Mobile equipment usage of stored concealed subscriber identifiers

WO2026166976A1PCT designated stage Publication Date: 2026-08-13TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-02-03
Publication Date
2026-08-13

Smart Images

  • Figure EP2026052809_13082026_PF_FP_ABST
    Figure EP2026052809_13082026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments includes methods performed by mobile equipment (ME) that is part of user equipment (UE) configured to operate in a communication network. Such methods include receiving an error message indicating that information necessary to construct a concealed subscriber identifier is unavailable. Such methods include, based on the error message, obtaining a first concealed subscriber identifier from storage of the ME. The first concealed subscriber identifier was previously received or constructed by the ME. Such methods include sending, to a network entity of the communication network, a message that includes the first concealed subscriber identifier. Other embodiments include complementary methods performed by the network entity, as well as MEs and network entities configured to perform such methods.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] MOBILE EQUIPMENT USAGE OF STORED CONCEALED SUBSCRIBER IDENTIFIERS TECHNICAL FIELD

[0002] The present disclosure relates generally to the field of communication networks, and more specifically to techniques for mobile equipment (ME) to use concealed subscriber (or user subscription) identifiers that were previously constructed and stored by the ME, such as when the ME is unable to obtain or construct a new concealed subscriber identifier (e.g., due to necessary information being unavailable).

[0003] BACKGROUND

[0004] The fifth generation (5G) of cellular systems has been standardized within the Third-Generation Partnership Project (3GPP). 5G was developed for maximum flexibility to support a variety of use cases including enhanced mobile broadband (eMBB), machine type communications (MTC), ultra-reliable low latency communications (URLLC), side-link device-to-device (D2D), and several others. 5G was initially specified in Release 15 (Rel-15) and continues to evolve through subsequent releases.

[0005] At a high level, the 5G System (5GS) consists of an Access Network (AN) and a Core Network (CN). The AN provides user equipment (UEs) connectivity to the CN, e.g., via base stations such as gNBs or ng-eNBs. The 5G CN (also called “5GC”) includes a variety of Network Functions (NF) that provide a wide range of different functionalities such as session management, connection management, charging, authentication, etc.

[0006] Two types of user identifiers are used in 5G networks. Subscription Permanent Identifier (SUPI) is a unique identifier that represents a subscriber's permanent identity in a 5G network. It is intended to provide enhanced privacy and security compared to the International Mobile Subscriber Identity (IMSI) used in fourth-generation (4G) and earlier networks. Subscription Concealed Identifier (SUCI) is a temporary identifier used to conceal a subscriber's SUPI in a 5G network, e.g., to avoid sending the SUPI over the air. SUCI contains several concatenated values including a Protection Scheme Output that is generated cryptographically by a user equipment (UE) and decrypted by the 5G network to determine the corresponding SUPI.

[0007] In more detail, a UE generates SUCI using a protection scheme with input of the Home Network Public Key, which was securely provisioned to the UE by the UE’ s home network. 3 GPP TS 33.501 (vl9.1.0) Annex C specifies the following two protection schemes used to generate SUCI: (i) Null scheme, and (ii) Elliptic Curve Integrated Encryption Scheme (ECIES). The null scheme does not actually conceal the SUPI, since the input is returned as the output for both encryption and decryption. As such, the null scheme provides no privacy protection. The use ofECIES for concealment of SUPI must adhere to Standards for Efficient Cryptography (SECG) specifications SEC1 (“Recommended Elliptic Curve Cryptography, Version 2.0”) and SEC2 (“Recommended Elliptic Curve Domain Parameters, Version 2.0”). 3GPP TS 33.501 Annex C.3 describes protection processing on UE and home network side at a high level.

[0008] At a high level, a 3 GPP-compliant UE includes a universal subscriber identity module (USIM) and mobile equipment (ME), which work together to provide UE security features. Every USIM has a unique identity and is associated with one and only one home environment. It shall be possible for a home environment to uniquely identify a user by the USIM. On the other hand, an ME may support multiple USIMs (on the same UICC or on different UICCs) that are registered at the same time with the same or different home environments (e.g., different public land mobile networks, PLMNs). According to 3GPP TS 33.501 section 4, “user domain security” refers to the set of security features that secure the user access to the ME. In contrast, “network access security” refers to the set of security features that enable a UE to authenticate and access services via the network securely, including 3GPP and non-3GPP ANs.

[0009] UE generation of SUCI is performed by the ME or the USIM based on a configuration stored on the USIM by the network operator of the home environment. To obtain an ECIES-protected SUCI, the ME sends a GET IDENTITY command to the USIM. In normal operation, if the USIM is configured to perform SUCI calculation, the USIM returns the SUCI to the ME. If the USIM is configured to facilitate SUCI calculation by the ME, the USIM a status word “6985” that indicates “conditions of use not satisfied.” The ME then computes SUCI based on other necessary information made available to the ME by the USIM.

[0010] SUMMARY

[0011] Even so, there may be some cases where certain information necessary for USIM or ME to determine a protected SUCI is not available in the USIM. In these cases, the UE is unable to compute an ECIES -protected SUCI, such that the UE may only identify itself to a serving PLMN using an unprotected SUCI (i.e., SUPI in cleartext). This is not only undesirable but may also violate security policies of the serving (or user’s home) PLMN.

[0012] An object of embodiments of the present disclosure address these and other problems, issues, and / or difficulties by providing secure techniques for determining and using a protected SUCI when information necessary for conventional techniques to protect SUCI is missing from a USIM.

[0013] Some embodiments of the present disclosure include methods (e.g., procedures) for ME that is part of a UE configured to operate in a communication network.These exemplary methods include receiving an error message indicating that information necessary to construct a concealed subscriber identifier is unavailable. These exemplary methods also include, based on the error message, obtaining a first concealed subscriber identifier from storage of the ME, wherein the first concealed subscriber identifier was previously received or constructed by the ME. These exemplary methods also include sending, to a network entity of the communication network, a message that includes the first concealed subscriber identifier.

[0014] In some embodiments, these exemplary methods also include sending a request for a concealed subscriber identifier to an identity module in the UE. The error message is received as one of the following options in a response from the identity module:

[0015] • the error message;

[0016] • a second concealed subscriber identifier constructed by the identity module; and

[0017] • a status message indicating that conditions are not satisfied for the identity module to construct the requested concealed subscriber identifier.

[0018] In some of these embodiments, these exemplary methods also include, based on the status message, constructing the second concealed subscriber identifier based on a non-concealed subscriber identifier. In some variants of these embodiments, the message includes the first concealed subscriber identifier when it is obtained from the storage, but the message includes the second concealed subscriber identifier when it is received from the identity module or constructed by the ME.

[0019] In some of these embodiments, these exemplary methods also include selectively storing the second concealed subscriber identifier in the storage of the ME. In some variants of these embodiments, the storage in the ME is capable of storing a single concealed subscriber identifier, and selectively storing the first concealed subscriber identifier in the storage of the ME includes one of the following operations:

[0020] • refraining from replacing the first concealed subscriber identifier with the second concealed subscriber identifier;

[0021] • replacing the first concealed subscriber identifier with the second concealed subscriber identifier; or

[0022] • replacing the first concealed subscriber identifier with the second concealed subscriber identifier, when the first concealed subscriber identifier has been stored in the storage for at least a predetermined duration.

[0023] In other variants of these embodiments, the storage in the ME is capable of storing a maximum number of concealed subscriber identifiers, and selectively storing the second concealed subscriber identifier in the storage of the ME comprises:• when a number of concealed subscriber identifiers currently stored in the storage is less than the maximum number, storing the second concealed subscriber identifier in the storage of the ME; and

[0024] • when the number of concealed subscriber identifiers currently stored in the storage is equal to the maximum number, replacing one of the stored concealed subscriber identifiers with the second concealed subscriber identifier.

[0025] In some of these embodiments, the identity module is a USIM, the first and second concealed subscriber identifiers are SUCIs, and the network entity is one of the following: authentication server function (AUSF), unified data management function (UDM), or one or more sub-functions of an AUSF or a UDM.

[0026] In some embodiments, the message sent to the network entity includes an explicit indication that the first concealed subscriber identifier was obtained from storage of the ME. The explicit indication is included as one of the following:

[0027] • as part of the first concealed subscriber identifier;

[0028] • appended to the first concealed subscriber identifier; or

[0029] • in a separate field or part of the message than the first concealed subscriber identifier.

[0030] Other embodiments include complementary methods for a network entity configured to operate in a communication network.

[0031] These exemplary methods include receives a message that includes a concealed subscriber identifier of a subscriber of the communication network. These exemplary methods also include determining whether the received concealed subscriber identifier corresponds to a first concealed subscriber identifier, of the subscriber, that was previously received by the network entity. These exemplary methods also include, based on determining that the received concealed subscriber identifier corresponds to the first concealed subscriber identifier, determining that an error condition exists in an identity module associated with the subscriber.

[0032] In some embodiments, these exemplary methods also include obtaining a de-concealed subscriber identifier from the received concealed subscriber identifier, based on one of the following:

[0033] • de-concealing the received concealed subscriber identifier; or

[0034] • sending the received concealed subscriber identifier to a second network entity and receiving the de-concealed subscriber identifier from the network entity in response. In some embodiments, determining that the received concealed subscriber identifier corresponds to the first concealed subscriber identifier is based on an explicit indication included in the message, according to one of the following:

[0035] • as part of the received concealed subscriber identifier;• appended to the received concealed subscriber identifier;

[0036] • in a separate field or part of the message than the received concealed subscriber identifier. In some of these embodiments, the explicit indication is integrity protected based on security keys derived from security keys used to construct the received concealed subscriber identifier.

[0037] In other embodiments, determining that the received concealed subscriber identifier corresponds to the first concealed subscriber identifier comprises:

[0038] • sending the received concealed subscriber identifier to a second network entity; and • receiving from the second network entity an indication that the received concealed subscriber identifier was previously received by the second network entity from the network entity.

[0039] In other embodiments, determining that the received concealed subscriber identifier corresponds to the first concealed subscriber identifier comprises detecting a match or correspondence between the received concealed subscriber identifier and one of a plurality concealed subscriber identifiers, of the subscriber, in a storage of the network entity.

[0040] In some of these embodiments, these exemplary methods also include selectively storing the received concealed subscriber identifier in the storage. In some variants of these embodiments, the storage of the network entity is capable of storing a maximum number of concealed subscriber identifiers of the subscriber, and selectively storing the received concealed subscriber identifier in the storage includes the following operations:

[0041] • when a number of concealed subscriber identifiers currently stored in the storage is less than the maximum number, storing the received concealed subscriber identifier in the storage of the network entity; and

[0042] • when the number of concealed subscriber identifiers currently stored in the storage is equal to the maximum number, replacing one of the stored concealed subscriber identifiers with the received concealed subscriber identifier.

[0043] In some of these embodiments, these exemplary methods also include removing one or more of the stored concealed subscriber identifiers having longest duration in the storage. In some of these embodiments, the storage comprises one of the following: a database, a bloom filter, or in a cuckoo hash table.

[0044] In some embodiments, the message is received from ME operating in the communication network. In some embodiments, the identity module is a USIM, the first and second concealed subscriber identifiers are SUCIs, and the network entity is one of the following: AUSF, UDM, or one or more sub-functions of an AUSF or a UDM.

[0045] Other embodiments include MEs (e.g., parts of UEs or wireless devices) and network equipment (e.g., that implement UDM, AUSF, or sub-functions thereof) configured to performoperations corresponding to any of the exemplary methods described herein. Other embodiments include non-transitory, computer-readable media storing computer-executable instructions that, when executed by processing circuitry, configure such MEs and network equipment to perform operations corresponding to any of the exemplary methods described herein.

[0046] Embodiments may provide various benefits and / or advantages. For example, when embodiments are used in an ME, the ME’ s visible behavior appears to be conventional so long as the ME (or USIM) is able to construct SUCIs. But when the ME (or USIM) is unable to construct a SUCI due to necessary information being unavailable, the ME may (re)use a previously-constructed SUCI instead of sending SUPI in cleartext. As such, embodiments may improve the security and reduce the vulnerability of permanent user subscription credentials (e.g., SUPI) used in communication network. In this manner, embodiments may prevent and / or reduce the risk of unauthorized and / or fraudulent access to communication networks and services.

[0047] These and other objects, features, and advantages of the present disclosure will become apparent upon reading the following Detailed Description in view of the Drawings briefly described below.

[0048] BRIEF DESCRIPTION OF THE DRAWINGS

[0049] Figures 1-2 illustrate various aspects of an exemplary 5G network architecture.

[0050] Figure 3 shows an exemplary structure of a SUCI.

[0051] Figures 4-5 show signaling diagram of procedures in which a protected SUCI is computed by USIM and ME, respectively.

[0052] Figure 6 shows a signaling diagram of a procedure in which information necessary for computation of a protected SUCI is unavailable in the USIM.

[0053] Figure 7 shows a signaling diagram of a procedure between USIM, ME, and a network entity, according to various embodiments of the present disclosure.

[0054] Figure 8 shows an exemplary method (e.g., procedure) for ME, according to various embodiments of the present disclosure.

[0055] Figure 9 shows an exemplary method (e.g., procedure) for a network entity, according to various embodiments of the present disclosure.

[0056] Figure 10 shows a communication system according to various embodiments of the present disclosure.

[0057] Figure 11 shows a UE according to various embodiments of the present disclosure.

[0058] Figure 12 shows a network node according to various embodiments of the present disclosure.Figure 13 is a block diagram of a virtualization environment in which some embodiments of the present disclosure may be virtualized.

[0059] DETAILED DESCRIPTION

[0060] Embodiments briefly summarized above will now be described more fully with reference to the accompanying drawings. These descriptions are provided by way of example to explain the subject matter to those skilled in the art and should not be construed as limiting the scope of the subject matter to only the embodiments described herein. More specifically, examples are provided below that illustrate the operation of various embodiments according to the advantages discussed above.

[0061] In general, all terms used herein are to be interpreted according to their ordinary meaning in the relevant technical field, unless a different meaning is clearly given and / or is implied from the context in which it is used. All references to a / an / the element, apparatus, component, means, step, etc. are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise. The operations of any methods and / or procedures disclosed herein do not have to be performed in the exact order disclosed, unless an operation is explicitly described as following or preceding another operation and / or where it is implicit that an operation must follow or precede another operation. Any feature of any embodiment disclosed herein can apply to any other disclosed embodiment, as appropriate. Likewise, any advantage of any embodiment described herein can apply to any other disclosed embodiment, as appropriate.

[0062] Furthermore, the following terms are used throughout the description given below:

[0063] • Radio Access Node: As used herein, a “radio access node” (or equivalently “radio network node,” “radio access network node,” or “RAN node”) can be any node in a radio access network (RAN) that operates to wirelessly transmit and / or receive signals. Some examples of a radio access node include, but are not limited to, a base station (e.g., gNB in a 3GPP 5G / NR network or an enhanced or eNB in a 3GPP Long-Term Evolution (LTE) network), base station distributed components (e.g., CU and DU), a high-power or macro base station, a low-power base station (e.g., micro, pico, femto, or home base station, or the like), an integrated access backhaul (IAB) node, a transmission point (TP), a transmission reception point (TRP), a remote radio unit (RRU or RRH), and a relay node.

[0064] • Core Network Node: As used herein, a “core network node” is any type of node in a core network. Some examples of a core network node include, e.g., a Mobility Management Entity (MME), a serving gateway (SGW), a PDN Gateway (P-GW), a Policy and Charging Rules Function (PCRF), an access and mobility management function (AMF), a sessionmanagement function (SMF), a user plane function (UPF), a Charging Function (CHF), a Policy Control Function (PCF), an Authentication Server Function (AUSF), a location management function (LMF), or the like.

[0065] • Wireless Device: As used herein, a “wireless device” (or “WD” for short) is any type of device that is capable, configured, arranged and / or operable to communicate wirelessly with network nodes and / or other wireless devices. Communicating wirelessly can involve transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information through air. Unless otherwise noted, the term “wireless device” is used interchangeably herein with the term “user equipment” (or “UE” for short), with both of these terms having a different meaning than the term “network node”.

[0066] • Radio Node: As used herein, a “radio node” can be either a “radio access node” (or equivalent term) or a “wireless device.”

[0067] • Network Node: As used herein, a “network node” is any node that is either part of the radio access network (e.g., a radio access node or equivalent term) or of the core network (e.g., a core network node discussed above) of a cellular communications network. Functionally, a network node is equipment capable, configured, arranged, and / or operable to communicate directly or indirectly with a wireless device and / or with other network nodes or equipment in the cellular communications network, to enable and / or provide wireless access to the wireless device, and / or to perform other functions (e.g., administration) in the cellular communications network.

[0068] • Node: As used herein, the term “node” (without prefix) can be any type of node that can in or with a wireless network (including RAN and / or core network), including a radio access node (or equivalent term), core network node, or wireless device. However, the term “node” may be limited to a particular type (e.g., radio access node) based on its specific characteristics in any given context.

[0069] The above definitions are not meant to be exclusive. In other words, various ones of the above terms may be explained and / or described elsewhere in the present disclosure using the same or similar terminology. Nevertheless, to the extent that such other explanations and / or descriptions conflict with the above definitions, the above definitions should control.

[0070] Note that the description given herein focuses on a 3 GPP cellular communications system and, as such, 3GPP terminology or terminology similar to 3GPP terminology is often used. However, the concepts disclosed herein are not limited to a 3GPP system and can be applied in any system that can benefit from the concepts, principles, and / or embodiments described herein.Figure 1 shows a high-level view of an exemplary 5G network architecture, including a Next Generation Radio Access Network (NG-RAN, 199) and a 5GC (198). As shown in the figure, the NG-RAN can include gNBs (e.g., 110a,b) and ng-eNBs (e.g., 120a, b) that are connected via respective Xn interfaces. The gNBs and ng-eNBs are also connected to the 5GC via the NG interfaces, more specifically to access and mobility management function (AMFs, e.g., 130a, b) via respective NG-C interfaces and to user plane functions (UPFs, e.g., 140a, b) via respective NG-U interfaces. Moreover, the AMFs can communicate with one or more policy control functions (PCFs, e.g., 150a, b) and network exposure functions (NEFs, e.g., 160a, b).

[0071] Each of the gNBs can support the NR radio interface including frequency division duplexing (FDD), time division duplexing (TDD), or a combination thereof. In contrast, each of ng-eNBs can support the 4G LTE radio interface but, unlike conventional LTE eNodeBs (eNBs), connect to the 5GC via the NG interface. Each of the gNBs and ng-eNBs can serve a geographic coverage area including one more cells (e.g., llla-b, 121a-b). The gNBs and ng-eNBs can also use various directional beams to provide coverage in the respective cells. Depending on the cell in which it is located, a UE (105) can communicate with the gNB or ng-eNB serving that cell via the NR or LTE radio interface, respectively. Although Figure 1 shows gNBs and ng-eNBs separately, it is also possible that a single NG-RAN node provides both types of functionality.

[0072] Each gNB can include a central (or centralized) unit (CU or gNB-CU) and one or more distributed (or decentralized) units (DU or gNB-DU), which can be viewed as logical nodes. CUs host higher-layer protocols and perform various gNB functions such controlling the operation of DUs, which host lower-layer protocols and can include various subsets of the gNB functions. A CU connects to its associated DUs over respective Fl logical interfaces. Each of the CUs and DUs can include various circuitry needed to perform their respective functions, including processing circuitry, communication interface circuitry (e.g., for communication via Xn, NG, radio, etc. interfaces), and power supply circuitry.

[0073] In the 5GC, traditional peer-to-peer interfaces and protocols found in earlier-generation networks are modified and / or replaced by a Service Based Architecture (SBA) in which Network Functions (NFs) provide one or more services to one or more service consumers. This can be done, for example, by Hyper Text Transfer Protocol / Representational State Transfer (HTTP / REST) application programming interfaces (APIs). In general, the various services are self-contained functionalities that can be changed and modified in an isolated manner without affecting other services.

[0074] Figure 2 shows an exemplary non-roaming reference architecture for a 5G network (200). As shown in Figure 2, this architecture includes various 3 GPP-defined NFs and servicebased interfaces, with the following being the most relevant to the present disclosure:• User Plane Function (UPF) - supports handling of user plane traffic based on the rules received from SMF, including packet inspection and different enforcement actions (e.g., event detection and reporting). UPFs communicate with the RAN (e.g., NG-RAN) via the N3 reference point, with SMFs (discussed below) via the N4 reference point, and with an external packet data network (PDN) via the N6 reference point. The N9 reference point is for communication between two UPFs.

[0075] • Access and Mobility Management Function (AMF, 220, with Namf interface) - terminates the RAN CP interface and handles all mobility and connection management of UEs (210). AMFs communicate with UEs via the N1 reference point and with the RAN (e.g., NG-RAN) via the N2 reference point.

[0076] • Network Exposure Function (NEF, with Nnef interface) - acts as the entry point into operator's network, by securely exposing to AFs the network capabilities and events provided by 3GPPNFs and by providing ways for the AF to securely provide information to 3GPP network. For example, NEF provides a service that allows an AF to provision specific subscription data (e.g., expected UE behavior) for various UEs.

[0077] • Network Repository Function (NRF, with Nnrf interface) - provides service registration and discovery, enabling NFs to identify appropriate services available from other NFs.

[0078] • Authentication Server Function (AUSF, 230, with Nausf interface) - based in a user’s home network (HPLMN), it performs user authentication and computes security key materials for various purposes.

[0079] • Unified Data Management function (UDM, 240, with Nudm interface) - supports generation of 3GPP authentication credentials, user identification handling, access authorization based on subscription data, and other subscriber-related functions. To provide this functionality, the UDM uses subscription data (including authentication data) stored in the 5GC unified data repository (UDR). In addition, UDR supports storage and retrieval of policy data by the PCF, as well as storage and retrieval of application data by NEF.

[0080] The UDM may include an authentication credential repository and processing function (ACRPF) that is responsible for generating 5G Home Environment Authentication Vectors (HEAVs) based on a subscriber’s shared secret key. For example, the ARPF centralizes and performs all authentication procedures interfacing the rest of the network via the UDM. As another example, the ARPF also stores and manages all cryptographic keys and algorithms, performs vector generation, and in some cases handles subscription de-concealing.

[0081] In some cases, the UDM may include a subscription identifier de-concealing function (SIDF) that is responsible for de-concealment of concealed user subscription identifiers (e.g.,SUCI) using a Home Network Private Key. The SIDF also holds the Home Network Public Key Identifier(s) for the private / public key pair(s) used for subscriber privacy.

[0082] As briefly mentioned above, two types of user identifiers are used in 5G networks. SUPI is a unique identifier that represents a subscriber's permanent identity in a 5G network. SUPIs can have either of two forms: (i) international mobile subscription identifier (IMSI) as defined in 3GPP TS 23.003 (vl9.1.0), or (ii) network access identifier (NAI) as defined in IETF RFC 7542.

[0083] In contrast, SUCI is a temporary identifier used to conceal a subscriber's SUPI in a 5G network, e.g., to avoid sending the SUPI over the air. SUCI contains several concatenated values including a Protection Scheme Output that is generated cryptographically by a UE and decrypted by the 5G network to determine the corresponding SUPI. 5G Globally Unique Temporary Identity (5G-GUTI) is another identifier used in 5G networks to identify a mobile device and its associated subscription information. For example, a 5G-GUTI may be used instead of a user’s IMSI to provide improved security and privacy.

[0084] According to 3GPP TS 33.501, a UE shall include SUCI only in the following 5G NAS messages:

[0085] • if the UE is sending a Registration Request message of type "initial registration" to a PLMN for which the UE does not already have a 5G-GUTI, the UE shall include a SUCI in the Registration Request message;

[0086] • if the UE responds to an Identity Request message by which the network requests the UE to provide its permanent identifier, the UE includes a SUCI in the Identity Response message as specified in 3GPP TS 33.501 clause 6.12.4; and

[0087] • if the UE is sending a De-Regi strati on Request message to a PLMN during an initial registration procedure for which the UE did not receive the registration accept message with 5G-GUTI, the UE shall include the SUCI used in the initial registration to the DeRegistration Request message.

[0088] In more detail, a UE generates SUCI using a protection scheme with input of the Home Network Public Key, which was securely provisioned to the UE by the UE’ s home network. 3 GPP TS 33.501 Annex C specifies the following two protection schemes used to generate SUCI: (i) Null scheme, and (ii) Elliptic Curve Integrated Encryption Scheme (ECIES). The null scheme does not actually conceal the SUPI, since the input is returned as the output for both encryption and decryption. As such, the null scheme provides no privacy protection. The use of ECIES for concealment of SUPI must adhere to SECG specifications SEC1 (“Recommended Elliptic Curve Cryptography, Version 2.0”) and SEC2 (“Recommended Elliptic Curve Domain Parameters,Version 2.0”). 3GPP TS 33.501 Annex C.3 describes protection processing on UE and home network side at a high level.

[0089] For either protection scheme, a UE constructs a Scheme Input from the subscription identifier part of the SUPI as follows:

[0090] • for SUPIs containing IMSI, the subscription identifier part of the SUPI includes the Mobile Subscriber Identification Number (MSIN) from the IMSI; and

[0091] • for SUPIs taking the form of an NAI, the subscription identifier part of the SUPI includes the "username" portion of the NAI.

[0092] The UE execute the protection scheme with the constructed Scheme Input and obtains the Scheme Output. Figure 3 shows an exemplary structure of a SUCI that is derived from an IMSI-based Scheme Input. In particular, the SUCI shown in Figure 3 includes the following fields as defined further in 3GPP TS 23.003 and / or 3GPP TS 33.501:

[0093] • SUPI Type identifies the type of the SUPI concealed in the SUCI;

[0094] • Home Network Identifier field is set to the mobile country code (MCC) and mobile network code MNC of the IMSI as specified in 23.003.

[0095] • Routing Indicator;

[0096] • Protection Scheme Identifier (e.g., null or ECIES);

[0097] • Home Network Public Key Identifier; and

[0098] • Scheme Output as specified in this document and detailed in TS 23.003.

[0099] Note that Home Network Identifier and Routing Indicator are not concealed in the Scheme Output.

[0100] In contrast, according to 3GPP specifications, a UE is allowed to generate a SUCI using the Null scheme only in the following cases:

[0101] • the UE is making an unauthenticated emergency session and it does not have a 5G-GUTI for the chosen PLMN;

[0102] • the UE’s home network has configured "null-scheme" to be used by the UE; and

[0103] • the UE’s home network has not provisioned the public key needed to generate a SUCI.

[0104] As discussed above, a 3 GPP-compliant UE includes a USIM and ME, which work together to provide UE security features. Every USIM has a unique identity and is associated with one and only one home environment. It shall be possible for a home environment to uniquely identify a user by the USIM. On the other hand, an ME may support multiple USIMs (on the same UICC or on different UICCs) that are registered at the same time with the same or different home environments (e.g., different public land mobile networks, PLMNs).

[0105] UE generation of SUCI is performed by the ME or the USIM based on a configuration stored on the USIM by the network operator of the home environment. Figures 4-6 show differentvariants of this procedure that involve a UE (400) and a network entity (430), where the UE includes an ME (420) and a USIM (410).

[0106] Figure 4 shows a signaling diagram of a procedure in which an ECIES-protected SUCI is computed by the USIM. In operation 1, the ME sends a GET IDENTITY command to the USIM. Since the USIM is configured to perform SUCI calculation, the USIM returns the SUCI to the ME in operation 2. In operation 3, the ME sends the obtained SUCI to the network entity (e.g., AUSF, UDM, or a function thereof), e.g., in one of the 5G NAS messages mentioned above.

[0107] Figure 5 shows a signaling diagram of a procedure in which an ECIES-protected SUCI is computed by the ME. In operation 1, the ME sends a GET IDENTITY command to the USIM. Since the USIM is configured to facilitate SUCI calculation by the ME, the USIM returns a status word “6985” that indicates “conditions of use not satisfied.” Based on this returned status, the ME computes SUCI based on the following information that is available from the USIM in normal operation:

[0108] • home network identifier (i.e., MCC and MNC when SUPI is IMSI-based or domain name when SUPI is NAI-based);

[0109] • routing indicator;

[0110] • home network public key;

[0111] • home network public key identifier;

[0112] • protection scheme identifier; and

[0113] • SUPI.

[0114] If SUCI calculation is to be performed by the ME, the SUCI Calculation Information EF (EFsuci calc info) is also required to be present in the USIM. This EF contains information needed by the ME for the support of subscription identifier privacy as defined in 3GPP TS 33.501. In some cases, however, this EFsuci calc info may not be available to the ME. For example, the file may be present but not readable by the ME, the file may be present but deactivated, etc.

[0115] Figure 6 shows a signaling diagram of a procedure in which information necessary for computation of an ECIES-protected SUCI is unavailable in the USIM. As in Figures 4-5, the ME sends a GET IDENTITY command to the USIM in operation 1. In operation 2, the USIM responds with an error that indicates information necessary for computation of an ECIES-protected SUCI (e.g., EFsuci calc info). Upon receiving this error, the ME’s further behavior in operation 3 is undefined in 3GPP specifications.

[0116] When the UE is unable to compute an ECIES-protected SUCI, such as in Figure 6, the UE may only identify itself to a serving PLMN using an unprotected SUCI (i.e., SUPI in cleartext) computed using the null scheme. This is not only undesirable but may also violate security policies of the serving PLMN and / or the user’s home PLMN. Since UE behavior in thisinstance is undefined / unrestricted, there is a risk that UE / ME vendors implement solutions that reveal SUPI by sending it to the network in clear text.

[0117] Embodiments of the present disclosure address these and other problems, issues, and / or difficulties with techniques by which the ME stores ECIES-protected SUCIs when it is able to compute them based on necessary information available from USIM. When the ME or USIM is no longer able compute SUCIs, the ME uses previously stored SUCIs in messages to the network. In some embodiments, the network may have functionality to detect that the ME cannot compute SUCIs anymore, such as a mechanism (e.g., based on locally stored state) to detect that the ME has sent a previously constructed SUCI, or an explicit indication from the ME that the provided SUCI is one that was previously constructed / stored and / or is being reused.

[0118] In more detail, if the ME receives an error from the USIM that SUCI cannot be constructed, the ME re-uses one of a set of previously constructed SUICs. The set is initially empty and at least one SUCI must be created and stored, although the ME may add and remove SUCIs from the set. In general, when a new SUCI is successfully constructed it may be added to the set. In some embodiments, the ME may remove a previously added SUCI from the set when a newly-constructed SUCI is added, such as when the set size reaches or exceeds a threshold.

[0119] Embodiments may provide various benefits and / or advantages. For example, when embodiments are used in an ME, the ME’ s visible behavior appears to be conventional so long as the ME (or USIM) is able to construct SUCIs. But when the ME (or USIM) is unable to construct a SUCI due to necessary information being unavailable, the ME may (re)use a previously-constructed SUCI instead of sending SUPI in cleartext. As such, embodiments may improve the security and reduce the vulnerability of permanent user subscription credentials (e.g., SUPI) used in communication network. In this manner, embodiments may prevent and / or reduce the risk of unauthorized and / or fraudulent access to communication networks and services.

[0120] Embodiments are described below in the context of a UE that, unlike conventional UEs, is unable to compute SUCI or similar concealed user subscription (or subscriber) identifier. This UE may be operational in a network together with other UEs that are able to compute SUCI or similar concealed user identifier.

[0121] Some embodiments include methods for ME, such as in a UE. The ME obtains an error response (e.g., from a USIM) indicating that a concealed user subscription identifier (e.g., SUCI) cannot be constructed. When the ME receives this response, it selects a previously constructed concealed user subscription identifier and sends it to a network entity. In general, the previously constructed concealed user subscription identifier needs to be stored in the ME, most probably ina non-volatile memory if the solution has to be resilient to ME power off. The ME could store one or more previously constructed concealed user subscription identifiers, e.g., in a set.

[0122] In some embodiments, when the ME stores only one previously constructed concealed user subscription identifier, then the ME would also need some logic to determine whether / when to replace the stored identifier. Some examples are given below:

[0123] • once stored, an identifier is never updated;

[0124] • the ME updates the stored identifier periodically, e.g., daily, weekly, monthly, etc.; or • the ME updates the stored identifier each time it receives or computes a new concealed user subscription identifier.

[0125] In other embodiments, when the ME can store a plurality (or set) of previously constructed concealed user subscription identifiers, then the ME would also need some logic to determine how to maintain the set, e.g., to let the set grow indefinitely large or to prune keep the set at or below a maximum size / number. For example, the maximum size of the set may be 100, 1000, 10000, etc. previously constructed concealed user subscription identifier. In some variants, the maximum size of the set may be configurable, e.g., as a UE implementation option. To ensure the size of the set does not grow beyond the maximum size, the ME may remove certain entries until the size is at or below the maximum size. This may be referred to as “pruning logic” and may have various forms / criteria, such as removing entries in the chronological order in which they were added (e.g., oldest first).

[0126] In some embodiments, the ME may store previously constructed concealed user subscription identifiers that the ME obtained (from USIM) or computed but did send to the network. In other words, a previously constructed concealed identifier does not need to be sent to a network in order to be stored by the ME in the set.

[0127] In some embodiments, after receiving an error message from USIM and determining that it cannot compute any more concealed user subscription identifiers, the ME selects a stored (previously constructed) concealed user subscription identifier and sends it to the network to which the ME is trying to connect. If the ME stores a set of a plurality of identifiers, the ME may select one of the stored identifiers in various ways, such as randomly, first in (or oldest), last in (or newest), etc.

[0128] In some variants, each stored identifier may include an explicit indication that it was stored and / or previously constructed (i.e., not currently constructed). In other variants, such an explicit indication may not be part of the stored identifier, but the ME may add such an indication to the stored identifier (or to a message containing the stored identifier) when it sends the identifier is to the network. For example, the explicit indication may be integrity protected based on security keys derived from security keys used to construct the concealed user subscription identifier.Other embodiments include methods for a network entity, such as an AUSF, a UDM (or sub-function thereof, such as SIDF and / or APRF), or other function in a 5G network, or network nodes, entities, or functions that provide similar and / or corresponding functionality in futuregeneration networks.

[0129] When the network entity receives from an ME an identification message that includes a concealed user subscription identifier, the network entity obtains the user subscription identifier from the received concealed identifier. In some variants, the network entity obtains the user subscription identifier by performing the de-concealment. In other variants, the network entity sends the concealed user subscription identifier to a second network entity, which returns the deconcealed the user subscription identifier.

[0130] The network entity may also determine whether an error condition exists in the UE that sent the identification message. This determination can be done by checking whether the received concealed identifier was previously received by the network entity. In some embodiments, the network entity may store concealed user subscription identifiers previously received from the UE, along with the respective times when they were received. Alternatively, the network entity may send concealed user subscription identifiers received from the UE to a second network entity for storage.

[0131] In either alternative, the previously received concealed user subscription identifiers may be stored in a database, in a bloom filter, or in a cuckoo hash table. A bloom filter is a spaceefficient probabilistic data structure that may be used to test whether an element is a member of a set. False positive matches are possible, but false negatives are not - in other words, a query returns either “possibly in set” or “definitely not in set.” The basic idea of cuckoo hashing is to resolve collisions in a hash table by using two hash functions instead of only one. This provides two possible locations in the hash table for each key associated with a value (i.e., a concealed user subscription identifier).

[0132] The network entity that stores the previously received concealed user subscription identifiers may need to remove some of them occasionally to keep the storage size below a maximum size limit. Different criteria may be used to determine when entries should be removed in this situation. For example, removal can be based on the respective timestamps of the entries, such that all entries older than a particular duration (e.g., one week) are removed. As another example, removal can be based on the total number of stored concealed user subscription identifiers being greater than a maximum number N (which may be configurable). When this condition occurs, removal may start with entries having the oldest timestamps and continue until the number of remaining entries is smaller than N by some predetermined amount.In some embodiments, each received concealed user subscription identifier may include an explicit indication that it was stored and / or previously constructed (i.e., not currently constructed) by the ME. In other variants, such an explicit indication may not be part of the received concealed user subscription identifier itself but rather part of the same identification message. For example, the explicit indication may be integrity protected based on security keys derived from security keys used to construct the concealed user subscription identifier. In any case, the network entity may determine that the concealed identifier was previously constructed (i.e., due to an error condition in the UE) based on this explicit indication.

[0133] If the network entity determines that the received concealed identifier was previously constructed (i.e., due to an error condition in the UE), then the network entity notifies the second network entity or an operations / administration / maintenance (0 AM) system of the error condition using a non-concealed identity of the user subscription. This notification enables the network to take corrective action against the error condition in the UE.

[0134] Figure 7 shows a signaling diagram of a procedure involving a network entity (730) and a USIM (710) and an ME (720) of a UE (700), according to various embodiments of the present disclosure. In particular, Figure 7 shows a procedure for when the USIM is configured for determining SUCI itself (i.e., in USIM) and providing SUCI to the ME.

[0135] Initially, the ME starts with an empty SpareSuciSet. When the ME first needs a SUCI, it sends a GET IDENTIY message to the USIM, which responds with SUCIi. The ME adds SUCIi to SpareSuciSet and sends SUCIi in an appropriate message to the network entity, such as described above. The network entity resolves the SUPI associated with the SUCIi determines if SUCIi is associated with an error state at the ME / USIM. In this instance, SUCIi is not associated with an error state.

[0136] When the ME needs another SUCI, it sends a GET IDENTIY message to the USIM, which responds with SUCE. The ME adds SUCI2 to SpareSuciSet and sends SUCI2 in an appropriate message to the network entity, such as described above. The network entity resolves the SUPI associated with SUCI2 and determines if SUCI2 is associated with an error state at the ME / USIM. In this instance, SUCI2 is not associated with an error state.

[0137] These operations are repeated until the ME has SUCIi, i=l...n, in SpareSuciSet. As mentioned above, however, the ME may choose to remove some SUCIs from the SpareSuciSet from time to time to keep it from growing indefinitely.

[0138] Subsequently, when the ME needs another SUCI, it sends a GET IDENTIY message to the USIM. However, the USIM responds with an error instead of SUCI. (Conditions of use not satisfied), the ME chooses a SUCH, x=l...n, from SpareSuciSet and sends SUCE in an appropriate message to the network entity. The ME may select SUCE from SpareSuciSet invarious ways, such as randomly, first-in-first-out (FIFO), last-in-first-out (LIFO), etc. The network entity resolves the SUPI associated with SUCL and determines if SUCL is associated with an error state at the ME / USIM. In this instance, SUCL is associated with an error state.

[0139] In case the ME sends another GET IDENTIY message to the USIM and receives another error message in response, the ME may select SUCIy, y=l...n, from SpareSuciSet in a similar manner and send SUCIy in an appropriate message to the network entity. The network entity resolves the SUPI associated with SUCIy and determines if SUCIy is associated with an error state at the ME / USIM. In this instance, SUCIy is associated with an error state.

[0140] If the USIM is configured such that SUCI is to be computed in the ME, the USIM responds to the ME’s GET IDENTITY messages in Figure 7 with status 6985 (conditions of use not satisfied) in normal operation. When the USIM responds to GET IDENTITY command with an error instead, the ME chooses a SUCL, x=l...n, from SpareSuciSet and sends SUCL in an appropriate message to the network entity, which behaves in the same manner as discussed above for USIM-computed SUCIs.

[0141] Note that SpareSuciSet maintained by the ME may include SUCIs computed by the USIM, SUCIs computed by the ME, or a combination thereof. In any case, SpareSuciSet should be stored in ME non-volatile memory so that information is not lost when the ME is powered off.

[0142] The embodiments described above can be further illustrated with reference to Figures 8-9, which depict exemplary methods (e.g., procedures) for ME and a network entity, respectively. Put differently, various features of the operations described below correspond to various embodiments described above. The exemplary methods shown in Figures 8-9 may be complementary to each other such that they can be used cooperatively to provide benefits, advantages, and / or solutions to problems described herein. Although the exemplary methods are illustrated in Figures 8-9 by specific blocks in particular orders, the operations corresponding to the blocks can be performed in different orders than shown and can be combined and / or divided into operations having different functionality than shown. Optional blocks and / or operations are indicated by dashed lines.

[0143] More specifically, Figure 8 illustrates an exemplary method (e.g., procedure) for ME that is part of a UE configured to operate in a communication network, according to various embodiments of the present disclosure. The exemplary method shown in Figure 8 can be performed by any appropriate ME (e.g., wireless device, AIoT device, ZE-IoT device, UE, etc.) such as described elsewhere herein.

[0144] The exemplary method includes the operations of block 820, where the ME receives an error message indicating that information necessary to construct a concealed subscriber identifier is unavailable. The exemplary method also includes the operations of block 830, where based onthe error message, the ME obtains a first concealed subscriber identifier from storage of the ME, wherein the first concealed subscriber identifier was previously received or constructed by the ME. The exemplary method also includes the operations of block 860, where the ME sends, to a network entity of the communication network, a message that includes the first concealed subscriber identifier.

[0145] In some embodiments, the exemplary method also includes the operations of block 810, where the ME sends a request for a concealed subscriber identifier to an identity module (e.g., SIM, USIM, etc.) in the UE . The error message is received in block 820 as one of the following options in a response from the identity module:

[0146] • the error message;

[0147] • a second concealed subscriber identifier constructed by the identity module; and

[0148] • a status message (e.g., status 6985 discussed above) indicating that conditions are not satisfied for the identity module to construct the requested concealed subscriber identifier. Figures 4-6 show examples of the above-listed options.

[0149] In some of these embodiments, the exemplary method also includes the operations of block 840, where based on the status message, the ME constructs the second concealed subscriber identifier based on a non-concealed subscriber identifier. In some variants of these embodiments, the message in block 860 includes the first concealed subscriber identifier when it is obtained from the storage. Also, the message in block 860 includes the second concealed subscriber identifier when it is received from the identity module or constructed by the ME.

[0150] In some of these embodiments, the exemplary method also includes the operations of block 850, where the ME selectively stores the second concealed subscriber identifier in the storage of the ME. In some variants of these embodiments, the storage in the ME is capable of storing a single concealed subscriber identifier, and selectively storing the first concealed subscriber identifier in the storage of the ME in block 850 includes one of the following operations, labelled with corresponding sub-block numbers:

[0151] • (851) refraining from replacing the first concealed subscriber identifier with the second concealed subscriber identifier;

[0152] • (852) replacing the first concealed subscriber identifier with the second concealed subscriber identifier; or

[0153] • (852) replacing the first concealed subscriber identifier with the second concealed subscriber identifier, when the first concealed subscriber identifier has been stored in the storage for at least a predetermined duration.

[0154] In some further variants, the predetermined duration is one of the following: one day, one week, or one month.In other variants of these embodiments, the storage in the ME is capable of storing a maximum number of concealed subscriber identifiers, and selectively storing the second concealed subscriber identifier in the storage of the ME in block 850 includes the following operations, labelled with corresponding sub-block numbers:

[0155] • (854) when a number of concealed subscriber identifiers currently stored in the storage is less than the maximum number, storing the second concealed subscriber identifier in the storage of the ME; and

[0156] • (855) when the number of concealed subscriber identifiers currently stored in the storage is equal to the maximum number, replacing one of the stored concealed subscriber identifiers with the second concealed subscriber identifier.

[0157] In some further variants, the replaced stored concealed subscriber identifiers is one of the following: randomly selected, earliest stored, or latest stored.

[0158] In some of these embodiments, the identity module is a universal subscriber identity module (USIM), the first and second concealed subscriber identifiers are SUCIs, and the network entity is one of the following: an AUSF, a UDM, or one or more sub-functions of an AUSF or a UDM.

[0159] In some embodiments, the message sent to the network entity includes an explicit indication that the first concealed subscriber identifier was obtained from storage of the ME. The explicit indication is included as one of the following:

[0160] • as part of the first concealed subscriber identifier;

[0161] • appended to the first concealed subscriber identifier; or

[0162] • in a separate field or part of the message than the first concealed subscriber identifier. In some of these embodiments, the explicit indication is integrity protected based on security keys derived from security keys used to construct the first concealed subscriber identifier.

[0163] In some embodiments, the storage of the ME is a non-volatile storage. In some embodiments, the message sent to the network entity is one of the following: an initial registration request, a response to an identity request, or a deregistration request.

[0164] In addition, Figure 9 illustrates an exemplary method (e.g., procedure) for a network entity configured to operate in a communication network, according to various embodiments of the present disclosure. The exemplary method shown in Figure 9 can be performed by any appropriate network entity (e.g., AUSF, UDM, sub-functions thereof, or network equipment configured to implement the same) such as described elsewhere herein.

[0165] The exemplary method includes the operations of block 910, where the network entity receives a message that includes a concealed subscriber identifier of a subscriber of the communication network. The exemplary method also includes the operations of block 920, wherethe network entity determines whether the received concealed subscriber identifier corresponds to a first concealed subscriber identifier, of the subscriber, that was previously received by the network entity. The exemplary method also includes the operations of block 960, where based on a determination that the received concealed subscriber identifier corresponds to the first concealed subscriber identifier, the network entity determines that an error condition exists in an identity module (e.g., SIM, USIM, etc.) associated with the subscriber.

[0166] In some embodiments, the exemplary method also includes the operations of block 930, where the network entity obtains a de-concealed subscriber identifier from the received concealed subscriber identifier, based on one of the following (labelled with corresponding sub-block numbers):

[0167] • (931) de-concealing the received concealed subscriber identifier; or

[0168] • (932) sending the received concealed subscriber identifier to a second network entity and receiving the de-concealed subscriber identifier from the network entity in response. In some embodiments, determining that the received concealed subscriber identifier corresponds to the first concealed subscriber identifier is based on an explicit indication included in the message, according to one of the following:

[0169] • as part of the received concealed subscriber identifier;

[0170] • appended to the received concealed subscriber identifier;

[0171] • in a separate field or part of the message than the received concealed subscriber identifier. In some of these embodiments, the explicit indication is integrity protected based on security keys derived from security keys used to construct the received concealed subscriber identifier.

[0172] In other embodiments, determining that the received concealed subscriber identifier corresponds to the first concealed subscriber identifier in block 920 includes the following operations, labelled with corresponding sub-block numbers:

[0173] • (921) sending the received concealed subscriber identifier to a second network entity; and • (922) receiving from the second network entity an indication that the received concealed subscriber identifier was previously received by the second network entity from the network entity.

[0174] In other embodiments, determining that the received concealed subscriber identifier corresponds to the first concealed subscriber identifier in block 920 includes the operations of subblock 932, where the network entity detects a match or correspondence between the received concealed subscriber identifier and one of a plurality concealed subscriber identifiers, of the subscriber, in a storage of the network entity.

[0175] In some of these embodiments, the exemplary method also includes the operations of block 940, where the network entity selectively stores the received concealed subscriber identifierin the storage. In some variants of these embodiments, the storage of the network entity is capable of storing a maximum number of concealed subscriber identifiers of the subscriber, and selectively storing the received concealed subscriber identifier in the storage in block 940 includes the following operations, labelled with corresponding sub-block numbers:

[0176] • (941) when a number of concealed subscriber identifiers currently stored in the storage is less than the maximum number, storing the received concealed subscriber identifier in the storage of the network entity; and

[0177] • (942) when the number of concealed subscriber identifiers currently stored in the storage is equal to the maximum number, replacing one of the stored concealed subscriber identifiers with the received concealed subscriber identifier.

[0178] In some further variants, the replaced stored concealed subscriber identifiers is one of the following: randomly selected, earliest stored, or latest stored.

[0179] In some of these embodiments, the exemplary method also includes the operations of block 950, where the network entity removes one or more of the stored concealed subscriber identifiers having longest duration in the storage. In some of these embodiments, the storage comprises one of the following: a database, a bloom filter, or in a cuckoo hash table.

[0180] In some embodiments, the message is received from mobile equipment (ME) operating in the communication network. In some of these embodiments, the message received from the ME is one of the following: an initial registration request, a response to an identity request, or a deregistration request.

[0181] In some embodiments, the identity module is a universal subscriber identity module (USIM), the first and second concealed subscriber identifiers are SUCIs, and the network entity is one of the following: AUSF, UDM, or one or more sub-functions of an AUSF or a UDM. In some embodiments, the exemplary method also includes the operations of block 970, where the network entity sends a notification of the error condition in the identity module to a second network entity or an operations / administration / maintenance (0 AM) system of the communication network. For example, the notification includes a non-concealed subscriber identifier corresponding to the received concealed subscriber identifier.

[0182] Although various embodiments are described above in terms of methods, apparatus, devices, computer-readable medium and receivers, the person of ordinary skill will readily comprehend that such methods can be embodied by various combinations of hardware and software in various systems, communication devices, computing devices, control devices, apparatuses, non-transitory computer-readable media, etc.

[0183] Figure 10 shows an example of a communication system 1000 in accordance with some embodiments. In this example, communication system 1000 includes a telecommunicationnetwork 1002 that includes an access network 1004 (e.g., RAN) and a core network 1006, which includes one or more core network nodes 1008. Access network 1004 includes one or more access network nodes, such as network nodes lOlOa-b (one or more of which may be referred to as network nodes 1010), or any other similar 3GPP access nodes or non-3GPP access points. Moreover, as will be appreciated by those of skill in the art, a network node is not necessarily limited to an implementation in which a radio portion and a baseband portion are supplied and integrated by a single vendor.

[0184] As such, network nodes may include disaggregated implementations or portions thereof. For example, in some embodiments, telecommunication network 1002 includes one or more Open-RAN (ORAN) network nodes. An ORAN network node is a node in telecommunication network 1002 that supports an ORAN specification (e.g., a specification published by the O-RAN Alliance, or any similar organization) and may operate alone or together with other nodes to implement one or more functionalities of any node in telecommunication network 1002, including one or more network nodes 1010 and / or core network nodes 1008.

[0185] Examples of an ORAN network node include an open radio unit (O-RU), an open distributed unit (O-DU), an open central unit (O-CU), including an O-CU control plane (O-CU-CP) or an O-CU user plane (O-CU-UP), a RAN intelligent controller (near-real time or non-real time) hosting software or software plug-ins, such as a near-real time control application (e.g., xApp) or a non-real time control application (e.g., rApp), or any combination thereof (the adjective “open” designating support of an ORAN specification). The network node may support a specification by, for example, supporting an interface defined by the ORAN specification, such as an Al, Fl, Wl, El, E2, X2, Xn interface, an open fronthaul user plane interface, or an open fronthaul management plane interface. Moreover, an ORAN access node may be a logical node in a physical node. Furthermore, an ORAN network node may be implemented in a virtualization environment (described further below) in which one or more network functions are virtualized. For example, the virtualization environment may include an O-Cloud computing platform orchestrated by a Service Management and Orchestration Framework via an O-2 interface defined by the O-RAN Alliance or comparable technologies. Network nodes 1010 facilitate direct or indirect connection of UEs, such as by connecting UEs 1012a-d (one or more of which may be referred to as UEs 1012) to core network 1006 over one or more wireless connections.

[0186] Example wireless communications over a wireless connection include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Moreover, in different embodiments, communication system 1000 may include any number of wired or wireless networks, network nodes, UEs, and / or any othercomponents or systems that may facilitate or participate in the communication of data and / or signals whether via wired or wireless connections. Communication system 1000 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar type of system.

[0187] UEs 1012 may be any of a wide variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with network nodes 1010 and other communication devices. Similarly, network nodes 1010 are arranged, capable, configured, and / or operable to communicate directly or indirectly with UEs 1012 and / or with other network nodes or equipment in telecommunication network 1002 to enable and / or provide network access, such as wireless network access, and / or to perform other functions, such as administration in telecommunication network 1002.

[0188] In the depicted example, core network 1006 connects network nodes 1010 to one or more hosts, such as host 1016. These connections may be direct or indirect via one or more intermediary networks or devices. In other examples, network nodes may be directly coupled to hosts. Core network 1006 includes one or more core network nodes (e.g., 1008) that are structured with hardware and software components. Features of these components may be substantially similar to those described with respect to the UEs, network nodes, and / or hosts, such that the descriptions thereof are applicable to the corresponding components of core network node 1008. Example core network nodes include functions of one or more of a Mobile Switching Center (MSC), Mobility Management Entity (MME), Home Subscriber Server (HSS), Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Server Function (AUSF), Subscription Identifier De-concealing function (SIDF), Unified Data Management (UDM), Security Edge Protection Proxy (SEPP), Network Exposure Function (NEF), and / or a User Plane Function (UPF).

[0189] Host 1016 may be under the ownership or control of a service provider other than an operator or provider of access network 1004 and / or telecommunication network 1002, and may be operated by the service provider or on behalf of the service provider. Host 1016 may host a variety of applications to provide one or more service. Examples of such applications include live and pre-recorded audio / video content, data collection services such as retrieving and compiling data on various ambient conditions detected by a plurality of UEs, analytics functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for an alarm and surveillance center, or any other such function performed by a server.

[0190] As a whole, communication system 1000 of Figure 10 enables connectivity between the UEs, network nodes, and hosts. In that sense, the communication system may be configured to operate according to predefined rules or procedures, such as specific standards that include, butare not limited to: Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long Term Evolution (LTE), and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standard (e.g., 6G); wireless local area network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 1002.11 standards (WiFi); and / or any other appropriate wireless communication standard, such as the Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, LiFi, and / or any low-power wide-area network (LPWAN) standards such as LoRa and Sigfox.

[0191] In some examples, telecommunication network 1002 is a cellular network that implements 3GPP standardized features. Accordingly, telecommunication network 1002 may support network slicing to provide different logical networks to different devices that are connected to telecommunication network 1002. For example, telecommunication network 1002 may provide Ultra Reliable Low Latency Communication (URLLC) services to some UEs, while providing Enhanced Mobile Broadband (eMBB) services to other UEs, and / or Massive Machine Type Communication (mMTC) / Massive loT services to yet further UEs.

[0192] In some examples, UEs 1012 are configured to transmit and / or receive information without direct human interaction. For instance, a UE may be designed to transmit information to access network 1004 on a predetermined schedule, when triggered by an internal or external event, or in response to requests from access network 1004. Additionally, a UE may be configured for operating in single- or multi-RAT or multi -standard mode. For example, a UE may operate with any one or combination of Wi-Fi, NR (New Radio) and LTE, i.e., being configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Evolved-UMTS Terrestrial Radio Access Network) New Radio - Dual Connectivity (EN-DC).

[0193] In the example, hub 1014 communicates with access network 1004 to facilitate indirect communication between one or more UEs (e.g., 1012c and / or 1012d) and network nodes (e.g., 1010b). In some examples, hub 1014 may be a controller, router, content source and analytics, or any of the other communication devices described herein regarding UEs. For example, hub 1014 may be a broadband router enabling access to core network 1006 for the UEs. As another example, hub 1014 may be a controller that sends commands or instructions to one or more actuators in the UEs. Commands or instructions may be received from the UEs, network nodes 1010, or by executable code, script, process, or other instructions in hub 1014. As another example, hub 1014 may be a data collector that acts as temporary storage for UE data and, in some embodiments, may perform analysis or other processing of the data. As another example, hub 1014 may be a content source. For example, for a UE that is a VR headset, display, loudspeaker or other media delivery device, hub 1014 may retrieve VR assets, video, audio, or other media or data related tosensory information via a network node, which hub 1014 then provides to the UE either directly, after performing local processing, and / or after adding additional local content. In still another example, hub 1014 acts as a proxy server or orchestrator for the UEs, in particular if one or more of the UEs are low energy loT devices.

[0194] Hub 1014 may have a constant / persistent or intermittent connection to network node 1010b. Hub 1014 may also allow for a different communication scheme and / or schedule between hub 1014 and UEs (e.g., 1012c and / or 1012d), and between hub 1014 and core network 1006. In other examples, hub 1014 is connected to core network 1006 and / or one or more UEs via a wired connection. Moreover, hub 1014 may be configured to connect to an M2M service provider over access network 1004 and / or to another UE over a direct connection. In some scenarios, UEs may establish a wireless connection with network nodes 1010 while still connected via hub 1014 via a wired or wireless connection. In some embodiments, hub 1014 may be a dedicated hub - that is, a hub whose primary function is to route communications to / from the UEs from / to network node 1010b. In other embodiments, hub 1014 may be a non-dedicated hub - that is, a device which is capable of operating to route communications between the UEs and network node 1010b, but which is additionally capable of operating as a communication start and / or end point for certain data channels.

[0195] In some embodiments, core network node 1008 and / or host 1016 may be configured to perform operations attributed to a network entity in the above descriptions of the procedures shown in Figures 4-9. In some embodiments, any of UEs 1012 (or portions thereof) may be configured to perform operations attributed to mobile equipment (ME) in the above descriptions of the procedures shown in Figures 4-9.

[0196] Figure 11 shows a UE 1100 in accordance with some embodiments. Examples of a UE include, but are not limited to, a smart phone, mobile phone, cell phone, voice over IP (VoIP) phone, wireless local loop phone, desktop computer, personal digital assistant (PDA), wireless cameras, gaming console or device, music storage device, playback appliance, wearable terminal device, wireless endpoint, mobile station, tablet, laptop, laptop -embedded equipment (LEE), laptop-mounted equipment (LME), smart device, wireless customer-premise equipment (CPE), vehicle, vehicle-mounted or vehicle embedded / integrated wireless device, etc. Other examples include any UE identified by 3 GPP, including a narrow band internet of things (NB-IoT) UE, a machine type communication (MTC) UE, and / or an enhanced MTC (eMTC) UE.

[0197] A UE may support device-to-device (D2D) communication, for example by implementing a 3GPP standard for sidelink communication, Dedicated Short-Range Communication (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle-to-everything (V2X). In other examples, a UE may not necessarily have a user in the sense of a human user who ownsand / or operates the relevant device. Instead, a UE may represent a device that is intended for sale to, or operation by, a human user but which may not, or which may not initially, be associated with a specific human user (e.g., a smart sprinkler controller). Alternatively, a UE may represent a device that is not intended for sale to, or operation by, an end user but which may be associated with or operated for the benefit of a user (e.g., a smart power meter).

[0198] UE 1100 includes processing circuitry 1102 that is operatively coupled via bus 1104 to input / output interface 1106, power source 1108, memory 1110, communication interface 1112, and optionally to one or more other components not explicitly shown. Certain UEs may utilize all or a subset of the components shown in Figure 11. The level of integration between the components may vary from one UE to another UE. Further, certain UEs may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.

[0199] Processing circuitry 1102 is configured to process instructions and data and may be configured to implement any sequential state machine operative to execute instructions stored as machine-readable computer programs in memory 1110. Processing circuitry 1102 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, field-programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), etc.); programmable logic together with appropriate firmware; one or more stored computer programs, general-purpose processors, such as a microprocessor or digital signal processor (DSP), together with appropriate software; or any combination of the above. For example, processing circuitry 1102 may include multiple central processing units (CPUs).

[0200] In the example, input / output interface 1106 may be configured to provide an interface or interfaces to an input device, output device, or one or more input and / or output devices. Examples of an output device include a speaker, a sound card, a video card, a display, a monitor, a printer, an actuator, an emitter, a smartcard, another output device, or any combination thereof. An input device may allow a user to capture information into UE 1100. Examples of an input device include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a web camera, etc.), a microphone, a sensor, a mouse, a trackball, a directional pad, a trackpad, a scroll wheel, a smartcard, and the like. The presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. A sensor may be, for instance, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, a biometric sensor, etc., or any combination thereof. An output device may use the same type of interface port as an input device. For example, a Universal Serial Bus (USB) port may be used to provide an input device and an output device.In some embodiments, power source 1108 is structured as a battery or battery pack. Other types of power sources, such as an external power source (e.g., an electricity outlet), photovoltaic device, or power cell, may be used. Power source 1108 may further include power circuitry for delivering power from power source 1108 itself, and / or an external power source, to the various parts of UE 1100 via input circuitry or an interface such as an electrical power cable. Delivering power may be, for example, for charging of power source 1108. Power circuitry may perform any formatting, converting, or other modification to the power from power source 1108 to make the power suitable for the respective components of UE 1100 to which power is supplied.

[0201] Memory 1110 may be or be configured to include memory such as random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, hard disks, removable cartridges, flash drives, and so forth. In one example, memory 1110 includes one or more application programs 1114, such as an operating system, web browser application, a widget, gadget engine, or other application, and corresponding data 1116. Memory 1110 may store, for use by UE 1100, any of a variety of various operating systems or combinations of operating systems.

[0202] Memory 1110 may be configured to include a number of physical drive units, such as redundant array of independent disks (RAID), flash memory, USB flash drive, external hard disk drive, thumb drive, pen drive, key drive, high-density digital versatile disc (HD-DVD) optical disc drive, internal hard disk drive, Blu-Ray optical disc drive, holographic digital data storage (HDDS) optical disc drive, external mini-dual in-line memory module (DIMM), synchronous dynamic random access memory (SDRAM), external micro-DIMM SDRAM, smartcard memory such as tamper resistant module in the form of a universal integrated circuit card (UICC) including one or more subscriber identity modules (SIMs), such as a USIM and / or ISIM, other memory, or any combination thereof. The UICC may for example be an embedded UICC (eUICC), integrated UICC (iUICC) or a removable UICC commonly known as ‘SIM card.’ Memory 1110 may allow UE 1100 to access instructions, application programs and the like, stored on transitory or non-transitory memory media, to off-load data, or to upload data. An article of manufacture, such as one utilizing a communication system may be tangibly embodied as or in memory 1110, which may be or comprise a device-readable storage medium.

[0203] Processing circuitry 1102 may be configured to communicate with an access network or other network using communication interface 1112. Communication interface 1112 may comprise one or more communication subsystems and may include or be communicatively coupled to an antenna 1122. Communication interface 1112 may include one or more transceivers used to communicate, such as by communicating with one or more remote transceivers of another devicecapable of wireless communication (e.g., another UE or a network node in an access network). Each transceiver may include a transmitter 1118 and / or a receiver 1120 appropriate to provide network communications (e.g., optical, electrical, frequency allocations, and so forth). Moreover, transmitter 1118 and receiver 1120 may be coupled to one or more antennas (e.g., antenna 1122) and may share circuit components, software, or firmware, or alternatively be implemented separately.

[0204] In the illustrated embodiment, communication functions of communication interface 1112 may include cellular communication, Wi-Fi communication, LPWAN communication, data communication, voice communication, multimedia communication, short-range communications such as Bluetooth, near-field communication, location-based communication such as the use of the global positioning system (GPS) to determine a location, another like communication function, or any combination thereof. Communications may be implemented in according to one or more communication protocols and / or standards, such as IEEE 802.11, Code Division Multiplexing Access (CDMA), Wideband Code Division Multiple Access (WCDMA), GSM, LTE, New Radio (NR), UMTS, WiMax, Ethernet, transmission control protocol / internet protocol (TCP / IP), synchronous optical networking (SONET), Asynchronous Transfer Mode (ATM), QUIC, Hypertext Transfer Protocol (HTTP), and so forth.

[0205] Regardless of the type of sensor, a UE may provide an output of data captured by its sensors, through its communication interface 1112, via a wireless connection to a network node. Data captured by sensors of a UE can be communicated through a wireless connection to a network node via another UE. The output may be periodic (e.g., once every 15 minutes if it reports the sensed temperature), random (e.g., to even out the load from reporting from several sensors), in response to a triggering event (e.g., when moisture is detected an alert is sent), in response to a request (e.g., a user initiated request), or a continuous stream (e.g., a live video feed of a patient).

[0206] As another example, a UE comprises an actuator, a motor, or a switch, related to a communication interface configured to receive wireless input from a network node via a wireless connection. In response to the received wireless input the states of the actuator, the motor, or the switch may change. For example, the UE may comprise a motor that adjusts the control surfaces or rotors of a drone in flight according to the received input or to a robotic arm performing a medical procedure according to the received input.

[0207] A UE, when in the form of an Internet of Things (loT) device, may be a device for use in one or more application domains, these domains comprising, but not limited to, city wearable technology, extended industrial application and healthcare. Non-limiting examples of such an loT device are a device which is or which is embedded in: a connected refrigerator or freezer, a TV, a connected lighting device, an electricity meter, a robot vacuum cleaner, a voice controlled smartspeaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a flood / moisture sensor, an electrical door lock, a connected doorbell, an air conditioning system like a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoring device, an electric vehicle charging station, a smart watch, a fitness tracker, a head-mounted display for Augmented Reality (AR) or Virtual Reality (VR), a wearable for tactile augmentation or sensory enhancement, a water sprinkler, an animal- or item-tracking device, a sensor for monitoring a plant or animal, an industrial robot, an Unmanned Aerial Vehicle (UAV), and any kind of medical device, like a heart rate monitor or a remote controlled surgical robot. A UE in the form of an loT device comprises circuitry and / or software in dependence of the intended application of the loT device in addition to other components as described in relation to UE 1100 shown in Figure 11.

[0208] As yet another specific example, in an loT scenario, a UE may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another UE and / or a network node. The UE may in this case be an M2M device, which may in a 3GPP context be referred to as an MTC device. As one particular example, the UE may implement the 3 GPP NB-IoT standard. In other scenarios, a UE may represent a vehicle, such as a car, a bus, a truck, a ship and an airplane, or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.

[0209] In practice, any number of UEs may be used together with respect to a single use case. For example, a first UE might be or be integrated in a drone and provide the drone’ s speed information (obtained through a speed sensor) to a second UE that is a remote controller operating the drone. When the user makes changes from the remote controller, the first UE may adjust the throttle on the drone (e.g., by controlling an actuator) to increase or decrease the drone’s speed. The first and / or the second UE can also include more than one of the functionalities described above. For example, a UE might comprise the sensor and the actuator, and handle communication of data for both the speed sensor and the actuators.

[0210] In some embodiments, UE 1100 (or a portion thereof) may be configured to perform operations attributed to mobile equipment (ME) in the above descriptions of the procedures shown in Figures 4-9. In other words, the ME comprises the components of UE 1100 described above, with the exception of the UICC that includes the SIM / USIM / ISIM functionality.

[0211] Figure 12 shows a network node 1200 in accordance with some embodiments. Examples of network nodes include, but are not limited to, access points (e.g., radio access points), base stations (e.g., radio base stations, Node Bs, eNBs, gNBs), and 0-RAN nodes or components of an 0-RAN node (e.g, O-RU, O-DU, O-CU).Base stations may be categorized based on the amount of coverage they provide (or, stated differently, their transmit power level) and so, depending on the provided amount of coverage, may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. A base station may be a relay node or a relay donor node controlling a relay. A network node may also include one or more (or all) parts of a distributed radio base station such as centralized digital units, distributed units (e.g., in an 0-RAN access node) and / or remote radio units (RRUs), sometimes referred to as Remote Radio Heads (RRHs). Such remote radio units may or may not be integrated with an antenna as an antenna integrated radio. Parts of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS).

[0212] Other examples of network nodes include multiple transmission point (multi-TRP) 5G access nodes, multi -standard radio (MSR) equipment such as MSRBSs, network controllers such as radio network controllers (RNCs) or base station controllers (BSCs), base transceiver stations (BTSs), transmission points, transmission nodes, multi-cell / multicast coordination entities (MCEs), Operation and Maintenance (O&M) nodes, Operations Support System (OSS) nodes, Self-Organizing Network (SON) nodes, positioning nodes (e.g., Evolved Serving Mobile Location Centers (E-SMLCs)), and / or Minimization of Drive Tests (MDTs).

[0213] Network node 1200 includes processing circuitry 1202, memory 1204, communication interface 1206, and power source 1208. Network node 1200 may be composed of multiple physically separate components (e.g., a NodeB component and a RNC component, or a BTS component and a BSC component, etc.), which may each have their own respective components. In certain scenarios in which network node 1200 comprises multiple separate components (e.g., BTS and BSC components), one or more of the separate components may be shared among several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair, may in some instances be considered a single separate network node. In some embodiments, network node 1200 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be duplicated (e.g., separate memory 1204 for different RATs) and some components may be reused (e.g., a same antenna 1210 may be shared by different RATs). Network node 1200 may also include multiple sets of the various illustrated components for different wireless technologies integrated into network node 1200, for example GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z-wave, LoRaWAN, Radio Frequency Identification (RFID) or Bluetooth wireless technologies. These wireless technologies may be integrated into the same or different chip or set of chips and other components within network node 1200.

[0214] Processing circuitry 1202 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor,application-specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other network node 1200 components, such as memory 1204, to provide network node 1200 functionality.

[0215] In some embodiments, processing circuitry 1202 includes a system on a chip (SOC). In some embodiments, processing circuitry 1202 includes radio frequency (RF) transceiver circuitry 1212 and / or baseband processing circuitry 1214. In some embodiments, RF transceiver circuitry 1212 and / or baseband processing circuitry 1214 may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. In alternative embodiments, part or all of RF transceiver circuitry 1212 and / or baseband processing circuitry 1214 may be on the same chip or set of chips, boards, or units.

[0216] Memory 1204 may comprise any form of volatile or non-volatile computer-readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD) or a Digital Video Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory devices that store information, data, and / or instructions that may be used by processing circuitry 1202. Memory 1204 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions (collectively denoted computer program 1204a, which may be in the form of a computer program product) capable of being executed by processing circuitry 1202 and utilized by network node 1200. Memory 1204 may be used to store any calculations made by processing circuitry 1202 and / or any data received via communication interface 1206. In some embodiments, processing circuitry 1202 and memory 1204 is integrated.

[0217] Communication interface 1206 is used in wired or wireless communication of signaling and / or data between a network node, access network, and / or UE. As illustrated, communication interface 1206 comprises port(s) / terminal(s) 1216 to send and receive data, for example to and from a network over a wired connection. Communication interface 1206 also includes radio frontend circuitry 1218 that may be coupled to, or in certain embodiments a part of, antenna 1210. Radio front-end circuitry 1218 comprises filters 1220 and amplifiers 1222. Radio front-end circuitry 1218 may be connected to an antenna 1210 and processing circuitry 1202. The radio front-end circuitry may be configured to condition signals communicated between antenna 1210 and processing circuitry 1202. Radio front-end circuitry 1218 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. Radio front-end circuitry1218 may convert the digital data into a radio signal having the appropriate channel and bandwidth parameters using a combination of filters 1220 and / or amplifiers 1222. The radio signal may then be transmitted via antenna 1210. Similarly, when receiving data, antenna 1210 may collect radio signals which are then converted into digital data by radio front-end circuitry 1218. The digital data may be passed to processing circuitry 1202. In other embodiments, the communication interface may comprise different components and / or different combinations of components.

[0218] In certain alternative embodiments, network node 1200 does not include separate radio front-end circuitry 1218, instead, processing circuitry 1202 includes radio front-end circuitry and is connected to antenna 1210. Similarly, in some embodiments, all or some of RF transceiver circuitry 1212 is part of communication interface 1206. In still other embodiments, communication interface 1206 includes one or more ports or terminals 1216, radio front-end circuitry 1218, and RF transceiver circuitry 1212, as part of a radio unit (not shown), and communication interface 1206 communicates with baseband processing circuitry 1214, which is part of a digital unit (not shown).

[0219] Antenna 1210 may include one or more antennas, or antenna arrays, configured to send and / or receive wireless signals. Antenna 1210 may be coupled to radio front-end circuitry 1218 and may be any type of antenna capable of transmitting and receiving data and / or signals wirelessly. In certain embodiments, antenna 1210 is separate from network node 1200 and connectable to network node 1200 through an interface or port.

[0220] Antenna 1210, communication interface 1206, and / or processing circuitry 1202 may be configured to perform any receiving operations and / or certain obtaining operations described herein as being performed by the network node. Any information, data and / or signals may be received from a UE, another network node and / or any other network equipment. Similarly, antenna 1210, communication interface 1206, and / or processing circuitry 1202 may be configured to perform any transmitting operations described herein as being performed by the network node. Any information, data and / or signals may be transmitted to a UE, another network node and / or any other network equipment.

[0221] Power source 1208 provides power to the various components of network node 1200 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). Power source 1208 may further comprise, or be coupled to, power management circuitry to supply the components of network node 1200 with power for performing the functionality described herein. For example, network node 1200 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of power source 1208. As a further example, power source 1208 may comprise a source of powerin the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail.

[0222] Embodiments of network node 1200 may include additional components beyond those shown in Figure 12 for providing certain aspects of the network node’s functionality, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, network node 1200 may include user interface equipment to allow input of information into network node 1200 and to allow output of information from network node 1200. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for network node 1200.

[0223] In some embodiments, network node 1200 may be configured to perform operations attributed to a network entity in the above descriptions of the procedures shown in Figures 4-9.

[0224] Figure 13 is a block diagram illustrating a virtualization environment 1300 in which functions implemented by some embodiments may be virtualized. In the present context, virtualizing means creating virtual versions of apparatuses or devices which may include virtualizing hardware platforms, storage devices and networking resources. As used herein, virtualization can be applied to any device described herein, or components thereof, and relates to an implementation in which at least a portion of the functionality is implemented as one or more virtual components. Some or all of the functions described herein may be implemented as virtual components executed by one or more virtual machines (VMs) implemented in one or more virtual environments 1300 hosted by one or more of hardware nodes, such as a hardware computing device that operates as a network node, UE, core network node, or host. Further, in embodiments in which the virtual node does not require radio connectivity (e.g., a core network node or host), then the node may be entirely virtualized. In some embodiments, the virtualization environment 1300 includes components defined by the O-RAN Alliance, such as an O-Cloud environment orchestrated by a Service Management and Orchestration Framework via an O-2 interface.

[0225] Applications 1302 (which may alternatively be called software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) are run in the virtualization environment 1300 to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein. For example, various virtual nodes 1302 may be configured to perform operations attributed to a network entity in the above descriptions of the procedures shown in Figures 4-9.

[0226] Hardware 1304 includes processing circuitry, memory that stores software and / or instructions (collectively denoted computer program 1304a, which may be in the form of a computer program product) executable by hardware processing circuitry, and / or other hardware devices as described herein, such as a network interface, input / output interface, and so forth.Software may be executed by the processing circuitry to instantiate one or more virtualization layers 1306 (also referred to as hypervisors or virtual machine monitors (VMMs)), provide VMs 1308a-b (one or more of which may be referred to as VMs 1308), and / or perform any of the functions, features and / or benefits described in relation with some embodiments described herein. Virtualization layer 1306 may present a virtual operating platform that appears like networking hardware to the VMs 1308.

[0227] VMs 1308 comprise virtual processing, virtual memory, virtual networking or interface and virtual storage, and may be run by a corresponding virtualization layer 1306. Different embodiments of the instance of a virtual appliance 1302 may be implemented on one or more of VMs 1308, and the implementations may be made in different ways. Virtualization of the hardware is in some contexts referred to as network function virtualization (NFV). NFV may be used to consolidate many network equipment types onto industry standard high volume server hardware, physical switches, and physical storage, which can be located in data centers, and customer premise equipment.

[0228] In the context of NFV, each VM 1308 may be a software implementation of a physical machine that runs programs as if they were executing on a physical, non-virtualized machine. Each VM 1308, and that part of hardware 1304 that executes that VM, be it hardware dedicated to that VM and / or hardware shared by that VM with others of the VMs, forms separate virtual network elements. Still in the context of NFV, a virtual network function is responsible for handling specific network functions that run in one or more VMs 1308 on top of the hardware 1304 and corresponds to the application 1302.

[0229] Hardware 1304 may be implemented in a standalone network node with generic or specific components. Hardware 1304 may implement some functions via virtualization. Alternatively, hardware 1304 may be part of a larger cluster of hardware (e.g., such as in a data center or CPE) where many hardware nodes work together and are managed via management and orchestration function 1310, which, among others, oversees lifecycle management of applications 1302. In some embodiments, hardware 1304 is coupled to one or more radio units that each include one or more transmitters and one or more receivers that may be coupled to one or more antennas. Radio units may communicate directly with other hardware nodes via one or more appropriate network interfaces and may be used in combination with the virtual components to provide a virtual node with radio capabilities, such as a radio access node or a base station. In some embodiments, some signaling can be provided with the use of a control system 1312 which may alternatively be used for communication between hardware nodes and radio units.

[0230] The foregoing merely illustrates the principles of the disclosure. Various modifications and alterations to the described embodiments will be apparent to those skilled in the art in view ofthe teachings herein. It will thus be appreciated that those skilled in the art will be able to devise numerous systems, arrangements, and procedures that, although not explicitly shown or described herein, embody the principles of the disclosure and can be thus within the spirit and scope of the disclosure. Various exemplary embodiments may be used together with one another, as well as interchangeably therewith, as should be understood by those having ordinary skill in the art.

[0231] The term unit, as used herein, can have conventional meaning in the field of electronics, electrical devices and / or electronic devices and can include, for example, electrical and / or electronic circuitry, devices, modules, processors, memories, logic solid state and / or discrete devices, computer programs or instructions for carrying out respective tasks, procedures, computations, outputs, and / or displaying functions, and so on, as such as those that are described herein.

[0232] Any appropriate steps, methods, features, functions, or benefits disclosed herein may be performed through one or more functional units or modules of one or more virtual apparatuses. Each virtual apparatus may comprise a number of these functional units. These functional units may be implemented via processing circuitry, which may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include Digital Signal Processor (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as Read Only Memory (ROM), Random Access Memory (RAM), cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory may include program instructions for executing one or more telecommunications and / or data communications protocols as well as instructions for carrying out one or more of the techniques described herein. In some implementations, the processing circuitry may be used to cause the respective functional unit to perform corresponding functions according to one or more embodiments of the present disclosure.

[0233] As described herein, device and / or apparatus may be represented by a semiconductor chip, a chipset, or a (hardware) module comprising such chip or chipset; this, however, does not exclude the possibility that a functionality of a device or apparatus, instead of being hardware implemented, be implemented as a software module such as a computer program or a computer program product comprising executable software code portions for execution or being run on a processor. Furthermore, functionality of a device or apparatus may be implemented by any combination of hardware and software. A device or apparatus may also be regarded as an assembly of multiple devices and / or apparatuses, whether functionally in cooperation with or independently of each other. Moreover, devices and apparatuses may be implemented in a distributed fashion throughout a system, so long as the functionality of the device or apparatus is preserved. Such and similar principles are considered known to a skilled person.Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs. It will be further understood that terms used herein should be interpreted as having a meaning that is consistent with their meaning in the context of this specification and the relevant art and will not be interpreted in an idealized or overly formal sense unless expressly so defined herein.

[0234] In addition, certain terms used in the present disclosure, including the specification and drawings, may be used synonymously in certain instances (e.g., “data” and “information”). It should be understood that although such terms may be used synonymously herein, there can be instances when such terms are not intended to be used synonymously.

[0235] Embodiments of the present disclosure also include but are not limited to the following enumerated examples:

[0236] Al . A method performed by mobile equipment (ME), the ME being part of a user equipment (UE) configured to operate in a communication network, the method comprising:

[0237] receiving an error message indicating that information necessary to construct a concealed subscriber identifier is unavailable;

[0238] based on the error message, obtaining a first concealed subscriber identifier from storage of the ME, wherein the first concealed subscriber identifier was previously received or constructed by the ME; and

[0239] sending, to a network entity of the communication network, a message that includes the first concealed subscriber identifier.

[0240] Ala. The method of embodiment Al, further comprising sending a request for a concealed subscriber identifier to a subscriber identity module (SIM) of the UE, wherein the error message is received as one of the following options in a response from the SIM:

[0241] the error message;

[0242] a second concealed subscriber identifier constructed by the SIM; and

[0243] a status message indicating that conditions are not satisfied for the SIM to construct the requested concealed subscriber identifier.

[0244] Alb. The method of embodiment Ala, further comprising, based on the status message, constructing the second concealed subscriber identifier based on a non-concealed subscriber identifier.Ale. The method of any of embodiment Alb, wherein:

[0245] the message sent to the network entity includes the first concealed subscriber identifier when it is obtained from the storage; and

[0246] the message sent to the network entity includes the second concealed subscriber identifier when it is received from the SIM or constructed by the ME.

[0247] A2. The method of any of embodiments Ala-Alc, further comprising selectively storing the second concealed subscriber identifier in the storage of the ME.

[0248] A3. The method of embodiment A2, wherein the storage in the ME is capable of storing a single concealed subscriber identifier, and selectively storing the first concealed subscriber identifier in the storage of the ME comprises one of the following:

[0249] refraining from replacing the first concealed subscriber identifier with the second concealed subscriber identifier;

[0250] replacing the first concealed subscriber identifier with the second concealed subscriber identifier; or

[0251] replacing the first concealed subscriber identifier with the second concealed subscriber identifier, when the first concealed subscriber identifier has been stored in the storage for at least a predetermined duration.

[0252] A3a. The method of embodiment A3, wherein the predetermined duration is one of the following: one day, one week, or one month.

[0253] A4. The method of embodiment A2, wherein the storage in the ME is capable of storing a maximum number of concealed subscriber identifiers, and selectively storing the second concealed subscriber identifier in the storage of the ME comprises:

[0254] when a number of concealed subscriber identifiers currently stored in the storage is less than the maximum number, storing the second concealed subscriber identifier in the storage of the ME; and

[0255] when the number of concealed subscriber identifiers currently stored in the storage is equal to the maximum number, replacing one of the stored concealed subscriber identifiers with the second concealed subscriber identifier.

[0256] A4a. The method of embodiment A4, wherein the replaced stored concealed subscriber identifiers is one of the following: randomly selected, earliest stored, or latest stored.A5. The method of any of embodiments Ala-A4, wherein the SIM is a universal SIM (USIM), the first and second concealed subscriber identifiers are subscription concealed identifiers (SUCIs), and the network entity is one of the following: authentication server function (AUSF), unified data management function (UDM), or one or more sub-functions of an AUSF or a UDM.

[0257] A6. The method of any of embodiments A1-A5, wherein the message sent to the network entity includes an explicit indication that the first concealed subscriber identifier was obtained from storage of the ME, wherein the explicit indication is included as one of the following: as part of the first concealed subscriber identifier;

[0258] appended to the first concealed subscriber identifier; or

[0259] in a separate field or part of the message than the first concealed subscriber identifier.

[0260] A6a. The method of embodiment A6, wherein the explicit indication is integrity protected based on security keys derived from security keys used to construct the first concealed subscriber identifier.

[0261] A7. The method of any of embodiments Al-A6a, wherein the storage of the ME is a nonvolatile storage.

[0262] A8. The method of any of embodiments A1-A7, wherein the message sent to the network entity is one of the following: an initial registration request, a response to an identity request, or a deregistration request.

[0263] Bl. A method for a network entity configured to operate in a communication network, the method comprising:

[0264] receiving a message that includes a concealed subscriber identifier of a subscriber of the communication network;

[0265] determining whether the received concealed subscriber identifier corresponds to a first concealed subscriber identifier, of the subscriber, that was previously received by the network entity; and

[0266] based on determining that the received concealed subscriber identifier corresponds to the first concealed subscriber identifier, determining that an error condition exists in a subscriber identity module (SIM) associated with the subscriber.B2. The method of embodiment Bl, further comprising obtaining a de-concealed subscriber identifier from the received concealed subscriber identifier, based on one of the following:

[0267] de-concealing the received concealed subscriber identifier; or

[0268] sending the received concealed subscriber identifier to a second network entity and receiving the de-concealed subscriber identifier from the network entity in response.

[0269] B3. The method of any of embodiments B1-B2, wherein determining that the received concealed subscriber identifier corresponds to the first concealed subscriber identifier is based on an explicit indication included in the message, according to one of the following:

[0270] as part of the received concealed subscriber identifier;

[0271] appended to the received concealed subscriber identifier;

[0272] in a separate field or part of the message than the received concealed subscriber identifier.

[0273] B3a. The method of embodiment B3, wherein the explicit indication is integrity protected based on security keys derived from security keys used to construct the received concealed subscriber identifier.

[0274] B4. The method of any of embodiments B1-B2, wherein determining that the received concealed subscriber identifier corresponds to the first concealed subscriber identifier comprises:

[0275] sending the received concealed subscriber identifier to a second network entity; and receiving from the second network entity an indication that the received concealed subscriber identifier was previously received by the second network entity from the network entity.

[0276] B5. The method of any of embodiments B1-B2, determining that the received concealed subscriber identifier corresponds to the first concealed subscriber identifier comprises detecting a match or correspondence between the received concealed subscriber identifier and one of a plurality concealed subscriber identifiers, of the subscriber, in a storage of the network entity.

[0277] B5a. The method of embodiment B5, further comprising selectively storing the received concealed subscriber identifier in the storage.B5b. The method of embodiment B5a, wherein the storage of the network entity is capable of storing a maximum number of concealed subscriber identifiers of the subscriber, and selectively storing the received concealed subscriber identifier in the storage comprises:

[0278] when a number of concealed subscriber identifiers currently stored in the storage is less than the maximum number, storing the received concealed subscriber identifier in the storage of the network entity; and

[0279] when the number of concealed subscriber identifiers currently stored in the storage is equal to the maximum number, replacing one of the stored concealed subscriber identifiers with the received concealed subscriber identifier.

[0280] B5c. The method of embodiment B5b, wherein the replaced stored concealed subscriber identifiers is one of the following: randomly selected, earliest stored, or latest stored.

[0281] B6. The method of any of embodiments B5-B5c, further comprising removing one or more of the stored concealed subscriber identifiers having longest duration in the storage.

[0282] B7. The method of any of embodiments B5-B6, wherein the storage comprises one of the following: a database, a bloom filter, or in a cuckoo hash table.

[0283] B8. The method of any of embodiments B1-B7, wherein the message is received from mobile equipment (ME) operating in the communication network.

[0284] B8a. The method of embodiment B8, wherein the message received from the ME is one of the following: an initial registration request, a response to an identity request, or a deregistration request.

[0285] B9. The method of any of embodiments Bl-B8a, wherein the SIM is a universal SIM (USIM), the first and second concealed subscriber identifiers are subscription concealed identifiers (SUCIs), and the network entity is one of the following: authentication server function (AUSF), unified data management function (UDM), or one or more sub-functions of an AUSF or a UDM.

[0286] BIO. The method of any of embodiments B1-B9, further comprising sending a notification of the error condition in the SIM to a second network entity or an operations / administration / maintenance (0AM) system of the communication network, wherein the notification includes anon-concealed subscriber identifier corresponding to the received concealed subscriber identifier.

[0287] C 1. Mobile equipment (ME) arranged to operate as part of user equipment (UE) configured to operate in a communication network, the ME comprising:

[0288] communication interface circuitry configured to communicate with at least a network entity of the communication network; and

[0289] processing circuitry operably coupled to the communication interface circuitry, wherein the processing circuitry and interface circuitry are configured to perform operations corresponding to any of the methods of embodiments A1-A8.

[0290] C2. Mobile equipment (ME) arranged to operate as part of user equipment (UE) configured to operate in a communication network, the ME being further arranged to perform operations corresponding to any of the methods of embodiments A1-A8.

[0291] C3. A non-transitory, computer-readable medium storing computer-executable instructions that, when executed by processing circuitry of mobile equipment (ME) arranged to operate as part of user equipment (UE) configured to operate in a communication network, configure the ME to perform operations corresponding to any of the methods of embodiments A1-A8.

[0292] C4. A computer program product comprising computer-executable instructions that, when executed by processing circuitry of mobile equipment (ME) arranged to operate as part of user equipment (UE) configured to operate in a communication network, configure the ME to perform operations corresponding to any of the methods of embodiments A1-A8.

[0293] DI . Network equipment arranged to implement a network entity of a communication network, the network equipment comprising:

[0294] communication interface circuitry configured to communicate with mobile equipment (ME) operating in the communication network; and

[0295] processing circuitry operably coupled to the communication interface circuitry, wherein the processing circuitry and interface circuitry are configured to perform operations corresponding to any of the methods of embodiments Bl -BIO.D2. Network equipment arranged to implement a network entity of a communication network, the network equipment being further arranged to perform operations corresponding to any of the methods of embodiments Bl -BIO.

[0296] D3. A non-transitory, computer-readable medium storing computer-executable instructions that, when executed by processing circuitry of network equipment arranged to implement a network entity of a communication network, configure the network equipment to perform operations corresponding to any of the methods of embodiments Bl -BIO.

[0297] D4. A computer program product comprising computer-executable instructions that, when executed by processing circuitry of network equipment arranged to implement a network entity of a communication network, configure the network equipment to perform operations corresponding to any of the methods of embodiments Bl -BIO.

Claims

CLAIMS1. A method performed by mobile equipment, ME, that is part of a user equipment, UE, configured to operate in a communication network, the method comprising:receiving (820) an error message indicating that information necessary to construct a concealed subscriber identifier is unavailable;based on the error message, obtaining (830) a first concealed subscriber identifier from storage of the ME, wherein the first concealed subscriber identifier was previously received or constructed by the ME; andsending (860), to a network entity of the communication network, a message that includes the first concealed subscriber identifier.

2. The method of claim 1, further comprising sending (810) a request for a concealed subscriber identifier to an identity module, identity module, in the UE, wherein the error message is received as one of the following options in a response from the identity module: the error message;a second concealed subscriber identifier constructed by the identity module; and a status message indicating that conditions are not satisfied for the identity module to construct the requested concealed subscriber identifier.

3. The method of claim 2, further comprising, based on the status message, constructing (840) the second concealed subscriber identifier based on a non-concealed subscriber identifier.

4. The method of any of claim 3, wherein:the message sent to the network entity includes the first concealed subscriber identifier when it is obtained from the storage; andthe message sent to the network entity includes the second concealed subscriber identifier when it is received from the identity module or constructed by the ME.

5. The method of any of claims 2-4, further comprising selectively storing (850) the second concealed subscriber identifier in the storage of the ME.

6. The method of claim 5, wherein the storage in the ME is capable of storing a single concealed subscriber identifier, and selectively storing (850) the first concealed subscriber identifier in the storage of the ME comprises one of the following:44refraining from replacing (851) the first concealed subscriber identifier with the second concealed subscriber identifier;replacing (852) the first concealed subscriber identifier with the second concealed subscriber identifier; orreplacing (853) the first concealed subscriber identifier with the second concealed subscriber identifier, when the first concealed subscriber identifier has been stored in the storage for at least a predetermined duration.

7. The method of claim 6, wherein the predetermined duration is one of the following: one day, one week, or one month.

8. The method of claim 5, wherein the storage in the ME is capable of storing a maximum number of concealed subscriber identifiers, and selectively storing (850) the second concealed subscriber identifier in the storage of the ME comprises:when a number of concealed subscriber identifiers currently stored in the storage is less than the maximum number, storing (854) the second concealed subscriber identifier in the storage of the ME; andwhen the number of concealed subscriber identifiers currently stored in the storage is equal to the maximum number, replacing (855) one of the stored concealed subscriber identifiers with the second concealed subscriber identifier.

9. The method of claim 8, wherein the replaced stored concealed subscriber identifiers is one of the following: randomly selected, earliest stored, or latest stored.

10. The method of any of claims 2-9, wherein:the identity module is a universal subscriber identity module, USIM;the first and second concealed subscriber identifiers are subscription concealed identifiers, SUCIs; andthe network entity is one of the following: authentication server function, AUSF; unified data management function, UDM; or one or more sub-functions of an AUSF or a UDM.

11. The method of any of claims 1-10, wherein the message sent to the network entity includes an explicit indication that the first concealed subscriber identifier was obtained from storage of the ME, wherein the explicit indication is included as one of the following:45as part of the first concealed subscriber identifier;appended to the first concealed subscriber identifier; orin a separate field or part of the message than the first concealed subscriber identifier.

12. The method of claim 11, wherein the explicit indication is integrity protected based on security keys derived from security keys used to construct the first concealed subscriber identifier.

13. The method of any of claims 1-12, wherein the storage of the ME is a non-volatile storage.

14. The method of any of claims 1-13, wherein the message sent to the network entity is one of the following: an initial registration request, a response to an identity request, or a deregistration request.

15. A method for a network entity configured to operate in a communication network, the method comprising:receiving (910) a message that includes a concealed subscriber identifier of a subscriber of the communication network;determining (920) whether the received concealed subscriber identifier corresponds to a first concealed subscriber identifier, of the subscriber, that was previously received by the network entity; andbased on a determination that the received concealed subscriber identifier corresponds to the first concealed subscriber identifier, determining (960) that an error condition exists in an identity module associated with the subscriber.

16. The method of claim 15, further comprising obtaining (930) a de-concealed subscriber identifier from the received concealed subscriber identifier, based on one of the following: de-concealing (931) the received concealed subscriber identifier; orsending (932) the received concealed subscriber identifier to a second network entity and receiving the de-concealed subscriber identifier from the network entity in response.4617. The method of any of claims 15-16, wherein the determination that the received concealed subscriber identifier corresponds to the first concealed subscriber identifier is based on an explicit indication included in the message according to one of the following:as part of the received concealed subscriber identifier;appended to the received concealed subscriber identifier;in a separate field or part of the message than the received concealed subscriber identifier.

18. The method of claim 17, wherein the explicit indication is integrity protected based on security keys derived from security keys used to construct the received concealed subscriber identifier.

19. The method of any of claims 15-16, wherein determining (920) whether the received concealed subscriber identifier corresponds to the first concealed subscriber identifier comprises:sending (921) the received concealed subscriber identifier to a second network entity; andreceiving (922) from the second network entity an indication that the received concealed subscriber identifier was previously received by the second network entity from the network entity.

20. The method of any of claims 15-16, wherein determining (920) whether the received concealed subscriber identifier corresponds to the first concealed subscriber identifier comprises detecting (923) a match or correspondence between the received concealed subscriber identifier and one of a plurality concealed subscriber identifiers, of the subscriber, in a storage of the network entity.

21. The method of claim 20, further comprising selectively storing (940) the received concealed subscriber identifier in the storage.

22. The method of claim 21, wherein the storage of the network entity is capable of storing a maximum number of concealed subscriber identifiers of the subscriber, and selectively storing (940) the received concealed subscriber identifier in the storage comprises:when a number of concealed subscriber identifiers currently stored in the storage is less than the maximum number, storing (941) the received concealed subscriber identifier in the storage of the network entity; andwhen the number of concealed subscriber identifiers currently stored in the storage is equal to the maximum number, replacing (942) one of the stored concealed subscriber identifiers with the received concealed subscriber identifier.

23. The method of claim 22, wherein the replaced stored concealed subscriber identifiers is one of the following: randomly selected, earliest stored, or latest stored.

24. The method of any of claims 20-23, further comprising removing (950) one or more of the stored concealed subscriber identifiers having longest duration in the storage.

25. The method of any of claims 20-24, wherein the storage comprises one of the following: a database, a bloom filter, or in a cuckoo hash table.

26. The method of any of claims 15-25, wherein the message is received from mobile equipment, ME, operating in the communication network.

27. The method of claim 26, wherein the message received from the ME is one of the following: an initial registration request, a response to an identity request, or a deregistration request.

28. The method of any of claims 15-27, wherein:the identity module is a universal subscriber identity module, USIM;the first and second concealed subscriber identifiers are subscription concealed identifiers, SUCIs; andthe network entity is one of the following: authentication server function, AUSF; unified data management function, UDM;, or one or more sub-functions of an AUSF or a UDM.

29. The method of any of claims 15-28, further comprising sending (970) a notification of the error condition in the identity module to a second network entity or an operations / administration / maintenance, 0AM, system of the communication network, wherein the notification includes a non-concealed subscriber identifier corresponding to the received concealed subscriber identifier.

30. Mobile equipment, ME (420, 720) arranged to operate as part of user equipment, UE (105, 210, 400, 700, 1012, 1100) configured to operate in a communication network (200, 1002), the ME comprising:communication interface circuitry (1112) configured to communicate with at least a network entity of the communication network; andprocessing circuitry (1102) operably coupled to the communication interface circuitry, wherein the processing circuitry and the communication interface circuitry are configured to:receive an error message indicating that information necessary to construct a concealed subscriber identifier is unavailable;based on the error message, obtain a first concealed subscriber identifier from storage of the ME, wherein the first concealed subscriber identifier was previously received or constructed by the ME; and send, to a network entity (230, 240, 430, 730) of the communication network, a message that includes the first concealed subscriber identifier.

31. The ME of claim 30, wherein the processing circuitry and the communication interface circuitry are further configured to perform operations corresponding to any of the methods of claims 2-14.

32. Mobile equipment, ME (420, 720) arranged to operate as part of user equipment, UE (105, 210, 400, 700, 1012, 1100) configured to operate in a communication network (200, 1002), the ME being further arranged to:receive an error message indicating that information necessary to construct a concealed subscriber identifier is unavailable;based on the error message, obtain a first concealed subscriber identifier from storage of the ME, wherein the first concealed subscriber identifier was previously received or constructed by the ME; andsend, to a network entity (230, 240, 430, 730) of the communication network, a message that includes the first concealed subscriber identifier.

33. The ME of claim 32, being further arranged to perform operations corresponding to any of the methods of claims 2-14.4934. Non-transitory, computer-readable medium (1110) storing computer-executable instructions that, when executed by processing circuitry (1102), cause the method of any of claims 1-14 to be performed by mobile equipment, ME (420, 720) arranged to operate as part of the user equipment, UE (105, 210, 400, 700, 1012, 1100) configured to operate in the communication network (200, 1002).

35. Computer program product (1114) comprising computer-executable instructions that, when executed by processing circuitry (1102), cause the method of any of claims 1-14 to be performed by mobile equipment, ME (420, 720) arranged to operate as part of the user equipment, UE (105, 210, 400, 700, 1012, 1100) configured to operate in the communication network (200, 1002).

36. Network equipment (1008, 1016, 1200, 1302) arranged to implement a network entity (230, 240, 430, 730) of a communication network (200, 1002), the network equipment comprising:communication interface circuitry (1206, 1304) configured to communicate with mobile equipment, ME (420, 720) operating in the communication network; and processing circuitry (1202, 1304) operably coupled to the communication interface circuitry, wherein the processing circuitry and the communication interface circuitry are configured to:receive a message that includes a concealed subscriber identifier of a subscriber of the communication network;determine whether the received concealed subscriber identifier corresponds to a first concealed subscriber identifier, of the subscriber, that was previously received by the network entity; andbased on a determination that the received concealed subscriber identifier corresponds to the first concealed subscriber identifier, determine that an error condition exists in an identity module (410, 710) associated with the subscriber.

37. The network equipment of claim 36, wherein the processing circuitry and the communication interface circuitry are further configured to perform operations corresponding to any of the methods of claims 16-29.5038. Network equipment (1008, 1016, 1200, 1302) arranged to implement a network entity (230, 240, 430, 730) of a communication network (200, 1002), the network equipment being further arranged to:receive a message that includes a concealed subscriber identifier of a subscriber of the communication network;determine whether the received concealed subscriber identifier corresponds to a first concealed subscriber identifier, of the subscriber, that was previously received by the network entity; andbased on a determination that the received concealed subscriber identifier corresponds to the first concealed subscriber identifier, determine that an error condition exists in an identity module (410, 710) associated with the subscriber.

39. The network equipment of claim 38, being further configured to perform operations corresponding to any of the methods of claims 16-29.

40. Non-transitory, computer-readable medium (1204, 1304) storing computer-executable instructions that, when executed by processing circuitry (1202, 1304), cause the method of any of claims 15-29 to be performed by network equipment (1008, 1016, 1200, 1302) arranged to implement the network entity (230, 240, 430, 730) of the communication network (200, 1002).

41. Computer program product comprising computer-executable instructions that, when executed by processing circuitry (1202, 1304), cause the method of any of claims 15-29 to be performed by network equipment (1008, 1016, 1200, 1302) arranged to implement the network entity (230, 240, 430, 730) of the communication network (200, 1002).51