Method and apparatus for managing security context in a wireless communication system
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2026-01-20
- Publication Date
- 2026-08-13
Smart Images

Figure KR2026001178_13082026_PF_FP_ABST
Abstract
Description
METHOD AND APPARATUS FOR MANAGING SECURITY CONTEXT IN A WIRELESS COMMUNICATION SYSTEM
[0001] The disclosure relates to a communication system, more particularly, to handling Non-Access Stratum (NAS) count and security context for store-and-forward (S&F) mode of operations in a non-terrestrial network.
[0002] 5G mobile communication technologies define broad frequency bands such that high transmission rates and new services are possible, and can be implemented not only in “Sub 6GHz” bands such as 3.5GHz, but also in “Above 6GHz” bands referred to as mmWave including 28GHz and 39GHz. In addition, it has been considered to implement 6G mobile communication technologies (referred to as Beyond 5G systems) in terahertz (THz) bands (for example, 95GHz to 3THz bands) in order to accomplish transmission rates fifty times faster than 5G mobile communication technologies and ultra-low latencies one-tenth of 5G mobile communication technologies.
[0003] At the beginning of the development of 5G mobile communication technologies, in order to support services and to satisfy performance requirements in connection with enhanced Mobile BroadBand (eMBB), Ultra Reliable Low Latency Communications (URLLC), and massive Machine-Type Communications (mMTC), there has been ongoing standardization regarding beamforming and massive MIMO for mitigating radio-wave path loss and increasing radio-wave transmission distances in mmWave, supporting numerologies (for example, operating multiple subcarrier spacings) for efficiently utilizing mmWave resources and dynamic operation of slot formats, initial access technologies for supporting multi-beam transmission and broadbands, definition and operation of BWP (BandWidth Part), new channel coding methods such as a LDPC (Low Density Parity Check) code for large amount of data transmission and a polar code for highly reliable transmission of control information, L2 pre-processing, and network slicing for providing a dedicated network specialized to a specific service.
[0004] Currently, there are ongoing discussions regarding improvement and performance enhancement of initial 5G mobile communication technologies in view of services to be supported by 5G mobile communication technologies, and there has been physical layer standardization regarding technologies such as V2X (Vehicle-to-everything) for aiding driving determination by autonomous vehicles based on information regarding positions and states of vehicles transmitted by the vehicles and for enhancing user convenience, NR-U (New Radio Unlicensed) aimed at system operations conforming to various regulation-related requirements in unlicensed bands, NR UE Power Saving, Non-Terrestrial Network (NTN) which is UE-satellite direct communication for providing coverage in an area in which communication with terrestrial networks is unavailable, and positioning.
[0005] Moreover, there has been ongoing standardization in air interface architecture / protocol regarding technologies such as Industrial Internet of Things (IIoT) for supporting new services through interworking and convergence with other industries, IAB (Integrated Access and Backhaul) for providing a node for network service area expansion by supporting a wireless backhaul link and an access link in an integrated manner, mobility enhancement including conditional handover and DAPS (Dual Active Protocol Stack) handover, and two-step random access for simplifying random access procedures (2-step RACH for NR). There also has been ongoing standardization in system architecture / service regarding a 5G baseline architecture (for example, service based architecture or service based interface) for combining Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) for receiving services based on UE positions.
[0006] As 5G mobile communication systems are commercialized, connected devices that have been exponentially increasing will be connected to communication networks, and it is accordingly expected that enhanced functions and performances of 5G mobile communication systems and integrated operations of connected devices will be necessary. To this end, new research is scheduled in connection with eXtended Reality (XR) for efficiently supporting AR (Augmented Reality), VR (Virtual Reality), MR (Mixed Reality) and the like, 5G performance improvement and complexity reduction by utilizing Artificial Intelligence (AI) and Machine Learning (ML), AI service support, metaverse service support, and drone communication.
[0007] Furthermore, such development of 5G mobile communication systems will serve as a basis for developing not only new waveforms for providing coverage in terahertz bands of 6G mobile communication technologies, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), array antennas and large-scale antennas, metamaterial-based lenses and antennas for improving coverage of terahertz band signals, high-dimensional space multiplexing technology using OAM (Orbital Angular Momentum), and RIS (Reconfigurable Intelligent Surface), but also full-duplex technology for increasing frequency efficiency of 6G mobile communication technologies and improving system networks, AI-based communication technology for implementing system optimization by utilizing satellites and AI (Artificial Intelligence) from the design stage and internalizing end-to-end AI support functions, and next-generation distributed computing technology for implementing services at levels of complexity exceeding the limit of UE operation capability by utilizing ultra-high-performance communication and computing resources.
[0008] The integration of satellite communication within a fifth generation (5G) system enables the provision of connectivity to User Equipment (UE) located in remote or underserved areas. One operational mode supported in such a system is the Store and Forward (S&F) satellite operation mode, which is configured to support delay-tolerant communication services. The S&F satellite operation mode is particularly applicable when satellite connectivity is intermittent or temporary, such as when a satellite is not connected to a ground network through a feeder link or an inter-satellite link (ISL).
[0009] In a normal satellite operation mode of a 5G system, continuous end-to-end connectivity between the UE and a remote ground network is required. Such continuous connectivity is achieved by maintaining an active service link between the UE and a satellite and concurrently an active feeder link between the satellite and the ground network, thereby ensuring an uninterrupted communication path between the UE, the satellite, and the ground network.
[0010] In contrast, the S&F satellite operation mode includes a two-step communication process that does not require concurrent connectivity. In a first step, the UE exchanges signaling and / or data with the satellite while the satellite is not connected to the ground network. In a second step, the satellite subsequently establishes connectivity with the ground network and forwards previously stored signaling and / or data. The S&F satellite operation mode is particularly suitable for delay-tolerant or non-real-time services, including Internet of Things (IoT) services, and is especially relevant for Non-Geostationary Orbit (NGSO) satellite deployments.
[0011] In 3GPP-based systems, the Non-Access Stratum (NAS) security is maintained using NAS COUNT counters for uplink and downlink NAS messages. The NAS COUNT counters include sequence numbers and overflow counters and are used to ensure integrity protection and confidentiality of NAS messages exchanged between the UE and a mobility management entity (MME).
[0012] A technical problem arises when a UE communicates with different mobility management entities (MMEs) onboard different satellites, each satellite maintaining an independent NAS security context, including NAS COUNT values. Since the NAS COUNT values are independently maintained by the UE and by the MMEs onboard the respective satellites, inconsistencies may occur. For example, when the UE receives a downlink NAS message from a second satellite, referred to as Satellite ID 2, with a NAS COUNT value lower than a NAS COUNT value previously received from a first satellite, referred to as Satellite ID 1, the UE discards the downlink NAS message as outdated or invalid. Such discarding of downlink NAS messages may result in abnormal behavior at the UE or within the network, including rejection of valid signaling messages and failure of communication procedures. The problem arises due to a lack of synchronization between NAS COUNT values maintained by the UE and NAS COUNT values maintained by the MMEs onboard different satellites when the UE transitions between satellite coverage areas.
[0013] Accordingly, while the S&F satellite operation mode in a 5G system with satellite access provides a mechanism for supporting delay-tolerant communication services, it also introduces challenges related to synchronization of NAS COUNT values across multiple satellites, particularly in scenarios involving intermittent connectivity and frequent transitions of the UE between different satellites.
[0014] Thus, it is desired to address the above-mentioned disadvantages, issues, or other shortcomings, or at least provide a useful alternative.
[0015] The principal object of the disclosure herein is handling NAS count and security context for store-and-forward operations in a non-terrestrial network.
[0016] Yet another object of the disclosure is to provide a method for handling NAS count and security context in a non-terrestrial network that enables independent management of security contexts per satellite identifier, thereby preventing replay attacks and ensuring secure communication during satellite handovers in store-and-forward operations.
[0017] Yet another object of the disclosure is to provide the method for storing and maintaining separate pairs of uplink NAS count and downlink NAS count for each satellite in a non-terrestrial network, thereby enabling the UE and MME to independently increment and manage NAS counters without synchronization across different satellites.
[0018] In an aspect, the objectives are achieved by providing a method of handling NAS count and security context for store-and-forward operations in a non-terrestrial network. Further, the method includes receiving by the UE a broadcast information from a network apparatus. The broadcast information includes a satellite identifier identifying a satellite currently serving the UE from among a plurality of satellites in the non-terrestrial network. Further, the method includes storing by the UE a plurality of security contexts associated with a respective satellite identifier. Each security context includes a pair of an uplink NAS count and a downlink NAS count. The pair of the uplink NAS count and the downlink NAS count of each security context plurality of security contexts are stored independently from other pairs of uplink NAS count and downlink NAS count of other security contexts of the plurality of security contexts. Further, the method may include selecting by the UE based on the received satellite identifier a security context from the plurality of security contexts stored at the UE. The selected security context corresponds to the satellite identifier of the satellite currently serving the UE. Further, the method includes activating by the UE the selected security context for securing NAS message exchanges associated with the satellite identifier.
[0019] In another aspect, the objectives are achieved by providing a method of handling NAS count and security context for store-and-forward operations in a non-terrestrial network. Further, the method includes storing by the MME the plurality of security contexts associated with a respective satellite identifier of the plurality of satellites in the non-terrestrial network. Each security context includes a pair of an uplink NAS count and a downlink NAS count. The pair of the uplink NAS count and the downlink NAS count of each security context plurality of security contexts are stored independently from other pairs of uplink NAS count and downlink NAS count of other security contexts of the plurality of security contexts. Further, the method includes selecting by the MME the security context from the plurality of security contexts based on the satellite identifier associated with the satellite on which the MME is located. Further, the method includes activating by the MME the selected security context for securing NAS message exchanges associated with the satellite identifier.
[0020] In another aspect, the objectives are achieved by providing the UE for handling NAS count and security context for store-and-forward operations in a non-terrestrial network. Further, the UE includes a memory, a processor, and a NAS security context controller. Further, the NAS security context controller is coupled to the memory and the processor. The NAS security context controller receives the broadcast information from the network apparatus. The broadcast information includes the satellite identifier identifying the satellite currently serving the UE from among the plurality of satellites in the non-terrestrial network. Further, the NAS security context controller stores the plurality of security contexts associated with a respective satellite identifier. Each security context includes a pair of the uplink NAS count and the downlink NAS count. The pair of the uplink NAS count and the downlink NAS count of each security context plurality of security contexts are stored independently from other pairs of uplink NAS count and downlink NAS count of other security contexts of the plurality of security contexts. Further, the NAS security context controller selects the security context from the plurality of security contexts stored at the UE. The selected security context corresponds to the satellite identifier of the satellite currently serving the UE. Further, the NAS security context controller activates the selected security context for securing NAS message exchanges associated with the satellite identifier.
[0021] In another aspect, the objectives are achieved by providing the MME for handling NAS count and security context for store-and-forward operations in a non-terrestrial network. Further, the MME includes a memory, a processor, and a NAS security context controller coupled to the memory and the processor. The NAS security context controller stores the plurality of security contexts associated with the respective satellite identifier of the plurality of satellites in the non-terrestrial network. Each security context includes a pair of the uplink NAS count and the downlink NAS count. The pair of the uplink NAS count and the downlink NAS count of each security context plurality of security contexts are stored independently from other pairs of uplink NAS count and downlink NAS count of other security contexts of the plurality of security contexts. Further, the NAS security context controller selects the security context from the plurality of security contexts based on the satellite identifier associated with the satellite on which the MME is located. Further, the NAS security context controller activates the selected security context for securing NAS message exchanges associated with the satellite identifier.
[0022] These aspects and others will be better appreciated and understood with the following description and accompanying drawings. The descriptions, indicating preferred embodiments and specific details, are for illustration and not limitation. Many changes and modifications are possible within the scope of the embodiments, which include all such modifications.
[0023] Aspects of the disclosure are to address at least the above-mentioned problems and / or disadvantages and to provide at least the advantages described below. Accordingly, an aspect of the disclosure is to provide efficient communication methods in a wireless communication system.
[0024] These and other features, aspects, and advantages of the present disclosure are illustrated in the accompanying drawings, throughout which like reference letters indicate corresponding parts in the various figures. The embodiments herein will be better understood from the following description with reference to the drawings, in which:
[0025] FIG. 1A illustrates a schematic diagram of the normal / default satellite operation mode according to prior art.
[0026] FIG. 1B illustrates a schematic diagram of the Store & Forward (S&F) Satellite operation mode according to prior art.
[0027] FIG. 1C illustrates a sequence diagram showing a scenario where the first satellite ID and the second satellite ID store different NAS COUNT values, causing abnormal behavior at the UE or network according to prior art.
[0028] FIG. 2A is a block diagram that illustrates the UE for handling NAS count and security context for store-and-forward operations in a non-terrestrial network according to embodiments as disclosed herein.
[0029] FIG. 2B is a block diagram that illustrates the Mobility Management Entity (MME) for handling NAS count and security context for store-and-forward operations in a non-terrestrial network.
[0030] FIG. 3A is a flowchart that illustrates a method of handling NAS count and security context for store-and-forward operations in the non-terrestrial network according to embodiments as disclosed herein.
[0031] FIG. 3B is a flowchart that illustrates a method of handling NAS count and security context for store-and-forward operations in the non-terrestrial network according to embodiments as disclosed herein.
[0032] FIG. 4 illustrates a sequence diagram depicting a scenario in which the UE stores and uses UL NAS COUNT and DL NAS COUNT and UE Security Context per satellite ID according to embodiments as disclosed herein.
[0033] FIG. 5 illustrates a sequence diagram depicting a scenario in which the UE maintains and stores independent NAS security contexts per satellite according to embodiments disclosed herein.
[0034] FIG. 6 is a block diagram of a terminal or user equipment (UE) 600 according to an embodiment of the disclosure.
[0035] FIG. 7 is a block diagram of a base station (BS) 700 according to an embodiment of the disclosure.
[0036] FIG.8 is a block diagram of a network entity 800 according to an embodiment of the disclosure.
[0037] Hereinafter, embodiments of the disclosure will be described in detail with reference to the accompanying drawings.
[0038] In describing the embodiments, while numerous details are set forth for the purpose of illustration, it is understood that some aspects of the disclosure may be practiced with less than all of these details. Numerous variations and alternatives to the details provided herein are possible and are considered within the scope of the disclosure. In some instances, descriptions related to technical contents well-known in the art may be omitted so as to not obscure an understanding of the disclosure, and such omitted descriptions are understood to be within the scope of the disclosure.
[0039] For the same reason, in the accompanying drawings, some elements may be exaggerated, omitted, or schematically illustrated. Further, the size of each element does not completely reflect the actual size. In the drawings, identical or corresponding elements are provided with identical reference numerals or different reference numerals.
[0040] The advantages and features of the disclosure and ways to achieve them will be apparent by making reference to embodiments as described herein in detail in conjunction with the accompanying drawings. However, the disclosure is not limited to the embodiments set forth herein, but may be implemented in various different forms. Other features, aspects, and advantages of the subject matter described herein will become apparent from the disclosure. The following embodiments are merely examples to aid in an understanding of the disclosure and should not be construed to narrow the scope or spirit of the subject matter described herein in any way, but on the contrary, the disclosure covers all modifications, equivalents and alternatives falling within the spirit and scope of the subject matter as defined by the appended claims and equivalents thereof. Throughout the specification, the same or like reference numerals designate the same or like elements. Furthermore, terms which will be described herein are terms defined in consideration of the functions in the disclosure, and may be different according to users, intentions of the operators, or customs. Therefore, the definitions of the terms should be made based on the contents throughout the specification.
[0041] Herein, it will be understood that each block of flowchart illustrations, and combinations of blocks in the flowchart illustrations, may be performed based on computer program instructions. These computer program instructions may be loaded collectively onto at least one processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which perform through any one of, or in any combination of, the at least one processor of the computer or other programmable data processing apparatus, create means for performing the functions specified in the flowchart block(s). These computer program instructions may also be stored in a non-transitory computer usable or computer-readable memory that may direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer usable or computer-readable memory produce an article of manufacture including instruction means that perform the function specified in the flowchart block(s). The computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable data processing apparatus to produce a computer executed process such that the instructions that perform on the computer or other programmable data processing apparatus provide steps for executing the functions specified in the flowchart block(s).
[0042] Further, each block may represent a module, segment, or portion of code, which includes one or more executable instructions for executing the specified logical function(s). It should also be noted that in some alternative implementations, the functions noted in the blocks may occur out of the order. For example, two blocks(or functions) shown in succession may in fact be performed substantially concurrently or the blocks may sometimes be performed in the reverse order, depending upon the functionality involved.
[0043] As used in embodiments of the disclosure, a “~unit / module” may refer to a software element or a hardware element, such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC), which performs a predetermined function. However, the term including the word “~unit / module” does not always have a meaning limited to software or hardware. The “~unit / module” may be constructed either to be stored in an addressable storage medium or to execute one or more processors. Therefore, the “~unit / module” includes, for example, software elements, object-oriented software elements, components such as class elements and task elements, processes, functions, properties, procedures, sub-routines, segments of a program code, drivers, firmware, micro-codes, circuits, data, database, data structures, tables, arrays, and parameters. The components and functions provided by the “~unit / module” may be either combined into a smaller number of components and a “~unit / module,” or divided into additional components and a “~unit / module.” Moreover, the components and “~units / modules” may be implemented to reproduce one or more central processing units (CPUs) within a device or a security multimedia card. Further, in the embodiments, the “~unit / module” may include one or more processors.
[0044] The entirety of the one or more computer programs may be stored in a single memory device or the one or more computer programs may be divided with different portions stored in different multiple memory devices.
[0045] Any of the functions or operations described herein can be processed by one processor or a combination of processors. The one processor or the combination of processors is circuitry performing processing and includes circuitry like an application processor (AP, e.g. a CPU), a communication processor (CP, e.g., a modem), a graphics processing unit (GPU), a neural processing unit (NPU) (e.g., an artificial intelligence (AI) chip), a Wi-Fi chip, a Bluetooth® chip, a global positioning system (GPS) chip, a near field communication (NFC) chip, connectivity chips, a sensor controller, a touch controller, a finger-print sensor controller, a display driver integrated circuit (IC), an audio CODEC chip, a universal serial bus (USB) controller, a camera controller, an image processing IC, microprocessors, microcontrollers, digital signal processors, FPGA, ASIC, a microprocessor unit (MPU), a system on chip (SoC), an IC, or the like. The one processor or the combination of processors executes instructions that can be stored in a memory, such as the operating system, in order to control the overall operation of the device. Also, the one processor or the combination of processors is also capable of executing other processes and programs resident in the memory, such as processes for the disclosure.
[0046] It will be appreciated that various embodiments of the disclosure according to the claims and description in the specification can be realized in the form of hardware, software or a combination of hardware and software.
[0047] Any such software may be stored in non-transitory computer readable storage media. The non-transitory computer readable storage media store one or more computer programs (software modules), the one or more computer programs include computer-executable instructions that, when executed by one or more processors of an electronic device individually or collectively, cause the electronic device to perform a method of the disclosure. Additionally, or alternatively, such software may be a computer program [product] comprising instructions which, when executed by one or more processors of an electronic device individually or collectively, cause the electronic device to perform a method of the disclosure.
[0048] Any such software may be stored in the form of volatile or non-volatile storage such as, for example, a storage device like read only memory (ROM), whether erasable or rewritable or not, or in the form of memory such as, for example, random access memory (RAM), memory chips, device or integrated circuits or on an optically or magnetically readable medium such as, for example, a compact disk (CD), digital versatile disc (DVD), magnetic disk or magnetic tape or the like. It will be appreciated that the storage devices and storage media are various embodiments of non-transitory machine-readable storage that are suitable for storing a computer program or computer programs comprising instructions that, when executed, implement various embodiments of the disclosure. Accordingly, various embodiments of the present disclosure may provide a program comprising code for implementing apparatus or a method as claimed in any one of the claims of this specification and a non-transitory machine-readable storage storing such a program.
[0049] Hereinafter, the determination of priority between A and B in the present disclosure may refer to various actions such as selecting the one having a higher priority based on a predefined priority rule and performing an operation corresponding thereto, or omitting or dropping an operation corresponding to the one having a lower priority.
[0050] Hereinafter, "A or B" as described in the present disclosure may be understood as "A and / or B," which may include A, or B, or both A and B.
[0051] In addition, "at least one of A, B, and C" as described in the present disclosure may be understood to include A, or B, or C, or any combination of A, B, and C.
[0052] In addition, "at least one of A, B, or C" as described in the present disclosure may be understood to include A, or B, or C, or any combination of A, B, and C.
[0053] Furthermore, "A / B" as described in the present disclosure may be understood as "A and / or B," which may include A, or B, or both A and B.
[0054] Furthermore, "A, B" as described in the present disclosure may be understood as "A and / or B," which may include A, or B, or both A and B.
[0055] Furthermore, "A and B" as described in the present disclosure may be understood as "A and / or B," which may include A, or B, or both A and B.
[0056] Furthermore, “if condition A and condition B are satisfied,” as described in the present disclosure, may not be limited to a case where both condition A and condition B are satisfied, but may be understood to include a case where either condition A or condition B is individually satisfied, both condition A and condition B are satisfied, or one or more additional conditions are satisfied in combination.
[0057] Furthermore, throughout this disclosure, ordinal terms such as "first," "second," "third," etc., (and similar qualifiers) are used merely to distinguish between different instances, occurrences, configurations, messages, stages, elements or aspects of elements, operations, or information as described herein. Unless the context clearly dictates otherwise, the use of such ordinal terms does not itself require that the elements, operations, or information distinguished by these terms be structurally different, numerically distinct, or substantively dissimilar. For example, a "first signal" and a "second signal" may refer to instances of the same signal transmitted at different times or containing the same core information despite minor variations, or they may refer to signals with different content or characteristics, depending on the specific context. Similarly, a "first value" and a "second value" may represent the same magnitude but measured or applied in different circumstances, or they may represent different magnitudes. The interpretation should be guided by the specific technical context, function, and relationship described in the relevant portion of the specification and claims.
[0058] Furthermore, the terms “first ~”, “second ~”, etc., as described in the present disclosure with respect to various elements (e.g., information, objects, operation, sequences, or the like), should not limit those elements. These terms may only be intended to distinguish one element from another, and may not be intended to indicate a specific order. For example, a first element could be termed a second element, and, similarly, a second element could be termed a first element.
[0059] Furthermore, even if “first ~” and “second ~” are described in the present disclosure, it may be understood that element(s) referred to by “first ~” and “second ~” may be the same or different. For example, in case of element(s) being information, first information and second information may both be same information and, in some cases, are separate and different information.
[0060] In addition, the terms “if ~” and “in case that ~” as used in the disclosure or claims may be interpreted to include the meanings of “when (or upon) ~,” “in response to ~,” “based on ~,” or “according to ~,” and may be used interchangeably with these expressions. In addition, expressions other than those exemplified herein may also be used, as long as they have substantially the same meaning and do not impair the technical features of the present disclosure. If a method step (e.g. transmit a signal) is performed according to the disclosure of the application in connection with one of the above terms (such as “in case that ~” or the like), it may be interpreted to include the meanings (disclosure) of a prior determination that a feature has a specific state “~” (e.g. a bit length is above X), and then perform the method step in response to said determination.
[0061] For example, the physical layer signaling may be referred to as Layer 1 (L1) signaling and may include downlink control information (DCI). In addition, the higher layer signaling may include a medium access control (MAC) control message, a radio resource control (RRC) signaling message, a non-access stratum (NAS) signaling message, or an application layer message. The RRC signaling message may be referred to as L3 (layer 3) signaling. It should be noted, however, that the higher layer signaling is not limited to the aforementioned examples.
[0062] In addition, the term "not perform" as used in the present disclosure or claims may, in context, be understood to mean that the corresponding step is omitted or skipped. Such a term may be replaced with other terms having the same or substantially equivalent meaning.
[0063] In addition, "transmitting a message including A and B" as described in the present disclosure, may be understood as encompassing both (i) transmitting A and B in a single message, and (ii) transmitting A and B separately via multiple messages (e.g., transmitting a first message including A and a second message including B). This interpretation may also apply to messages that include two or more items (e.g., A, B, C), transmitted either together or separately.
[0064] In addition, "transmitting a message including A and transmitting a message including B" may also be interpreted as transmitting a message including A and B in a single message.
[0065] In the embodiments of the present disclosure described herein, terms or components included in the disclosure may be expressed in singular or plural form depending on the specific embodiments presented. However, such singular or plural expressions are selected appropriately for convenience of description, and the present disclosure is not limited to a singular or plural number of components. A component expressed in the plural form may be implemented as a single component, and a component expressed in the singular form may be implemented as multiple components.
[0066] The drawings or flowcharts described herein illustrate example methods that may be implemented according to the principles of the present disclosure, and various modifications may be made to the methods illustrated in the flowcharts of the present disclosure. For example, although illustrated as a series of steps, various steps in each drawing or flowchart may overlap, occur in parallel, occur in a different order, or be repeated. In other examples, any step may be omitted or replaced with another step.
[0067] The process of the flowchart may be performed by a device. One or more of the steps of the flowchart can be implemented by one or more processors / computer programs executing instructions to perform the noted functions.
[0068] The methods and apparatuses proposed in the embodiments of the present disclosure may be disclosed in connection with drawings disclosing flowcharts to illustrate example methods that may be implemented according to the principles of the present disclosure. Such flowcharts may contain different branches and / or sub-branches. It is understood that the principles of the present disclosure do not only contain the combination of all branches / sub-branches disclosed in the embodiment, but the present disclosure also contains at least one isolated branch / isolated sub-branch, in particular to a single branch / single sub-branch.
[0069] The methods and apparatuses proposed in the embodiments of the present disclosure are not limited to each embodiment individually, but may also be applied in combination of all or some of the embodiments proposed in the disclosure. Therefore, the embodiments of the present disclosure may be modified and applied without significantly departing from the scope of the present disclosure, as would be understood by those skilled in the art.
[0070] In this case, even if certain wordings are described differently across embodiments, they may be used interchangeably or in substitution or in combination if their underlying concepts are equivalent. For example, for the same or equivalent concept, even if one embodiment uses the expression "A" and another embodiment uses the expression "B", such expressions may be understood interchangeably, in substitution, or in combination.
[0071] The terms used in the following description to refer to access nodes, network entities, messages, interfaces between network entities, various types of identification information, and the like, are provided merely for the convenience of explanation by way of example. Therefore, the present disclosure is not limited to the terms describedherein, and other terms having equivalent technical meanings may also be used. Such terms may also be interchangeable with terms defined in any 3rd generation partnership project (3GPP) technical specifications (TS) or similar technical specifications, e.g., from the European telecommunications standards institute (ETSI), where appropriate.
[0072] Hereinafter, a base station (BS) is an entity that allocates resources to terminals, and may be at least one of a gNode B, an eNode B, a Node B, a wireless access unit, a BS controller, or a node on a network.
[0073] Furthermore, the base station of the present disclosure may include a split architecture comprising a central unit (CU) and a distributed unit (DU). In this structure, the CU is configured to process the higher layers of the control and user planes, while the DU is configured to process lower-layer radio resource functions. The embodiments of the present disclosure may be equally applicable to 5th generation (5G) base station architectures in which such CU and DU functional splits are implemented.
[0074] A terminal may include a user equipment (UE), a mobile station (MS), a cellular phone, a smartphone, a computer, a tablet, a wearable device, an Internet of Things (IoT) device, or any other device / system capable of performing communication functions.
[0075] In the disclosure, a downlink (DL) refers to a radio link through which a BS transmits a signal to a terminal, and an uplink (UL) refers to a radio link through which a terminal transmits a signal to a BS.
[0076] Furthermore, hereinafter, 5G mobile communication technologies (e.g., 5G new radio (NR)), 6th generation (6G) mobile communication technologies may be described by way of example, but the embodiments of the present disclosure may also be applied to other communication systems having similar technical backgrounds or channel types. For example, newly evolved mobile communication systems developed after 5G and 6G may be included. Furthermore, based on determinations by those skilled in the art, the embodiments of the present disclosure may also be applied to other communication systems (e.g., Wi-Fi systems) through some modifications without significantly departing from the scope of the present disclosure
[0077] In the following description, the terms physical channel and signal may be used interchangeably with data or control signal. For example, the term physical downlink shared channel (PDSCH) refers to a physical channel through which data is transmitted, but the term PDSCH may also be used to refer to the data itself. That is, in the present disclosure, the expression "transmit a physical channel" may be interpreted as being equivalent to the expression "transmit data or a signal via a physical channel."
[0078] Hereinafter, in the context of the present disclosure, higher layer signaling may refer to signaling corresponding to at least one or any combination of the following: master information block (MIB), system information block (SIB) or SIB M (M = 1, 2, ...), RRC, or MAC control element (CE), or a non-access stratum (NAS) signaling message, or an application layer message. The RRC signaling message may be referred to as Layer 3 (L3) signaling.
[0079] In addition, L1 signaling may refer to signaling corresponding to at least one or any combination of signaling techniques using the at least one or any combination of the following physical layer channels or signaling: physical downlink control channel (PDCCH), DCI, UE-specific DCI, group-common DCI, common DCI, scheduling DCI (e.g., DCI used for scheduling downlink or uplink data), non-scheduling DCI (e.g., DCI not used for scheduling downlink or uplink data) physical uplink control channel (PUCCH), or uplink control information (UCI). The L1 signaling message may be referred to as a physical layer signaling.
[0080] Hereinafter, the expression that information is configured by the BS, as used in the present disclosure or claims, may, in context, be understood to mean that the terminal receives the corresponding information from the BS via a physical layer signaling or a higher layer signaling. Such an expression may be replaced with other terms having the same or substantially equivalent meaning.
[0081] Hereinafter, the operational principle of the present disclosure will be described in detail with reference to the accompanying drawings.
[0082] The embodiments herein and the various features and advantageous details thereof are explained more fully with reference to the non-limiting embodiments that are illustrated in the accompanying drawings and detailed in the following description. Descriptions of well-known components and processing techniques are omitted so as to not unnecessarily obscure the embodiments herein. Also, the various embodiments described herein are not necessarily mutually exclusive, as some embodiments can be combined with one or more other embodiments to form new embodiments. The term “or” as used herein, refers to a non-exclusive or, unless otherwise indicated. The examples used herein are intended merely to facilitate an understanding of ways in which the embodiments herein can be practiced and to further enable those skilled in the art to practice the embodiments herein. Accordingly, the examples are not be construed as limiting the scope of the embodiments herein.
[0083] As is traditional in the field, embodiments are described and illustrated in terms of blocks that carry out a described function or functions. These blocks, which referred to herein as managers, units, modules, hardware components or the like, are physically implemented by analog and / or digital circuits such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits and the like, and optionally be driven by firmware and software. The circuits, for example, be embodied in one or more semiconductor chips, or on substrate supports such as printed circuit boards and the like. The circuits constituting a block be implemented by dedicated hardware, or by a processor (e.g., one or more programmed microprocessors and associated circuitry), or by a combination of dedicated hardware to perform some functions of the block and a processor to perform other functions of the block. Each block of the embodiments be physically separated into two or more interacting and discrete blocks without departing from the scope of the proposed method. Likewise, the blocks of the embodiments be physically combined into more complex blocks without departing from the scope of the proposed method.
[0084] The accompanying drawings facilitate understanding of various technical features. The embodiments are not limited by these drawings and extend to any alterations, equivalents, and substitutes. Terms like first, second, etc., are used for distinction and do not limit the elements.
[0085] Various definitions and interpretative provisions used in the present disclosure are set forth below and, unless otherwise indicated, apply throughout the specification. A Visited Public Land Mobile Network (VPLMN) refers to a Public Land Mobile Network (PLMN) that is different from a Home Public Land Mobile Network (HPLMN) when an Equivalent Home PLMN (EHPLMN) list is not present or is empty, or, when the EHPLMN list is present and non-empty, a PLMN that is not included in the EHPLMN list. An “allowable PLMN” refers, in a case of a Mobile Station (MS) operating in MS operation mode A or MS operation mode B, to a PLMN that is not included in a list of forbidden PLMNs stored in the MS, and, in a case of an MS operating in MS operation mode C or an MS not supporting A / Gb mode and not supporting Iu mode, to a PLMN that is not included in the list of forbidden PLMNs and not included in a list of forbidden PLMNs for GPRS service stored in the MS. An “available PLMN” refers to one or more PLMNs identified in a given area based on information broadcast by one or more cells (e.g., broadcast system information indicating PLMN identity) from which a UE can attempt to obtain wireless communication service.
[0086] “Camped on a cell” refers to a state in which the MS, or mobile equipment (ME) when no Subscriber Identity Module (SIM) is present, has completed a cell selection or reselection process and has selected a cell on which it intends to monitor for service and from which it may attempt to receive available services. Such services may be limited, and the PLMN or a Standalone Non-Public Network (SNPN) may not be aware of the existence of the MS or ME within the selected cell. An Equivalent Home PLMN (EHPLMN) refers to any PLMN identity contained in an Equivalent Home PLMN list. An “Equivalent Home PLMN list” refers to a list of PLMN identities stored on a Universal Subscriber Identification Module (USIM), wherein PLMN identities in the list are treated as equivalent to the HPLMN identity derived from an International Mobile Subscriber Identity (IMSI) for PLMN selection purposes and may replace the HPLMN identity derived from the IMSI. The EHPLMN list may include the HPLMN identity derived from the IMSI; if the HPLMN identity derived from the IMSI is not included in the EHPLMN list, then, for PLMN selection purposes, the HPLMN identity derived from the IMSI is treated as a visited PLMN. A “Home PLMN (HPLMN)” refers to a PLMN for which a Mobile Country Code (MCC) and a Mobile Network Code (MNC) of the PLMN identity match the MCC and MNC of the IMSI.
[0087] A Registered PLMN (RPLMN) refers to the PLMN on which a location registration outcome, also referred to as a registration procedure outcome, has occurred such that the MS / UE is regarded as registered on that PLMN; in a shared network, the RPLMN is defined by the PLMN identity of a core network (CN) operator that accepted the location registration. “Registration” refers to a process by which the UE becomes registered with a PLMN or an SNPN and, in one example, includes camping on a cell and performing one or more required registration-related procedures, including one or more location registrations and / or NAS registration signaling as applicable to the relevant system. A User Controlled PLMN (UPLMN) refers to a PLMN and access-technology combination listed, in priority order, in a User Controlled PLMN Selector with Access Technology data file stored in a SIM / USIM. An Operator Controlled PLMN (OPLMN) refers to a PLMN and access-technology combination listed, in priority order, in an Operator Controlled PLMN Selector with Access Technology data file stored in a SIM / USIM and / or stored, in priority order, in the ME.
[0088] A “serving satellite” refers to a satellite that provides satellite access to a UE and, in a case of a non-geostationary orbit (NGSO) satellite system, the serving satellite changes over time due to relative movement between the UE and satellites in a constellation. “Store-and-Forward (S&F) satellite operation” refers to an operation mode of a 5G system with satellite access in which the system provides a level of service by storing data and forwarding the stored data when connectivity to a ground segment (e.g., via a feeder link) is intermittently or temporarily unavailable, including scenarios in which control-plane and / or user-plane messages are buffered and delivered when the feeder link becomes available. An “S&F data retention period” refers to a data storage validity period in S&F satellite operation after which undelivered stored data is discarded or otherwise invalidated. “UE-satellite-UE communication” refers to communication, in a 5G system with satellite access, between UEs under coverage of one or more serving satellites using satellite access without routing through a ground segment. “S&F mode” refers to a mode in which the UE, radio access network (RAN), and one or more core network entities perform Store-and-Forward satellite operation, including applying procedures and parameter settings that account for delayed delivery and intermittent feeder-link availability.
[0089] As used herein, “NAS messages” refers to Non-Access Stratum signaling messages, and examples include, but are not limited to, Registration Request, Deregistration Request, Service Request, Control Plane Service Request, Identity Request, Authentication Request, Authentication Result, Authentication Reject, Registration Reject, Registration Accept, Deregistration Accept, Service Reject, Service Accept, UE Configuration Update, and UE Parameters Update.
[0090] As used herein, “Radio Access Technology (RAT)” refers to a radio access technology used for network access, including but not limited to NG-RAN / NR, E-UTRA / LTE, NB-IoT, WB-IoT, LTE-M, and satellite-access variants thereof (e.g., NR satellite access in LEO / MEO / GEO or other satellite configurations). As used herein, the term “5GS registration type” refers to a registration type in a 5G System (5GS), including initial registration, mobility registration updating, periodic registration updating, emergency registration, SNPN onboarding registration, disaster roaming initial registration, and disaster roaming mobility registration updating, and a “non-disaster 5GS registration type” refers to a 5GS registration type other than disaster roaming initial registration and disaster roaming mobility registration updating.
[0091] Unless expressly limited, the embodiments are described using 5G Core Network functions (e.g., AMF) and NR / NG-RAN access as examples, and the disclosed principles are also applicable to other access technologies and core network architectures, including E-UTRAN / EPC, by replacing corresponding entities (e.g., AMF with MME, gNB with eNB, and UDM with HSS) while maintaining the same underlying principles. The messages and procedures described herein are provided as illustrative examples, and the disclosure is not limited to the specific message names or entity names used in the examples. As used herein, an “area” may refer to a cell or cell identifier, a Tracking Area Code (TAC) or Tracking Area Identity (TAI), a PLMN, an MCC / MNC, a Closed Access Group (CAG) cell / identifier, geographic coordinates, or another geographic designation depending on the applicable system. References to “discontinuous coverage,” “DisCo,” or related terms are intended to cover intermittent connectivity conditions including feeder-link unavailability in satellite systems, and the terms “camp” and “register” may be used interchangeably in the embodiments where the context indicates a combined access-and-registration state for obtaining service.
[0092] Top of Form
[0093] Bottom of Form
[0094] FIG. 1A illustrates a schematic diagram of the normal / default satellite operation mode according to prior art. The normal / default satellite operation mode is depicted in FIG. 1A, where the S&F satellite operation in a 5G system with satellite access is configured to provide communication service to UEs (102) under satellite coverage. This configuration supports delay-tolerant communication even when satellite connectivity is intermittent or temporarily unavailable, such as when the satellite (101) is not connected to the external network or IoT service endpoint (104) via a feeder link or inter-satellite link.
[0095] In the normal / default satellite operation mode, as illustrated in FIG. 1A, the UE (102) communicates with the satellite (101) over a service link while the satellite (101) maintains simultaneous connectivity with the ground network (103) via a feeder link. In this mode, signaling and data traffic exchanged between the UE (102) and the network occur in real-time, ensuring a continuous end-to-end connectivity path between the UE (102), the satellite (101), and the ground network (103). Both the service link and the feeder link are active concurrently, with no storage or delay-tolerant handling of data performed. Communication is only possible when the satellite (101) is connected to both the UE (102) and the external network / IoT service endpoint (104), ensuring uninterrupted end-to-end data exchange.
[0096] FIG. 1B illustrates a schematic diagram of the Store & Forward (S&F) satellite operation mode according to prior art. Under the S&F satellite operation mode, as shown in FIG. 1B, the end-to-end exchange of signaling and data traffic is performed in a combination of two steps that are not concurrent in time (step A (101a) and step B (101b) in FIG. 1B). In step A, signaling and / or data exchange between the UE (102) and the satellite (101) occurs without the satellite (101) being simultaneously connected to the ground network (103), meaning the satellite (101) operates the service link without an active feeder link connection. In step B, connectivity between the satellite (101) and the ground network (103) is established to enable the satellite to forward the stored signaling and / or data to the ground network. Consequently, the satellite transitions from being connected to the UE (102) in step A to being connected to the ground network in step B.
[0097] The concept of S&F service is widely used in delay-tolerant networking and disruption-tolerant networking. In a 3GPP context, a service equivalent to the S&F service is SMS, where end-to-end connectivity between end-points is not required; instead, connectivity is only required between each end-point and the SMSC, which stores and relays the messages. The support of S&F satellite operation is particularly suitable for delivering delay-tolerant and non-real-time IoT satellite services using NGSO satellites.
[0098] The MME functionality is split into two parts: MME-onboard, which is the MME part onboard the satellite, and MME-ground. When the UE (102) initiates an Attach or TAU procedure, it indicates support for S&F mode to the MME in accordance with existing NAS capability. If the procedure cannot be completed due to S&F operation, the MME sends an Attach or TAU Reject message to the UE (102). This message includes: a) information indicating that the attach or TAU procedure cannot be completed due to S&F operation and that the UE (102) may re-attempt the attach or TAU in this PLMN in the next satellite pass, thereby indicating that the information contained in the Attach or TAU Request message is stored by the MME and the network will be available after interaction with the ground network; b) a wait timer indicating the time the UE (102) should wait before re-attempting the Attach or TAU procedure in the current or another satellite of the same PLMN; and c) optionally, a list of Satellite IDs over which the UE (102) may re-attempt the Attach or TAU procedure after the wait timer expires, wherein the Satellite IDs are based on SIB information broadcasted by the eNB.
[0099] During the wait timer, the UE (102) may search for another terrestrial or satellite PLMN to obtain normal service. If the UE (102) receives a non-integrity protected reject message from the network and is not configured to use T3245, the UE (102) shall start a timer T3247 with a value randomly drawn between 30 minutes to 60 minutes and maintain a counter for SIM / USIM considered invalid for non-GPRS services or SIM / USIM considered invalid for GPRS services with an MS implementation-specific maximum value.
[0100] Further, upon expiry of timer T3247, the MS shall:
[0101] - erase the list of "forbidden location areas for regional provision of service" and the list of "forbidden location areas for roaming";
[0102] - set the SIM / USIM to valid for non-GPRS services, if
[0103] - the MS does not maintain a counter for "SIM / USIM considered invalid for non-GPRS services" events; or
[0104] - the MS maintains a counter for "SIM / USIM considered invalid for non-GPRS services" events and this counter has a value less than an MS implementation-specific maximum value.
[0105] - set the SIM / USIM to valid for GPRS services, if
[0106] - the MS does not maintain a counter for "SIM / USIM considered invalid for GPRS services" events; or
[0107] - the MS maintains a counter for "SIM / USIM considered invalid for GPRS services" events and this counter has a value less than an MS implementation-specific maximum value.
[0108] - erase the list of "forbidden location areas for non-GPRS services" and the list of "forbidden location areas for GPRS services", if the MS maintains these lists;
[0109] - if the MS maintains a list of PLMN-specific attempt counters, for each PLMN-specific attempt counter that has a value greater than zero and less than an MS implementation-specific maximum value, remove the respective PLMN from the extension of the "forbidden PLMNs" list; and
[0110] - if the MS maintains a list of PLMN-specific PS-attempt counters, for each PLMN-specific PS-attempt counter that has a value greater than zero and less than an MS implementation-specific maximum value, remove the respective PLMN from the "forbidden PLMNs for GPRS service" list. If the resulting "forbidden PLMNs for GPRS service" list is empty and the MS is supporting S1 mode, the MS re-enables the E-UTRA capability as specified in 3GPP TS 24.301
[0120] for the case when timer T3247 expires.
[0111] FIG. 1C illustrates a sequence diagram showing a scenario where the first satellite ID (105) and the second satellite ID (106) store different NAS COUNT values, causing abnormal behavior at the UE (102) or network according to prior art. Each EPS security context may be associated with two separate counters, NAS COUNT, one for uplink NAS messages and one for downlink NAS messages. The NAS COUNT counters may use a 24-bit internal representation and are independently maintained by the UE (102) and the MME. The NAS COUNT may be constructed as a NAS sequence number (8 least significant bits) concatenated with a NAS overflow counter (16 most significant bits).
[0112] When the NAS COUNT is input to NAS ciphering or NAS integrity algorithms, it may be considered as a 32-bit entity constructed by padding the 24-bit internal representation with 8 zeros in the most significant bits. The value of the uplink NAS COUNT stored or read from the USIM or non-volatile memory may be used in the next NAS message. Similarly, the value of the downlink NAS COUNT stored or read from the USIM or non-volatile memory may correspond to the largest downlink NAS COUNT used in a successfully integrity-checked NAS message. The value of the uplink NAS COUNT stored in the MME may correspond to the largest uplink NAS COUNT used in a successfully integrity-checked NAS message, and the value of the downlink NAS COUNT stored in the MME may be used in the next NAS message.
[0113] The NAS sequence number portion of the NAS COUNT may be exchanged between the UE (102) and the MME as part of NAS signaling. After each new or retransmitted outbound security-protected NAS message, the sender may increment the NAS COUNT by one, except for initial NAS messages when lower layers indicate failure to establish the RRC connection. On the sender side, the NAS sequence number may be increased by one, and if the result is zero due to wrap-around, the NAS overflow counter may also be incremented by one. On the receiving side, the NAS COUNT used by the sender may be estimated, and if the NAS sequence number wraps around, the NAS overflow counter may also be incremented by one.
[0114] The UE (102) or MME may increment the NAS COUNT by one after successfully transmitting NAS messages in the uplink or downlink. In the Store and Forward Satellite operation in a 4G or 5G system with satellite access, the UE (102) may communicate with different MMEs onboard different satellites (101) and, as a result, may use different NAS COUNT values. If the UE (102) receives a downlink NAS message with a NAS COUNT value lower than that of a previously received NAS message, the UE (102) may discard the downlink NAS message, which is unexpected and may lead to abnormal behavior.
[0115] At step S1, the UE (102) initiates an initial Attach procedure or TAU procedure and transmits an attach request or TAU request to the MME onboard the satellite, for example, first satellite ID (105), via an available service link. At step S2, the MME onboard the satellite initiates a security procedure by performing an AKA procedure, for example, by transmitting a DL NAS message of Security Mode Command. At step S3, the UE (102) establishes the Security Context and transmits a UL NAS message, for example, Security Mode Accept. At step S4, the UE (102) and MME reset the UL and the DL NAS counts to zero (0) and store the counts independently.
[0116] At steps S5-S8, the UE (102) and MME onboard the satellite exchange additional NAS messages and increment the respective UL and the DL NAS counts at each entity independently. At step S9, due to the movement of the satellite, the UE moves out of the coverage of the first satellite ID (105) and comes under the coverage of the second satellite ID (106). At step S10, the UE (102) initiates a UL NAS message, for example, a Service Request message, TAU Request, or PDN Connectivity Request message. At step S11, the MME onboard the satellite (for example, second satellite ID (106)) transmits the DL NAS message, for example, Service Accept message, TAU Accept, or ESM message (for example, ActivateDefault EPS Bearer Context Request) using the previously stored DL NAS count in the UE context.
[0117] In the existing system, the first satellite ID (105) and second satellite ID (106) store different DL NAS counts. When the second satellite ID (106) transmits a DL NAS message with a DL NAS count lower than the DL NAS count stored at the UE (102), the UE (102) discards the message, resulting in abnormal behavior at the UE (102) or in the network.
[0118] To overcome the disadvantages of the existing system, there is a need for a method for handling NAS count and security context for store-and-forward operations in a non-terrestrial network. The UE (102) stores and manages a plurality of security contexts corresponding to different satellites (101), selects a security context based on the satellite currently serving the UE (102), and activates the selected security context for securing NAS message exchanges.
[0119] FIG. 2A is a block diagram illustrating a user equipment (UE) (102) configured to handle a NAS count and a NAS security context for store-and-forward operation in a non-terrestrial network (NTN), according to one or more embodiments disclosed herein.
[0120] Examples of the UE (102) include, but are not limited to, a mobile phone, a smartphone, a tablet, a wearable device, a computing device, an Internet-of-Things (IoT) device, a vehicle platform supporting V2X communications, a public safety device, a medical device, and other equipment capable of performing NAS procedures and exchanging NAS messages.
[0121] In the context of the present disclosure, the non-terrestrial network (NTN) includes a satellite-based access network and associated ground segment, wherein the UE (102) is served via one or more satellites and may experience intermittent or discontinuous connectivity between a serving satellite and the ground network, including store-and-forward operation. The NTN may be integrated with a 3GPP system (e.g., EPC / EPS and / or 5GS), such that NAS procedures are performed between the UE and one or more core network entities via the satellite-based access.
[0122] The UE (102) includes a processor (201), a memory (203), an input / output (I / O) interface (202), and a NAS security context controller (204). The processor (201) is operatively coupled to the memory (203), the I / O interface (202), and the NAS security context controller (204), and is configured to execute instructions stored in the memory (203) to perform one or more processes disclosed herein. The processor (201) may include one or more processing units, such as a central processing unit (CPU), an application processor (AP), and / or other processors.
[0123] The memory (203) includes one or more computer-readable storage media addressable by the processor (201) and stores information used for NAS security processing. In an embodiment, the memory (203) stores a plurality of security contexts associated with respective satellite identifiers, and each security context includes at least one of an uplink NAS count and a downlink NAS count, a key set identifier (KSI), integrity and ciphering algorithm identifiers, integrity and ciphering key material, and one or more NAS-related keys applicable to an EPC / EPS system and / or a 5GS system. The memory (203) stores and maintains the plurality of security contexts independently for different satellite identifiers, thereby enabling the UE (102) to maintain separate NAS counts and security parameters when the serving satellite changes and / or when store-and-forward operation affects NAS message delivery timing.
[0124] The I / O interface (202) is configured to provide communication between internal components of the UE (102) and one or more external or peripheral components, and may further provide an interface to one or more radio / modem components for transmission and reception of control-plane signaling including NAS messages.
[0125] The NAS security context controller (204) is coupled to the processor (201) and the memory (203) and is implemented as a dedicated integrated circuit, a secure processing module, or a microcontroller-based circuit within the UE (102). The NAS security context controller (204) is configured to manage security contexts on a per-satellite basis for store-and-forward operation, including receiving or obtaining a satellite identifier associated with a serving satellite, selecting a corresponding security context from among the plurality of stored security contexts, applying the selected security context to protect NAS message exchanges, and updating at least the uplink NAS count and the downlink NAS count responsive to successful NAS message transmission and reception. The NAS security context controller (204) is further configured to detect a change in a serving satellite and to switch to a different stored security context corresponding to the new serving satellite and / or to initialize a new security context for the new serving satellite, while maintaining the NAS counts independently for different satellite identifiers to support replay protection and continuity of NAS security procedures under intermittent connectivity conditions.
[0126] Further, the NAS security context controller (204) receives the broadcast information from the network apparatus. The broadcast information includes the satellite identifier identifying a satellite currently serving the UE (102) from among a plurality of satellites in the non-terrestrial network. The broadcasting is performed by the RAN node (e.g., eNB or gNB) onboard the satellite, and the broadcast information includes the satellite identifier (satellite ID). Further, the NAS security context controller (204) stores the plurality of security contexts associated with a respective satellite identifier. Each security context includes the pair of the uplink NAS count and a downlink NAS count. The pair of the uplink NAS count and the downlink NAS count of each security context in the plurality of security contexts are stored independently from other pairs of uplink NAS count and downlink NAS count of other security contexts in the plurality of security contexts. The NAS security context controller (204) selects, based on the received satellite identifier, the security context from the plurality of security contexts stored at the UE (102). The selected security context corresponds to the satellite identifier of the satellite currently serving the UE (102). Further, the NAS security context controller (204) activates the selected security context for securing NAS message exchanges associated with the satellite identifier.
[0127] Further, the NAS security context controller (204) initializes the pair of the uplink NAS count and the downlink NAS count in the selected security context to a predefined initial value. Further, the NAS security context controller (204) exchanges the plurality of NAS messages using the pair of the uplink NAS count and the downlink NAS count of the selected security context. Further, the NAS security context controller (204) increments the pair of the uplink NAS count and the downlink NAS count in the selected security context after the successful exchange of the plurality of NAS messages. The pair of the incremented uplink NAS count and the incremented downlink NAS count is stored independently per satellite identifier for the satellite currently serving the UE (102) and is not synchronized with the pair of the uplink NAS count and downlink NAS count associated with other satellites.
[0128] Further, the NAS security context controller (204) detects the change in the satellite currently serving the UE (102) from the first satellite having the first satellite identifier (also referred to as satellite ID 1 (105)) to a second satellite having a second satellite identifier (also referred to as satellite ID 2 (106)). Further, the NAS security context controller (204) selects by the UE (102) the second security context associated with the second satellite identifier. Further, the NAS security context controller (204) initializes the pair of a second uplink NAS count or a second downlink NAS count independently of NAS count associated with the first satellite identifier.
[0129] Further, the NAS security context controller (204) maintains each security context such that the security context includes at least one of a key set identifier (KSI), an integrity and ciphering algorithm identifier, an integrity key context, a ciphering key context, a KASME key, an EPS NAS ciphering key, DL NAS count, UL NAS COUNTor an EPS NAS integrity key. Each security context is stored independently for a corresponding satellite identifier, thereby enabling the UE (102) to accept downlink NAS messages associated with different downlink NAS counts.
[0130] Further, the NAS security context controller (204) receives a downlink NAS message including a received downlink NAS count. Further, the NAS security context controller (204) compares the received downlink NAS count with an expected downlink NAS count stored in the selected security context. Further, the NAS security context controller (204) accepts or rejects the downlink NAS message based on the comparison to prevent replay attacks.
[0131] Further, the NAS security context controller (204) initializes the pair of the uplink NAS count and the downlink NAS count, including resetting the uplink NAS count and the downlink NAS count to zero when the selected security context is activated for the first time or when the UE (102) moves from one satellite ID to another, thereby maintaining separate security contexts for each satellite ID and storing them independently.
[0132] Further, the NAS security context controller (204) determines the satellite identifier based on System Information Block (SIB) information broadcast by the network apparatus i.e. the RAN node like eNB or gNB or NG-RAN.
[0133] FIG. 2B is a block diagram that illustrates the Mobility Management Entity (MME) for handling NAS count and security context for store-and-forward operations in a non-terrestrial network.
[0134] The MME includes various hardware and software components that facilitate mobility management, session management, and security functions in the non-terrestrial network. Examples of the MME may include, but are not limited to, Mobility Management Entity servers with multi-core processors and dedicated memory for managing user authentication, tracking area updates, and bearer management, Security Gateway modules with cryptographic processors for handling Authentication and Key Agreement (AKA) procedures and generating security keys (KASME, K'ASME), core control-plane database units with integrated storage for storing and managing UE contexts, NAS security contexts, and mobility states across multiple satellite connections, Hardware Security Modules (HSM) with tamper-resistant storage for securely maintaining encryption keys, integrity keys, key set identifiers (KSI), and NAS count values per satellite ID, and Core Network Control Plane servers with real-time operating systems for processing NAS signaling messages, managing attach procedures, tracking area updates, and coordinating handovers between satellites in store-and-forward operations.
[0135] The MME (205) includes the processor (206), the memory (208), an I / O interface (207) and a NAS security context controller (209). The processor (206) of the MME (205) communicates with the memory (208), the I / O interface (207) and the NAS security context controller (209). The processor (206) is configured to execute instructions stored in the memory (208) and to perform various processes. The processor (206) may include one or a plurality of processors, and may be a general-purpose processor, such as a central processing unit (CPU), an application processor (AP), or the like, wherein the processor (206) executes control-plane instructions for NAS signaling handling, security mode control, and mobility management procedures under store-and-forward operation.
[0136] Further, the memory (208) of the MME (205) includes storage locations to be addressable through the processor (206). The memory (208) is not limited to a volatile memory and / or a non-volatile memory. Further, the memory (208) may include one or more computer-readable storage media. The memory (208) may include non-volatile storage elements. For example, non-volatile storage elements may include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. In the present disclosure, the memory (208) stores a plurality of security contexts associated with respective satellite identifiers of a plurality of satellites in the non-terrestrial network, where each security context includes at least one of a pair of uplink NAS count and downlink NAS count, key set identifier (KSI), integrity and ciphering algorithms, integrity and ciphering key context, KASME or K'ASME, EPS NAS ciphering key, and EPS NAS integrity key. The memory (208) stores and maintains said security contexts independently per satellite ID, thereby enabling the MME (205) to manage separate NAS counts and security parameters for each UE (102) accessing different satellites in the non-terrestrial network and to perform independent security procedures for store-and-forward operations, including maintaining independent uplink / downlink NAS count continuity per satellite identifier to support replay protection when NAS message delivery is delayed or reordered in store-and-forward operation.
[0137] Replay protection must assure that one and the same NAS message is not accepted twice by the receiver. Specifically, for a given EPS security context, a given NAS COUNT value shall be accepted at most one time and only if message integrity verifies correctly.
[0138] The I / O interface (207) transmits the information between the memory (208) and external peripheral devices. The peripheral devices are the input-output devices associated with the MME (205). The I / O interface (207) receives several information from the MME (205). In an embodiment, the I / O interface (207) includes one or more network interface controllers and protocol interface modules configured to exchange control-plane signaling and context information with satellite-based and ground-based network entities for store-and-forward operation.
[0139] The NAS security context controller (209) is coupled to the memory (208) and the processor (206). This coupling allows for efficient data transfer and communication between the components, ensuring that the NAS security context controller (209) may access and process NAS security context data in real time. The NAS security context controller (209) is an innovative integrated circuit that is implemented in the MME (205). In an embodiment, the structure of such innovative integrated circuit includes a multi-core architecture that enables dynamic management and processing of NAS security contexts for store-and-forward operations in a non-terrestrial network. Each core is optimized for specific tasks, such as obtaining satellite identifier information associated with a serving satellite and / or a store-and-forward path, storing a plurality of security contexts associated with respective satellite identifiers, selecting a security context based on the satellite identifier associated with the satellite on which the MME (205) is located, activating the selected security context for securing NAS message exchanges, incrementing the pair of uplink NAS count and downlink NAS count after successfully exchanging NAS messages with the UE (102), verifying received uplink NAS counts against expected uplink NAS counts, and initiating security procedures by transmitting Security Mode Command messages to establish independent security contexts per satellite. The innovative integrated circuit for handling NAS count and security context for store-and-forward operations is composed of a combination of analog and digital components designed to optimize security context management accuracy and processing precision. The analog components include a high-precision clock and timing reference circuit to ensure accurate NAS message exchange timing and security context synchronization across satellite handovers, while the digital components include a microcontroller unit (MCU) and a digital signal processor (DSP) that work in tandem to dynamically store and manage multiple independent security contexts per satellite ID, process NAS count increments and verifications, authenticate received uplink NAS messages to prevent replay attacks, reset downlink NAS counts for security mode procedures, and manage security context activation based on UE mobility between different satellites, wherein the NAS security context controller (209) further includes a secure key storage circuit and a hardware-assisted cryptographic processing circuit configured to protect the integrity and confidentiality of stored key material and to accelerate integrity / ciphering processing for NAS messages associated with the selected security context.
[0140] Further, the NAS security context controller (209) stores the plurality of security contexts associated with a respective satellite identifier of the plurality of satellites in the non-terrestrial network. Each security context includes a pair of an uplink NAS count and a downlink NAS count. The pair of the uplink NAS count and the downlink NAS count of each security context in the plurality of security contexts are stored independently from other pairs of uplink NAS count and downlink NAS count of other security contexts of the plurality of security contexts. The NAS security context controller (209) selects the security context from the plurality of security contexts based on the satellite identifier associated with the satellite on which the MME (205) is located. The NAS security context controller (209) activates the selected security context for securing NAS message exchanges associated with the satellite identifier.
[0141] Further, the NAS security context controller (209) initializes the pair of the uplink NAS count or the downlink NAS count in the selected security context to a predefined initial value. Further, the NAS security context controller (209) exchanges the plurality of NAS messages using the pair of the uplink NAS count and the downlink NAS count of the selected security context. Further, the NAS security context controller (209) increments by the MME (205) a pair of the uplink NAS count and the downlink NAS count in the selected security context after successfully exchanging the plurality of NAS messages. The pair of the incremented uplink NAS count and the incremented downlink NAS count is stored separately per satellite identifier and is not synchronized with the pair of the uplink NAS count and the downlink NAS count associated with other satellite identifiers.
[0142] Further, the NAS security context controller (209) ensures each security context includes at least one of a key set identifier (KSI), integrity and ciphering technique, an integrity key context, a ciphering key context, a KASME key, an EPS NAS ciphering key, or an EPS NAS integrity key, each stored independently per satellite identifier.
[0143] Further, the NAS security context controller (209) receives the uplink NAS message including a received uplink NAS count. Further, the NAS security context controller (209) verifies the received uplink NAS count against an expected uplink NAS count from the pair of uplink NAS count and downlink NAS count stored in the selected security context. Further, the NAS security context controller (209) updates the uplink NAS count based on successful verification.
[0144] Further, the NAS security context controller (209) initiates a security procedure by transmitting a security mode command message. Further, the NAS security context controller (209) resets at least the downlink NAS count from the pair of uplink NAS count and downlink NAS count of the selected security context to zero for integrity protection of a security mode command message. The resetting is performed when the UE (102) moves from one satellite ID to another, thereby maintaining separate security contexts for each satellite ID and storing them independently.
[0145] Further, the NAS security context controller (209) obtains the satellite identifier broadcast by the MME (205) within a System Information Block (SIB).
[0146] FIG. 3A is a flowchart illustrating a method of handling NAS count and security context for store-and-forward operations in the non-terrestrial network according to embodiments disclosed herein. At step 301, the method includes receiving the broadcast information from the network apparatus. The broadcast information includes the satellite identifier identifying the satellite currently serving the UE (102) from among a plurality of satellites in the non-terrestrial network.
[0147] At step 302, the method includes storing, by the UE (102), the plurality of security contexts associated with a respective satellite identifier. Each security context includes a pair of the uplink NAS count and the downlink NAS count. The pair of the uplink NAS count and the downlink NAS count of each security context in the plurality of security contexts are stored independently from other pairs of uplink NAS count and downlink NAS count of other security contexts in the plurality of security contexts.
[0148] At step 303, the method includes selecting, by the UE (102), based on the received satellite identifier, a security context from the plurality of security contexts stored at the UE (102). The selected security context corresponds to the satellite identifier of the satellite currently serving the UE (102).
[0149] At step 304, the method includes activating, by the UE (102), the selected security context for securing NAS message exchanges associated with the satellite identifier.
[0150] FIG. 3B is a flowchart illustrating a method of handling NAS count and security context for store-and-forward operations in the non-terrestrial network according to embodiments disclosed herein. At step 305, the method includes storing, by the MME (205), the plurality of security contexts associated with the respective satellite identifier of the plurality of satellites in the non-terrestrial network. Each security context includes a pair of the uplink NAS count and the downlink NAS count. The pair of the uplink NAS count and the downlink NAS count of each security context in the plurality of security contexts are stored independently from other pairs of uplink NAS count and downlink NAS count of other security contexts in the plurality of security contexts.
[0151] At step 306, the method includes selecting, by the MME (205), the security context from the plurality of security contexts based on the satellite identifier associated with the satellite on which the MME (205) is located.
[0152] At step 307, the method includes activating, by the MME (205), the selected security context for securing NAS message exchanges associated with the satellite identifier.
[0153] FIG. 4 is a sequence diagram illustrating a scenario in which the UE (102) stores and uses UL NAS COUNT and DL NAS COUNT, as well as UE Security Context, per satellite ID according to the disclosed embodiments.
[0154] At step S1, the UE (102) initiates an initial attach procedure or TAU procedure and transmits an Attach request or TAU request to the MME (205) on-board the satellite (e.g., the first satellite ID (105)) via an available service link.
[0155] In step S2, the MME (205) on-board the first satellite ID (105) initiates a security procedure by performing an Authentication and Key Agreement (AKA) procedure, for example, by transmitting the downlink NAS message including a security mode command to the UE (102). The security Mode Command is marked with "X," indicating no feeder link to the ground network (103).
[0156] At step S3, the UE (102) establishes the security context and transmits the uplink NAS message (for example, Security Mode Accept) to the MME (205) on-board the first satellite ID (105).
[0157] During step S4, the UE (102) resets the NAS count and uses a fresh NAS count. Both the UL NAS COUNT and the DL NAS COUNT at the UE (102) are reset to zero (0), updated, and stored independently per satellite identifier.
[0158] From steps S5 through S8, the UE (102) and the MME (205) on-board the first satellite ID (105) exchange a plurality of NAS messages and increment respective UL and DL NAS counts at each entity independently. The exchanged messages include downlink NAS messages (e.g., Attach Accept or Tracking Area Update Accept) and uplink NAS messages (e.g., Service Request Msg or PDN connectivity request Msg), where the UL NAS COUNT and the DL NAS COUNT at the UE (102) are updated and incremented after each successful message exchange with the MME (205) on-board the first satellite ID (105).
[0159] At step S9, due to the movements of the satellites, the first satellite ID (105) moves away from the coverage area, and the UE (102) is now being served by the second satellite ID (106).
[0160] In step S10, the UE (102) initiates the uplink NAS message, for example, a Service Request Msg, TAU Request, or PDN connectivity request Msg, and transmits said message to the MME (205) on-board the second satellite ID (106).
[0161] At step S11, the MME (205) on-board the second satellite ID (106) transmits a downlink NAS message, for example, a Service Accept Msg, TAU Accept, or ESM Msg (e.g., Activate Default EPS Bearer Context Request) to the UE (102) using the previously stored DL NAS count in the UE (102) context.
[0162] Furthermore, at step S12, the UE (102) stores and uses the UL NAS COUNT and the DL NAS COUNT along with the UE (102) security context per satellite ID. The UE (102) security context includes, for example, a key set identifier (KSI), integrity and ciphering algorithms, integrity and ciphering key context, KASME or K"ASME, EPS NAS ciphering key, and EPS NAS integrity key, each stored independently per satellite ID. Reference may be made to TS 24501, TS 24301, or TS 33401 for a complete list of security context parameters. Accordingly, the UE (102) may accept the downlink NAS messages with different DL NAS counts from different satellites.
[0163] FIG. 5 illustrates a sequence diagram depicting a scenario in which the UE (102) maintains and stores independent NAS security contexts per satellite according to embodiments disclosed herein. In this scenario, the UE (102) maintains and stores two or more independent NAS security contexts for each satellite using respective UL NAS COUNT, DL NAS COUNT, encryption and integrity algorithms, and ciphering and integrity keys while accessing the satellites.
[0164] At step S1, the UE (102) initiates the initial Attach procedure or TAU procedure and transmits an Attach request or TAU request to the MME (205) on-board the satellite (e.g., first satellite ID (105)) via an available service link. The attach request or TAU request includes a support indication for S&F satellite access.
[0165] The MME on-board first satellite ID (105) initiates the security procedure at step S2 by performing an Authentication and Key Agreement (AKA) procedure, for example, by transmitting the downlink NAS message including a security mode command to the UE (102).
[0166] At step S3, the UE (102) establishes the security context and transmits the uplink NAS message, such as a Security Mode Accept, to the MME (205) on-board first satellite ID (105).
[0167] The UE (102) resets the NAS count and uses a fresh NAS count at step S4. Both the UL NAS COUNT and the DL NAS COUNT at the UE (102) are reset to zero (0) and stored in the UE (102) for this satellite.
[0168] At step S5, the MME (205) on-board first satellite ID (105) transmits the downlink NAS message, such as an Attach Accept or TAU Accept, to the UE (102). The downlink NAS message includes an S&F Monitor list, which removes second satellite ID (106).
[0169] Upon receiving the updated S&F Monitor list and identifying that second satellite ID (106) is removed from the S&F Monitor list, the UE (102) resets all the security context stored for second satellite ID (106) at step S6. This includes resetting UL / DL NAS COUNT (to zero or a pre-agreed value), security algorithms such as integrity and ciphering algorithms and keys, and Key Set Identifier (KSI) values, and deleting said security context from the stored location of the UE (102), for example, from memory or from a Universal Subscriber Identity Module (USIM) file.
[0170] Due to movements of the satellites, the first satellite ID (105) moves away from the coverage area at step S7, and the UE (102) is now being served by second satellite ID (106).
[0171] When the UE (102) accesses second satellite ID (106) for the first time at step S8, it uses the latest security context or a NULL security context.
[0172] The MME (205) on-board second satellite ID (106) initiates a separate and independent security procedure at step S9 by transmitting the security mode command to the UE (102) to establish and maintain the separate and independent security context for each satellite (101).
[0173] At step S10, the UE (102) transmits the uplink NAS message, such as a security mode accept message, to the MME (205) on-board second satellite ID (106) to complete the AKA procedure.
[0174] The UE (102) resets the NAS count and uses a fresh NAS count at step S11, storing said NAS count in the UE (102) for second satellite ID (106). This may be an independent security context from the security context for first satellite ID (105). Thus, the UE (102) and the network (e.g., MME (205) on-board satellites) maintain and store two or more independent NAS security contexts for each of the satellites and use the respective UL NAS COUNT, DL NAS COUNT, encryption and integrity algorithms, and ciphering and integrity keys while accessing the respective satellites.
[0175] In an embodiment, the term UE (102) Security Context refers to at least one of the NAS counts, i.e., downlink NAS count or uplink NAS count, key set identifier (KSI), integrity and ciphering algorithms, integrity and ciphering key context, KASME or K"ASME, EPS NAS ciphering key, and EPS NAS integrity key. For a complete list of security context parameters, refer to TS 24501, TS 24301, or TS 33401.
[0176] In another embodiment, the UE (102) Security Context is stored per satellite ID. This implies that at least one of the parameters of the UE (102) Security Context is stored, maintained, and managed per satellite ID by the UE (102) and the core network element, such as the MME (205) on-board satellites.
[0177] Furthermore, the MME (205) shall reset the downlink NAS COUNT counter and use it to integrity protect the initial SECURITY MODE COMMAND message if the security mode control procedure is initiated from the MME (205) in a new satellite (i.e., for a different satellite ID), resetting the downlink NAS COUNT counter value to zero.
[0178] In an embodiment, the network system includes hardware devices such as the UE (102), the Satellite (MME on-board), and the ground network (MME ground) (103). These hardware devices include a memory, a processor, a communicator, and an innovative hardware controller for handling NAS COUNT and EMM Security Context (as described above in FIG. 3 and FIG. 4).
[0179] FIG. 6 is a block diagram of a terminal or user equipment (UE) 600 according to an embodiment of the disclosure.
[0180] The terminal is an electronic device capable of wireless communication and having various form factors, examples of the terminal may include a UE, a mobile station (MS), a cellular phone, a smartphone, a computer, a tablet, a wearable device, an Internet of Things (IoT) device, or any other device / system capable of performing wireless communication with a base station (BS) and / or another terminal through a wireless channel.
[0181] Referring to FIG. 6, the UE 600 may include at least one transceiver (hereinafter, referred to as simply “transceiver”) 601, at least one processor (hereinafter, referred to as simply “processor”) 602, and at least one memory (hereinafter, referred to as simply “memory”) 603. According to at least one or a combination of methods corresponding to the embodiments described in the present disclosure, the transceiver 601, the processor 602, and the memory 603 of the UE 600 may operate. However, components of the UE 600 are not limited to the example components illustrated in FIG. 6. In another embodiment, the UE 600 may further include additional components in addition to the above-mentioned components, or some components may be omitted. Further, in some embodiments, any combination of the transceiver 601, the processor 602, or the memory 603 may be integrated in the form of one component.
[0182] The transceiver 601 may be a communication circuit or communication circuitry that enables the UE 600 to perform wireless communication with a node or an entity of a network. For example, the transceiver 601 may enable the UE 600 to transmit or receive a signal to or from a BS through cellular communication, or to transmit or receive a signal to or from another UE through cellular communication. For example, the transceiver 601 may support at least one of various cellular communication technologies including 3rd generation (3G), 4th generation (4G), long term evolution (LTE), 5th generation (5G) NR, 6th generation (6G), and various cellular wireless communication technologies supported by the transceiver (601) may include all subsequent generations of evolved wireless communications.
[0183] According to an embodiment, the UE 600 may include a plurality of transceivers. For example, in the case of supporting evolved-universal terrestrial radio access-new radio (E-UTRA-NR) dual connectivity (EN-DC), the UE 600 may include a first transceiver supporting the 4G LTE wireless communication and a second transceiver supporting the 5G NR wireless communication. According to another embodiment, in the case of supporting NR-dual connectivity (NR-DC), the UE 600 may include a plurality of transceivers supporting the 5G NR wireless communication. According to still another embodiment, in the case of supporting near field wireless communication, the UE 600 may separately include a transceiver supporting at least one standard in the group of wireless communication protocol standards as defined in the protocol standards for Bluetooth®, wireless local area network (WLAN) network (including institute of electrical and electronics engineers (IEEE) 802.11-2016 standard or its amendments, e.g., 802.11ah, 802.11ad, 802.11ay, 802.11ax, 802.11az, 802.11ba, and 802.11be, without being limited thereto).
[0184] According to an embodiment, the transceiver 601 may include various circuit structures used to transmit or receive signals to or from a BS through a wireless channel. The signals may include control information and data. For example, the transceiver 601 may include a radio frequency (RF) transmitter for up-converting and amplifying the frequency of a transmitted signal and an RF receiver for low-noise-amplifying a received signal and down-converting the frequency thereof. The transceiver 601 may output a signal received through a wireless channel to the processor 602 and may transmit, through a wireless channel, a signal output from the processor 602.
[0185] The processor 602 may control general operations of the UE 600 according to embodiments of the disclosure. The processor 602 may be implemented by one or more integrated circuit (or circuitry) (IC) chips and may execute various data processing operations. The processor 602 may include at least one electric circuit, and may execute instructions (or a program, codes, data, etc.) stored in the memory 603, individually, collectively or in any combination thereof. Further, the processor 602 may include a single-core processor or multi-core processor, and may include a processor assembly including a plurality of processing circuits (circuitry) according to a specific implementation scheme.
[0186] The processor 602 may be electrically, operatively, and / or communicatively coupled to the transceiver 601 to control the transceiver 601.
[0187] The processor 602 may include at least one processor (or processing circuitry), and the at least one processor may perform the following operations individually, collectively or in any combination thereof. For example, the processor 602 may include a communication processor (CP) configured to control communication operations and an application processor (AP) configured to control execution of an upper layer (for example, an application layer). In a specific embodiment, at least a part of the processor 602 may be included in one chip (or IC) and the other part of the processor 602 may be included in another chip (or IC). Otherwise, at least one processor may be included in another component, for example, the transceiver 601 or the memory 603.
[0188] The processor 602 may perform or control or cause an operation of the UE 600 for executing at least one or a combination of methods according to embodiments of the disclosure. For example, the processor 602 may control operations of the UE 600 for processing a downlink signal received from a BS or generating and transmitting an uplink signal to a BS. To this end, the processor 602 may execute a computer program, codes, or instructions stored in the memory 603, so as to control other components of the UE 600 to enable execution of various operations.
[0189] The memory 603 corresponds to a hardware storage device capable of temporarily or permanently storing information and may include one or more storage media. For example, the memory 603 may include a memory assembly including one or more storage media. For example, the one or more storage media may include permanent memory, such as a hard drive, flash memory, or read-only memory (ROM), semipermanent memory, such as random access memory (RAM), cache memory, or a combination thereof.
[0190] The memory 603 may be electrically, operatively, and / or communicatively coupled to the processor 602 and may be accessed by the processor 602.
[0191] The memory 603 may store a computer program, codes, or instructions executable by the processor 602. According to an embodiment, a computer program, codes, or instructions executable by the processor 602 may be either stored in a single memory device or separated and distributedly stored in two or more memory devices. By executing the instructions stored in the memory 603, the processor 602 may perform various functions according to an embodiment of the disclosure.
[0192] According to an embodiment of the disclosure, operations of the UE 600 may be caused to be performed based on execution of instructions (or a computer program or codes) stored in the memory 603 by at least one processor (or processing circuitry) configured to execute the same individually, collectively, or in any combination thereof, based on processing circuitry that is not configured to execute instructions, and / or based on components of processing circuitry that is not configured to execute instructions.
[0193] FIG. 7 is a block diagram of a base station (BS) 700 according to an embodiment of the disclosure.
[0194] The BS 700 may perform wireless communication with at least one user equipment (UE) located within the area of the BS 700 through a wireless channel. The BS 700 may perform communication with a node or an entity of a network through wired or wireless communication.
[0195] Referring to FIG. 7, the BS 700 may include at least one transceiver (hereinafter, referred to as simply “transceiver”) 701, at least one processor (hereinafter, referred to as simply “processor”) 702, and at least one memory (hereinafter, referred to as simply “memory”) 703. According to at least one or a combination of methods corresponding to the embodiments described in the present disclosure, the transceiver 701, the processor 702, and the memory 703 of the BS 700 may operate. However, components of the BS 700 are not limited to the example components illustrated in FIG. 7. In another embodiment, the BS 700 may further include additional components in addition to the above-mentioned components, or some components may be omitted. Further, in some embodiments, any combination of the transceiver 701, the processor 702, or the memory 703 may be integrated in the form of one component.
[0196] The transceiver 701 may be a communication circuit or communication circuitry that enables the BS 700 to perform wireless communication with a node or an entity of a network. For example, the transceiver 701 may enable the BS 700 to transmit or receive a signal to or from the UE 600 through cellular communication, or to transmit or receive a signal to or from another network entity through wireless communication. For example, the transceiver 701 may support various cellular communication technologies including 3rd generation (3G), 4th generation (4G), long term evolution (LTE), 5th generation (5G) NR, 6th generation (6G), and various cellular wireless communication technologies supported by the transceiver (701) may include all subsequent generations of evolved wireless communications.. According to an embodiment, the transceiver 701 may include various circuit structures used to transmit or receive signals to or from a UE through a wireless channel. The signals may include control information and data. For example, the transceiver 701 may include a radio frequency (RF) transmitter for up-converting and amplifying the frequency of a transmitted signal and an RF receiver for low-noise-amplifying a received signal and down-converting the frequency thereof. The transceiver 701 may output a signal received through a wireless channel to the processor 702 and may transmit, through a wireless channel, a signal output from the processor 702.
[0197] Meanwhile, according to an embodiment of the present disclosure, the BS 700 may perform communication with a node or an entity of a network through wired or wireless communication. For example, the BS 700 may perform wired or wireless communication with an adjacent BS, or a node or an entity of a core network through a backhaul network. Although not illustrated in FIG. 7, when the BS 700 performs wired communication, the BS 700 may further include a separate network interface for wired communication in addition to the transceiver 701. The network interface may be referred to as network interface circuitry or communication interface circuitry.
[0198] The processor 702 may control general operations of the BS 700 according to embodiments of the disclosure. The processor 702 may be implemented by one or more integrated circuit (or circuitry) (IC) chips and may execute various data processing operations. The processor 702 may include at least one electric circuit, and may execute instructions (or a program, codes, data, etc.) stored in the memory 703, individually, collectively or in any combination thereof. Further, the processor 702 may include a single-core processor or multi-core processor, and may include a processor assembly including a plurality of processing circuits (circuitry) according to a specific implementation scheme.
[0199] The processor 702 may be electrically, operatively, and / or communicatively coupled to the transceiver 701 to control the transceiver 701.
[0200] The processor 702 may include at least one processor (or processing circuitry), and the at least one processor may perform the following operations individually, collectively or in any combination thereof. In a specific embodiment, at least a part of the processor 702 may be included in one chip (or IC) and the other part of the processor 702 may be included in another chip (or IC). Otherwise, at least one processor may be included in another component, for example, the transceiver 701 or the memory 703.
[0201] The processor 702 may perform or control or cause an operation of the BS 700 for executing at least one or a combination of methods according to embodiments of the disclosure. For example, the processor 702 may control operations of the BS 700 for generating and transmitting a downlink signal to a UE or processing an uplink signal received from a UE. Otherwise, the BS 700 may transmit or receive a signal to or from a neighboring BS, transfer a signal received from a UE to an upper node of the network, or transmit a signal transferred from an upper node of the network to a UE. To this end, the processor 702 may execute a computer program, codes, or instructions stored in the memory 703, so as to control other components of the BS 700 to enable execution of various operations.
[0202] The memory 703 corresponds to a hardware storage device capable of temporarily or permanently storing information and may include one or more storage media. For example, the memory 703 may include a memory assembly including one or more storage media. For example, the one or more storage media may include permanent memory, such as a hard drive, flash memory, or read-only memory (ROM), semipermanent memory, such as random access memory (RAM), cache memory, or a combination thereof.
[0203] The memory 703 may be electrically, operatively, and / or communicatively coupled to the processor 702 and may be accessed by the processor 702.
[0204] The memory 703 may store a computer program, codes, or instructions executable by the processor 702. According to an embodiment, a computer program, codes, or instructions executable by the processor 702 may be either stored in a single memory device or separated and distributedly stored in two or more memory devices. By executing the instructions stored in the memory 703, the processor 702 may perform various functions according to an embodiment of the disclosure.
[0205] According to an embodiment of the disclosure, operations of the BS 700 may be caused to be performed based on execution of instructions (or a computer program or codes) stored in the memory 703 by at least one processor (or processing circuitry) configured to execute the same individually, collectively, or in any combination thereof, based on processing circuitry that is not configured to execute instructions, and / or based on components of processing circuitry that is not configured to execute instructions.
[0206] The UE or the base station may perform various communication procedures related to the control plane or the user plane by cooperating with one or more network entities based on wireless communication. For example, the UE may communicate with a network entity (for example, an Access and Mobility Management Function (AMF), a Session Management Function (SMF), rtc.) via the base station, or the base station may perform at least one communication procedure by directly transmitting and receiving signals to / from, or relaying signals between, the network entities.
[0207] The structure of the above-described network entity will be described in more detail with reference to the drawings.
[0208] FIG. 8 is a block diagram of a network entity 800 according to an embodiment of the disclosure.
[0209] The network entity 800 may include an entity (apparatus, device, or server, etc.) that performs one or more network functions (NFs) or a part of a network function constituting a core network (e.g., a 5th generation (5G) core (5GC)) in a communication system. In this case, multiple NFs may be implemented within a single network entity, or a single NF may be distributed and implemented across a plurality of network entities. In addition, when an NF is implemented within the network entity, the NF may be implemented in the form of software, and in such a case, a program for operating the NF may be stored in memory of the network entity 800.
[0210] A single NF may be implemented by one or more instances, which may be deployed on the same network entity or distributed across multiple network entities to operate. The instance may be a software unit that logically executes a specific network function, and may be implemented in a form that is decoupled from physical hardware resources. Further, one or more NFs may be implemented in the form of one network slice to operate to satisfy specifications required by a particular service.
[0211] The NF may include at least one of an access and mobility management function (AMF), a session management function (SMF), a local session management function (L-SMF), a user plane function (UPF), a local user plane function (L-UPF), a policy control function (PCF), a unified data management (UDM), a unified data repository (UDR), a network exposure function (NEF), a network repository function (NRF), an application function (AF), a network slice selection function (NSSF), a network data analytics function (NWDAF), a network slice admission control function (NSACF), an authentication server function (AUSF), or a data network (DN), etc.
[0212] Referring to FIG. 8, the network entity 800 may include at least one network interface 801, at least one processor 802 (hereinafter, “processor”), and at least one memory 803 (hereinafter, “memory”). As described above, a NF may be implemented in the form of a physical device such as the network entity 800, or may be virtualized and executed in the form of an instance. When implemented as an instance, the NF need not necessarily include physical components as illustrated in FIG. 8. In such a case, the instance may be logically represented as comprising one or more logical functional elements.
[0213] According to at least one or a combination of methods corresponding to the embodiments described in the present disclosure, the network interface 801, the processor 802, and the memory 803 of the network entity 800 may operate. However, components of the network entity 800 are not limited to the example components illustrated in FIG. 8. In another embodiment, the network entity 800 may further include additional components in addition to the above-mentioned components, or some components may be omitted. Further, in an embodiment, the network interface 801, the processor 802, or the memory 803 may be integrated in the form of one component.
[0214] The network interface 801 is a collective term for a transmitter part of the network entity 800 and a receiver part of the network entity 800, and may be a communication circuit for transmitting or receiving a signal to or from a user equipment (UE), a base station (BS), or another network entity. Here, the communication circuit may include both a communication circuit for wireless communication and a communication circuit for a wired communication. For example, the network interface 801 may include a circuit, logic, hardware, etc., configured to exchange a control plane message or a user plane message with a UE, a BS, or other core network entities through wireless communication or wired communication. The network interface 801 may operate using various protocols (e.g., non-access stratum (NAS) protocol). The network interface 801 may also be referred to, for convenience of description or depending on implementation, as communication circuitry, network interface circuitry, or a communication interface circuitry.
[0215] The processor 802 may control general operations of the network entity 800 according to embodiments of the disclosure. The processor 802 may be implemented by one or more integrated circuit (or circuitry) (IC) chips and may execute various data processing operations. The processor 802 may include at least one electric circuit, and may execute instructions (or a program, codes, data, etc.) stored in the memory 803, individually, collectively or in any combination thereof. Further, the processor 802 may include a single-core processor or multi-core processor, and may include a processor assembly including a plurality of processing circuits (circuitry) according to a specific implementation scheme. Further, it should be noted that, according to another embodiment, in a case where NF is implemented in the form of an instance, the network function may be not necessarily configured by physical hardware.
[0216] According to an embodiment, the processor 802 may be electrically, operatively, and / or communicatively coupled to the network interface 801 to control the network interface 801.
[0217] The processor 802 may include at least one processor (or processing circuitry), and the at least one processor may perform the following operations individually, collectively or in any combination thereof. In a specific embodiment, at least a part of the processor 802 may be included in one chip (or IC) and the other part of the processor 802 may be included in another chip (or IC). Otherwise, at least one processor may be included in another component, for example, the network interface 801 or the memory 803.
[0218] The processor 802 may perform or control or cause an operation of the network entity 800 for executing at least one or a combination of methods according to embodiments of the disclosure. For example, the processor 802 may control operations of the network entity 800 for exchanging a control plane message or a user plane message with a UE, a BS, or other core network entities through wireless or wired communication, using various protocols (e.g., NAS protocol). To this end, the processor 802 may execute a computer program, codes, or instructions stored in the memory 803, so as to control other components of the network entity 800 to enable execution of various operations.
[0219] The memory 803 corresponds to a hardware storage device capable of temporarily or permanently storing information and may include one or more storage media. For example, the memory 803 may include a memory assembly including one or more storage media. For example, the one or more storage media may include permanent memory, such as a hard drive, flash memory, or read-only memory (ROM), semipermanent memory, such as random access memory (RAM), cache memory, or a combination thereof.
[0220] The memory 803 may be electrically, operatively, and / or communicatively coupled to the processor 802 and may be accessed by the processor 802.
[0221] The memory 803 may store a computer program, codes, or instructions executable by the processor 802. According to an embodiment, a computer program, codes, or instructions executable by the processor 802 may be either stored in a single memory device or separated and distributedly stored in two or more memory devices. By executing the instructions stored in the memory 803, the processor 802 may perform various functions according to an embodiment of the disclosure.
[0222] According to an embodiment of the disclosure, operations of the network entity 800 may be caused to be performed based on execution of instructions (or a computer program or codes) stored in the memory 803 by at least one processor (or processing circuitry) configured to execute the same individually, collectively, or in any combination thereof, based on processing circuitry that is not configured to execute instructions, and / or based on components of processing circuitry that is not configured to execute instructions.
[0223] In various embodiments, a method of handling Non-Access Stratum (NAS) count and security context for store-and-forward operations in a non-terrestrial network, comprising: receiving, by a User Equipment (UE) (102), a broadcast information from a network apparatus, wherein the broadcast information comprises a satellite identifier identifying a satellite currently serving the UE (102) from among a plurality of satellites in the non-terrestrial network; storing, by the UE (102), a plurality of security contexts associated with a respective satellite identifier, wherein each security context comprises a pair of an uplink NAS count and a downlink NAS count , wherein the pair of the uplink NAS count and the downlink NAS count of each security context plurality of security contexts are stored independently from other pair of uplink NAS count and downlink NAS count of other security contexts of the plurality of security contexts; selecting, by the UE (102) based on the received satellite identifier, a security context from the plurality of security contexts stored at the UE (102), wherein the selected security context corresponds to the satellite identifier of the satellite currently serving the UE (102); and activating, by the UE (102), the selected security context for securing NAS message exchanges associated with the satellite identifier.
[0224] In various embodiments, the method further comprising: initializing, by the UE (102), the pair of the uplink NAS count and the downlink NAS count in the selected security context to a predefined initial value; exchanging, by the UE (102) with the MME (205), a plurality of NAS messages using the pair of the uplink NAS count and the downlink NAS count of the selected security context; and incrementing, by the UE (102), the pair of the uplink NAS count and the downlink NAS count in the selected security context after successfully exchange of the plurality of NAS messages, wherein the pair of the incremented uplink NAS count and the incremented downlink NAS count is stored independently per satellite identifier for the satellite currently serving the UE (102) and is not synchronized with the pair of the uplink NAS count and downlink NAS count associated with other satellites.
[0225] In various embodiments, the network apparatus is a RAN node comprising at least one of an eNB, a gNB, and an NG-RAN node.
[0226] In various embodiments, the method further comprising: detecting, by the UE (102), a change in the satellite currently serving the UE (102) from a first satellite having a first satellite identifier to a second satellite having a second satellite identifier; selecting, by the UE (102), a second security context associated with the second satellite identifier; and initializing, by the UE (102), a pair of a second uplink NAS count or a second downlink NAS count independently of NAS count is associated with the first satellite identifier.
[0227] In various embodiments, each security context comprises at least one of a key set identifier (KSI), integrity and ciphering technique, an integrity key context, a ciphering key context, a KASME key, an EPS NAS ciphering key, or an EPS NAS integrity key, each stored independently per satellite identifier enabling the UE (102) to accept DL NAS messages with different DL NAS counts.
[0228] In various embodiments, the method further comprising: receiving, by the UE (102), a downlink NAS message comprising a received downlink NAS count; comparing, by the UE (102), the received downlink NAS count with an expected downlink NAS count stored in the selected security context; and accepting or rejecting, by the UE (102), the downlink NAS message based on the comparison to prevent replay attacks.
[0229] In various embodiments, initializing the pair of the uplink NAS count and the downlink NAS count comprises resetting the uplink NAS count and the downlink NAS count to zero when the selected security context is activated for a first time or when the UE (102) moves from one satellite ID to another, thereby maintaining separate security contexts for each satellite ID and storing them independently.
[0230] In various embodiments, the satellite identifier is based on System Information Block (SIB) broadcasted by the network apparatus.
[0231] In various embodiments, a method of handling Non-Access Stratum (NAS) count and security context for store-and-forward operations in a non-terrestrial network, comprising: storing, by the Mobility Management Entity (MME), a plurality of security contexts associated with a respective satellite identifier of a plurality of satellites in the non-terrestrial network, and wherein each security context comprises a pair of an uplink NAS count and a downlink NAS count, wherein the pair of the uplink NAS count and the downlink NAS count of each security context plurality of security contexts are stored independently from other pair of uplink NAS count and downlink NAS count of other security contexts of the plurality of security contexts; selecting, by the MME (205), a security context from the plurality of security contexts based on the satellite identifier associated with the satellite on which the MME (205) is located; and activating, by the MME (205), the selected security context for securing NAS message exchanges associated with the satellite identifier.
[0232] In various embodiments, the method further comprising: initializing, by the MME (205), the pair of the uplink NAS count or the downlink NAS count in the selected security context to a predefined initial value; exchanging, by the MME (205) with the UE (102), a plurality of NAS messages using the pair of the uplink NAS count and the downlink NAS count of the selected security context; and incrementing, by the MME (205) , a pair of the uplink NAS count and the downlink NAS count in the selected security context after successfully exchanging the plurality of NAS messages, wherein the pair of the incremented uplink NAS count and the incremented downlink NAS count is stored separately per satellite identifier and is not synchronized with the pair of the uplink NAS count and the downlink NAS count associated with other satellite identifiers.
[0233] In various embodiments, each security context comprises at least one of a key set identifier (KSI), integrity and ciphering technique, an integrity key context, a ciphering key context, a KASME key, an EPS NAS ciphering key, or an EPS NAS integrity key, each stored independently per satellite identifier.
[0234] In various embodiments, the method further comprising: receiving, by the MME (205), an uplink NAS message comprising a received uplink NAS count; verifying, by the MME (205), the received uplink NAS count against an expected uplink NAS count from the pair of uplink NAS count and downlink NAS count stored in the selected security context; and updating, by the MME (205), the uplink NAS count based on successful verification.
[0235] In various embodiments, the method further comprising: initiating, by the MME (205), a security procedure by transmitting a security mode command message; and resetting, by the MME (205), at least the downlink NAS count from the pair of uplink NAS count and downlink NAS count of the selected security context to zero for integrity protection of a security mode command message, wherein the resetting is performed when the UE (102) moves from one satellite ID to another, thereby maintaining separate security contexts for each satellite ID and storing them independently.
[0236] In various embodiments, the satellite identifier is broadcast by the MME (205) within a System Information Block (SIB).
[0237] In various embodiments, a User Equipment (UE) for handling Non-Access Stratum (NAS) count and security context for store-and-forward operations in a non-terrestrial network, comprising: a memory (203); a processor (201); and a NAS security context controller (204) coupled to the memory (203) and the processor (201), wherein the NAS security context controller (204): receive a broadcast information from a network apparatus, wherein the broadcast information comprises a satellite identifier identifying a satellite currently serving the UE (102) from among a plurality of satellites in the non-terrestrial network; store a plurality of security contexts associated with a respective satellite identifier, wherein each security context comprises a pair of an uplink NAS count and a downlink NAS count, wherein the pair of the uplink NAS count and the downlink NAS count of each security context plurality of security contexts are stored independently from other pair of uplink NAS count and downlink NAS count of other security contexts of the plurality of security contexts; select a security context from the plurality of security contexts stored at the UE (102), wherein the selected security context corresponds to the satellite identifier of the satellite currently serving the UE (102); and activate the selected security context for securing NAS message exchanges associated with the satellite identifier.
[0238] In various embodiments, a Mobility Management Entity (MME) (205) for handling Non-Access Stratum (NAS) count and security context for store-and-forward operations in a non-terrestrial network, comprising: a memory (208); a processor (206); and a NAS security context controller coupled to the memory (208) and the processor (206), wherein the NAS security context controller (209): store a plurality of security contexts associated with a respective satellite identifier of a plurality of satellites in the non-terrestrial network, and wherein each security context comprises a pair of an uplink NAS count and a downlink NAS count, wherein the pair of the uplink NAS count and the downlink NAS count of each security context plurality of security contexts are stored independently from other pair of uplink NAS count and downlink NAS count of other security contexts of the plurality of security contexts; select a security context from the plurality of security contexts based on the satellite identifier associated with the satellite on which the MME (205) is located; and activate the selected security context for securing NAS message exchanges associated with the satellite identifier.
[0239] The foregoing description of the specific embodiments will so fully reveal the general nature of the embodiments herein that others can, by applying current knowledge, readily modify and / or adapt for various applications such specific embodiments without departing from the generic concept, and, therefore, such adaptations and modifications should and are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Therefore, while the embodiments herein have been described in terms of preferred embodiments, those skilled in the art will recognize that the embodiments herein can be practiced with modification within the scope of the embodiments as described herein.
[0240] Meanwhile, although specific embodiments of the present disclosure have been described in detail, various modifications may be made without departing from the scope of the present disclosure. Therefore, the scope of the present disclosure should not be limited to the described embodiments, but should be defined by the claims and equivalents thereof.
Claims
1.A method performed by a user equipment (UE) in a wireless communication system, the method comprising:maintaining at least one pair of non access stratum (NAS) counts associated with a respective satellite identifier;receiving, from a network entity, a broadcast information including a satellite identifier of a satellite currently serving the UE in the non-terrestrial network; andactivating a pair of NAS counts associated with the received satellite identifier,wherein the pair of NAS counts includes an uplink NAS count and a downlink NAS count.2.The method of claim 1, wherein the pair of the uplink NAS count and the downlink NAS count is stored independently from other pair of an uplink NAS count and a downlink NAS count.3.The method of claim 1, wherein the maintaining of the at least one pair of NAS counts associated with a respective satellite identifier includes:storing the at least one pair of NAS counts associated with a respective satellite identifier.4.The method of claim 1, further comprising:selecting, based on the received satellite identifier, the pair of NAS counts,wherein the pair of NAS counts corresponds to the satellite identifier of the satellite currently serving the UE (102).5.The method of claim 1, further comprising:setting the uplink NAS count and the downlink NAS count to be zero.6.A method performed by a network entity in a wireless communication system, the method comprising:transmitting, to a user equipment (UE), a broadcast information including a satellite identifier of a satellite currently serving the UE in the non-terrestrial network; andinteracting to the UE based on using a pair of NAS counts associated with the satellite identifier,wherein at least one pair of NAS counts associated with a respective satellite identifier are maintained, andwherein the pair of NAS counts includes an uplink NAS count and a downlink NAS count.7.The method of claim 6, wherein the pair of the uplink NAS count and the downlink NAS count are stored independently from other pair of an uplink NAS count and a downlink NAS count.8.The method of claim 6, further comprising:setting the uplink NAS count and the downlink NAS count to be zero.9.A user equipment (UE) comprising:at least one transceiver;at least one processor communicatively coupled to the at least one transceiver; andat least one memory, communicatively coupled to the at least one processor, storing instructions executable by the at least one processor individually or in any combination to cause the UE to:maintain at least one pair of NAS counts associated with a respective satellite identifier;receive, from a network entity, a broadcast information including a satellite identifier of a satellite currently serving the UE in the non-terrestrial network; andactivate a pair of NAS counts associated with the received satellite identifier,wherein the pair of NAS counts includes an uplink NAS count and a downlink NAS count.10.The UE of claim 9, wherein the pair of the uplink NAS count and the downlink NAS count is stored independently from other pair of an uplink NAS count and a downlink NAS count.11.The UE of claim 9, wherein the instructions further cause the UE to:storing the at least one pair of NAS counts associated with a respective satellite identifier.12.The UE of claim 9, wherein the instructions further cause the UE to:select, based on the received satellite identifier, the pair of NAS counts,wherein the pair of NAS counts corresponds to the satellite identifier of the satellite currently serving the UE (102), andwherein the uplink NAS count and the downlink NAS count are set to be zero.13.A network entity comprising:at least one transceiver;at least one processor communicatively coupled to the at least one transceiver; andat least one memory, communicatively coupled to the at least one processor, storing instructions executable by the at least one processor individually or in any combination to cause the network entity to:transmit, to a user equipment (UE), a broadcast information including a satellite identifier of a satellite currently serving the UE in the non-terrestrial network; andinteract to the UE based on using a pair of NAS counts associated with the satellite identifier,wherein at least one pair of NAS counts associated with a respective satellite identifier are maintained, andwherein the pair of NAS counts includes an uplink NAS count and a downlink NAS count.14.The network entity of claim 13, wherein a pair of the uplink NAS count and the downlink NAS count are stored independently from other pair of an uplink NAS count and a downlink NAS count.15.The network entity of claim 13, wherein the instructions further cause the network entity to:set the uplink NAS count and the downlink NAS count to be zero.