Network Access Control for UE Registration in NPN and VPLMN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems face inefficiencies in managing User Equipment (UE) permissions for accessing networks, particularly in scenarios involving Non-Public Networks (NPN) and Visited Public Land Mobile Networks (VPLMN), leading to increased overhead and incorrect handling of mobility restrictions due to lack of indication of network selection mode in registration requests.

Innovation Solution

A method and system that allow a first network to receive registration requests from User Equipment (UE) and verify permissions for access to a second network, determining a reject mode based on the UE's network selection mode, enabling efficient rejection and handover processes by indicating the mode of selection, whether automatic or manual, to reduce signaling overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the network verifies permissions for every registration request from UE to access NPN or VPLMN, then network security and access control are improved, but signaling overhead and network processing load increase

Engineering Contradiction:
Improvenetwork access controlVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The network performs permission verification in advance during the registration phase before the UE attempts actual data transmission. By determining whether to allow or reject access upfront based on the selected network mode, the system avoids repeated verification signaling during subsequent communication sessions, thereby reducing overall signaling overhead while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts the verification process based on the network selection mode (automatic or manual) indicated by the UE. Different verification strategies are applied depending on the mode: for automatic selection, the network verifies against configured allowed networks; for manual selection, the network performs additional checks. This dynamic approach optimizes the balance between security and signaling efficiency

Inventive Principle:
Principle #15Dynamics

2Quantity of substance

If the network does not verify permissions for registration requests, then signaling overhead is reduced, but network security and access control reliability deteriorate

Engineering Contradiction:
Improvesignaling overheadVSAvoidnetwork access control
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

Permission verification is performed in advance during the registration phase before the UE attempts actual data transmission. By determining whether to allow or reject access upfront based on the selected network mode, the system avoids repeated verification signaling during subsequent communication sessions, thereby reducing overall signaling overhead while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts the verification process based on the network selection mode (automatic or manual) indicated by the UE. Different verification strategies are applied depending on the mode: for automatic selection, the network verifies against configured allowed networks; for manual selection, the network performs additional checks. This dynamic approach optimizes the balance between security and signaling efficiency

Inventive Principle:
Principle #15Dynamics

3Device complexity

If the network handles mobility restrictions without considering network selection mode, then processing complexity is reduced, but mobility management accuracy and service provision quality deteriorate

Engineering Contradiction:
Improveprocessing complexityVSAvoidmobility management accuracy
Core Design Contradiction:
Device complexityVSManufacturing precision

Solution Approach 1:

The system dynamically adjusts mobility management procedures based on the network selection mode (automatic or manual) indicated by the UE in the registration request. For automatic mode, the network applies standard mobility restriction handling; for manual mode, it implements enhanced verification and more precise control mechanisms. This dynamic adaptation ensures accurate mobility management while avoiding unnecessary complexity for automatic selections

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different levels of processing precision are applied to different cases: automatic network selection receives standard handling, while manual network selection receives enhanced verification. This localized quality approach ensures that additional processing complexity is only introduced where necessary (manual selection cases), thereby maintaining mobility management accuracy without uniformly increasing system complexity

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12041448B2Methods and apparatus for controlling permissions of a UE for accessing a network
Publication Date: 2024.07.16 SAMSUNG ELECTRONICS CO LTD
  • US12041448B2 patent drawing
  • US12041448B2 patent drawing
  • US12041448B2 patent drawing

AI summary

Methods and systems for controlling permissions of a UE for accessing a network. A method disclosed herein includes initiating, by a User Equipment (UE), a registration procedure with a serving network for accessing a selected network, wherein the selected network includes one of at least one CAG cell of an NPN and a VPLMN. The registration procedure indicates a network selection mode using which the UE has selected the network and the network selection mode includes one of an automatic mode and a manual mode. The method further incudes determining, by the serving network, a reject mode for rejecting the registration request of the UE based on the network selection mode indicated in the registration request, when the permissions of the UE to access the selected network have not been verified, wherein the reject mode includes a protected reject mode and an unprotected reject mode.