Service management for devices

WO2026198867A1PCT designated stage Publication Date: 2026-09-24CHUN SUNGDUCK +12
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/US2026/020078
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-21
Filing Date
2026-03-20
Publication Date
2026-09-24

Smart Images

  • Figure US2026020078_24092026_PF_FP_ABST
    Figure US2026020078_24092026_PF_FP_ABST
Patent Text Reader

Abstract

A method includes sending, by a wireless device to a network node, a first message indicating that the wireless device supports an ambient internet of things (AIoT) wireless device reader operation. The method also includes receiving, by the wireless device, from an AIoT device, an AIoT message. The method also includes sending, by the wireless device to the network node, a message. The message includes a type indicator indicating whether the message includes the AIoT message. The message also includes a container including the AIoT message.
Need to check novelty before this filing date? Find Prior Art

Description

Docket No.: 25-1063PCTTITLEService Management for DevicesCROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This application claims the benefit of U.S. Provisional Application No.63 / 775,603, filed March 21, 2025, which is hereby incorporated by reference in its entirety.BRIEF DESCRIPTION OF THE DRAWINGS

[0002] Examples of several of the various embodiments of the present disclosure are described herein with reference to the drawings.

[0003] FIG. 1 A and FIG. 1 B illustrate example communication networks including an access network and a core network.

[0004] FIG. 2A, FIG. 2B, FIG. 2C, and FIG.2D illustrate various examples of a framework for a service-based architecture within a core network.

[0005] FIG. 3 illustrates an example communication network including core network functions.

[0006] FIG. 4A and FIG. 4B illustrate example of core network architecture with multiple user plane functions and untrusted access.

[0007] FIG. 5 illustrates an example of a core network architecture for a roaming scenario.

[0008] FIG. 6 illustrates an example of network slicing.

[0009] FIG. 7A, FIG. 7B, and FIG. 7C illustrate a user plane protocol stack, a control plane protocol stack, and services provided between protocol layers of the user plane protocol stack.

[0010] FIG. 8 illustrates an example of a quality of service model for data exchange

[0011] FIG. 9A, FIG. 9B, FIG. 9C, and FIG.9D illustrate example states and state transitions of a wireless device.

[0012] FIG. 10 illustrates an example of a registration procedure for a wireless device.

[0013] FIG. 11 illustrates an example of a service request procedure for a wireless device.

[0014] FIG. 12 illustrates an example of a protocol data unit session establishment procedure for a wireless device.

[0015] FIG. 13 illustrates examples of components of the elements in a communications network.

[0016] FIG. 14A, FIG. 14B, FIG. 14C, and FIG. 14D illustrate various examples of physical core network deployments, each having one or more network functions or portions thereof.

[0017] FIG. 15 is a diagram of an aspect of an example embodiment of the present disclosure.

[0018] FIG. 16 is a diagram of an aspect of an example embodiment of the present disclosure.

[0019] FIG. 17 is a diagram of an aspect of an example embodiment of the present disclosure.

[0020] FIG. 18 is a diagram of an aspect of an example embodiment of the present disclosure.

[0021] FIG. 19A, FIG. 19B, FIG. 19C, FIG. 19D, and FIG. 19E are diagrams of an aspect of an example embodiment of the present disclosure.Docket No.: 25-1063PCT

[0022] FIG. 20 is a diagram of an aspect of an example embodiment of the present disclosure.

[0023] FIG. 21Aand FIG. 21 B are diagrams of an aspect of an example embodiment of the present disclosure.

[0024] FIG. 22 is a diagram of an aspect of an example embodiment of the present disclosure.

[0025] FIG. 23 is a diagram of an aspect of an example embodiment of the present disclosure.

[0026] FIG. 24 is a diagram of an aspect of an example embodiment of the present disclosure.

[0027] FIG. 25 is a diagrams of an aspect of an example embodiment of the present disclosure.

[0028] FIG. 26 is a diagram of an aspect of an example embodiment of the present disclosure.

[0029] FIG. 27 is a diagram of an aspect of an example embodiment of the present disclosure.

[0030] FIG. 28 is a diagram of an aspect of an example embodiment of the present disclosure.

[0031] FIG. 29 is a diagram of an aspect of an example embodiment of the present disclosure.

[0032] FIG. 30 is a diagram of an aspect of an example embodiment of the present disclosure.

[0033] FIG. 31 is a diagram of an aspect of an example embodiment of the present disclosure.

[0034] FIG. 32 is a diagram of an aspect of an example embodiment of the present disclosure.

[0035] FIG. 33 is a diagram of an aspect of an example embodiment of the present disclosure.

[0036] FIG. 34 is a diagram of an aspect of an example embodiment of the present disclosure.DETAILED DESCRIPTION

[0037] In the present disclosure, various embodiments are presented as examples of how the disclosed techniques may be implemented and / or how the disclosed techniques may be practiced in environments and scenarios. It will be apparent to persons skilled in the relevant art that various changes in form and detail can be made therein without departing from the scope. In fact, after reading the description, it will be apparent to one skilled in the relevant art how to implement alternative embodiments. The present embodiments should not be limited by any of the described exemplary embodiments. The embodiments of the present disclosure will be described with reference to the accompanying drawings. Limitations, features, and / or elements from the disclosed example embodiments may be combined to create further embodiments within the scope of the disclosure. Any figures which highlight the functionality and advantages are presented for example purposes only. The disclosed architecture is sufficiently flexible and configurable, such that it may be utilized in ways other than that shown. For example, the actions listed in any flowchart may be re-ordered or only optionally used in some embodiments.

[0038] Embodiments may be configured to operate as needed. The disclosed mechanism may be performed when certain criteria are met, for example, in a wireless device, a base station, a radio environment, a network, a combination of the above, and / or the like. Example criteria may be based, at least in part, on for example, wireless device or network node configurations, traffic load, initial system set up, packet sizes, traffic characteristics, a combination of the above, and / or the like. When the one or more criteria are met, various example embodiments may be applied. Therefore, it may be possible to implement example embodiments that selectively implement disclosed protocols.

[0039] A base station may communicate with a mix of wireless devices. Wireless devices and / or base stationsDocket No.: 25-1063PCTmay support multiple technologies, and / or multiple releases of the same technology. Wireless devices may have one or more specific capabilities. When this disclosure refers to a base station communicating with a plurality of wireless devices, this disclosure may refer to a subset of the total wireless devices in a coverage area. This disclosure may refer to, for example, a plurality of wireless devices of a given LTE or 5G release with a given capability and in a given sector of the base station. The plurality of wireless devices in this disclosure may refer to a selected plurality of wireless devices, and / or a subset of total wireless devices in a coverage area which perform according to disclosed methods, and / or the like. There may be a plurality of base stations or a plurality of wireless devices in a coverage area that may not comply with the disclosed methods, for example, those wireless devices or base stations may perform based on older releases of LTE or 5G technology.

[0040] In this disclosure, “a” and “an” and similar phrases refer to a single instance of a particular element, but should not be interpreted to exclude other instances of that element. For example, a bicycle with two wheels may be described as having “a wheel”. Any term that ends with the suffix “(s)” is to be interpreted as “at least one” and / or “one or more.” In this disclosure, the term “may” is to be interpreted as “may, for example.” In other words, the term “may” is indicative that the phrase following the term “may” is an example of one of a multitude of suitable possibilities that may, or may not, be employed by one or more of the various embodiments. The terms "comprises” and “consists of”, as used herein, enumerate one or more components of the element being described. The term “comprises” is interchangeable with “includes” and does not exclude unenumerated components from being included in the element being described. By contrast, “consists of” provides a complete enumeration of the one or more components of the element being described.

[0041] The phrases “based on”, “in response to”, “depending on”, “employing”, “using”, and similar phrases indicate the presence and / or influence of a particular factor and / or condition on an event and / or action, but do not exclude unenumerated factors and / or conditions from also being present and / or influencing the event and / or action. For example, if action X is performed “based on” condition Y, this is to be interpreted as the action being performed “based at least on” condition Y. For example, if the performance of action X is performed when conditions Y and Z are both satisfied, then the performing of action X may be described as being “based on Y”.

[0042] The term “configured" may relate to the capacity of a device whether the device is in an operational or non-operational state. Configured may refer to specific settings in a device that affect the operational characteristics of the device whether the device is in an operational or non-operational state. In other words, the hardware, software, firmware, registers, memory values, and / or the like may be “configured” within a device, whether the device is in an operational or nonoperational state, to provide the device with specific characteristics. Terms such as “a control message to cause in a device” may mean that a control message has parameters that may be used to configure specific characteristics or may be used to implement certain actions in the device, whether the device is in an operational or non-operational state.

[0043] In this disclosure, a parameter may comprise one or more information objects, and an information object may comprise one or more other objects. For example, if parameter J comprises parameter K, and parameter KDocket No.: 25-1063PCTcomprises parameter L, and parameter L comprises parameter M, then J comprises L, and J comprises M. A parameter may be referred to as a field or information element. In an example embodiment, when one or more messages comprise a plurality of parameters, it implies that a parameter in the plurality of parameters is in at least one of the one or more messages, but does not have to be in each of the one or more messages.

[0044] This disclosure may refer to possible combinations of enumerated elements. For the sake of brevity and legibility, the present disclosure does not explicitly recite each and every permutation that may be obtained by choosing from a set of optional features. The present disclosure is to be interpreted as explicitly disclosing all such permutations. For example, the seven possible combinations of enumerated elements A, B, C consist of: (1) "A”; (2) “B”; (3) “C”; (4) “A and B”; (5) “A and C”; (6) “B and C”; and (7) “A, B, and C”. For the sake of brevity and legibility, these seven possible combinations may be described using any of the following interchangeable formulations: "at least one of A, B, and C”; “at least one of A, B, or C”; “one or more of A, B, and C”; “one or more of A, B, or C"; “A, B, and / or C”. It will be understood that impossible combinations are excluded. For example, “X and / or not-X” should be interpreted as “X or not-X". It will be further understood that these formulations may describe alternative phrasings of overlapping and / or synonymous concepts, for example, “identifier, identification, and / or ID number”.

[0045] This disclosure may refer to sets and / or subsets. As an example, set X may be a set of elements comprising one or more elements. If every element of X is also an element of Y, then X may be referred to as a subset of Y. In this disclosure, only non-empty sets and subsets are considered. For example, if Y consists of the elements Y1, Y2, and Y3, then the possible subsets of Y are {Y1, Y2, Y3}, {Y1, Y2}, {Y1, Y3}, {Y2, Y3}, {Y1 }, {Y2}, and {Y3}.

[0046] FIG. 1 A illustrates an example of a communication network 100 in which embodiments of the present disclosure may be implemented. The communication network 100 may comprise, for example, a public land mobile network (PLMN) run by a network operator. As illustrated in FIG. 1A, the communication network 100 includes a wireless device 101 , an access network (AN) 102, a core network (CN) 105, and one or more data network (DNs) 108.

[0047] The wireless device 101 may communicate with DNs 108 via AN 102 and CN 105. In the present disclosure, the term wireless device may refer to and encompass any mobile device or fixed (non-mobile) device for which wireless communication is needed or usable. For example, a wireless device may be a telephone, smart phone, tablet, computer, laptop, sensor, meter, wearable device, Internet of Things (loT) device, vehicle roadside unit (RSU), relay node, automobile, unmanned aerial vehicle, urban air mobility, and / or any combination thereof. The term wireless device encompasses other terminology, including user equipment (UE), user terminal (UT), access terminal (AT), mobile station, handset, wireless transmit and receive unit (WTRU), and / or wireless communication device.

[0048] The AN 102 may connect wireless device 101 to CN 105 in any suitable manner. The communication direction from the AN 102 to the wireless device 101 is known as the downlink and the communication directionDocket No.: 25-1063PCTfrom the wireless device 101 to AN 102 is known as the uplink. Downlink transmissions may be separated from uplink transmissions using frequency division duplexing (FDD), time-division duplexing (TDD), and / or some combination of the two duplexing techniques. The AN 102 may connect to wireless device 101 through radio communications over an air interface. An access network that at least partially operates over the air interface may be referred to as a radio access network (RAN). The CN 105 may set up one or more end-to-end connection between wireless device 101 and the one or more DNs 108. The CN 105 may authenticate wireless device 101 and provide charging functionality.

[0049] In the present disclosure, the term base station may refer to and encompass any element of AN 102 that facilitates communication between wireless device 101 and AN 102. Access networks and base stations have many different names and implementations. The base station may be a terrestrial base station fixed to the earth. The base station may be a mobile base station with a moving coverage area. The base station may be in space, for example, on board a satellite. For example, WiFi and other standards may use the term access point. As another example, the Third-Generation Partnership Project (3GPP) has produced specifications for three generations of mobile networks, each of which uses different terminology. Third Generation (3G) and / or Universal Mobile Telecommunications System (UMTS) standards may use the term Node B. 4G, Long Term Evolution (LTE), and / or Evolved Universal Terrestrial Radio Access (E-UTRA) standards may use the term Evolved Node B (eNB).5G and / or New Radio (NR) standards may describe AN 102 as a next-generation radio access network (NG-RAN) and may refer to base stations as Next Generation eNB (ng-eNB) and / or Generation Node B (gNB). Future standards (for example, 6G, 7G, 8G) may use new terminology to refer to the elements which implement the methods described in the present disclosure (e.g., wireless devices, base stations, ANs, CNs, and / or components thereof). A base station may be implemented as a repeater or relay node used to extend the coverage area of a donor node. A repeater node may amplify and rebroadcast a radio signal received from a donor node. A relay node may perform the same / similar functions as a repeater node but may decode the radio signal received from the donor node to remove noise before amplifying and rebroadcasting the radio signal.

[0050] The AN 102 may include one or more base stations, each having one or more coverage areas. The geographical size and / or extent of a coverage area may be defined in terms of a range at which a receiver of AN 102 can successfully receive transmissions from a transmitter (e.g., wireless device 101) operating within the coverage area (and / or vice-versa). The coverage areas may be referred to as sectors or cells (although in some contexts, the term cell refers to the carrier frequency used in a particular coverage area, rather than the coverage area itself). Base stations with large coverage areas may be referred to as macrocell base stations. Other base stations cover smaller areas, for example, to provide coverage in areas with weak macrocell coverage, or to provide additional coverage in areas with high traffic (sometimes referred to as hotspots). Examples of small cell base stations include, in order of decreasing coverage area, microcell base stations, picocell base stations, and femtocell base stations or home base stations. Together, the coverage areas of the base stations may provide radio coverage to wireless device 101 over a wide geographic area to support wireless device mobility.Docket No.: 25-1063PCT

[0051] A base station may include one or more sets of antennas for communicating with the wireless device 101 over the air interface. Each set of antennas may be separately controlled by the base station. Each set of antennas may have a corresponding coverage area. As an example, a base station may include three sets of antennas to respectively control three coverage areas on three different sides of the base station. The entirety of the base station (and its corresponding antennas) may be deployed at a single location. Alternatively, a controller at a central location may control one or more sets of antennas at one or more distributed locations. The controller may be, for example, a baseband processing unit that is part of a centralized or cloud RAN architecture. The baseband processing unit may be either centralized in a pool of baseband processing units or virtualized. A set of antennas at a distributed location may be referred to as a remote radio head (RRH).

[0052] FIG. 1 B illustrates another example communication network 150 in which embodiments of the present disclosure may be implemented. The communication network 150 may comprise, for example, a PLMN run by a network operator. As illustrated in FIG. 1B, communication network 150 includes UEs 151, a next generation radio access network (NG-RAN) 152, a 5G core network (5G-CN) 155, and one or more DNs 158. The NG-RAN 152 includes one or more base stations, illustrated as generation node Bs (g N Bs) 152A and next generation evolved Node Bs (ng eNBs) 152B. The 5G-CN 155 includes one or more network functions (NFs), including control plane functions 155Aand user plane functions 155B. The one or more DNs 158 may comprise public DNs (e.g., the Internet), private DNs, and / or intra-operator DNs. Relative to corresponding components illustrated in FIG. 1A, these components may represent specific implementations and / or terminology.

[0053] The base stations of the NG-RAN 152 may be connected to the UEs 151 via Uu interfaces. The base stations of the NG-RAN 152 may be connected to each other via Xn interfaces The base stations of the NG-RAN 152 may be connected to 5G CN 155 via NG interfaces. The Uu interface may include an air interface. The NG and Xn interfaces may include an air interface, or may consist of direct physical connections and / or indirect connections over an underlying transport network (e.g., an internet protocol (IP) transport network).

[0054] Each of the Uu, Xn, and NG interfaces may be associated with a protocol stack. The protocol stacks may include a user plane (UP) and a control plane (CP). Generally, user plane data may include data pertaining to users of the UEs 151 , for example, internet content downloaded via a web browser application, sensor data uploaded via a tracking application, or email data communicated to or from an email server. Control plane data, by contrast, may comprise signaling and messages that facilitate packaging and routing of user plane data so that it can be exchanged with the DN(s). The NG interface, for example, may be divided into an NG user plane interface (NG-U) and an NG control plane interface (NG-C). The NG-U interface may provide delivery of user plane data between the base stations and the one or more user plane network functions 155B. The NG-C interface may be used for control signaling between the base stations and the one or more control plane network functions 155A. The NG-C interface may provide, for example, NG interface management, UE context management, UE mobility management, transport of NAS messages, paging, PDU session management, and configuration transfer and / or warning message transmission. In some cases, the NG-C interface may support transmission of user data (forDocket No.: 25-1063PCTexample, a small data transmission for an loT device).

[0055] One or more of the base stations of the NG-RAN 152 may be split into a central unit (CU) and one or more distributed units (DUs). A CU may be coupled to one or more DUs via an F1 interface. The CU may handle one or more upper layers in the protocol stack and the DU may handle one or more lower layers in the protocol stack. For example, the CU may handle RRC, PDCP, and SDAP, and the DU may handle RLC, MAC, and PHY. The one or more DUs may be in geographically diverse locations relative to the CU and / or each other. Accordingly, the CU / DU split architecture may permit increased coverage and / or better coordination.

[0056] The gNBs 152A and ng-eNBs 152B may provide different user plane and control plane protocol termination towards the UEs 151. For example, the gNB 154A may provide new radio (NR) protocol terminations over a Uu interface associated with a first protocol stack. The ng-eNBs 152B may provide Evolved UMTS Terrestrial Radio Access (E-UTRA) protocol terminations over a Uu interface associated with a second protocol stack.

[0057] The 5G-CN 155 may authenticate UEs 151, set up end-to-end connections between UEs 151 and the one or more DNs 158, and provide charging functionality. The 5G-CN 155 may be based on a service-based architecture, in which the NFs making up the 5G-CN 155 offer services to each other and to other elements of the communication network 150 via interfaces. The5G-CN 155 may include any number of other NFs and any number of instances of each NF.

[0058] FIG. 2A, FIG. 2B, FIG. 2C, and FIG.2D illustrate various examples of a framework for a service-based architecture within a core network. In a service-based architecture, a service may be sought by a service consumer and provided by a service producer. Prior to obtaining a particular service, an NF may determine where such a service can be obtained. To discover a service, the NF may communicate with a network repository function (NRF). As an example, an NF that provides one or more services may register with a network repository function (NRF). The NRF may store data relating to the one or more services that the NF is prepared to provide to other NFs in the service-based architecture. A consumer NF may query the NRF to discover a producer NF (for example, by obtaining from the NRF a list of NF instances that provide a particular service).

[0059] In the example of FIG. 2A, an NF 211 (a consumer NF in this example) may send a request 221 to an NF 212 (a producer NF). The request 221 may be a request for a particular service and may be sent based on a discovery that NF 212 is a producer of that service. The request 221 may comprise data relating to NF 211 and / or the requested service. The NF 212 may receive request 221 , perform one or more actions associated with the requested service (e.g., retrieving data), and provide a response 221. The one or more actions performed by the NF 212 may be based on request data included in the request 221, data stored by NF 212, and / or data retrieved by NF 212. The response 222 may notify NF 211 that the one or more actions have been completed. The response 222 may comprise response data relating to NF 212, the one or more actions, and / or the requested service.

[0060] In the example of FIG. 2B, an NF 231 sends a request 241 to an NF 232. In this example, part of the service produced by NF 232 is to send a request 242 to an NF 233. The NF 233 may perform one or more actionsDocket No.: 25-1063PCTand provide a response 243 to NF 232. Based on response 243, NF 232 may send a response 244 to NF 231. It will be understood from FIG.2B that a single NF may perform the role of producer of services, consumer of services, or both. A particular NF service may include any number of nested NF services produced by one or more other NFs.

[0061] FIG. 2C illustrates examples of subscribe-notify interactions between a consumer NF and a producer NF.In FIG.2C, an NF 251 sends a subscription 261 to an NF 252. An NF 253 sends a subscription 262 to the NF 252. Two NFs are shown in FIG. 2C for illustrative purposes (to demonstrate that the NF 252 may provide multiple subscription services to different NFs), but it will be understood that a subscribe-notify interaction only requires one subscriber. The NFs 251, 253 may be independent from one another. For example, the NFs 251, 253 may independently discover NF 252 and / or independently determine to subscribe to the service offered by NF 252. In response to receipt of a subscription, the NF 252 may provide a notification to the subscribing NF. For example, NF 252 may send a notification 263 to NF 251 based on subscription 261 and may send a notification 264 to NF 253 based on subscription 262.

[0062] As shown in the example illustration of FIG. 2C, the sending of the notifications 263, 264 may be based on a determination that a condition has occurred. For example, the notifications 263, 264 may be based on a determination that a particular event has occurred, a determination that a particular condition is outstanding, and / or a determination that a duration of time associated with the subscription has elapsed (for example, a period associated with a subscription for periodic notifications). As shown in the example illustration of FIG.2C, NF 252 may send notifications 263, 264 to NFs 251 , 253 simultaneously and / or in response to the same condition.However, it will be understood that the NF 252 may provide notifications at different times and / or in response to different notification conditions. In an example, the NF 251 may request a notification when a certain parameter, as measured by the NF 252, exceeds a first threshold, and the NF 252 may request a notification when the parameter exceeds a second threshold different from the first threshold. In an example, a parameter of interest and / or a corresponding threshold may be indicated in the subscriptions 261, 262.

[0063] FIG. 2D illustrates another example of a subscribe-notify interaction. In FIG. 2D, an NF 271 sends a subscription 281 to an NF 272. In response to receipt of subscription 281 and / or a determination that a notification condition has occurred, NF 272 may send a notification 284. The notification 284 may be sent to an NF 273. Unlike the example in FIG. 2C (in which a notification is sent to the subscribing NF), FIG. 2D demonstrates that a subscription and its corresponding notification may be associated with different NFs. For example, NF 271 may subscribe to the service provided by NF 272 on behalf of NF 273.

[0064] FIG. 3 illustrates another example communication network 300 in which embodiments of the present disclosure may be implemented. Communication network 300 includes a user equipment (UE) 301 , an access network (AN) 302, and a data network (DN) 308. The remaining elements depicted in FIG.3 may be included in and / or associated with a core network. Each element of the core network may be referred to as a network function (NF).Docket No.: 25-1063PCT

[0065] The NFs depicted in FIG. 3 include a user plane function (UPF) 305, an access and mobility management function (AMF) 312, a session management function (SMF) 314, a policy control function (PCF) 320, a network repository function (NRF) 330, a network exposure function (NEF) 340, a unified data management (UDM) 350, an authentication server function (AUSF) 360, a network slice selection function (NSSF) 370, a charging function (CHF) 380, a network data analytics function (NWDAF) 390, and an application function (AF) 399. The UPF 305 may be a user-plane core network function, whereas the NFs 312, 314, and 320-390 may be control-plane core network functions. Although not shown in the example of FIG.3, the core network may include additional instances of any of the NFs depicted and / or one or more different NF types that provide different services. Other examples of NF type include a gateway mobile location center (GMLC), a location management function (LMF), an operations, administration, and maintenance function (OAM), a public warning system (PWS), a short message service function (SMSF), a unified data repository (UDR), and an unstructured data storage function (UDSF).

[0066] Each element depicted in FIG. 3 has an interface with at least one other element. The interface may be a logical connection rather than, for example, a direct physical connection. Any interface may be identified using a reference point representation and / or a service-based representation. In a reference point representation, the letter ‘N’ is followed by a numeral, indicating an interface between two specific elements. For example, as shown in FIG.3, AN 302 and UPF 305 interface via ‘N3’, whereas UPF 305 and DN 308 interface via ‘N6’. By contrast, in a service-based representation, the letter 'N' is followed by letters. The letters identify an NF that provides services to the core network. For example, PCF 320 may provide services via interface 'Npcf. The PCF 320 may provide services to any NF in the core network via 'Npcf. Accordingly, a service-based representation may correspond to a bundle of reference point representations. For example, the Npcf interface between PCF 320 and the core network generally may correspond to an N7 interface between PCF 320 and SMF 314, an N30 interface between PCF 320 and NEF 340, etc.

[0067] The UPF 305 may serve as a gateway for user plane traffic between AN 302 and DN 308. The UE 301 may connect to UPF 305 via a Uu interface and an N3 interface (also described as NG-U interface). The UPF 305 may connect to DN 308 via an N6 interface. The UPF 305 may connect to one or more other UPFs (not shown) via an N9 interface. The UE 301 may be configured to receive services through a protocol data unit (PDU) session, which is a logical connection between UE 301 and DN 308. The UPF 305 (or a plurality of UPFs if desired) may be selected by SMF 314 to handle a particular PDU session between UE 301 and DN 308. The SMF 314 may control the functions of UPF 305 with respect to the PDU session. The SMF 314 may connect to UPF 305 via an N4 interface. The UPF 305 may handle any number of PDU sessions associated with any number of UEs (via any number of ANs). For purposes of handling the one or more PDU sessions, UPF 305 may be controlled by any number of SMFs via any number of corresponding N4 interfaces.

[0068] The AMF 312 depicted in FIG. 3 may control UE access to the core network. The UE 301 may register with the network via AMF 312. It may be necessary for UE 301 to register prior to establishing a PDU session. The AMF 312 may manage a registration area of UE 301, enabling the network to track the physical location of UE 301Docket No.: 25-1063PCTwithin the network. For a UE in connected mode, AMF 312 may manage UE mobility, for example, handovers from one AN or portion thereof to another. For a UE in idle mode, AMF 312 may perform registration updates and / or page the UE to transition the UE to connected mode.

[0069] The AMF 312 may receive, from UE 301, non-access stratum (NAS) messages transmitted in accordance with NAS protocol. NAS messages relate to communications between UE 301 and the core network. Although NAS messages may be relayed to AMF 312 via AN 302, they may be described as communications via the N1 interface. NAS messages may facilitate UE registration and mobility management, for example, by authenticating, identifying, configuring, and / or managing a connection of UE 301. NAS messages may support session management procedures for maintaining user plane connectivity and quality of service (QoS) of a session between UE 301 and DN 309. If the NAS message involves session management, AMF 312 may send the NAS message to SMF 314. NAS messages may be used to transport messages between UE 301 and other components of the core network (e.g., core network components other than AMF 312 and SMF 314). The AMF 312 may act on a particular NAS message itself, or alternatively, forward the NAS message to an appropriate core network function (e.g., SMF 314, etc.)

[0070] The SMF 314 depicted in FIG. 3 may establish, modify, and / or release a PDU session based on messaging received UE 301. The SMF 314 may allocate, manage, and / or assign an IPaddress to UE 301, for example, upon establishment of a PDU session. There maybe multiple SMFs in the network, each of which may be associated with a respective group of wireless devices, base stations, and / or UPFs. A UE with multiple PDU sessions may be associated with a different SMF for each PDU session. As noted above, SMF 314 may select one or more UPFs to handle a PDU session and may control the handling of the PDU session by the selected UPF by providing rules for packet handling (PDR, FAR, QER, etc.). Rules relating to QoS and / or charging for a particular PDU session may be obtained from PCF 320 and provided to UPF 305.

[0071] The PCF 320 may provide, to other NFs, services relating to policy rules. The PCF 320 may use subscription data and information about network conditions to determine policy rules and then provide the policy rules to a particular NF which may be responsible for enforcement of those rules. Policy rules may relate to policy control for access and mobility, and may be enforced by the AMF. Policy rules may relate to session management, and may be enforced by the SMF 314. Policy rules may be, for example, network-specific, wireless device-specific, session-specific, or data flow-specific.

[0072] The NRF 330 may provide service discovery. The NRF 330 may belong to a particular PLMN The NRF 330 may maintain NF profiles relating to other NFs in the communication network 300. The NF profile may include, for example, an address, PLMN, and / or type of the NF, a slice identifier, a list of the one or more services provided by the NF, and the authorization required to access the services.

[0073] The NEF 340 depicted in FIG. 3 may provide an interface to external domains, permitting external domains to selectively access the control plane of the communication network 300. The external domain may comprise, for example, third-party network functions, application functions, etc. The NEF 340 may act as a proxyDocket No.: 25-1063PCTbetween external elements and network functions such as AMF 312, SMF 314, PCF 320, UDM 350, etc. As an example, NEF 340 may determine a location or reachability status of UE 301 based on reports from AMF 312, and provide status information to an external element. As an example, an external element may provide, via NEF 340, information that facilitates the setting of parameters for establishment of a PDU session. The NEF 340 may determine which data and capabilities of the control plane are exposed to the external domain. The NEF 340 may provide secure exposure that authenticates and / or authorizes an external entity to which data or capabilities of the communication network 300 are exposed. The NEF 340 may selectively control the exposure such that the internal architecture of the core network is hidden from the external domain.

[0074] The UDM 350 may provide data storage for other NFs. The UDM 350 may permit a consolidated view of network information that may be used to ensure that the most relevant information can be made available to different NFs from a single resource. The UDM 350 may store and / or retrieve information from a unified data repository (UDR). For example, UDM 350 may obtain user subscription data relating to UE 301 from the UDR.

[0075] The AUSF 360 may support mutual authentication of UE 301 by the core network and authentication of the core network by UE 301. The AUSF 360 may perform key agreement procedures and provide keying material that can be used to improve security.

[0076] The NSSF 370 may select one or more network slices to be used by the UE 301. The NSSF 370 may select a slice based on slice selection information. For example, the NSSF 370 may receive Single Network Slice Selection Assistance Information (S-NSSAI) and map the S-NSSAI to a network slice instance identifier (NSI).

[0077] The CHF 380 may control billing-related tasks associated with UE 301. For example, UPF 305 may report traffic usage associated with UE 301 to SMF 314. The SMF 314 may collect usage data from UPF 305 and one or more other UPFs. The usage data may indicate how much data is exchanged, what DN the data is exchanged with, a network slice associated with the data, or any other information that may influence billing. The SMF 314 may share the collected usage data with the CHF. The CHF may use the collected usage data to perform billing- related tasks associated with UE 301. The CHF may, depending on the billing status of UE 301, instruct SMF 314 to limit or influence access of UE 301 and / or to provide billing-related notifications to UE 301.

[0078] The NWDAF 390 may collect and analyze data from other network functions and offer data analysis services to other network functions. As an example, NWDAF 390 may collect data relating to a load level for a particular network slice instance from UPF 305, AMF 312, and / or SMF 314. Based on the collected data, NWDAF 390 may provide load level data to the PCF 320 and / or NSSF 370, and / or notify the PC220 and / or NSSF 370 if load level for a slice reaches and / or exceeds a load level threshold.

[0079] The AF 399 may be outside the core network, but may interact with the core network to provide information relating to the QoS requirements or traffic routing preferences associated with a particular application. The AF 399 may access the core network based on the exposure constraints imposed by the NEF 340. However, an operator of the core network may consider the AF 399 to be a trusted domain that can access the network directly.Docket No.: 25-1063PCT

[0080] FIGS. 4A, 4B, and 5 illustrate other examples of core network architectures that are analogous in some respects to the core network architecture 300 depicted in FIG. 3. For conciseness, some of the core network elements depicted in FIG.3 are omitted. Many of the elements depicted in FIGS.4A, 4B, and 5 are analogous in some respects to elements depicted in FIG. 3. For conciseness, some of the details relating to their functions or operation are omitted.

[0081] FIG. 4A illustrates an example of a core network architecture 400A comprising an arrangement of multiple UPFs. Core network architecture 400A includes a UE 401, an AN 402, an AMF 412, and an SMF 414. Unlike previous examples of core network architectures described above, FIG.4A depicts multiple UPFs, including a UPF 405, a UPF 406, and a UPF 407, and multiple DNs, including a DN 408 and a DN 409. Each of the multiple UPFs 405, 406, 407 may communicate with the SMF 414 via an N4 interface. The DNs 408, 409 communicate with the UPFs 405, 406, respectively, via N6 interfaces. As shown in FIG. 4A, the multiple UPFs 405, 406, 407 may communicate with one another via N9 interfaces.

[0082] The UPFs 405, 406, 407 may perform traffic detection, in which the UPFs identify and / or classify packets.Packet identification may be performed based on packet detection rules (PDR) provided by the SMF 414. A PDR may include packet detection information comprising one or more of: a source interface, a UE IP address, core network (CN) tunnel information (e.g., a CN address of an N3 / N9 tunnel corresponding to a PDU session), a network instance identifier, a quality of service flow identifier (QFI), a filter set (for example, an IP packet filter set or an ethernet packet filter set), and / or an application identifier.

[0083] In addition to indicating how a particular packet is to be detected, a PDR may further indicate rules for handling the packet upon detection thereof. The rules may include, for example, forwarding action rules (FARs), multi-access rules (MARs), usage reporting rules (URRs), QoS enforcement rules (QERs), etc. For example, the PDR may comprise one or more FAR identifiers, MAR identifiers, URR identifiers, and / or QER identifiers. These identifiers may indicate the rules that are prescribed for the handling of a particular detected packet.

[0084] The UPF 405 may perform traffic forwarding in accordance with a FAR. For example, the FAR may indicate that a packet associated with a particular PDR is to be forwarded , duplicated, dropped, and / or buffered. The FAR may indicate a destination interface, for example, “access” for downlink or “core” for uplink. If a packet is to be buffered, the FAR may indicate a buffering action rule (BAR). As an example, UPF 405 may perform data buffering of a certain number of downlink packets if a PDU session is deactivated.

[0085] The UPF 405 may perform QoS enforcement in accordance with a QER. For example, the QER may indicate a guaranteed bitrate that is authorized and / or a maximum bitrate to be enforced for a packet associated with a particular PDR. The QER may indicate that a particular guaranteed and / or maximum bitrate may be for uplink packets and / or downlink packets. The UPF 405 may mark packets belonging to a particular QoS flow with a corresponding QFI. The marking may enable a recipient of the packet to determine a QoS of the packet.

[0086] The UPF 405 may provide usage reports to the SMF 414 in accordance with a URR. The URR may indicate one or more triggering conditions for generation and reporting of the usage report, for example, immediateDocket No.: 25-1063PCTreporting, periodic reporting, a threshold for incoming uplink traffic, or any other suitable triggering condition. The URR may indicate a method for measuring usage of network resources, for example, data volume, duration, and / or event.

[0087] As noted above, the DNs 408, 409 may comprise public DNs (e.g., the Internet), private DNs (e.g., private, internal corporate-owned DNs), and / or intra-operator DNs. Each DN may provide an operator service and / or a third-party service. The service provided by a DN may be the Internet, an IP multimedia subsystem (IMS), an augmented or virtual reality network, an edge computing or mobile edge computing (MEC) network, etc. Each DN may be identified using a data network name (DNN). The UE 401 may be configured to establish a first logical connection with DN 408 (a first PDU session), a second logical connection with DN 409 (a second PDU session), or both simultaneously (first and second PDU sessions).

[0088] Each PDU session may be associated with at least one UPF configured to operate as a PDU session anchor (PSA, or “anchor"). The anchor may be a UPF that provides an N6 interface with a DN.

[0089] In the example of FIG. 4A, UPF 405 may be the anchor for the first PDU session between UE 401 and DN 408, whereas the UPF 406 may be the anchor for the second PDU session between UE 401 and DN 409. The core network may use the anchor to provide service continuity of a particular PDU session (for example, IP address continuity) as UE 401 moves from one access network to another. For example, suppose that UE 401 establishes a PDU session using a data path to the DN 408 using an access network other than AN 402. The data path may include UPF 405 acting as anchor. Suppose further that the UE 401 later moves into the coverage area of the AN 402. In such a scenario, SMF414 may select a new UPF (UPF 407) to bridge the gap between the newly-entered access network (AN 402) and the anchor UPF (UPF 405). The continuity of the PDU session may be preserved as any number of UPFs are added or removed from the data path. When a UPF is added to a data path, as shown in FIG.4A, it may be described as an intermediate UPF and / or a cascaded UPF.

[0090] As noted above, UPF 406 may be the anchor for the second PDU session between UE 401 and DN 409.Although the anchor for the first and second PDU sessions are associated with different UPFs in FIG. 4A, it will be understood that this is merely an example. It will also be understood that multiple PDU sessions with a single DN may correspond to any number of anchors. When there are multiple UPFs, a UPF at the branching point (UPF 407 in FIG.4A) may operate as an uplink classifier (UL-CL). The UL-CL may divert uplink user plane traffic to different UPFs.

[0091] The SMF414 may allocate, manage, and / or assign an IPaddress to UE 401, for example, upon establishmentof a PDU session. The SMF 414 may maintain an internal pool of IP addresses to be assigned. The SMF 414 may, if necessary, assign an IP address provided by a dynamic host configuration protocol (DHCP) server or an authentication, authorization, and accounting (AAA) server. IP address management may be performed in accordance with a session and service continuity (SSC) mode. In SSC mode 1, an IP address of UE 401 may be maintained (and the same anchor UPF may be used) as the wireless device moves within the network. In SSC mode 2, the IP address of UE 401 changes as UE 401 moves within the network (e.g., the old IP addressDocket No.: 25-1063PCTand UPF may be abandoned and a new IP address and anchor UPF may be established). In SSC mode 3, it may be possible to maintain an old IP address (similar to SSC mode 1) temporarily while establishing a new IP address (similar to SSC mode 2), thus combining features of SSC modes 1 and 2. Applications that are sensitive to IP address changes may operate in accordance with SSC mode 1.

[0092] UPF selection may be controlled by SMF 414. For example, upon establishment and / or modification of a PDU session between UE 401 and DN 408, SMF 414 may select UPF 405 as the anchor for the PDU session and / or UPF 407 as an intermediate UPF. Criteria for UPF selection include path efficiency and / or speed between AN 402 and DN 408. The reliability, load status, location, slice support and / or other capabilities of candidate UPFs may also be considered.

[0093] FIG. 4B illustrates an example of a core network architecture 400B that accommodates untrusted access.Similar to FIG.4A, UE 401 as depicted in FIG. 4B connects to DN 408 via AN 402 and UPF 405. The AN 402 and UPF 405 constitute trusted (e.g., 3GPP) access to the DN 408. By contrast, UE 401 may also access DN 408 using an untrusted access network, AN 403, and a non-3GPP interworking function (N3IWF) 404.

[0094] The AN 403 may be, for example, a wireless land area network (WLAN) operating in accordance with the IEEE 802.11 standard. The UE 401 may connect to AN 403, via an interface Y1, in whatever manner is prescribed for AN 403. The connection to AN 403 may or may not involve authentication. The UE 401 may obtain an IP address from AN 403. The UE 401 may determine to connect to core network 400B and select untrusted access for that purpose. The AN 403 may communicate with N3IWF 404 via a Y2 interface. After selecting untrusted access, the UE 401 may provide N3IWF 404 with sufficient information to select an AMF. The selected AMF may be, for example, the same AMF that is used by UE 401 for 3GPP access (AMF 412 in the present example). The N3IWF 404 may communicate with AMF 412 via an N2 interface. The UPF 405 may be selected and N3IWF 404 may communicate with UPF 405 via an N3 interface. The UPF 405 may be a PDU session anchor (PSA) and may remain the anchor for the PDU session even as UE 401 shifts between trusted access and untrusted access.

[0095] FIG. 5 illustrates an example of a core network architecture 500 in which a UE 501 is in a roaming scenario. In a roaming scenario, UE 501 is a subscriber of a first PLMN (a home PLMN, or HPLMN) but attaches to a second PLMN (a visited PLMN, or VPLMN). Core network architecture 500 includes UE 501, an AN 502, a UPF 505, and a DN 508. The AN 502 and UPF 505 may be associated with a VPLMN. The VPLMN may manage the AN 502 and UPF 505 using core network elements associated with the VPLMN, including an AMF 512, an SMF 514, a PCF 520, an NRF 530, an NEF 540, and an NSSF 570. An AF 599 may be adjacent the core network of the VPLMN.

[0096] The UE 501 may not be a subscriber of the VPLMN. The AMF 512 may authorize UE 501 to access the network based on, for example, roaming restrictions that apply to UE 501. In order to obtain network services provided by the VPLMN, it may be necessary for the core network of the VPLMN to interact with core network elementsofa HPLMN of UE 501, in particular, a PCF 521, an NRF 531, an NEF 541, a UDM 551, and / or an AUSF 561. The VPLMN and HPLMN may communicate using an N32 interface connecting respective security edgeDocket No.: 25-1063PCTprotection proxies (SEPPs). In FIG.5, the respective SEPPs are depicted as a VSEPP 590 and an HSEPP 591.

[0097] The VSEPP 590 and the HSEPP 591 communicate via an N32 interface for defined purposes while concealing information about each PLMN from the other. The SEPPs may apply roaming policies based on communications via the N32 interface. The PDF 520 and PDF 521 may communicate via the SEPPs to exchange policy-related signaling. The NRF 530 and NRF 531 may communicate via the SEPPs to enable service discovery of NFs in the respective PLMNs. The VPLMN and HPLMN may independently maintain NEF 540 and NEF 541. The NSSF 570 and NSSF 571 may communicate via the SEPPs to coordinate slice selection for UE 501. The HPLMN may handle all authentication and subscription related signaling. For example, when the UE 501 registers or requests service via the VPLMN, the VPLMN may authenticate UE 501 and / or obtain subscription data of UE 501 by accessing, via the SEPPs, the UDM 551 and AUSF 561 of the HPLMN.

[0098] The core network architecture 500 depicted in FIG.5 may be referred to as a local breakout configuration, in which UE 501 accesses DN 508 using one or more UPFs of the VPLMN (i.e., UPF 505). However, other configurations are possible. For example, in a home-routed configuration (not shown in FIG. 5), UE 501 may access a DN using one or more UPFs of the HPLMN. In the home-routed configuration, an N9 interface may run parallel to the N32 interface, crossing the frontier between the VPLMN and the HPLMN to carry user plane data. One or more SMFs of the respective PLMNs may communicate via the N32 interface to coordinate session management for UE 501. The SMFs may control their respective UPFs on either side of the frontier.

[0099] FIG. 6 illustrates an example of network slicing. Network slicing may refer to division of shared infrastructure (e.g., physical infrastructure) into distinct logical networks. These distinct logical networks may be independently controlled, isolated from one another, and / or associated with dedicated resources.

[0100] Network architecture 600A illustrates an un-sliced physical network corresponding to a single logical network. The network architecture 600A comprises a user plane wherein UEs 601A, 601B, 601C (collectively, UEs 601) have a physical and logical connection to a DN 608 via an AN 602 and a UPF 605. The network architecture 600A comprises a control plane wherein an AMF 612 and a SMF 614 control various aspects of the user plane.

[0101] The network architecture 600A may have a specific set of characteristics (e.g., relating to maximum bit rate, reliability, latency, bandwidth usage, power consumption, etc.). This set of characteristics may be affected by the nature of the network elements themselves (e.g., processing power, availability of free memory, proximity to other network elements, etc.) or the management thereof (e.g., optimized to maximize bit rate or reliability, reduce latency or power bandwidth usage, etc.). The characteristics of network architecture 600A may change over time, for example, by upgrading equipment or by modifying procedures to target a particular characteristic. However, at any given time, network architecture 600A will have a single set of characteristics that may or may not be optimized for a particular use case. For example, UEs 601A, 601B, 601C may have different requirements, but network architecture 600A can only be optimized for one of the three.

[0102] Network architecture 600B is an example of a sliced physical network divided into multiple logical networks. In FIG. 6, the physical network is divided into three logical networks, referred to as slice A, slice B, andDocket No.: 25-1063PCTslice C. For example, UE 601Amay be served by AN 602A, UPF605A, AMF 612, and SMF 614A. UE601B may be served by AN 602B, UPF 605B, AMF 612, and SMF 614B. UE 601 C may be served by AN 602C, UPF 605C, AMF 612, and SMF 614C. Although the respective UEs 601 communicate with different network elements from a logical perspective, these network elements may be deployed by a network operator using the same physical network elements.

[0103] Each network slice may be tailored to network services having different sets of characteristics. For example, slice A may correspond to enhanced mobile broadband (eMBB) service. Mobile broadband may refer to internet access by mobile users, commonly associated with smartphones. Slice B may correspond to ultra-reliable low-latency communication (URLLC), which focuses on reliability and speed. Relative to eMBB, URLLC may improve the feasibility of use cases such as autonomous driving and telesurgery. Slice C may correspond to massive machine type communication (mMTC), which focuses on low-power services delivered to a large number of users. For example, slice C may be optimized for a dense network of battery-powered sensors that provide small amounts of data at regular intervals. Many mMTC use cases would be prohibitively expensive if they operated using an eMBB or URLLC network.

[0104] If the service requirements for one of the UEs 601 changes, then the network slice serving that UE can be updated to provide better service. Moreover, the set of network characteristics corresponding to eMBB, URLLC, and mMTC may be varied, such that differentiated species of eMBB, URLLC, and mMTC are provided.Alternatively, network operators may provide entirely new services in response to, for example, customer demand.

[0105] In FIG.6, each of the UEs 601 has its own network slice. However, it will be understood that a single slice may serve any number of UEs and a single UE may operate using any number of slices. Moreover, in the example network architecture 600B, the AN 602, UPF 605 and SMF 614 are separated into three separate slices, whereas the AMF 612 is unsliced. However, it will be understood that a network operator may deploy any architecture that selectively utilizes any mix of sliced and unsliced network elements, with different network elements divided into different numbers of slices. Although FIG. 6 only depicts three core network functions, it will be understood that other core network functions may be sliced as well. A PLMN that supports multiple network slices may maintain a separate network repository function (NFR) for each slice, enabling other NFs to discover network services associated with that slice.

[0106] Network slice selection may be controlled by an AMF, or alternatively, by a separate network slice selection function (NSSF). For example, a network operator may define and implement distinct network slice instances (NSIs). Each NSI may be associated with single network slice selection assistance information (S-NSSAI). The S-NSSAI may include a particular slice / service type (SST) indicator (indicating eMBB, URLLC, mMTC, etc.). As an example, a particular tracking area may be associated with one or more configured S-NSSAIs. UEs may identify one or more requested and / or subscribed S-NSSAIs (e.g., during registration). The network may indicate to the UE one or more allowed and / or rejected S-NSSAIs.

[0107] The S-NSSAI may further include a slice differentiator (SD) to distinguish between different tenants of aDocket No.: 25-1063PCTparticular slice and / or service type. For example, a tenant may be a customer (e.g vehicle manufacture, service provider, etc.) of a network operator that obtains (for example, purchases) guaranteed network resources and / or specific policies for handling its subscribers. The network operator may configure different slices and / or slice types, and use the SD to determine which tenant is associated with a particular slice.

[0108] FIG. 7A, FIG. 7B, and FIG. 7C illustrate a user plane (UP) protocol stack, a control plane (CP) protocol stack, and services provided between protocol layers of the UP protocol stack.

[0109] The layers may be associated with an open system interconnection (OSI) model of computer networking functionality. In the OSI model, layer 1 may correspond to the bottom layer, with higher layers on top of the bottom layer. Layer 1 may correspond to a physical layer, which is concerned with the physical infrastructure used for transfer of signals (for example, cables, fiber optics, and / or radio frequency transceivers). In New Radio (NR), layer 1 may comprise a physical layer (PHY). Layer 2 may correspond to a data link layer. Layer 2 may be concerned with packaging of data (into, e.g., data frames) for transfer, between nodes of the network, using the physical infrastructure of layer 1. In NR, layer 2 may comprise a media access control layer (MAC), a radio link control layer (RLC), a packet data convergence layer (PDCP), and a service data application protocol layer (SDAP).

[0110] Layer 3 may correspond to a network layer. Layer 3 may be concerned with routing of the data which has been packaged in layer 2. Layer 3 may handle prioritization of data and traffic avoidance. In NR, layer 3 may comprise a radio resource control layer (RRC) and a non-access stratum layer (NAS). Layers 4 through 7 may correspond to a transport layer, a session layer, a presentation layer, and an application layer. The application layer interacts with an end user to provide data associated with an application. In an example, an end user implementing the application may generate data associated with the application and initiate sending of that information to a targeted data network (e.g., the Internet, an application server, etc.). Starting at the application layer, each layer in the OSI model may manipulate and / or repackage the information and deliver it to a lower layer. At the lowest layer, the manipulated and / or repackaged information may be exchanged via physical infrastructure (for example, electrically, optically, and / or electromagnetical ly) . As it approaches the targeted data network, the information will be unpackaged and provided to higher and higher layers, until it once again reaches the application layer in a form that is usable by the targeted data network (e.g., the same form in which it was provided by the end user). To respond to the end user, the data network may perform this procedure in reverse.

[0111] FIG. 7A illustrates a user plane protocol stack. The user plane protocol stack may be a new radio (NR) protocol stack for a Uu interface between a UE 701 and a gNB 702. In layer 1 of the UP protocol stack, the UE 701 may implement PHY 731 and the gNB 702 may implement PHY 732. In layer 2 of the UP protocol stack, the UE 701 may implement MAC 741, RLC 751, PDCP 761, and SDAP 771. The gNB 702 may implement MAC 742, RLC 752, PDCP 762, and SDAP 772.

[0112] FIG. 7B illustrates a control plane protocol stack. The control plane protocol stack may be an NR protocol stack for the Uu interface between the UE 701 and the gNB 702 and / or an N1 interface between the UE 701 andDocket No.: 25-1063PCTan AMF 712. In layer 1 of the CP protocol stack, the UE701 may implement PHY 731 and the gNB 702 may implement PHY 732. In layer 2 of the CP protocol stack, the UE 701 may implement MAC 741, RLC 751, PDCP 761, RRC 781, and NAS 791. The gNB 702 may implement MAC 742, RLC 752, PDCP 762, and RRC 782. The AMF 712 may implement NAS 792.

[0113] The NAS maybe concerned with the non-access stratum, in particular, communication between the UE 701 and the core network (e.g., the AMF 712). Lower layers may be concerned with the access stratum, for example, communication between the UE 701 and the gNB 702. Messages sent between the UE 701 and the core network may be referred to as NAS messages. In an example, a NAS message may be relayed by the gNB 702, but the content of the NAS message (e.g., information elements of the NAS message) may not be visible to the gNB 702.

[0114] FIG. 7C illustrates an example of services provided between protocol layers of the NR user plane protocol stack illustrated in FIG. 7A. The UE 701 may receive services through a PDU session, which may be a logical connection between the UE 701 and a data network (DN). The UE 701 and the DN may exchange data packets associated with the PDU session. The PDU session may comprise one or more quality of service (QoS) flows. SDAP 771 and SDAP 772 may perform mapping and / or demapping between the one or more QoS flows of the PDU session and one or more radio bearers (e.g., data radio bearers). The mapping between the QoS flows and the data radio bearers may be determined in the SDAP 772 by the gNB 702, and the UE 701 may be notified of the mapping (e.g., based on control signaling and / or reflective mapping). For reflective mapping, the SDAP 772 of the gNB 220 may mark downlink packets with a QoS flow indicator (QFI) and deliver the downlink packets to the UE 701. The UE 701 may determine the mapping based on the QFI of the downlink packets.

[0115] PDCP 761 and PDCP 762 may perform header compression and / or decompression. Header compression may reduce the amount of data transmitted over the physical layer. The PDCP 761 and PDCP 762 may perform ciphering and / or deciphering. Ciphering may reduce unauthorized decoding of data transmitted over the physical layer (e.g., intercepted on an air interface), and protect data integrity (e.g., to ensure control messages originate from intended sources). The PDCP 761 and PDCP 762 may perform retransmissions of undelivered packets, in-sequence delivery and reordering of packets, duplication of packets, and / or identification and removal of duplicate packets. In a dual connectivity scenario, PDCP 761 and PDCP 762 may perform mapping between a split radio bearer and RLC channels.

[0116] RLC 751 and RLC 752 may perform segmentation, retransmission through Automatic Repeat Request (ARQ). The RLC 751 and RLC 752 may perform removal of duplicate data units received from MAC 741 and MAC 742, respectively. The RLCs 213 and 223 may provide RLC channels as a service to PDCPs 214 and 224, respectively.

[0117] MAC 741 and MAC 742 may perform multiplexing and / or demultiplexing of logical channels. MAC 741 and MAC 742 may map logical channels to transport channels. In an example, UE 701 may, in MAC 741, multiplex data units of one or more logical channels into a transport block. The UE 701 may transmit the transport block toDocket No.: 25-1063PCTthe g N B 702 using PHY 731. The g N B 702 may receive the transport block using PHY 732 and demultiplex data units of the transport blocks back into logical channels. MAC 741 and MAC 742 may perform error correction through Hybrid Automatic Repeat Request (HARQ), logical channel prioritization, and / or padding.

[0118] PHY 731 and PHY 732 may perform mapping of transport channels to physical channels. PHY 731 and PHY 732 may perform digital and analog signal processing functions (e.g., coding / decoding and modulation / demodulation) for sending and receiving information (e.g., transmission via an air interface). PHY 731 and PHY 732 may perform multi-antenna mapping.

[0119] FIG. 8 illustrates an example of a quality of service (QoS) model for differentiated data exchange. In the QoS model of FIG.8, there are a UE 801, a AN 802, and a UPF 805. The QoS model facilitates prioritization of certain packet or protocol data units (PDUs), also referred to as packets. For example, higher-priority packets may be exchanged faster and / or more reliably than lower-priority packets. The network may devote more resources to exchange of high-QoS packets.

[0120] In the example of FIG. 8, a PDU session 810 is established between UE 801 and UPF 805. The PDU session 810 may be a logical connection enabling the UE 801 to exchange data with a particular data network (for example, the Internet). The UE 801 may request establishment of the PDU session 810. At the time that the PDU session 810 is established, the UE 801 may, for example, identify the targeted data network based on its data network name (DNN). The PDU session 810 maybe managed, for example, by a session management function (SMF, not shown). In order to facilitate exchange of data associated with the PDU session 810, between the UE 801 and the data network, the SMF may select the UPF 805 (and optionally, one or more other UPFs, not shown).

[0121] One or more applications associated with UE 801 may generate uplink packets 812A-812E associated with the PDU session 810. In order to work within the QoS model, UE 801 may apply QoS rules 814 to uplink packets 812A-812E. The QoS rules 814 may be associated with PDU session 810 and may be determined and / or provided to the UE 801 when PDU session 810 is established and / or modified. Based on QoS rules 814, UE 801 may classify uplink packets 812A-812E, map each of the uplink packets 812A-812E to a QoS flow, and / or mark uplink packets 812A-812E with a QoS flow indicator (QFI). As a packet travels through the network, and potentially mixes with other packets from other UEs having potentially different priorities, the QFI indicates how the packet should be handled in accordance with the QoS model. In the present illustration, uplink packets 812A, 812B are mapped to QoS flow 816A, uplink packet 812C is mapped to QoS flow 816B, and the remaining packets are mapped to QoS flow 816C.

[0122] The QoS flows may be the finest granularity of QoS differentiation in a PDU session. In the figure, three QoS flows 816A-816C are illustrated. However, it will be understood that there may be any number of QoS flows. Some QoS flows may be associated with a guaranteed bit rate (GBR QoS flows) and others may have bit rates that are not guaranteed (non-GBR QoS flows). QoS flows may also be subject to per-UE and per-session aggregate bit rates One of the QoS flows may be a default QoS flow The QoS flows may have different priorities. For example, QoS flow 816A may have a higher priority than QoS flow 816B, which may have a higher priority thanDocket No.: 25-1063PCTQoS flow 816C. Different priorities may be reflected by different QoS flow characteristics. For example, QoS flows may be associated with flow bit rates. A particular QoS flow may be associated with a guaranteed flow bit rate (GFBR) and / or a maximum flow bit rate (MFBR). QoS flows may be associated with specific packet delay budgets (PDBs), packet error rates (PERs), and / or maximum packet loss rates. QoS flows may also be subject to per-UE and per-session aggregate bit rates.

[0123] In order to work within the QoS model, UE 801 may apply resource mapping rules 818 to the QoS flows 816A-816C. The air interface between UE 801 and AN 802 may be associated with resources 820. In the present illustration, QoS flow 816A is mapped to resource 820A, whereas QoS flows 816B, 816C are mapped to resource 820B. The resource mapping rules 818 may be provided by the AN 802. In order to meet QoS requirements, the resource mapping rules 818 may designate more resources for relatively high-priority QoS flows. With more resources, a high-priority QoS flow such as QoS flow 816A may be more likely to obtain the high flow bit rate, low packet delay budget, or other characteristic associated with QoS rules 814. The resources 820 may comprise, for example, radio bearers. The radio bearers (e.g., data radio bearers) may be established between the UE 801 and the AN 802. The radio bearers in 5G, between the UE 801 and the AN 802, may be distinct from bearers in LTE, for example, Evolved Packet System (EPS) bearers between a UE and a packet data network gateway (PGW), S1 bearers between an eNB and a serving gateway (SGW), and / or an S5 / S8 bearer between an SGW and a PGW.

[0124] Once a packet associated with a particular QoS flow is received at AN 802 via resource 820A or resource 820B, AN 802 may separate packets into respective QoS flows 856A-856C based on QoS profiles 828. The QoS profiles 828 may be received from an SMF. Each QoS profile may correspond to a QFI, for example, the QFI marked on the uplink packets 812A-812E. Each QoS profile may include QoS parameters such as 5G QoS identifier (5QI) and an allocation and retention priority (ARP). The QoS profile for non-GBR QoS flows may further include additional QoS parameters such as a reflective QoS attribute (RQA).The QoS profile for GBR QoS flows may further include additional QoS parameters such as a guaranteed flow bit rate (GFBR), a maximum flow bit rate (MFBR), and / or a maximum packet loss rate. The 5QI may be a standardized 5QI which has one-to-one mapping to a standardized combination of 5G QoS characteristics per well-known services. The 5QI may be a dynamically assigned 5QI which the standardized 5QI values are not defined. The 5QI may represent 5G QoS characteristics. The 5QI may comprise a resource type, a default priority level, a packet delay budget (PDB), a packet error rate (PER), a maximum data burst volume, and / or an averaging window. The resource type may indicate a non-GBR QoS flow, a GBR QoS flow or a delay-critical GBR QoS flow. The averaging window may represent a duration over which the GFBR and / or MFBR is calculated. ARP may be a priority level comprising pre-emption capability and a pre-emption vulnerability. Based on the ARP, the AN 802 may apply admission control for the QoS flows in a case of resource limitations.

[0125] The AN 802 may select one or more N3 tunnels 850 for transmission of the QoS flows 856A-856C. After the packets are divided into QoS flows 856A-856C, the packet may be sent to UPF 805 (e.g., towards a DN) via the selected one or more N3 tunnels 850. The UPF 805 may verify that the QFIsof the uplink packets 812A-812EDocket No.: 25-1063PCTare aligned with the QoS rules 814 provided to the UE 801. The UPF 805 may measure and / or count packets and / or provide packet metrics to, for example, a PCF.

[0126] The figure also illustrates a process for downlink. In particular, one or more applications may generate downlink packets 852A-852E. The UPF 805 may receive downlink packets 852A-852E from one or more DNs and / or one or more other UPFs. As per the QoS model, UPF 805 may apply packet detection rules (PDRs) 854 to downlink packets 852A-852E. Based on PDRs 854, UPF 805 may map packets 852A-852E into QoS flows. In the present illustration, downlink packets 852A, 852B are mapped to QoS flow 856A, downlink packet 852C is mapped to QoS flow 856B, and the remaining packets are mapped to QoS flow 856C.

[0127] The QoS flows 856A-856C may be sent to AN 802. The AN 802 may apply resource mapping rules to the QoS flows 856A-856C. In the present illustration, QoS flow 856A is mapped to resource 820A, whereas QoS flows 856B, 856C are mapped to resource 820B. In order to meet QoS requirements, the resource mapping rules may designate more resources to high-priority QoS flows.

[0128] FIGS. 9A- 9D illustrate example states and state transitions of a wireless device (e.g., a UE). At any given time, the wireless device may have a radio resource control (RRC) state, a registration management (RM) state, and a connection management (CM) state.

[0129] FIG. 9A is an example diagram showing RRC state transitions of a wireless device (e.g., a UE). The UE maybe in one of three RRC states: RRC idle 910, (e.g., RRC JDLE), RRC inactive 920 (e.g., RRC -INACTIVE), or RRC connected 930 (e.g., RRC -CONNECTED). The UE may implement different RAN-related control-plane procedures depending on its RRC state. Other elements of the network, for example, a base station, may track the RRC state of one or more UEs and implement RAN-related control-plane procedures appropriate to the RRC state of each.

[0130] In RRC connected 930, it may be possible for the UE to exchange data with the network (for example, the base station). The parameters necessary for exchange of data may be established and known to both the UE and the network. The parameters may be referred to and / or included in an RRC context of the UE (sometimes referred to as a UE context). These parameters may include, for example: one or more AS contexts; one or more radio link configuration parameters; bearer configuration information (e.g., relating to a data radio bearer, signaling radio bearer, logical channel, QoS flow, and / or PDU session); security information; and / or PHY, MAC, RLC, PDCP, and / or SDAP layer configuration information. The base station with which the UE is connected may store the RRC context of the UE.

[0131] While in RRC connected 930, mobility of the UE may be managed by the access network, whereas the UE itself may manage mobility while in RRC idle 910 and / or RRC inactive 920. While in RRC connected 930, the UE may manage mobility by measuring signal levels (e.g., reference signal levels) from a serving cell and neighboring cells and reporting these measurements to the base station currently serving the UE. The network may initiate handover based on the reported measurements. The RRC state may transition from RRC connected 930 to RRC idle 910 through a connection release procedure 930 or to RRC inactive 920 through a connectionDocket No.: 25-1063PCTinactivation procedure 932.

[0132] In RRC idle 910, an RRC context may not be established for the UE. In RRC idle 910, the UE may not have an RRC connection with a base station. While in RRC idle 910, the UE may be in a sleep state for a majority of the time (e.g., to conserve battery power). The UE may wake up periodically (e.g. , once in every discontinuous reception cycle) to monitor for paging messages from the access network. Mobility of the UE may be managed by the UE through a procedure known as cell reselection. The RRC state may transition from RRC idle 910 to RRC connected 930 through a connection establishment procedure 913, which may involve a random access procedure, as discussed in greater detail below.

[0133] In RRC inactive 920, the RRC context previously established is maintained in the UE and the base station. This may allow for a fast transition to RRC connected 930 with reduced signaling overhead as compared to the transition from RRC idle 910 to RRC connected 930. The RRC state may transition to RRC connected 930 through a connection resume procedure 923. The RRC state may transition to RRC idle 910 though a connection release procedure 921 that may be the same as or similar to connection release procedure 931.

[0134] An RRC state may be associated with a mobility management mechanism. In RRC idle 910 and RRC inactive 920, mobility may be managed by the UE through cell reselection. The purpose of mobility management in RRC idle 910 and / or RRC inactive 920 is to allow the network to be able to notify the UE of an event via a paging message without having to broadcast the paging message over the entire mobile communications network. The mobility management mechanism used in RRC idle 910 and / or RRC inactive 920 may allow the network to track the UE on a cell-group level so that the paging message may be broadcast over the cells of the cell group that the UE currently resides within instead of the entire communication network. Tracking may be based on different granularities of grouping. For example, there may be three levels of cell-grouping granularity: individual cells; cells within a RAN area identified by a RAN area identifier (RAI); and cells within a group of RAN areas, referred to as a tracking area and identified by a tracking area identifier (TAI).

[0135] Tracking areas may be used to track the UE at the CN level. The CN may provide the UE with a list of TAIs associated with a UE registration area. If the UE moves, through cell reselection, to a cell associated with a TAI not included in the list of TAIs associated with the UE registration area, the UE may perform a registration update with the CN to allow the CN to update the UE's location and provide the UE with a new the UE registration area.

[0136] RAN areas may be used to track the UE at the RAN level For a UE in RRC inactive 920 state, the UE may be assigned a RAN notification area. A RAN notification area may comprise one or more cell identities, a list of RAIs, and / or a list of TAIs. In an example, a base station may belong to one or more RAN notification areas. In an example, a cell may belong to one or more RAN notification areas. If the UE moves, through cell reselection, to a cell not included in the RAN notification area assigned to the UE, the UE may perform a notification area update with the RAN to update the UE's RAN notification area

[0137] A base station storing an RRC context for a UE or a last serving base station of the UE may be referredDocket No.: 25-1063PCTto as an anchor base station. An anchor base station may maintain an RRC context for the UE at least during a period of time that the UE stays in a RAN notification area of the anchor base station and / or during a period of time that the UE stays in RRC inactive 920.

[0138] FIG. 9B is an example diagram showing registration management (RM) state transitions of a wireless device (e.g., a UE). The states are RM deregistered 940, (e.g., RM-DEREGISTERED) and RM registered 950 (e.g., RM-REGISTERED).

[0139] In RM deregistered 940, the UE is not registered with the network, and the UE is not reachable by the network. In order to be reachable by the network, the UE must perform an initial registration. As an example, the UE may register with an AMF of the network. If registration is rejected (registration reject 944), then the UE remains in RM deregistered 940. If registration is accepted (registration accept 945), then the UE transitions to RM registered 950. While the UE is RM registered 950, the network may store, keep, and / or maintain a UE context for the UE. The UE context may be referred to as wireless device context. The UE context corresponding to network registration (maintained by the core network) may be different from the RRC context corresponding to RRC state (maintained by an access network, .e.g., a base station). The UE context may comprise a UE identifier and a record of various information relating to the UE, for example, UE capability information, policy information for access and mobility management of the UE, lists of allowed or established slices or PDU sessions, and / or a registration area of the UE (i.e., a list of tracking areas covering the geographical area where the wireless device is likely to be found).

[0140] While the UE is RM registered 950, the network may store the UE context of the UE, and if necessary, use the UE context to reach the UE Moreover, some services may not be provided by the network unless the UE is registered. The UE may update its UE context while remaining in RM registered 950 (registration update accept 955). For example, if the UE leaves one tracking area and enters another tracking area, the UE may provide a tracking area identifier to the network. The network may deregister the UE, or the UE may deregister itself (deregistration 954). For example, the network may automatically deregister the wireless device if the wireless device is inactive for a certain amount of time. Upon deregistration, the UE may transition to RM deregistered 940.

[0141] FIG. 9C is an example diagram showing connection management (CM) state transitions of a wireless device (e.g., a UE), shown from a perspective of the wireless device. The UE may be in CM idle 960 (e.g., CM- IDLE) or CM connected 970 (e.g., CM-CONNECTED).

[0142] In CM idle 960, the UE does not have a non-access stratum (NAS) signaling connection with the network As a result, the UE cannot communicate with core network functions. The UE may transition to CM connected 970 by establishing an AN signaling connection (AN signaling connection establishment 967). This transition may be initiated by sending an initial NAS message. The initial NAS message may be a registration request (e.g., if the UE is RM deregistered 940) or a service request (e.g., if the UE is RM registered 950). If the UE is RM registered 950, then the UE may initiate the AN signaling connection establishment by sending a service request, or the network may send a page, thereby triggering the UE to send the service request.Docket No.: 25-1063PCT

[0143] In CM connected 970, the UE can communicate with core network functions using NAS signaling. As an example, the UE may exchange NAS signaling with an AMF for registration management purposes, service request procedures, and / or authentication procedures. As another example, the UE may exchange NAS signaling, with an SMF, to establish and / or modify a PDU session. The network may disconnect the UE, or the UE may disconnect itself (AN signaling connection release 976). For example, if the UE transitions to RM deregistered 940, then the UE may also transition to CM idle 960. When the UE transitions to CM idle 960, the network may deactivate a user plane connection of a PDU session of the UE.

[0144] FIG. 9D is an example diagram showing CM state transitions of the wireless device (e.g., a UE), shown from a network perspective (e.g., an AMF). The CM state of the UE, as tracked by the AMF, may be in CM idle 980 (e.g., CM-IDLE) or CM connected 990 (e.g., CM-CONNECTED). When the UE transitions from CM idle 980 to CM connected 990, the AMF may establish an N2 context of the UE (N2 context establishment 989). When the UE transitions from CM connected 990 to CM idle 980, the AMF may release the N2 context of the UE (N2 context release 998).

[0145] FIGS. 10-12 illustrate example procedures for registering, service request, and PDU session establishment of a UE.

[0146] FIG. 10 illustrates an example of a registration procedure for a wireless device (e.g., a UE). Based on the registration procedure, the UE may transition from, for example, RM deregistered 940 to RM registered 950.

[0147] Registration may be initiated by a UE for the purposes of obtaining authorization to receive services, enabling mobility tracking, enabling reachability, or other purposes. The UE may perform an initial registration as a first step toward connection to the network (for example, if the UE is powered on, airplane mode is turned off, etc.) Registration may also be performed periodically to keep the network informed of the UE’s presence (for example, while in CM-IDLE state), or in response to a change in UE capability or registration area. Deregistration (not shown in FIG. 10) may be performed to stop network access.

[0148] At 1010, the UE transmits a registration request to an AN. As an example, the UE may have moved from a coverage area of a previous AMF (illustrated as AMF#1) into a coverage area of a new AMF (illustrated as AMF#2). The registration request maybe a NAS message. The registration request may include a UE identifier. The AN may select an AMF for registration of the UE. For example, the AN may select a default AMF. For example, the AN may select an AMF that is already mapped to the UE (e.g., a previous AMF). The NAS registration request may include a network slice identifier and the AN may select an AMF based on the requested slice. After the AMF is selected, the AN may send the registration request to the selected AMF.

[0149] At 1020, the AMF that receives the registration request (AMF#2) performs a context transfer. The context may be a UE context, for example, an RRC context for the UE. As an example, AMF#2 may send AM F#1 a message requesting a context of the UE. The message may include the UE identifier. The message may be a Namf_ Communication, UEContextTransfer message. AMF#1 may send to AMF#2 a message that includes the requested UE context. This message may be a Namf_ Communication, UEContextTransfer message. After theDocket No.: 25-1063PCTUE context is received, the AMFS2 may coordinate authentication of the UE. After authentication is complete, AMF#2 may send to AM F#1 a message indicating that the UE context transfer is complete This message may be a Namf_ Communication- UEContextTransfer Response message.

[0150] Authentication may require participation of the UE, an AUSF, a UDM and / or a UDR (not shown). For example, the AMF may request that the AUSF authenticate the UE. For example, the AUSF may execute authentication of the UE. For example, the AUSF may get authentication data from UDM. For example, the AUSF may send a subscription permanent identifier (SUPI) to the AMF based on the authentication being successful. For example, the AUSF may provide an intermediate key to the AMF. The intermediate key may be used to derive an access-specific security key for the UE, enabling the AMF to perform security context management (SCM). The AUSF may obtain subscription data from the UDM. The subscription data may be based on information obtained from the UDM (and / or the UDR). The subscription data may include subscription identifiers, security credentials, access and mobility related subscription data and / or session related data.

[0151] At 1030, the new AMF, AMF#2, registers and / or subscribes with the UDM. AMF#2 may perform registration using a UE context management service of the UDM (Nudm_ UECM). AMF#2 may obtain subscription information of the UE using a subscriber data management service of the UDM (Nudm_ SDM). AMF#2 may further request that the UDM notify AMF#2 if the subscription information of the UE changes. As the new AMF registers and subscribes, the old AMF, AMF#1, may deregister and unsubscribe. After deregistration, AMF#1 is free of responsibility for mobility management of the UE.

[0152] At 1040, AMF#2 retrieves access and mobility (AM) policies from the PDF. As an example, the AMF#2 may provide subscription data of the UE to the PDF. The PCF may determine access and mobility policies for the UE based on the subscription data, network operator data, current network conditions, and / or other suitable information. For example, the owner of a first UE may purchase a higher level of service than the owner of a second UE. The PCF may provide the rules associated with the different levels of service. Based on the subscription data of the respective UEs, the network may apply different policies which facilitate different levels of service.

[0153] For example, access and mobility policies may relate to service area restrictions, RAT / frequency selection priority (RFSP, where RAT stands for radio access technology), authorization and prioritization of access type (e.g., LTE versus NR), and / or selection of non-3GPP access (e.g., Access Network Discovery and Selection Policy (AN DSP)). The service area restrictions may comprise a list of tracking areas where the UE is allowed to be served (or forbidden from being served). The access and mobility policies may include a UE route selection policy (URSP)) that influences routing to an established PDU session or a new PDU session. As noted above, different policies may be obtained and / or enforced based on subscription data of the UE, location of the UE (i.e., location of the AN and / or AMF), or other suitable factors.

[0154] At 1050, AMF#2 may update a context of a PDU session. For example, if the UE has an existing PDU session, the AMF#2 may coordinate with an SMF to activate a user plane connection associated with the existingDocket No.: 25-1063PCTPDU session. The SMF may update and / or release a session management context of the PDU session (Nsmf_PDUSession_UpdateSMContext, Nsmf_ PDUSession_ ReleaseSMContext).

[0155] At 1060, AMF#2 sends a registration accept message to the AN, which forwards the registration accept message to the UE. The registration accept message may include a new UE identifier and / or a new configured slice identifier. The UE may transmit a registration complete message to the AN, which forwards the registration complete message to the AMF#2. The registration complete message may acknowledge receipt of the new UE identifier and / or new configured slice identifier.

[0156] At 1070, AMF#2 may obtain UE policy control information from the PCF. The PCF may provide an access network discovery and selection policy (ANDSP) to facilitate non-3GPP access. The PCF may provide a UE route selection policy (URSP) to facilitate mapping of particular data traffic to particular PDU session connectivity parameters. As an example, the URSP may indicate that data traffic associated with a particular application should be mapped to a particular SSC mode, network slice, PDU session type, or preferred access type (3GPP or non- 3GPP).

[0157] FIG. 11 illustrates an example of a service request procedure for a wireless device (e.g., a UE). The service request procedure depicted in FIG. 11 is a network-triggered service request procedure for a UE in a CM- IDLE state. However, other service request procedures (e.g., a UE-triggered service request procedure) may also be understood by reference to FIG. 11 , as will be discussed in greater detail below.

[0158] At 1110, a UPF receives data. The data may be downlink data for transmission to a UE. The data may be associated with an existing PDU session between the UE and a DN. The data may be received, for example, from a DN and / or another UPF. The UPF may buffer the received data. In response to the receiving of the data, the UPF may notify an SMF of the received data. The identity of the SMF to be notified may be determined based on the received data. The notification may be, for example, an N4 session report. The notification may indicate that the UPF has received data associated with the UE and / or a particular PDU session associated with the UE. In response to receiving the notification, the SMF may send PDU session information to an AMF. The PDU session information maybe sent in an N1N2 message transfer for forwarding to an AN. The PDU session information may include, for example, UPF tunnel endpoint information and / or QoS information.

[0159] At 1120, the AMF determines that the UE is in a CM-IDLE state. The determining at 1120 may be in response to the receiving of the PDU session information. Based on the determination that the UE is CM-IDLE, the service request procedure may proceed to 1130 and 1140, as depicted in FIG. 11. However, if the UE is not CM- IDLE (e.g., the UE is CM-CONNECTED), then 1130 and 1140 may be skipped, and the service request procedure may proceed directly to 1150.

[0160] At 1130, the AMF pages the UE. The paging at 1130 may be performed based on the UE being CM- IDLE. To perform the paging, the AMF may send a page to the AN. The page may be referred to as a paging or a paging message. The page may be an N2 request message. The AN may be one of a plurality of ANs in a RAN notification area of the UE. The AN may send a page to the UE. The UE may be in a coverage area of the AN andDocket No.: 25-1063PCTmay receive the page.

[0161] At 1140, the UE may request service. The UE may transmit a service request to the AMF via the AN As depicted in FIG. 11, the UE may request service at 1140 in response to receiving the paging at 1130. However, as noted above, this is for the specific case of a network-triggered service request procedure. In some scenarios (for example, if uplink data becomes available at the UE), then the UE may commence a UE-triggered service request procedure. The UE-triggered service request procedure may commence starting at 1140.

[0162] At 1150, the network may authenticate the UE. Authentication may require participation of the UE, an AUSF, and / or a UDM, for example, similar to authentication described elsewhere in the present disclosure. In some cases (for example, if the UE has recently been authenticated), the authentication at 1150 may be skipped.

[0163] At 1160, the AMF and SMF may perform a PDU session update. As part of the PDU session update, the SMF may provide the AMF with one or more UPF tunnel endpoint identifiers In some cases (not shown in FIG.11), it may be necessary for the SMF to coordinate with one or more other SMFs and / or one or more other UPFs to set up a user plane.

[0164] At 1170, the AMF may send PDU session information to the AN. The PDU session information may be included in an N2 request message. Based on the PDU session information, the AN may configure a user plane resource for the UE. To configure the user plane resource, the AN may, for example, perform an RRC reconfiguration of the UE. The AN may acknowledge to the AMF that the PDU session information has been received. The AN may notify the AMF that the user plane resource has been configured, and / or provide information relating to the user plane resource configuration.

[0165] In the case of a UE-triggered service request procedure, the UE may receive, at 1170, a NAS service accept message from the AMF via the AN. After the user plane resource is configured, the UE may transmit uplink data (for example, the uplink data that caused the UE to trigger the service request procedure).

[0166] At 1180, the AMF may update a session management (SM) context of the PDU session. For example, the AMF may notify the SMF (and / or one or more other associated SMFs) that the user plane resource has been configured, and / or provide information relating to the user plane resource configuration. The AMF may provide the SMF (and / or one or more other associated SMFs) with one or more AN tunnel endpoint identifiers of the AN. After the SM context update is complete, the SMF may send an update SM context response message to the AMF.

[0167] Based on the update of the session management context, the SMF may update a PDF for purposes of policy control. For example, if a location of the UE has changed, the SMF may notify the PCF of the UE's a new location.

[0168] Based on the update of the session management context, the SMF and UPF may perform a session modification. The session modification may be performed using N4 session modification messages. After the session modification is complete, the UPF may transmit downlink data (for example, the downlink data that caused the UPF to trigger the network-triggered service request procedure) to the UE. The transmitting of the downlink data may be based on the one or more AN tunnel endpoint identifiers of the AN.Docket No.: 25-1063PCT

[0169] FIG. 12 illustrates an example of a protocol data unit (PDU) session establishment procedure for a wireless device (e.g., a UE). The UE may determine to transmit the PDU session establishment request to create a new PDU session, to hand over an existing PDU session to a 3GPP network, or for any other suitable reason.

[0170] At 1210, the UE initiates PDU session establishment. The UE may transmit a PDU session establishment request to an AMP via an AN. The PDU session establishment request may be a NAS message. The PDU session establishment request may indicate: a PDU session ID; a requested PDU session type (new or existing); a requested DN (DNN); a requested network slice (S-NSSAI); a requested SSC mode; and / or any other suitable information. The PDU session ID may be generated by the UE. The PDU session type may be, for example, an Internet Protocol (IP)-based type (e.g., IPv4, IPv6, or dual stack IPv4 / IPv6), an Ethernet type, or an unstructured type.

[0171] The AMF may select an SME based on the PDU session establishment request. In some scenarios, the requested PDU session may already be associated with a particular SME. For example, the AMF may store a UE context of the UE, and the UE context may indicate that the PDU session ID of the requested PDU session is already associated with the particular SMF. In some scenarios, the AMF may select the SMF based on a determination that the SMF is prepared to handle the requested PDU session. For example, the requested PDU session may be associated with a particular DNN and / or S-NSSAI, and the SMF may be selected based on a determination that the SMF can manage a PDU session associated with the particular DNN and / or S-NSSAI.

[0172] At 1220, the network manages a context of the PDU session. After selecting the SMF at 1210, the AMF sends a PDU session context request to the SMF. The PDU session context request may include the PDU session establishment request received from the UE at 1210 The PDU session context request may be a Nsmf_ PDUSession_CreateSMContext Request and / or a Nsmf_PDUSession_UpdateSMContext Request. The PDU session context request may indicate identifiers of the UE; the requested DN; and / or the requested network slice. Based on the PDU session context request, the SMF may retrieve subscription data from a UDM. The subscription data may be session management subscription data of the UE. The SMF may subscribe for updates to the subscription data, so that the PCF will send new information if the subscription data of the UE changes. After the subscription data of the UE is obtained, the SMF may transmit a PDU session context response to the AMG. The PDU session context response may be a Nsmf_ PDUSession_ CreateSMContext Response and / or a Nsmf_PDUSession_UpdateSMContext Response. The PDU session context response may include a session management context ID.

[0173] At 1230, secondary authorization / authentication may be performed, if necessary. The secondary authorization / authentication may involve the UE, the AMF, the SMF, and the DN. The SMF may access the DN via a Data Network Authentication, Authorization and Accounting (DN AAA) server.

[0174] At 1240, the network sets up a data path for uplink data associated with the PDU session. The SMF may select a PCF and establish a session management policy association. Based on the association, the PCF may provide an initial set of policy control and charging rules (PCC rules) for the PDU session. When targeting aDocket No.: 25-1063PCTparticular PDU session, the PCF may indicate, to the SMF, a method for allocating an IP address to the PDU Session, a default charging method for the PDU session, an address of the corresponding charging entity, triggers for requesting new policies, etc. The PCF may also target a service data flow (SDF) comprising one or more PDU sessions. When targeting an SDF, the PCF may indicate, to the SMF, policies for applying QoS requirements, monitoring traffic (e.g . , for charging purposes), and / or steering traffic (e.g., by using one or more particular N6 interfaces).

[0175] The SMF may determine and / or allocate an IP address for the PDU session. The SMF may select one or more UPFs (a single UPF in the example of FIG. 12) to handle the PDU session. The SMF may send an N4 session message to the selected UPF. The N4 session message may be an N4 Session Establishment Request and / or an N4 Session Modification Request. The N4 session message may include packet detection, enforcement, and reporting rules associated with the PDU session. In response, the UPF may acknowledge by sending an N4 session establishment response and / or an N4 session modification response.

[0176] The SMF may send PDU session management information to the AMF. The PDU session management information may be a session service request (e.g., Namf_Communication_N1 N2MessageTransfer) message. The PDU session management information may include the PDU session ID. The PDU session management information may be a NAS message. The PDU session management information may include N1 session management information and / or N2 session management information. The N1 session management information may include a PDU session establishment accept message. The PDU session establishment accept message may include tunneling endpoint information of the UPF and quality of service (QoS) information associated with the PDU session.

[0177] The AMF may send an N2 request to the AN. The N2 request may include the PDU session establishment accept message. Based on the N2 request, the AN may determine AN resources for the UE. The AN resources may be used by the UE to establish the PDU session, via the AN, with the DN. The AN may determine resources to be used for the PDU session and indicate the determined resources to the UE. The AN may send the PDU session establishment accept message to the UE. For example, the AN may perform an RRC reconfiguration of the UE. After the AN resources are set up, the AN may send an N2 request acknowledge to the AMF. The N2 request acknowledge may include N2 session management information, for example, the PDU session ID and tunneling endpoint information of the AN.

[0178] After the data path for uplink data is set up at 1240, the UE may optionally send uplink data associated with the PDU session. As shown in FIG. 12, the uplink data may be sent to a DN associated with the PDU session via the AN and the UPF.

[0179] At 1250, the network may update the PDU session context. The AMF may transmit a PDU session context update request to the SMF. The PDU session context update request may be a Nsmf_PDUSession_UpdateSMContext Request. The PDU session context update request may include the N2 session management information received from the AN. The SMF may acknowledge the PDU session contextDocket No.: 25-1063PCTupdate. The acknowledgement may be a Nsmf_PDUSession_UpdateSMContext Response. The acknowledgement may include a subscription requesting that the SMF be notified of any UE mobility event. Based on the PDU session context update request, the SMF may send an N4 session message to the UPF. The N4 session message may be an N4 Session Modification Request. The N4 session message may include tunneling endpoint information of the AN. The N4 session message may include forwarding rules associated with the PDU session. In response, the UPF may acknowledge by sending an N4 session modification response.

[0180] After the UPF receives the tunneling endpoint information of the AN, the UPF may relay downlink data associated with the PDU session. As shown in FIG. 12, the downlink data maybe received from a DN associated with the PDU session via the AN and the UPF.

[0181] FIG. 13 illustrates examples of components of the elements in a communications network. FIG. 13 includes a wireless device 1310, a base station 1320, and a physical deployment of one or more network functions 1330 (henceforth "deployment 1330”). Any wireless device described in the present disclosure may have similar components and may be implemented in a similar manner as the wireless device 1310. Any other base station described in the present disclosure (or any portion thereof, depending on the architecture of the base station) may have similar components and may be implemented in a similar manner as the base station 1320. Any physical core network deployment in the present disclosure (or any portion thereof, depending on the architecture of the base station) may have similar components and may be implemented in a similar manner as the deployment 1330.

[0182] The wireless device 1310 may communicate with base station 1320 over an air interface 1370. The communication direction from wireless device 1310 to base station 1320 over air interface 1370 is known as uplink, and the communication direction from base station 1320 to wireless device 1310 over air interface 1370 is known as downlink. Downlink transmissions may be separated from uplink transmissions using FDD, TDD, and / or some combination of duplexing techniques. FIG. 13 shows a single wireless device 1310 and a single base station 1320, but it will be understood that wireless device 1310 may communicate with any number of base stations or other access network components over air interface 1370, and that base station 1320 may communicate with any number of wireless devices over air interface 1370.

[0183] The wireless device 1310 may comprise a processing system 1311 and a memory 1312. The memory 1312 may comprise one or more computer-readable media, for example, one or more non-transitory computer readable media. The memory 1312 may include instructions 1313. The processing system 1311 may process and / or execute instructions 1313. Processing and / or execution of instructions 1313 may cause wireless device 1310 and / or processing system 1311 toperform one or more functions or activities. The memory 1312 may include data (not shown). One of the functions or activities performed by processing system 1311 may be to store data in memory 1312 and / or retrieve previously-stored data from memory 1312. In an example, downlink data received from base station 1320 may be stored in memory 1312, and uplink data for transmission to base station 1320 may be retrieved from memory 1312. As illustrated in FIG. 13, the wireless device 1310 may communicate with base station 1320 using a transmission processing system 1314 and / or a reception processing system 1315.Docket No.: 25-1063PCTAlternatively, transmission processing system 1314 and reception processing system 1315 may be implemented as a single processing system, or both may be omitted and all processing in the wireless device 1310 may be performed by the processing system 1311. Although not shown in FIG. 13, transmission processing system 1314 and / or reception processing system 1315 may be coupled to a dedicated memory that is analogous to but separate from memory 1312, and comprises instructions that may be processed and / or executed to carry out one or more of their respective functionalities. The wireless device 1310 may comprise one or more antennas 1316 to access air interface 1370.

[0184] The wireless device 1310 may comprise one or more other elements 1319. The one or more other elements 1319 may comprise software and / or hardware that provide features and / or functionalities, for example, a speaker, a microphone, a keypad, a display, a touchpad, a satellite transceiver, a universal serial bus (USB) port, a hands-free headset, a frequency modulated (FM) radio unit, a media player, an Internet browser, an electronic control unit (e.g., for a motor vehicle), and / or one or more sensors (e.g., an accelerometer, a gyroscope, a temperature sensor, a radar sensor, a lidar sensor, an ultrasonic sensor, a light sensor, a camera, a global positioning sensor (GPS) and / or the like). The wireless device 1310 may receive user input data from and / or provide user output data to the one or more one or more other elements 1319. The one or more other elements 1319 may comprise a power source. The wireless device 1310 may receive power from the power source and may be configured to distribute the power to the other components in wireless device 1310. The power source may comprise one or more sources of power, for example, a battery, a solar cell, a fuel cell, or any combination thereof.

[0185] The wireless device 1310 may transmit uplink data to and / or receive downlink data from base station 1320 via air interface 1370. To perform the transmission and / or reception, one or more of the processing system 1311, transmission processing system 1314, and / or reception system 1315 may implement open systems interconnection (OSI) functionality. As an example, transmission processing system 1314 and / or reception system 1315 may perform layer 1 OSI functionality, and processing system 1311 may perform higher layer functionality. The wireless device 1310 may transmit and / or receive data over air interface 1370 using one or more antennas 1316. For scenarios where the one or more antennas 1316 include multiple antennas, the multiple antennas may be used to perform one or more multi-antenna techniques, such as spatial multiplexing (e.g., single-user multipleinput multiple output (MIMO) or multi-user MIMO), transmit / receive diversity, and / or beamforming.

[0186] The base station 1320 may comprise a processing system 1321 and a memory 1322. The memory 1322 may comprise one or more computer-readable media, for example, one or more non-transitory computer readable media. The memory 1322 may include instructions 1323. The processing system 1321 may process and / or execute instructions 1323. Processing and / or execution of instructions 1323 may cause base station 1320 and / or processing system 1321 to perform one or more functions or activities. The memory 1322 may include data (not shown). One of the functions or activities performed by processing system 1321 may be to store data in memory 1322 and / or retrieve previously-stored data from memory 1322. The base station 1320 may communicate with wireless device 1310 using a transmission processing system 1324 and a reception processing system 1325.Docket No.: 25-1063PCTAlthough not shown in FIG. 13, transmission processing system 1324 and / or reception processing system 1325 may be coupled to a dedicated memory that is analogous to but separate from memory 1322, and comprises instructions that may be processed and / or executed to carry out one or more of their respective functionalities. The wireless device 1320 may comprise one or more antennas 1326 to access air interface 1370.

[0187] The base station 1320 may transmit downlink data to and / or receive uplink data from wireless device 1310 via air interface 1370. To perform the transmission and / or reception, one or more of the processing system 1321, transmission processing system 1324, and / or reception system 1325 may implement OSI functionality. As an example, transmission processing system 1324 and / or reception system 1325 may perform layer 1 OSI functionality, and processing system 1321 may perform higher layer functionality. The base station 1320 may transmit and / or receive data over air interface 1370 using one or more antennas 1326. For scenarios where the one or more antennas 1326 include multiple antennas, the multiple antennas may be used to perform one or more multi-antenna techniques, such as spatial multiplexing (e.g., single-user multiple-input multiple output (MIMO) or multi-user MIMO), transmit / receive diversity, and / or beamforming.

[0188] The base station 1320 may comprise an interface system 1327. The interface system 1327 may communicate with one or more base stations and / or one or more elements of the core network via an interface 1380. The interface 1380 may be wired and / or wireless and interface system 1327 may include one or more components suitable for communicating via interface 1380. In FIG. 13, interface 1380 connects base station 1320 to a single deployment 1330, but it will be understood that wireless device 1310 may communicate with any number of base stations and / or CN deployments over interface 1380, and that deployment 1330 may communicate with any number of base stations and / or other CN deployments over interface 1380. The base station 1320 may comprise one or more other elements 1329 analogous to one or more of the one or more other elements 1319.

[0189] The deployment 1330 may comprise any number of portions of any number of instances of one or more network functions (NFs). The deployment 1330 may comprise a processing system 1331 and a memory 1332. The memory 1332 may comprise one or more computer-readable media, for example, one or more non-transitory computer readable media. The memory 1332 may include instructions 1333. The processing system 1331 may process and / or execute instructions 1333. Processing and / or execution of instructions 1333 may cause the deployment 1330 and / or processing system 1331 to perform one or more functions or activities. The memory 1332 may include data (not shown). One of the functions or activities performed by processing system 1331 may be to store data in memory 1332 and / or retrieve previously-stored data from memory 1332. The deployment 1330 may access the interface 1380 using an interface system 1337. The deployment 1330 may comprise one or more other elements 1339 analogous to one or more of the one or more other elements 1319.

[0190] One or more of the systems 1311, 1314, 1315, 1321, 1324, 1325, and / or 1331 may comprise one or more controllers and / or one or more processors. The one or more controllers and / or one or more processors may comprise, for example, a general-purpose processor, a digital signal processor (DSP), a microcontroller, an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) and / or other programmableDocket No.: 25-1063PCTlogic device, discrete gate and / or transistor logic, discrete hardware components, an on-board unit, or any combination thereof. One or more of the systems 1311, 1314, 1315, 1321, 1324, 1325, and / or 1331 mayperform signal coding / processing, data processing, power control, input / output processing, and / or any other functionality that may enable wireless device 1310, base station 1320, and / or deployment 1330 to operate in a mobile communications system.

[0191] Many of the elements described in the disclosed embodiments may be implemented as modules. A module is defined here as an element that performs a defined function and has a defined interface to other elements. The modules described in this disclosure may be implemented in hardware, software in combination with hardware, firmware, wetware (e.g. hardware with a biological element) ora combination thereof, which may be behaviorally equivalent. For example, modules may be implemented as a software routine written in a computer language configured to be executed by a hardware machine (such as C, C++, Fortran, Java, Basic, Matlab and / or the like) or a modeling / simulation program such as Simulink, Stateflow, GNU Octave, or LabVI E WMathScript. It may be possible to implement modules using physical hardware that incorporates discrete or programmable analog, digital and / or quantum hardware. Examples of programmable hardware comprise computers, microcontrollers, microprocessors, DSPs, ASICs, FPGAs, and complex programmable logic devices (CPLDs). Computers, microcontrollers and microprocessors may be programmed using languages such as assembly, C, C++ and / or the like. FPGAs, ASICs and CPLDs are often programmed using hardware description languages (HDL) such as VHSIC hardware description language (VHDL) or Verilog that configure connections between internal hardware modules with lesser functionality on a programmable device. The mentioned technologies are often used in combination to achieve the result of a functional module.

[0192] The wireless device 1310, base station 1320, and / or deployment 1330 may implement timers and / or counters. A timer / counter may start at an initial value. As used herein, starting may comprise restarting. Once started, the timer / counter may run. Running of the timer / counter may be associated with an occurrence. When the occurrence occurs, the value of the timer / counter may change (for example, increment or decrement). The occurrence may be, for example, an exogenous event (for example, a reception of a signal, a measurement of a condition, etc.), an endogenous event (for example, a transmission of a signal, a calculation, a comparison, a performance of an action or a decision to so perform, etc.), or any combination thereof. In the case of a timer, the occurrence may be the passage of a particular amount of time. However, it will be understood that a timer may be described and / or implemented as a counter that counts the passage of a particular unit of time. A timer / counter may run in a direction of a final value until it reaches the final value. The reaching of the final value may be referred to as expiration of the timer / counter. The final value may be referred to as a threshold. A timer / counter may be paused, wherein the present value of the timer / counter is held, maintained, and / or carried over, even upon the occurrence of one or more occurrences that would otherwise cause the value of the timer / counter to change. The timer / counter may be un-paused or continued, wherein the value that was held, maintained, and / or carried over begins changing again when the one or more occurrence occur. A timer / counter may be set and / or reset. As usedDocket No.: 25-1063PCTherein, setting may comprise resetting. When the timer / counter sets and / or resets, the value of the timer / counter may be set to the initial value. A timer / counter may be started and / or restarted. As used herein, starting may comprise restarting. In some embodiments, when the timer / counter restarts, the value of the timer / counter may be set to the initial value and the timer / counter may begin to run.

[0193] FIGS. 14A, 14B, 14C, and 14D illustrate various example arrangements of physical core network deployments, each having one or more network functions or portions thereof. The core network deployments comprise a deployment 1410, a deployment 1420, a deployment 1430, a deployment 1440, and / or a deployment 1450. Each deployment may be analogous to, for example, the deployment 1330 depicted in FIG. 13. In particular, each deployment may comprise a processing system for performing one or more functions or activities, memory for storing data and / or instructions, and an interface system for communicating with other network elements (for example, other core network deployments). Each deployment may comprise one or more network functions (NFs). The term NF may refer to a particular set of functionalities and / or one or more physical elements configured to perform those functionalities (e.g., a processing system and memory comprising instructions that, when executed by the processing system, cause the processing system to perform the functionalities). For example, in the present disclosure, when a network function is described as performing X, Y, and Z, it will be understood that this refers to the one or more physical elements configured to perform X, Y, and Z, no matter how or where the one or more physical elements are deployed. The term NF may refer to a network node, network element, and / or network device.

[0194] As will be discussed in greater detail below, there are many different types of NF and each type of NF may be associated with a different set of functionalities. A plurality of different NFs may be flexibly deployed at different locations (for example, in different physical core network deployments) or in a same location (for example, co-located in a same deployment). A single NF may be flexibly deployed at different locations (implemented using different physical core network deployments) or in a same location. Moreover, physical core network deployments may also implement one or more base stations, application functions (AFs), data networks (DNs), or any portions thereof. NFs may be implemented in many ways, including as network elements on dedicated or shared hardware, as software instances running on dedicated or shared hardware, or as virtualized functions instantiated on a platform (e.g., a cloud-based platform).

[0195] FIG. 14A illustrates an example arrangement of core network deployments in which each deployment comprises one network function. A deployment 1410 comprises an NF 1411, a deployment 1420 comprises an NF 1421, and a deployment 1430 comprises an NF 1431. The deployments 1410, 1420, 1430 communicate via an interface 1490. The deployments 1410, 1420, 1430 may have different physical locations with different signal propagation delays relative to other network elements. The diversity of physical locations of deployments 1410, 1420, 1430 may enable provision of services to a wide area with improved speed, coverage, security, and / or efficiency.

[0196] FIG. 14B illustrates an example arrangement wherein a single deployment comprises more than one NF.Docket No.: 25-1063PCTUnlike FIG. 14A, where each NF is deployed in a separate deployment, FIG. 14B illustrates multiple NFs in deployments 1410, 1420. In an example, deployments 1410, 1420 may implement a software-defined network (SDN) and / or a network function virtualization (NFV).

[0197] For example, deployment 1410 comprises an additional network function, NF 1411A. The NFs 1411, 1411A may consist of multiple instances of the same NF type, co-located at a same physical location within the same deployment 1410. The NFs 1411, 1411A maybe implemented independently from one another (e.g., isolated and / or independently controlled). For example, the NFs 1411, 1411A may be associated with different network slices. A processing system and memory associated with the deployment 1410 may perform all of the functionalities associated with the NF 1411 in addition to all of the functionalities associated with the NF 1411 A. In an example, NFs 1411, 1411A may be associated with different PLMNs, but deployment 1410, which implements NFs 1411, 1411 A, maybe owned and / or operated by a single entity.

[0198] Elsewhere in FIG. 14B, deployment 1420 comprises NF 1421 and an additional network function, NF 1422. The NFs 1421, 1422 maybe different NF types. Similar to NFs 1411, 1411A, the NFs 1421, 1422 maybe co-located within the same deployment 1420, but separately implemented. As an example, a first PLMN may own and / or operate deployment 1420 having NFs 1421, 1422. As another example, the first PLMN may implement NF 1421 and a second PLMN may obtain from the first PLMN (e.g., rent, lease, procure, etc.) at least a portion of the capabilities of deployment 1420 (e.g., processing power, data storage, etc.) in order to implement NF 1422. As yet another example, the deployment may be owned and / or operated by one or more third parties, and the first PLMN and / or second PLMN may procure respective portions of the capabilities of the deployment 1420. When multiple NFs are provided at a single deployment, networks may operate with greater speed, coverage, security, and / or efficiency.

[0199] FIG. 14C illustrates an example arrangement of core network deployments in which a single instance of an NF is implemented using a plurality of different deployments. In particular, a single instance of NF 1422 is implemented at deployments 1420, 1440. As an example, the functionality provided by NF 1422 maybe implemented as a bundle or sequence of subservices. Each subservice may be implemented independently, for example, ata different deployment. Each subservices may be implemented in a different physical location. By distributing implementation of subservices of a single NF across different physical locations, the mobile communications network may operate with greater speed, coverage, security, and / or efficiency.

[0200] FIG. 14D illustrates an example arrangement of core network deployments in which one or more network functions are implemented using a data processing service. In FIG. 14D, NFs 1411, 1411 A, 1421, 1422 are included in a deployment 1450 that is implemented as a data processing service. The deployment 1450 may comprise, for example, a cloud network and / or data center. The deployment 1450 may be owned and / or operated by a PLMN or by a non-PLMN third party. The NFs 1411, 1411A, 1421, 1422 that are implemented using the deployment 1450 may belong to the same PLMN or to different PLMNs. The PLMN(s) may obtain (e.g., rent, lease, procure, etc.) at least a portion of the capabilities of the deployment 1450 (e.g., processing power, data storage,Docket No.: 25-1063PCTetc.). By providing one or more NFs using a data processing service, the mobile communications network may operate with greater speed, coverage, security, and / or efficiency.

[0201] As shown in the figures, different network elements (e.g., NFs) may be located in different physical deployments, or co-located in a single physical deployment. It will be understood that in the present disclosure, the sending and receiving of messages among different network elements is not limited to inter-deployment transmission or intra-deployment transmission, unless explicitly indicated.

[0202] In an example, a deployment may be a ‘black box’ that is preconfigured with one or more NFs and preconfigured to communicate, in a prescribed manner, with other 'black box' deployments (e.g., via the interface 1490). Additionally, or alternatively, a deployment may be configured to operate in accordance with open-source instructions (e.g., software) designed to implement NFs and communicate with other deployments in a transparent manner. The deployment may operate in accordance with open RAN (O-RAN) standards.

[0203] FIG. 15 illustrates an example of ambient internet-of-thing (AloT) communications as per an aspect of an embodiment of the present disclosure. The AloT communications may comprise communication(s) between a reader and an AloT device. AloT may be interchangeable with A-loT.

[0204] The reader may comprise a base station (AN 102 in FIG. 1A, gNB 152A in FIG. 1B). The reader may comprise a wireless device (e.g., Wireless device 101 in FIG. 1A, UE 151 in FIG. 1B).

[0205] An AloT device may refer to a device (e.g., wireless device) and / or a thing with sensors, processing ability, software and other technologies that connect and exchange data with other devices and systems (e.g., reader) over communications networks (e.g., AN 102, CN 105). An AloT device may be low-cost and self-powered device.

[0206] An AloT device may be referred to as an ambient intelligence device, an ambient power-enabled loT device, an ambient computing device, and / or the like. The AloT device may comprise a hardware, e.g., a sensor, actuator, gadget, appliance, or machine, that may be programmed for certain applications. The AloT device may be a smart watch, smart eyewear, smart refrigerator, smart door lock, and so on. The AloT device may be battery- free based on energy harvested from ambient sources.

[0207] In the AloT communications, multiple readers may communicate with one or more AloT devices. For example, in FIG. 15, Reader 1 and Reader 2 communicate with AloT device 1. In the AloT communications, a reader may communicate with one or more AloT devices. For example, in FIG. 15, Reader 2 communicates with AloT device 1 and AloT device 2.

[0208] A communication channel from a reader to an AloT device may be referred to as a reader-to-device channel (e.g., R2D channel), AloT downlink channel, a sidelink channel from a reader to an AloT device, a R2D sidelink channel, and / or the like. In the present disclosure, for a sake of simplicity, a communication channel from a reader to an AloT device may be referred to as an R2D channel.

[0209] A communication channel from an AloT device to a reader may be referred to as a device-to-reader channel (e.g., D2R channel), AloT uplink channel, a sidelink channel from an AloT device to a reader, a D2RDocket No.: 25-1063PCTchannel, and / or the like. In the present disclosure, for a sake of simplicity, a communication channel from an AloT device to a reader may be referred to as a D2R channel.

[0210] An AloT device may refer to a device primarily or substantially powered by harvesting energy from one or more viable ambient loT energy sources. The AloT device may be battery-less or with limited energy storage capability (e.g., using a capacitor). The one or more viable ambient loT energy sources may comprise radio waves (e.g., radio frequency (RF) wave). The one or more viable ambient loT energy sources may comprise light, motion, heat, or any other suitable power sources.

[0211] An AloT device may harvest the energy from radio waves. The AloT device may receive, from a reader or energy source (e.g., RF emitter), a radio wave (e.g., carrier wave). The AloT device may store the harvested energy in an energy storage. The AloT device may use the harvested energy for transmitting a signal to the reader via D2R channel(s). For example, the AloT device may transmit, to the reader, a reflected (e.g., backscatter) signal using the power converted from the harvested energy.

[0212] An AloT device may employ, use, transmit, trigger, initiate, and / or perform a transmission of a backscatter signal. The backscatter signal or backscatter transmission may be referred to as ambient backscatter, bistatic communication, and / or the like. Transmitting a backscatter signal may comprise reflecting, by the AloT device, waves, particles, or signals back in the direction from which they were detected. The backscatter signal may be a backscatter (or backscattered) information signal and / or a backscatter (orbackscattered) modulated information signal.

[0213] For example, the AloT device may modify and / or reflect the received signal with encoded data by using the power converted from the harvested energy. The encoded data may include a response to a command. Antennas on other devices (e.g., a reader) may, in turn, detect the signal reflected by the AloT device.

[0214] In an example, the backscatter may be a method of communication in which an AloT device with a limited capability (e.g., a device without a battery or without any internal power source) receives energy from a reader’s (e.g., RF emitter’s) transmission. The AloT device may use at least a portion of the received energy to send back a reply. The AloT device may receive the energy via electromagnetic waves propagated from an RF emitter (e.g., a reader, an intermediate wireless device, a continuous wave (CW) transmitter, and / or the like). Once the waves reach the AloT device, the energy may travel through the AloT device's internal antenna, and activates the chip, or integrated circuit (IC). The remaining energy may be modulated with the chip’s data and flows back via the AloT device’s antenna to the reader’s antenna in the form of electromagnetic waves For example, the remaining energy is used as and / or is converted to the transmission power of the backscatter signal transmitted by the AloT device to the reader.

[0215] Harvesting an energy from radio (e.g., RF) wave may be used for data decoding, signal filtering operation, data reception, data encoding, and / or data transmission. A purpose of harvesting the energy may be to energize the AloT device and / or to charge a battery of the AloT device. The AloT device may perform the one or more tasks using the harvested energy. The AloT device may perform the one or more tasks based at least in part on anDocket No.: 25-1063PCTaccumulation of harvested energy over a period of time.

[0216] The harvested energy may be derived from a radio wave (e.g. , RF signals) transmitted by a network (e.g., a reader, a base station and / or an RF emitter) and / or by a wireless device (e.g., an intermediate / assisting wireless device) connected to the network. The AloT device may communicate with the network using the harvested energy and / or power (e.g., transmitting and / or receiving power) converted from the harvested energy. For example, RF energy harvesting may lead to a longer battery lifespan of the AloT device with a battery. RF energy harvesting may lead to a battery-less loT device, such as a medical sensor or an implanted sensor.

[0217] An amount of energy that the AloT device harvests from the radio wave may depend on one or more parameters. For example, the one or more parameters comprise a frequency of the radio wave. For example, the one or more parameters comprise a distance (e.g., between an RF emitter and the AloT device) traveled by the radio wave. For example, the one or more parameters comprise a transmission power of the radio wave. For example, the one or more parameters comprise a received power (e.g., received signal strength, RSRP, and / or the like), of the radio wave, measured by the AloT device. The signal source (e.g., transmitter) of the radio wave may be a network entity (or node) such as a base station (e.g., AN 102) in FIG. 1A (and / or gNB 152A, ng-eNB 152B, and / or NG-RAN 152 in FIG. 1 B) and / or another device, such as a wireless device (e.g., an intermediate / assisting wireless device) connected to the wireless device 101 in FIG. 1A (and / or UE 151 in FIG. 1B).

[0218] The AloT device may perform the energy harvesting from various energy sources, such as solar, vibration, thermal, laser or light, and / or RF. Energy harvesting from a solar source may use photovoltaic cells, may provide a relatively high power density, and / or may require exposure to light (not implantable). Energy harvesting from a vibration source may use piezoelectric, electrostatic, and / or electromagnetic techniques. Energy harvesting from a vibration source may be implantable and / or may suffer from material physical limitations. Energy harvesting from a thermal source may use thermoelectric or pyroelectric techniques. Energy harvesting from a thermal source may provide a relatively high power density. Energy harvesting from a thermal source maybe implantable, and / or may produce excess heat. Energy harvesting from RF (a radio wave) may use an antenna maybe implantable. Energy harvesting from RF (a radio wave) may provide a relatively low power density where an efficiency is inversely proportional to a distance.

[0219] Referring to FIG. 15, a transmitter of an energy signal may transmit, to an AloT device, an energy signal to energize the AloT device.

[0220] The transmitter may be a reader. For example, the reader comprises the transmitter.

[0221] The transmitter may not be a reader. For example, the transmitter may be a network entity or node deployed separately from the reader. For example, the transmitter may be an RF emitter.

[0222] The energy signal may be a continuous waveform and / or continuous wave. The energy signal may be an unmodulated signal. The reader may transmit, to an AloT device, one or more AloT commands. For example, the transmitter may transmit the energy signal prior to the one or more AloT commands. For example, a channel via which the transmitter transmits the energy signal may be referred to as a CW-to-Device (CW2D) channel.Docket No.: 25-1063PCT

[0223] For example, a channel (e.g., CW2D channel) via which the transmitter transmits the energy signal may be a R2D channel. For example, the R2D channel may comprise the CW2D channel, e.g., if the reader comprises the transmitter transmitting the energy signal. For example, the CW2D channel may comprise the R2D channel.

[0224] For example, a channel (e.g., CW2D channel) via which the transmitter transmits the energy signal may be different from the R2D channel. For example, the CW2D channel is different from the R2D channel, e.g., if the reader does not comprise the transmitter transmitting the energy signal.

[0225] Referring to FIG. 15, an AloT device may receive, from the transmitter (e.g., reader) and via CW2D channel, an energy signal. The AloT device may comprise an RF energy harvester. For example, the RF energy harvester may comprise a rectifier performing RF signal alternating current (AC) to direct current (DC) conversion. The AloT device may comprise an energy storage (e.g., capacitor). The energy storage may store harvested energy from the RF energy harvester. The AloT device may supply the harvested energy to active component blocks (e.g., decoder, encoder, backscatter modulator, and / or the like) of the AloT device.

[0226] Referring to FIG. 15, an AloT device may receive, from the reader and via R2D channel, one or more AloT commands. The AloT device may transmit, to the reader and via D2R channel, a backscatter modulated information signal using the transmit power. The backscatter modulated information signal may comprise one or more responses respective to the one or more AloT commands. The backscatter modulated information signal may be referred to as a backscatter signal, a backscattering signal, and / or the like.

[0227] The AloT device may determine the transmit power based on an amount of harvested energy and / or an amount of stored energy. For example, the AloT device may couple its transmitter to its receiver with either load modulation orbackscatter, eg., depending on whether the AloT device is operating in the near-field orfar-field of the reader. The coupling (e.g., its transmitter to its receiver) may be the transfer of energy from one medium to another medium. For example, the AloT device uses it to obtain power and transfer data. For example, the type of coupling used, e.g., inductive coupling or backscatter coupling (also known as radiative coupling), depends on the frequency and the distance between the AloT device and the reader’s antenna. For example, the inductive coupling uses near-field effects. For example, the backscatter coupling uses far-field effects.

[0228] In the present embodiments, for example, the backscatter signal refers to a signal using the transmit power that the wireless device determines based on an amount of harvested energy and / or an amount of stored energy. For example, the AloT device obtains and / or determines the transmit power, used for the backscatter signal, using inductive coupling and / or backscatter coupling.

[0229] For example, the transmit power based on the amount of harvested (and / or stored) energy that the AloT device obtained from a signal (e.g., RF signal) received from the reader may be referred to as a backscattered power. For example, the backscattered power may be referred to as the backscattered power of the signal (e.g., RF signal) received from the reader. For example, the backscattered power may be referred to as the backscattered power of the received energy (and / or power) of the signal (e.g., RF signal) received from the reader

[0230] The AloT device may comprise an antenna shared for the RF energy harvester and receiver / transmitter ofDocket No.: 25-1063PCTthe AloT device. The AloT device may comprise at least one first antenna and / or at least one second antenna. The at least one first antenna may be dedicated for the RF energy harvester. The at least one second antenna may be dedicated for the receiver to receiving the energy signal and / or AloT commands. The at least one second antenna may be dedicated for the transmitter to transmit the backscatter modulated information signal.

[0231] An AloT device may be categorized based on its capability of energy storage, a transmitting signal generation, and / or amplification of transmitting signal.

[0232] For example, an AloT device may be referred to as Device 1 (or Device A). The AloT device categorized as Device 1 may have (or support) peak power consumption less than or equal to 1 W peak power consumption. The AloT device categorized as Device 1 may have energy storage. The AloT device categorized as Device 1 may have initial sampling frequency offset (SFO) up to 10X ppm. The AloT device categorized as Device 1 may have neither DL nor UL amplification in the device. The UL transmission of the AloT device categorized as Device 1 may be backscattered on a carrier wave provided externally.

[0233] For example, an AloT device may be referred to as Device 2a (or Device B). The AloT device categorized as Device 2a may have (or support) peak power consumption less than or equal to a few hundred piW peak power consumption. The AloT device categorized as Device 2a may have (or support) energy storage. The AloT device categorized as Device 2a may have (or support) initial sampling frequency offset (SFO) up to 10X ppm. The AloT device categorized as Device 2a may have (or support) both DL and / or UL amplification in the device. The UL transmission of the AloT device categorized as Device 2a may be backscattered on a carrier wave provided externally.

[0234] For example, an AloT device may be referred to as Device 2b (or Device C). The AloT device categorized as Device 2b may have (or support) peak power consumption less than or equal to a few hundred W peak power consumption. The AloT device categorized as Device 2b may have (or support) energy storage. The AloT device categorized as Device 2b may have (or support) initial sampling frequency offset (SFO) up to 10X ppm. The AloT device categorized as Device 2b may have (or support) both DL and / or UL amplification in the device. The UL transmission of the AloT device categorized as Device 2b may be generated internally by the AloT device.

[0235] A (e.g., maximum) message size of the AloT device may be approximately 1000 bits to be received by the AloT device. A (e.g., maximum) message size of the AloT device may be approximately 1000 bits to be transmitted from the AloT device. The one-way end-to-end (e.g., maximum) latency (e.g., including query / triggering time) of the AloT device may be from 1 second to 10 seconds The (e.g., maximum) connection density of the AloT communications maybe about 150 AloT devices per 100 m2 for indoor scenarios. The (e.g., maximum) connection density of the AloT communications may be about 20 AloT devices per 100 m2 for outdoor scenarios. The AloT device may be a fixed or static (not moving) device. The AloT device may have a moving speed of 10 km / h, e.g., at least for indoor scenarios.

[0236] FIG. 16 illustrates an example of AloT device architecture as per an aspect of an embodiment of the present disclosure. The block diagrams in FIG. 16 may be an example AloT device architecture of Device 1. ForDocket No.: 25-1063PCTexample, the AloT device may comprise one or more antennas. The one or more antenna may be either shared or separate for RF energy harvester and receiver / transmitter. For example, the AloT device may comprise a block for a matching network. The matching network may be to match impedance between antenna and other components (including RF energy harvester and receiver related blocks). For example, the AloT device may comprise an RF energy harvester. The RF energy harvester may comprise rectifier performing RF signal (AC) to DC conversion. For example, the AloT device may comprise an energy storage (e.g., capacitor). The energy storage may store harvested energy from RF energy harvester. For example, the AloT device may comprise a power management unit (PMU). The PMU may manage storing energy to energy storage from energy harvester and supplying power to active component blocks which needs power supply.

[0237] In FIG. 16, the AloT device may comprise a digital baseband (BB) logic. The digital BB logic may include functional blocks like encoder, decoder, controller, etc. For example, the AloT device may comprise a memory. The memory may comprise at least one of Non-Volatile Memory (NVM) and / or registers. For example, the NVM may comprise an Erasable Programmable Read-Only Memory (EEPROM), e.g., for permanently storing device ID, etc. For example, the registers may be for temporarily keeping information for its operation, e.g., while energy is available for the operation in energy storage. For example, the AloT device may comprise a clock generator. The clock generator may provide clock signal(s).

[0238] In FIG. 16, the AloT device may comprise an RF signal (e.g., AloT signal) reception related blocks. For example, the AloT device may comprise RF band-pass filter (BPF), e.g., for improving selectivity. The RF BPF may be optional to be implemented in the AloT device. For example, the AloT device may comprise an RF envelope detector. The RF envelop detector may convert RF signal to baseband. For example, the AloT device may comprise a BB low-pass filter (LPF). The BB LPF may filter out harmonics and high frequency components to improve input signal quality to comparator. The BB LPF may be optional to be implemented in the AloT device. For example, the AloT device may comprise a comparator that determines high / low of input signal.

[0239] In FIG. 16, the AloT device may comprise transmission related blocks. For example, the AloT device may comprise a backscatter modulator. The backscatter modulator may switch impedance to modulate backscattered signal with Tx signal (e.g., an AloT signal transmitted via a D2R channel) from BB logics.

[0240] FIG. 17 illustrates an example of AloT device architecture as per an aspect of an embodiment of the present disclosure. The block diagrams in FIG. 17 may be an example AloT device architecture of Device 2a. Comparing with the AloT device architecture in FIG. 16, the AloT device architecture in FIG. 17 may further comprise one or more additional blocks. The one or more additional blocks may comprise a low-noise amplifier (LNA). The LNA may improve a signal strength and sensitivity of receiver. The one or more additional blocks may comprise a BB amplifier. The BB amplifier may amplify a BB signal to improve signal strength. The one or more additional blocks may comprise a reflection amplifier. The reflection amplifier may amplify reflected backscattered signal. The one or more additional blocks may comprise a large frequency shifter. The large frequency shifter (eg., tens of MHz) may shift a backscattered signal from one frequency (e.g., FDD-DL frequency) to another frequencyDocket No.: 25-1063PCT (e.g., FDD-UL frequency).Docket No.: 25-1063PCT

[0241] In FIG. 17, the AloT device may comprise an N-bit analog-to-digital converter (ADC), e.g. , instead of the comparator. The AloT device may have one or more energy source. For example, the AloT device may comprise an RF energy harvester for harvesting an energy from an RF signal (e.g., radio wave). The RF energy harvester may include a rectifier performing RF signal (AC) to DC conversion. The AloT device may comprise an energy harvester (other than the RF energy harvester) for energy harvesting from energy source(s) other than the RF signal.

[0242] FIG. 18 illustrates an example of AloT device architecture as per an aspect of an embodiment of the present disclosure. The block diagrams in FIG. 18 may be an example AloT device architecture of Device 2b. Comparing with the AloT device architectures in FIG. 16 and / or FIG. 17, the AloT device architecture in FIG. 18 may further comprise one or more additional blocks. The one or more additional blocks may comprise a Tx modulator, e.g., where baseband bits are modulated according to modulation scheme The Tx modulator block may be a part of BB logic. The one or more additional blocks may comprise a digital to analog converter (DAC) that converts digital signal to analog signal. The one or more additional blocks may comprise a low pass filter (LPF) for filtering out undesired signal. The one or more additional blocks may comprise a mixer that performs up-converting baseband signal to RF range. The one or more additional blocks may comprise a local oscillator (LO) for carrier frequency generation. The block diagrams in FIG. 18 may comprise a phase locked loop (PLL) and / or a frequency locked loop (FLL) that are used to generate frequencies suitable for the LO in a respective frequency range. The one or more additional blocks may comprise a power amplifier (PA) that amplifies TX signal, if present.

[0243] In FIG. 15, FIG. 16, FIG. 17, and / or FIG. 18, the RF energy harvester and the reception related blocks may operate in a simultaneous manner with. For example, an RF energy harvester of the AloT device may receive RF signals from a first set of antennas. For example, a reception related blocks of the AloT device may receive RF signals from a second set of antennas.

[0244] In FIG. 15, FIG. 16, FIG. 17, and / or FIG. 18, the AloT device may comprise common antenna(s) shared between the energy harvester and the reception related blocks. For example, the common antenna(s) between the energy harvester and the reception related blocks may receive RF signals. The received RF signals may be split into two streams for the energy harvester and the reception related blocks. For example, a power of the received RF signals may be split between the energy harvester and the reception related blocks. For example, the AloT device may switch the antenna(s) between the RF energy harvester and the reception related blocks using time switching For example, RF signals received at the antenna(s) may be directed to the energy harvester when a path is switched to be directed to the energy harvester. The RF signals received at the antenna(s) may be directed to the reception related blocks, e.g., when a path is switched to be directed to the reception related blocks.

[0245] The AloT communications may comprise one or more topologies. The one or more topologies may comprise at least one of: a topology for an AloT direct network communication, a topology for an AloT Indirect network communication, and / or a topology for an AloT device to UE direct communication.

[0246] FIG. 19A illustrates an aspect of an example embodiment according to the present disclosure. TheDocket No.: 25-1063PCTtopology in FIG. 19A may be an example of an AloT direct network communication. For example, the AloT direct network communication comprises an AloT device and a network node (Network or reader in FIG. 19A). The topology for the AloT direct network communication may comprise a direct link between the network node and the AloT device.

[0247] In an AloT direct network communication, the AloT device may directly and / or bidirectionally communicates, via the direct link, with the network node. The communication between the network node and the AloT device may include AloT data and / or signaling.

[0248] The topology in FIG. 19A may comprise a second direct link between the AloT device and a second network node. For example, the network node transmits, to the AloT device and via a first direct link, one or more signal and / or AloT data. The AloT device may transmit, to the second network node and via the second direct link, one or more second signals and / or a second AloT data. For example, the network node transmitting to the AloT device may be a different from the second network node receiving from the AloT device.

[0249] In the AloT direct network communication, the direct link may comprise and / or referred to as a downlink, an uplink, a sidelink, an AloT link, and / or the like. The direct link from the network node to the AloT device may comprise an R2D channel. The direct link from the AloT device to the network node may comprise a D2R channel.

[0250] FIG. 19B, FIG. 19C, and FIG. 19D illustrate an aspect of example embodiments according to the present disclosure. The topologies in FIG. 19B, FIG. 19C, and FIG. 19D maybe examples of an AloT device communication comprising an indirect link. For example, a topology for an AloT indirect network communication comprises an AloT device, a network node (Network in FIG. 19A), and / or a wireless device. The wireless device maybe Intermediate wireless device in FIG. 19B and / or Assisting wireless device in FIG. 19C and / or in FIG. 19D. The AloT indirect network communication may comprise communication(s) between the AloT device and the network. In the AloT indirect network communication, there is a wireless device that helps in conveying information between the AloT device and the network. For example, the wireless device may be referred to as an intermediate (wireless) device, an assisting (wireless) device, and / or the like. In FIG. 19B, FIG. 19C, and FIG. 19D, Network may comprise at least one of: a base station, a cell, a transmission-reception point (TRP), a repeater, a relay, and / or an integrated access and backhaul (IAB) node.

[0251] FIG. 19B illustrates an aspect of an example embodiment according to the present disclosure. The AloT indirect network communication in FIG. 19B may not comprise a direct link between the AloT device and the network. The communications between the AloT device and the network may be via a wireless device (e.g., Intermediate wireless device in FIG. 19B). The wireless device may relay and / or convey control information (AloT signaling) and / or AloT data generated / transmitted by the network to the AloT device. The wireless device may relay and / or convey control information and / or AloT data / signaling generated / transmitted by the AloT device to the network.

[0252] For example, the wireless device in FIG. 19B may be referred to as an intermediate wireless device (e.g., an intermediate device and / or an intermediate node). The intermediate wireless device may be referred to as aDocket No.: 25-1063PCTreader, an interrogator, and / or the like.

[0253] The intermediate wireless device may receive, from the network (e.g., base station) and via a downlink channel (e.g., PDCCH and / or PDSCH), AloT data and / or a control signal. For example, the intermediate wireless device may transmit, to the AloT device, the AloT data and / or a control signal.

[0254] The intermediate wireless device may receive, from the AloT device, AloT data / signaling. For example, the intermediate wireless device may transmit, e.g., via an uplink channel (e.g., PUCCH and / or PUSCH), to the network, the AloT device, AloT data / signaling. The link between the intermediate wireless device and the network may comprise an uplink (e.g., PUCCH and / or PUSCH). The link between the intermediate wireless device and the network may comprise downlink (e.g., PDCCH and / or PDSCH). The link between the intermediate wireless device and the AloT device may comprise a sidelink, AloT link and / or the like.

[0255] The intermediate wireless device may comprise a wireless device, relay, IAB node, a second cell, a second base station, a reader, an interrogator, an access point, and / or the like. The intermediate wireless device may transmit, to the AloT device, an RF signal (e.g., energy signal and / or wireless energy transmission). The AloT device may harvest, from the RF signal, an energy to be used for AloT communication(s).

[0256] FIG. 19C and FIG. 19D illustrate an aspect of example embodiments according to the present disclosure.The topologies in FIG. 19C and in FIG. 19D may comprise an AloT indirect network communication between the AloT device and the network node (Network in FIG. 19C and / or in FIG. 19D). The topologies in FIG. 19C and in FIG. 19D may comprise a direct link between the AloT device and the network node. The communications between the AloT device and the network may be via a wireless device (e.g., Assisting wireless device in FIG. 19C and / or in FIG. 19D). Between the AloT device and the network, there are a direct link (e.g., Uu link in FIG. 19C and / or FIG. 19D) and an indirect link.

[0257] For example, the direct link in FIG. 19C may be for transmission between the network and the AloT device. For example, the direct link may be for transmission from the AloT device to the network. For example, the indirect link may be for transmission from the network to the AloT device. For example, the direct link may comprise a link between Network and AloT device in FIG. 19C. For example, the indirect link (e.g., Uu link and / or downlink) may comprise a link between the network and Assisting wireless device in FIG. 19C. For example, the indirect link (e.g., R2D link or channel) may comprise a link between AloT device and Assisting wireless device in FIG. 19C.

[0258] In FIG. 19C, the network may transmit a control signal (e.g., AloT signaling) and / or AloT data to the wireless device via an Uu link. The Uu link may comprise a downlink, PDSCH, PBCH, PDCCH, and / or a sidelink. The wireless device may convey (relay, forward, and / or transmit), to the AloT device and via R2D channel, the control signal and / or the AloT data that the wireless device receives from the network. The AloT device may transmit a second control signal and / or second AloT data to the network via the direct link. The direct link may comprise a D2R link (or channel), uplink, and / or sidelink. The second control signal and / or second AloT data may comprise the response to the received control signal and / or AloT data from the wireless device.Docket No.: 25-1063PCT

[0259] For example, the direct link in FIG. 19D may be for transmission between the network and the AloT device. For example, the direct link may be for transmission from the network to the AloT device. For example, the indirect link may be for transmission from the AloT device to the network. For example, the direct link may comprise a link between Network and AloT device in FIG. 19D. For example, the indirect link (e.g., Uu link and / or uplink) may comprise a link between the network and Assisting wireless device in FIG. 19D. For example, the indirect link (e.g., D2R link or channel) may comprise a link between AloT device and Assisting wireless device in FIG. 19D.

[0260] In FIG. 19D, the network may transmit a control signal (e.g., AloT signaling) and / or AloT data to AloT device via a direct link. The direct link may comprise a downlink, PDSCH, PBCH, PDCCH, and / or an R2D link (or channel). The AloT device may transmit a second control signal and / or second AloT data to the network via the indirect link. For example, the AloT device may transmit the second control signal and / or second AloT data to the wireless device via a link between the AloT device and the wireless device. The link between the AloT device and the wireless device may comprise an uplink, a sidelink and / or a D2R link (or channel). The wireless device may convey (relay, forward, and / or transmit), to the network and via Uu link, the second control signal and / or second AloT data that the wireless device receives from the AloT device. The Uu link may comprise an uplink, PUCCH, PUSCH, and / or a sidelink

[0261] Referring to FIG. 19C and in FIG. 19D, the wireless device may be referred to as an assisting wireless device (e.g., an intermediate wireless device, an assisting device and / or an assisting node), a reader, an interrogator, and / or the like.

[0262] For example, the assisting wireless device may receive, from the network (e.g., base station) and via a Uu link comprising a downlink channel (e.g., PDCCH and / or PDSCH), AloT data and / or a control signal (AloT signaling). The assisting wireless device may convey (relay, forwards, and / or transmits), to the AloT device via an R2D link (or channel), the AloT data and / or the control signal.

[0263] For example, the assisting wireless device may receive, from the AloT device and via a D2R link (or channel), AloT data and / or a control signal. The assisting wireless device conveys (relays, forwards, and / or transmits), to the network (e.g., base station) and via a Uu link comprising an uplink channel (e.g., PUCCH and / or PUSCH), AloT data and / or a control signal.

[0264] Referring to FIG. 19C and in FIG. 19D, the link (e.g., Uu link) between the assisting wireless device and the network may comprise an uplink (e.g., PUCCH and / or PUSCH) and / or downlink (e.g , PDCCH and / or PDSCH). The link between the assisting wireless device and the AloT device may comprise an R2D link (or channel), a D2R link (or channel), a sidelink, AloT link, and / or the like. The assisting wireless device may comprise a wireless device, relay, IAB device, a second cell, a second base station, a reader, an interrogator, an access point, and / or the like. The assisting wireless device may transmit, to the AloT device, a signal (e.g., RF signal, energy signal, wireless energy transmission) from which the AloT device harvests an energy to be used for AloTcommunication(s).Docket No.: 25-1063PCT

[0265] FIG. 19E illustrate an aspect of example embodiments according to the present disclosure. The topology in FGI.21 E may be for an AloT device to a wireless device direct communication. The topology may comprise a communication between an AloT device and an Ambient capable wireless device (Wireless device in FIG. 19E) with no network node in the middle. The AloT device communicates bidirectionally with the wireless device. The communication between the wireless device and the AloT device may comprise the AloT data and / or signaling. The communication link between the wireless device and the AloT device may comprise a sidelink (e.g., comprising a sidelink channel such as PSFCH, PSSCH, PSCCH, PSDCH, and / or the like), AloT link, and / or the like. For example, a channel or link from the wireless device to the AloT device may comprise a R2D link or R2D channel. For example, a channel or link from the AloT device to the wireless device may comprise a D2R link or D2R channel.

[0266] The device-to-device (D2D) communication may comprise AloT communications and / or AloT topologies.The D2D communication may comprise a communication between a network node and an AloT device. The D2D communication may comprise a communication between a wireless device and an AloT device.

[0267] A link defined, included, and used for the D2D communication may be referred to as a sidelink (SL). The link used for the D2D communication may be referred to as other terminologies, e.g., an loT link, an AloT link, a D2D link, and / or the like.

[0268] In the present disclosure, a reader may comprise a network node (e.g., a base station, a base station central unit, a base station distributed unit, a TRP, an IAB node, a cell, and / or a relay). In the present disclosure, a reader may comprise a wireless device (e.g., an assisting wireless device, and / or an intermediate wireless device) that a network assigns as a reader. A reader may be at least one of a base station reader (BS reader) and / or a UE reader. The UE reader may be at least one of an AloT UE reader, a UE acting as an AloT reader, and / or the like.

[0269] The AloT communications may comprise an inventory procedure. The inventory procedure may refer to a procedure, a process, and / or an operation by which a reader identifies one or more AloT devices. The inventory procedure may be referred to as an inventory process, an inventory operation, AloT device population, and / or the like.

[0270] The inventory procedure may comprise or be referred to as a random access procedure. For example, the inventory procedure may comprise a procedure, a process, and / or an operation that initiate a random access of one or more AloT devices. For example, each AloT device accesses to a network (e.g., reader) using a randomly selected radio resource (e.g., slot and / or frequency), e.g., in response to, during, or after the inventory procedure.

[0271] The inventory procedure may comprise or be referred to as a paging procedure. For example, the inventory procedure may comprise a procedure, a process, and / or an operation that initiate one or more AloT devices to perform one or more procedures (e.g., random access procedure). For example, an AloT device receives, from a reader, a paging message during the inventory procedure. For example, an AloT device initiates the inventory procedure, e.g., in response to or after receiving the paging message.

[0272] The paging message may initiate the one or more procedures (e.g., random access procedure and / orDocket No.: 25-1063PCTinventory procedure). The paging message may comprise a trigger indication that initiate the one or more procedures (e.g., random access procedure and / or inventory procedure). An AloT device may initiate the one or more procedures (e.g., random access procedure and / or inventory procedure) in response to receiving the paging message and / or the trigger indication.

[0273] The paging message may comprise one or more parameters for one or more procedures (e.g., random access procedure and / or inventory procedure). For example, the one or more parameters comprise an identifier of one or more AloT devices, a group identifier of one or more AloT devices, one or more bits (e.g., least significant bit (LSB) and / or most significant bit (MSB)) of an identifier of one or more AloT devices. The field containing (or carrying) the one or more bits may be referred to as a mask field. An AloT device that has a respective identifier matching to the one or more bits may initiate the one or more procedures. For example, an LSB of the identifier of the AloT device matches to the one or more bits. For example, an MSB of the identifier of the AloT device matches to the one or more bits.

[0274] AloT services may comprise an inventory service, an inventory & command service, a command (only) service. An AloT network / system may provide / support / operate the AloT services. FIG. 20 illustrates an example as per an aspect of an embodiment of the present disclosure, the basic AloT network nodes / functions / components (e.g., AloT device, AloT reader, AloT Function (AloTF), AF (application function)) for the AloT services. In an example, the AF may be an application function / server which is owned by cellular operators or 3'rd party service provider. The owner of the AF may own one or more AloT devices for the AloT service. The AF may request and provide the inventory and command service. In an example, the AF may be owned / operated by a warehouse operator (e.g., Walmart, Amazon). The AloTF (AloT Function) may be a core network node and acts as a coordinator or bridge point between one or more AFs and one or more AloT readers. The AloTF may be owned / operated by a cellular operator and provide interfaces with the AFs and one or more AloT readers. The AloT reader may interact with one or more AloT devices via the AloT radio interface. The AloT radio may comprise and / or refer to a radio interface between AloT device and AloT reader. AloT reader may comprise RAN reader (for topology 1, FIG. 19A, AloT RAN reader) and UE reader (for topology 2, FIG. 19B, AloT UE reader). In an example, the AloT reader may support two different reader type. The reader type may comprise a RAN reader and a UE reader. The reader type may comprise a RAN type and UE type. For the RAN reader, a base station (g NB) may act as an AloT reader (RAN reader) and may cover larger area (e.g., a coverage of a warehouse). The RAN reader may be located in one place and does not move. The RAN reader may do the AloT reader operation based on a request from the AF and AloTF. The RAN reader (base station) may do the inventory and / or command operations with AloT devices. For the UE reader, a wireless device (UE) may act as an AloT reader (and do the AloT reader operation). The UE reader may cover relatively smaller area (smaller coverage area) compared to the RAN reader. The UE reader may comprise a wireless device (Wireless device 101 in FIG. 1A, UE 151 in FIG. 1B) and an AloT reader function. The UE reader may moves from / to different area and may be implemented as a handheld device. The RAN reader may comprise a RAN / AN / base station (AN 102 in FIG. 1A, NG-RAN 152 in FIG. 1 B) and the AloTDocket No.: 25-1063PCTreader function. In an example, the AloT reader function may comprise sending AloT paging messages and receiving response for the paging messages from the AloT device, interacting with AloTF for AloT services. AloT Function, AloTF and AIOTF is interchangeable each other.

[0275] In an example, the AloT reader operation / AloT service / reader function may comprise an inventory and a command operation / service. The AloT inventory may be to identify (e.g., existence, location, tracking) one or more AloT devices. The AloT command may comprise read, write, enable, disable. The reading command (e.g., command type: read) may comprise reading of a specific memory field of one or more AloT devices. The writing command (e.g., command type: write) may comprise writing to a specific memory filed of one or more AloT devices. The disabling command (e.g., command type: disable) may comprise disabling (e.g., turn off the RF transmission of the AloT device) of one or more AloT devices. The enabling command (e.g., command type: enable) may comprise enabling (e.g., turn on the RF transmission of the AloT device) of one or more AloT devices and indicating do the AloT service.

[0276] In an example, the command operation / service may be standalone operation or performed with the inventory operation / service (e.g., performing command procedure after the inventory) together.

[0277] As illustrated in FIG. 20, the AF 1 may request to AloTF 1, an AloT inventory service for all AloT devices located in the Area 1. The AF 1 may send an AloT message, to the AloTF 1 , requesting an AloT inventory service for the Area 1. In response to receiving the AloT message, the AloTF 1 may select AloT reader A which covers the Area 1. The AloTF 1 may request the AloT inventory service (e.g., identify the AloT devices in the Area 1) to the AloT reader by sending an AloT inventory service request. In response to receiving the request from the AloTF 1 , the AloT reader A may send AloT paging messages for the inventory In an example, the paging messages may be for all AloT devices. In Area 1, there may be the AloT device 1 and the AloT device 2. In response to receiving the AloT paging messages, the AloT device 1 and the AloT device 2 may respond to the AloT reader A. The AloT device 1 and AloT device 2 may send AloT identifies of the AloT device 1 and AloT device 2 to AloT reader A, respectfully. In response to receiving the response messages from the AloT device 1 and AloT device 2, the AloT reader A may indicate to the AloTF 1 , the successful inventory result. The successful inventory result may comprise the AloT identifies of the AloT device 1 and AloT device 2. The AloT 1 may respond to the AF 1 with the inventory result. Accordingly, the AF 1 recognize that the AloT device 1 and AloT device 2 are located inside the Area 1.

[0278] FIG. 21A illustrates the interface of the AloT RAN reader and FIG. 21 B illustrates the interface of the AloT UE reader. The AloT UE reader (FIG .21 B) may comprise AloT enabled wireless device and AloT reader function (e.g., capability of the reader operation). The AloT UE reader may connect to the AloT CN (e.g., AloTF, AMF, SMF, UPF) via base station (AloT enabled base station) and the interface between the AloT UE reader and the base station may be Uu interface. The AloT UE reader may be a wireless device and capable of the reader function to communicate with the AloT device. Wireless device may be installed in the AloT UE reader

[0279] FIG. 22 illustrates an example as per an aspect of an embodiment of the present disclosure. FIG. 22Docket No.: 25-1063PCTdepicts an AloT system / network architecture for the AloT UE reader case (topology 2). The AloT system / network architecture may be based on the cellular network architecture (e.g., 5G system, 6G system) as illustrated in FIG.3. In an example, the UE reader may be a wireless device. The UE reader may comprise the wireless device. The UE reader may comprise the wireless device and a reader function (e.g., capability for the reader operation). Network functions (e.g., AM F, SMF, UPF, UDM, UPF) may be used to provide connectivity / mobility of the UE reader to a data network (e.g., internet, application service, application function, application provider). The connectivity to the AloTF may be provided by the cellular network. Connectivity, for transmitting and receiving data, between the UE reader and the AloTF may be realized via control plane path or user plane path.

[0280] In an example, the UE reader and the AloTF may communicate / connect via control plane path (CP path / solution). The control plane path may be via AMF using the SRB (signaling radio bearer). The control plane path may comprise an RRC signaling / message, NG interface (e.g., N2 interface) and SBI (service based interface). The RRC signaling / message may be between the UE reader and the AN (g NB, base station, AloT enabled base station). The NG interface (e.g., N2 interface) may be between the AN and the AMF. The SBI (service based interface) may be between the AMF and the AloTF. AloTF may invoke AMF service (e.g., AMF N1N2 message transfer service) to send an AloT message to the UE reader via the SBI. AMF may invoke AloTF service to subscribe / register a newly detected UE reader.

[0281] The UE reader and the AloTF may communicate via user plane path (UP path / solution). As described in FIG.22, the user plan path may comprise the Uu interface (DRB / data radio bearer), the N3 interface (e.g., NG-U interface) between the AN and the UPF, the N6 interface between the UPF and the AloTF. The user plane path may be access agnostic and provide scalability for larger data compared to the control plane path The user plane path maybe available via the 3GPP access radio or the non-3GPP access radio. The user plane path / solution may be used for large data transmission. In an example, aggregated data from AloT devices may be large for the control plane path, then the user plane path / solution may be used for larger data transmission / reception between the UE reader and the AloTF.

[0282] FIG. 23 illustrates a protocol stack for the user plane (path / solution) architecture for AloT (topology 2). A protocol stack of the AloT device may comprise the AloT AS layer, the AloT non-access stratum (NAS) layer and the AloT data layer. From the UE reader side (e.g., AloT enabled wireless device), the interface between the UE reader and the AloT device may be the AloT AS layer. For the UE reader side, the protocol stack, interacting with the network (NG-RAN / AN, UPF, AloTF), may comprise the Uu AS layer (Uu interface), the PDU layer, the IP transport layer and the AloT UE reader control layer. In an example, the UE reader and the AloTF may interact using AloT application protocol (AP) (AloT-AP) via the AloT UE reader control layer. The AloT AP will be established above the PDU session via UPF. An AloT NAS layer may be terminated in the AloTF and the AloT device and used to communicate between the AloTF and AloT device. The AloT AP layer may encapsulate the AloT NAS layer. The AloT NAS layer may encapsulate the AloT Data.

[0283] FIG. 24 illustrates an example as per an aspect of an embodiment of the present disclosure. The wirelessDocket No.: 25-1063PCTdevice may send a registration request message to an AMF via a base station (g N B), to register the wireless device to the network. The registration request message may be used to authenticate the wireless device, to request a network slice, to manage mobility of the wireless device, and / or the like. If a registration via the registration request is not successful, the wireless device may not be able to move on to next step. For example, the next step may be at least one of making a voice call, receiving a SMS message, establishing a PDU session, requesting registration as an AloT UE reader. In an example, the base station may support the AloT UE reader operation. The base station may indicate, in SIB (system information block) message, support for the AloT UE reader operation to the wireless device.

[0284] The registration request message may comprise an AloT (UE) reader capability. The AloT reader capability may indicate an intention / request to act as a AloT reader of the wireless device. In response to receiving the registration request message, the registration procedure will be executed by the AMF and with other network functions (e.g., UDM, AloTF, AUSF) as illustrated in FIG. 10. During the registration procedure (FIG. 10), the AMF may query subscription information from UDM / UDR for mobility management and / or subscription information for mobility management. If the subscription information of the wireless device in the UDM / UDR indicates that the wireless device is authorized and / or for the one or more network slices and / or for the AloT UE reader, the AMF may store the authorization information in the UE context of the wireless device.

[0285] After a successful registration procedure, the AMF may send a registration accept message to the wireless device indicating at least one of one or more allowed network slices, indicating that the wireless device is successfully registered for mobility management, the AloT authorization information. The AloT authorization information may indicate whether the wireless device is authorized / allowed for the AloT UE reader operation. The AMF may indicate to the base station, the AloT authorization information of the wireless device. The base station may use the authorization information for AloT (radio) resource allocation. In an example, the base station may reject an AloT resource request from the wireless device or the AloTF, if the wireless device is not authorized to act as a AloT UE reader. The registration accept message may indicate that the wireless devices is registered for mobility management (e.g., in 5GS, or in 6GS), and / or that the wireless device is registered for AloT reader functionality.

[0286] In an example, the wireless device may be successfully registered and authorized for the AloT UE reader operation. The AMF may indicate to the AloTF, the wireless device is ready for the AloT reader operation by sending an indication of the wireless device as an AloT reader to the AloTF. The AMF may indicate to the AloTF, the wireless device is a new AloT UE reader candidate.

[0287] In an example, the AloTF may have a list of AloT UE readers (AloT UE reader information). In response to receiving the indication, the AloTF may add the wireless device to the list of the AloT UE readers. The list of the AloT UE readers may comprise an identity of the wireless device, location / position of the wireless device, serving AMF of the wireless device, user plane path / association for the wireless device, connection status of the wireless device, availability of the wireless device for the AloT UE reader operation. In an example, the identity of theDocket No.: 25-1063PCTwireless device may comprise SUPI, I MSI, IMEI, GPSI. The location / position of the wireless device may comprise a tracking area (TA) identity, the RA (one or more TAs where the wireless device is registered for mobility management), cell identity, GPS coordination of the wireless device. The serving AMP of the wireless device may comprise the address of the AMP (e.g., IPv4, IPV6, IPv4v6). The user plane path / association may indicate an existence of a secure user plane association between the wireless device and the AloTF. Connection status of the wireless device may comprise CM-CONNECTED, CM-IDLE. Connection status of the wireless device may comprise RRC-CONNECTED, RRC-I NACTIVE, RRC-IDLE.

[0288] Alternatively and / or additionally, the registration accept message may not comprise indication of whether the wireless device is registered for AloT UE reader functionality. In this case, based on receiving the registration accept message, the wireless device may consider that the wireless device is successfully registered for mobility management, for 5GS, and / or for 6GS. Based on that the wireless device is registered for mobility management, the wireless device may determine to perform registration for AloT UE reader. In this case, the wireless device may send a NAS message to a mobility management node (e.g., AMP, 6G AMP). The NAS message may comprise a first AloT message. The first AloT message may be an AloT (UE reader) registration request message, a message for registration of an AloT UE reader, and / or the like. Based on sending the first AloT message, the wireless device may receive a second AloT message. The second AloT message may indicate to the wireless device that the wireless device is registered as an AloT UE reader.

[0289] Alternatively and / or additionally, after successfully registered for mobility management at the AMP and / or after receiving the one or more allowed network slices, the wireless device may establish a PDU session (as shown in the example of FIG. 12) over the one or more allowed network slices. After successfully establishing the PDU session, the UE may send a registration requestion for AloT reader operation, to the AloTF, via the user plane.

[0290] In an example, because the wireless device is successfully registered to the network via a mobility management node (e.g., the AMP, an 6G AMP) for mobility management, the wireless device may consider that the network is not overloaded. In another example, based on that the PDU session is successfully established, the wireless device may consider that the network is not overloaded. Based on considering that the network is not overloaded / congested, the wireless device may determine to perform additional registration procedure for AloT UE reader. Alternatively and / or additionally, because the wireless device is registered for mobility management, because the wireless device is registered for 5G service (and / or 6G service), and / or the like, the wireless device may determine to move onto next registration procedure (e.g., registration for AloT UE reader). On the other hand, if the wireless device fails to register to the mobility management node, and / or if a PDU session establishment procedure fails, the wireless device may not trigger the procedure to register the wireless device as the AloT UE reader.

[0291] In an example, capability and / or processing power of the AloTF may be limited For example, a maximum number of AloT UE readers that the AloTF supports may be limited. The maximum number may be N. A firstDocket No.: 25-1063PCTnumber of wireless devices (from among the one or more wireless devices) may have performed AloT reader registration procedures to the AloTF. After the first number of wireless devices perform the AloT UE reader registration procedure, a second number of AloT UE readers being registered at the AloTF may be equal to or greater than N. In this case, the AloTF may be congested and / or may not be able to receive / handle additional AloT reader registration requests. That the AloTF is congested may be that the AloTF is in an overloaded situation.

[0292] Alternatively and / or additionally, there may be one or more wireless devices supporting AloT reader functionality. For example, the one or more wireless devices may be one or more AloT UE readers. To function as an AloT UE reader, the one or more wireless devices may perform one or more registration procedures to the AloTF, as shown in previous examples. While functioning as the AloT UE reader, the one or more wireless devices may exchange one or more AloT messages with the AloTF. As a result, the AloTF may be overloaded.

[0293] After the AloTF is overloaded, a second wireless device may initiate / trigger a registration procedure to register the second wireless device as an AloT UE reader, toward the AloTF. For example, the second wireless device may send a AloTF UE reader registration request message to the AloTF. In this case, because the AloTF is overloaded and / or congested, the AloTF may not be able accept / process / handle the AloT UE reader registration request message.

[0294] Based on that the AloTF is overloaded, the AloTF may not respond to the AloT UE reader registration request message, may not send a response message to the AloT UE reader registration request message, and / or may send a registration reject message indicating that the wireless device is not registered for the AloT UE reader.

[0295] Because the wireless device is not registered for the AloT UE reader functionality and / or because the wireless device may prefer to operate as the AloT UE reader, the wireless device may perform another round of registration procedures for the AloT UE reader functionality and / or may keep trying the registration procedure for the AloT UE reader functionality. Because the AloTF is already congested, sending of the AloT UE reader registration request messages may further aggravate the overload situation at the AloTF.

[0296] In another example, the wireless device may move to a second area different from a first area in which the wireless device previously performed the AloT UE reader registration procedure. In this case, the wireless device may have difficulty in determining whether to perform another AloT UE registration procedure. For example, if the second area is still associated with the AloTF, additional attempts of the wireless device for registration as AloT UE reader may aggravate congestion of the AloTF control resources.

[0297] Example embodiments of the present disclosure may solve the above issues. In one embodiment, an AloT-supporting core network node may send, to a wireless device acting as a AloT reader, one or more of the following: information of a cause of rejection, a time period for retriggering a procedure, an area information associated with an AloT reader operation, and / or the like. This may help the wireless device to determine when the wireless device can perform the procedure, thereby reducing unnecessary signaling congestion. In another embodiment, a wireless device may send, to a mobility management node, a message indicating whether the wireless device requests registration toward the mobility management node and / or whether the wireless deviceDocket No.: 25-1063PCTrequests registration toward the AloT supporting core network node. The wireless device may receive an indication indicating whether the wireless device is registered for mobility management node and / or whether the wireless device is registered for the AloT reader. This may help in reducing a number of transactions from / to the wireless device and may help in reducing congestion in the core network for AloT related operation. In nother example embodiments, a mobility management node and / or a session management node may determine whether a AloTF is congested or not, and / or may determine whether to reject a AloT procedure initiated by the wireless device. This may help, for a wireless device, to quickly determine whether the network is congested for a AloT procedure. In another example, the wireless device may receive, from a core network node, information on AloT operation area and / or an information on a registration area for mobility management This may help the wireless device to differentiate when the wireless device can perform registration for a mobility management and / or registration for a AloT reader operation. In another example, a core network node for AloT operation may send a message, to a wireless device, indicating a de-registration of the wireless device for the AloT reader operation. This may help for a network to proactively prevent the wireless device from sending messages to the AloTF.

[0298] In the specification, the term “network system” may be interpreted as, or may refer to, a system, a communication system, and / or a generation of the communication system. For example, one or more network systems may comprise an EPS, a 5GS, a 6th generation (6G) system, and / or the like. For example, a first network system may be the EPS. The EPS may comprise of one or more UEs, one or more eNB, one or more en-gNBs, and / or one or more EPCs. The one or more EPCs may comprise a MME, a SGW, a PGW (e.g., a PGW-C+SMF, a PGW-U+UPF), HSS, PCRF, and / or the like. For example, a second network system may be the 5GS. The 5GS may comprise of one or more UEs, one or more g N B, one or more ng-eNBs, one or more 5G core networks. The one or more 5G core networks may comprise one or more core network nodes. The one or more core network nodes may comprise an AMF, a SMF, a PCF, a UPF, a UDM, a NEF, and / or the like. In some embodiments, a core network node may be a combination of one or more core network nodes of one or more core networks. For example, a SMF+PGW-C (e.g., PGW-C+SMF) may act as both a SMF and a PGW (e.g., PGW-C). For example, a SMF may act as a 5G core network node and a 6G core network node. For example, a third network system may be a 6th generation (6G) system (6GS). The 6GS may comprise of one or more UEs, one or more 6G-RAN (e.g., a radio access network node of 6G system), one or more 6g N Bs (e.g., an equivalent of gNB for 6GS), one or more 6G core networks. The one or more 6G core networks may comprise one or more 6G core network nodes (e.g., 6G core network functions). Each of the one or more core network nodes may support (implement) one or more functions (or services) provided by each of the one or more 5G core network nodes. For example, a node of the 6GS may perform a function of a radio access network and / or one or more roles performed by one or more 6G core network nodes (or by 5G core network nodes).

[0299] In the specification, the term “5G System” may be interpreted as, or may refer to, a 3GPP system consisting of at least one of 5G access network (or NG-RAN), 5G core network and / or a UE.

[0300] In the specification, the term “6G System” may be interpreted as, or may refer to, a 3GPP systemDocket No.: 25-1063PCTconsisting of at least one of 6G access network (or 6G-RAN), 6G core network and / or a UE.

[0301] In the specification, the term “EPS” may be interpreted as, or may refer to, a 3GPP system consisting of at least one of EPC, E-UTRAN and / or a UE.

[0302] In the specification, the term “network node” may be interpreted as, or may refer to, at least one of a core network node, an access node, a base station, a UE, the like, and / or a combination thereof. A network may comprise one or more network nodes.

[0303] In the specification, the term "core network node” may be interpreted as, or may refer to, a core network device, which may comprise at least one of an AMP, a SMF, a NSS F, a UPF, a NRF a UDM, a PCF, a SoR-AF, an AF, an DDNMF, an MB-SMF, an MB-UPF, a MME, a SGW, a PGW, a SMF+PGW-C, a SMF+PGW-U, 6G MMF (6G mobility management function / node), 6G SMF (6G session management function / node), a UDM+HSS and / or the like. The core network node may be a 5G core network node, a 6G core network node, a 4G core network node, the likes, and / or a combination thereof. One or more names may be used by a core network node. A function performed by a first core network node of 5GS may be performed by a second core network node of 6GS.

[0304] In the specification, the term “5G core network” may be interpreted as, or may refer to, a core network connecting to a 5G access network. This may be 5G core (5GC).

[0305] In the specification, the term "5G access network” may be interpreted as, or may refer to, an access network comprising at least one of a NG-RAN and / or non-3GPP RAN, and connecting to a 5G core network.

[0306] In the specification, the term “3GPP RAN” may be interpreted as, or may refer to, a radio access network using 3GPP RAT. For example, this may comprise at least one of a gNB, an eNB, a ng-eNB, an en-gNB, the like, and / or a combination thereof. For example, this may be at least one of an E-UTRAN, NG-RAN, 6G-RAN (6th generation RAN), the like, and / or a combination thereof. The 3GPP RAN may be 3GPP access node.

[0307] In the specification, the term “NG-RAN” may be interpreted as, or may refer to, a base station, which may comprise at least one of a gNB, a ng-eNB, a relay node, a base station central unit (e.g., gNB-CU), a base station distributed unit (e.g., gNB-DU), and / or the like. This may be a radio access network that connects to 5GC, supporting at least one of NR, E-UTRA, and / or a combination thereof.

[0308] In the specification, the term “E-UTRAN” may be interpreted as, or may refer to, a base station, which may comprise at least one of an eNB, an en-gNB, and / or the like. This may be a radio access network that connects to evolved packet core (EPC), supporting at least one of NR, E-UTRA, and / or a combination thereof.

[0309] In the specification, the term “mobility management node” may be interpreted as, or may refer to, a function and / or a node performing mobility management for a UE. For example, mobility management may be at least one of management of registration status, management of context, management of authorization, management of registration area, management of paging, and / or the like. For example, the mobility management node may comprise at least one of a MME, AMF, a 6G AMF, and / or the like.

[0310] In the specification, the term “session management node” may be interpreted as, or may refer to, a function and / or a node performing session management for a UE. For example, session management may be atDocket No.: 25-1063PCTleast one of management of data session status, management of data session context, management of authorization of data session, management of quality of service of a data session, and / or the like. For example, the session management node may comprise at least one of a PGW, a SGW, a SMF, a 6G SMF, and / or the like.

[0311] In the specification, a term “procedure” may be interpreted as, or may refer to, comprising at least one of sending by a first node to a second node a first message, receiving by the second node from the first node the first message, sending by the second node to the first node a second message, and / or receiving by the first node from the second node the second message. The first node may be one or more first network nodes, and the second node may be a one or more second network nodes. The procedure may comprise a registration procedure, a deregistration procedure, a service request procedure, a notification procedure, a PDU session establishment procedure, a PDU session modification procedure, a UE configuration update procedure, a cell selection procedure, a cell reselection procedure, a random access procedure, a capability update procedure, and / or the like.

[0312] In the specification, a term “NAS message" may be interpreted as, or may refer to, a message exchanged between a UE and a core network node. The NAS message may be exchanged via a 3GPP access and / or via a N3GPP access. The NAS message may comprise a MM (mobility management) message, a SM (session management) message, and / or the like. The MM message may comprise at least one of a registration request message, a registration accept message, a registration reject message, a UE configuration update message, a UL NAS transport message, a DL NAS transport message, a deregistration message, a service request message, a service accept message, a service reject message, and / or the like. The SM message may comprise at least one of a PDU session establishment request message, a PDU session establishment accept message, a PDU session establishment reject message, a PDU session modification request message, a PDU session modification accept message, a PDU session modification reject message, a PDU session modification command message, a PDU session release request message, a PDU session release command message, and / or the like. For example, the MM message may be a message exchanged between a UE and a mobility management node. For example, the SM message may be a message exchanged between a UE and a session management node.

[0313] In the specification, a term “AloT” may be interpreted as, or may refer to, Ambient loT.

[0314] In the specification, a term “AloT device” may be interpreted as, or may refer to, an loT device powered by energy harvesting, with limited energy storage capability. The AloT device may communicate with an application function via at least one or more AloT readers and / or one or more AloTFs.

[0315] In the specification, a term “AloT service" may be interpreted as, or may refer to functionalities and procedures to support Ambient loT use cases.

[0316] In the specification, a term “AloT reader” may be interpreted as, or may refer to, an entity (node, function) supporting A-Uu air interface towards Ambient loT Devices, registers with an AloT Controller (e.g., AloTF), supports the following functionality, based on requests from an AloT Controller: perform one-time or periodic Inventory, deliver Inventory result to AloT Controller; delivers Commands from an AloT controller to an AloTDocket No.: 25-1063PCTDevice; delivers Command Responses received from an AloT Device to an AloT Controller. The AloT reader may be at least one of a AloT UE reader or a AloT BS reader. The AloT UE reader may be a UE AloT reader, a UE configured for AloT reader functionality, and / or the like. The AloT UE reader may be a UE supporting AloT reader functionality. The AloT UE reader may be used interchangeably with a UE AloT reader, a AloT wireless device reader, a UE supporting the AloT UE reader functionality, a UE configured for operating as AloT UE reader, and / or the like.

[0317] In the specification, a term "UE” may be used interchangeably with “wireless device”. The UE maybe at least one of a AloT device, a UE not supporting AloT reader functionality, a UE supporting AloT reader functionality, and / or the like.

[0318] In the specification, a term “AloT Controller” may be interpreted as, or may refer to, an entity (node, function) register AloT readers, authenticate and authorize Afs, based on requests from an AF: verify whether an AF is entitled to issue a specific Inventory Request; select Readers to fulfil Inventory or Command request by AFs; forward Inventory request to Readers and deliver Inventory result to AF; forward Command to Readers and Command Responses to AF; collect usage data per AF, e.g. for charging purposes. The AloT controller may be an AloTF.

[0319] In the specification, a term “AloT message” may be interpreted as, or may refer to, a message exchanged between a UE and a core network node supporting AloT. For example, the core network node supporting the AloT maybe an AloTF. The AloT message maybe a NAS container, a AloT container, an AloT control message, an AloT reader control message, and / or the like.

[0320] In an example, a timer may begin running once it is started and continue running until it is stopped or until it expires. A timer may be started if it is not running or restarted if it is running. A timer may be associated with a value (e.g. the timer may be started or restarted from a value or may be started from zero and expire once it reaches the value). The duration of a timer may not be updated until the timer is stopped or expires (e.g., due to change of the value). A timer may be used to measure a time period / window for a process. When the specification refers to an implementation and procedure related to one or more timers, it will be understood that there are multiple ways to implement the one or more timers. For example, it will be understood that one or more of the multiple ways to implement a timer may be used to measure a time period / window for the procedure. For example, a network slice inactivity window timer (e.g., a NS UE monitoring timer, a NS PDU monitoring timer) may be used for measuring a window of time for measuring the network slice inactivity. In an example, instead of starting and expiry of a network slice inactivity window timer, the time difference between two time stamps may be used. When a timer is restarted, a process for measurement of time window may be restarted. Other example implementations may be provided to restart a measurement of a time window.

[0321] In an example, indication (e.g., indicate, indicating) may be achieved in various ways. For example, a first indication may be done by including a first field in a first signalling (e.g., a message). Alternatively and / or additional, a second indication may be done by not including the first field in the first signalling. For example, if aDocket No.: 25-1063PCTfirst message comprises the first field (e.g. , used / assigned for the first indication, e.g. , field A), the first indication (e.g. , a timer is used) may be done (e.g., achieved, delivered from a sender to a receiver). For example, if the first field in the first message is set to a value A, a third indication (e.g., timer value is value A) may be done. For example, if the first message does not comprise the first field, the second indication (e.g., timer is not used) may be done. In another example, a fourth indication (e.g., a UE is allowed for action C) may be done by sending a second signalling (e.g., a message whose name comprises ‘C and / or 'accept'). Alternatively and / or additionally, a fifth indication (e.g., a UE is not allowed for action C) may be done by not sending the second signalling (e.g., a message, a field (e.g., allowed bit)). For example, the sender can indicate A, by sending a message A1 comprising an indicator (e.g., an information element) indicating A and / or by sending a message A2. For example, the message A2 may be used only to indicate A and / or the message A2 itself may indicate the A. For example, when a first entity indicates to a second entity about first something, the first entity may send to the second entity, an indicator (e.g., an information element) indicating the first something, and / or may send to the second entity, a message comprising the indicator and / or may send a first dedicated message for the first something. In other example, when a first entity does not indicate to a second entity about second something, the first entity may not send to the second entity, a first indicator (e.g., an information element) indicating the second something, may not send to the second entity, a message comprising the first indicator, and / or may send to the second entity, a second indicator indicating that the second something does not apply, and / or may send a message not comprising the first indicator, and / or may send to the second entity, a second dedicated message for indicating the second something. In another example, ‘not sending any message’ may be interpreted as an indication. In an example, ‘indicate’ may mean ‘comprise one or more parameter indicating’.

[0322] In an example, an indicator and / or an indication may be a parameter. In an example, an indicator and / or an indication may comprise one or more parameters, and / or may be implemented using one or more parameters.

[0323] In an example, ‘based on a message (one or more messages)’ may be interpreted, or may refer to, as, ‘based on one or more information (one or more parameters) included in the message (the one or more messages)', ‘using (acting) on one or more information (one or more parameters) included in the message (the one or more messages)', and / or the like.

[0324] In an example, that a message indicates A may be interpreted that a parameter of the message indicates A, that the parameter of the message is A, and / or the like.

[0325] FIG. 25 illustrates an example as per an aspect of an embodiment of the present disclosure. For brevity, based on the other part of the present disclosure, redundant details will be omitted.

[0326] For example, a UE configured for acting an AloT reader may have two interfaces. A first interface may be an interface between the UE and a AloT device, and a second interface may be an interface between the UE and the AloTF. The interface between the UE and the AloT device may be an AloT-Uu interface, an A-Uu interface, and / or the like. The interface between the UE and the AloTF may comprise one or more sub-interfaces. For example, the one or more sub-interface may comprise a first sub-interface, a second sub-interface, and / or the like.Docket No.: 25-1063PCTThe first sub-interface may be a Uu interface, which is between the UE and a base station (e.g. , RAN, g N B, 6g NB). The second sub-interface may be an interface between the base station and one or more core network nodes. The one or more core network nodes may comprise at least one of a MM node, a SM node, an AloTF.

[0327] For example, the UE may serve one or more AloT devices. Based on the number of the one or more AloT devices, based on a total amount of data delivered from / to the one or more AloT devices, and / or based on an amount of radio resources allocated for the A-Uu interface, resources for communication between the UE and the one or more AloT devices may be congested and / or overloaded. In this case, the AloT reader may determine to address congestion by itself. For example, addressing the congestion may be at least one of that the AloT reader sends a request for more radio resources for A-Uu interface, that the AloT readers applies an unified access control so that accesses of the one or more AloT devices are distributed over time, that AloT readers distributes A- Uu interface resource among the one or more AloT devices, and / or the like. This may help the UE to resolve overload situation.

[0328] On the other hand, the interface between the UE and the AloTF may be congested. For example, if a lot of UEs acting as AloT UE reader access the AloTF, the interface between the UE and the AloTF may be congested. For example, the AloTF may not be able to handle all requests from the one or more UEs. In this case, while the UE may be able to handle congestion between the AloT devices and the UE, the UE may not be able to handle the congestion of the AloTF. Alternatively speaking, the solution to address the congestion between the UE and the AloT device may not be able to handle / al leviate the congestion between the UE and the AloTF.

[0329] FIG. 26 illustrates an example as per an aspect of an embodiment of the present disclosure. When an AloTF is congested, the AloTF may send a response message, to a wireless device, comprising one or more parameters. Based on the one or more parameters, the UE may determine when to (re)send a request message to the AloTF. This may help to resolve overload situation at the AloTF. For brevity, based on the other part of the present disclosure, redundant details will be omitted.

[0330] In an example, an AloTF may send a first AloT message to a sender. The sender may be configured for an AloT reader functionality. The AloTF may send the first AloT message, in response to receiving an AloT message from the sender. The sender may be at least one of a UE and / or a BS (base station).

[0331] The AloTF may determine to send the first AloT message, based on at least one of whether the AloTF is congested, based on whether the AloTF does not have resources, based on whether the sender is allowed to operate as the AloT reader, based on priority of the sender as the AloT reader, and / or the like. For example, if the AloTF is congested, the AloTF may determine to send an indication of a rejection to the sender. The rejection may be a rejection to a request (indicated by the AloT message) of the sender. In another example, if the AloTF is not congested, the AloTF may determine not to send the indication of the rejection and / or may determine to send an indication of allowance.

[0332] For example, the AloT message may be at least one of an AloT reader registration request message, an AloT UL transport message, an AloT service request message, and / or the like. The AloT reader registrationDocket No.: 25-1063PCTrequest message may be a message for requesting registration of the sender (e.g., the UE, the base station) as the AloT reader and / or may not be a request of registration for mobility management. The AloT UL transport message may be a message for transporting one or more AloT related messages from one or more AloT devices and / or the sender to the AloTF. The AloT service request message may be a message for requesting a service (e.g., activating resources, configuration) associated with AloT operation. The AloT message may be a request for registration, service, transport, and / or the like.

[0333] For example, the sender may be at least one of a AloT UE reader or AloT BS reader. The AloT UE reader may be a UE supporting an AloT reader functionality, a UE configured for the AloT reader functionality, and / or the like.

[0334] For example, the first AloT message may comprise one or more parameters, for AloT operation. The one or more parameters may comprise at least one of: a first parameter indicating the rejection; a second parameter indicating a cause; a third parameter indicating one or more areas; a fourth parameter indicating a time value; a fifth parameter indicating one or more conditions; and / or the like.

[0335] The first parameter may indicate that the request (e.g., indicated by the AloT message, a request from the sender) is rejected. For example, that the request is rejected is that the registration of the AloT reader is rejected, that the service request for the AloT is rejected, that the transport is rejected, that AloT related procedure is rejected, and / or the like. The rejection may be associated with AloT and / or may not be related to the mobility management.

[0336] The second parameter may indicate a reason why the request is rejected. The reason may be at least one of that the AloTF is congested, that the sender is not authorized as the AloT reader, that the sender is not valid entity, that a current area of the sender is not allowed for the AloT reader, and / or the like. For example, the sender may be a node or device which sends the AloT message and / or the request. This may help the sender of the AloT message to be aware a problem.

[0337] The third parameter may indicate the one or more areas whether the rejection applies. For example, if the AloTF determines that the sender is not allowed as the AloT reader in area A1 , the third parameter may indicate the area A1. The area may be associated with an AloT operation and / or an AloT UE reader functionality. This may help the sender to understand where the sender can be allowed to operate as the AloT reader, where the sender is not allowed for AloT reader, where the sender can send the request, where the sender can perform AloT related procedures, and / or the like. This may help the sender to be aware of when . In an example, this may be an AloT registration areas, one or more cells, one or more tracking areas, and / or the like. In an example, this may not a registration area for mobility management. In an example, this may be one or more AloT forbidden areas.

[0338] The fourth parameter may indicate at least one of a time period during which the rejection applies, a time period during which the sender is not allowed to send the request again, and / or the like. The time period may be indicated by a time value. For example, the fourth parameter may be the time value. This may help the sender to understand how long the sender is not allowed to send one or more AloT messages to the AloTF. Not allowed toDocket No.: 25-1063PCTsend one or more AloT messages to the AloTF may be not allowed to trigger AloT related procedure toward the AloTF. This may help the AloTF to remedy any congestion. The timer may be an AloT timer. The AloT timer may be a timer used to control one or more AloT procedures and / or may not be used to control one or more mobility management related procedures.

[0339] The fifth parameter may indicate one or more conditions where the rejection (e.g., rejection for registration, rejection for service request, and / or the like) applies. For example, if at least one of the one or more conditions are met, the rejection may apply. For example, if at least one of the one or more conditions are not met, the rejection may not apply. That the rejection may apply may be that the sender is not allowed to trigger one or more AloT related procedure. Not allowed to trigger one or more AloT related procedure may be that the sender may not be allowed to send one or more messages associated with AloT. While the rejection applies, the UE may send one or more messages (e.g., service request, registration request) associated with mobility management, because mobility management node is not congested.

[0340] In examples described later, further details on the one or more parameters are provided.

[0341] In an example, the sender may receive the first AloT message. Based on the one or more parameters in the first AloT message, the sender may determine whether to send a second AloT message to the AloTF or not.

[0342] For example, based on the fourth parameter, based on that the first AloT message indicates the rejection and / or based on receiving the first AloT message indicating the rejection, the sender may start a timer with the time value. The timer may be a timer dedicated to AloT reader operation. While the timer is running, until the timer stops, and / or before expiry of the timer, the sender may not send the request (e.g., an AloT service request, an AloT UE reader registration request, a uplink AloT data transport request) to the AloTF. In another example, after the expiry of the timer, while the timer is not running, and / or after the timer stops, the sender may send the request to the AloTF. In another example, if the sender moves into area not indicated by the third parameter and / or if the sender moves out of the area indicated by the third parameter, the sender may stop the timer and / or may send the request. For example, sending the request may be sending the second AloT message indicating the request. The request may be the request of the AloT message.

[0343] For example, based on the third parameter, the sender may determine whether the sender is located inside the area indicated by the third parameter or not. If the sender determines that the sender is located outside of the area, the sender may determine that the sender is allowed to send the second AloT message. The second AloT message may be similar to the AloT message and / or may be used for a same procedure and / or a purpose of the AloT message. For example, the second AloT message may comprise one or more fields. The one or more fields may comprise an indication indicating request for registration of the sender as the AloT reader.

[0344] For example, based on the fifth parameter, the sender may determine whether the one or more conditions are met. For example, if the one or more conditions are met, the sender may determine that the sender is allowed to act as an AloT reader. For example, if the one or more conditions are not met, the sender may determine that the sender is not allowed for acting as an AloT reader. The one or more conditions may comprise at least a timeDocket No.: 25-1063PCTcondition, a location condition, and / or the like. This may help for the sender to reduce unnecessary signalling toward the AloTF.

[0345] For example, based on the second parameter, the sender may determine what causes the rejection. For example, if the cause indicates that the sender is not allowed for AloT reader functionality, the sender may not send one or more AloT messages to the AloTF. For example, if the cause indicates that the sender is not allowed for AloT reader functionality in an area, the sender may send the request, after the sender moves out of the area. For example, if the cause indicates that the AloTF is congested, the sender may send the request, after the timer expires.

[0346] The example of FIG.26 may help unnecessary signalling from the sender to the AloTF.

[0347] Fig.27 illustrates an example as per an aspect of an embodiment of the present disclosure. By performing congestion control based on status of AloTF, a network can control whether to allow a procedure associated with an AloT. For brevity, based on the other part of the present disclosure, redundant details will be omitted.

[0348] In an example, a UE may perform a registration procedure. The UE may be a UE supporting an AloT reader functionality. The AloT reader functionality may be an AloT UE reader functionality. The registration procedure may be similar to example shown in FIG. 10.

[0349] Revering to FIG.27, the UE may send a registration request message to a mobility management (MM) node. The MM node may be at least one of an AMF, a 6G AMF, a 6G mobility management function, and / or the like. The MM node may perform mobility management. Performing mobility management may be to handle mobility issue of the UE. The mobility issue may be managing registration of the UE toward a communication system (e.g., a 5GS, a 6G system), authenticating the UE, paging the UE, keeping registration area of the UE, determining whether to allow mobility registration of the UE or not, determining and / or the like. For example, based on general congestion of a network, the MM node may determine whether to accept registration of the UE for mobility management or not. For example, if the MM node determines to rejection the UE registration for mobility management, the UE may not able to further perform procedures (e.g., PDU session establishment, AloT service request), until the UE registers for mobility management.

[0350] The registration request message may further comprise a parameter indicating that the UE supports the AloT reader functionality, an identifier for mobility management and / or the like. The identifier for mobility management may be at least one of GUTI, SUPI, PEI, and / or the like. The identifier for mobility management may be a UE identifier and / or may allow one or more network nodes of the network to identify the UE. The indication that the UE supports the AloT reader functionality may help the MM node to determine whether the MM node is a right one to handle the UE, in terms of AloT reader functionality. For example, if the MM node does not support the AloT reader functionality, the MM node may ask other MM node to take care of the UE.

[0351] In response to receiving the registration request message, the MM node may send a registration accept message to the UE. The registration accept message may indicate that the UE is registered for mobilityDocket No.: 25-1063PCTmanagement and / or that the network (of the MM node) supports AloT functionality. That the network supports AloT functionality may be that the network supports AloT UE reader functionality. The AloT UE reader functionality may be one or more procedure (e.g., inventory, command) for AloT using the AloT UE reader. This may help the UE to determine whether the UE can proceed to perform registration requesting registration as AloT reader. For example, if registration accept message indicates that the network supports the AloT reader functionality, the UE may send a request for AloT reader registration. For example, if registration accept message does not indicate that the network supports the AloT reader functionality, the UE may not send a request for AloT reader registration. For example, before sending the registration accept message, the MM node may determine whether the network resource is congested or not, considering one or more network nodes.

[0352] For example, the registration accept message may comprise at least one of a temporary identifier allocated to the UE for mobility management, one or more network slices allowed for the UE, one or more features supported by the network, and / or the like.

[0353] Based on receiving the registration accept message, the UE may determine that the UE is registered for mobility management, for 5GS, for 6GS and / or the like. After receiving the registration accept message and / or based on that the network supports the AloT functionality, the UE may send a first RRC message. The first RRC message may be at least one of first RRC UL Transport message, first RRC reconfiguration complete message, first RRC setup complete message, and / or the like. The first RRC message may comprise a first NAS message.

[0354] The first NAS message may be at least one of a first NAS UL transport message, a first service request message, a first registration request message, and / or the like. For example, the first NAS message may comprise at least one of a first AloT message, a type indicator, and / or the like. The type indicator may indicate whether the first NAS message comprises an AloT message (e.g., the first AloT message) or not. For example, if the type indicator is set to a first value (e.g., a value associated with AloT message type), the first NAS message may comprise the AloT message. For example, if the type indicator is not set to the first value, the first NAS message may not comprise the AloT message. The type indicator may help a receiver (e.g., the MM node) to determine whether the first NAS message comprise the AloT message and / or whether the MM node needs to forward the AloT message in the first NAS message to the AloTF.

[0355] An AloT message may be an AloT message container (AloT container). The AloT message may be a message exchanged between the UE and the AloTF.

[0356] The first AloT message in the first NAS message may be at least one of a first AloT reader registration request message, a first AloT service request message, a first AloT UL transport request message, and / or the like. The first AloT reader registration request message may be a message indicating (requesting) that the UE wants to be registered as an AloT reader. The first AloT reader registration request message may comprise an AloT UE reader identifier, one or more capabilities associated with the AloT UE reader functionality, and / or the like. The AloT UE reader identifier may be an identifier associated with the AloT reader functionality The AloT UE reader identifier may be different from the identifier for mobility management. The AloT UE reader identifier may be anDocket No.: 25-1063PCTidentifier used for AloT functionality and / or AloT UE reader functionality. The AloT UE reader identifier may uniquely identify the UE among the one or more UEs acting as the AloT UE reader. The identifier for mobility management may be an identifier allocated to identify the UE among one or more mobility management nodes (e.g., AMFs), for mobility management, and / or among one or more core network nodes.

[0357] In response to receiving the first NAS message and / or based on the type indicator indicating that the first NAS message comprises the AloT message, the MM node may determine to forward the first AloT message included in the first NAS message to the AloTF. Based on determining to forward the first AloT message, the MM node may send a first Naiotf service request message to the AloTF. The first Naiotf service request message may comprise at least one of the first AloT message, the identifier of the UE, and / or the like. The identifier of the UE may be the identifier for mobility management, the UE identifier. The identifier of the UE may help the MM node and the AloTF to identify the UE, regardless of whether the MM node is aware of the AloT UE reader identifier. The identifier of the UE may be allocated by the MM node, and / or may uniquely identify the UE regardless of whether the UE supports the AloT UE reader functionality or not.

[0358] In response to receiving the first Naiotf service request message, the AloTF may determine whether to accept the request conveyed by the first Naiotf service request and / or the first AloT message. Determining whether to accept the request may be whether to accept or reject the request delivered by the first AloT message. For example, whether to accept or reject may be whether to accept the registration request for AloT UE reader or not. The registration request for AloT UE reader may be the AloT UE reader registration request.

[0359] In an example, based on that the AloTF is congested, that the UE is not authorized for AloT UE reader functionality, and / or that the UE is located in an area whether the UE is not allowed for AloT UE functionality, the AloTF may determine to reject the request from the UE. For example, to reject the request from the UE may be that the AloTF determines to reject the registration request of the UE as the AloT UE reader.

[0360] In an example, based on determining to reject the request from the UE, the AloTF may send a first Naiotf service response message to the MM node. For example, the first Naiotf service response message may comprise at least one of a second AloT message, the identifier of the UE, a result code, and / or the like.

[0361] The second AloT message may be a first AloT reader registration response message. The first AloT reader registration response message may be a first AloT reader registration reject message and / or a first AloT reader registration accept message. The first AloT reader registration reject message may be a message indicating that the AloTF rejects the request of the UE being registered for / as the AloT UE reader. The first AloT reader registration reject message may comprise the AloT UE reader identifier, the one or more parameters (as shown in the example of FIG.26, e.g., the first parameter, the second parameter, the third parameter, the fourth parameter, the fifth parameter), and / or the like.

[0362] The result code may indicate whether the request from the UE is successfully accepted or rejected. For example, the AloT message (e.g., the first AloT message, the second AloT message) exchanged between the UE and / or the AloTF may be encrypted. Because the AloT message is encrypted, a middle entity (e.g., the MM node)Docket No.: 25-1063PCTmay not be able to interpret information delivered by the AloT message. In this case, by adding a separate field into the first Naiotf service response, the MM node may determine whether the request from the UE is accepted or rejected.

[0363] In an example, the MM node may receive the first Naiotf service response. In response to receiving the first Naiotf service response and / or based on that the first Naiotf service response comprises the second AloT message, the MM node may determine to send a second NAS message to the UE. The second NAS message may be at least one of a first DL transport message, a first service response (accept / reject) message, a first registration response (accept / reject) message, and / or the like. The second NAS message may comprise at least one of the second AloT message, a second type indicator. The second type indicator may serve same purpose as the type indicator. The second type indicator may indicate whether the second NAS message comprises a AloT message (e.g., the second AloT message) or not. For example, the second type indicator may be set to a value. The value may be a value reserved to indicate a AloT message type.

[0364] In an example, the UE may receive a second RRC message, from a base station. The second RRC message may be at least one of a first RRC DL Transport message, a first RRC reconfiguration message, a first RRC setup message, and / or the like. The second RRC message may comprise the second NAS message.

[0365] In an example, the UE may receive the second NAS message delivered by the second RRC message.The UE may determine whether the UE is successfully registered as the AloT UE reader. For example, based on receiving the second AloT message indicating that the request for registration as the AloT UE reader is rejected, the UE may determine that the UE is not registered as the AloT UE reader. For example, based on being rejected for registration as the AloT UE reader, and / or based on receiving the one or more parameters, the UE may start the timer as the time value (as shown in the example of FIG. 26). For example, because the request of the UE for being registered as the AloT UE reader is rejected (based on the second AloT message), because the second AloT message comprises the time value (e.g., the fourth parameter), the UE may start the timer with the time value. The timer may be associated with the AloT UE reader functionality.

[0366] For example, based on receiving the second NAS message indicating that the UE is not registered as the AloT UE reader and / or based on receiving the registration accept for mobility management, the UE may remain as registered for mobility management and / or may remain as unregistered for AloT UE reader functionality.

[0367] In an example, while the timer is running, the UE may not send a third AloT message, to the AloTF and / or the UE may not send a third NAS message comprising the third AloT message, to the MM node. For example, the third AloT message may indicate the same request as the request of the first AloT message. For example, the third AloT message may be a second AloT reader registration request message.

[0368] For example, while the timer is running, the UE may send a periodic registration request message to the MM node. For example, the periodic registration request message may be used for the UE to remain as registered for mobility management, in the MM node. For example, a first type registration (e.g., MM registration) at the MM node may be associated with 5GS / 6GS procedure and / or may be used to get allowance to further perform aDocket No.: 25-1063PCTsecond type registration (e.g. , registration as AloT UE reader). For example, if the UE is not registered for the MM (mobility management), the UE may not request registration for the AloT UE reader. For example, if the UE is registered for the MM (mobility management), the UE may request registration for the AloT UE reader. In this sense, regardless of whether the UE is registered to the AloTF as AloT UE reader or not, and / or regardless of whether the timer is running to prevent the UE from sending AloT UE reader registration request message (e.g., performing AloT related procedure), the UE may send a registration request message to the MM node, for request / update registration for mobility management.

[0369] In an example, after starting the timer, before the expiry of the timer, and / or while the timer is running, the UE may stop the timer, if the UE moves into a new area (e.g., cell, TA, AloT area) different from one or more areas (indicated by the third parameter, indicated by one or more forbidden AloT area, indicated by a AloT registration area). Alternatively and / or additionally, if the UE sends a deregistration request for mobility management to the MM node, the UE may stop the timer.

[0370] In an example, the timer may expire. Based on that the timer expires, based on that the UE wants to register to the AloTF as the AloTF UE reader, and / or based on that the UE is still registered for mobility management, the UE may send the third AloT message to the AloTF. To send the third AloT message to the AloTF, similar procedure as shown for the delivery of the first AloT message to the AloTF may be used. For example, the UE may send the third NAS message comprising the third AloT message, to the MM node.

[0371] In examples shown above, a AloT message is exchanged between the UE and the AloTF via the AMF.Alternatively and / or additionally, the AloT message (e.g., the first AloT message, the second AloT message, the third AloT message) may be delivered / transported without traversing the MM node. For example, if the base station has a direct communication path to the AloTF, the AloT message may be routed from / to the base station to the AloTF, without traversing the MM node. In this case, same procedure and / or principle described above may be applicable.

[0372] For example, the UE may send the first RRC message to the base station. The first RRC message may comprise the first AloT message and / or the type indicator. Based on the type indicator, the base station may determine that the first RRC message comprises at least one AloT message and / or may forward the at least one AloT message (e.g., the first AloT message) to the AloTF, not to the MM node. Similarly, if the base station and the AloTF have a direct connection, the AloTF may send the second AloT message directly to the base station, and not to the MM node. In this case, the base station may send the second RRC message comprising the second AloT message and the type indicator indicating that the second RRC message comprises at least one AloT message, to the UE.

[0373] Alternatively and / or additionally, the UE may perform multiple AloT UE reader registrations toward multiple AloTFs. For example, if different AloT devices are associated with different AloT service providers, each AloT service provider may be associated with different AloTFs. In these case, the UE may send a plurality of AloT UE reader registration request messages to a plurality of AloTF. In this case, some AloTFs may be congestedDocket No.: 25-1063PCTwhile the other AloTFs may not be congested. For the UE to determine to which AloTF the timer applies, a AloT session identifier may be used. For example, the first NAS message may further comprise a first AloT session identifier, to indicate that the first AloT message may be associated with the first AloT session and / or a first AloTF. The first AloT session identifier may be associated with a first AloT service provider and / or the first AloTF. For example, a fourth NAS message, sent by the UE to the MM node, may further comprise a second AloT session identifier, to indicate that a fourth AloT message (included in the fourth NAS message) may be associated with the second AloT session. The second AloT session identifier may be associated with a second AloT service provider and / or a second AloTF. This AloT session identifier may help the MM node to determine to which AloTF each AloT message should be routed to. This AloT session identifier may help the UE to identify to which AloTF a AloT related procedure is allowed and / or restricted. For example, based on the AloT session identifier, the MM node may determine not to forward the AloT message, if the AloTF associated with the AloT session identifier is congested.

[0374] The example of FIG.27 may help in preventing a UE from sending unnecessary AloT UE reader registration request to the AloTF.

[0375] Fig.28 illustrates an example as per an aspect of an embodiment of the present disclosure. In an example, an AloTF may send to a MM node (mobility management node), an information indicating that the AloTF is congested. This may help for the MM node in reducing unnecessary signaling toward the AloTF. For brevity, based on the other part of the present disclosure, redundant details will be omitted.

[0376] In an example, the UE may send the registration request message to the MM node and / or may receive the registration response (accept) message from the MM node (as shown in the example of the FIG.27).

[0377] In an example, the AloTF may determine that the AloTF is congested, that the AloTF is overloaded, that the AloTF cannot further process any more request related to AloT operation (e.g., AloT UE reader functionality), and / or the like. Based on the determination, the AloTF may send to the MM node, a notification. For example, the notification may be a Naiotf Notification message. For example, the MM node may be at least one of an AMF, an 6G AMF, a 6G mobility management node and / or the like. The notification may comprise a notification parameter. The notification parameter may indicate at least one of that determine that the AloTF is congested, that the AloTF is overloaded, that the AloTF cannot further process any more request related to AloT operation (e.g., AloT UE reader functionality), and / or the like. The notification may comprise at least one of an identifier of the AloTF, one or more AloT session identifiers associated with the AloTF, one or more areas (e.g., cells, TAs, PLMNs) served by the AloTF, and / or the like.

[0378] In an example, the MM node may receive the Naiotf Notification message. Based on the Naiotf Notification message, the MM node may determine that the AloTF is congested.

[0379] In an example, the MM node may receive from the UE, the first NAS message (as shown in the example of FIG.27). Based on one or more information in the first NAS message, the MM node may determine that the UE is requesting a AloT service. For example, the one or more information may be one or more fields. For example,Docket No.: 25-1063PCTthe one or more fields may comprise a type indicator. For example, that the UE is requesting the AloT service may be that the UE is requesting registration of the UE as the AloT UE reader, that the UE is sending a AloT messages to the AloTF, and / or the like. For example, based on that the type indicator of the first NAS message indicates the AloT message (e.g., the first AloT message), the MM node may determine that the UE is sending the AloT message to the AloTF. Alternatively, and / or additionally, the first NAS message may comprise an AloT session identifier. Based on that the AloT session identifier is associated with the AloTF, the MM node may determine that the UE is sending the AloT message to the AloTF. That the type indicator of the first NAS message indicates the AloT message may be that the type indicator is set to a value reserved for a AloT message type. That the UE is sending the AloT message to the AloTF may be that the first NAS message comprises the AloT message (e.g., the first AloT message).

[0380] In an example, based on that the UE is sending the AloT message to the AloTF, the MM node may determine whether the AloTF is congested or not. For example, based on the notification received from the AloTF, the MM node may determine that the AloTF is congested. Based on determining that the AloTF is congested, and / or based on that the UE is sending the AloT message to the AloTF, the MM node may determine not to forward the AloT message (delivered by the first NAS message) to the AloTF, may determine to reject a service request of the UE, may determine to reject the first NAS message, may determine to reject the AloT message, and / or may determine to send a reject to the UE. To send the reject to the UE may be that to send an indication of rejection to the UE. To reject the AloT message may be that to reject a request of the UE to deliver the AloT message (e.g., the first AloT message) to the AloTF.

[0381] For example, to send the reject to the UE may be that the MM node sends a downlink NAS message to the UE. The downlink NAS message may comprise an indication that the request of the UE for the AloT (service / procedure) is rejected, the one or more parameters (e.g., as shown in the example of FIG. 26, 27). That the request of the UE for the AloT (service / procedure) is rejected may be that the MM node rejects the delivery of the AloT message to the AloTF. For example, the downlink NAS message may not comprise any AloT message received from the AloTF, because the MM node does not receive any response for the first AloT message, due to congestion of the AloTF. The downlink NAS message may comprise the first AloT message received from the UE, to indicate to the UE that the delivery of the first AloT message is failed (rejected). For example, the downlink NAS message may comprise the fourth parameter, to indicate the time value. For example, the UE may start the timer with the time value. For example, the downlink NAS message may comprise a cause value indicating that the delivery of the first AloT message fails, that the AloTF is congested, and / or the like. For example, the fourth parameter may be determined by the MM node, because the AloTF is congested.

[0382] In an example, the UE may receive the downlink NAS message from the MM node. Based on receiving the downlink NAS message, based on that the downlink NAS message comprises the time value, and / or based on that the delivery of the AloT message fails, the UE may start the timer with the time value. The behavior of the UE, with regard to the timer and / or the one or more parameters, may be similar to the behavior as shown in previousDocket No.: 25-1063PCTexamples (e.g. , FIG. 26, FIG, 27).

[0383] For example, the timer value and / or the one or more parameters of the FIG. 28 may be similar to those of the FIG 26 and / or FIG.27. While the timer value and / or the one or more parameters of example of the FIG.28 is originated / determined by the MM node and delivered to the UE by one or more fields of the downlink NAS message, the timer value and / or the one or more parameters of the example of the FIG. 26 / 27 is originated / determined by the AloTF by one or more fields in the AloT message (e.g.., the second AloT message).

[0384] For example, while the timer is running, the UE may not send additional request related to the AloT procedure. The additional request may be similar as the request of the first NAS message. For example, after the timer expires, the UE may send the additional request. For example, the additional request may be a third NAS message. For example, the contents of the third NAS message may be similar to the contents of the first NAS message.

[0385] The example of FIG.28 may help unnecessary signalling from the sender to the AloTF by a control of the MM node in the middle.

[0386] Fig.29 illustrates an example as per an aspect of an embodiment of the present disclosure. In an example, a registration request message for mobility management may further comprises a request for registration as an AloT UE reader. This combined registration request may help in reducing resource usage over air interface. For brevity, based on the other part of the present disclosure, redundant details will be omitted.

[0387] In an example, a UE (configured to operate as an AloT UE reader) may perform registration procedure (as shown in the previous example). For example, the UE may send a registration request message to the MM node. The registration message may comprise at least one of a UE identifier (i.e., the identifier for mobility management), a mobile registration type indicator indicating a type of mobility management registration, a network slice identifier indicating a requested network slice for mobility management, a parameter of the AloT (UE) reader capability, a parameter indicating that the UE supports the AloT UE reader capability, a parameter indicating a request for registration as the AloT UE reader, and / or the like. For example, based on that the registration request message comprises at least one of the parameter of the AloT (UE) reader capability, the parameter indicating that the UE supports the AloT UE reader capability, the parameter indicating a request for registration as the AloT UE reader, the MM node (e.g., the AMF, the 6G AMF) may determine that the UE is requesting not only registration for mobility management at the MM node, but also registration for AloT UE reader at the AloTF. Based on that the UE is requesting the registration for AloT UE reader, the MM node may send a first Naiotf service request message to the AloTF.

[0388] The first Naiotf service request message may comprise at least one of the UE identifier (e.g., the identifier of the UE), the AloT session identifier, the AloT UE reader identifier, the request for registration of the UE as the AloT UE reader, current location (e.g., cell ID, tracking area ID, PLMN ID) of UE and / or the like. For example, the current location of the UE may help the AloTF to understand current location of the UE and may help the AloTF when the AloTF perform AloT UE selection procedure. The request for registration of the UE as the AloT UEDocket No.: 25-1063PCTreader may indicate to the AloTF that the UE associated with the AloT UE reader identifier and / or the UE identifier is requesting registration as the AloT UE reader.

[0389] Based on receiving the first Naiotf service request, the AloTF may determine whether to accept or reject the request for registration of the UE as the AloT UE reader or not. For example, the AloTF may determine to reject the request based on congestion of the AloTF. In response to determining to reject the request, the AloTF may send a first Naiotf service response message to the MM node. For example, the first Naiotf service response may comprise at least one of the one or more parameters (e.g. , the first parameter, the second parameter, the third parameter, the fourth parameter, the fifth parameter, shown in the previous examples), the AloT UE reader identifier, the UE identifier, and / or the like.

[0390] In an example, the MM node may receive from the AloTF the first Naiotf service response message.Based on the one or more parameters and / or based on the first Naiotf service response message, the MM node may determine that the request for registration as the AloTF UE reader is rejected for the UE. For example, based on the first Naiotf service response message, the MM node may determine to reject the request of the UE registration as the AloT UE reader. Based on determining to reject the request of the UE as the AloT UE reader, the MM node may send to the UE, a second NAS message to the UE. For example, the second NAS message may be at least one of a registration accept message, a UE configuration update message, a downlink NAS transport message, and / or the like. Alternatively and / or additionally, the MM node may determine to reject the request of the UE registration as the AloT UE reader, based on receiving the Naiotf Notification message (as shown in the example of the FIG.28).

[0391] For example, the second NAS message may comprise at least one of the one or more parameters (as shown in previous examples), indication of successful registration for mobility management (at the MM node), indication of unsuccessful (e.g., rejection) registration for the AloT UE reader functionality (at the AloTF), indication of whether a network (e.g., of the MM node) supports the AloT (e.g., AloT UE reader functionality) and / or the like. For example, the second NAS message may indicate that the UE is successfully registered for the mobility management (e.g., to 5GS, to 6GS, for the network slice) and / or that the UE is not successfully registered for the AloT UE reader functionality. That the UE is not successfully registered for the AloT UE reader functionality may be that the request for registration as the AloT UE reader is rejected and / or that the UE is not allowed for operating as the AloT UE reader.

[0392] In an example, the UE may receive the second NAS message. Based on the second NAS message and / or based on that the second NAS message indicates successful registration for mobility management, the UE may determine that the UE is successfully registered to the network for mobility management (e.g., for the network slice, for the 5GS, for the 6GS). Based on the second NAS message and / or based on that the second NAS message indicates unsuccessful registration as the AloT UE reader, the UE may determine that the UE is not successfully registered to the AloTF and / or that the UE is not registered as the AloT UE reader.

[0393] In an example, the UE may determine whether to start the timer with the time value (e.g., as shown in theDocket No.: 25-1063PCTprevious examples), based on the one or more parameters in the second NAS message. Based on that the UE is not registered for the AloT UE reader, based on that the UE is rejected for registration as the AloT UE reader, based on that the UE is registered for mobility management, based on that the second NAS message comprises the time value (which is not zero), the UE may start the timer with the time value.

[0394] Alternatively and / or additionally, if the second NAS message comprises an indication that the UE is not registered for mobility management, and / or if the second NAS message indicates rejection of registration for mobility management, based on that the UE is not registered for the AloT UE reader, based on that the UE is rejected for registration as the AloT UE reader, based on that the UE is not registered for mobility management, and / or based on that the second NAS message comprises the time value (which is zero), the UE may not start the timer and / or the UE may not perform additional attempt for registration for the AloT UE reader functionality.

[0395] In an example, once the timer is started, while the timer is running, and / or while the timer is not stopped, the UE may not trigger registration for the AloT UE reader functionality. Not triggering registration for the AloT UE reader functionality may be that the UE sends another registration request message which is requesting registration for the mobility management and which is not requesting registration for AloT UE reader functionality, that the UE does not send a request for registration as the AloT UE reader, and / or that the UE sends a request for mobility management, and / or the like.

[0396] In an example, once the timer is stopped, once the timer expires, once the UE changes a selected PLMN, once the UE moves into new area, once the UE moves out of current registration area, once the UE moves out of an AloT registration area, and / or the like, the UE may stop the timer and / or the UE may trigger another registration procedure. For example, triggering another registration procedure may be to send another registration request message to the MM node. For example, the another registration request message may be similar to the registration request message (e.g., having similar contents) included in the registration request message. For example, the another registration request message may comprise at least one of the UE identifier (i.e. , the identifier for mobility management), the mobile registration type indicator indicating the type of mobility management registration, the network slice identifier indicating a requested network slice for mobility management, the parameter of the AloT (UE) reader capability, the parameter indicating that the UE supports the AloT UE reader capability, the parameter indicating a request for registration as the AloT UE reader, and / or the like.

[0397] In an example, based on receiving the another registration request, the MM node may send a second Naiotf service request message to the AloTF. The second Naiotf service request message may comprise a similar contents as the first Naiotf service request message.

[0398] In response to receiving the second Naiotf service request message, the AloTF may determine whether to accept / reject the request of the UE as the AloT UE reader. For example, after sending the first Naiotf service response message, the congestion at the AloTF may be resolved. Based on that the AloTF is not congested and / or the UE is authorized as the AloTF reader, the AloTF may determine to accept / allow the registration of the UE as the AloT UE reader. Based on determining, the AloTF may send a second Naiotf service responseDocket No.: 25-1063PCTmessage. The second Naiotf service response may comprise at least one of the identifier of the UE, the AloT UE reader identifier, indication of acceptance of the UE as the AloT UE reader, one or more areas where the UE is registered / allowed as the AloT UE reader, and / or the like. One or more areas where the UE is registered / allowed as the AloT UE reader may be a AloT registration area (e.g., an AloT UE reader registration area). In an example, for efficient congestion handling, the AloT registration area may be separate from the RA (e.g., for mobility management).

[0399] For example, the one or more areas may be one or more cells, TAs, and / or the like. The one or more areas may be a AloT registration area. The AloT registration area may be defined and / or managed by the AloTF. The AloT registration area may be different from the registration area for mobility management. For example, the registration area for mobility management may be managed / defined by the MM node. For example, the MM node maybe responsible for management in one or more TAs (eg., TA 1, TA 2, TA 3). For example, a first AloTF may be responsible for management in a first TAs (e.g., TA1, TA2) and / or a second AloTF maybe responsible for management in a second TAs (e.g., TA3). To support different scope of responsible area, using different registration area for AloT from the registration area for mobility management may be helpful. For example, by defining different area scope for each AloTF may help in reducing chances of congestion at the AloTF and / or in distributing requests associated with the AloT readers among multiple AloTFs. For example, when the UE moves into area which does not belong to the registration area for mobility management, the UE performs a registration procedure for mobility management, to the MM node. For example, when the UE moves into area which does not belong to the registration area for AloT UE reader functionality, the UE performs a registration procedure for AloT UE reader functionality, to the AloTF.

[0400] In an example, the MM node may receive the second Naiotf service response message from the AloTF.In response to receiving the second Naiotf service response, the MM node may send a fourth NAS message to the UE.

[0401] For example, the fourth NAS message may be at least one of a registration accept message, a UE configuration update message, a downlink NAS transport message, and / or the like.

[0402] For example, the fourth NAS message may comprise at least one of the one or more parameters, indication of successful registration for mobility management (at the MM node), indication of successful (e.g., allowance, accept) registration for the AloT UE reader functionality (at the AloTF), indication of whether a network (e.g., of the MM node) supports the AloT (e.g., AloT UE reader functionality), the identifier of the UE, the AloT UE reader identifier, indication of acceptance of the UE as the AloT UE reader, the one or more areas where the UE is registered / allowed as the AloT UE reader, a registration area (RA) where the UE is registered for the mobility management, and / or the like. For example, the fourth NAS message may indicate that the UE is successfully registered for the mobility management (e.g., to 5GS, to 6GS, for the network slice) and / or that the UE is successfully registered for the AloT UE reader functionality. That the UE is successfully registered for the AloT UE reader functionality may be that the request for registration as the AloT UE reader is accepted.Docket No.: 25-1063PCT

[0403] The example of FIG.29 may help efficient signalling to the AloTF, reducing congestion and supporting efficient NAS signalling.

[0404] Fig.30 illustrates an example as per an aspect of an embodiment of the present disclosure. In an example, the UE may perform registration to the AloTF via a user plane. This may help for AloTF to reduce congestion in the user plane. For brevity, based on the other part of the present disclosure, redundant details will be omitted.

[0405] In an example, the UE may perform a registration procedure toward the MM node (e.g., AMF, 6G AMF, 6G mobility management node), as shown in previous examples (e.g., FIG. 10). The UE maybe registered to a system (e.g., 5GS, 6GS) for a network service and / or for a mobility management. In this registration procedure, the UE may receive a registration accept message indicating an allowed network slice, one or more mobility management UE temporary identifier, information of a RA (registration area), and / or the like.

[0406] In an example, after performing registration procedure for mobility management, the UE may perform PDU session establishment procedure toward a SM node (e.g., SMF, 6G SMF, 6G session management node), as shown in previous examples (e.g., FIG. 12), for / via the allowed network slice. For example, the UE may establish a first PDU session for the allowed network slice, during the PDU session establishment procedure. For example, during the PDU session establishment procedure, the UE may receive a PDU session establishment accept message. The PDU session establishment accept message may comprise an identifier of the PDU session.

[0407] In an example, at least one of the registration accept message, the PDU session establishment accept message may comprise one or more security materials. The security materials may be a security token, a security key, and / or a security identifier This may help for the AloTF to verify whether the UE is a valid and legitimate UE.

[0408] Alternatively and / or additionally, via the control plane, the UE may receive a command from the AloTF.The command may comprise at least one of the one or more security materials and / or a user plane address of the AloTF, and / or a user plane port number of the AloTF. Based on receiving the command, the UE may send the AloT reader registration request message via the user plane, over the PDU session, to the address and the port number. For example, to reduce congestion via the control plane, the AloTF may send the command, indicating to use the user plane to establish a communication channel between the UE and the AloTF.

[0409] In an example, after establishing the PDU session, the UE may send the AloT reader registration request message to the AloTF via the PDU session. That the UE sends the AloT reader registration request message via the PDU session may be that the UE sends the AloT reader registration request message via the user plane, that the UE does not send the AloT reader registration request message via the control plane, that a RRC message or a NAS message is not used to encapsulate the AloT reader registration request message, that the AloT reader registration request is not delivered to the AloTF via a MM node, that the AloT reader registration request is delivered to the AloTF not via a MM node, and / or the like. On the other hand, in the example of FIG.26 and / or 27, the AloT reader registration request message is sent to the AloTF via the MM node and / or via the control plane. If the control plane interface of the AloTF is congested, using user plane interface of the AloTF may help in reducingDocket No.: 25-1063PCTcongestion of the control plane. The user plane may be associated with the PDU session and / or may be available via the PDU session. E.g., communication via the PDU session maybe communication via the user plane. The AloT reader registration request message may be the AloT reader registration request message as shown in previous examples.

[0410] For example, the AloT reader registration request message may comprise the UE identifier for mobility management, the AloT UE reader identifier, the indication that the UE supports the AloT UE reader functionality, the indication that the UE requests registration as the AloT UE reader, the one or more security materials, and / or the like. For example, based on the one or more security materials, the AloTF may determine whether the UE is a valid UE for AloT UE reader registration. For example, if the AloTF does not recognize the one or more security materials, the AloTF may reject the AloT UE reader registration, to reduce congestion.

[0411] In an example, the AloTF may receive the AloT reader registration request sent by the UE, via the user plane. Due to one or more reasons, the AloTF may determine to reject the request. For example, the one or more reasons maybe that the AloTF is congested also in the user plane, that the UE is notallowed for AloT UE reader functionality and / or the like.

[0412] In response to determining to reject, the AloTF may send a AloT Reader registration response message to the UE, via a user plane. For example, determining to reject may be determining to reject the AloT UE reader registration request and / or not to allow the UE as the AloT UE reader. For example, the AloT reader registration response message may comprise similar information as shown in previous examples. For example, the AloT reader registration response may comprise the one or more parameters (e.g., the first parameter, the second parameter, the third parameter, the fourth parameter, the fifth parameter, and / or the like), a AloT UE reader identifier, and / or the like. The AloT Reader registration response message may be at least one of a AloT Reader registration accept message and / or a AloT Reader registration reject message.

[0413] In an example, the UE may receive the AloT reader registration response message. Based on receiving the AloT reader registration response message indicating rejection (e.g., rejection of registration as the AloT UE reader), and / or based on the one or more parameters in the AloT reader registration response message, the UE may start the timer with the time value (as shown in previous examples). The timer may bean AloT backoff timer and / or may be a timer dedicated for AloT operation, and / or may be a timer to control one or more AloT procedure (associated with AloT UE reader operation). For example, the timer is used to control when the UE can send one or more AloT messages.

[0414] In an example, the UE may not send another AloT reader registration request message to the AloTF via the user plane, while the timer is running, until expiry of the timer, and / or until the timer is stopped. In another example, the UE may send the another reader registration request message to the AloTF via the user plane, after the timer expires, after the timer is stopped, and / or the like. The another AloT reader registration request message may be similar to the AloT reader registration request message (shown in previous examples).

[0415] In an example, based on sending the another AloT reader registration request message via the userDocket No.: 25-1063PCTplane, the UE may receive another AloT reader registration response via the user plane. The another reader registration response may indicate at least one of that the UE is registered as the AloT UE reader, one or more allocated AloT UE reader temporary identifiers, AloT UE reader registration areas, and / or the like. For example, the one or more allocated UE reader temporary identifiers may help the UE to be uniquely identified among the AloTF, while the UE is registered to the AloTF, for AloT related procedures.

[0416] Alternatively and / or additionally, when the UE receives, via the user plane, the AloT Reader registration response message indicating that the registration for the AloT UE reader functionality is rejected, the UE may send a report message to at least one of the SM node, the MM node, the AloTF, via the control plane. This may help for the SM node, the MM node or the AloTF to determine that there is also a problem in the user plane. For example, the problem may be a congestion in the user plane and / or in the PDU session and / or in the network slice.

[0417] The example of FIG.30 may help the AloTF to control congestion via using control plane and user plane.

[0418] Fig.31 illustrates an example as per an aspect of an embodiment of the present disclosure. After being rejected for registration as an AloT UE reader, a UE may move to an area managed by another AloTF which is not congested. The UE may retry registration as the AloT UE reader. This will help not only reducing congestion but also allowing the UE as the AloT UE reader on time. For brevity, based on the other part of the present disclosure, redundant details will be omitted.

[0419] In an example, a network may employ one or more areas. The one or more areas may be one or more tracking areas (TAs). Each TA of the one or more TAs may comprise one or more cells.

[0420] In an example, the UE may send a registration request message to a MM node. For example, the registration request message may be for mobility management. For example, the MM node may perform the mobility management. The registration request may comprise an identifier of the UE. The identifier of the UE may be a UE identifier. The UE identifier may be used for the mobility management. The MM node may be at least one of an AMF, an 6G AMF, a 6G mobility management node, and / or the like. The identifier of the UE may be at least one of a GUTI (global uniquely routable temporary identifier), a SURI, a SUCI, a PEI and / or the like.

[0421] In an example, in response to receiving the registration request message, the MM node may send a registration accept message to the UE. For example, based on determining to accept registration of the UE for the mobility management, based on determining a registration area (RA) of the UE, and / or based on determining one or more allowed network slices for the UE, the registration accept message may comprise at least one of information of the RA, the one or more allowed network slices, and / or the like. For example, based on that the MM node is not congested, the MM node may send the registration accept message. In another example, based on that the MM node is congested, the MM node may send the registration reject message. In this case, to alleviate the congestion of the MM node, the MM node may send to the UE, a value for a mobility backoff timer. Based on this value, the UE may run a mobility backoff timer. While the mobility backoff timer is running, the UE may not send another registration request message for mobility management and / or any message requesting registration for the AloT UE reader functionality.Docket No.: 25-1063PCT

[0422] The information of the RA may comprise one or more TAI (tracking area identifiers) of the one or more TAs. The RA may comprise the one or more TAs. As long as the UE moves between one or more cells of the one or more TAs, the UE may be allowed to use the one or more allowed network slices and / or the UE may be considered as registered for the mobility management, and / or the UE may not need to perform additional registration procedure for the mobility management. For example, when the UE moves into a cell which does not belong to the one more TAs of the RA, the UE may send another registration request for the mobility management, to indicate new location of the UE and / or to receive an updated information of the RA.

[0423] For example, the one or more TAs of the RA may comprise TA1 , TA2, TA3. The TA 1 may comprise cell 1, TA 2 may comprise cell 2, TA3 may comprise cell 3. For example, the RA may not comprise TA4 and / or TA5. The TA 4 may comprise cell 4, the TA 5 may comprise cell 5.

[0424] In an example, after performing the registration procedure (e.g., for the mobility management), the UE may determine to perform AloT UE reader registration procedure. For example, the AloT reader registration procedure may comprise at least one of: sending by the UE, a AloT UE reader registration request message; receiving, by the UE, a AloT UE reader registration response (accept / reject) message; and / or the like.

[0425] In an example, after receiving the registration accept message, the UE may determine to perform an AloT UE reader registration procedure. For example, the UE may send to the AloTF (and / or via the MM node), the AloT UE reader registration request message (as shown in the previous examples). Alternatively and / or additionally, registration for AloT UE reader can be performed while the UE performs registration for mobility management (as shown in previous examples).

[0426] In an example, the AloTF may receive the AloT UE reader registration request message In response to receiving the AloT UE reader registration request message, the AloTF may determine to send a response. For example, the response may be an AloT UE reader registration response message. For example, the AloT UE reader registration response message may be at least one of the AloT UE reader registration accept message and / or the AloT UE reader registration reject message. The AloT UE reader registration response message may comprise at least one of the AloT UE reader identifier, the AloT UE session identifier, information of AloT registration area, the one or more parameters, and / or the like (as shown in the previous examples). For example, the AloT UE reader identifier may be assigned to the UE, and / or may be used to identify the UE in the AloTF. For example, by using the AloT UE reader identifier, the AloTF may uniquely identify the UE and / or may prevent revealing real identity of the UE to a security attacker.

[0427] The AloT registration area may be different from the RA (e.g., of mobility management). For example, the RA may be used by the MM node, for mobility management. The AloT registration area may be used by the AloTF, for management of the AloT UE reader. For example, when the UE operates as the AloT UE reader moves within the AloT registration area, the UE may not perform additional AloT UE reader registration procedure. For example, when the UE operates as the AloT UE reader moves outside of the AloT registration area, the UE may perform the additional AloT registration procedure, to indicate to the AloT an updated current location of the UE. For example,Docket No.: 25-1063PCTthe AloT registration area may comprise one or more cells and / or one or more TAs. For example, the information of the AloT registration area may comprise one or more TAIs belonging to the AloT registration area. For example, the AloT registration area may be identified by one or more AloT area identifiers.

[0428] For example, after receiving the information of the AloT registration area, the UE may determine whether new cell belongs to the AloT registration area and / or to the RA. For example, when the UE camps on a (new) cell, the UE may receive a SIB. The SIB may comprise a TAI of the cell. Based on the TAI, the UE may determine whether a TA indicated by the TAI of the cell belongs to the RA and / or the AloT registration area. If the TA does not belong to the RA, the UE may perform registration procedure for mobility management. If the TA belongs to the RA, the UE may not perform registration procedure for mobility management. If the TA does not belong to the AloT registration area, the UE may perform an AloT UE reader registration procedure. If the TA belongs to the AloT registration area, the UE may not perform an AloT UE reader registration procedure. Performing AloT UE reader registration procedure may be sending an AloT UE reader registration request message and / or receiving an AloT UE reader response message. Performing registration procedure for mobility management may be sending registration request for mobility management and / or receiving registration accept / reject for mobility management.

[0429] Alternatively and / or additionally, instead of using TA and / or TAI, an AloT area identifier may be used. For example, each cell may broadcast a TAI to which the each cell belongs and / or an AloT area identifier to which the each cell belongs. In this case, the information of the AloT registration area may comprise one or more AloT area identifiers. In this case, the SIB may comprise an AloT area identifier to which the cell belongs. By checking whether the AloT area identifier of the new cell belongs to the one or more AloT area identifiers of AloT registration area, the UE may determine whether to perform registration for the AloT UE reader For example, performing registration for the AloT UE reader may be sending the AloT UE reader registration request message. For example, if the one or more AloT area identifiers of the AloT registration area does not comprise the AloT area identifier of the new cell, the UE may determine to send the AloT UE reader registration request message.

[0430] The example of FIG.31 may help the UE to trigger a AloT UE reader registration procedure at optimal time, while reducing unnecessary performing registration for AloT UE reader toward the AloTF.

[0431] Fig.32 illustrates an example as per an aspect of an embodiment of the present disclosure. For brevity, based on the other part of the present disclosure, redundant details will be omitted.

[0432] In an example, the UE (acting as an AloT UE reader and / or configured as the AloT UE reader) may send a first message. The first message may comprise a first AloT message. The first AloT message may be at least one of a first AloT UE reader registration request message, a first AloT UL transport message, a first AloT UE reporting message, a first AloT UE service request message, a first AloT UE reader deregistration request message, and / or the like. For example, the first AloT UE reader registration request message may be used for registering the UE as the AloT UE reader toward the AloTF. For example, the first AloT UL transport message may comprise one or more messages / data sent by one or more AloT devices, and / or may be used to deliver the one or more messages / data from the one or more AloT devices to the AloTF. For example, the first AloT UE serviceDocket No.: 25-1063PCTrequest message may comprise a service request sent by the UE and / or by the one or more AloT devices. For example, the AloT UE reporting message may be used to deliver reporting information to the AloTF.

[0433] In an example, the AloTF may receive the first message. For example, in response to receiving the first message and / or based on that the AloTF is congested, the AloTF may send a second message to the UE. The second message may be at least one of a first AloT UE reader registration response message, a first AloT DL transport message, a first AloT UE configuration message, a first AloT UE service response message, a first AloT UE reader deregistration response message, and / or the like. For example, the second message may comprise the one or more parameters (as shown in previous examples). For example, the second message may indicate at least one of a rejection to a request (e.g., a request associated with the first message) of the UE and / or an acceptance of the request. For example, the request of the UE may be at least one of a request for registration as the AloT UE reader, a request for UL AloT data transport, a request for AloT service, a request for deregistration of the AloT UE reader, and / or the like. For example, the one or more parameters may comprise the fourth parameter. For example, the fourth parameter may comprise the time value. For example, the second message may comprise information of the one or more areas. For example, the one or more areas may be at least one of one or more AloT registration areas and / or one or more AloT forbidden areas. For example, the one or more AloT forbidden areas may be one or more areas whether the UE is not allowed for AloT and / or for AloT UE reader operation. For example, that the UE is not allowed for AloT may be that the UE is not allowed for AloT UE reader functionality.

[0434] In an example, the UE may receive the second message. In response to receiving the second message, based on that the message is associated with the AloT, and / or based on that the one or more parameters comprises a time value, the UE may start a time value for the AloT. That the UE starts the time value for the AloT may be that the UE starts the time value to determine whether to send one or more AloT related messages and / or to perform one or more AloT related procedures. That the UE starts the time value for the AloT may be not that the UE starts the time value to determine whether to send one or more mobility management related messages and / or to perform one or more mobility management procedures. For example, if a MM node is congested, the MM node may send to the UE, a second time value, for a second timer. The second timer may be different from the timer. For example, the second timer is used to control mobility management procedure, while the timer is used to control AloT related procedure.

[0435] In an example, while the timer is running, and / or before the expiry of the timer, the UE may not send the AloT related message, to the AloTF. For example, the AloT related message may comprise at least one of a second AloT UE reader registration request, a second AloT UL transport message, a second AloT UE reporting message, a second AloT UE service request message, a second AloT UE reader deregistration request message and / or the like.

[0436] In an example, if the timer is not running, if the timer is stopped, and / or if the timer expires, the UE may send the AloT related message to the AloTF.

[0437] In an example, the UE may determine whether the UE enters into a new cell. When the UE enters into theDocket No.: 25-1063PCTnew cell, the UE may receive a SIB from the new cell. Based on the SIB, the UE may determine whether the new cell belongs to the one or more AloT registration areas and / or the one or more AloT forbidden areas. For example, the one or more AloT forbidden areas may be one or more areas where operating as the AloT reader may not be allowed.

[0438] For example, if the new cell does not belong to the one or more AloT registration area and / or if the new cell does not belongs to the forbidden areas, the UE may stop the timer and / or may send the AloT related message to the AloTF.

[0439] For example, if the new cell belongs to the one or more AloT registration area and / or if the new cell belongs to the forbidden areas, the UE may not stop the timer and / or may not send the AloT related message to the AloTF.

[0440] The example of FIG.32 may help to reduce unnecessary signalling from the UE to the AloTF, while the UE sends an AloT related message to the AloTF, as soon as the UE needs to send.

[0441] Fig.33 illustrates an example as per an aspect of an embodiment of the present disclosure. In an example, an AloTF may determine whether the AloTF is congested or not. Based on the determination, the AloTF may send a AloT message to the UE, indicating de-registration of the UE as the AloT UE reader. This may help the UE from generating additional congestion toward the AloTF. For brevity, based on the other part of the present disclosure, redundant details will be omitted.

[0442] In an example, the UE may send the AloT UE reader registration request message to the AloTF. In response to sending the AloT UE reader registration request message, the UE may receive the AloT UE reader registration response message. For example, the AloT UE reader registration response message may indicate that the UE is successfully registered as the AloT UE reader to the AloTF. For example, when the AloTF is not congested and / or when the UE is authorized for operating as the AloT UE reader, the UE may receive the AloT UE reader registration response indicating successful registration as the AloT UE reader.

[0443] In an example, after the UE receives the AloT UE reader registration response message, the AloTF may determine to deregister the UE from the AloT UE reader. For example, the AloTF may determine to deregister the UE, based on that the AloTF is congested, that a subscription information of the UE may change and / or that a policy of the UE may change. For example, the AloTF may be congested for the control plane and / or for the user plane.

[0444] In an example, in response determining to deregister the UE as the AloT UE reader, the AloTF may send to the UE, the AloT UE reader deregistration request message. The AloT UE reader deregistration request message may comprise the one or more parameters (as shown in the previous examples). For example, the one or more parameters may be used to prevent the UE from immediately accessing the AloTF, after the UE receives the AloT UE reader deregistration request message. For example, the behavior of the UE after receiving the one or more parameters may be similar to what is described in previous examples.

[0445] For example, in response to receiving the AloT UE reader deregistration request message, based on theDocket No.: 25-1063PCTone or more parameters (e.g. , the fourth parameter), the UE may start the timer with the time value. For example, until the expiry of the timer and / or until the UE moves into a new area (e.g., outside of the one or more AloT registration areas, the one or more forbidden AloT areas), the UE may not initiate a AloT UE reader registration procedure. For example, after the expiry of the timer and / or after the UE moves into a new area (e.g., outside of the one or more AloT registration areas, the one or more forbidden AloT areas), the UE may initiate a AloT UE reader registration procedure. To initiate the AloT UE reader registration procedure may be to send the AloT UE reader registration request message.

[0446] Alternatively and / or additionally, the AloT UE reader deregistration request message may be sent by an MM node. For example, if the MM node manages both registration for mobility management and / or registration for AloT UE reader, and / or if the MM node is aware of overload situation of the AloTF, the MM node may send a message to the UE indicating that the UE is deregistered for the AloT UE functionality and / or that the UE is registered for mobility management. In an example, based on receiving the message, the UE may determine that the UE is registered for mobility management and / or that the UE is not registered for AloT UE reader functionality.

[0447] The example of FIG.33 may help to reduce unnecessary signalling from the UE to the AloTF, by the AloTF proactively managing AloT UE reader registration.

[0448] Fig.34 illustrates an example as per an aspect of an embodiment of the present disclosure. For brevity, based on the other part of the present disclosure, redundant details will be omitted.

[0449] In an example, the UE may send a registration request message to a mobility management node (e.g., a core network node, an AMF, a 6G AMF). The registration request message may comprise one or more requested network slice identifiers, one or more capabilities of the UE, one or more UE identifiers associated with a mobility management, and / or the like.

[0450] In an example, the UE may receive a registration response message from the mobility management node. The registration response message may comprise one or more allowed network slice identifiers, one or more allocated UE identifiers allocated by the mobility management node, and / or the like. The registration response message may indicate that the UE is registered at the mobility management node, for mobility management.

[0451] In an example, based on that the UE is registered, the UE may send a request message for AloT registration as an AloT UE reader. For example, if the registration response message does not indicate that the UE is registered for the mobility management, the UE may not send the request message for AloT registration as the AloT UE reader.

[0452] In an example, the UE may receive a response message for the request message. For example, the response message may indicate a rejection. For example, the rejection may be that the UE is not authorized as the AloT UE reader, and / or that the registration request for registration as the AloT UE reader is rejected. Alternatively, if the response message indicates an allowance, the UE may act as the AloT UE reader.

[0453] In an example, based on receiving the rejection, the UE may determine whether the response message comprises a time value. For example, the time value may be a back-off time value for an AloT procedure. ForDocket No.: 25-1063PCTexample, the AloT procedure may comprise at least one of an AloT UE reader registration procedure, an AloT UE configuration procedure, an AloT service request procedure, an AloT message transport procedure, and / or the like.

[0454] In an example, based on that the response message comprises the time value, the UE may start a AloT timer with the time value. While the AloT timer is running and / or before the AloT timer expires / stops, the UE does not initiate / trigger the AloT procedure. Not initiating / triggering the AloT procedure may be that the UE does not send an AloT message. For example, the AloT message may be at least one of the AloT UE reader registration request message, a UL AloT message transport message, a AloT service request message and / or the like. While the AloT timer is not running and / or after the AloT timer expires / stops, the UE may initiate / trigger the AloT procedure. Alternatively and / or additionally, while the AloT timer is running and / or before the AloT timer expires / stops, the UE may send another request message requesting de-registration of the UE as the AloT UE reader, to relieve congestion of the AloTF.

[0455] In one example, an embodiment may comprise: sending, by a wireless device to an access and mobility management function (AM F), a registration request message; receiving, by the wireless device from the AMF, a registration accept message; sending, by the wireless device to an ambient internet of things (AloT) function (AloTF), a first message requesting registration of the wireless device as an AloT reader; receiving, by the wireless device from the AloTF and after sending the first message, a second message indicating the wireless device not being registered as the AloT reader, wherein the second message comprises at least one of: a cause of not being registered; a time value; starting, by the wireless device, a timer with the time value; sending, by the wireless device to the AloTF and based on expiry of the timer, a third message requesting registration of the wireless device as the AloT reader.

[0456] In one example, an embodiment may comprise: sending, by a wireless device to an ambient internet of things (AloT) function (AIOTF), a first message requesting registration of the wireless device as an AloT reader; receiving, by a wireless device, a second message, indicating the wireless device not being registered as the AloT reader; and sending, by the wireless device and based on one or more conditions being met, a third message requesting registration of the wireless device.

[0457] In one example, an embodiment may comprise: receiving, by a wireless device, a first message, indicating the wireless device not being registered for an ambient internet of things (AloT) reader functionality; and sending, by the wireless device and based on at least one condition being met, a second message requesting registration for AloT reader functionality.

[0458] In one example, in the embodiment, the first message comprises at least one of a first field indicating a cause of not being registered and a second field indicating a time value.

[0459] In one example, the embodiment may further comprise: sending, by the wireless device, a third message requesting registration for the AloT reader functionality

[0460] In one example, in the embodiment, the wireless device sends the third message, to at least one of anDocket No.: 25-1063PCTAloT function (AIOTF) ora mobility management function.

[0461] In one example, in the embodiment, the first message comprises at least one of a first field indicating a cause of not being registered for AloT, a second field indicating a time value, a third field indicating one or more AloT areas, a fourth field indicating rejection of registration for AIOT functionality, a fifth field indicating an identifier associated with of the AIOTF.

[0462] In one example, the embodiment may further comprise: starting by the wireless device and based on the second field, a timer.

[0463] In one example, in the embodiment, one or more conditions comprising the at least one condition comprise at least one of an expiry of the timer and mobility of the wireless device.

[0464] In one example, in the embodiment, the wireless device stops the timer when the wireless devices moves to an area.

[0465] In one example, in the embodiment, the area does not belong to the one or more AloT areas or is outside of registration area of the wireless device.

[0466] In one example, in the embodiment, the third message further comprises indication that the wireless device requests registration for mobility management.

[0467] In one example, in the embodiment, wherein the third message further comprise a type field indicating an AloT message and a container comprising the AloT message.

[0468] In one example, in the embodiment, wherein the AloT message comprises a request for the registration for the AloT reader functionality.

[0469] In one example, in the embodiment, wherein the wireless device sends request for the registration for mobility management via a control plane and sends the third message requesting registration of for the AloT reader functionality via a user plane.

[0470] In one example, in the embodiment, wherein the third message comprises a first device identifier for mobility management and a second device identifier for the AloT reader functionality.

[0471] In one example, in the embodiment, the first message comprises an indication of congestion and the third message.

[0472] In one example, in the embodiment, the first message comprises an indication of registration accept for mobility management and an indication of registration reject for the AloT functionality.

[0473] In one example, in the embodiment, the wireless device receives from the mobility management function, a parameter indicating the registration area for mobility management.

[0474] In one example, the embodiment may further comprise: receiving by the wireless device after sending the second message, a fourth message indicating successful registration of the wireless device for the AloT functionality.

[0475] In one example, in the embodiment, the fourth message further comprises at least one of a third device identifier for the AloT functionality, one or more second AloT area identifiers where the wireless device isDocket No.: 25-1063PCTregistered for the AloT functionality.

[0476] In one example, the embodiment may further comprise: receiving by the wireless device and after receiving the fourth message, a fifth message indicating that the wireless device is deregistered for the AloT functionality.

[0477] In one example, the embodiment may further comprise: deleting by the wireless device, based on receiving the fourth message, the third device identifier and the one or more second AloT area identifiers.

[0478] In one example, an embodiment may comprise: sending, by a wireless device to an access and mobility management function (AM F), a registration request message; receiving, by the wireless device from the AMF, a registration accept message; sending, by the wireless device to the AMF, a first message comprising: a first type indicator indicating a type of message, wherein the type comprises: an ambient internet of things (AloT) message type; and a session management message type; and a first AloT message, based on the first type indicator indicating the AloT message type; receiving, by the wireless device from the AMF and after sending the first message, a second message comprising a second type indicator indicating the AloT message type.

[0479] In one example, an embodiment may comprise: sending, by a wireless device to an access and mobility management function, a first message comprising: a type indicator indicating a type of message, wherein the type comprises: an ambient internet of things (AloT) message type; and a session management message type; and a AloT message, based on the type indicator indicating the AloT message type.

[0480] In one example, an embodiment may comprise: sending, by a wireless device to an access and mobility management function (AMF), a registration request message; receiving, by the wireless device from the AMF, a registration accept message comprising: information of a registration area where the wireless device is registered for mobility management; and an identifier of one or more allowed network slices; sending, by the wireless device to an ambient internet of things (AloT) function (AloTF), a first message requesting registration of the wireless device as an AloT reader; receiving, by the wireless device from the AloTF and after sending the first message, a second message, indicating the wireless device being registered as the AloT reader, comprising information of one or more areas where the wireless device is allowed as the AloT reader.

[0481] In one example, an embodiment may comprise: sending, by a wireless device to an ambient internet of things (AloT) function (AloTF), a first message requesting registration of the wireless device as an AloT reader; receiving, by the wireless device from the AloTF and after sending the first message, a second message, indicating the wireless device being registered as the AloT reader, comprising information of one or more areas where the wireless device is allowed as the AloT reader.

[0482] In one example, the embodiment may further comprise: selecting by the wireless device, a cell.

[0483] In one example, in the embodiment, the wireless device receives, from the cell, a system information block indicating one or more area identifiers.

[0484] In one example, the embodiment may further comprise: determining by the wireless device, whether the one or more areas comprise an area indicated by the one or more area identifiers.Docket No.: 25-1063PCT

[0485] In one example, in the embodiment, the wireless device sends a third message requesting registration of the wireless device as the AloT reader, based on that the one or more areas does not comprise the area indicate by the one or more area identifiers.

[0486] In the specification, many examples are described in terms of AloT UE registration procedure point of view. This specification is not limited to the AloT UE registration procedure, and is applicable to AloT message transport procedure, AloT configuration update procedure, AloT service request procedure, and / or the like. For example, in the description, the AloT UE reader registration request message can be a AloT UL message transport message, a AloT service request message, and / or the like. For example, in the description, the AloT UE reader registration response message can be a AloT DL message transport message, a AloT service response message, a AloT configuration update message and / or the like.

Claims

Docket No.: 25-1063PCTCLAIMSWhat is claimed is:

1. A method comprising:receiving, by a wireless device from a base station, a system information block (SIB) indicating support for ambient internet of things (AloT) wireless device reader operation;sending, by the wireless device to the base station, a first message indicating that the wireless device supports the AloT wireless device reader operation;receiving, by the wireless device from the base station and after sending the first message, a second message indicating the wireless device not being registered as an AloT wireless device reader, wherein the second message comprises at least one of:a cause of not being registered; ora time value;starting, by the wireless device, a timer with the time value;sending, by the wireless device to the base station and based on expiry of the timer, a third message requesting registration of the wireless device as the AloT wireless device reader;receiving, by the wireless device, from an AloT device, an AloT message; andsending, by the wireless device to the base station, a message comprising:a type indicator indicating whether the message comprises the AloT message; and a container comprising the AloT message.

2. A method comprising:sending, by a wireless device to a network node, a first message indicating that the wireless device supports an ambient internet of things (AloT) wireless device reader operation;receiving, by the wireless device, from an AloT device, an AloT message; andsending, by the wireless device to the network node, a message comprising:a type indicator indicating whether the message comprises the AloT message; and a container comprising the AloT message.

3. The method of claim 2, further comprising, receiving, by the wireless device from the network node and after sending the first message, a second message, indicating that the wireless device is not registered as an AloT wireless device reader.

4. The method of claim 3, wherein the second message comprises at least one of: a first field indicating a cause of not being registered, a second field indicating a time value, a third field indicating one or more AloT areas, a fourth field indicating rejection of registration as an AloT wireless device reader, or a fifth field indicating an identifier associated with an AloT function (AloTF).Docket No.: 25-1063PCT5. The method of claim 4, further comprising starting, by the wireless device and based on the second field, a timer.

6. The method of claim 5, wherein the wireless device stops the timer when the wireless device moves to an area, and the area does not belong to the one or more AloT areas or the area is outside of registration area of the wireless device.

7. The method of any one of claims 5 to 6, wherein the second message comprises information of one or more conditions comprising at least one condition.

8. The method of claim 7, wherein the at least one condition is expiry of the timer or a mobility of the wireless device.

9. The method of claim 8, wherein the mobility of the wireless device is that the wireless device moves out of the one or more AloT areas.

10. The method of any one of claims 3 to 9, wherein the second message comprises an indication of congestion.

11. The method of any one of claims 2 to 10, wherein the type indicator indicates at least one of a first value indicating an AloT message, a second value indicating a non-AloT message.

12. The method of any one of claims 2 to 11 , wherein the AloT message comprises at least one of an AloT message sent by an AloT device or an AloT message of the wireless device, for the AloT wireless device reader operation.

13. The method of any one of claims 7 to 12, further comprising sending, by the wireless device to the network node and based on at least one condition being met, a third message.

14. The method of claim 13, wherein the sending the third message comprises sending the third message via a user plane of a PDU session.

15. The method of claim 13, wherein the third message comprises a first device identifier of the wireless device, wherein the first device identifier is used for mobility management.

16. The method of claim 13, wherein the third message comprises a second device identifier of the wireless device for the AloT wireless device reader operation.

17. The method of claim 13, further comprising receiving by the wireless device after sending the third message, a fifth message indicating successful registration of the wireless device for the AloT wireless device reader operation.

18. The method of claim 17, wherein the fifth message further comprises at least one of a third device identifier of the wireless device for the AloT wireless device reader operation, or one or more second identifiers of the one or more AloT areas where the wireless device is registered as the AloT wireless device reader.

19. The method of claim 18, further comprising receiving by the wireless device and after receiving the fifth message, a sixth message indicating that the wireless device is deregistered for the AloT wireless device reader operation.Docket No.: 25-1063PCT20. The method of claim 19, further comprising deleting by the wireless device, based on receiving at least one of the fifth message or the sixth message, the third device identifier and the one or more second identifiers of the one or more AloT areas.

21. The method of any one of claims 2 to 20, wherein the wireless device receives from a cell, at least one of information of an AloT area to which the cell belongs, an information element indicating that the cell supports AloT wireless device reader operation.

22. The method of any one of claims 2 to 21 , wherein the network node is at least one of an AIOTF, a mobility management function, or a base station.

23. The method of any one of claims 2 to 22, further comprising receiving, by the wireless device from the network node, a system information block (SIB) indicating support for AloT wireless device reader operation.

24. An apparatus comprising one or more processors and memory storing instructions that, when executed by the one or more processors, cause the apparatus to perform the method of any one of claims 1 to 23.

25. A non-transitory computer-readable medium comprising instructions that, when executed by one or more processors of an apparatus, cause the apparatus to perform the method of any one of claims 1 to 23.

26. A method comprising:sending, by a wireless device to a network node, a first message comprising:a first type indicator indicating a type of message, wherein the type comprises:an ambient internet of things (AloT) message type; anda non-AloT message type; anda first AloT message, based on the first type indicator indicating the AloT message type; receiving, by the wireless device from the network node and after sending the first message, a second message comprising a second type indicator indicating the AloT message type.

27. An apparatus comprising one or more processors and memory storing instructions that, when executed by the one or more processors, cause the apparatus to perform the method of claim 26.

28. A non-transitory computer-readable medium comprising instructions that, when executed by one or more processors of an apparatus, cause the apparatus to perform the method of claim 2.

29. A method comprising:sending, by a wireless device to a network node, a registration request message;receiving, by the wireless device from the network node, a registration accept message comprising: information of a registration area where the wireless device is registered for mobility management; andan identifier of one or more allowed network slices;sending, by the wireless device to a second network node, a first message requesting registration of the wireless device as an AloT wireless device reader; andDocket No.: 25-1063PCTreceiving, by the wireless device from the second network node and after sending the first message, a second message:indicating that the wireless device is registered as an AloT wireless device reader; and comprising information of one or more areas where the wireless device is allowed as the AloT wireless device reader.

30. A method comprising:sending, by a wireless device to a network node, a first message requesting registration of the wireless device as an ambient internet of things (AloT) wireless device reader; andreceiving, by the wireless device from the network node and after sending the first message, a second message, indicating the wireless device being registered as an AloT wireless device reader, comprising information of one or more AloT areas where the wireless device is allowed as the AloT wireless device reader.

31. The method of claim 30, wherein the wireless device receives, system information indicating one or more AloT area identifiers.

32. The method of claim 31 , further comprising determining, by the wireless device, whether the one or more AloT areas comprise an area indicated by the one or more AloT area identifiers.

33. The method of claim 32, further comprising sending a third message requesting registration of the wireless device as the AloT wireless device reader, based on the determining.

34. An apparatus comprising one or more processors and memory storing instructions that, when executed by the one or more processors, cause the apparatus to perform the method of any one of claims 29 to 33.

35. A non-transitory computer-readable medium comprising instructions that, when executed by one or more processors of an apparatus, cause the apparatus to perform the method of any one of claims 29 to 33.

36. A method comprising:receiving, by a base station from an access and mobility management function (AM F), a first message comprising an information element indicating whether a wireless device is authorized for ambient internet of things (AloT) wireless device reader operation;receiving, by the base station from the wireless device, a request for AloT radio resources; and performing, by the base station and based on the information element, at least one of:allocating AloT radio resources for the wireless device; orrejecting the request for AloT radio resources.

37. The method of claim 36, wherein the first message is a message from the AMF to the base station indicating context information of the wireless device.

38. The method of any one of claims 36 to 37, wherein the performing comprises allocating, by the base station, the AloT radio resources for the wireless device, based on that the wireless device is authorized for the AloT wireless device reader operation.Docket No.: 25-1063PCT39. The method of any one of claims 36 to 38, further comprising, broadcasting, by the base station, at least one of an indication of support for the AloT wireless device reader operation, one or more AloT area identifiers to which a cell of the base station belongs.

40. The method of any one of claims 36 to 39, wherein the AloT wireless device reader operation is a type AloT reader operation in which the wireless device scans for and collects information from one or more AloT devices.

41. The method of any one of claims 36 to 40, further comprising storing, by the base station, the information element for AloT radio resource allocation for the wireless device.

42. A method comprising:determining, by an access and mobility management function (AM F), that a wireless device is authorized for ambient internet of things (AloT) wireless device reader operation based on subscription information, of the wireless device, received from a data management function;sending, by the AMF to a base station, an information element indicating whether the wireless device is authorized for the AloT wireless device reader operation; andsending, by the AMF to an AloT function (AloTF), an indication that the wireless device is ready for the AloT wireless device reader operation.

43. The method of claim 42, wherein the sending of the information element to the base station causes the base station to use the authorization for AloT radio resource allocation for the wireless device, to send and receive an AloT message with an AloT device served by the wireless device.

44. The method of claim 42 or 43, wherein the indication sent to the AloTF comprises an identifier of the wireless device.

45. The method of any one of claims 42 to 44, further comprising storing, by the AMF, the authorization in a context of the wireless device.

46. An apparatus comprising one or more processors and memory storing instructions that, when executed by the one or more processors, cause the apparatus to perform the method of any one of claims 36 to 45.

47. A non-transitory computer-readable medium comprising instructions that, when executed by one or more processors of an apparatus, cause the apparatus to perform the method of any one of claims 36 to 45.

48. A method comprising:maintaining, for AloT wireless device reader operation and by an ambient internet of things (AloT) function (AloTF), a context of an AloT wireless device reader, the context comprising at least one of: an identity of a wireless device allowed as the AloT wireless device reader;a location or position of the wireless device;a serving access and mobility management function (AMF) of the wireless device;a user plane path or association for the wireless device; ora connection status of the wireless device;receiving, by the AloTF, a request, requesting an AloT service for an AloT device; andDocket No.: 25-1063PCTsending, by the AloTF, a request indicating at least one of:the wireless device;the AloT device;the AloT service.

49. The method of claim 48, further comprising, receiving, by the AloTF , a first message requesting registration of the wireless device as an AloT wireless device reader.

50. The method of claim 49, further comprising, determining, by the AloTF, whether to reject or to accept, the registration request based on at least one of:congestion at the AloTF; oran authorization status of the wireless device.

51. The method of claim 50, further comprising, sending, by the AloTF, a second message, comprising one or more parameters indicating at least one of:rejection of the registration request; oracceptance of the registration request.

52. The method of claim 51 , wherein, based on determining to reject the registration request, the one or more parameters comprise at least one of a time value or one or more AloT areas.

53. The method of claim 51 , wherein, based on determining to accept the registration request, the one or more parameters comprise at least one of an AloT wireless device reader identifier for the wireless device, one or more areas where the wireless device is registered or allowed as the AloT wireless device reader.

54. The method of any one of claims 49 to 53, wherein the first message is received via at least one of:a control plane path through an access and mobility management function (AMF); ora user plane path via a protocol data unit (PDU) session of the wireless device.

55. The method of any one of claims 50 to 54, further comprising:after accepting the registration request, determining, by the AloTF, to deregister the wireless device from being registered as the AloT wireless device reader; andsending, by the AloTF to the wireless device, a deregistration message.

56. The method of claim 55, wherein the determining to deregister the wireless device is based on at least one of:congestion at the AloTF for a control plane or a user plane;a change in subscription information of the wireless device; ora change in a policy of the wireless device.

57. The method of any one of claims 55 to 56, wherein the deregistration message comprises at least one of:a time value;one or more AloT registration areas; orone or more forbidden AloT areas.

58. The method of any one of claims 51 to 57, further comprising:Docket No.: 25-1063PCTafter sending the second message rejecting the registration request, receiving, by the AloTF from the wireless device, a fourth message requesting registration of the wireless device as the AloT wireless device reader;determining, by the AloTF, that the congestion at the AloTF is resolved; andbased on the determination, sending, by the AloTF to the wireless device, a fifth message accepting the registration request.

59. The method of any one of claims 48 to 58, wherein the AloT wireless device reader operation comprises at least one of an inventory operation or a command operation, that is performed with one or more AloT devices.

60. An apparatus comprising one or more processors and memory storing instructions that, when executed by the one or more processors, cause the apparatus to perform the method of any one of claims 48 to 59.

61. A non-transitory computer-readable medium comprising instructions that, when executed by one or more processors of an apparatus, cause the apparatus to perform the method of any one of claims 48 to 59.