session Management Function SMS  Short Message Service SMS-SC  SMS Service Center SMSF  Short Message Service Function SN  Sequence Number SN  Secondary Node SN name  Serving Network Name. SNPN  Stand-alone Non-Public Network S-NSSAI  Single Network Slice Selection Assistance Information SOR  Steering of Roaming SSC  Session and Service Continuity SSCMSP  Session and Service Continuity Mode Selection Policy SST  Slice / Service Type SUCI  Subscription Concealed Identifier SUPI  Subscription Permanent Identifier SV  Software Version TAC  Tracking Area Code TAI  Tracking Area Identity TAU  Tracking Area Update TEID  Tunnel Endpoint Identifier TMGI  Temporary Mobile Group Identity TMSI  Temporary Mobile Subscriber Identity TNAN  Trusted Non-3GPP Access Network TNAP  Trusted Non-3GPP Access Point TNGF  Trusted Non-3GPP Gateway Function TNL  Transport Network Layer TNLA  Transport Network Layer Association TSC  Time Sensitive Communication TSCAI  TSC Assistance Information TSN  Time Sensitive Networking TSN GM  TSN Grand Master TSP  Traffic Steering Policy TT  TSN Translator TWIF  Trusted WLAN Interworking Function UCMF  UE radio Capability Management Function UCU  UE Configuration Update UDM  Unified Data Management UDR  Unified Data Repository UDSF  Unstructured Data Storage Function UE  User Equipment UL  Uplink UL CL  Uplink Classifier UPF  User Plane Function UPSI  UE Policy Section Identifier URLLC  Ultra Reliable Low Latency Communication URRP-AMF  UE Reachability Request Parameter for AMF URSP  UE Route Selection Policy USIM  User Services Identity Module VID  VLAN Identifier VLAN  Virtual Local Area Network VLR  Visitors Location Register VPLMN  Visited Public Land Mobile Network VR  Virtual Reality W-5GAN  Wireline 5G Access Network W-5GBAN  Wireline BBF Access Network W-5GCAN  Wireline 5G Cable Access Network W-AGF  Wireline Access Gateway Function WPT  Wireless Power Transfer

[0022] <Definitions>   For the purposes of the present document, the terms and definitions given in 3GPP TR 21.905 [1] and the following apply. A term defined in the present document takes precedence over the definition of the same term, if any, in 3GPP TR 21.905 [1].

[0023] <General>   Those skilled in the art will appreciate that elements in the figures are illustrated for simplicity and may not have necessarily been drawn to scale. Furthermore, in terms of the construction of the device, one or more components of the device may have been represented in the figures by conventional symbols, and the figures may show only those specific details that are pertinent to understanding the Aspects of the present disclosure so as not to obscure the figures with details that will be readily apparent to those skilled in the art having the benefit of the description herein.

[0024] For the purpose of promoting an understanding of the principles of the disclosure, reference will now be made to the Aspect illustrated in the figures and specific language will be used to describe them. It will nevertheless be understood that no limitation of the scope of the disclosure is thereby intended. Such alterations and further modifications in the illustrated system, and such further applications of the principles of the disclosure as would normally occur to those skilled in the art are to be construed as being within the scope of the present disclosure.

[0025] The terms "comprises", "comprising", or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a process or method that comprises a list of steps does not include only those steps but may include other steps not expressly listed or inherent to such a process or method. Similarly, one or more devices or entities or sub-systems or elements or structures or components preceded by "comprises... a" does not, without more constraints, preclude the existence of other devices, sub-systems, elements, structures, components, additional devices, additional sub-systems, additional elements, additional structures or additional components. Appearances of the phrase "in an Aspect", "in another Aspect" and similar language throughout this specification may, but not necessarily do, all refer to the same Aspect.

[0026] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this disclosure belongs. The system, methods, and examples provided herein are only illustrative and not intended to be limiting.

[0027] In the following specification and the claims, reference will be made to a number of terms, which may be defined to have the following meanings. The singular forms "a", "an", and "the" include plural references unless the context clearly dictates otherwise.

[0028] As used herein, information is associated with data and knowledge, as data is meaningful information and represents the values attributed to parameters. Further knowledge signifies understanding of an abstract or concrete concept. Note that this example system is simplified to facilitate description of the disclosed subject matter and is not intended to limit the scope of this disclosure. Other devices, systems, and configurations may be used to implement the Aspects disclosed herein in addition to, or instead of, a system, and all such Aspects are contemplated as within the scope of the present disclosure.

[0029] Each of Aspects and elements included in the each of Aspects described below may be implemented independently or in combination with any other. These Aspects include novel characteristics different from one another. Accordingly, these Aspects contribute to achieving objects or solving problems different from one another and contribute to obtaining advantages different from one another.

[0030] Any lists described in following aspects include at least one parameter or multiple parameters.

[0031] An example object of this disclosure is to provide a method and apparatus that can solve the above-mentioned problem.

[0032] Any lists described in following aspects include at least one parameter or multiple parameters.

[0033] An example object of this disclosure is to provide a method and apparatus that can solve the above-mentioned problem.

[0034] In this disclosure, regarding listed parameters in the certain message, at least one of the listed parameters may be included in the certain message. For example, "the message including parameter A and parameter B" may mean "the message including at least one of parameter A and parameter B". In addition, for example, "A including (or containing, or similar wording etc.) B and C" may mean "A including at least one of B and C."

[0035] Although this disclosure discloses a mechanism to utilize the multi-orbit satellites for cellular communication in the EPS, all mechanisms in this disclosure can equally apply to the 5G, 6G and / or any other system as well. In case all mechanisms in this disclosure are to apply to the 5GS, the following terminology conversions apply: - eNodeB -> gNB - MME -> AMF - SGW or PGW or combined SGW and PGW -> SMF - SGW-U or PGW-U or combined SGW-U and PGW-U -> UPF - HSS -> UDM - S1AP -> NGAP - S1-MME reference point -> N2 reference point - S1-U reference point -> N3 reference point - S5 or S8 reference point -> N9 reference point - S10 reference point -> N14 reference point - RRC Connection Setup Request -> RRC Setup Request - RRC Connection Setup -> RRC Setup - RRC Connection Setup Complete -> RRC Setup Complete - S1 SETUP REQUEST message -> NG SETUP REQUET message - S1 SETUP RESPONSE message -> NG SETUP RESPONSE message - S2 SETUP REQUEST message -> XN SETUP REQUET message - S2 SETUP RESPONSE message -> XN SETUP RESPONSE message - MME CONFIGURATION UPDATE message -> AMF CONFIGURATION UPDATE message - MME CONFIGURATION UPDATE ACKNOWLEDGE message -> AMF CONFIGURATION UPDATE ACKNOWLEDGE - ENB CONFIGURATION UPDATE message -> RAN CONFIGURATION UPDATE message - ENB CONFIGURATION UPDATE ACKNOWLEDGE message -> RAN CONFIGURATION UPDATE ACKNOWLEDGE - Any S1AP messages -> Respective NGAP messages - Attach Request message or TAU Request message -> Registration Request message - Attach Accept message or TAU Accept message -> Registration Accept message - Attach Complete message or TAU Complete message -> Registration Complete message - GTP-C messages -> Any respective AMF service-related messages (ex. Namf_Communication_NonUeN2InfoNotify) - DIAMETER messages -> Any respective UDM service-related messages (ex. Nudm_SDM_Notification) - GUTI -> 5G-GUTI - S-TMSI -> 5G-S-TMSI - TEID or TEID and IP address -> PDU Session ID

[0036] Fig. 1 illustrates an example of an architecture for Store and Forward Satellite Operation.   A Satellite may be a GEO satellite, a Low-Earth Orbit (LEO) satellite, a Medium-Earth Orbit (MEO) satellite, a Geostationary-satellite Earth Orbit (GEO) satellite or a High-Altitude Platforms (HAPs) satellite.

[0037] An MME is split into two parts, one part is in an MME-SAT 7001 onboarded in a satellite and the other part is an MME-GND 7002 located in the ground. The MME-SAT 7001 and the MME-GND 7002 are connected via a Gateway located in the ground. For example, there is a possibility that multiple MME-SAT 7001 onboarded in the satellite for one MME-GND 7002, This is because multiple satellites each comprising MME-SAT 7001 may cover the same area covered by the one MME-GND 7002 due to changes in satellite orbits and positions.

[0038] A Feeder link connects the MME-SAT 7001 and the MME-GND 7002 with the Gateway.

[0039] A Service link connects the UE 3 and RAN 501 that is onboarded in the Satellite.

[0040] If the Satellite is a LEO satellite, a MEO satellite, a HAPs satellite such as none Geosynchronous Orbit (GSO), the Feeder link and Service link may break due to obit and are not available for communication.

[0041] The Service link may not be available for the UE 3 if a geographical location of the UE is not in a coverage area of the satellite.

[0042] The Feeder link may not be available for the Gateway if a geographical location of the Gateway is not in a coverage area of the satellite.

[0043] There is a case where the Service link is available while the Feeder link is not available at one time.

[0044] There is a case where the Service link is not available while the Feeder link is available at one time.

[0045] There is a case where both the Service link and the Feeder link are available at one time.

[0046] There is a case where both the Service link and the Feeder link are not available at one time.

[0047] <First Aspect>   This aspect includes mechanisms for handling of NAS Integrity protection between UE 3 and the MME-SAT 7001 in the architecture for the Store and Forward Satellite Operation.

[0048] Fig. 2 illustrates an example of a mobility management scenario that the First Aspect deals with.

[0049] The scenario includes the following two steps. - Step 1: The UE 3 is under a coverage of cells with the RAN 502 and the UE 3 has registered with the MME 7002 though the RAN 502 that is located in the ground (terrestrial network). I.e. the Security context is shared between the UE 3 and the MME 7003. - Step 2: The UE 3 moves to out of coverage with cells in the terrestrial network (example, moving to forest area where there is no cell coverage) and the UE 3 sends the Tracking area update (TAU) request message to the MME-SAT 7001 though the RAN 501 that is located in the satellite where a Feeder link for the MME-SAT 7001 is not available.

[0050] Note that this aspect refers to S2-2410989 [2] and S2-2410927 [3] as an architecture and procedures for the Store and Forward Satellite Operation.

[0051] <First example of the First Aspect>   This example includes mechanisms for the UE 3 and the MME-SAT 7001 to performs the Tracking Update location procedure at Step 2 in Fig. 2.

[0052] <First scenario in the First example of the First Aspect>   The First scenario in the First example of the First Aspect includes a mechanism for the NAS integrity protection at Step 2 in Fig. 2 between the UE 3 and the MME-SAT 7001.

[0053] Fig. 3 illustrates an example of mechanism on communicating between the UE 3 and the MME-SAT 7001 without sharing the same security context, as the MME-SAT 7001 is not able to obtain the security context for the UE 3 as the feeder link is not available.

[0054] In the scenario, the UE 3 receives a down link NAS message from the MME-SAT 7001 without the NAS integrity protection in case where a condition matches for the Store and Forward Satellite Operation.

[0055] The detailed processes of this example are described below with reference to Fig. 3.

[0056] Step 0. The UE 3 is attached to the EPC with an MME 7003. A GUTI 1 is assigned to the UE 3 by the MME 7003. The UE 3, the MME-SAT 7001 and the MME-GND 7002 store the EPS security context which stores Key Set Identifier (KSI), Encryption Keys. Integrity Protection Keys downlink NAS count, uplink NAS count and Security Algorithms.

[0057] Step 1. The UE 3 tunes to (moves to) a cell with RAN 501 onboarded on a Satellite and decides to perform the TAU procedure with the cell.

[0058] Step 2. The UE 3 reads system information broadcasted by a cell with the RAN 501. The broadcasting system information includes a S&F mode. The S&M mode indicates that the cell supports the Store and Forward Satellite Operation.

[0059] One example, S&F mode may be expressed by another expression. For example, Store and Forward mode, Store and Forward operation or S&F active.

[0060] For example, the S&F mode is received, from the RAN 501, via a dedicated message.

[0061] Step 3. The UE 3 sends a TAU request message to an MME-SAT 7001 including GUTI and S&F capability.

[0062] The following bullets explain each parameter in detail. - GUTI: The GUTI is a temporary user identifier for the UE 3, Refer to 3GPP TS 23.003 [7] for details. - In this scenario, the GUTI 1 is set to GUTI as the GUTI 1 is assigned by the MME 7003. - S&F capability: The S&F capability indicates that the UE 3 supports the Store and Forward Satellite Operation. One example, S&F capability may be expressed by another expression.

[0063] The TAU request message is integrity protected with Uplink NAS count as defined in the sub clause 4.4.3.3 of 3GPP TS 24.301 [8]. The UE 3 increases the Uplink NAS count after sending the Tracking Area Update Request message. One example, the UE 3 sends the TAU request message to an MME-SAT 7001 without ciphering (i.e. clear text)

[0064] Step 4. Upon Reception of the TAU request message from the UE 3 in Step 3, the MME-SAT 7001 checks whether the Feeder link is available or not. If the Feeder link is not available and the MME-SAT 7001 recognizes that a Security context for the UE 3 cannot be obtained from the MME 7003. .

[0065] With this situation, the MME-SAT 7001 decided to send a TAU reject message without the NAS integrity protection. Note that the NAS integrity protection is defined in section 8.1.2 in 3GPP TS 33.401 [6].

[0066] The MME-SAT 7001 sends a TAU reject message including cause set to "S&F not supported" and S&F wait timer. One example, the TAU reject message includes at least one of the cause set to "S&F not supported" and S&F wait timer.

[0067] The following bullets explain each parameter in detail. - cause set to "S&F not supported": The cause set to "S&F not supported" indicates that the TAU request is rejected due to no Feeder link available at this time for the S&F operation. One example, "S&F not supported" may be expressed by another expression. - S&F wait timer: The S&F wait timer indicates a timer value that the UE 3 waits and sends the same TAU request message in Step 3 when the timer expires. The S&F wait timer specifies the duration for which the UE 3 waits before resending the same TAU request message in Step 3 when the timer expires. One example, "S&F wait timer" may be expressed by another expression.

[0068] The MME-SAT 7001 does not increase the downlink NAS COUNT for the UE 3 even though the MME-SAT 7001 sends the TAU reject message to the UE 3. The UE 3 creates a UE context with received GUTI ,in the TAU reject message, as an Identifier for the UE 3.

[0069] Upon Reception of the TAU reject message including cause set to "S&F not supported" and S&F wait timer from the AMF-SAT 7001 without the NAS integrity protection, the UE 3 exceptionally accepts the TAU reject message without the NAS integrity protection only if one or multiple condition(s) in the following bullets are met: - When the UE 3 is accessing to a cell that supports S&F mode. - When the UE 3 indicates the S&F capability parameter in the NAS message sent to the AMF-SAT 7001. - When the NAS message in Step 4 includes the cause set to S&F not supported. - When the NAS message in Step 4 includes the S&F wait timer. - When the NAS message in Step 4 includes both the cause set to S&F not supported and the S&F wait timer. - When the UE 3 is in the S&F mode.

[0070] After the UE 3 accepts the TAU reject message without the NAS integrity protection, the UE 3 follows the procedure as defined in the 3GPP document in S2-2410989 [2] and S2-2410927 [3].

[0071] The UE 3 does not increase the downlink NAS COUNT for the AMF-SAT 7001 even though the UE 3 receives the TAU reject message from the AMF-SAT 7001.

[0072] When the UE receives the TAU Reject message with cause indicating that the TAU is rejected due to S&F cause, and / or the UE receives wait timer related to the S&F i.e., S&F wait timer then the UE 3 decreases the Uplink NAS Count by one. The UE 3 uses this uplink NAS count when the UE 3 sends uplink NAS message.

[0073] <First Variant of the First scenario in the First example of the First Aspect>   In step 4, The MME-SAT 7001 increases the downlink NAS COUNT for the UE 3 when the MME-SAT 7001 sends the TAU reject message to the UE 3 without the NAS integrity protection.

[0074] Similarly, the UE 3 increases the downlink NAS COUNT for the AMF-SAT 7001 when the UE 3 receives the TAU reject message from the AMF-SAT 7001 without the NAS integrity protection.

[0075] <Second Variant of the First scenario in the First example of the First Aspect>   In steps 3 and 4, The TAU request and TAU reject can be replaced with any other NAS message combination. For example, ATTACH request and ATACH reject, Service Request and Service Reject, PDN connectivity request and PDN connectivity reject, Control Plane Service Request and Control Plane Service Reject, respectively.

[0076] <Third Variant of the First scenario in the First example of the First Aspect>   In one example, in step 3, the MME-SAT 7001 stores the NAS sequence number received in the TAU request message in the UE context created at MME-SAT 7001. The MME-SAT 7001 stores the UE context in the MME-GND 7002 (i.e., The MME-SAT 7001 sends the UE context to the MME-GND 7002). The MME-GND 7002 satellite sends Context Request message including the TAU request message to the MME 7003. The MME-GND 7002 also includes ,in the Context Request message, S&F support capability which indicates that the MME-GND 7002 supports S&F capability or a first indicator indicating that the UE is registering to the MME-GND via the cell supporting S&F procedure.

[0077] The MME-7003 checks the integrity protection of the TAU request message and after successful integrity check of the TAU request message the MME-7003 sends the context response message containing the UE MM context (includes the UE EPS security context), ESM context IMSI, IMEISV, MSISDN the MME-GND 7002 and other parameters as mentioned in the sub clause 5.3.3.1 of 3GPP TS 23.401 [4]. When the MME -7003 receives the first indicator indicating that the UE is in S&F satellite coverage then the MME-7003 sends the EPS context which is only supported when the UE 3 registers in the S&F network (i.e. S&F satellite coverage). For example, the MME-7003 sends the EPS bearer context related to Control plane CIoT and doesn't send EPS bearer context related to user plane CIoT or EPS bearer context related to the IMS voice call or other IMS services.

[0078] When the MME-GND 7002 receives the UE context in the context response message, the MME GND 7002 removes the NAS sequence number of the Uplink NAS Counter and decrement the stored NAS sequence number by one and uses this NAS sequence number in the Uplink NAS Count received from the MME 7003. The MME-SAT 7001 or the MME-GND 7002 uses this Uplink NAS count for the security procedure to the next NAS message from the UE 3.

[0079] <Forth Variant of the First scenario in the First example of the First Aspect>   In step 3, when the MME-GND 7002 receives the TAU request message from the UE3 via the MME-SAT 7001, the MME-GND 7002 determines that the UE 3 is under coverage of the cell supporting S&F mode procedure, then the MME-GND 7002 always fetches the IMSI from the UE 3 using identity request procedure and initiates authentication procedure and security procedure as defined in sub clause 5.3.3.1 of 3GPP TS 23.401 [4]. After the successful authentication procedure, the MME-GND 7002 sends the context request message with the parameter UE validated parameter set indicating that the UE is already validated.

[0080] On receiving the context request message with UE validated set, the MME 7003 sends IMSI, MSISDN, IMEISV, MM Context, EPS context and other UE parameters stored in the MME 7003 to the MME-GND 7002.

[0081] <Second scenario in the First example of the First Aspect>   The Second scenario in the First example of the First Aspect includes a mechanism for the NAS integrity protection at Step 2 in Fig. 2 between the UE 3 and the MME-SAT 7001.

[0082] Fig. 4 illustrates an example of mechanism on communicating between the UE 3 and the MME-SAT 7001 without sharing the same security context, as the MME-SAT 7001 is not able to obtain the security context for the UE 3 as the feeder link is not available.

[0083] In the scenario, the UE 3 sends the Attach request message with IMSI and conveys a small data for the Store and Forward Satellite Operation. Note that small data transmission is defined in section 18 in 3GPP TS 38.321 [9].

[0084] The detailed processes of this example are described below with reference to Fig. 4.

[0085] Step 1. Steps 0 to 1 in Fig. 3 take place.

[0086] Step 2. The UE 3 reads system information broadcasted by a cell with the RAN 501. The broadcasting system information includes a S&F mode and Feeder link status.

[0087] The S&F mode indicates that the cell supports the Store and Forward Satellite Operation.

[0088] The Feeder link status indicates that a Feeder link for the RAN 501 to connect to a core network 7 is available. For example, the feeder link status indicates whether a Feeder link for the RAN 501 to connect to a core network 7 is available.

[0089] One example, S&F mode may be expressed by another expression. For example, Store and Forward mode, Store and Forward operation or S&F active.

[0090] One example, feeder link status may be expressed by another expression.

[0091] The UE 3 may receive the S&F mode and Feeder link status via a dedicated message.

[0092] Step 3. If the Feeder link status in the system information indicates that the Feeder link is not available for the RAN 501 in Step 2, the UE 3 removes a Security context in the UE 3 and sends an Attach request message to an MME-SAT 7001 including EPS mobile identity set to IMSI and ESM message container without ciphering (i.e. clear text). One example, with this situation, the Attach request message is not integrity protected with Uplink NAS count, and the UE 3 doesn't increase the Uplink NAS count after sending the Attach request message.

[0093] The following bullets explain each parameter in detail. - EPS mobile identity: The EPS mobile identity indicates the UE 3 in the core network 7. - In this scenario, the IMSI is used to identify the UE 3. One example, EPS mobile identity may be expressed by another expression. - ESM message container: The ESM message container contains a small data for CIoT communication. One example, ESM message container may be expressed by another expression.

[0094] Step 4. Upon Reception of the Attach request message from the UE 3 in Step 3 including EPS mobile identity set to IMSI and ESM message container, the MME-SAT 7001 checks whether the Feeder link is available or not. If the Feeder link is not available and the MME-SAT 7001 recognizes that a Security context for the UE 3 cannot be obtained from the MME 7003.

[0095] With this situation, the MME-SAT 7001 decided to send an Attach reject message without the NAS integrity protection and without ciphering (i.e. clear text). One example, with this situation, the Attach reject message is not integrity protected with Downlink NAS count, and the MME-SAT 7001 doesn't increase the Downlink NAS count after sending the Attach reject message.

[0096] The MME-SAT 7001 sends the Attach reject message including cause set to "S&F not supported" and S&F wait timer.

[0097] The following bullets explain each parameter in detail. - cause set to "S&F not supported": Refer to Step 4 in Fig. 3. - S&F wait timer: Refer to Step 4 in Fig. 3.

[0098] Upon Reception of the Attach reject message including cause set to S&F not supported and S&F wait timer from the AMF-SAT 7001 without the NAS integrity protection and without ciphering (i.e. clear text), the UE 3 accepts the Attach reject message as there is no security context in the UE 3.

[0099] <First Variant of the Second scenario in the First example of the First Aspect>   In one example, the 'Feeder link status' parameter in step 2 of Fig. 4 may be provided from the MME-SAT 7001 in a new message from the MME-SAT 7001 to RAN 501, for example, called Feeder Link Status message or any other notation for a new message between MME-SAT 7001 and RAN 501 with the aim to update the RAN 501 with the status of the Feeder link between the MME-SAT 7001 and the MME-GND 7002. The 'Feeder link status' parameter may also be relayed from the MME-SAT 7001 to the RAN 501 within one of the existing messages between the MME-SAT 7001 and RAN 501. Then RAN 501 broadcast the Feeder Link status received from MME-SAT 7001 in one of the SIB messages. Then the process continues as per step 3 and step 4 in Fig. 4.

[0100] <Second variant of Second scenario in the First example of the First Aspect>   In one example, in step 3 when the UE 3 determines that the UE 3 has selected a cell supporting S&F operation then the UE 3, discard the security context created in the step 1, initiates initial attach procedure instead of tracking area update procedure and sends Attach Request message with IMSI. The attach request message doesn't contain ESM message. When the MME-SAT 7001 receives the attach request message, the MME-SAT 7001 sends attach Reject message with cause indicating the S&F reject or S&F wait time. The MME-SAT 7001 and MME-GND 7002 executes authentication procedure / security procedure and completes the attach procedure.

[0101] The default PDN connection is initiated by the UE 03 after the attach procedure is successful.

[0102] In one example the above embodiment can also be executed when the UE 3 is powered on and the UE 3 selects a cell supporting S&F operation.

[0103] <Second Aspect>   This aspect includes mechanisms for handling of a small data or SMS message that is stored in the MME-SAT 7001 in the architecture for the Store and Forward Satellite Operation.

[0104] Fig. 5 illustrates an example of a mobility management scenario that the Second Aspect deals with.

[0105] The scenario includes the following two steps. - Step 1: The UE 3 has attached to the MME-SAT 7001 and MME-GND 7002 with the Store and Forward Satellite Operation. For example, the UE 3 uses the Store and Forward Satellite Operation since the UE 3 is out of coverage by cells located in the ground (terrestrial network). - Then, the UE 3 sends a small data or SMS message to MME-SAT 7001 and the small data or SMS message sent by the UE 3 is stored in the MME-SAT 7001 since there in no Feeder link available. - Note that the small data or SMS message stored in the MME-SAT 7001 is illustrated in the grey box close to the MME-SAT 7001. - Step 2: The UE moves to an area where cells located in the ground (terrestrial network) is available (example, moving to town where there is a cell coverage) and the UE 3 sends the TAU message to the MME 7003 though the RAN 502 that is located in the in the ground (terrestrial network).

[0106] Note that this aspect refers to S2-2410989 [2] and S2-2410927 [3] as an architecture and procedures for the Store and Forward Satellite Operation.

[0107] Note that small data transmission is defined in section 18 in 3GPP TS 38.321 [9].

[0108] <First example of the Second Aspect>   This example includes mechanisms for the UE 3 to confirms whether the small data stored in the MME-SAT 7001 in Step 1 of Fig. 5 has successfully delivered to a destination or not.

[0109] <First scenario in the First example of the Second Aspect>   The First scenario in the First example of the Second Aspect includes a mechanism to confirm by the UE 3 whether a CIoT data stored in the MME-SAT 7001 in Step 1 of Fig. 5 has successfully delivered to the AF 201 or not.

[0110] This process disclosed in the scenario takes place when the UE 3 is at Step 1 of Fig. 5.

[0111] Fig. 6 illustrates an example of mechanism on conforming a successful delivery of the CIoT data to the AF 201 using the Store and Forward Satellite Operation.

[0112] The detailed processes of this example are described below with reference to Fig. 6.

[0113] Step 0-1. The UE 3 is attached to the EPC with the MME-SAT 7001 and the MME-GND 7002.

[0114] Note that a combination of the MME-SAT 7001 and the MME-GND 7002 can be considered as the full function of the MME node.

[0115] Step 0-2. The Feeder link is not available at this time.

[0116] Step 1. The UE 3 sends the Control Plane Service Request message including ESM message container and Delivery conformation requested. One example, the Control Plane Service Request message includes at least one of ESM message container and Delivery conformation requested.

[0117] The following bullets explain each parameter in detail. - ESM message container: The ESM message container includes the CIoT user data that the UE 3 requests to delivery to the AF 201. One example, ESM message container may be expressed by another expression. - Delivery conformation requested: The Delivery conformation requested indicates that the UE 3 requests to receive a conformation message once the CIoT data in the ESM message container will have successfully delivered to the AF 201. One example, Delivery conformation requested may be expressed by another expression.

[0118] Step 2. The MME-SAT 7001 sends the Control Plane Service Reject message to the UE 3 since there in no Feeder link available. The MME-SAT 7001 may store in the MM context the received CIoT data or an indicator indicating that the MME-SAT 7001 holds a CIoT data (i.e. the received CIoT data).

[0119] The stored CIoT data or indicator in the MM context for the UE 3 may be shared with other MME-SAT 7001(s). For example, it (the stored CIoT data or indicator in the MM context for the UE 3) may be shared with other MME-SAT 7001(s) onboarded in other MEO satellite (s) or LEO satellite(s) which structures the constellation operation with the MME-SAT 7001.

[0120] The stored CIoT data or indicator in the MM context for the UE 3 may be shared with the MME-GND 7002 when the Feeder link becomes available in step 4.

[0121] Step 3. Upon reception of the Control Plane Service Request message from the UE 3 in step 1, the MME-SAT 7001 stores the received EMS message container and memorizes a time as the time stamp when the EMS message container is received. In addition, the MME-SAT 7001 stores an associated EPS Bearer Id and APN.

[0122] Step 4. The Feeder link becomes available.

[0123] Step 5. The MME-SAT 7001 sends a GTP-U message including GTP-U header (Delivery conformation requested) and G-PDU (User data) to the S-GW 71 via the MME-GND 7002.

[0124] The following bullets explain each parameter in detail. - Delivery conformation requested: The Delivery conformation requested is set in the GTP-U header and it indicates to peer node that the confirmation of the user data delivery is requested. One example, Delivery conformation requested may be expressed by another expression. - G-PDU: The G-PDU is a packet data unit that includes user data in the GTP-U protocol. One example, G-PDU may be expressed by another expression.

[0125] Step 6. The S-GW 71 forwards the received GTP-U message from the MME-SAT 7001 in Step 5 to the P-GW 72.

[0126] Step 7. The P-GW 72 sends the received G-PDU (user data) in the G-PDU to the AF 201.   One example, once the AF 201 receives the user data from the P-GW 72, the AF 201 immediately sends back a downlink User data to the P-GW 72.

[0127] Step 8. After successful delivery of the user data to the AF 201, the P-GW 72 sends the GTP-U message including GTP-U header (Delivery conformed) and G-PDU (User data) to the S-GW 71.

[0128] The following bullets explain each parameter in detail. - Delivery conformed: The Delivery conformed indicates that the user data sent from the UE 3 has successfully been delivered to the AF 201. One example, Delivery conformed may be expressed by another expression. - G-PDU: The G-PDU is a packet data unit that includes user data in the GTP-U protocol. In this case G-PDU has a downlink user data only if the AF 201 immediately sends back the downlink User data to the P-GW 72. One example, G-PDU may be expressed by another expression.

[0129] Step 9. The S-GW 71 forwards the received GTP-U message from the P-GW 72 in Step 8 to the MME-SAT 7001 via the MME-GND 7001.

[0130] Step 10. The MME-SAT 7001 sends a NAS message to the UE 3 including the Delivery conformed, Time stamp, EPS Bearer Id and APN. The NAS message includes at least one of the Delivery conformed, Time stamp, EPS Bearer Id and APN.

[0131] The following bullets explain each parameter in detail. - Delivery conformed: Refer to Step 8. - Time stamp: The Time stamp indicates that a time when the MME-SAT 7001 receives the request to send CIoT data to the AF 201 from the UE 3. For example, Time stamp may be a time when the MME-SAT 7001 receives the Control Plane Service Request message from the UE 3 in this scenario. One example, Time stamp may be expressed by another expression. - EPS Bearer Id: The EPS Bearer Id is an identifier of the EPS bearer that the UE 3 is associated with for the CIoT service. One example, EPS Bearer Id may be expressed by another expression. - APN: The APN is an identifier of the EPS bearer that the UE 3 is associated with for the CIoT service. One example, APN may be expressed by another expression.

[0132] Once the UE 3 receives the NAS message from the MME-SAT 7001, the UE 3 confirms a successful CIoT data delivery to the AF 201. Otherwise, the UE 3 takes an appropriate action. For example, possible actions that UE 3 may take are disclosed in the aspect.

[0133] <First Variant of the First scenario in the First example of the Second Aspect>   In step 10, The NAS message may be a Downlink generic NAS transport message or another existing NAS message or new NAS message.

[0134] <Second Variant of the First scenario in the First example of the Second Aspect>   In step 10, if the UE 3 is in EMM-IDLE state, the MME-SAT 7001 pages the UE 3 and sends the NAS message.

[0135] <Third Variant of the First scenario in the First example of the Second Aspect>   In step 9, if the Feeder link is not available, the MME-GND 7002 stores the received GTP-U message from the S-GW 71 and Time stamp, EPS Bearer Id and APN that are shared with the MME-SAT 7001 when the Feeder link was available.

[0136] Then, when the Feeder link will be available, the MME-GND 7002 forward the stored GTP-U message to the MME-SAT 7001.

[0137] <Fourth Variant of the First scenario in the First example of the Second Aspect>   In order to the Third Variant of the First scenario in the First example of the Second Aspect possible, the MME-GND 7002 maintains the MM context and associated data for the UE 3 for a while in case that the MME-GND 7002 receives the Cancel location request message from the HSS 74.

[0138] A holding duration of the MM context and associated data for the UE 3 after the MME-GND 7002 receives the Cancel location request message from the HSS 74 is locally configured in the MME-GND 7002 based on an operator policy.

[0139] Holding the MM context and associated data for the UE 3 in the MME-SAT 7001 guarantees a successful delivery of the Delivery conformed, Time stamp, EPS Bearer Id and APN to the UE 3.

[0140] <Fifth Variant of the First scenario in the First example of the Second Aspect>   In order to the Third Variant of the First scenario in the First example of the Second Aspect possible, the MME-GND 7002 starts an internal timer when the MME-GND 7002 receives the Context Request message from the MME 7003. The MM context and associated data for the UE 3 may be deleted when the internal timer expires. A value of the internal timer is locally configured in the MME-GND 7002 based on an operator policy.

[0141] Holding the MM context and associated data for the UE 3 in the MME-SAT 7001 guarantees a successful delivery of the Delivery conformed, Time stamp, EPS Bearer Id and APN to the UE 3.

[0142] <Sixth Variant of the First scenario in the First example of the Second Aspect>   This process is equally applicable to the Attach procedure with the following replacements: - Control Plane Service Request message is replaced with Attach request message. - Control Plane Service Reject message is replaced with Attach reject message.

[0143] <Second scenario in the First example of the Second Aspect>   The Second scenario in the First example of the Second Aspect includes a mechanism to confirm by the UE 3 whether a non-IP data stored in the MME-SAT 7001 in Step 1 of Fig. 5 has successfully delivered to the SCS / AS 211 or not.

[0144] This process disclosed in the scenario takes place when the UE 3 is at Step 1 of Fig. 5.

[0145] Fig. 7 illustrates an example of mechanism on conforming a successful delivery of the non-IP data to the SCS / AS 211 using the Store and Forward Satellite Operation.

[0146] The detailed processes of this example are described below with reference to Fig. 7.

[0147] Step 1. Steps 0-1 to 4 in Fig. 6 take place.

[0148] Step 2. The MME-SAT 7001 sends a NIDD Submit Request message to the SCEF 75 including Delivery conformation requested and non-IP data.

[0149] The following bullets explain each parameter in detail. - Delivery conformation requested: Refer to step 1 in Fig. 6. - non-IP data: The non-IP data is a user data sent from the UE 3 that is not structured with the IP protocol. One example, non-IP data may be expressed by another expression.

[0150] Step 3. Upon reception of the NIDD Submit Request message from the MME-SAT 7001, the SCEF 75 sends the MO NIDD Indication message including the non-IP data.

[0151] Step 4. Upon reception of the MO NIDD Indication message from the SCEF 75, the SCS / AS 211 stores the received non-IP data and sends the MO NIDD Acknowledgement message to the SCEF 75 confirming a successful non-IP data delivery.

[0152] Step 5. Upon reception of a NIDD Submit Response message from the SCEF 75, the MME-SAT sends a NAS message to the UE 3 including the Delivery conformed, Time stamp, EPS Bearer Id and APN.

[0153] Refer to Step 10 in Fig. 6 for parameter details.

[0154] Once the UE 3 receives the NAS message from the MME-SAT 7001, the UE 3 confirms a successful non-IP data delivery to the SCS / AS 211. Otherwise, the UE 3 takes an appropriate action. For example, possible actions that UE 3 may take are disclosed in the aspect.

[0155] <First Variant of the Second scenario in the First example of the Second Aspect>   In step 6, The NAS message may be a Downlink generic NAS transport message or another existing NAS message or new NAS message.

[0156] <Second Variant of the Second scenario in the First example of the Second Aspect>   In step 6, if the UE 3 is in EMM-IDLE state, the MME-SAT 7001 pages the UE 3 and sends the NAS message.

[0157] <Third Variant of the Second scenario in the First example of the Second Aspect>   In step 5, if the Feeder link is not available, the MME-GND 7002 stores the received MO NIDD Acknowledgement message from the SCEF 75 and the Time stamp, EPS Bearer Id and APN that are shared with the MME-SAT 7001 when the Feeder link was available.

[0158] Then, when the Feeder link becomes available, the MME-GND 7002 forwards the stored MO NIDD Acknowledgement message to the MME-SAT 7001.

[0159] <Fourth Variant of the First scenario in the First example of the Second Aspect>   In order to the Third Variant of the Second scenario in the First example of the Second Aspect possible, the MME-GND 7002 maintains the MM context and associated data for the UE 3 for a while in case that the MME-GND 7002 receives the Cancel location request message from the HSS 74.

[0160] A holding duration of the MM context and associated data for the UE 3 after the MME-GND 7002 receives the Cancel location request message from the HSS 74 is locally configured in the MME-GND 7002 based on an operator policy.

[0161] Holding the MM context and associated data for the UE 3 in the MME-SAT 7001 guarantees a successful delivery of the Delivery conformed, Time stamp, EPS Bearer Id and APN to the UE 3.

[0162] <Fifth Variant of the First scenario in the First example of the Second Aspect>   In order to the Third Variant of the Second scenario in the First example of the Second Aspect possible, the MME-GND 7002 starts an internal timer when the MME-GND 7002 receives the Context Request message from the MME 7003. The MM context and associated data for the UE 3 may be deleted when the internal timer expires. A value of the internal timer is locally configured in the MME-GND 7002 based on an operator policy.

[0163] Holding the MM context and associated data for the UE 3 in the MME-SAT 7001 guarantees a successful delivery of the Delivery conformed, Time stamp, EPS Bearer Id and APN to the UE 3.

[0164] <Sixth Variant of the First scenario in the First example of the Second Aspect>   In one example at step 2 of Fig. 6, when the MME-SAT 7001 sends Control Plane Service Reject message to the UE 3 for the reason that the Feeder link is not available and the UE 3 had included in the Control Plane Service Request message at step 1 the delivery confirmation requested parameter, the MME-SAT 7001 may also include in the Control Plane Service Reject message to the UE 3 a reject cause. The reject cause may, for example, be called 'Feeder Link not available' or any other notation for a reject cause to indicate the absence of the Feeder Link. When the UE 3 receives Control Plane Service Reject message with a reject cause Feeder Link not available, the UE 3 behavior (e.g. the state transition diagram) is adjusted so that the UE 3 is aware that the requested delivery confirmation may be received later, i.e. in step 10 as per Fig. 6.

[0165] In another example the MME-SAT 7001 may also include in the Control Plane Service Reject message at step 2 of Fig. 6 another parameter to indicate to the UE 3 after how long the Feeder Link is expected to be available. Again, such information about when the Feeder link may become available may be used by UE 3 to further adjust its behavior in terms of when to expect the delivery confirmation in step 10 of Fig. 6.

[0166] <Seventh Variant of the First scenario in the First example of the Second Aspect>   This process is equally applicable to the Attach procedure with the following replacements: - Control Plane Service Request message is replaced with Attach request message. - Control Plane Service Reject message is replaced with Attach reject message.

[0167] <Third scenario in the First example of the Second Aspect>   The third scenario in the First example of the Second Aspect includes a mechanism to confirm by the UE 3 whether CIoT data stored in the MME-SAT 7001 in Step 1 of Fig. 5 has successfully delivered to each destination.

[0168] Fig. 8 illustrates an example of mechanism on conforming a possible unsuccessful delivery of CIoT data stored in the MME-SAT 7001 in Step 1 of Fig. 5.

[0169] The detailed processes of this example are described below with reference to Fig. 8.

[0170] At Step 1 of Fig. 5, the following steps are implemented:   Step 0-1. The UE 3 has attached with the MME-SAT 7001 and MME-GND 7002. A GUTI 1 is assigned by the MME-SAT 7001 and MME-GND 7002.

[0171] Step 0-2. The Feeder link is not available.

[0172] Step 1. The UE 3 sends a Control Plane Service Request message to the MME-SAT 7001 including ESM message container.   The following bullets explain each parameter in detail. - ESM message container: The ESM message container is a container that contains a CIoT data or non-IP data. One example, ESM message container may be expressed by another expression.

[0173] Step 2. Upon reception of the Control Plane Service Request message from the UE 3, the MME-SAT 7001 sends the Control Plane Service Reject message to the UE 3 since there in no Feeder link available.

[0174] Step 3. Upon reception of the Control Plane Service Request message from the UE 3, the MME-SAT 7001 stores the ESM message container that is received in step 1.

[0175] Step 4. The UE 3 moves to a cell in ground. (example, moving to town where there is a cell coverage)

[0176] At Step 2 of Fig. 5, the following steps are implemented:   Step 5. The UE 3 sends the TAU request message to the MME 7003 including GUTI set to GUTI 1.

[0177] Step 6. Upon reception of the TAU request message from the UE 3, the MME 7003 finds the MME-GND 7002, from the received GUTI 1, as an old MME where the MM context for the UE 3 is available. The MME 7003 sends the Context request message to the MME-GND 7002 including a complete TAU Request message.

[0178] Step 7. Upon reception of the Context request message from the MME 7003, the MME-GND 7002 performs the integrity check with the received complete TAU Request message. The integrity check fails as the MME-GND 7002 does not hold the latest Uplink NAS count for the UE 3 as the feeder link is disconnected.

[0179] Step 8. The MME-GND 7002 sends the Context response message to the MME 7003 including cause, Feeder link disconnected time and Suspended CIoT data.   The following bullets explain each parameter in detail. - Cause "User authentication failed": The Cause "User authentication failed" indicates that the User authentication is failed. One example, "User authentication failed" may be expressed by another expression. - Feeder link disconnected time: The Feeder link disconnected time indicates that a time when the Feeder link with the MME-SAT 7001 is disconnected. One example, Feeder link disconnected time may be expressed by another expression. - Suspended CIoT data: The Suspended CIoT data is a CIoT data or indicator stored in the MM context for the UE 3. The CIoT data or indicator may be stored in the MME-GND 7002 in step 2 in Fig. 6. One example, Suspended CIoT data may be expressed by another expression.

[0180] Step 9. Upon reception of the Context response message from the MME-GND 7002 including the cause indicating that the User authentication failed, the MME 7003 initiates an Authentication procedure with the UE 3.

[0181] Step 10. After successful authentication procedure in Step 9, the MME 7003 sends the TAU accept message to the UE 3 including GUTI set to GUTI 2, Feeder link disconnected time and Suspended CIoT data. The GUTI 2 is newly assigned GUTI by the MME 7003.   For Feeder link disconnected time and Suspended CIoT data, refer to step 8 for details.

[0182] Step 11. Upon reception of the TAU accept message from the MME 7003, the UE 3 may take an action if UE suspects, example based on the received Feeder link disconnected time and Suspended CIoT data, that there may be a chance for mis-delivery of the CIoT data sent after a time indicated by the received Feeder link disconnected time.   Example 1: the UE 3 may resend the CIoT data to the MME 7003 that was once sent to the MME-SAT 7001 after a time indicated by the received Feeder link disconnected time.

[0183] Example 2: the UE 3 reports Feeder link disconnected time and Suspended CIoT data to upper layer of the UE 3 indicating that the sent CIoT data may be mis-delivered.

[0184] <First Variant of the Third scenario in the First example of the Second Aspect>   This process is equally applicable to the Attach procedure with the following replacements: - Control Plane Service Request message is replaced with Attach request message. - Control Plane Service Reject message is replaced with Attach reject message.

[0185] <Fourth scenario in the First example of the Second Aspect>   The fourth scenario in the First example of the Second Aspect includes a mechanism to confirm by the UE 3 whether CIoT data stored in the MME-SAT 7001 in Step 1 of Fig. 5 has successfully delivered to each destination.

[0186] Fig. 9 illustrates an example of mechanism on conforming a possible unsuccessful delivery of CIoT data stored in the MME-SAT 7001 in Step 1 of Fig. 5.

[0187] The detailed processes of this example are described below with reference to Fig. 9.

[0188] Step 1. Steps 0-1 to 1 in Fig. 8 take place.

[0189] Step 2. Upon reception of the Control Plane Service Request message from the UE 3, the MME-SAT 7001 sends the Control Plane Service Reject message to the UE 3 including S&F active and Expected delivery time.

[0190] The following bullets explain each parameter in detail. - S&F active: The S&F active indicates that the S&F action is about to take place for the CIoT data delivery. Having receives the S&F active by the UE 3, the UE 3 realizes that it takes some time that the CIoT data to be delivered since the Feeder link is not available. One example, S&F active may be expressed by another expression. - Expected delivery time: The Expected delivery time indicates an expected time when the CIoT data will be delivered. One example, Expected delivery time may be expressed by another expression. - For example, the Expected delivery time is set by the MME-SAT 7001 when the Feeder link will be available next time.

[0191] When the UE 3 receives the Expected delivery time, the UE 3 may take the following actions: - Stores the received Expected delivery time together with associated APN, a time when the UE 3 sends a CIoT data or an SMS message to the MME-SAT 7001. - Reports to upper layer of the UE 3 that the CIoT data or the SMS message is suspended to be sent due to the Store and Forward Satellite Operation and is going to be sent approximately the time that the received Expected delivery time indicates.

[0192] Step 3. Steps 3 to 10 in Fig. 8 take place.

[0193] Step 4. Upon reception of the TAU accept message from the MME 7003, the UE 3 may take an action if UE suspects that there may be a chance for mis-delivery of the CIoT data.

[0194] One example, the UE 3 may resend to the MME 7003 the CIoT data that was once sent to the MME-SAT 7001 if a time indicated by the Expected delivery time that was received in Step 2 is not yet coming.

[0195] <First Variant of the Fourth scenario in the First example of the Second Aspect>   This process is equally applicable to the Attach procedure with the following replacements: - Control Plane Service Request message is replaced with Attach request message. - Control Plane Service Reject message is replaced with Attach reject message.

[0196] <Second Variant of the Fourth scenario in the First example of the Second Aspect>   If the UE 3 receives the Expected delivery time and stores the received Expected delivery time together with associated APN, a time in step 2 and later the UE 3 encounters an event that may deduce a mis-delivery, the UE 3 re-sends the stored data again or reports to upper layer of the UE 3 that the CIoT data or the SMS message is sent indicating about possible mis-delivery and suggests to re-send it again if needed.

[0197] The possible events that the UE 3 may deduce a mis-delivery is listed below as examples: - The UE 3 deregisters from the 3GPP access before the time indicated by the received Expected delivery time indicates. - The UE 3 powered off and powered on again before a time that the received Expected delivery time indicates. - The UE 3 swaps a USIM before a time that the received Expected delivery time indicates. - The UE 3moves to another PLMN before a time that the received Expected delivery time indicates. - The UE moves to a cell that is located in the ground (terrestrial network) before a time that the received Expected delivery time indicates.

[0198] <Third Aspect>   This aspect includes mechanisms for handling of a SMS message delivery using the Circuit Switch (CS) domain in the architecture for the Store and Forward Satellite Operation.

[0199] Fig. 10 illustrates an example of an architecture that the Third Aspect deals with.

[0200] <First example of the Third Aspect>   This example includes mechanisms for the UE 3 to perform a combined attach procedure to both Packet Switch (PS) domain and Circuit Switch (CS) domain with the Store and Forward Satellite Operation.

[0201] <First scenario in the First example of the Third Aspect>   The First scenario in the First example of the Third Aspect includes a mechanism for the UE 3 to perform a combined attach procedure registering to both EPC and CS domain in parallel in the Store and Forward Satellite Operation.

[0202] When a UE supporting S&F mode of operation is in CS / PS mode 1 or PS Mode and selects a cell supporting S&F operation, the UE first changes mode to CS / PS mode 2 or PS mode 2. After changing to CS / PS mode 2 or PS mode 2 the UE initiates attach procedure on the selected cell and proceeds as described below. The UE may take additional steps as described in sub clause 4.3.2.1 of 3GPP TS 24.301 when changing UE operation mode from CS / PS mode 1 to CS / PS mode 2 or PS mode 2 or PS mode 1 to PS mod 2.

[0203] Fig. 11 illustrates an example of mechanism for the combined attach procedure registering to both EPC and CS domain in parallel in the Store and Forward Satellite Operation.

[0204] The detailed processes of this example are described below with reference to Fig. 11.

[0205] Step 1. The Feeder link is not available.

[0206] Step 2. The UE 3 in CS / PS mode 1 or CS / PS mode 2 of operation sends an Attach request message to the MME-SAT 7001 including EPS attach type set to "combined EPS / IMSI attach" or attach type combined EPS / IMSI and indicates SMS only attach. The "combined EPS / IMSI attach" in the EPS attach type indicates that this Attach request is a request to attach for both EPC and CS domain.

[0207] Note that CS / PS mode 1 and CS / PS mode 2 are defined in section 4.3 in 3GPP TS 24.301 [8].

[0208] Note that EPS attach type is defined in 3GPP TS 24.301 [8].

[0209] Step 3. Upon Reception of the Attach request message from the UE 3 in Step 2, the MME-SAT 7001 checks whether the Feeder link is available or not. If the Feeder link is not available, the MME-SAT 7001 sends an Attach reject message including the S&F wait timer. Refer to Step 4 in Fig. 3 for the S&F wait timer in details.

[0210] Step 4. The Feeder link becomes available.

[0211] Step 5. The MME-SAT 7001 forwards the Attach request message received form the UE 3 in step 2 to the MME-GND 7002.

[0212] Step 6. The MME-GND 7002 sends the Update Location Request message to the HSS 74 including Provisional.

[0213] The following bullets explain each parameter in detail. - Provisional: The Provisional indicates that the Update Location Request message is sent in the Store and Forward Satellite Operation and asking to receive a subscriber data for the UE 3 but not to register the MME-GND 7002 as a service node for the UE 3. Once the authentication for the UE 3 will have done, the MME-GND 7002 will send the Update Location Request message without Provisional. I.e. this is an indication for provisional registration. One example, Provisional may be expressed by another expression. For instance, Provisional can be referred to as Provisional flag.

[0214] Step 7. Upon reception of the Update Location Request message from the MME-GND 702 in step 6, the HSS 74 sends the Update Location Response message to the MME-GND 702 including Subscriber data for the UE 3.

[0215] Step 8. As the MME-GND 7002 recognizes that this procedure as the combined EPS / IMSI attach and there is a SGs interface between the MME-GND 7002 and MSC / VLR 78, the MME-GND 7002 sends the Location Update Request message to the MSC / VLR 78 including Provisional and optionally sends a second indicator indicating that the UE is attaching for S&F operation mode or the serving cell supports S&F operation. Refer to Step 6 for Provisional in details. However, The Provisional in this message indicates the MSC / VLR 78 that this Location Update Request message is for Provisional and sends it and the second indicator to the HSS 74 when the MSC / VLR 78 performs the Updata Location procedure toward the HSS 74.

[0216] Step 9. Upon reception of the Location Update Request message from the MME-GND 702 in step 8, the MSC / VLR 78 sends the MAP UPDATE LOCATION Request message to the HSS 74 including Provisional and the second indicator. The Provisional in this message indicates the HSS 74 that this message is for provisional and asking (requesting) to receive a subscriber data for the UE 3 but not to register the MSC / VLR 78 as a service node for the UE 3 in the CS domain.

[0217] Step 10. Upon reception of the MAP UPDATE LOCATION Request message from the MSC / VLR 78 in step 9, the HSS 74 sends the MAP UPDATE LOCATION Response message to the MSC / VLR 78.

[0218] Step 11. The HSS 74 sends the MAP INSERT SUBSCRIBER DATA Request message to the MSC / VLR 78 including Subscriber data. The Subscriber data includes a Subscriber data for the UE 3 for the CS domain.

[0219] Step 12. The MSC / VLR 78 stores the received Subscriber data for the UE 3 and sends MAP INSERT SUBSCRIBER DATA response message to the HSS 74.

[0220] Step 13. The MSC / VLR 78 assigns a VLR TMSI for the UE 3 and sends a Location Update Accept message to the MME-GND 7002 including VLR TMSI.

[0221] The following bullets explain each parameter in detail. - VLR TMSI: The VLR TMSI indicates a temporary identifier for the UE 3 in the CS domain. One example, VLR TMSI may be expressed by another expression.

[0222] If the UE is registering for both combined attach for EPS / IMSI services, the MSC / VLR sends SMS only attach to the MME-GND 7002 even though the MSC / VLR has received an indication that UE is registering for the combined EPS / IMSI from the MME-GND and subscription parameter indicates that the UE has subscription for both SMS services and other CS service when the MSC / VLR knows that the UE 3 is registering for the S&F operation or the serving cell supports S&F mode as indicated in the second indicator. In one example the MSC / VLR determines that the UE is registering to the S&F operation or serving cell supports S&F operation if the MSC / VLR receives the provisional indicator in message 8.

[0223] Step 14. The MME-GND 7002 sends an Attach Accept message to the MME-SAT 7001 including GUTI and VLR TMSI.

[0224] The following bullets explain each parameter in detail. - GUTI: Refer to step 3 in Fig. 3. - VLR TMSI: Refer to step 13.

[0225] In one example instead of sending the attach accept message the MME-GNF 7002 sends subscriber information received for CS and PS domain received from MSC / VLR 78 and HSS 74 and CS registration outcome from MSC / VLR 78 (e.g., VLR TMSI) to the MME-SAT. How the information between MME-SAT 7001 and MME-GND 7002 communicate and transfer information between each other is internal implementation.

[0226] Step 15. The MME-SAT 7001 forwards the Attach Accept message to the UE 3 if there is the Service link established.

[0227] When the UE 3 initiates Attach Request message after the S&F wait timer expires, the MME-SAT 7001 sends the attach accept message containing GUTI and with EPS attach result set to combined EPS / IMSI attach. If the UE 3 has sent attach request message with attach type combined EPS / IMSI attach or attach type combined EPS / IMSI and an indication SMS only attach.

[0228] Step 16. After sending the Attach accept message, the AMF-SAT 7001 or / and AMF-GND 7002 sends Update location request message to the MSC / VLR 78 which considered the Location update successful for the SMS service. The MSC / VLR 78 further sends the MAP UPDATE Location Request to the HSS 74 which considered the UE is registered for SMS services via MSC / VLR 78.

[0229] The AMF-SAT 7001 or / and AMF-GND 7002 also sends Location Update Request to HSS 74 for PS domain to indicate that the UE 3 is attached for the PS domain.

[0230] The HSS 74 considers the UE 3 attached for PS services and CS service which is for SMS only.

[0231] <First Variant of the First scenario in the First example of the Third Aspect>   In step 9, if the MAP UPDATE LOCATION Request message does not include Provisional, the HSS 74 recognizes the MAP UPDATE LOCATION Request as the provisional request in case the HSS 74 receives the Update Location Request message from the MME-GNS 7002 including Provisional.

[0232] If the HSS 74 is separated into two parts, one for the CS domain (Example, HLR) and the other one for the PS domain, The PS domain part of the HSS 74 informs the provisional information to the CS part of the HSS 74 in step 6.

[0233] <Second Variant of the First scenario in the First example of the Third Aspect>   In one example at step 3 of Fig. 11, when the MME-SAT 7001 sends Attach Reject message to the UE 3 for the reason that the Feeder link is not available, the MME-SAT 7001 may also include in the Attach Reject message to UE 3 a reject cause. The reject cause may, for example, be called 'Feeder Link not available' or any other notation for a reject cause to indicate the absence of the Feeder Link between the MME-SAT 7001 and the MME-GND 7002. When the UE 3 receives Attach Reject message with a reject cause Feeder Link not available, the UE 3 behavior (e.g. the state transition diagram) is adjusted so that the UE 3 is aware that the Attach Accept message, as per step 15 of Fig. 11, is still a possibility regardless the Attached Reject received at step 3. The UE 3 would adjust its behavior (e.g. states transition diagram) so that an Attach Accept message can be received with delay after the receipt of Attach Reject message with a reject cause Feeder Link not available.

[0234] <Third Variant of the First scenario in the First example of the Third Aspect>   This process is equally applicable to the TAU procedure with the following replacements: - Attach request message is replaced with TAU request message. In addition, the EPS attach type is not included in the TAU request message. - Attach reject message is replaced with TAU reject message. - Attach accept message is replaced with TAU accept message.

[0235] <Forth Variant of the First scenario in the First example of the Third Aspect>   In one example when the UE 3 requires establishing a PDN connection during the attach procedure, The UE 3 includes a PDN connectivity request message in the ESM message container in the attach request message. The UE 3 may include Access Point Name (APN) in the PDN connection request message. When the APN is included in the PDN connection request message then the UE 3 shall not include ESM information transfer flag.

[0236] One example, the UE 3 shall not include ESM information transfer flag in case one or multiple of the following bullet is met in the UE 3: - The UE 3 does not have a valid security context. - The UE 3 includes a IMSI or IMEI in the EPS mobile identity in the Attach request message in step 2. - The UE 3 does not include a GUTI in the EPS mobile identity in the Attach request message in step 2. - The Attach request message in step 2 is an initial attach for the UE 3.

[0237] In case the Attach request message in step 2 includes the PDN connectivity request message in the ESM message container, the following steps take place: - In step 5 when the MME-GND 7002 receives attach request message, the MME GND 7002 fetches the authentication vector(s) from the HSS 74. The MME-GND 7002 fetches the subscription information from the HSS 74 as well. - One example, the MME GND 7002 sends the Authentication Information Request message to the HSS 74 including new parameter "provisional" to fetch the authentication vector(s) from the HSS 74. The new parameter "provisional" indicates to the HSS 74 that this is a request to provide authentication vector(s) provisionally for UE 3 in S&F mode. Upon reception of the Authentication Information Request message, the HSS 74 provides the authentication vector(s) to the MME GND 7002. - If the APN is not supported (or not subject) for the S&F operation mode of operation, MME-SAT 7001 / MME-GND 7002, S-GW 71, P-GW 72 may reject the establishment of the PDN connection with an existing ESM cause or a new cause that the APN is not supported in S&F operation mode. - Then, the MME-GND establishes a PDN connection for the APN received in the PDN connection request message by executing steps 12-16 of sub clause 5.3.2.1 of 3GPP TS 23.401 [4] with the following modifications. - In the step 12 of sub clause 5.3.2.1 of 3GPP TS 23.401 [4], the MME-GND 7002 sends the Create session Request message to the S-GW 71 includes the APN, new parameter "provisional" and the S&F UE capability or / and an indication that UE 3 is attaching to the core network 7 in the S&F operation mode. If the APN is not supported (or not subject) for the S&F operation mode of operation, S-GW 71 may reject the establishment of the PDN connection with an existing ESM cause or a new cause that the APN is not supported in S&F operation mode. - In the step 13 of sub clause 5.3.2.1 of 3GPP TS 23.401 [4], the S-GW 71 further forwards the Create session Request message to the P-GW 72 includes the APN, new parameter "provisional" and the received S&F UE capability or / and the received indication that UE 3 is attaching to the core network 7 in the S&F operation mode. If the APN is not supported (or not subject) for the S&F operation mode of operation, P-GW 72 may reject the establishment of the PDN connection with an existing ESM cause or a new cause that the APN is not supported in S&F operation mode. The P-GW 72 assigns GTP-C and GTP-U resources to the UE 3 and configures a GTP tunnel. - The P-GW 72 may allocate an IP address (UE IP address) for the UE 3 provisionally. (i.e., the allocated IP address for the UE 3 is provisionally and any DL packets destined to the IP address is discarded at the P-GW72 as far as the assigned IP address is provisional. DL packet and UP packet to / from the assigned IP address will be handled normally after the P-GW 72 receives the Modify bearer request message from the S-GW 71 without new parameter "provisional".) - The P-GW 72 may not start the charging control to the UE 3 or start the charging control for provisional state as far as the PDN connection being created is provisional. - In the step 14 of sub clause 5.3.2.1 of 3GPP TS 23.401 [4], the PGW 72 provides new parameter "provisional" in addition to the IMSI, APN, UE IP address to the PCRF 73 to obtains the PCC rule for the UE 3. The PCRF 73 may not start the charging control to the UE 3 or start the charging control for provisional state as far as the PDN connection being created is provisional. - Steps 15 and 16 of sub clause 5.3.2.1 of 3GPP TS 23.401 [4] take place.

[0238] The modifications to steps 12, 13 and 14 of sub clause 5.3.2.1 of 3GPP TS 23.401 [4] in the bullets above are applicable to the UE requested PDN connectivity procedure in clause 5.10.2 of 3GPP TS 23.401 [4] as well after the attach procedure is successful (i.e., for the standalone PDN connection establishment procedure.)

[0239] The MME-GND 7002 sync- up the information it has regarding the authentication vector, UE subscription, CS attach procedure at SGs interface and outcome of the PDN connection procedure. To the MME-SAT 7001 in step 14 when feeder link is available. When the service link is available between the UE 3 and MME-SAT 7001, the MME-SAT 7001 executes authentication and security procedure as described in step 5a of sub clause 5.3.2.1 of 3GPP TS 23.401 [4]. After successful authentication and security procedure the MME-SAT 7001 sends Attach accept message to the UE 3 as per step 17 of the sub clause 5.3.2.1 of 3GPP TS 23.401 [4]. When the UE 3 receives attach accept message, the UE 3 sends attach complete message to the MME-SAT 7001 as per the step 21 of the sub clause 5.3.2.1 of 3GPP TS 23.401 [4].

[0240] When the PDN connection establishment procedure fails then the MME-SAT 7001 sends Attach Reject message containing PDN connection Reject message with received ESM cause from the S-GW 71 or P-GW 72 as described above bullets. When the UE 3 receives the PDN connection Reject message with new cause that APN is not supported in S&F operation mode then the UE 3 shall not initiate any new establishment of the PDN connection when the UE 3 is attaching or attached to a cell supporting S&F operation mode.

[0241] One example, the PDN connection established during the attach procedure is control plane only PDN connection. In step 17, the network (MME-GND 7002 or MME-SAT 7001) shall include the Control plane only indication IE in the ACTIVATE DEFAULT EPS BEARER CONTEXT REQUEST if the UE 3 supports S&F operation and attaching to network via a cell supporting S&F operation mode.

[0242] In one example the MME-GND 7002 includes provisional information in the create session Request message in step 12 to the S-GW 71. The S-GW 71 sends the provisional information in the Create session request message to the P-GW 72. After sending the Create session establishment message the P-GW 72 doesn't send downlink data for this PDN connection or doesn't initiate Dedicated EPS bearer establishment procedure. After step 15 of the figure 11, when the UE 3 initiates steps 23 and 24 of sub clause 5.3.2 of TS 23.401 [4] the modify bearer request procedure including an information element that the PDN connection is established successfully. After receiving the information element by the P-GW 72, the P-GW 72 will start sending the downlink data or accepting the uplink data or the P-GW 72 may initiate dedicated EPS bearer establishment procedure.

[0243] In one example, when a PDN connection is being established either during the attach procedure or after the attach procedure, the S-GW 71 and P-GW 72 may indicate that the PDN connection is S&F only mode in Create Session Response message. The MME-SAT 7001 and / or MME-GND 7002 include this information element to the UE 3. The MME-SAT 7001 sends this information element to the RAN 501 (ex. gNB) as well. In this case, the RAN 501 (ex. gNB) doesn't initiate any DRB for this EPS bearer context. When the UE 3 receives this information element, the UE 3 either release the PDN connection after the UE 3 registers to the cell not supporting S&F operation mode (i.e. a normal cell e.g. Terrestrial network or NTN with simultaneous feeder link and service link connection). The UE 3 may establish the DRB for this PDN connection which is marked S&F only. The MME-GND 7002 and MME-SAT 7001 may not transfer this PDN connection with S&F mode only to an MME for cells in the Terrestrial network when the UE 3 is attached to a normal cell in the Terrestrial network during the mobility procedure or initial attach procedure. The MME-SAT 7001 and the MME-GND 7002 may not initiate procedure to establish dedicate EPS bearer.

[0244] In one example the S&F only indicator is sent from P-GW 7002 to MME-GND 7002 and MME-SAT 7001 via S-GW 71 in Create session response message using an existing information element and MME-SAT 7001 and MME-GND indicates that the PDN connection is established with S&F only operation in an existing information element.

[0245] In one example the UE 3 includes S&F indication in the existing information element or in a new information element in the PDN connectivity request message. When the MME-GND 7002 receives this information element in the PDN connectivity request it sends this indicator to the S-GW in a create session request message. The S-GW 71 further sends this indicator to the P-GW 72 in a create session request message. The P-GW or MME-GND 7002 or HSS indicates to the PCRF that the PDN connection is for the S&F operation.

[0246] In one example when the UE changes cells from TN to NTN supporting S&F operation mode then after successful TAU or attach procedure to the TNT network the UE 3 initiates UE requested bearer resource modification procedure to deactivate dedicate bearer resources and optionally include S&F operation mode in the an existing IE or in a new IE sends an existing ESM message to the MME-SAT 7002. When the feeder link is available and the MME-SAT and MME-GND sync then the UE MME-GND 7002 initiates bearer resource release or modification procedure by sending an existing ESM message defined between MME-GND 7002 and UE 3 from network to UE direction.

[0247] In one example, when the UE 3 is attaching for the S&F mode of operation then the MME-SAT 7001 / MM-GND 7002 send UE EPS session management timers (e.g. T3481, T3480, T3492) as defined in TS 24.301 in the existing EMM (Attach accept or Tracking area update accept) or ESM message. The UE 3 uses the value of the received EPS session management timer in corresponding procedure while the UE is attached to the network via a cell supporting S&F operation mode.

[0248] <Fifth Variant of the First scenario in the First example of the Third Aspect>   In one example, the UE 3 is registering to a cell supporting S&F operation mode then the UE 3 attaches to the core network 7 without PDN connection during the attach procedure as the procedure defined in sub clause 5.3.2 of 3GPP TS 23.401 [4] for the "Attach without PDN connection establishment" procedure. After the attach procedure, the UE 3 establishes a standalone PDN connection to transfer the user data as defined in sub clause 5.10.2 of 3GPP TS 23.401 [4].

[0249] Example, the UE 3 attaches to the core network 7 without PDN connection during the attach procedure in case one or multiple of the following bullet is met in the UE 3: - The UE 3 does not have a valid security context. - The UE 3 includes a IMSI or IMEI in the EPS mobile identity in the Attach request message in step 2. - The UE 3 does not include a GUTI in the EPS mobile identity in the Attach request message in step 2. - The Attach request message in step 2 is an initial attach for the UE 3.

[0250] <Sixth Variant of the First scenario in the First example of the Third Aspect>   When the MME-GND 7002 is configured to support SMS in MME as described in 3GPP TS 23.272, the MME-GND 7002 will fetch subscription data for SMS or CS services in step 6-7 from HSS 74. The MME-GND 7002 skips step 8-13 and proceeds with steps 14 and 15 and sends attach accept and indicates that UE 3 is registered for SMS only through an existing IE in the attach accept message.

[0251] In one example, when the feeder link is not available the MME-GND 7002 receives SMS it stores the SMS and in this case the MME-GND 7002 doesn't set the Mobile-Not-Reachable-Flag-in-MME-for-SMS (MNRF-MME) indication in the MME-GND 7002. When the feeder link is available then the stored SMS is sent to the MME-SAT 7001. When the next feeder link is available and the MME-GDN 7002 doesn't receive the SMS ack (RP-ACK of RP-DATA sent to the UE 3 via MME-SAT 7001) then the MME-SAT 7002 set the Mobile-Not-Reachable-Flag-in-MME-for-SMS (MNRF-MME). When the subsequent SMS is transmitted to the UE 3 successfully and the MME-GND 7002 received the RP ACK of the RP DATA transmitted then the MME shall clear Mobile-Not-Reachable-Flag-in-MME-for-SMS (MNRF-MME). The MME-GND 7002 further sends SM (IMSI, UE-Present) message to the HSS to the HSS 74 as defined in C6 of 3GPP TS 23.272.

[0252] In one example the UE 3 shall always select the default APN when it supports S&F operation and attaching to the network via a cell supporting S&F operation mode. The UE 3 shall not include APN in the PDN connectivity request message sent in the attach request message.

[0253] <Second scenario in the First example of the Third Aspect>   The Second scenario in the First example of the Third Aspect includes a mechanism for the UE 3 to perform a combined attach procedure registering to both EPC and CS domain in sequence order in the Store and Forward Satellite Operation.

[0254] Fig. 12 illustrates an example of mechanism for the combined attach procedure registering to both EPC and CS domain in parallel in the Store and Forward Satellite Operation.

[0255] The detailed processes of this example are described below with reference to Fig. 12.

[0256] Step 1. Steps 1 to 7 in Fig. 11 take place.

[0257] Step 2. Steps 14 and 15 in Fig. 11 take place with the following difference. - The Attach Accept message in Steps 14 and 15 does not include the VLR TMSI.

[0258] Step 3. The Feeder link becomes not available.

[0259] Step 4. The Service link becomes available.

[0260] Step 5. The UE 3 in CS / PS mode 1 or CS / PS mode 2 of operation sends an Attach request message to the MME-SAT 7001 including EPS attach type set to "combined EPS / IMSI attach".

[0261] Step 6. The Authentication procedure takes place between the UE 3 and the MME-SAT 7001.

[0262] Step 7. After the successful Authentication in Step 6, the MME-SAT 7001 sends the Attach Accept message to the MME-SAT 7001 including GUTI and VLR TMSI to be assigned.

[0263] The following bullets explain each parameter in detail. - GUTI: Refer to step 3 in Fig. 3. - VLR TMSI to be assigned: The VLR TMSI to be assigned indicates to the UE 3 that the Attach procedure for the CS domain has not yet completed. One example, VLR TMSI to be assigned may be expressed by another expression. For example, VLR TMSI suspended, CS attach suspended, CS domain suspended, CS domain attach suspended, SMS service suspended.

[0264] Step 8. The UE 3 accepts the Attach Accept message without VLR TMSI. Although the UE 3 indicates the EPS attach type set to "combined EPS / IMSI attach" in the Attach Request message.

[0265] The UE 3 recognizes that the attaching to the EPS is only accepted and any services over the EPS (Example, CIoT service) are ready to use. However, any services over the CS domain (Example, SMS service over the CS domain) are not ready to use at this moment. However, the UE 3 expects to receive the VLR TMSI later and the UE 3 will be able to attach to the CS domain later.

[0266] Step 9. The Feeder link becomes not available.

[0267] Step 10. Steps 5 to 15 in Fig. 11 take place with the following difference. - The Location Update Request message in step 8 does not include Provisional. - The MAP UPDATE LOCATION Request in step 9 does not include Provisional.

[0268] <First Variant of the Second scenario in the First example of the Third Aspect>   This process is equally applicable to the TAU procedure with the following replacements: - Attach request message is replaced with TAU request message. - Attach reject message is replaced with TAU reject message. - Attach accept message is replaced with TAU accept message.

[0269] <Second Variant of the Second scenario in the First example of the Third Aspect>   When a UE 3 needs to attach for combined EPS / IMSI attach for PS and SMS only service via MSC / VLR 78 then the network shall perform the PS attach procedure first and the network instructs the UE 3 to perform the combined EPS / IMSI service for the SMS service. When the UE 3 receives the attach accept message with information that IMSI attach is pending then the UE 3 performs the combined TAU for EPS / IMSI attach for CS service only.

[0270] In one example in step 5, after the UE 3 is successfully attached for the PS domain, the UE 3 sends TAU request message with update type set to combined EPS / IMSI attach to perform the combined EPS / IMSI attach for the SMS service only, steps 5 to 15 are executed with attach request is replaced with TAU request message. Attach accept is replaced with TAU accept message.

[0271] <Third Variant of the Second scenario in the First example of the Third Aspect>   If the UE 3 needs to perform the combined EPS / IMSI service, the UE 3 first performs the Attach procedure for PS services only by sending the Attach request message with attach type EPS attach. Step 1 and Step 2 of the Fig. 12 takes place. The UE sends attach type EPS attach in the Attach request message in step 1 in Fig. 11.

[0272] After the successful registration for the EPS service the UE 3 performs combined TAU procedure for EPS / IMSI by sending TAU request message with update type set to combined EPS / IMSI attach and an additional indicator that the UE 3 is attaching for the SMS only for the CS service. steps 5 to 15 of Fig. 11 is executed with Attach request is replaced with TAU request. Attach accept is replaced with TAU accept message. In steps 8 and step 9, the provisional indicator is not sent to the MSC / VLR 78 and HSS 74 respectively.

[0273] <Forth Variant of the Second scenario in the First example of the Third Aspect>   In step 1, if the UE 3 includes a PDN connectivity request message in the ESM message container in the attach request message requesting to establish a PDN connection during attach procedure but the PDN connection is not established. (Due to no security context in the UE 3 or / and the EMS transfer flag is not set or / and APN and / or PCO are set in the PDN connectivity request message), a PDN connection will be established after a successful authentication in step 6.

[0274] In this case, the Attach accept message or Attach reject message includes the S&F wait timer and / or additional information either in the existing information element or in a new information element indicating that the PDN connection establishment is pending. For example, new information element may be expressed as PS service suspended, PDN connection suspended, CIoT service suspended. When the feeder link is established the MME-GND 7002 after sync up with MME-SAT 7001 initiates the PDN connection establishment procedure by executing steps 12 to 16 in subclause 5.3.2.1 of 3GPP TS 23.401 [4]. After the successful PDN connection establishment procedure and the MME-GND 7001 sync up with MME-SAT 7002.

[0275] In next Attach request from the UE 3 including the EMS transfer flag is set after successful authentication. After the successful PDN connection establishment procedure and the MME-GND 7001 sync up with MME-SAT 7002, result of the PDN connection establishment is transferred to the UE 3 in the Attach accept message. At this point, the SGs association result may also be transferred to the UE 3. The result of the PDN connection establishment may include the PCO, Extended Protocol Configuration Options (ePCO) and other PDN connection related parameters.

[0276] In one example, the MME-GND 7001 or MME-SAT 7002 after successful establishment of the PDN connection initiates GUTI Reallocation procedure sends ACTIVATE DEFAULT EPS BEARER CONTEXT REQUEST in the TMSI reallocation command message and indicating combined attach in an existing IE and optionally additional update type SMS only in an existing IE, the UE sends GUTI relocation complete message containing ACTIVATE DEFAULT EPS BEARER CONTEXT RESPONSE message.

[0277] <Second example of the Third Aspect>   This example includes mechanisms on the domain selection when the Mobile Terminating SMS message arrives for the UE 3 in CS / PS mode 1 or CS / PS mode 2 of operation with the Store and Forward Satellite Operation.

[0278] <First scenario in the Second example of the Third Aspect>   The First scenario in the Second example of the Third Aspect includes a mechanism for the Attach procedure taking the domain selection for the Mobile Terminating SMS service into account with the Store and Forward Satellite Operation.

[0279] Fig. 13 illustrates an example of mechanism for the Attach procedure taking the domain selection for the Mobile Terminating SMS service into account.

[0280] The detailed processes of this example are described below with reference to Fig. 13.

[0281] Step 1. Steps 1 to 5 in Fig. 11 take place.

[0282] Step 2. The MME-GND 7002 sends the Update Location Request message to the HSS 74 including Provisional and S&F Location update.

[0283] The following bullets explain each parameter in detail. - Provisional: Refer to the Step 6 in Fig. 11. - S&F Location update: The S&F Location update indicates that the UE 3 is under the Store and Forward Satellite Operation. One example, S&F Location update to be assigned may be expressed by another expression.

[0284] Step 3. Upon reception of the Update Location Request message from the MME-GND 702 in step 2, the HSS 74 sends the Update Location Response message to the MME-GND 702 including Subscriber data for the UE 3.

[0285] Step 4. As the MME-GND 7002 recognizes that this procedure as the combined EPS / IMSI attach and there is a SGs interface between the MME-GND 7002 and MSC / VLR 78, the MME-GND 7002 sends the Location Update Request message to the MSC / VLR 78 including Provisional. The Provisional in this message indicates the MSC / VLR 78 that this Location Update Request message is for Provisional and indicates it to the HSS 74 when the MSC / VLR 78 performs the Updata Location procedure toward the HSS 74.

[0286] Step 5. Upon reception of the Location Update Request message from the MME-GND 702 in step 4, the MSC / VLR 78 sends the MAP UPDATE LOCATION Request message to the HSS 74 including Provisional and S&F Location update. Refer to Step 2 for Provisional and S&F Location update in details.

[0287] Step 6. Steps 10 to 15 in Fig. 11 take place.

[0288] With this process, the HSS 74 recognizes that the UE 3 is under the Store and Forward Satellite Operation and light weight services, including CIoT services, SMS services, are only available. I.e., the real time services (example, voice and video services) are not available as far as the UE is under the Store and Forward Satellite Operation.

[0289] <First Variant of the First scenario in the Second example of the Third Aspect>   This process is equally applicable to the TAU procedure with the following replacements: - Attach request message is replaced with TAU request message. - Attach reject message is replaced with TAU reject message. - Attach accept message is replaced with TAU accept message.

[0290] <Second Variant of the First scenario in the Second example of the Third Aspect>   The S&F Location update information in the HSS 74 may be removes if the HSS receives the Update Location Request message without S&F Location update.

[0291] <Second scenario in the Second example of the Third Aspect>   The Second scenario in the Second example of the Third Aspect includes a mechanism on the domain selection when the Mobile Terminating SMS message arrives for the UE 3 with the Store and Forward Satellite Operation.

[0292] Fig. 14 illustrates an example of mechanism on domain selection when the Mobile Terminating SMS message arrives to the UE 3.

[0293] The detailed processes of this example are described below with reference to Fig. 13.

[0294] Step 1. SMS message arrives to the SC 7A.

[0295] Step 2. The SC 7A forward the received SMS message to the SMS-GMSC 79.

[0296] Step 3. The SMS-GMSC 79 sends the MAP-SEND-ROUTING-INFO-FOR-SM request message including MSISDN. The MSISDN is a Mobile Subscriber ISDN numbers (i.e. E.164 numbers) that is assigned to the UE 3. Refer to 3GPP TS 23.003 [7] for details.

[0297] Step 4. Upon reception of the MAP-SEND-ROUTING-INFO-FOR-SM request message from the SMS-GMSC 79 in step 3, the HSS 74 performs the domain selection for delivering the SMS message to the UE 3. The domain selection may take a status of Store and Forward Satellite Operation of the UE 3. The following bullets may be a decision-making criterion: - If the UE 3 has not attached to the CS domain, any MSC in the CS domain should not be a target node for SMS delivery. - If the UE 3 is under the Store and Forward Satellite Operation, any IP-SM-GW should not be a target node for SMS delivery. I.e. SMS delivery over the IMS should not performed if the UE 3 is under the Store and Forward Satellite Operation. - One example, HSS 74 recognized that the UE 3 is under the Store and Forward Satellite Operation when the HSS 74 receives the S&F Location update information from the service node (MME 74 or MSC / VLR 78) as disclosed in First scenario in the Second example of the Third Aspect.

[0298] Step 5. After the HSS 74 selects a target node for the SMS delivery, the HSS 74 sends the MAP-SEND-ROUTING-INFO-FOR-SM response message to the SMS-GMSC 79 including Network Node number. The Network Node number includes a routing address for the chosen target node.

[0299] Step 6-1. This is an optional step in case that the MME-GND 7002 is chosen as the target node.   The SMS-GMSC 79 sends the MAP-MT-FORWARD-SHORT-MESSAGE to the MME-GND 7002 including the SMS message.

[0300] Step 6-2. This is an optional step in case that the MSC / VLR 78 is chosen as the target node.   The SMS-GMSC 79 sends the MAP-MT-FORWARD-SHORT-MESSAGE to the MSC / VLR 78 including the SMS message.

[0301] Step 7. After Step 6-1 or 6-2, the serving node ((MME 74 or MSC / VLR 78) delivers the SMS message to the UE 3.

[0302] <System overview>   Fig. 15 schematically illustrates a telecommunication system 1 for a mobile (cellular or wireless) to which the above aspects are applicable.

[0303] The telecommunication system 1 represents a system overview in which an end-to-end communication is possible. For example, UE 3 (or user equipment, 'mobile device' 3) communicates with other UEs 3, service servers in the data network 20 or the non-IP data servers in the non-IP data network 21 via respective (R)AN nodes 5 and a core network 7.

[0304] The (R)AN node 5 supports any radio accesses including 3G and 4G radio access technology (RAT), an E-UTRA radio access technology, a UTRA, a 5G RAT, a beyond 5G RAT and a 6G RAT.

[0305] The (R)AN node 5 can also support a communication using the satellite access. In some aspects, the (R)AN node 5 may support a satellite access and a terrestrial access.

[0306] In addition, the (R)AN node 5 can also be referred as an access node for a non-wireless access. The non-wireless access includes a fixed line access as defined by the Broadband Forum (BBF) and an optical access as defined by the Innovative Optical and Wireless Network (IOWN).

[0307] The core network 7 may include logical nodes (or 'functions') for supporting a communication in the telecommunication system 1. For example, the core network 7 may be 4G Core Network (EPC) that includes, amongst other functions, control plane functions and user plane functions.

[0308] As is well known, a UE 3 may enter and leave the areas (i.e. radio cells) served by the (R)AN node 5 as the UE 3 is moving around in the geographical area covered by the telecommunication system 1. In order to keep track of the UE 3 and to facilitate movement between the different (R)AN nodes 5, the core network 7 comprises at least one access and mobility management function (MME) 70. The MME 70 is in communication with the (R)AN node 5 coupled to the core network 7. In some core networks, a Serving GPRS Support Node (SGSN), a mobility management entity (MME) or a mobility management node for beyond 5G or a mobility management node for 6G may be used instead of the MME 70.

[0309] The core network 7 also includes, amongst others, a Serving Gateway (S-GW) 71, a PDN Gateway (P-GW) 72, a Policy and Charging Rules Function (PCRF) 73, a Home Subscriber Server (HSS) 74, a Service Capability Exposure Function (SCEF) 75. When the UE 3 is roaming to a visited Public Land Mobile Network (VPLMN), a home Public Land Mobile Network (HPLMN) of the UE 3 provides the HSS 74 and at least some of the functionalities of the P-GW 72 and PCRF 73 for the roaming-out UE 3.

[0310] The OAM 8 includes, amongst others, Operational functions, Administrational functions and Maintenance related functions. The OAM 8 has interfaces with RAN 5, logical nodes in the core network 7 in a PLMN. In addition, the OAM 8 has interfaces to the AF 201, SCS / AS 211 and other entities that are located in the data network 20 and the non-IP data network 21 respectively.

[0311] The UE 3 and a respective serving (R)AN node 5 are connected via an appropriate air interface (for example the so-called "Uu" interface and / or the like). Neighboring (R)AN node 5 are connected to each other via an appropriate (R)AN node 5 to (R)AN node interface (such as the so-called "X2" interface and / or the like). Each (R)AN node 5 is also connected to nodes in the core network 7 (such as the so-called core network nodes) via an appropriate interface (such as the so-called "S1" interface(s) and / or the like).

[0312] From the core network 7, connection to a data network 20 is also provided. The data network 20 can be an internet, a public network, an external network, a private network or an internal network of the PLMN. In case that the data network 20 is provided by a PLMN operator or Mobile Virtual Network Operator (MVNO), the IP Multimedia Subsystem (IMS) service may be provided by that data network 20. The UE 3 can be connected to the data network 20 using IPv4, IPv6, IPv4v6, Ethernet or unstructured data type. The data network 20 may include an Application Function (AF) 201.

[0313] From the core network 7, connection to a non-IP data network 21 is also provided. The non-IP data network 21 can be a dedicated network structured without Internet Protocol (IP). The non-IP data network 21 may be provided by a PLMN operator or Mobile Virtual Network Operator (MVNO). The non-IP data network 21 may include a Services Capability Server / Application Server (SCS / AS) 211.

[0314] The "Uu" interface may include a Control plane of Uu interface and User plane of Uu interface.

[0315] The User plane of Uu interface is responsible to convey user traffic between the UE 3 and a serving (R)AN node 5. The User plane of Uu interface may have a layered structure with PDCP, RLC and MAC sublayer over the physical connection (i.e. PHY sublayer).

[0316] The Control plane of Uu interface is responsible to establish, modify and release a connection between the UE 3 and a serving (R)AN node 5. The Control plane of Uu interface may have a layered structure with RRC, PDCP, RLC and MAC sublayers over the physical connection.

[0317] The UE 3 and the MME 70 are connected via an appropriate interface (for example the so-called NAS interface and / or the like). The NAS interface is responsible to provide a communication between the UE 3 and the MME 70. The NAS interface may be established over a 3GPP access.

[0318] <User equipment (UE)>   Fig. 16 is a block diagram illustrating the main components of the UE 3 (mobile device 3). As shown, the UE 3 includes a transceiver circuit 31 which is operable to transmit signals to and to receive signals from the connected node(s) via one or more antennas 32. Further, the UE 3 may include a user interface 34 for inputting information from outside or outputting information to outside. Although not necessarily shown in the Figure, the UE 3 may have all the usual functionality of a conventional mobile device and this may be provided by any one or any combination of hardware, software and firmware, as appropriate. Software may be pre-installed in the memory and / or may be downloaded via the telecommunication network or from a removable data storage device (RMD), for example. A controller 33 controls the operation of the UE 3 in accordance with software stored in a memory 36. The software includes, among other things, an operating system 361 and a communications control module 362 having at least a transceiver control module 3621. The communications control module 362 (using its transceiver control module 3621) is responsible for handling (generating / sending / receiving) signalling and uplink / downlink data packets between the UE 3 and other nodes, such as the (R)AN node 5 and the MME 70. Such signalling may include, for example, appropriately formatted signalling messages (e.g. a attach request message and associated response messages) relating to access and mobility management procedures (for the UE 3). The controller 33 interworks with one or more Universal Subscriber Identity Module (USIM) 35. If there are multiple USIMs 35 equipped, the controller 33 may activate only one USIM 35 or may activate multiple USIMs 35 at the same time.

[0319] The UE 3 may, for example, support the Non-Public Network (NPN). The NPN may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).

[0320] The UE 3 may, for example, be an item of equipment for production or manufacture and / or an item of energy related machinery (for example equipment or machinery such as: boilers; engines; turbines; solar panels; wind turbines; hydroelectric generators; thermal power generators; nuclear electricity generators; batteries; nuclear systems and / or associated equipment; heavy electrical machinery; pumps including vacuum pumps; compressors; fans; blowers; oil hydraulic equipment; pneumatic equipment; metal working machinery; manipulators; robots and / or their application systems; tools; molds or dies; rolls; conveying equipment; elevating equipment; materials handling equipment; textile machinery; sewing machines; printing and / or related machinery; paper converting machinery; chemical machinery; mining and / or construction machinery and / or related equipment; machinery and / or implements for agriculture, forestry and / or fisheries; safety and / or environment preservation equipment; tractors; precision bearings; chains; gears; power transmission equipment; lubricating equipment; valves; pipe fittings; and / or application systems for any of the previously mentioned equipment or machinery etc.).

[0321] The UE 3 may, for example, be an item of transport equipment (for example transport equipment such as: rolling stocks; motor vehicles; motor cycles; bicycles; trains; buses; carts; rickshaws; ships and other watercraft; aircraft; rockets; satellites; drones; balloons etc.).

[0322] The UE 3 may, for example, be an item of information and communication equipment (for example information and communication equipment such as: electronic computer and related equipment; communication and related equipment; electronic components etc.).

[0323] The UE 3 may, for example, be a refrigerating machine, a refrigerating machine applied product, an item of trade and / or service industry equipment, a vending machine, an automatic service machine, an office machine or equipment, a consumer electronic and electronic appliance (for example a consumer electronic appliance such as: audio equipment; video equipment; a loud speaker; a radio; a television; a microwave oven; a rice cooker; a coffee machine; a dishwasher; a washing machine; a dryer; an electronic fan or related appliance; a cleaner etc.).

[0324] The UE 3 may, for example, be an electrical application system or equipment (for example an electrical application system or equipment such as: an x-ray system; a particle accelerator; radio isotope equipment; sonic equipment; electromagnetic application equipment; electronic power application equipment etc.).

[0325] The UE 3 may, for example, be an electronic lamp, a luminaire, a measuring instrument, an analyzer, a tester, or a surveying or sensing instrument (for example a surveying or sensing instrument such as: a smoke alarm; a human alarm sensor; a motion sensor; a wireless tag etc.), a watch or clock, a laboratory instrument, optical apparatus, medical equipment and / or system, a weapon, an item of cutlery, a hand tool, or the like.

[0326] The UE 3 may, for example, be a wireless-equipped personal digital assistant or related equipment (such as a wireless card or module designed for attachment to or for insertion into another electronic device (for example a personal computer, electrical measuring machine)).

[0327] The UE 3 may be a device or a part of a system that provides applications, services, and solutions described below, as to "internet of things (IoT)", using a variety of wired and / or wireless communication technologies.

[0328] Internet of Things devices (or "things") may be equipped with appropriate electronics, software, sensors, network connectivity, and / or the like, which enable these devices to collect and exchange data with each other and with other communication devices. IoT devices may comprise automated equipment that follow software instructions stored in an internal memory. IoT devices may operate without requiring human supervision or interaction. IoT devices might also remain stationary and / or inactive for a long period of time. IoT devices may be implemented as a part of a (generally) stationary apparatus. IoT devices may also be embedded in non-stationary apparatus (e.g. vehicles) or attached to animals or persons to be monitored / tracked.

[0329] It will be appreciated that IoT technology can be implemented on any communication devices that can connect to a communications network for sending / receiving data, regardless of whether such communication devices are controlled by human input or software instructions stored in memory.

[0330] It will be appreciated that IoT devices are sometimes also referred to as Machine-Type Communication (MTC) devices or Machine-to-Machine (M2M) communication devices or Narrow Band-IoT UE (NB-IoT UE). It will be appreciated that a UE 3 may support one or more IoT or MTC applications.

[0331] The UE 3 may be a smart phone or a wearable device (e.g. smart glasses, a smart watch, a smart ring, or a hearable device). For a wearable device, the UE 3 may be a reduced capability device (RedCap).

[0332] The UE 3 may be a car, or a connected car, or an autonomous car, or a vehicle device, or a motorcycle or V2X (Vehicle to Everything) communication module (e.g. Vehicle to Vehicle communication module, Vehicle to Infrastructure communication module, Vehicle to People communication module and Vehicle to Network communication module).

[0333] <(R)AN node>   Fig. 17 is a block diagram illustrating the main components of an exemplary (R)AN node 5, for example a base station ('RNC' in GERAN, 'eNodeB' in LTE, 'gNB' in 5G, a base station for 5G beyond, a base station for 6G). As shown, the (R)AN node 5 includes a transceiver circuit 51 which is operable to transmit signals to and to receive signals from connected UE(s) 3 via one or more antennas 52 and to transmit signals to and to receive signals from other network nodes (either directly or indirectly) via a network interface 53. A controller 54 controls the operation of the (R)AN node 5 in accordance with software stored in a memory 55. Software may be pre-installed in the memory and / or may be downloaded via the telecommunication network or from a removable data storage device (RMD), for example. The software includes, among other things, an operating system 551 and a communications control module 552 having at least a transceiver control module 5521.

[0334] The communications control module 552 (using its transceiver control sub-module) is responsible for handling (generating / sending / receiving) signalling between the (R)AN node 5 and other nodes, such as the UE 3, another (R)AN node 5, the MME 70 and the S-GW 71 (e.g. directly or indirectly). The signalling may include, for example, appropriately formatted signalling messages relating to a radio connection and a connection with the core network 7 (for a particular UE 3), and in particular, relating to connection establishment and maintenance (e.g. RRC connection establishment and other RRC messages), S1 Application Protocol (S1AP) messages (i.e. messages by S1 reference point) and X2 application protocol (X2AP) messages (i.e. messages by X2 reference point), etc. Such signalling may also include, for example, broadcast information (e.g. Master Information and System information) in a sending case.

[0335] The controller 54 is also configured (by software or hardware) to handle related tasks such as, when implemented, UE mobility estimate and / or moving trajectory estimation.

[0336] The (R)AN node 5 may support the Non-Public Network (NPN). The NPN may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).

[0337] The (R)AN node 5 may be expressed as a RAN node, RAN, (R)AN etc.

[0338] <MME>   Fig. 18 is a block diagram illustrating the main components of the MME 70. As shown, the apparatus includes a transceiver circuit 701 which is operable to transmit signals to and to receive signals from other nodes (including the UE 3) via a network interface 702. A controller 703 controls the operation of the MME 70 in accordance with software stored in a memory 704. Software may be pre-installed in the memory 704 and / or may be downloaded via the telecommunication network or from a removable data storage device (RMD), for example. The software includes, among other things, an operating system 7041 and a communications control module 7042 having at least a transceiver control module 70421. The communications control module 7042 (using its transceiver control module 70421) is responsible for handling (generating / sending / receiving) signalling between the MME 70 and other nodes, such as the UE 3 (e.g. via the (R)AN node 5) and other core network nodes (including core network nodes in the HPLMN of the UE 3 when the UE 3 is roaming-in). Such signalling may include, for example, appropriately formatted signalling messages (e.g. a registration request message and associated response messages) relating to access and mobility management procedures (for the UE 3).

[0339] The MME 70 may support the Non-Public Network (NPN), The NPN may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).

[0340] <S-GW>   Fig. 19 is a block diagram illustrating the main components of the S-GW 71. As shown, the apparatus includes a transceiver circuit 711 which is operable to transmit signals to and to receive signals from other nodes (including the MME 70) via a network interface 712. A controller 713 controls the operation of the S-GW 71 in accordance with software stored in a memory 714. Software may be pre-installed in the memory 714 and / or may be downloaded via the telecommunication network or from a removable data storage device (e.g. a removable memory device (RMD)), for example. The software includes, among other things, an operating system 7141 and a communications control module 7142 having at least a transceiver control module 71421. The communications control module 7142 (using its transceiver control module 71421) is responsible for handling (generating / sending / receiving) signalling between the S-GW 71 and other nodes, such as the MME 70 and other core network nodes (including core network nodes in the HPLMN of the UE 3 (e.g., the Network Relay UE 300 and the UE 3) when the UE 3 is roaming-in). Such signalling may include, for example, appropriately formatted signalling messages (e.g. an interface based on GTP protocol) relating to policy management procedures (for the UE 3).

[0341] The S-GW 71 may support the Non-Public Network (NPN). The NPN may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).

[0342] <P-GW>   Fig. 20 is a block diagram illustrating the main components of the P-GW 72. As shown, the apparatus includes a transceiver circuit 721 which is operable to transmit signals to and to receive signals from other nodes (including the S-GW 71) via a network interface 722. A controller 723 controls the operation of the P-GW 72 in accordance with software stored in a memory 724. Software may be pre-installed in the memory 724 and / or may be downloaded via the telecommunication network or from a removable data storage device (e.g. a removable memory device (RMD)), for example. The software includes, among other things, an operating system 7241 and a communications control module 7242 having at least a transceiver control module 72421. The communications control module 7242 (using its transceiver control module 72421) is responsible for handling (generating / sending / receiving) signalling between the P-GW 72 and other nodes, such as the S-GW 71 and other core network nodes (including core network nodes in the HPLMN of the UE 3 (e.g., the Network Relay UE 300 and the UE 3) when the UE 3 is roaming-in). Such signalling may include, for example, appropriately formatted signalling messages (e.g. an interface based on GTP protocol) relating to policy management procedures (for the UE 3).

[0343] The P-GW 72 may support the Non-Public Network (NPN). The NPN may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).

[0344] <PCRF>   Fig. 21 is a block diagram illustrating the main components of the PCRF 73. As shown, the apparatus includes a transceiver circuit 731 which is operable to transmit signals to and to receive signals from other nodes (including the MME 70) via a network interface 732. A controller 733 controls the operation of the PCRF 73 in accordance with software stored in a memory 734. Software may be pre-installed in the memory 734 and / or may be downloaded via the telecommunication network or from a removable data storage device (e.g. a removable memory device (RMD)), for example. The software includes, among other things, an operating system 7341 and a communications control module 7342 having at least a transceiver control module 73421. The communications control module 7342 (using its transceiver control module 73421) is responsible for handling (generating / sending / receiving) signalling between the PCRF 73 and other nodes, such as the MME 70 and other core network nodes (including core network nodes in the HPLMN of the UE 3 (e.g., the Network Relay UE 300 and the UE 3) when the UE 3 is roaming-in). Such signalling may include, for example, appropriately formatted signalling messages (e.g. an interface based on DIAMETER protocol) relating to policy management procedures (for the UE 3).

[0345] The PCRF 73 may support the Non-Public Network (NPN). The NPN may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).

[0346] <HSS>   Fig. 22 is a block diagram illustrating the main components of the HSS 74. As shown, the apparatus includes a transceiver circuit 741 which is operable to transmit signals to and to receive signals from other nodes (including the MME 70 and the UDM 75) via a network interface 742. A controller 743 controls the operation of the HSS 74 in accordance with software stored in a memory 744. Software may be pre-installed in the memory 744 and / or may be downloaded via the telecommunication network or from a removable data storage device (e.g. a removable memory device (RMD)), for example. The software includes, among other things, an operating system 7441 and a communications control module 7442 having at least a transceiver control module 74421. The communications control module 7442 (using its transceiver control module 74421) is responsible for handling (generating / sending / receiving) signalling between the HSS 74 and other nodes, such as the MME 70 and other core network nodes (including core network nodes in the HPLMN of the UE 3 when the UE 3 is roaming-in). Such signalling may include, for example, appropriately formatted signalling messages (e.g. an interface based on DIAMETER protocol) relating to subscriber data management procedures (for the UE 3).

[0347] The HSS 74 may support the Non-Public Network (NPN). The NPN may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).

[0348] <SCEF>   Fig. 23 is a block diagram illustrating the main components of the SCEF 75. As shown, the apparatus includes a transceiver circuit 751 which is operable to transmit signals to and to receive signals from other nodes (including the MME 70) via a network interface 752. A controller 753 controls the operation of the SCEF 75 in accordance with software stored in a memory 754. Software may be pre-installed in the memory 754 and / or may be downloaded via the telecommunication network or from a removable data storage device (RMD), for example. The software includes, among other things, an operating system 7541 and a communications control module 7542 having at least a transceiver control module 75421. The communications control module 7542 (using its transceiver control module 75421) is responsible for handling (generating / sending / receiving) signalling between the SCEF 75 and other nodes, such as the MME 70 and other core network nodes (including core network nodes in the VPLMN of the UE 3 (e.g., the Network Relay UE 300 and the UE 3) when the UE 3 is roaming-out). Such signalling may include, for example, appropriately formatted signalling messages (e.g. an interface based on DIAMETER protocol) relating to data exposure related procedures (for the UE 3).

[0349] The SCEF 75 may support the Non-Public Network (NPN). The NPN may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).

[0350] <SGSN>   Fig. 24 is a block diagram illustrating the main components of the SGSN 76. As shown, the apparatus includes a transceiver circuit 761 which is operable to transmit signals to and to receive signals from other nodes (including the MME 70) via a network interface 762. A controller 763 controls the operation of the SGSN 76 in accordance with software stored in a memory 764. Software may be pre-installed in the memory 764 and / or may be downloaded via the telecommunication network or from a removable data storage device (RMD), for example. The software includes, among other things, an operating system 7641 and a communications control module 7642 having at least a transceiver control module 76421. The communications control module 7642 (using its transceiver control module 76421) is responsible for handling (generating / sending / receiving) signalling between the SGSN 76 and other nodes, such as the GGSN 77 and other core network nodes (including core network nodes in the VPLMN of the UE 3 when the UE 3 is roaming-out). Such signalling may include, for example, appropriately formatted signalling messages (e.g. an interface based on GTP protocol) relating to mobility management procedures (for the UE 3).

[0351] The SGSN 76 may support the Non-Public Network (NPN). The NPN may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).

[0352] <GGSN>   Fig. 25 is a block diagram illustrating the main components of the GGSN 77. As shown, the apparatus includes a transceiver circuit 771 which is operable to transmit signals to and to receive signals from other nodes (including the SGSN 76) via a network interface 772. A controller 773 controls the operation of the GGSN 77 in accordance with the software stored in a memory 774. The Software may be pre-installed in the memory 774 and / or may be downloaded via the telecommunication network or from a removable data storage device (e.g. a removable memory device (RMD)), for example. The software includes, among other things, an operating system 7741 and a communications control module 7742 having at least a transceiver control module 77421. The communications control module 7742 (using its transceiver control module 77421) is responsible for handling (generating / sending / receiving) signalling between the GGSN 77 and other nodes, such as the MME 70 and other core network nodes (including core network nodes in the HPLMN of the UE 3 when the UE 3 is roaming-in). Such signalling may include, for example, appropriately formatted signalling messages (e.g. an interface based on GTP protocol) relating to network data analytics function procedures (for the UE 3).

[0353] The GGSN 77 may support the Non-Public Network (NPN). The NPN may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).

[0354] <MSC / VLR>   Fig. 26 is a block diagram illustrating the main components of the SMS-SC 79. As shown, the apparatus includes a transceiver circuit 781 which is operable to transmit signals to and to receive signals from other nodes (including the HSS 74) via a network interface 782. A controller 783 controls the operation of the SMS-SC 79 in accordance with the software stored in a memory 784. The Software may be pre-installed in the memory 784 and / or may be downloaded via the telecommunication network or from a removable data storage device (e.g. a removable memory device (RMD)), for example. The software includes, among other things, an operating system 7841 and a communications control module 7842 having at least a transceiver control module 78421. The communications control module 7842 (using its transceiver control module 78421) is responsible for handling (generating / sending / receiving) signalling between the SMS-SC 79 and other nodes, such as the MME 70 and other core network nodes (including core network nodes in the HPLMN of the UE 3 when the UE 3 is roaming-in). Such signalling may include, for example, appropriately formatted signalling messages (e.g. an interface based on MAP protocol) relating to network data analytics function procedures (for the UE 3).

[0355] <SMS-GMSC>   Fig. 27 is a block diagram illustrating the main components of the SMS-GMSC 79. As shown, the apparatus includes a transceiver circuit 781 which is operable to transmit signals to and to receive signals from other nodes (including the HSS 74) via a network interface 792. A controller 793 controls the operation of the SMS-GMSC 79 in accordance with the software stored in a memory 794. The Software may be pre-installed in the memory 794 and / or may be downloaded via the telecommunication network or from a removable data storage device (e.g. a removable memory device (RMD)), for example. The software includes, among other things, an operating system 7941 and a communications control module 7942 having at least a transceiver control module 79421. The communications control module 7942 (using its transceiver control module 79421) is responsible for handling (generating / sending / receiving) signalling between the SMS-GMSC 79 and other nodes, such as the HSS 74 and other core network nodes (including core network nodes in the HPLMN of the UE 3 when the UE 3 is roaming-in). Such signalling may include, for example, appropriately formatted signalling messages (e.g. an interface based on MAP protocol) relating to SMS delivery function procedures (for the UE 3).

[0356] <SC>   Fig. 28 is a block diagram illustrating the main components of the SC 7A. As shown, the apparatus includes a transceiver circuit 781 which is operable to transmit signals to and to receive signals from other nodes (including the HSS 74) via a network interface 7A2. A controller 7A3 controls the operation of the SC 7A in accordance with the software stored in a memory 7A4. The Software may be pre-installed in the memory 7A4 and / or may be downloaded via the telecommunication network or from a removable data storage device (e.g. a removable memory device (RMD)), for example. The software includes, among other things, an operating system 7A41 and a communications control module 7A42 having at least a transceiver control module 7A421. The communications control module 7A42 (using its transceiver control module 7A421) is responsible for handling (generating / sending / receiving) signalling between the SC 7A and other nodes, such as the HSS 74 and other core network nodes (including core network nodes in the HPLMN of the UE 3 when the UE 3 is roaming-in). Such signalling may include, for example, appropriately formatted signalling messages (e.g. an interface based on MAP protocol) relating to SMS delivery function procedures (for the UE 3).

[0357] <OAM>   Fig. 29 is a block diagram illustrating the main components of the OAM 8. As shown, the apparatus includes a transceiver circuit 811 which is operable to transmit signals to and to receive signals from other nodes via a network interface 8012. A controller 813 controls the operation of the OAM 8 in accordance with software stored in a memory 814. Software may be pre-installed in the memory 814 and / or may be downloaded via the telecommunication network or from a removable data storage device (e.g. a removable memory device (RMD)), for example. The software includes, among other things, an operating system 8141 and a communications control module 8142 having at least a transceiver control module 81421. The communications control module 8142 (using its transceiver control module 81421) is responsible for handling (generating / sending / receiving) signalling between the OAM 8 and other nodes. Such signalling may include, for example, appropriately formatted signalling messages (e.g. a proprietary protocol) relating to operation and management related procedures (for the UE 3).

[0358] The OAM 8 may support the Non-Public Network (NPN). The NPN may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).

[0359] <AF>   Fig. 30 is a block diagram illustrating the main components of the AF 201. As shown, the apparatus includes a transceiver circuit 2011 which is operable to transmit signals to and to receive signals from other nodes (including the UE 3 (e.g., the Network Relay UE 300 and the UE 3)) via a network interface 2012. A controller 2013 controls the operation of the AF 201 in accordance with software stored in a memory 2014. Software may be pre-installed in the memory 2014 and / or may be downloaded via the telecommunication network or from a removable data storage device (e.g. a removable memory device (RMD)), for example. The software includes, among other things, an operating system 20141 and a communications control module 20142 having at least a transceiver control module 201421. The communications control module 20142 (using its transceiver control module 201421) is responsible for handling (generating / sending / receiving) signalling between the AF 201 and other nodes, such as the UE 3 and other core network nodes (including core network nodes in the HPLMN of the UE 3 when the UE 3 is roaming-in). Such signalling may include, for example, appropriately formatted signalling messages (e.g. a HTTP restful methods based on the service based interfaces) relating to policy management procedures (for the UE 3).

[0360] The AF 201 may support the Non-Public Network (NPN). The NPN may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).

[0361] The Energy monitor AF 20102 and Energy supply AF 20101 may have same components to the AF 201.

[0362] <SCS / AS>   Fig. 31 is a block diagram illustrating the main components of the SCS / AS 211. As shown, the apparatus includes a transceiver circuit 2011 which is operable to transmit signals to and to receive signals from other nodes (including the UE 3 (e.g., the Network Relay UE 300 and the UE 3)) via a network interface 2012. A controller 2013 controls the operation of the SCS / AS 211 in accordance with software stored in a memory 2014. Software may be pre-installed in the memory 2014 and / or may be downloaded via the telecommunication network or from a removable data storage device (e.g. a removable memory device (RMD)), for example. The software includes, among other things, an operating system 20141 and a communications control module 20142 having at least a transceiver control module 201421. The communications control module 20142 (using its transceiver control module 201421) is responsible for handling (generating / sending / receiving) signalling between the SCS / AS 211 and other nodes, such as the UE 3 and other core network nodes (including core network nodes in the HPLMN of the UE 3 when the UE 3 is roaming-in). Such signalling may include, for example, appropriately formatted signalling messages (e.g. a Non-IP data protocol) relating to Non-IP data delivery (for the UE 3).

[0363] The SCS / AS 211 may support the Non-Public Network (NPN). The NPN may be a Stand-alone Non-Public Network (SNPN) or a Public Network Integrated NPN (PNI-NPN).

[0364] The Energy monitor SCS / AS 21102 and Energy supply SCS / AS 21101 may have same components to the SCS / AS 211.

[0365] <Modifications and Alternatives>   Detailed aspects have been described above. As those skilled in the art will appreciate, a number of modifications and alternatives can be made to the above aspects whilst still benefiting from the disclosures embodied therein. By way of illustration only a number of these alternatives and modifications will now be described.

[0366] In the above description, the UE 3 and the network apparatus are described for ease of understanding as having a number of discrete modules (such as the communication control modules). Whilst these modules may be provided in this way for certain applications, for example where an existing system has been modified to implement the disclosure, in other applications, for example in systems designed with the inventive features in mind from the outset, these modules may be built into the overall operating system or code and so these modules may not be discernible as discrete entities. These modules may also be implemented in software, hardware, firmware or a mix of these.

[0367] Each controller may comprise any suitable form of processing circuitry including (but not limited to), for example: one or more hardware implemented computer processors; microprocessors; central processing units (CPUs); arithmetic logic units (ALUs); input / output (IO) circuits; internal memories / caches (program and / or data); processing registers; communication buses (e.g. control, data and / or address buses); direct memory access (DMA) functions, hardware or software implemented counters, pointers and / or timers; and / or the like.

[0368] In the above aspects, a number of software modules were described. As those skilled in the art will appreciate, the software modules may be provided in compiled or un-compiled form and may be supplied to the UE 3 and the network apparatus as a signal over a computer network, or on a recording medium. Further, the functionality performed by part or all of this software may be performed using one or more dedicated hardware circuits. However, the use of software modules is preferred as it facilitates the updating of the UE 3 and the network apparatus in order to update their functionalities.

[0369] In the above aspects, a 3GPP radio communications (radio access) technology is used. However, any other radio communications technology (e.g. WLAN, Wi-Fi, WiMAX, Bluetooth, etc.) and other fix line communications technology (e.g. BBF Access, Cable Access, optical access, etc.) may also be used in accordance with the above aspects.

[0370] Items of user equipment might include, for example, communication devices such as mobile telephones, smartphones, user equipment, personal digital assistants, laptop / tablet computers, web browsers, e-book readers and / or the like. Such mobile (or even generally stationary) devices are typically operated by a user, although it is also possible to connect so-called 'Internet of Things' (IoT) devices and similar machine-type communication (MTC) devices to the network. For simplicity, the present application refers to mobile devices (or UEs) in the description but it will be appreciated that the technology described can be implemented on any communication devices (mobile and / or generally stationary) that can connect to a communications network for sending / receiving data, regardless of whether such communication devices are controlled by human input or software instructions stored in memory.

[0371] Various other modifications will be apparent to those skilled in the art and will not be described in further detail here.

[0372] As will be appreciated by one of skill in the art, the present disclosure may be embodied as a method, and system. Accordingly, the present disclosure may take the form of an entirely hardware embodiment, a software embodiment or an embodiment combining software and hardware aspects.

[0373] It will be understood that each block of the block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general-purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. A general-purpose processor may be a microprocessor, but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices, e.g., a plurality of microprocessors, one or more microprocessors, or any other such configuration.

[0374] The methods or algorithms described in connection with the examples disclosed herein may be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module may reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. A storage medium may be coupled to the processor such that the processor can read information from, and write information to, the storage medium. In the alternative, the storage medium may be integral to the processor. The processor and the storage medium may reside in an ASIC.

[0375] The previous description of the disclosed examples is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these examples will be readily apparent to those skilled in the art, and the generic principles defined herein may be applied to other examples without departing from the spirit or scope of the disclosure. Thus, the present disclosure is not intended to be limited to the examples shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0376] While the disclosure has been particularly shown and described with reference to exemplary Aspects thereof, the disclosure is not limited to these Aspects. It will be understood by those of ordinary skill in the art that various changes in form and details may be made therein without departing from the spirit and scope of the present disclosure as defined by this document. For example, the Aspects above are not limited to 5GS, and the Aspects are also applicable to communication system other than 5GS (e.g., 6G system, 5G beyond system).

[0377] <Supplementary notes>   The whole or part of the example Aspects disclosed above can be described as, but not limited to, the following supplementary notes.   (Supplementary note 1)   A method performed by a user equipment (UE), the method comprising:   receiving, from a Radio Access Network (RAN) corresponding to a first satellite, system information comprising information related to whether the RAN supports a store and forward operation;   sending, to a core network device corresponding to the first satellite, a first Non-Access-Stratum (NAS) request message with NAS integrity protection, the first NAS message comprising a Globally Unique Temporary UE Identity (GUTI) and a capability related to the store and forward operation;   increasing an Uplink NAS count after sending the first NAS request message; and   receiving, from the core network device corresponding to the first satellite, a first NAS reject message without NAS integrity protection, the first NAS reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation, wherein   the method comprises determining, based on a first condition, whether to decrease the Uplink NAS count after receiving the first NAS reject message.   (Supplementary note 2)   The method according to supplementary note 1, wherein   the first condition comprises at least one of:   the UE accesses to a cell that supports the store and forward operation;   the UE indicates the capability related to the store and forward operation in the first NAS request message sent to the core network device corresponding to the first satellite;   the first NAS reject message comprises the cause indicating the store and forward operation not supported,   the first NAS reject message comprises the wait timer related to the store and forward operation,   the first NAS reject message comprises both the cause indicating the store and forward operation not supported and the wait timer related to the store and forward operation, and   the UE is in the store and forward operation.   (Supplementary note 3)   The method according to supplementary note 1, wherein   the method comprises updating a Downlink NAS count after receiving the NAS reject message,   the updating the Downlink NAS count comprises increasing the Downlink NAS count or not increasing the Downlink NAS count.   (Supplementary note 4)   The method according to supplementary note 1, wherein   the first NAS request message comprising a Tracking Area Update (TAU) request message, an ATTACH request message, a Service Request message, a Packet Data Network (PDN) connectivity request message, and a Control Plane Service Request message.   (Supplementary note 5)   The method according to supplementary note 1, wherein   the first NAS reject message comprising a Tracking Area Update (TAU) reject message, an ATTACH reject message, a Service Reject message, a Packet Data Network (PDN) connectivity reject message, and a Control Plane Service Reject message.   (Supplementary note 6)   A method performed by a core network device corresponding to a first satellite, the method comprising:   receiving, from a user equipment (UE), a first Non-Access-Stratum (NAS) request message with NAS integrity protection, the first NAS message comprising a Globally Unique Temporary UE Identity (GUTI) and a capability related to the store and forward operation;   determining whether a feeder link for the core network device is available; and   sending, to the UE, a first NAS reject message without NAS integrity protection based on the determination that the feeder link is not available, the first NAS reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation.   (Supplementary note 7)   The method according to supplementary note 6, wherein   the method comprises increasing a Downlink NAS count after sending the first NAS reject message.   (Supplementary note 8)   A method performed by a user equipment (UE), the method comprising:   receiving, from a Radio Access Network (RAN) corresponding to a first satellite, system information comprising information related to whether the RAN supports a store and forward operation and a status related to a feeder link for the RAN;   sending, to a core network device corresponding to the first satellite, an Attach Request message comprising EPS mobile identity and a first data; and   receiving, from the core network device corresponding to the first satellite, an Attach Reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation.   (Supplementary note 9)   A method performed by a core network device corresponding to the first satellite, the method comprising:   receiving, from a user equipment (UE), an Attach Request message comprising EPS mobile identity and a first data;   determining whether a feeder link for the core network device is available; and   sending, to the UE, an Attach Reject message based on the determination that the feeder link is not available, the Attach Reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation.   (Supplementary note 10)   A user equipment (UE) comprising:   one or more memories storing instructions; and   one or more processors configured to process the instructions to control the UE to:   receive, from a Radio Access Network (RAN) corresponding to a first satellite, system information comprising information related to whether the RAN supports a store and forward operation;   send, to a core network device corresponding to the first satellite, a first Non-Access-Stratum (NAS) request message with NAS integrity protection, the first NAS message comprising a Globally Unique Temporary UE Identity (GUTI) and a capability related to the store and forward operation;   increase an Uplink NAS count after sending the first NAS request message; and   receive, from the core network device corresponding to the first satellite, a first NAS reject message without NAS integrity protection, the first NAS reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation, wherein   the one or more processors are configured to process the instructions to control the UE to determine, based on a first condition, whether to decrease the Uplink NAS count after receiving the first NAS reject message.   (Supplementary note 11)   The UE according to supplementary note 10, wherein   the first condition comprises at least one of:   the UE accesses to a cell that supports the store and forward operation;   the UE indicates the capability related to the store and forward operation in the first NAS request message sent to the core network device corresponding to the first satellite;   the first NAS reject message comprises the cause indicating the store and forward operation not supported,   the first NAS reject message comprises the wait timer related to the store and forward operation,   the first NAS reject message comprises both the cause indicating the store and forward operation not supported and the wait timer related to the store and forward operation, and   the UE is in the store and forward operation.   (Supplementary note 12)   The UE according to supplementary note 10, wherein   the one or more processors are configured to process the instructions to control the UE to update a Downlink NAS count after receiving the NAS reject message, wherein   the update of the Downlink NAS count comprises increasing the Downlink NAS count or not increasing the Downlink NAS count.   (Supplementary note 13)   The UE according to supplementary note 10, wherein   the first NAS request message comprising a Tracking Area Update (TAU) request message, an ATTACH request message, a Service Request message, a Packet Data Network (PDN) connectivity request message, and a Control Plane Service Request message.   (Supplementary note 14)   The UE according to supplementary note 10, wherein   the first NAS reject message comprising a Tracking Area Update (TAU) reject message, an ATTACH reject message, a Service Reject message, a Packet Data Network (PDN) connectivity reject message, and a Control Plane Service Reject message.   (Supplementary note 15)   A core network device corresponding to a first satellite, the core network device comprising:   one or more memories storing instructions; and   one or more processors configured to process the instructions to control the core network device to:   receive, from a user equipment (UE), a first Non-Access-Stratum (NAS) request message with NAS integrity protection, the first NAS message comprising a Globally Unique Temporary UE Identity (GUTI) and a capability related to the store and forward operation;   determine whether a feeder link for the core network device is available; and   send, to the UE, a first NAS reject message without NAS integrity protection based on the determination that the feeder link is not available, the first NAS reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation.   (Supplementary note 16)   The core network device according to supplementary note 15, wherein   the one or more processors are configured to process the instructions to control the core network device to increase a Downlink NAS count after sending the first NAS reject message.   (Supplementary note 17)   A user equipment (UE) comprising:   one or more memories storing instructions; and   one or more processors configured to process the instructions to control the UE to:   receive, from a Radio Access Network (RAN) corresponding to a first satellite, system information comprising information related to whether the RAN supports a store and forward operation and a status related to a feeder link for the RAN;   send, to a core network device corresponding to the first satellite, an Attach Request message comprising EPS mobile identity and a first data; and   receive, from the core network device corresponding to the first satellite, an Attach Reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation.   (Supplementary note 18)   A core network device corresponding to the first satellite, the core network device comprising:   one or more memories storing instructions; and   one or more processors configured to process the instructions to control the core network device to:   receive, from a user equipment (UE), an Attach Request message comprising EPS mobile identity and a first data;   determine whether a feeder link for the core network device is available; and   send, to the UE, an Attach Reject message based on the determination that the feeder link is not available, the Attach Reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation. <Key Issue 1>   TS 24.301 5.5.1.1  General   The attach procedure is used to attach to an EPC for packet services in EPS.   The attach procedure is used for the following purposes: -  by a UE in PS mode of operation to attach for EPS services only; -  by a UE in CS / PS mode 1 or CS / PS mode 2 of operation to attach for both EPS and non-EPS services; -  by a UE supporting NB-S1 mode only in PS mode of operation to attach for EPS services and "SMS only"; -  to attach for emergency bearer services; -  an attach for access to RLOS; -  the UE has initiated a GPRS attach procedure while in A / Gb mode or Iu mode or an initial registration procedure while in N1 mode and moves to E-UTRAN coverage; or -  when the UE attached to a network supporting S&F mode and changes TA which is not the registration area list, the UE in this case ignores the valid GUTI and sends IMSI in the attach request message. The attach request message is sent without integrity protection.   The lower layers indicate to NAS that the network does not support emergency bearer services for the UE in limited service state (3GPP TS 36.331

[0022] ). This information is taken into account when deciding whether to initiate attach for emergency bearer services in WB-S1 mode.   If the MME does not support an attach for emergency bearer services, the MME shall reject any request to attach with an attach type set to "EPS emergency attach".   If the MUSIM UE initiates the attach procedure and sets the attach type to "EPS emergency attach" in the ATTACH REQUEST message, the network shall not indicate the support of: -  the NAS signalling connection release; -  the paging indication for voice services; -  the reject paging request; -  the paging restriction; or -  the paging timing collision control;   in the ATTACH ACCEPT message.   The lower layers may indicate to NAS whether the network supports access to RLOS (3GPP TS 36.331

[0022] ). This information is taken into account when deciding whether to initiate attach for access to RLOS in WB-S1 mode.   With a successful attach procedure, a context is established for the UE in the MME. Furthermore, if the UE requested PDN connectivity, a default bearer is established between the UE and the PDN GW, thus enabling always-on IP connectivity to the UE. In WB-S1 mode, the network may also initiate the activation of dedicated bearers as part of the attach procedure. In NB-S1 mode the network shall not initiate the activation of dedicated bearers.   With a successful attach procedure in NB-S1 mode, a context is established for the UE in the MME. If the attach request included information to request PDN connectivity, a default bearer is also established between the UE and the PDN.   If EMM-REGISTERED without PDN connection is supported by the UE and the MME, a default bearer need not be requested by the UE during the attach procedure. If EMM-REGISTERED without PDN connection is not supported by the UE or the MME, then the UE shall request establishment of a default bearer.   During the attach procedure with default bearer establishment, the UE may also obtain the home agent IPv4 or IPv6 address or both.   In a shared network, the UE shall choose one of the PLMN identities as specified in 3GPP TS 23.122 [6]. The UE shall construct the TAI of the cell from this chosen PLMN identity and the TAC received for this PLMN identity as part of the broadcast system information. The chosen PLMN identity shall be indicated to the E-UTRAN (see 3GPP TS 36.331

[0022] ). Whenever an ATTACH REJECT message with the EMM cause #11 "PLMN not allowed" is received by the UE, the chosen PLMN identity shall be stored in the "forbidden PLMN list" and if the UE is configured to use timer T3245 (see 3GPP TS 24.368 [15A] or 3GPP TS 31.102

[0017] ) then the UE shall start timer T3245 and proceed as described in clause 5.3.7a. Whenever an ATTACH REJECT message with the EMM cause #14 "EPS services not allowed in this PLMN" is received by the UE, the chosen PLMN identity shall be stored in the "forbidden PLMNs for GPRS service" and if the UE is configured to use timer T3245 (see 3GPP TS 24.368 [15A] or 3GPP TS 31.102

[0017] ) then the UE shall start timer T3245 and proceed as described in clause 5.3.7a. Whenever an ATTACH REJECT message is received by the UE with the EMM cause #12 "tracking area not allowed", #13 "roaming not allowed in this tracking area", or #15 "no suitable cells in tracking area", the constructed TAI shall be stored in the suitable list.   An attach attempt counter is used to limit the number of subsequently rejected attach attempts. The attach attempt counter shall be incremented as specified in clause 5.5.1.2.6. Depending on the value of the attach attempt counter, specific actions shall be performed. The attach attempt counter shall be reset when: -  the UE is powered on; -  a USIM is inserted; -  an attach or combined attach procedure is successfully completed; NOTE:  The attach procedure can be initiated in S1 or S101 mode as described in clause 5.5.1. -  a GPRS attach or combined GPRS attach procedure is successfully completed in A / Gb or Iu mode; -  a registration procedure for initial registration performed over 3GPP access is successfully completed in N1 mode and the UE is operating in single-registration mode; -  a combined attach procedure is completed for EPS services only with cause #2, #16, #17, #18 or #22; -  an attach or combined attach procedure is rejected with cause #11, #12, #13, #14, #15, #25 or #35: -  a network initiated detach procedure is completed with cause #11, #12, #13, #14, #15 or #25; or -  a new PLMN is selected.   Additionally the attach attempt counter shall be reset when the UE is in substate EMM-DEREGISTERED.ATTEMPTING-TO-ATTACH and: -  a new tracking area is entered; -  timer T3402 expires; or -  timer T3346 is started.   The UE implementation specific attempt counter defined in clause 5.5.1.2.6 case aa) shall be reset when: -  the UE is powered on; -  a USIM is inserted; -  the UE enters EMM-CONNECTED mode; -  the attach request fails due to abnormal cases b), c) or d), as well as l) when the "Extended wait time" is ignored, and la) when the "Extended wait time CP data" is ignored in clause 5.5.1.2.6; -  a GPRS attach or combined GPRS attach procedure is successfully completed in A / Gb or Iu mode; -  a registration procedure for initial registration performed over 3GPP access is successfully completed in N1 mode and the UE is operating in single-registration mode; or -  a new suitable cell of the selected PLMN or a new PLMN is selected in S1 mode. 4.4.3  Handling of NAS COUNT and NAS sequence number 4.4.3.1  General   Each EPS security context shall be associated with two separate counters NAS COUNT: one related to uplink NAS messages and one related to downlink NAS messages. The NAS COUNT counters use 24 bit internal representation and are independently maintained by UE and MME. The NAS COUNT shall be constructed as a NAS sequence number (8 least significant bits) concatenated with a NAS overflow counter (16 most significant bits).   When NAS COUNT is input to NAS ciphering or NAS integrity algorithms it shall be considered to be a 32-bit entity which shall be constructed by padding the 24-bit internal representation with 8 zeros in the most significant bits.   The value of the uplink NAS COUNT that is stored or read out of the USIM or non-volatile memory as described in annex C, is the value that shall be used in the next NAS message.   The value of the downlink NAS COUNT that is stored or read out of the USIM or non-volatile memory as described in annex C, is the largest downlink NAS COUNT used in a successfully integrity checked NAS message.   The value of the uplink NAS COUNT stored in the MME is the largest uplink NAS COUNT used in a successfully integrity checked NAS message.   The value of the downlink NAS COUNT stored in the MME is the value that shall be used in the next NAS message.   The NAS sequence number part of the NAS COUNT shall be exchanged between the UE and the MME as part of the NAS signalling. After each new or retransmitted outbound security protected NAS message, the sender shall increase the NAS COUNT number by one, except for the initial NAS messages if the lower layers indicated the failure to establish the RRC connection (see 3GPP TS 36.331

[0022] ) or the MME rejects the initial NAS message (e.g. attach request or tracking area update message) with cause related to S&F or with S&F wait time. Specifically, on the sender side, the NAS sequence number shall be increased by one, and if the result is zero (due to wrap around), the NAS overflow counter shall also be incremented by one (see clause 4.4.3.5). The receiving side shall estimate the NAS COUNT used by the sending side. Specifically, if the estimated NAS sequence number wraps around, the NAS overflow counter shall be incremented by one. NOTE 0:  When estimating a NAS COUNT, the receiver is required to ensure that a given NAS COUNT value is accepted at most one time, as specified in clause 4.4.3.2.   After the derivation of a NAS token due to an inter-system change from S1mode to A / Gb mode or Iu mode in idle mode as specified in 3GPP TS 24.008

[0013] , the UE shall increase the uplink NAS COUNT by one.   When the MME receives a NAS token via SGSN during an idle mode inter-system change from S1 mode to A / Gb mode or Iu mode, the MME shall check the NAS token as specified in 3GPP TS 33.401

[0019] , clause 9.1.1, and update its uplink NAS COUNT with the uplink NAS COUNT value used for the successful check of the NAS token. NOTE 1:  The MME does not check the NAS token if it is received via SGSN during a connected mode inter-system change from S1 mode to A / Gb mode or Iu mode.   During the handover from UTRAN / GERAN to E-UTRAN, when a mapped EPS security context is derived and taken into use, the MME shall set both the uplink and downlink NAS COUNT counters of this EPS security context to zero. The UE shall set both the uplink and downlink NAS COUNT counters to zero.   When a mapped EPS security context is derived as specified in 3GPP TS 33.501

[0056] and taken into use in the following cases: -  during the inter-system change from N1 mode to S1 mode in 5GMM-CONNECTED mode; or -  during the inter-system change from N1 mode to S1 mode in EMM-IDLE mode for the UE operating in single-registration mode in a network supporting N26 interface,   the MME shall store the mapped EPS NAS security context with the uplink and downlink NAS COUNT counters associated with the derived K'ASMEkey set to the uplink and downlink NAS COUNT counters of the mapped EPS NAS security context respectively. The UE shall set the uplink and downlink NAS COUNT counters to the uplink and downlink NAS COUNT counters of the current 5G NAS security context respectively.   During the handover from E-UTRAN to UTRAN / GERAN the MME signals the current downlink NAS COUNT value in a NAS security transparent container (see clause 9.9.2.6).   During handover to or from E-UTRAN, the MME shall increment downlink NAS COUNT by one after it has created a NAS security transparent container (see clause 9.9.2.6 and 9.9.2.7). NOTE 2:  During the handover from UTRAN / GERAN to E-UTRAN, the NAS security transparent container (see clause 9.9.2.7) is treated as an implicit SECURITY MODE COMMAND message for the UE and the MME, and therefore the MME regards the sending of the NAS security transparent container as the sending of an initial SECURITY MODE COMMAND message in order to derive and take into use a mapped EPS security context for the purpose of the NAS COUNT handling.   In some NAS messages only 5 of the 8 NAS sequence number bits are transmitted. When this is the case, the receiver shall estimate the remaining 3 most significant bits of the sequence number.   During a tracking area update procedure when the UE supporting S&F operation moves from one tracking area to another tracking area in a network operating in S&F mode, the new MME replaces the NAS sequence number part of the received uplink NAS COUNT with the received NAS sequence number of tracking area update request message which was received in the new MME after the new MME fetches the UE context from the old MME. Please refer CR S2-2410989 and S2-2410927. The MME stores this Uplink NAS COUNT and uses this uplink NAS COUNT for subsequent integrity protection or ciphering of the received uplink NAS message. <Key Issue 2>   TS 23.401 5.3.4B  Data Transport in Control Plane CIoT EPS Optimisation 5.3.4B.1  General   If the UE and MME use the Control Plane CIoT EPS Optimisation, they can transfer data in NAS PDUs including the EPS Bearer Identity of the PDN connection they relate to, for which there is no S1-U bearers established (i.e. when an S1-U bearer is established the UE shall use S1-U to transfer data PDUs). All PDN types are supported. If the UE and the MME support Control Plane CIoT EPS Optimisation, then for SMS transfer and EPC Mobile Originated Location Request (EPC-MO-LR) or EPC Mobile Terminated Location Request (EPC-MT-LR) the Service Request procedures defined in clause 5.3.4 are not used for MO and MT SMS or for EPC-MO-LR and EPC-MT-LR, but instead UE and MME shall be using the Data Transport in Control Plane CIoT EPS Optimisation.   This is accomplished by using the NAS transport capabilities of RRC and S1-AP protocols and the data transport of GTP-u tunnels between MME and S-GW and between S-GW and P-GW, or if a Non-IP connection is provided by via the MME with the SCEF, then data transfer occurs as indicated in TS 23.682

[0074] .   For IP data, the UE and MME may perform header compression based on ROHC framework IETF RFC 5795

[0077] . For uplink IP data, UE implements ROHC compressor, and MME implements the decompressor. For downlink IP data, MME implements the ROHC compressor, and UE implements the decompressor. The uplink and downlink ROHC channels are bound by UE and MME to support feedback. The configurations for the header compression are established during the PDN connection establishment procedure.   To minimise potential conflicts between NAS signalling PDUs and NAS Data PDUs, the MME should complete any security related procedures (e.g. Authentication, Security Mode Command, GUTI reallocation) before alerting the HSS, MSC or SGW of the UE's entry into ECM-CONNECTED state, and before commencing downlink transfer of NAS Data PDUs. The priority handling between the EMM / ESM NAS signalling PDUs and NAS Data PDUs is specified in TS 24.301

[0046] . 5.3.4B.2  Mobile Originated Data Transport in Control Plane CIoT EPS Optimisation with P-GW connectivity 0.  The UE is ECM-IDLE. The UE supports S&F operation mode and attached to the network supporting S&F. the MME is split into MME in the satellite and MME in the ground. The eNodeB and the MME in the satellite are in the satellite. The eNodeB broadcasts S&F support indicator in an existing SIB / MIB or a new SIB. 1.  The UE establishes a RRC connection or sends the RRCEarlyDataRequest message as defined in TS 36.300 [5] and sends as part of it an integrity protected NAS PDU. The NAS PDU carries the EPS Bearer ID and encrypted Uplink Data. For IP PDN type PDN connections configured to support Header Compression, the UE shall apply header compression before encapsulating data into the NAS message. The UE may also indicate in a NAS Release Assistance Information in the NAS PDU whether no further Uplink or Downlink Data transmissions are expected, or only a single Downlink data transmission (e.g. Acknowledgement or response to Uplink data) subsequent to this Uplink Data transmission is expected or delivery confirmation request which requests the network to send a delivery report of the NAS PDU to AF and PDU sequence number. 1b.  In the NB-IoT case, the eNodeB, based on configuration, may retrieve the EPS negotiated QoS profile from the MME, if not previously retrieved. The MME Code within the S-TMSI in the RRCConnectionRequest message is used to identify the MME. In the case of network sharing, the MME Codes shall be unique within the area of overlapping MME pools of the participating operators. The eNodeB may apply prioritisation between requests from different UEs before triggering step 2 and throughout the RRC connection. The eNodeB may retrieve additional parameters (e.g., UE Radio Capabilities - see TS 36.413

[0036] ). 2.  The NAS PDU sent in step 1 is relayed to the MME by the eNodeB using a S1-AP Initial UE message. If the RRCEarlyDataRequest message was received in step 1, the eNodeB includes the "EDT Session" indication in the S1-AP Initial UE message.   To assist Location Services, the eNodeB indicates the UE's Coverage Level to the MME.   If the NAS Release Assistance Information is received from the UE it overrides the Traffic Profile (see TS 23.682

[0074] ) and the MME does not send the Traffic Profile to the eNodeB. 3.  If there is a Service Gap timer running in the MME MM Context for the UE and the MME is not waiting for a MT paging response from the UE, the MME rejects the request by discarding the NAS data PDU and sending a Service Reject message to the UE with an appropriate cause. The MME may also provide UE with a Mobility Management Back-off timer set to the remaining value of Service Gap timer, followed by executing step 15.   The MME checks the integrity of the incoming NAS PDU and decrypts the data it contains. When the ROHC is configured to be used, the MME shall decompress the IP header if header compression applies to the PDN connection. The MME (MME in the satellite and MME in the ground) stores the delivery confirmation request received in the NAS PDU. The stores the time stamp when the MME receives the NAS PDU.   The MME performs (and the UE responds to) any EMM or ESM procedures if necessary, e.g. the security related procedures. Steps 4 to 9 can continue in parallel to this, however, steps 10 and 11 shall await completion of all the EMM and ESM procedures. 4a.  If the S11-U connection is not established, the MME sends a Modify Bearer Request message (MME address, MME TEID DL, Delay Downlink Packet Notification Request, RAT Type, LTE-M RAT type reporting to PGW flag, MO Exception data counter) for each PDN connection to the Serving GW. The Serving GW is now able to transmit downlink data towards the UE. The usage of the Delay Downlink Packet Notification Request Information Element is specified in clause 5.3.4.2 with reference to the UE initiated service request procedure, but it equally applies in this case. The MME shall indicate S11-U tunnelling of NAS user data and send its own S11-U IP address and MME DL TEID for DL data forwarding by the SGW. Also, regardless of whether the S11-U was already established: -  If the PDN GW requested UE's location and / or User CSG information and the UE's location and / or User CSG information has changed, the MME shall send the Modify Bearer Request message and also includes the User Location Information IE and / or User CSG Information IE in this message. -  If the Serving Network IE has changed compared to the last reported Serving Network IE then the MME shall send the Modify Bearer Request message and also includes the Serving Network IE in this message. -  If the UE Time Zone has changed compared to the last reported UE Time Zone then the MME shall send the Modify Bearer Request message and include the UE Time Zone IE in this message.   If the RAT type currently used is NB-IOT this shall be reported as different from other E-UTRA flavours.   If the UE is using the LTE-M RAT type and the PDN GW expects the LTE-M RAT type reporting as specified in clause 5.11.5, the MME also includes the LTE-M RAT type reporting to PGW flag to indicate to the Serving GW to forward the LTE-M RAT type to the PDN GW.   The MME only includes MO Exception data counter if the RRC establishment cause is set to "MO exception data" and the UE is accessing via the NB-IoT RAT. The Serving GW indicates each use of this RRC establishment cause by the related counter on its CDR. The MME maintains the MO Exception Data Counter for Serving PLMN Rate Control purposes (see clause 4.7.7.2). The MME may immediately send the MO Exception Data Counter to the Serving GW. Alternatively, in order to reduce signalling, the MME may send the MO Exception Data Counter to the Serving GW as indicated in TS 29.274

[0043] .   The MME sends the UEs S&F capability and optionally the UE is registered with S&F network in the modify bearer request message. 4b.  If the S11-U connection is established and the UE is accessing via the NB-IoT RAT with the RRC establishment cause set to "MO exception data", the MME should notify the Serving Gateway. The MME maintains the MO Exception Data Counter for Serving PLMN Rate Control purposes (see clause 4.7.7.2). The MME may immediately send the MO Exception Data Counter to the Serving GW. Alternatively, in order to reduce signalling, the MME may send the MO Exception Data Counter to the Serving GW as indicated in TS 29.274

[0043] . 5.  If the RAT Type has changed compared to the last reported RAT Type or if the UE's Location and / or Info IEs and / or UE Time Zone and Serving Network id are present in step 4, the Serving GW shall send the Modify Bearer Request message (RAT Type, MO Exception data counter) to the PDN GW. User Location Information IE and / or User CSG Information IE and / or Serving Network IE and / or UE Time Zone are also included if they are present in step 4.   If LTE-M RAT type and the LTE-M RAT type reporting to PGW flag were received at step 4a, the Serving GW shall include the LTE-M RAT type in the Modify Bearer Request message to the PGW. Otherwise the Serving GW includes RAT type WB-E-UTRAN.   If the Modify Bearer Request message is not sent because of above reasons and the PDN GW charging is paused, then the SGWS-GW shall send a Modify Bearer Request message with PDN Charging Pause Stop Indication to inform the PDN GW that the charging is no longer paused. Other IEs are not included in this message.   If the Modify Bearer Request message is not sent because of above reasons but the MME indicated MO Exception data counter, then the Serving Gateway should notify the PDN GW that this RRC establishment cause has been used by the indication of the MO Exception Data Counter (see TS 29.274

[0043] ). The Serving GW indicates each use of this RRC establishment cause by the related counter on its CDR.   The MME sends the UEs S&F capability and optionally the UE is registered with S&F network in the modify bearer request message. 6.  The PDN GW sends the Modify Bearer Response to the Serving GW.   The PDN GW indicates each use of the RRC establishment cause "MO Exception Data" by the related counter on its CDR. 7.  If a Modify Bearer Request message was sent at step 4 the Serving GW shall return a Modify Bearer Response (Serving GW address and TEID for uplink traffic) to the MME as a response to a Modify Bearer Request message. The Serving GW address for S11-U User Plane and Serving GW TEID are used by the MME to forward UL data to the SGW. 8.  The MME sends Uplink data to the P-GW via the S-GW. This Uplink data contains Delivery confirmation Report information element which the UE sent in step 1 in the NAS PDU. 9.  If no Downlink Data are expected based on the NAS Release Assistance Information from the UE in step 1, this means that all application layer data exchanges have completed with the UL data transfer, and if the MME is not aware of pending MT traffic and S1-U bearers are not established, step 10 is skipped and step 11 applies.   Otherwise, Downlink data may arrive at the P-GW and the P-GW sends them to the MME via the S-GW. If no data is received steps10-12 are skipped and the eNodeB may trigger step 14 after step 13 detects no activity. While the RRC connection is active, the UE may still send Uplink data and may receive Downlink data in NAS PDUs that are carried in a S1AP Uplink or (respectively) Downlink messages (not shown in the figure). At any time the UE has no user plane bearers established it may provide NAS Release Assistance Information with the Uplink data. In this case, to assist Location Services, the eNodeB may indicate, if needed, the UE's Coverage Level to the MME.   When the NAS DATA PDU contains Delivery confirmation Report information element then it is expected to receive the downlink data form the P-GW / S-GW. When the AF / SCEF / SCS receives NAS PDU with Delivery confirmation report, the AF sends a down data PDU with information element delivery confirmation, PDU sequence number as received in the Uplink data PDU to the P-GW and the P-GW forwards the downlink data PDU to the MME. The AF optionally includes the time stamp when the data is received at the AF. 10.  If Downlink data are received in step 9, the MME encrypts and integrity protects the Downlink data. The Downlink data contains the APN, PDU sequence number, EPS Bearer ID and delivery confirmation information element.   When the UE receives the downlink data PDU, the UE determines the successful reception of uplink data PDU sent in step 1 checking the PDU sequence number, delivery confirmation, APN and optionally time stamp. If the UE doesn't receives the delivery confirmation of the transmitted uplink NAS PDU and the UE changes the Tracking area then the UE retransmits the uplink NAS PDU after successful completion of the tracking area procedure. 11.  If step 10 is executed then Downlink data are encapsulated in a NAS PDU and sent to the eNodeB in a S1-AP Downlink NAS Message. If the configuration in the MME indicates that the eNodeB supports acknowledgements of downlink NAS data PDUs and if acknowledgements of downlink NAS data PDUs are enabled in the subscription information for the UE, the MME indicates in the S1-AP Downlink NAS message that acknowledgment is requested from the eNodeB. For IP PDN type PDN connections configured to support Header Compression, the MME shall apply header compression before encapsulating data into the NAS message. If step 10 is not executed, or NAS Service Accept message is not to be sent, the MME sends Connection Establishment Indication message to the eNodeB to complete the establishment of the UE-associated logical S1-connection. The UE Radio Capability may be provided from the MME to the eNodeB in the DL NAS Transport message or Connection Establishment Indication message, and the eNodeB shall store the received UE Radio Capability information as specified in TS 36.300 [5].   If the NAS Release Assistance Information was received with Uplink data and it indicated that Downlink data was expected, it means that the next downlink packet following the sending of the NAS Release Assistance Information is the last packet of the application layer data exchange, then for this case, unless the MME is aware of additional pending MT traffic and unless S1-U bearers are established, the MME sends a S1 UE Context Release Command immediately after the S1-AP message including the Downlink data encapsulated in NAS PDU as an indication that the eNodeB shall release the RRC connection promptly after successfully sending data to the UE. Alternatively, if "EDT Session" indication was received in step 2, the MME may include End Indication for no further data in the S1-AP message including the Downlink data encapsulated in NAS PDU. If the MME includes the End Indication indicating no further data and if the eNodeB does not proceed with RRC connection establishment, then the eNodeB skips step 12a and initiates step 12b.   If the NAS Release Assistance Information was received indicating no Downlink Data expected, it means that all application layer data exchanges have completed with the UL data transfer, then for this case, unless the MME is aware of additional pending MT traffic and unless S1-U bearers are established: -  the MME sends S1AP UE Context Release Command either: -  immediately after the S1AP DL NAS TRANSPORT (NAS Service Accept), in which case steps 12b and 14 are skipped, or -  immediately after S1AP CONNECTION ESTABLISHMENT INDICATION, in which case steps 12a, 12b, 13, and 14 are skipped. -  Alternatively, if the MME received "EDT Session" indication from the eNodeB in step 2, the MME should include End Indication with no further data in S1AP DL NAS TRANSPORT (NAS Service Accept) or S1AP CONNECTION ESTABLISHMENT INDICATION. If the eNodeB does not proceed with RRC connection establishment, the eNodeB skips step 12a and initiates stop 12b.   If the UE is accessing via an NB-IoT cell, or if it is accessing via an WB-E-UTRAN cell and is capable of CE mode B, to determine the NAS PDU retransmission strategy the MME should take into account the transmission delay of the NAS PDU and the CE mode B Restricted parameter stored in the MME's MM context and, if applicable, the CE mode, i.e. set the NAS timers long enough according to the worst transmission delay (see TS 24.301

[0046] ). 12a.  The eNodeB sends a RRC Downlink data message including the Downlink data encapsulated in NAS PDU. If in step 11 the S1-AP message with the NAS DATA PDU was followed by an S1 UE Context Release Command, step 15 is completed promptly after the Downlink Data transmission of the NAS PDU to the UE and the acknowledgement to MME in step 13 have been completed at the eNodeB, and the eNodeB does not need to enter step 14. If header compression was applied to the PDN, the UE would perform header decompression to rebuild the IP header. 12b.  If End Indication with no further data is received in S1AP message from the MME, the eNodeB may send the RRCEarlyDataComplete message with any NAS payload received from step 11 (either NAS data PDU or NAS service accept) as defined in TS 36.300 [5]. Step 14 is skipped in this case. 13.  The eNodeB sends a NAS Delivery indication to the MME if requested. If the eNodeB reports an unsuccessful delivery with an S1-AP NAS Non Delivery Indication, the MME should wait for some time until the UE has potentially changed cell and re-established contact with the MME, by which MME should resend the Downlink S1-AP message to the eNodeB, otherwise the MME reports an unsuccessful delivery to the SCEF in the case of T6a procedure (see TS 23.682

[0074] , clause 5.13.3). If the eNodeB reports a successful delivery with an S1-AP NAS Delivery Indication and if the Downlink data was received over the T6a interface, the MME should respond to the SCEF (see TS 23.682

[0074] , clause 5.13.3). If the eNodeB does not support S1-AP NAS delivery indications, the MME indicates a cause code 'Success Unacknowledged Delivery' to the SCEF otherwise 'Success Acknowledged Delivery', for the SCEF to know if reliable delivery was possible or not. 14.  If no NAS PDU activity exists for a while, the eNodeB starts an S1 release in step 15. 15.  An S1 release procedure according to clause 5.3.5 triggered by the eNodeB or MME. Alternatively, if the MME in step 11 sent S1 UE Context Release Command then the procedure starts with step 5 in clause 5.3.5, or Connection Suspend Procedure defined in clause 5.3.4A. The UE and the MME shall store the ROHC configuration and context for the uplink / downlink data transmission when entering ECM_CONNECTED state next time. 5.3.4B.3  Mobile Terminated Data Transport in Control Plane CIoT EPS Optimisation with P-GW connectivity 0.  The UE is EPS attached and in ECM-Idle mode. The UE supports S&F operation mode and attached to the network supporting S&F. the MME is split into MME in the satellite and MME in the ground. The eNodeB and the MME in the satellite are in the satellite. The eNodeB broadcasts S&F support indicator in an existing SIB / MIB or a new SIB. The AF / SCEF includes Delivery confirmation request, downlink data PDU, timestamp, downlink data PDU sequence number. 1.  When the S-GW receives a downlink data packet / control signalling for a UE, if the S- GW context data indicates no downlink user plane TEID towards the MME), it buffers the downlink data packet and identifies which MME is serving that UE   If that MME has requested the Serving GW to throttle downlink low priority traffic and if the downlink data packet is received on a low priority bearer to be throttled (see clause 4.3.7.4.1a), the S-GW drops the downlink data. The steps below are not executed.   If that MME has requested the S-GW to delay sending the Downlink Data Notification (see clause 5.3.4.2 on "Handling of abnormal conditions in UE triggered Service Request"), the Serving GW buffers the downlink data and waits until the timer expires before continuing with step 2. If the DL-TEID and MME address for that UE is received before the expiry of the timer, the timer shall be cancelled and the Mobile Terminated Data transport procedure is progressed from step 11 as Downlink data are sent to the UE.   If the Serving GW receives additional downlink data packets / control signalling for this UE before the expiry of the timer, the Serving GW does not restart this timer. 2.  If the Serving GW is buffering data in step 1, the Serving GW sends a Downlink Data Notification message (ARP, EPS Bearer ID) to the MME for which it has control plane connectivity for the given UE. The ARP and EPS Bearer ID are always set in Downlink Data Notification. The MME responds to the S-GW with a Downlink Data Notification Ack message.   An MME detects that the UE is in a power saving state (e.g. Power Saving Mode) and cannot be reached by paging at the time of receiving Downlink data notification, shall invoke extended buffering depending on operator configuration, except for cases described in next paragraphs. The MME derives the expected time before radio bearers can be established to the UE. The MME then indicates Downlink Buffering Requested to the Serving GW in the Downlink Data Notification Ack message and includes a Downlink Buffering Duration time and optionally a Downlink Buffering Suggested Packet Count. The MME stores a new value for the Downlink Data Buffer Expiration Time in the MM context for the UE based on the Downlink Buffering Duration time and skips the remaining steps of this procedure. The Downlink Data Buffer Expiration Time is used for UEs using power saving state and indicates that there are buffered data in the Serving GW and that the user plane setup procedure is needed when the UE makes signalling with the network. When the Downlink Data Buffer Expiration Time has expired, the MME considers no Downlink data to be buffered and no indications of Buffered Downlink Data Waiting are sent during context transfers at TAU procedures.   If there is an "Availability after DDN Failure" monitoring event configured for the UE in the MME, the MME does not invoke extended buffering. Instead, the MME sets the Notify-on-available-after-DDN-failure flag to remember to send an "Availability after DDN Failure" notification when the UE becomes available. If there is a "UE Reachability" monitoring event configured for the UE in the MME, the MME does not invoke extended buffering. NOTE 1:  When "Availability after DDN failure" and "UE reachability" monitoring events are used for a UE, the application server is assumed to send data only when the UE is reachable, hence no extended buffering is needed. If there are multiple application servers, the event notifications and extended buffering may be needed simultaneously. It is assumed this is handled through additional information based on SLA as described in the next paragraph.   The MME may use additional information based on a SLA with the MTC user for when to invoke extended buffering, e.g. only invoke it for a certain APN, do not invoke it for certain subscribers, invoke extended buffering in conjunction with "Availability after DDN failure" and "UE reachability" monitoring events, etc.   A Serving GW that receives a Downlink Buffering Requested indication in a Downlink Data Notification Ack message stores a new value for the Downlink Data Buffer Expiration Time based on the Downlink Buffering Duration time and does not send any additional Downlink Data Notification if subsequent downlink data packets are received in the Serving GW before the buffer time Downlink Data Buffer Expiration Time has expired for the UE.   If the Serving GW, while waiting for the user plane to be established, is triggered to send a second Downlink Data Notification for a bearer with higher priority (i.e. ARP priority level) than that of the bearer for which the first Downlink Data Notification was sent, the S-GW sends a new Downlink Data Notification message indicating the higher priority to the MME. If the Serving GW receives additional downlink data packets for a bearer with same or lower priority than the first Downlink Data Notification was sent for or if the Serving GW has sent the second Downlink Data Notification message indicating the higher priority and receives additional downlink data packets for this UE, the Serving GW buffers these downlink data packets and does not send a new Downlink Data Notification.   If the Serving GW, while waiting for the user plane to be established, receives a Modify Bearer Request message from an MME other than the one it sent a Downlink Data Notification message to, the Serving GW re-sends the Downlink Data Notification message but only to the new MME from which it received the Modify Bearer Request message.   If the MME holds stored Paging Restriction Information (see clause 4.3.33.6) for the UE that restricts the Downlink Data from causing paging, the MME sends Downlink Data Notification Ack message with an indication that the Downlink Data Notification message has been temporarily rejected.   Upon reception of a Downlink Data Notification Ack message with an indication that the Downlink Data Notification message has been temporarily rejected and if the Downlink Data Notification is triggered by the arrival of downlink data packets at the Serving GW, the Serving GW may start a locally configured guard timer and buffers all downlink user packets received to the given UE and waits for a Modify Bearer Request message to come. Upon reception of a Modify Bearer Request message, the Serving GW re-sends the Downlink Data Notification message but only to the new MME from which it received the Modify Bearer Request message. Otherwise the Serving GW releases buffered downlink user packets upon expiry of the guard timer or upon receiving the Delete Session Request message from MME.   If the S11-U is already established (buffering is in the MME), step 2 is not executed and step 11 is immediately executed. Steps 7,8,9,10 are executed only if conditions are met when the NAS control plane service request is received at step 6, as outlined below in the respective clauses.   An MME detecting that the UE is in a power saving state (e.g. Power Saving Mode) and cannot be reached by paging at the time of receiving Downlink data, shall start extended buffering depending on operator configuration, except for cases described in next paragraphs. The MME derives the expected time before radio bearers can be established to the UE, stores a new value for the Downlink Data Buffer Expiration Time in the MM context for the UE and skips the remaining steps of this procedure. When the Downlink Data Buffer Expiration Time has expired, the MME considers no Downlink data to be buffered.   Also for the case of buffering in the MME the "Availability after DDN Failure" monitoring event can be configured for the UE, even though the actual DDN is not received and the Downlink data is received. The "UE Reachability" monitoring event can also be configured. The extended buffering can also be configured as per what is described above in this step of the procedure for the case of buffering in S-GW. 3.  If the UE is registered in the MME and considered reachable, the MME sends Paging message(s) as specified in step 3a of clause 5.3.4.3. 4.  If eNodeBs receive paging messages from the MME, the UE is paged by the eNodeBs as specified in step 4a of clause 5.3.4.3. 5.  As the UE is in the ECM-IDLE state, upon reception of paging indication, the UE sends Control Plane Service Request NAS message (as defined in TS 24.301

[0046] ) over RRC Connection request and S1-AP initial message. The Control Plane Service Request NAS message, when Control Plane CIoT EPS Optimisation applies, does not trigger Data radio bearer establishment by the MME and the MME can immediately send Downlink Data it receives using a NAS PDU to the eNodeB. The MME supervises the paging procedure with a timer. If the MME receives no response from the UE to the Paging Request message, it may repeat the paging according to any applicable paging strategy described in step 3.   If the Multi-USIM UE in ECM-IDLE state, upon reception of paging indication in E-UTRAN access and if the UE decides not to accept the paging, the UE attempts to send a Reject Paging Indication in the Control Plane Service Request NAS message (as defined in TS 24.301

[0046] ) over RRC Connection request and S1-AP initial message. If the Control Plane Service Request NAS message includes a Reject Paging Indication, then: -  If the Service Request message includes Paging Restriction Information, the MME may accept or reject the Paging Restriction Information requested by the UE based on operator policy. If the MME rejects the Paging Restriction Information, the MME removes any stored Paging Restriction Information from the UE context and discards the UE requested Paging Restriction Information. If the MME accepts the Paging Restriction Information from the UE, the MME stores the Paging Restriction Information from the UE in the UE context. The MME informs the UE about the acceptance / rejection of the requested Paging Restriction Information in the Service Accept message. If no Paging Restriction Information is provided, no paging restrictions apply; -  no Downlink or Uplink Data is sent (steps 7-20 are skipped); -  the MME triggers the S1 release procedure in step 21. 5b.  In the NB-IoT case, the eNodeB, based on configuration, may retrieve the EPS negotiated QoS profile from the MME, if not previously retrieved. The MME Code within the S-TMSI in the RRCConnectionRequest message is used to identify the MME. In the case of network sharing, the MME Codes shall be unique within the area of overlapping MME pools of the participating operators. The eNodeB may apply prioritisation between requests from different UEs before triggering step 6 and throughout the RRC connection. The eNodeB may retrieve additional parameters (e.g., UE Radio Capabilities - see TS 36.413

[0036] ). 6.  If the MME receives no response from the UE after this paging repetition procedure, it shall use the Downlink Data Notification Reject message to notify the Serving GW about the paging failure (or, equivalently, if the buffering is in the MME, the MME simply discards data for the UE locally), unless the MME is aware of an ongoing MM procedure that prevents the UE from responding, i.e. the MME received a Context Request message indicating that the UE performs TAU with another MME. When a Downlink Data Notification Reject message is received, the Serving GW deletes the buffered packet(s). The Serving GW may invoke the procedure PDN GW Pause of Charging (clause 5.3.6A) if UE is in ECM IDLE and the PDN GW has enabled "PDN charging pause" feature. If buffering is in the MME, Pause Charging is triggered by the MME via a Release Access Bearer Request to the S-GW(not shown in Figure 5.3.4B.3-1) including a "Abnormal Release of Radio Link" cause, which releases the S11-U. NOTE 2:  The Serving GW (or MME, in the case of buffering in the MME) may initiate the procedure P-GW Pause of Charging at any time before step 5 if the UE is in ECM IDLE and the P-GW has indicated that the feature is enabled for this PDN. See clause 5.3.6A.0.   To assist Location Services, the eNodeB indicates the UE's Coverage Level to the MME.   The MME performs (and the UE responds to) any EMM or ESM procedures if necessary, e.g. the security related procedures. Steps 7 to 11 can continue in parallel to this, however, steps 12 and 13 shall await completion of all the EMM and ESM procedures. 7.  If the S11-U is not established, the MME sends a Modify Bearer Request message (MME address, MME TEID DL, Delay Downlink Packet Notification Request, RAT Type, LTE-M RAT type reporting to PGW flag) for each PDN connection to the Serving GW. The Serving GW is now able to transmit downlink data towards the UE. The usage of the Delay Downlink Packet Notification Request Information Element is specified in clause 5.3.4.2 with reference to the UE initiated service request procedure, but it equally applies in this case. The MME shall indicate S11-U tunnelling of NAS user data and send its own S11-U IP address and MME DL TEID for DL data forwarding by the SGW. Also, regardless of whether the S11-U was already established: -  If the P-GW requested UE's location and / or User CSG information and the UE's location and / or User CSG information has changed, the MME shall send the Modify Bearer Request message and also includes the User Location Information IE and / or User CSG Information IE in this message. -  If the Serving Network IE has changed compared to the last reported Serving Network IE then the MME shall send the Modify Bearer Request message and also includes the Serving Network IE in this message. -  If the UE Time Zone has changed compared to the last reported UE Time Zone then the MME shall send the Modify Bearer Request message and include the UE Time Zone IE in this message.   If the RAT type currently used is NB-IOT this shall be reported as different from other -E-UTRA flavours.   If the UE is using the LTE-M RAT type and the PDN GW expects the LTE-M RAT type reporting as specified in clause 5.11.5, the MME also includes the LTE-M RAT type reporting to PGW flag to indicate to the Serving GW to forward the LTE-M RAT type to the PDN GW. 8.  If the RAT Type has changed compared to the last reported RAT Type or if the UE's Location and / or Info IEs and / or UE Time Zone and Serving Network id are present in step 7, the Serving GW shall send the Modify Bearer Request message (RAT Type) to the P-GW. User Location Information IE and / or User CSG Information IE and / or Serving Network IE and / or UE Time Zone are also included if they are present in step 7.   If LTE-M RAT type and the LTE-M RAT type reporting to PGW flag were received at step 7, the Serving GW shall include the LTE-M RAT type in the Modify Bearer Request message to the PGW. Otherwise the Serving GW includes RAT type WB-E-UTRAN.   If the Modify Bearer Request message is not sent because of above reasons and the PDN GW charging is paused, then the S-GW shall send a Modify Bearer Request message with PDN Charging Pause Stop Indication to inform the PDN GW that the charging is no longer paused. Other IEs are not included in this message. 9.  The PDN GW sends the Modify Bearer Response to the Serving GW. 10.  If a Modify Bearer Request message was sent at step 7, the Serving GW shall return a Modify Bearer Response (Serving GW address and TEID for uplink traffic) to the MME as a response to a Modify Bearer Request message. The Serving GW address for S11-U User Plane and Serving GW TEID are used by the MME to forward UL data to the SGW. 11.  Buffered (if S11-U was not established) Downlink data is sent by the S-GW to the MME. 12-13.  The MME encrypts and integrity protects Downlink data and sends it to the eNodeB using a NAS PDU carried by a Downlink S1-AP message. If the configuration in the MME indicates that the eNodeB supports acknowledgements of downlink NAS data PDUs and if acknowledgements of downlink NAS data PDUs are enabled in the subscription information for the UE, the MME indicates in the Downlink S1-AP message that acknowledgment is requested from the eNodeB. For IP PDN type PDN connections configured to support Header Compression, the MME shall apply header compression before encapsulating data into the NAS message. Alternatively and if the MME decides that S1-U bearers need to be established in the case that the UE and MME accept User Plane EPS Optimisation or S1-U data transfer, steps 4-12 from clause 5.3.4.1 are followed.   If the UE is accessing via an NB-IoT cell, or if it is accessing via an WB-E-UTRAN cell and is capable of CE mode B, to determine the NAS PDU retransmission strategy the MME should take into account the transmission delay of the NAS PDU and the CE mode B Restricted parameter stored in the MME's MM context and, if applicable, the CE mode, i.e. set the NAS timers long enough according to the worst transmission delay (see TS 24.301

[0046] ). 14.  The NAS PDU with data is delivered to the UE via a Downlink RRC message. This is taken by the UE as implicit acknowledgment of the Service Request message sent in step 5. If header compression was applied, to the PDN, the UE shall perform header decompression to rebuild the IP header. When the delivery confirmation is information element is included in the downlink NAS PDU the UE transmits uplink NAD PDU containing data PDU with information delivery confirmation report, received downlink data PDU, timestamp, downlink data PDU sequence number and in addition the time stamp when the NAS PDU is received at the UE. 15.  The eNodeB sends a NAS Delivery indication to the MME if requested. If the eNodeB reports an unsuccessful delivery with an S1-AP NAS Non Delivery Indication, the MME should wait for some time until the UE has potentially changed cell and re-established contact with the MME, by which MME should resend the Downlink S1-AP message to the eNodeB, otherwise the MME reports an unsuccessful delivery to the SCEF in the case of T6a procedure (see TS 23.682

[0074] , clause 5.13.3). If the eNodeB reports a successful delivery with an S1-AP NAS Delivery Indication and if the Downlink data was received over the T6a interface, the MME should respond to the SCEF (see TS 23.682

[0074] , clause 5.13.3). If the eNodeB does not support S1-AP NAS delivery indications, the MME indicates a cause code 'Success Unacknowledged Delivery' to the SCEF otherwise 'Success Acknowledged Delivery', for the SCEF to know if reliable delivery was possible or not. 16.  While the RRC connection is still up, further Uplink and Downlink data can be transferred using NAS PDUs. In step 17 an Uplink data transfer is shown using an Uplink RRC message encapsulating a NAS PDU with data. At any time the UE has no user plane bearers established, the UE may provide a Release Assistance Information with Uplink data in the NAS PDU.   For IP PDN type PDN connections configured to support Header Compression, the UE shall apply header compression before encapsulating it into the NAS message. 17.  The NAS PDU with data is send to the MME in a Uplink S1-AP message.   To assist Location Services, the eNodeB may indicate, if changed, the UE's Coverage Level to the MME.   If the Release Assistance Information is received from the UE it overrides the Traffic Profile (see TS 23.682

[0074] ) and the MME does not send the Traffic Profile to the eNodeB. 18.  The data is checked for integrity and decrypted. If header compression was applied to the PDN, the MME shall perform header decompression to rebuild the IP header. 19.  The MME sends Uplink data to the PDN GW via the S-GW and executes any action related to the presence of Release Assistance Information as follows: -  for the case where the Release Assistance Information indicates there is no downlink data to follow the uplink data then unless the MME is aware of pending MT traffic, and unless S1-U bearers exist, the MME immediately releases the connection and therefore step 21 is executed. -  for the case where the Release Assistance Information indicates that downlink data will follow the uplink transmission then unless the MME is aware of additional pending MT traffic and unless S1-U bearers exist, the MME sends a S1 UE Context Release Command to the eNodeB immediately after the S1-AP message including the Downlink data encapsulated in NAS PDU. 20.  If no NAS activity exists for a while the eNodeB detects inactivity and executes step 21. 21.  The eNodeB starts an eNodeB initiated S1 release procedure according to clause 5.3.5 or Connection Suspend Procedure defined in clause 5.3.4A. The UE and the MME shall store the ROHC configuration and context for the uplink / downlink data transmission when entering ECM_CONNECTED state next time. <Key issue 3>   3GPP TS23.272. 5.2  Attach procedure   The attach procedure for the CS fallback, SMS over SGs or "SMS in MME" in EPS is realized based on the combined GPRS / IMSI Attach procedure specified in TS 23.060 [3]. 1)  The UE initiates the attach procedure by the transmission of an Attach Request (parameters as specified in TS 23.401 [2] including the Attach Type, old LAI and Mobile Station Classmark 2) message to the MME. The Attach Type indicates that the UE requests a combined EPS / IMSI attach and informs the network that the UE is capable and configured to use CS fallback and / or SMS over SGs. If the UE needs SMS service but not CSFB, the UE shall include an "SMS-only" indication in the combined EPS / IMSI Attach Request. See clause 5.6.   A UE that only supports NB-IoT (see TS 23.401 [2]) may request SMS service but set the Attach Type to EPS attach instead of combined EPS / IMSI attach.   When a UE supporting S&F operation attaches to the network broadcasting support of S&F operation for the combined EPS / IMS attach. 2)  Step 3 to step 16 of the EPS Attach procedure are performed as specified in TS 23.401 [2] with the differences as described below when "SMS in MME" applies: -  If the MME is enabled to use "SMS in MME" and the MME is not registered with an HSS for that UE (i.e. the MME stores no subscriber data for the UE), the MME performs a registration with HSS as described in Annex C, clause C.8. -  If the MME is enabled to use "SMS in MME" and the MME is registered with an HSS for that UE but has no valid SMS subscriber data (i.e. the MME stores subscriber data for the UE but SMS subscriber data have not been requested before or have been removed by the HSS), the MME may perform a re-registration with HSS as described in Annex C, clause C.8 to obtain SMS subscriber data and to provide the HSS with the MME identity to be used for MT-SMS delivery. -  If the HSS supports "SMS in MME", the HSS follows the registration procedures described in Annex C, clause C.8.   If the UE subscribes to the eMLPP (TS 22.067

[0037] ) service in the CS domain or to another CS domain priority scheme (e.g., based on TIA-917

[0046] or TR 22.952

[0047] ) and has a priority level that qualifies for CSFB priority call handling, the UE EPS subscription received from HSS contains the MPS CS Priority indication.   When a UE supporting S&F operation mode is registering to the network through a cell supporting S&F operation, then steps 3 to 7in the figure 5.2-1 are skipped. 3)  If the Attach Request message includes an Attach Type indicating that the UE requests a combined EPS / IMSI attach, or an NB-IoT-only UE requests SMS and the Attach Type indicates EPS attach, the MME allocates a new LAI for the UE as described in clause 5.1A.   The MME does not perform any registrations with a VLR, (i.e. it skips steps 4 to 7 and no SGs association is created), if the Network Access Mode information in the subscriber data indicate that the subscription has no CS subscriber data; or if the HSS registered the MME for "SMS in MME" for the UE as described in Annex C, clause C.8; or if local configuration, e.g. on MSISDN / IMSI segment, indicates that MME should not perform registration with a VLR for the UE (e.g. NB-IoT only UE).   If the registration with a VLR is required and multiple PLMNs are available for the CS domain, the MME performs selection of the PLMN for CS domain and CS domain operator if the selected CS network is shared network configuration, based on the PLMN ID contained in the current TAI, old LAI and operator selection policies on preferred RAT for CS domain. If the target network is a shared GERAN, the MME shall also take into account the UE capability of support or non-support of GERAN network sharing when selecting the PLMN for the CS domain as specified in TS 23.251

[0042] . The PLMN selected for CS should be the same that is used for this UE as a target PLMN for PS handovers or for any other mobility procedures related to CSFB. The MME may take any access restrictions provided by the HSS into account, if the network is using separate location areas for GERAN and UTRAN cells. The selected PLMN ID is included in the newly allocated LAI which is sent to MSC / VLR in step 4 and in Attach Accept to the UE.   The MME derives a VLR number based on the newly allocated LAI and the TMSI based NRI as provided by the UE or on the newly allocated LAI and an IMSI hash function defined in TS 23.236

[0023] . The MME starts the location update procedure towards the new MSC / VLR upon receipt of the subscriber data from the HSS in step 2). This operation marks the MS as EPS-attached in the VLR. 4)  The MME sends a Location Update Request (new LAI, IMSI, MME name, Location Update Type, selected CS domain operator) message to the VLR. MME name is a FQDN string. The cases in which the MME includes the selected CS domain operator towards the VLR are specified in TS 23.251

[0042] . 5)  The VLR creates an association with the MME by storing MME name. 6)  The VLR performs the normal subscription checks for CS and if all checks are successful performs Location Updating procedure in CS domain.   For GWCN configuration, the MSC selects the core network operator as specified in TS 23.251

[0042] . 7)  The VLR responds with Location Update Accept (VLR TMSI) to the MME. 8)  The EPS Attach procedure is completed by performing step 17 to step 26 as specified in TS 23.401 [2].   If the UE requested a combined EPS / IMSI Attach, the Attach Accept message includes the parameters as specified in TS 23.401 [2]: VLR TMSI and LAI as allocated in step 3 above. The existence of LAI and VLR TMSI indicates successful attach to CS domain.   If the UE requests combined EPS / IMSI Attach Request without the "SMS-only" indication, and if the network supports SGs procedures only for SMS or the network decided to provide "SMS in MME" for the UE, the MME shall indicate in the Attach Accept message that the IMSI attach is for "SMS-only". When the network accepts a combined EPS / IMSI attach without limiting to "SMS-only", the network may provide a "CSFB Not Preferred" indication to the UE.   If the UE requests combined EPS / IMSI Attach Request with the "SMS-only" indication, and if the network supports SGs procedures only for SMS or if it supports CSFB and SMS over SGs or the network decided to provide "SMS in MME" for the UE, the MME shall indicate in the Attach Accept message that the IMSI attach is for "SMS-only".   If the MME provides "SMS in MME" for a UE that requested combined EPS / IMSI Attach, then the TMSI and LAI are provided as specified in clause C.4.2.   The network provides the "SMS-only" or "CSFB Not Preferred" indications based on locally configured operator policies based on e.g. roaming agreement.   The UE behaviour upon receiving such indications is described in TS 23.221

[0026] .   If the PLMN ID for the CS domain (included in the LAI provided to the UE) differs from the PLMN ID provided as part of the GUTI, the equivalent PLMNs list includes the PLMN ID for the CS domain.   When a UE supporting S&F operation mode is registering to the network through a cell supporting S&F operation, the MME sends attach accept message with attach type EPS and indicates to the UE that CS attach is pending i.e. VLR TMSI to be assigned and additionally send the S&F wait time. When the UE is under the coverage of the cell supporting S&F the UE sends attach request message again with attach type combined EPS / IMSI attach and the attach request message includes S&F capability.The UE may also initiate tracking area update procedure with EPS update type = combined update RA / LA update or combined TA / LA updating with IMSI attach 9)  If the VLR has updated the SGs association and if a paging timer is still running for a MT service for this UE, the VLR shall repeat SGs Paging Request towards the updated SGs association.   When the MME-GND executes steps 3 to 7. Steps 3-7 can takes place in parallel with step 2 and 8 or any in any sequence.   10. When the MME receives attach request message sent in the step 8 and the MME is successfully registered to the CS domain i.e. SGs association is created then the MME sends attach accept message with attach result combined EPS / IMSI attach. If the SGs association is established only for the SMS service then the UE shall MME includes additional indicator that the UE is registered for the SMS services only.   When the MME receives tracking area update request message sent in the step 8 and the MME is successfully registered to the CS domain i.e. SGs association is created then the MME sends attach accept message with attach result combined EPS / IMSI attach. If the SGs association is established only for the SMS service then the UE shall MME includes additional indicator that the UE is registered for the SMS services only.NOTE 2:  The case of unsuccessful attach to CS domain is documented in stage 3 specifications, taking into account reachability for CS services of UEs that have the user preference to prioritize voice over data services and are not configured / supporting to use IMS voice services.

[0378] This application is based upon and claims the benefit of priority from Indian Patent Application No. 202411083743, filed on November 1, 2024, the disclosure of which is incorporated herein in its entirety by reference.

[0379] 3  USER EQUIPMENT(UE) 31  TRANSCEIVER CIRCUIT 32  ANTENNA 33  CONTROLLER 34  USER INTERFACE 35  USIM 36  MEMORY 361  OPERATING SYSTEM 362  COMMUNICATIONS CONTROL MODULE 3621  TRANSCEIVER CONTROL MODULE 5  RADIO ACCESS NETWORK (RAN) 501  RAN 502  RAN 51  TRANSCEIVER CIRCUIT 52  ANTENNA 53  NETWORK INTERFACE 54  CONTROLLER 55  MEMORY 551  OPERATING SYSTEM 552  COMMUNICATIONS CONTROL MODULE 5521  TRANSCEIVER CONTROL MODULE 7  CORE NETWORK 70  MOBILITY MANAGEMENT ENTITY (MME) 7001  MME-SAT 7002  MME-GRD 7003  MME 701  TRANSCEIVER CIRCUIT 702  NETWORK INTERFACE 703  CONTROLLER 704  MEMORY 7041  OPERATING SYSTEM 7042  COMMUNICATIONS CONTROL MODULE 70421  TRANSCEIVER CONTROL MODULE 71  S-GW 711  TRANSCEIVER CIRCUIT 712  NETWORK INTERFACE 713  CONTROLLER 714  MEMORY 7141  OPERATING SYSTEM 7142  COMMUNICATIONS CONTROL MODULE 71421  TRANSCEIVER CONTROL MODULE 72  P-GW 721  TRANSCEIVER CIRCUIT 722  NETWORK INTERFACE 723  CONTROLLER 724  MEMORY 7241  OPERATING SYSTEM 7242  COMMUNICATIONS CONTROL MODULE 72421  TRANSCEIVER CONTROL MODULE 73  PCRF 731  TRANSCEIVER CIRCUIT 732  NETWORK INTERFACE 733  CONTROLLER 734  MEMORY 7341  OPERATING SYSTEM 7342  COMMUNICATIONS CONTROL MODULE 73421  TRANSCEIVER CONTROL MODULE 74  HSS 741  TRANSCEIVER CIRCUIT 742  NETWORK INTERFACE 743  CONTROLLER 744  MEMORY 7441  OPERATING SYSTEM 7442  COMMUNICATIONS CONTROL MODULE 74421  TRANSCEIVER CONTROL MODULE 75  SCEF 751  TRANSCEIVER CIRCUIT 752  NETWORK INTERFACE 753  CONTROLLER 754  MEMORY 7541  OPERATING SYSTEM 7542  COMMUNICATIONS CONTROL MODULE 75421  TRANSCEIVER CONTROL MODULE 76  SGSN 761  TRANSCEIVER CIRCUIT 762  NETWORK INTERFACE 763  CONTROLLER 764  MEMORY 7641  OPERATING SYSTEM 7642  COMMUNICATIONS CONTROL MODULE 76421  TRANSCEIVER CONTROL MODULE 77  GGSN 771  TRANSCEIVER CIRCUIT 772  NETWORK INTERFACE 773  CONTROLLER 774  MEMORY 7741  OPERATING SYSTEM 7742  COMMUNICATIONS CONTROL MODULE 77421  TRANSCEIVER CONTROL MODULE 78  MSC / VLR 781  TRANSCEIVER CIRCUIT 782  NETWORK INTERFACE 783  CONTROLLER 784  MEMORY 7841  OPERATING SYSTEM 7842  COMMUNICATIONS CONTROL MODULE 78421  TRANSCEIVER CONTROL MODULE 79  SMS-GMSC 791  TRANSCEIVER CIRCUIT 792  NETWORK INTERFACE 793  CONTROLLER 794  MEMORY 7941  OPERATING SYSTEM 7942  COMMUNICATIONS CONTROL MODULE 79421  TRANSCEIVER CONTROL MODULE 7A  SC 7A1  TRANSCEIVER CIRCUIT 7A2  NETWORK INTERFACE 7A3  CONTROLLER 7A4  MEMORY 7A41  OPERATING SYSTEM 7A42  COMMUNICATIONS CONTROL MODULE 7A421  TRANSCEIVER CONTROL MODULE 8  OPERATIONS, ADMINISTRATION, AND MAINTENANCE (OAM) 811  TRANSCEIVER CIRCUIT 812  NETWORK INTERFACE 813  CONTROLLER 814  MEMORY 8141  OPERATING SYSTEM 8142  COMMUNICATIONS CONTROL MODULE 81421  TRANSCEIVER CONTROL MODULE 20  DATA NETWORK 201  APPLICATION FUNCTION (AF) 2011  TRANSCEIVER CIRCUIT 2012  NETWORK INTERFACE 2013  CONTROLLER 2014  MEMORY 20141  OPERATING SYSTEM 20142  COMMUNICATIONS CONTROL MODULE 201421  TRANSCEIVER CONTROL MODULE 21  NON-IP DATA NETWORK 211  SCS / AS 2111  TRANSCEIVER CIRCUIT 2112  NETWORK INTERFACE 2113  CONTROLLER 2114  MEMORY 21141  OPERATING SYSTEM 21142  COMMUNICATIONS CONTROL MODULE 211421  TRANSCEIVER CONTROL MODULE

Claims

A method performed by a user equipment (UE), the method comprising:  receiving, from a Radio Access Network (RAN) corresponding to a first satellite, system information comprising information related to whether the RAN supports a store and forward operation;  sending, to a core network device corresponding to the first satellite, a first Non-Access-Stratum (NAS) request message with NAS integrity protection, the first NAS message comprising a Globally Unique Temporary UE Identity (GUTI) and a capability related to the store and forward operation;  increasing an Uplink NAS count after sending the first NAS request message; and  receiving, from the core network device corresponding to the first satellite, a first NAS reject message without NAS integrity protection, the first NAS reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation, wherein  the method comprises determining, based on a first condition, whether to decrease the Uplink NAS count after receiving the first NAS reject message.  The method according to claim 1, wherein  the first condition comprises at least one of:  the UE accesses to a cell that supports the store and forward operation;  the UE indicates the capability related to the store and forward operation in the first NAS request message sent to the core network device corresponding to the first satellite;  the first NAS reject message comprises the cause indicating the store and forward operation not supported,  the first NAS reject message comprises the wait timer related to the store and forward operation,  the first NAS reject message comprises both the cause indicating the store and forward operation not supported and the wait timer related to the store and forward operation, and  the UE is in the store and forward operation.  The method according to claim 1, wherein  the method comprises updating a Downlink NAS count after receiving the NAS reject message,  the updating the Downlink NAS count comprises increasing the Downlink NAS count or not increasing the Downlink NAS count.  The method according to claim 1, wherein  the first NAS request message comprising a Tracking Area Update (TAU) request message, an ATTACH request message, a Service Request message, a Packet Data Network (PDN) connectivity request message, and a Control Plane Service Request message.  The method according to claim 1, wherein  the first NAS reject message comprising a Tracking Area Update (TAU) reject message, an ATTACH reject message, a Service Reject message, a Packet Data Network (PDN) connectivity reject message, and a Control Plane Service Reject message.  A method performed by a core network device corresponding to a first satellite, the method comprising:  receiving, from a user equipment (UE), a first Non-Access-Stratum (NAS) request message with NAS integrity protection, the first NAS message comprising a Globally Unique Temporary UE Identity (GUTI) and a capability related to the store and forward operation;  determining whether a feeder link for the core network device is available; and  sending, to the UE, a first NAS reject message without NAS integrity protection based on the determination that the feeder link is not available, the first NAS reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation.  The method according to claim 6, wherein  the method comprises increasing a Downlink NAS count after sending the first NAS reject message.  A method performed by a user equipment (UE), the method comprising:  receiving, from a Radio Access Network (RAN) corresponding to a first satellite, system information comprising information related to whether the RAN supports a store and forward operation and a status related to a feeder link for the RAN;  sending, to a core network device corresponding to the first satellite, an Attach Request message comprising EPS mobile identity and a first data; and  receiving, from the core network device corresponding to the first satellite, an Attach Reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation.  A method performed by a core network device corresponding to the first satellite, the method comprising:  receiving, from a user equipment (UE), an Attach Request message comprising EPS mobile identity and a first data;  determining whether a feeder link for the core network device is available; and  sending, to the UE, an Attach Reject message based on the determination that the feeder link is not available, the Attach Reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation.  A user equipment (UE) comprising:  one or more memories storing instructions; and  one or more processors configured to process the instructions to control the UE to:  receive, from a Radio Access Network (RAN) corresponding to a first satellite, system information comprising information related to whether the RAN supports a store and forward operation;  send, to a core network device corresponding to the first satellite, a first Non-Access-Stratum (NAS) request message with NAS integrity protection, the first NAS message comprising a Globally Unique Temporary UE Identity (GUTI) and a capability related to the store and forward operation;  increase an Uplink NAS count after sending the first NAS request message; and  receive, from the core network device corresponding to the first satellite, a first NAS reject message without NAS integrity protection, the first NAS reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation, wherein  the one or more processors are configured to process the instructions to control the UE to determine, based on a first condition, whether to decrease the Uplink NAS count after receiving the first NAS reject message.  The UE according to claim 10, wherein  the first condition comprises at least one of:  the UE accesses to a cell that supports the store and forward operation;  the UE indicates the capability related to the store and forward operation in the first NAS request message sent to the core network device corresponding to the first satellite;  the first NAS reject message comprises the cause indicating the store and forward operation not supported,  the first NAS reject message comprises the wait timer related to the store and forward operation,  the first NAS reject message comprises both the cause indicating the store and forward operation not supported and the wait timer related to the store and forward operation, and  the UE is in the store and forward operation.  The UE according to claim 10, wherein  the one or more processors are configured to process the instructions to control the UE to update a Downlink NAS count after receiving the NAS reject message, wherein  the update of the Downlink NAS count comprises increasing the Downlink NAS count or not increasing the Downlink NAS count.  The UE according to claim 10, wherein  the first NAS request message comprising a Tracking Area Update (TAU) request message, an ATTACH request message, a Service Request message, a Packet Data Network (PDN) connectivity request message, and a Control Plane Service Request message.  The UE according to claim 10, wherein  the first NAS reject message comprising a Tracking Area Update (TAU) reject message, an ATTACH reject message, a Service Reject message, a Packet Data Network (PDN) connectivity reject message, and a Control Plane Service Reject message.  A core network device corresponding to a first satellite, the core network device comprising:  one or more memories storing instructions; and  one or more processors configured to process the instructions to control the core network device to:  receive, from a user equipment (UE), a first Non-Access-Stratum (NAS) request message with NAS integrity protection, the first NAS message comprising a Globally Unique Temporary UE Identity (GUTI) and a capability related to the store and forward operation;  determine whether a feeder link for the core network device is available; and  send, to the UE, a first NAS reject message without NAS integrity protection based on the determination that the feeder link is not available, the first NAS reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation.  The core network device according to claim 15, wherein  the one or more processors are configured to process the instructions to control the core network device to increase a Downlink NAS count after sending the first NAS reject message.  A user equipment (UE) comprising:  one or more memories storing instructions; and  one or more processors configured to process the instructions to control the UE to:  receive, from a Radio Access Network (RAN) corresponding to a first satellite, system information comprising information related to whether the RAN supports a store and forward operation and a status related to a feeder link for the RAN;  send, to a core network device corresponding to the first satellite, an Attach Request message comprising EPS mobile identity and a first data; and  receive, from the core network device corresponding to the first satellite, an Attach Reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation.  A core network device corresponding to the first satellite, the core network device comprising:  one or more memories storing instructions; and  one or more processors configured to process the instructions to control the core network device to:  receive, from a user equipment (UE), an Attach Request message comprising EPS mobile identity and a first data;  determine whether a feeder link for the core network device is available; and  send, to the UE, an Attach Reject message based on the determination that the feeder link is not available, the Attach Reject message comprising at least one of a cause indicating the store and forward operation not supported and a wait timer related to the store and forward operation.