WO2025237653A1 - Cag verification for 5g nr femtocell - Google Patents

Cag verification for 5g nr femtocell

Info

Publication number
WO2025237653A1
WO2025237653A1 PCT/EP2025/061347 EP2025061347W WO2025237653A1 WO 2025237653 A1 WO2025237653 A1 WO 2025237653A1 EP 2025061347 W EP2025061347 W EP 2025061347W WO 2025237653 A1 WO2025237653 A1 WO 2025237653A1
Authority
WO
WIPO (PCT)
Prior art keywords
access
user equipment
femtocell
closed
mobility management
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/EP2025/061347
Other languages
French (fr)
Inventor
Rakshesh PRAVINCHANDRA BHATT
Basavaraj KIRAGI
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Nokia Technologies Oy
Original Assignee
Nokia Technologies Oy
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Nokia Technologies Oy filed Critical Nokia Technologies Oy
Publication of WO2025237653A1 publication Critical patent/WO2025237653A1/en
Pending legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/101Access control lists [ACL]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • H04W12/084Access security using delegated authorisation, e.g. open authorisation [OAuth] protocol
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/02Access restriction performed under specific conditions
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/18Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
    • H04W8/186Processing of subscriber group data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/04Large scale networks; Deep hierarchical networks
    • H04W84/042Public Land Mobile systems, e.g. cellular systems
    • H04W84/045Public Land Mobile systems, e.g. cellular systems using private Base Stations, e.g. femto Base Stations, home Node B

Definitions

  • Examples of embodiments herein relate generally to wireless communications and, more specifically, relate to access control for UEs (user equipment) for femtocells in 5G (fifth generation) cellular systems.
  • a group of subscribers are permitted/allowed to access one or more Femtocells via access control.
  • a Closed Access Group identifies these subscribers and the Femtocells can be CAG cells of a public land mobile network (PLMN) identified by CAG ID(s) (identification(s)), which is assumed to be reused for 5G Femtocell access control.
  • PLMN public land mobile network
  • a method includes based on a femtocell in a serving network supporting closed access, performing by an access and mobility management function in the serving network for a user equipment signaling comprising: sending, to a unified data management in a home network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; receiving, from the unified data management, the list of closed access groups the user equipment is allowed to access; and performing, by the access and mobility management function, verification of whether a provided closed access group identification is in the list of closed access groups the user equipment is allowed to access; and performing one of the following: based on the verification being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell; or based
  • An additional exemplary embodiment includes a computer program, comprising instructions for performing the method of the previous paragraph, when the computer program is run on an apparatus.
  • the computer program according to this paragraph wherein the computer program is a computer program product comprising a computer- readable medium bearing the instructions embodied therein for use with the apparatus.
  • Another example is the computer program according to this paragraph, wherein the program is directly loadable into an internal memory of the apparatus.
  • An exemplary apparatus includes one or more processors and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: based on a femtocell in a serving network supporting closed access, performing by an access and mobility management function in the serving network for a user equipment signaling comprising: sending, to a unified data management in a home network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; receiving, from the unified data management, the list of closed access groups the user equipment is allowed to access; and performing, by the access and mobility management function, verification of whether a provided closed access group identification is in the list of closed access groups the user equipment is allowed to access; and performing one of the following: based on the verification being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to provide the user equipment with access to
  • An exemplary computer program product includes a computer-readable storage medium bearing instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: based on a femtocell in a serving network supporting closed access, performing by an access and mobility management function in the serving network for a user equipment signaling comprising: sending, to a unified data management in a home network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; receiving, from the unified data management, the list of closed access groups the user equipment is allowed to access; and performing, by the access and mobility management function, verification of whether a provided closed access group identification is in the list of closed access groups the user equipment is allowed to access; and performing one of the following: based on the verification being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to provide the user equipment with access to a closed access group
  • an apparatus comprises means for: based on a femtocell in a serving network supporting closed access, performing by an access and mobility management function in the serving network for a user equipment signaling comprising: sending, to a unified data management in a home network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; receiving, from the unified data management, the list of closed access groups the user equipment is allowed to access; and performing, by the access and mobility management function, verification of whether a provided closed access group identification is in the list of closed access groups the user equipment is allowed to access; and performing one of the following: based on the verification being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell; or based on
  • An additional exemplary embodiment includes a computer program, comprising instructions for performing the method of the previous paragraph, when the computer program is run on an apparatus.
  • the computer program according to this paragraph wherein the computer program is a computer program product comprising a computer- readable medium bearing the instructions embodied therein for use with the apparatus.
  • Another example is the computer program according to this paragraph, wherein the program is directly loadable into an internal memory of the apparatus.
  • An exemplary apparatus includes one or more processors and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, by a unified data management in a home network for a user equipment and from an access and mobility management function in a serving network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access; and sending, by the unified data management to the access and mobility management function, the list of closed access groups the user equipment is allowed to access.
  • an apparatus comprises means for: receiving, by a unified data management in a home network for a user equipment and from an access and mobility management function in a serving network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access; and sending, by the unified data management to the access and mobility management function, the list of closed access groups the user equipment is allowed to access.
  • a method includes responsive to a user equipment sending a radio resource control connection complete message with non-access stratum registration request to a serving network for the user equipment, sending by a femtocell toward the serving network a message including an indicator for a cell access mode for the femtocell, a closed access group identification, and an identifier of the femtocell by the femtocell.
  • An additional exemplary embodiment includes a computer program, comprising instructions for performing the method of the previous paragraph, when the computer program is run on an apparatus.
  • the computer program according to this paragraph wherein the computer program is a computer program product comprising a computer- readable medium bearing the instructions embodied therein for use with the apparatus.
  • Another example is the computer program according to this paragraph, wherein the program is directly loadable into an internal memory of the apparatus.
  • An exemplary computer program product includes a computer-readable storage medium bearing instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: responsive to a user equipment sending a radio resource control connection complete message with non-access stratum registration request to a serving network for the user equipment, sending by a femtocell toward the serving network a message including an indicator for a cell access mode for the femtocell, a closed access group identification, and an identifier of the femtocell by the femtocell.
  • FIG. 1 is a signaling diagram of an embodiment, Embodiment 1 : CAG verification before UE authentication;
  • FIG. 1A shows the signaling diagram of FIG. 1, and is used to help visualize where parameters from step 4 are used;
  • FIG. 2 is a signaling diagram of an embodiment, Embodiment 2: CAG verification after UE authentication procedure;
  • FIG. 3 is a signaling diagram of an embodiment, Embodiment 3: CAG verification during UE Authentication procedure;
  • FIG. 4 is a table of information elements (IES) in an Uplink NAS Transport message, including some that are applicable to the examples;
  • FIG. 5 is a block diagram of one possible and non-limiting exemplary system in which the exemplary embodiments may be practiced.
  • Any flow diagram or signaling diagram (see FIGS. 1, 1A, 2, and 3) herein is considered to be a logic flow diagram, and illustrates the operation of an exemplary method, results of execution of computer program instructions embodied on a computer readable memory, functions performed by logic implemented in hardware, and/or interconnected means for performing functions in accordance with an exemplary embodiment.
  • FIGS. 1, 1A, 2, and 3 Any flow diagram or signaling diagram (see FIGS. 1, 1A, 2, and 3) herein is considered to be a logic flow diagram, and illustrates the operation of an exemplary method, results of execution of computer program instructions embodied on a computer readable memory, functions performed by logic implemented in hardware, and/or interconnected means for performing functions in accordance with an exemplary embodiment.
  • the orders of method steps, blocks in the flow, or signaling are not critical and instead are examples.
  • a femtocell is a small access point deployed in customer premises (e.g., on a campus or at home) for access to cellular operator, Internet, and local services, like local printers or local servers.
  • Femtocells are low-power, low- range cellular base stations (typically from 10 m to 1 km), that can operate in licensed and unlicensed spectrums.
  • Femtocells may also support only a limited number of UEs. For instance, current designs typically support four to eight simultaneously active UEs in a residential setting, and eight to sixteen mobile phones in enterprise settings.
  • HNB An HNB is a customer-premises equipment that connects a 3 GPP UE over a UTRAN wireless air interface to a mobile operator’s network using a broadband IP backhaul.
  • HeNB An HeNB is a customer-premises equipment that connects a 3 GPP UE over EUTRAN wireless air interface to a mobile operator’s network using a broadband IP backhaul.
  • 5G NR Femtocell 5G NR Femtocell
  • 5G NR Femto CAG cell 5G NR Femto CAG cell
  • femtocell will be shortened below to a femto, and also “femto” may be capitalized, though both Femto and femto have the same meaning.
  • a Closed Subscriber Group identifies a group of subscribers (corresponding to UEs) who are permitted/allowed to access one or more CSG cells of the PLMN identified by CSG ID(s).
  • a UE is a smartphone or other device which contains one or more Universal Subscriber Identity Modules (USIMs).
  • USIMs Universal Subscriber Identity Modules
  • One UE can have more than one USIM.
  • One USIM maps to one subscriber in UDM/UDR. Every USIM has a unique IMSI. A subscriber can be uniquely identified using SUPI/SUCI/5G-GUTI in 5G, which is derived from the IMSI.
  • the CSG Subscriber Server stores Closed Subscriber Group Information, which is a list of up to 50 CSG-Ids in the VPLMN, and for each CSG-Id, optionally an associated expiration date, which indicates the point in time when the subscription to the CSG-Id expires. An absent expiration date indicates unlimited subscription.
  • the CSG Subscriber Server is an optional element that stores CSG subscription data for roaming subscribers. The CSS stores and provides VPLMN specific CSG subscription information.
  • CSG-Ids that are not expired should not be removed at the CSS; rather the expiration date may be modified to an expired date and then be updated by the CSS to the VLR or SGSN or MME.
  • a Closed Access Group identifies a group of subscribers who are permitted/allowed to access one or more CAG cells of the PLMN identified by CAG ID(s), which is assumed to be reused for 5G Femto access control.
  • a CAG cell is a cell broadcasting one or several CAG IDs.
  • a small base station broadcasting CAG IDs is called a Femto base station.
  • the term “small” would mean a small range, usually in 10s of meters, although enterprise femtocells can have larger ranges covering a few 100s of meters also.
  • CAG membership of UE is configured in the user subscription data and on the UE. If a UE is roaming, the access control should be performed in the visited network based on CAG IDs configured in VPLMN, and UE is provisioned with the allowed visited CAG cell access information in the visited network.
  • Embodiment 1 proposes CAG-related access control check to be performed before the UE authentication procedure is initiated in the Core Network. This embodiment is efficient in that, if the CAG verification fails, the amount of subsequent signaling is minimized.
  • Embodiment 2 This embodiment proposes CAG-related access control check to be performed after the UE authentication procedure, but before the NAS Security Mode Command procedure. This embodiment allows the UE authentication to be successfully completed, and then the CAG access control checks are performed. This can be an optimum embodiment, which still ensures that NAS security procedure is avoided if CAG access control fails.
  • FIGS. 1-3 indicate signaling between and operations taken by the following devices: UE 10; 5G NR femtocell 70; 5G NR femto gateway 110; a serving network function 1 and a home network 100.
  • the serving network function 1 may include an AMF 99-1 that access a security anchor function (SEAF) 99-2 or incorporates the SEAF 99-2.
  • SEAF security anchor function
  • the home network 100 can include an authentication server function (AUSF) 199-1, a unified data management (UDM) 199-2, and a unified data repository (UDR) 199-3.
  • the serving network 1 provides the user with access to the telecom services even when roaming.
  • the serving network can also be referred to as the visited network.
  • the home network 100 holds the subscriber’s billing and authentication information, and only after successfully authenticating with home network, can a serving network provide services to any UE.
  • An AMF 99-1 receives all connection and session related information from the user equipment (UE) (e.g., using N1/N2 reference points), and is responsible for handling connection and mobility management tasks.
  • the SEAF 99-2 provides authentication functionality via the AMF in the serving network.
  • the SEAF is a logical function, which may be implemented as a separate NF or integrated in AMF.
  • the SEAF fulfils the following requirements:
  • the SEAF support primary authentication using Subscription Concealed Identifier (SUCI ).
  • SUCI Subscription Concealed Identifier
  • the SEAF is implicit for all authentications performed using the AMF.
  • the AUSF 199-1 is a function which performs authentication.
  • FIG. 1 is a signaling diagram of an embodiment, Embodiment 1 : CAG verification before UE authentication.
  • Step 1 an RRC connection between the UE 10 and the 5G NR femtocell 70 is established.
  • Step 2 there is signaling of Radio Resource Control (RRC) Connection Setup Complete and NAS Registration Request message from the UE 10 to the 5G NR femtocell 70.
  • the signaling includes UL NAS Transport (e.g., with a parameter of SUCI), but there are also additional information elements (IES) in UL NAS transport message carrying the NAS Registration Request message that are included: Cell Access Mode, CAG ID, HgNB ID. See FIG. 4 for more information about these additional IEs.
  • Steps 1-3 are common for FIGS. 1-3.
  • Step 5 In this step (CAC GET REQUEST), the AMF 99-1 requests UDM/UDR to provide the allowed CAG list for the UE, by providing the SUCI or Subscription Permanent Identifier (SUPI).
  • the 5G SUPI can be either: (1) An International Mobile Subscriber Identity (IMSI); or A Network Access Identifier (NAI).
  • IMSI International Mobile Subscriber Identity
  • NAI Network Access Identifier
  • a SUCI allows the SUPI to be signaled without exposing the identity of the user.
  • the SUCI uses a protection scheme that is used to encrypt the SUPI prior to including within a message.
  • the IMSI may be encrypted when used as part of a SUCI.
  • Step 6 In this step (Get Allowed CAG list), the UDM 199-2 retrieves (e.g., from the UDR 199-3) an allowed CAG list for that UE 10. See also block 180: 180: UDM retrieves list by accessing the UDR.
  • Step 7 The UDM 199-2 responds (via a CAC_GET_RESPONSE) to the AMF with allowed CAG list for that UE.
  • FIG. 1A shows the signaling diagram of FIG. 1, and is used to help visualize where parameters from Step 4 are used.
  • the Femto 70 supports closed access so that block 130 is performed (the case when the Femto 70 does not support closed access is not addressed herein).
  • the SUCI of the UL NAS Transport message is used at least in Step 5.
  • the cell access mode and the HgNB ID, respectively are used at least in Step 4. Step 4 in FIG.
  • FIG. 2 is a signaling diagram of an embodiment, Embodiment 2: CAG verification after UE authentication procedure.
  • FIG. 2 illustrates the message flow for Embodiment 2.
  • Steps 5 - 11 Same as steps 4-10 in Embodiment 1.
  • Step 6 The AUSF 199-1 Challenges the AMF for CAG verification using a new CAG Verification Challenge message. This challenge continues until step 11 (success) or step 13 (failure).
  • Step 7 The AMF requests the UDM to provide the allowed CAG list for that UE, using new CAG GET REQUEST message including SUCI or SUPI.
  • Step 8 UDM retrieves (from UDR) allowed CAG list.
  • Step 9 UDM responds to AMF with CAG GET RESPONSE message including allowed CAG list for that UE.
  • Step 10 AMF performs an access control check by comparing a CAG ID received in Step 3 and allowed CAG list received in Step 9.
  • Step 11 AMF sends new message CAG CHALLENGE RESPONSE with the parameter of Success (for the CAG verification challenge started in step 6) to the AUSF 199-1, if the check in Step 10 succeeds.
  • Step 12 If the check in step 10 succeeded, the next signaling involves proceeding with UE Authentication and NAS Security context establishment as defined in 3GPP TS 23.502 clause 4.2.2.2.2.
  • Step 13 If the check in step 10 failed, AMF sends a new CAG CHALLEGE RESPONSE message with a parameter of failure (for the CAG verification challenge started in step 6) to the AUSF 199-1.
  • Step 14 The AUSF 199-1 sends and authentication response to AMF with failure cause parameter listed as Unauthorized CAG access.
  • Step 15 The AMF sends NAS Registration Reject to UE with reject cause as Unauthorized CAG access (see 3GPP TS 24.501 clause 9.11.3.2).
  • FIG. 4 is a table of information elements (IES) in an Uplink NAS Transport message, including some that are applicable to the examples.
  • IES information elements
  • FIG. 4 illustrates an example of the updates required in 3 GPP TS 38.413 clause 9.2.5.3 for UL NAS transport message which is shown in step 3 in all above embodiments. This is merely exemplary, and other techniques may be used.
  • Clause 9.2.5.3 is UPLINK NAS TRANSPORT. This message is sent by the NG-RAN node and is used for carrying NAS information over the NG interface. The direction is from the NG-RAN node (e.g., the 5G NR Femto 70) to the AMF.
  • the TS provides a generic structure for UPLINK NAS TRANSPORT with optional IEs specifically for Femtocells.
  • the CAG ID 420 is an lE/group name, with an optional (O) presence; no indicated range; a 32-bit integer for IE type and reference; no indicated semantics description; criticality is indicated as yes, and assigned criticality is indicated as ignore.
  • the HgNB ID 430 is an lE/group name, with an optional (O) presence; no indicated range; a 32-bit integer for IE type and reference; no indicated semantics description; criticality is indicated as yes, and assigned criticality is indicated as ignore.
  • FIG. 5 shows a block diagram of one possible and non-limiting example of a system into which the examples can be implemented.
  • the system 500 shows the entities from the other figures: UE 10; entities of the serving network 1: 5G NR femtocell (Femto) 70; 5GNR Femto gateway 110; AMF 99-1; SEAF 99-2; entities of the home network 100: AUSF 199-1; UDM 199-2; UDR 199-3.
  • a UE 10 is a wireless communication device, such as a mobile device, that is configured to access a cellular network.
  • the Femto 70 provides access by the UE 10 to the serving network 1.
  • the 5G NR Femto gateway 110 which may be optional in some examples, enables communication between the Femto 70 and the serving network 1 (e.g., the AMF 99-1 in these examples).
  • the apparatus 510 may be used to implement the UE 10, Femto 70, or gateway 110.
  • the apparatus 510 is illustrated as having one or more antennas 58 that communicate over a wireless interface 11.
  • the apparatus 510 includes one or more processors 73, one or more memories 75, and other circuitry 76.
  • the other circuitry 76 includes one or more receivers (Rx(s)) 77 and one or more transmitters (Tx(s)) 78.
  • Instructions 72 are used to cause the base station 70 to perform the operations described herein.
  • the instructions 72 may be implemented via program(s) stored in memory/memories 75 and executed by processor(s) 73, or by circuitry such being implemented as part of the processor(s) or other hardware elements, or both.
  • the apparatus 510 may communicate over wired connection 79.
  • the receivers 77 and transmitters 78 may be wired or wireless or include both wired and wireless options.
  • the wired versions may include wired technologies such as Ethernet, or optical technologies, as examples.
  • the cellular networks 1 and 100 may each include a (e.g., different) core network 90 that includes core network functionality, and which may provide connectivity via a link or links 81 with a data network 91, such as a telephone network and/or a data communications network (e.g., the Internet).
  • the core network 90 includes one or more processors 93, one or more memories 95, and other circuitry 96.
  • the other circuitry 96 includes one or more receivers (Rx(s)) 97 and one or more transmitters (Tx(s)) 98.
  • Instructions 92 are used to cause the core network 90 to perform the operations described herein.
  • Instructions 92 may be implemented via program(s) stored in memory/memories 95 and executed by processor(s) 93, or by circuitry such being implemented as part of the processor(s) or other hardware elements, or both.
  • Core network 90 can communicate over interface(s) 71 with other elements in the serving network 1, such as the Femto gateway 110 (e.g., or in some cases, the Femto 70), along with other nodes such as gNBs or other RAN nodes [0087]
  • the core network 90 could be a 5G core network (5GC ).
  • the core network 90 can implement or comprise multiple network functions (NF(s)) 99/199, and the program 92 may comprise one or more of the network functions (NFs) 99/199.
  • a 5G core network may use circuitry such as memory and processors and a virtualization layer. It could be a single standalone computing system, a distributed computing system, or a cloud computing system.
  • the NFs 99/199, as network elements, of the core network could be containers or virtual machines running on the hardware of the computing system(s) making up the core network 90.
  • Core network functionality for 5G may include access and mobility management functionality that is provided by a network function 99/199 such as an access and mobility management function (AMF) 99-1, the SEAF 99-2, the AUSF 199-1, or UDM (Unified Data Management) 199-2/UDR (Unified Data Repository) 199-3.
  • AMF access and mobility management function
  • SEAF SEAF
  • AUSF AUSF
  • UDM Unified Data Management
  • 199-2/UDR Unified Data Repository
  • Block 2 illustrates that the core network 90 has a set of resources including 92, 93, 95, and 96.
  • the individual NFs 99/199 such as the AMF 99-1, the SEAF 99-2, the AUSF 199-1, the UDM 199-2, or the UDR 199-3, can be implemented via a corresponding subset 2’ of resources comprising 92-x, 93-x, and 95-x, where “x” indicates that different subsets of resources can be used for different NFs 99/199. It may be possible for the same subset of resources to be used for multiple NFs 99/199, such as one subset of resources being used for AMF 99-1 and SEAF 99-2.
  • the individual NFs 99/199 are implemented via a virtualization machine, VM, (e.g., a virtualization layer), a container, or cloud-native architecture, these are implemented via the subset 2’ of resources. That is, the NFs 99/199 such as the access and mobility management function (AMF) 99-1 are implemented via circuitry like the processors 93-x and memories 95-x, and the instructions 92-x. Specifically, the one or more memories 95-x store instructions 92-x of the AMF 99-1, wherein the instructions 92-x when executed by one or more processors 93-x cause an apparatus (e.g., core network 90 or a part of it) to perform operations as described herein.
  • an apparatus e.g., core network 90 or a part of it
  • the receivers 77 and 97, and the transmitters 78 and 98 may implement wired or wireless interfaces.
  • the receivers and transmitters may be grouped together as transceivers.
  • a computer-readable medium 94 In the data network 91, there is a computer-readable medium 94.
  • the computer-readable medium 94 contains instructions that, when downloaded and installed into the memories 75 or 95 of the corresponding apparatus 510 and/or core network element(s) 90, and executed by processor(s) 73 or 93, cause the respective device to perform corresponding actions described herein.
  • the computer-readable medium 94 may be implemented in other forms, such as via a compact disc or memory stick.
  • the instructions 72 and 92 may be stored by corresponding one or more memories 75 or 95. These instructions, when executed by the corresponding one or more processors 73 or 93, cause the corresponding apparatus 510 or 90 to perform the operations described herein.
  • the computer readable memories 75 or 95 are circuitry and may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor-based memory devices, flash memory, firmware, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory.
  • the processors 73 and 93 are circuitry and may be of any type suitable to the local technical environment.
  • these processors may include one or more of general-purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), processors based on a multi-core processor architecture, and may also include specialized circuits such as field-programmable gate arrays (FPGAs), application specific circuits (ASICs), signal processing devices and other devices, or combinations of these devices, as non-limiting examples.
  • the processors 73 and 93 are circuitry that can be programmed to perform functions via software, firmware or the like (including microcode), but are not solely software.
  • the cellular network 1 may implement network virtualization, which is the process of combining circuitry and software network resources and network functionality into a single, software-based administrative entity, a virtual network.
  • Network virtualization involves platform virtualization, often combined with resource virtualization.
  • Network virtualization is categorized as either external, combining many networks, or parts of networks, into a virtual unit, or internal, providing network-like functionality to software containers on a single system.
  • the virtualized entities such as network functions 99/199) that result from the network virtualization are still implemented, at some level, using circuitry such as processors 73 and/or 93 and memories 75 and/or 95, and also such virtualized entities create technical effects.
  • a technical effect and/or advantage of one or more of the example embodiments disclosed herein includes optimization of signaling flow because CAG verification happens at an early stage, and UE authentication, NAS security context, AS security context establishment signaling can be avoided if UE is not a member of a CAG list.
  • Another technical effect and/or advantage of one or more of the example embodiments disclosed herein is that the functionality of UE access control is also achieved.
  • Example 1 A method, comprising: based on a femtocell in a serving network supporting closed access, performing by an access and mobility management function in the serving network for a user equipment signaling comprising: sending, to a unified data management in a home network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; receiving, from the unified data management, the list of closed access groups the user equipment is allowed to access; and performing, by the access and mobility management function, verification of whether a provided closed access group identification is in the list of closed access groups the user equipment is allowed to access; and performing one of the following: based on the verification being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell; or based on the verification not being
  • Example 2 The method according to example 1, further comprising: receiving, at an access and mobility management function in the serving network for a user equipment, an indication of cell access mode and an identifier for the femtocell; determining, by the access and mobility management function using the identifier for the femtocell, the femtocell; and determining, by the access and mobility management function using the indicated cell access mode, that the femtocell supports closed access.
  • Example 3 The method according to example 2, wherein the identifier for the femtocell comprises an HgNB identification.
  • Example 4 The method according to example 2 or 3, wherein determining, by the access and mobility management function using the indicated cell access mode, that the femtocell supports only closed access.
  • Example 5 The method according to any of examples 1 to 4, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell; and participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
  • Example 6 The method according to example 1 or 2, further comprising: prior to sending, to the unified data management in the home network for the user equipment, the request comprising the identifier for the user equipment, participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell.
  • Example 7 The method according to example 6, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
  • Example 8 The method according to example 1 or 2, further comprising, prior to sending, to the unified data management in the home network for the user equipment, the request comprising the identifier for the user equipment: sending, by the access and 1 mobility management function to an authentication server function in the home network, an authentication request with an identifier of the user equipment, a network name indicating the serving network, and indication of a cell access mode; and receiving, by the access and mobility management function from the authentication server function, a closed access group verification challenge.
  • Example 9 The method according to example 8, further comprising: based on the verification being successful, sending by the access and mobility management function to the authentication server function a closed access group challenge response message indicating success.
  • Example 10 The method according to example 9, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell; and participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
  • Example 11 The method according to example 8, wherein the verification was a failure, and the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to an authentication server function, a message indicating there was a closed access group challenge failure; and receiving, by the access and mobility management function from the authentication server function, an authentication response indicating a failure due to unauthorized closed access group access.
  • Example 12 The method according to example 11, wherein the verification was a failure, and the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to the user equipment, a rejection with a cause of closed access group verification failure.
  • Example 13 The method according to any of examples 1 to 4, 6, and 8 wherein the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to the user equipment, a rejection with a cause of unauthorized closed access group access.
  • Example 14 The method according to any of examples 1 to 13, wherein the femtocell communicates with the access and mobility management function of the serving network via a femto gateway.
  • Example 15 A method, comprising: receiving, by a unified data management in a home network for a user equipment and from an access and mobility management function in a serving network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access; and sending, by the unified data management to the access and mobility management function, the list of closed access groups the user equipment is allowed to access.
  • Example 16 The method according to example 15, wherein the retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access comprises retrieving by the unified data management the list of closed access groups the user equipment is allowed to access from a database.
  • Example 17 A method, comprising: responsive to a user equipment sending a radio resource control connection complete message with non-access stratum registration request to a serving network for the user equipment, sending by a femtocell toward the serving network a message including an indicator for a cell access mode for the femtocell, a closed access group identification, and an identifier of the femtocell by the femtocell.
  • Example 18 The method according to example 17, wherein: the method further comprises, prior to sending the message: establishing, by a femtocell with a user equipment, a radio resource control connection; and receiving, by the femtocell from the user equipment, a non-access stratum registration request; the message is sent toward an access and mobility management function in the serving network.
  • Example 19 the method further comprises, prior to sending the message: establishing, by a femtocell with a user equipment, a radio resource control connection; and receiving, by the femtocell from the user equipment, a non-access stratum registration request; the message is sent toward an access and mobility management function in the serving network.
  • the radio resource control connection complete message with non-access stratum registration request requests the user equipment to be provided with access to a closed access group corresponding to the closed access group identification for the femtocell that is indicated by the identifier; and the method further comprises participating, by the femtocell, in one or more additional processes to provide the user equipment with access to the closed access group for the femtocell.
  • Example 20 An apparatus, comprising means for: based on a femtocell in a serving network supporting closed access, performing by an access and mobility management function in the serving network for a user equipment signaling comprising: sending, to a unified data management in a home network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; receiving, from the unified data management, the list of closed access groups the user equipment is allowed to access; and performing, by the access and mobility management function, verification of whether a provided closed access group identification is in the list of closed access groups the user equipment is allowed to access; and performing one of the following: based on the verification being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell; or based on the
  • Example 21 The apparatus according to example 20, wherein the means are further configured for: receiving, at an access and mobility management function in the serving network for a user equipment, an indication of cell access mode and an identifier for the femtocell; determining, by the access and mobility management function using the identifier for the femtocell, the femtocell; and determining, by the access and mobility management function using the indicated cell access mode, that the femtocell supports closed access.
  • Example 22 The apparatus according to example 21, wherein the identifier for the femtocell comprises an HgNB identification.
  • Example 23 The apparatus according to example 21 or 22, wherein determining, by the access and mobility management function using the indicated cell access mode, that the femtocell supports only closed access.
  • Example 24 The apparatus according to any of examples 20 to 23, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell; and participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
  • Example 25 The apparatus according to example 20 or 21, wherein the means are further configured for: prior to sending, to the unified data management in the home network for the user equipment, the request comprising the identifier for the user equipment, participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell.
  • Example 26 The apparatus according to example 25, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
  • Example 27 The apparatus according to example 20 or 21, wherein the means are further configured for, prior to sending, to the unified data management in the home network for the user equipment, the request comprising the identifier for the user equipment: sending, by the access and mobility management function to an authentication server function in the home network, an authentication request with an identifier of the user equipment, a network name indicating the serving network, and indication of a cell access mode; and receiving, by the access and mobility management function from the authentication server function, a closed access group verification challenge.
  • Example 28 The apparatus according to example 27, wherein the means are further configured for: based on the verification being successful, sending by the access and mobility management function to the authentication server function a closed access group challenge response message indicating success.
  • Example 29 The apparatus according to example 28, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell; and participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
  • Example 30 The apparatus according to example 27, wherein the verification was a failure, and the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to an authentication server function, a message indicating there was a closed access group challenge failure; and receiving, by the access and mobility management function from the authentication server function, an authentication response indicating a failure due to unauthorized closed access group access.
  • Example 31 The apparatus according to example 30, wherein the verification was a failure, and the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to the user equipment, a rejection with a cause of closed access group verification failure.
  • Example 32 The apparatus according to any of examples 20 to 23, 25, and 27 wherein the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to the user equipment, a rejection with a cause of unauthorized closed access group access.
  • Example 33 The apparatus according to any of examples 20 to 32, wherein the femtocell communicates with the access and mobility management function of the serving network via a femto gateway.
  • Example 34 An apparatus, comprising means for: receiving, by a unified data management in a home network for a user equipment and from an access and mobility management function in a serving network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access; and sending, by the unified data management to the access and mobility management function, the list of closed access groups the user equipment is allowed to access.
  • Example 35 The apparatus according to example 34, wherein the retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access comprises retrieving by the unified data management the list of closed access groups the user equipment is allowed to access from a database.
  • Example 36 An apparatus, comprising means for: responsive to a user equipment sending a radio resource control connection complete message with non-access stratum registration request to a serving network for the user equipment, sending by a femtocell toward the serving network a message including an indicator for a cell access mode for the femtocell, a closed access group identification, and an identifier of the femtocell by the femtocell.
  • Example 37 The apparatus according to example 36, wherein: the means are further configured for, prior to sending the message: establishing, by a femtocell with a user equipment, a radio resource control connection; and receiving, by the femtocell from the user equipment, a non-access stratum registration request; the message is sent toward an access and mobility management function in the serving network.
  • Example 38 The apparatus according to example 36 or 37, wherein: the radio resource control connection complete message with non-access stratum registration request requests the user equipment to be provided with access to a closed access group corresponding to the closed access group identification for the femtocell that is indicated by the identifier; and the means are further configured for participating, by the femtocell, in one or more additional processes to provide the user equipment with access to the closed access group for the femtocell.
  • Example 39 An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: based on a femtocell in a serving network supporting closed access, performing by an access and mobility management function in the serving network for a user equipment signaling comprising: sending, to a unified data management in a home network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; receiving, from the unified data management, the list of closed access groups the user equipment is allowed to access; and performing, by the access and mobility management function, verification of whether a provided closed access group identification is in the list of closed access groups the user equipment is allowed to access; and performing one of the following: based on the verification being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to provide the user
  • Example 40 The apparatus according to example 39, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, at an access and mobility management function in a serving network for a user equipment, an indication of cell access mode and an identifier for the femtocell; determining, by the access and mobility management function using the identifier for the femtocell, the femtocell; and determining, by the access and mobility management function using the indicated cell access mode, that the femtocell supports closed access.
  • Example 41 The apparatus according to example 40, wherein the identifier for the femtocell comprises an HgNB identification.
  • Example 42 The apparatus according to example 40 or 41, wherein determining, by the access and mobility management function using the indicated cell access mode, that the femtocell supports only closed access.
  • Example 43 The apparatus according to any of examples 39 to 42, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell; and participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
  • Example 44 The apparatus according to example 39 or 40, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform: prior to sending, to the unified data management in the home network for the user equipment, the request comprising the identifier for the user equipment, participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell.
  • Example 45 The apparatus according to example 44, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
  • Example 46 The apparatus according to example 39 or 40, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform, prior to sending, to the unified data management in the home network for the user equipment, the request comprising the identifier for the user equipment: sending, by the access and mobility management function to an authentication server function in the home network, an authentication request with an identifier of the user equipment, a network name indicating the serving network, and indication of a cell access mode; and receiving, by the access and mobility management function from the authentication server function, a closed access group verification challenge.
  • Example 47 The apparatus according to example 46, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform: based on the verification being successful, sending by the access and mobility management function to the authentication server function a closed access group challenge response message indicating success.
  • Example 48 The apparatus according to example 47, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell; and participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
  • Example 50 The apparatus according to example 49, wherein the verification was a failure, and the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to the user equipment, a rejection with a cause of closed access group verification failure.
  • Example 51 The apparatus according to any of examples 39 to 42, 44, and 46 wherein the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to the user equipment, a rejection with a cause of unauthorized closed access group access.
  • Example 52 The apparatus according to any of examples 39 to 51, wherein the femtocell communicates with the access and mobility management function of the serving network via a femto gateway.
  • Example 53 An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, by a unified data management in a home network for a user equipment and from an access and mobility management function in a serving network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access; and sending, by the unified data management to the access and mobility management function, the list of closed access groups the user equipment is allowed to access.
  • Example 55 An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: responsive to a user equipment sending a radio resource control connection complete message with non-access stratum registration request to a serving network for the user equipment, sending by a femtocell toward the serving network a message including an indicator for a cell access mode for the femtocell, a closed access group identification, and an identifier of the femtocell by the femtocell.
  • Example 56 Example 56.
  • Example 57 The apparatus according to example 55 or 56, wherein: the radio resource control connection complete message with non-access stratum registration request requests the user equipment to be provided with access to a closed access group corresponding to the closed access group identification for the femtocell that is indicated by the identifier; and the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform participating, by the femtocell, in one or more additional processes to provide the user equipment with access to the closed access group for the femtocell.
  • Example 58 A computer program, comprising instructions which, when the program is executed by an apparatus, cause the apparatus to carry out the methods of any of examples 1 to 19.
  • Example 59 The computer program according to example 58, wherein the computer program is a computer program product comprising a computer-readable medium bearing the instructions embodied therein for use with the apparatus.
  • Example 60 The computer program according to example 58, wherein the computer program is directly loadable into an internal memory of the apparatus.
  • Example 61 A system, comprising: an apparatus according to any of examples 20 to 33; an apparatus according to examples 34 or 35; and an apparatus according to any of examples 36 to 38.
  • circuitry may refer to one or more or all of the following:
  • software e.g., firmware
  • circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and/or firmware.
  • circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
  • a computer-readable medium may comprise a computer-readable storage medium (e.g., memories 75 and 95 or other device) that may be any media or means that can contain, store, and/or transport the instructions for use by or in connection with an instruction execution system, apparatus, or device, such as a computer.
  • a computer-readable storage medium does not comprise propagating signals, and therefore may be considered to be non-transitory.
  • the term “non- transitory”, as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM, random access memory, versus ROM, read-only memory).
  • the different functions discussed herein may be performed in a different order and/or concurrently with each other. Furthermore, if desired, one or more of the above-described functions may be optional or may be combined.
  • eNB or eNodeB evolved Node B (e.g., an LTE base station)
  • gNB or gNodeB base station for 5G/NR
  • HeNB home eNB (or eNodeB)
  • HgNB home gNB (or gNodeB)
  • VLR Visitor Location Register [00213]

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Databases & Information Systems (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

Techniques are disclosed for a UE via a femtocell for authorization for access to the femtocell when the femtocell supports (e.g., only) closed access. An AMF in a serving network for the UE checks whether the femtocell supports (e.g., only) closed access (for a CAG). If so, the AMF performs CAG verification to determine whether the verification of the UE (e.g., and corresponding CAG ID) is successful or fails. The verification uses NFs from the home network of the UE, including an AUSF, UDM and database. A list of allowed CAGs is accessed and used. If the verification is successful, the AMF participates in other operations to provide the UE with access to the CAG; if it fails, the AMD participates in other operations to reject CAG access by the UE. Authorization process for the UE may be performed at different times and a CAG challenge/response scheme may be used.

Description

CAG Verification for 5G NR Femtocell
TECHNICAL FIELD
[0001] Examples of embodiments herein relate generally to wireless communications and, more specifically, relate to access control for UEs (user equipment) for femtocells in 5G (fifth generation) cellular systems.
BACKGROUND
[0002] In some cellular systems, a group of subscribers (corresponding to UEs, user equipment) are permitted/allowed to access one or more Femtocells via access control. A Closed Access Group (CAG) identifies these subscribers and the Femtocells can be CAG cells of a public land mobile network (PLMN) identified by CAG ID(s) (identification(s)), which is assumed to be reused for 5G Femtocell access control.
[0003] The process for verification for this could be improved.
BRIEF SUMMARY
[0004] This section is intended to include examples and is not intended to be limiting.
[0005] In an exemplary embodiment, a method is disclosed that includes based on a femtocell in a serving network supporting closed access, performing by an access and mobility management function in the serving network for a user equipment signaling comprising: sending, to a unified data management in a home network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; receiving, from the unified data management, the list of closed access groups the user equipment is allowed to access; and performing, by the access and mobility management function, verification of whether a provided closed access group identification is in the list of closed access groups the user equipment is allowed to access; and performing one of the following: based on the verification being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell; or based on the verification not being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell.
[0006] An additional exemplary embodiment includes a computer program, comprising instructions for performing the method of the previous paragraph, when the computer program is run on an apparatus. The computer program according to this paragraph, wherein the computer program is a computer program product comprising a computer- readable medium bearing the instructions embodied therein for use with the apparatus. Another example is the computer program according to this paragraph, wherein the program is directly loadable into an internal memory of the apparatus.
[0007] An exemplary apparatus includes one or more processors and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: based on a femtocell in a serving network supporting closed access, performing by an access and mobility management function in the serving network for a user equipment signaling comprising: sending, to a unified data management in a home network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; receiving, from the unified data management, the list of closed access groups the user equipment is allowed to access; and performing, by the access and mobility management function, verification of whether a provided closed access group identification is in the list of closed access groups the user equipment is allowed to access; and performing one of the following: based on the verification being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell; or based on the verification not being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell.
[0008] An exemplary computer program product includes a computer-readable storage medium bearing instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: based on a femtocell in a serving network supporting closed access, performing by an access and mobility management function in the serving network for a user equipment signaling comprising: sending, to a unified data management in a home network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; receiving, from the unified data management, the list of closed access groups the user equipment is allowed to access; and performing, by the access and mobility management function, verification of whether a provided closed access group identification is in the list of closed access groups the user equipment is allowed to access; and performing one of the following: based on the verification being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell; or based on the verification not being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell.
[0009] In another exemplary embodiment, an apparatus comprises means for: based on a femtocell in a serving network supporting closed access, performing by an access and mobility management function in the serving network for a user equipment signaling comprising: sending, to a unified data management in a home network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; receiving, from the unified data management, the list of closed access groups the user equipment is allowed to access; and performing, by the access and mobility management function, verification of whether a provided closed access group identification is in the list of closed access groups the user equipment is allowed to access; and performing one of the following: based on the verification being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell; or based on the verification not being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell.
[0010] In an exemplary embodiment, a method is disclosed that includes receiving, by a unified data management in a home network for a user equipment and from an access and mobility management function in a serving network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access; and sending, by the unified data management to the access and mobility management function, the list of closed access groups the user equipment is allowed to access.
[0011] An additional exemplary embodiment includes a computer program, comprising instructions for performing the method of the previous paragraph, when the computer program is run on an apparatus. The computer program according to this paragraph, wherein the computer program is a computer program product comprising a computer- readable medium bearing the instructions embodied therein for use with the apparatus. Another example is the computer program according to this paragraph, wherein the program is directly loadable into an internal memory of the apparatus.
[0012] An exemplary apparatus includes one or more processors and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, by a unified data management in a home network for a user equipment and from an access and mobility management function in a serving network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access; and sending, by the unified data management to the access and mobility management function, the list of closed access groups the user equipment is allowed to access.
[0013] An exemplary computer program product includes a computer-readable storage medium bearing instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: receiving, by a unified data management in a home network for a user equipment and from an access and mobility management function in a serving network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access; and sending, by the unified data management to the access and mobility management function, the list of closed access groups the user equipment is allowed to access.
[0014] In another exemplary embodiment, an apparatus comprises means for: receiving, by a unified data management in a home network for a user equipment and from an access and mobility management function in a serving network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access; and sending, by the unified data management to the access and mobility management function, the list of closed access groups the user equipment is allowed to access.
[0015] In an exemplary embodiment, a method is disclosed that includes responsive to a user equipment sending a radio resource control connection complete message with non-access stratum registration request to a serving network for the user equipment, sending by a femtocell toward the serving network a message including an indicator for a cell access mode for the femtocell, a closed access group identification, and an identifier of the femtocell by the femtocell.
[0016] An additional exemplary embodiment includes a computer program, comprising instructions for performing the method of the previous paragraph, when the computer program is run on an apparatus. The computer program according to this paragraph, wherein the computer program is a computer program product comprising a computer- readable medium bearing the instructions embodied therein for use with the apparatus. Another example is the computer program according to this paragraph, wherein the program is directly loadable into an internal memory of the apparatus.
[0017] An exemplary apparatus includes one or more processors and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: responsive to a user equipment sending a radio resource control connection complete message with non-access stratum registration request to a serving network for the user equipment, sending by a femtocell toward the serving network a message including an indicator for a cell access mode for the femtocell, a closed access group identification, and an identifier of the femtocell by the femtocell.
[0018] An exemplary computer program product includes a computer-readable storage medium bearing instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: responsive to a user equipment sending a radio resource control connection complete message with non-access stratum registration request to a serving network for the user equipment, sending by a femtocell toward the serving network a message including an indicator for a cell access mode for the femtocell, a closed access group identification, and an identifier of the femtocell by the femtocell.
[0019] In another exemplary embodiment, an apparatus comprises means for: responsive to a user equipment sending a radio resource control connection complete message with non-access stratum registration request to a serving network for the user equipment, sending by a femtocell toward the serving network a message including an indicator for a cell access mode for the femtocell, a closed access group identification, and an identifier of the femtocell by the femtocell.
BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The accompanying drawings use reference numerals, where the same reference numerals may be used to refer to like parts throughout, but parts having the same reference numeral can differ in operation and components. In the attached drawings:
[0021] FIG. 1 is a signaling diagram of an embodiment, Embodiment 1 : CAG verification before UE authentication; [0022] FIG. 1A shows the signaling diagram of FIG. 1, and is used to help visualize where parameters from step 4 are used;
[0023] FIG. 2 is a signaling diagram of an embodiment, Embodiment 2: CAG verification after UE authentication procedure;
[0024] FIG. 3 is a signaling diagram of an embodiment, Embodiment 3: CAG verification during UE Authentication procedure;
[0025] FIG. 4 is a table of information elements (IES) in an Uplink NAS Transport message, including some that are applicable to the examples;
[0026] FIG. 5 is a block diagram of one possible and non-limiting exemplary system in which the exemplary embodiments may be practiced.
DETAILED DESCRIPTION OF THE DRAWINGS
[0027] Abbreviations that may be found in the specification and/or the drawing figures are defined below, at the end of the detailed description section.
[0028] The word “exemplary” is used herein to mean “serving as an example, instance, or illustration.” Any embodiment described herein as “exemplary” is not necessarily to be construed as preferred or advantageous over other embodiments. All of the embodiments described in this Detailed Description are exemplary embodiments provided to enable persons skilled in the art to make or use the examples.
[0029] When more than one drawing reference numeral, word, or acronym is used within this description with and in general as used within this description, the “/” may be interpreted as “or”, “and”, or “both”. As used herein, “at least one of the following: <a list of two or more elements>” and “at least one of <a list of two or more elements>” and similar wording, where the list of two or more elements are joined by “and” or “or,” mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0030] As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises”, “comprising”, “has”, “having”, “includes” and/or “including”, when used herein, specify the presence of stated features, elements, and/or components etc., but do not preclude the presence or addition of one or more other features, elements, components and/ or combinations thereof. [0031] It is noted that capital and lowercase words or phrases are considered to be the same herein. For instance, the words Slice and slice are the same, as are the phrases Network Repository Function and network repository function.
[0032] Any flow diagram or signaling diagram (see FIGS. 1, 1A, 2, and 3) herein is considered to be a logic flow diagram, and illustrates the operation of an exemplary method, results of execution of computer program instructions embodied on a computer readable memory, functions performed by logic implemented in hardware, and/or interconnected means for performing functions in accordance with an exemplary embodiment. For methods, flow diagrams, and signaling diagrams, the orders of method steps, blocks in the flow, or signaling are not critical and instead are examples.
[0033] Technical context is now provided for technical areas related to the understanding of the examples. A femtocell is a small access point deployed in customer premises (e.g., on a campus or at home) for access to cellular operator, Internet, and local services, like local printers or local servers. In further detail, Femtocells are low-power, low- range cellular base stations (typically from 10 m to 1 km), that can operate in licensed and unlicensed spectrums. Femtocells may also support only a limited number of UEs. For instance, current designs typically support four to eight simultaneously active UEs in a residential setting, and eight to sixteen mobile phones in enterprise settings. These are examples, but the term “femtocell” and what encompasses this term can be determined by one skilled in this area. In further detail, while the term “femtocell” is not yet explicitly defined in 3GPP, in previous releases, Home NodeB and Home eNodeB were defined in 3GPP TS 22.220. These terms are as follows.
[0034] HNB: An HNB is a customer-premises equipment that connects a 3 GPP UE over a UTRAN wireless air interface to a mobile operator’s network using a broadband IP backhaul.
[0035] HeNB: An HeNB is a customer-premises equipment that connects a 3 GPP UE over EUTRAN wireless air interface to a mobile operator’s network using a broadband IP backhaul.
[0036] In 5G, as of now HgNB is not explicitly defined, but the current plan appears to be to use the term “5G NR Femtocell” for an HgNB. The term 5G NR Femto CAG cell may also be used. It is noted that the term femtocell will be shortened below to a femto, and also “femto” may be capitalized, though both Femto and femto have the same meaning.
[0037] In Release- 19 (Rel-19) a study item on Femto support in 5G has been approved at TSG SA#102 in SP-231797 (NTT DOCOMO, “New SID: Study on System aspects of 5G NR Femto, TSG SA Meeting #102, 11-15 December 2023, Edinburgh, Scotland). In 3GPP SA3, the relevant security aspects are getting studied under 3GPP TR 33.745.
[0038] In Long Term Evolution (LIE) Femto, also called HeNB, or 4G femtos, a Closed Subscriber Group (CSG) identifies a group of subscribers (corresponding to UEs) who are permitted/allowed to access one or more CSG cells of the PLMN identified by CSG ID(s). For subscribers and corresponding UEs, a UE is a smartphone or other device which contains one or more Universal Subscriber Identity Modules (USIMs). One UE can have more than one USIM. One USIM maps to one subscriber in UDM/UDR. Every USIM has a unique IMSI. A subscriber can be uniquely identified using SUPI/SUCI/5G-GUTI in 5G, which is derived from the IMSI.
[0039] In LIE Femto, if the visited PLMN (VPLMN) supports VPLMN Autonomous CSG Roaming by providing CSG membership to the roaming subscriber, the CSG Subscriber Server (CSS) stores Closed Subscriber Group Information, which is a list of up to 50 CSG-Ids in the VPLMN, and for each CSG-Id, optionally an associated expiration date, which indicates the point in time when the subscription to the CSG-Id expires. An absent expiration date indicates unlimited subscription. In further detail, the CSG Subscriber Server (CSS) is an optional element that stores CSG subscription data for roaming subscribers. The CSS stores and provides VPLMN specific CSG subscription information.
[0040] NOTE 1 : The home PLMN (HPLMN) enables Autonomous CSG Roaming in the VPLMN via Service Level Agreement.
[0041] When a CSG-Id expires, or the expiration date is changed (e.g., added or modified) to an expired date, the CSG-Id may be removed from the CSS and the Visitor Location Register (VLR) or Serving GPRS Support Node (SGSN) or mobility management entity (MME) based on implementation.
[0042] NOTE 2: In the VLR or SGSN or MME, an expired CSG-Id subscription indicates that the UE is not allowed service in the CSG. However, since the CSG-Id removal from the UE is pending, the UE may still camp on that CSG and therefore the UE may still be paged in the CSG.
[0043] If the subscription is terminated by means other than expiry, then CSG-Ids that are not expired should not be removed at the CSS; rather the expiration date may be modified to an expired date and then be updated by the CSS to the VLR or SGSN or MME.
[0044] In 5G, a Closed Access Group (CAG) identifies a group of subscribers who are permitted/allowed to access one or more CAG cells associated to the CAG ID. A CAG cell is a cell broadcasting one or several CAG IDs.
[0045] In the approved study item SP-231797, one of the work items is the following: Study whether and how to support enabling the provisioning of subscribers allowed to access a CAG cell and to manage access control by the CAG owner or an authorized administrator. In the approved study item SP-231797, one of the work items is the following: Study whether and how to support enabling the provisioning of subscribers allowed to access a CAG cell and to manage access control by the CAG owner or an authorized administrator.
[0046] In Public network integrated non-public network (PNI-NPN), a Closed Access Group (CAG) identifies a group of subscribers who are permitted/allowed to access one or more CAG cells of the PLMN identified by CAG ID(s), which is assumed to be reused for 5G Femto access control. A CAG cell is a cell broadcasting one or several CAG IDs. A small base station broadcasting CAG IDs is called a Femto base station. As described previously, the term “small” would mean a small range, usually in 10s of meters, although enterprise femtocells can have larger ranges covering a few 100s of meters also. CAG membership of UE is configured in the user subscription data and on the UE. If a UE is roaming, the access control should be performed in the visited network based on CAG IDs configured in VPLMN, and UE is provisioned with the allowed visited CAG cell access information in the visited network.
[0047] The examples herein propose three embodiments as solutions at least to address the issue of UE access control with CAG concept of 5G NR Femto. First, an overview is provided, then more details are provided. For all three embodiments, as part of, e.g., the uplink (UL) Non-access stratum (NAS) transport message (which includes the NAS Registration Request), additional fields are proposed to be added: Cell Access Mode; CAG ID; and/or HgNB ID. [0048] Embodiment 1 : This embodiment proposes CAG-related access control check to be performed before the UE authentication procedure is initiated in the Core Network. This embodiment is efficient in that, if the CAG verification fails, the amount of subsequent signaling is minimized.
[0049] Embodiment 2: This embodiment proposes CAG-related access control check to be performed after the UE authentication procedure, but before the NAS Security Mode Command procedure. This embodiment allows the UE authentication to be successfully completed, and then the CAG access control checks are performed. This can be an optimum embodiment, which still ensures that NAS security procedure is avoided if CAG access control fails.
[0050] Embodiment 3: This embodiment proposes CAG-related access control check to be performed during the UE authentication procedure and embeds the relevant messages in this process. This embodiment allows re-use of authentication request and response messages and the CAG verification steps are embedded in the authentication procedure.
[0051] Steps 1-3 are common for all embodiments illustrated by FIGS. 1-3. FIGS. 1-3 indicate signaling between and operations taken by the following devices: UE 10; 5G NR femtocell 70; 5G NR femto gateway 110; a serving network function 1 and a home network 100. The serving network function 1 may include an AMF 99-1 that access a security anchor function (SEAF) 99-2 or incorporates the SEAF 99-2. The home network 100 can include an authentication server function (AUSF) 199-1, a unified data management (UDM) 199-2, and a unified data repository (UDR) 199-3. The serving network 1 provides the user with access to the telecom services even when roaming. The serving network can also be referred to as the visited network. The home network 100 holds the subscriber’s billing and authentication information, and only after successfully authenticating with home network, can a serving network provide services to any UE.
[0052] The 5G NR femto gateway 110 may have a number of options. 3GPP TS 23.830 defines a version of this as follows: H(e)NB Gateway: H(e)NB Gateway is a mobile network operator's equipment (usually physically located on mobile operator premises) through which the H(e)NB gets access to mobile operator's core network. For HeNBs, the HeNB Gateway is optional. Another option is as follows. The Home NodeB Gateway (HNB- GW) is the gateway through which the Home NodeB accesses the core network and includes the HNB and UE registration functions, UE access control, and an lu handling function to connect the HNB to the core network. Some optimization functions such as paging optimization for the UEs under HNB coverage may also be included. Further details can be found in 3GPP TS 25.467.
[0053] An AMF 99-1 receives all connection and session related information from the user equipment (UE) (e.g., using N1/N2 reference points), and is responsible for handling connection and mobility management tasks. The SEAF 99-2 provides authentication functionality via the AMF in the serving network. The SEAF is a logical function, which may be implemented as a separate NF or integrated in AMF. The SEAF fulfils the following requirements: The SEAF support primary authentication using Subscription Concealed Identifier (SUCI ). The SEAF is implicit for all authentications performed using the AMF. The AUSF 199-1 is a function which performs authentication. For instance, the AUSF may support the following functionality: Supports authentication for 3 GPP access and untrusted non-3GPP access as specified in TS 33.501; and Supports authentication of UE for a Disaster Roaming service as specified in TS 33.501. UDM 199-2 manages network user data in a single, centralized element. In particular, UDM manages UDR 199-3, which is a repository and essentially a database. Thus, a UDM can be paired with the UDR, which stores the user data such as customer profile information, customer authentication information, and encryption keys for the information. The UDR may be considered to be a database that provides storage and retrieval of subscription data by the UDM; Storage and retrieval of policy data by the policy control function (PCF); Storage and retrieval of structured data for exposure; Application data; and Storage and retrieval of an ID corresponding to subscriber identifier.
[0054] Implementations herein may have an integrated AUSF 199-1 with UDM 199-2/UDR 199-3, as illustrated in FIGS. 1 and 2, or have a separate NF as AUSF, which interfaces with UDM/UDR, as illustrated in FIG. 3. In FIG. 3, the proposal is more aligned with the functionality of AUSF, and this could be applied to FIGS. 1 or 2 (and the structure of FIGS. 1 or 2 could be applied to FIG. 3).
[0055] Turn to FIG. 1 for an example. FIG. 1 is a signaling diagram of an embodiment, Embodiment 1 : CAG verification before UE authentication. In Step 1 , an RRC connection between the UE 10 and the 5G NR femtocell 70 is established. In Step 2, there is signaling of Radio Resource Control (RRC) Connection Setup Complete and NAS Registration Request message from the UE 10 to the 5G NR femtocell 70. In Step 3, the signaling includes UL NAS Transport (e.g., with a parameter of SUCI), but there are also additional information elements (IES) in UL NAS transport message carrying the NAS Registration Request message that are included: Cell Access Mode, CAG ID, HgNB ID. See FIG. 4 for more information about these additional IEs. As previously stated, Steps 1-3 are common for FIGS. 1-3.
[0056] The rest of the signaling and operations in FIG. 1 are described as follows. It is noted that the serving network 1 is assumed to have, as a network function, an AMF 99-1 that has access to or incorporates the SEAF 99-2. In FIGS. 1-3, the “alt” block 120 indicates an if... else condition in the message sequence, showing one of the two alternative flows getting executed conditionally. The steps in block 130 are performed if the Femto supports only closed access (otherwise, for a Femto that does not support closed access, the block is not performed, and the operations that would be performed are not shown).
[0057] Step 4: The AMF 99-1 checks if the Femto supports only closed access mode. Subsequent CAG verification (Steps 5-8) is performed only for closed access mode.
[0058] Step 5: In this step (CAC GET REQUEST), the AMF 99-1 requests UDM/UDR to provide the allowed CAG list for the UE, by providing the SUCI or Subscription Permanent Identifier (SUPI). The 5G SUPI can be either: (1) An International Mobile Subscriber Identity (IMSI); or A Network Access Identifier (NAI). A SUCI allows the SUPI to be signaled without exposing the identity of the user. In particular, the SUCI uses a protection scheme that is used to encrypt the SUPI prior to including within a message. In particular, the IMSI may be encrypted when used as part of a SUCI.
[0059] Step 6: In this step (Get Allowed CAG list), the UDM 199-2 retrieves (e.g., from the UDR 199-3) an allowed CAG list for that UE 10. See also block 180: 180: UDM retrieves list by accessing the UDR.
[0060] Step 7: The UDM 199-2 responds (via a CAC_GET_RESPONSE) to the AMF with allowed CAG list for that UE.
[0061] Step 8: The AMF 99-1 checks (via a CAG verification) if the CAG ID received in Step 3 is in the allowed CAG list. [0062] Step 9: IF the CAG verification in Step 8 succeeds, the AMF 99-1 (along with the UE 10, 5G NR Femto 70, 5G NR Femto gateway) participates in one or more processes that include subsequent steps of continuing with UE Authentication, NAS Security Mode and Access Stratum (AS) security context establishment are followed as per legacy procedures. These processes provide the UE with access to the CAG for the Femto 70. The UE authentication process starts with “RRC Connection setup complete + NAS registration request” sent from the UE in Step 2. The UE authentication process ends with NAS Registration accept in a successful scenario.
[0063] Step 10: IF the CAG verification fails in Step 8, the AMF 99-1 sends a NAS Registration Reject to the UE 10 with reject cause as Unauthorized CAG access (see 3GPP TS 24.501 clause 9.11.3.2). This is illustrated by block 190: CAG verification not successful, e.g., CAG verification fails (failure). In other words, the CAG verification has failed.
[0064] Turning to FIG. 1A, this figure shows the signaling diagram of FIG. 1, and is used to help visualize where parameters from Step 4 are used. It is noted that the Femto 70 supports closed access so that block 130 is performed (the case when the Femto 70 does not support closed access is not addressed herein). As indicated by path 121, the SUCI of the UL NAS Transport message is used at least in Step 5. As indicated by paths 122 and 123, the cell access mode and the HgNB ID, respectively, are used at least in Step 4. Step 4 in FIG. 1 A also indicates that the check if the 5G NR Femto supports only closed access is performed based on the HgNB ID corresponding to the 5G NR Femto, and the support of the closed access being determined by the cell access mode parameter. As indicated by path 124, the CAG ID is used at least in Step 8. FIG. 1A also clarifies that Step 8 performs CAG verification at least by comparing the CAG ID parameter from Step 3 to items in the allowed CAG list and a verification is successful based on the CAG ID corresponding to (e.g., being in) an entry in the allowed CAG list.
[0065] Referring to FIG. 2, this figure is a signaling diagram of an embodiment, Embodiment 2: CAG verification after UE authentication procedure. FIG. 2 illustrates the message flow for Embodiment 2.
[0066] In this embodiment, the UE authentication procedure is completed as per legacy procedures in Step 4. [0067] Steps 5 - 11 : Same as steps 4-10 in Embodiment 1.
[0068] FIG. 3 is a signaling diagram of an embodiment, Embodiment 3: CAG verification during UE Authentication procedure. FIG. 3 illustrates the message flow for embodiment 3, and in this example, the home network 100 has core network functions of the AUSF 199-1 and the UDM199-2/UDR 199-3. The UDM 199-2 can access the UDR 199-3 or have a direct interface to query the UDR 1993 (and this applies to FIGS. 1 and 2 also). In this figure, for clarity of logical functionality, the AUSF is shown split from the UDM/UDR, because the AUSF is supposed to perform the authentication.
[0069] Step 4: The AMF checks if the Femto supports only closed access mode. Subsequent CAG verification (Steps 5-10) is performed only for closed access mode.
[0070] Step 5: The AMF sends an Authentication Request to the AUSF 199-1, including Cell Access Mode, along with SUCI or SUPI and SN-Name (serving network name for the serving network in which the AMF resides).
[0071] Step 6: The AUSF 199-1 Challenges the AMF for CAG verification using a new CAG Verification Challenge message. This challenge continues until step 11 (success) or step 13 (failure).
[0072] Step 7: The AMF requests the UDM to provide the allowed CAG list for that UE, using new CAG GET REQUEST message including SUCI or SUPI.
[0073] Step 8: UDM retrieves (from UDR) allowed CAG list.
[0074] Step 9: UDM responds to AMF with CAG GET RESPONSE message including allowed CAG list for that UE.
[0075] Step 10: AMF performs an access control check by comparing a CAG ID received in Step 3 and allowed CAG list received in Step 9.
[0076] Step 11 : AMF sends new message CAG CHALLENGE RESPONSE with the parameter of Success (for the CAG verification challenge started in step 6) to the AUSF 199-1, if the check in Step 10 succeeds.
[0077] Step 12: If the check in step 10 succeeded, the next signaling involves proceeding with UE Authentication and NAS Security context establishment as defined in 3GPP TS 23.502 clause 4.2.2.2.2. [0078] Step 13: If the check in step 10 failed, AMF sends a new CAG CHALLEGE RESPONSE message with a parameter of failure (for the CAG verification challenge started in step 6) to the AUSF 199-1.
[0079] Step 14: The AUSF 199-1 sends and authentication response to AMF with failure cause parameter listed as Unauthorized CAG access.
[0080] Step 15: The AMF sends NAS Registration Reject to UE with reject cause as Unauthorized CAG access (see 3GPP TS 24.501 clause 9.11.3.2).
[0081] FIG. 4 is a table of information elements (IES) in an Uplink NAS Transport message, including some that are applicable to the examples. Below illustrates an example of the updates required in 3 GPP TS 38.413 clause 9.2.5.3 for UL NAS transport message which is shown in step 3 in all above embodiments. This is merely exemplary, and other techniques may be used. Clause 9.2.5.3 is UPLINK NAS TRANSPORT. This message is sent by the NG-RAN node and is used for carrying NAS information over the NG interface. The direction is from the NG-RAN node (e.g., the 5G NR Femto 70) to the AMF. The TS provides a generic structure for UPLINK NAS TRANSPORT with optional IEs specifically for Femtocells.
[0082] In FIG. 4, the cell access mode 410 is an lE/group name, with an optional (O) presence; no indicated range; an ENUM for IE type and reference, where closed = 0, open = 1, and hybrid = 2; no indicated semantics description; criticality is indicated as yes, and assigned criticality is indicated as ignore. The CAG ID 420 is an lE/group name, with an optional (O) presence; no indicated range; a 32-bit integer for IE type and reference; no indicated semantics description; criticality is indicated as yes, and assigned criticality is indicated as ignore. The HgNB ID 430 is an lE/group name, with an optional (O) presence; no indicated range; a 32-bit integer for IE type and reference; no indicated semantics description; criticality is indicated as yes, and assigned criticality is indicated as ignore.
[0083] Turning to FIG. 5, this figure shows a block diagram of one possible and non-limiting example of a system into which the examples can be implemented. The system 500 shows the entities from the other figures: UE 10; entities of the serving network 1: 5G NR femtocell (Femto) 70; 5GNR Femto gateway 110; AMF 99-1; SEAF 99-2; entities of the home network 100: AUSF 199-1; UDM 199-2; UDR 199-3. [0084] A UE 10 is a wireless communication device, such as a mobile device, that is configured to access a cellular network. The Femto 70 provides access by the UE 10 to the serving network 1. The 5G NR Femto gateway 110, which may be optional in some examples, enables communication between the Femto 70 and the serving network 1 (e.g., the AMF 99-1 in these examples).
[0085] The apparatus 510 may be used to implement the UE 10, Femto 70, or gateway 110. The apparatus 510 is illustrated as having one or more antennas 58 that communicate over a wireless interface 11. The apparatus 510 includes one or more processors 73, one or more memories 75, and other circuitry 76. The other circuitry 76 includes one or more receivers (Rx(s)) 77 and one or more transmitters (Tx(s)) 78. Instructions 72 are used to cause the base station 70 to perform the operations described herein. The instructions 72 may be implemented via program(s) stored in memory/memories 75 and executed by processor(s) 73, or by circuitry such being implemented as part of the processor(s) or other hardware elements, or both. The apparatus 510 may communicate over wired connection 79. The receivers 77 and transmitters 78 may be wired or wireless or include both wired and wireless options. The wired versions may include wired technologies such as Ethernet, or optical technologies, as examples.
[0086] The cellular networks 1 and 100 may each include a (e.g., different) core network 90 that includes core network functionality, and which may provide connectivity via a link or links 81 with a data network 91, such as a telephone network and/or a data communications network (e.g., the Internet). The core network 90 includes one or more processors 93, one or more memories 95, and other circuitry 96. The other circuitry 96 includes one or more receivers (Rx(s)) 97 and one or more transmitters (Tx(s)) 98. Instructions 92 are used to cause the core network 90 to perform the operations described herein. Instructions 92 may be implemented via program(s) stored in memory/memories 95 and executed by processor(s) 93, or by circuitry such being implemented as part of the processor(s) or other hardware elements, or both. Core network 90 can communicate over interface(s) 71 with other elements in the serving network 1, such as the Femto gateway 110 (e.g., or in some cases, the Femto 70), along with other nodes such as gNBs or other RAN nodes [0087] The core network 90 could be a 5G core network (5GC ). The core network 90 can implement or comprise multiple network functions (NF(s)) 99/199, and the program 92 may comprise one or more of the network functions (NFs) 99/199. A 5G core network may use circuitry such as memory and processors and a virtualization layer. It could be a single standalone computing system, a distributed computing system, or a cloud computing system. The NFs 99/199, as network elements, of the core network could be containers or virtual machines running on the hardware of the computing system(s) making up the core network 90.
[0088] Core network functionality for 5G may include access and mobility management functionality that is provided by a network function 99/199 such as an access and mobility management function (AMF) 99-1, the SEAF 99-2, the AUSF 199-1, or UDM (Unified Data Management) 199-2/UDR (Unified Data Repository) 199-3. These are merely exemplary core network functionality that may be provided by the core network 90, and note that both 5G and LTE core network functionality might be provided by the core network 90.
[0089] Block 2 illustrates that the core network 90 has a set of resources including 92, 93, 95, and 96. The individual NFs 99/199, such as the AMF 99-1, the SEAF 99-2, the AUSF 199-1, the UDM 199-2, or the UDR 199-3, can be implemented via a corresponding subset 2’ of resources comprising 92-x, 93-x, and 95-x, where “x” indicates that different subsets of resources can be used for different NFs 99/199. It may be possible for the same subset of resources to be used for multiple NFs 99/199, such as one subset of resources being used for AMF 99-1 and SEAF 99-2. Regardless of how the individual NFs 99/199 are implemented, such as (see reference 5) via a virtualization machine, VM, (e.g., a virtualization layer), a container, or cloud-native architecture, these are implemented via the subset 2’ of resources. That is, the NFs 99/199 such as the access and mobility management function (AMF) 99-1 are implemented via circuitry like the processors 93-x and memories 95-x, and the instructions 92-x. Specifically, the one or more memories 95-x store instructions 92-x of the AMF 99-1, wherein the instructions 92-x when executed by one or more processors 93-x cause an apparatus (e.g., core network 90 or a part of it) to perform operations as described herein.
[0090] The receivers 77 and 97, and the transmitters 78 and 98 may implement wired or wireless interfaces. The receivers and transmitters may be grouped together as transceivers. [0091] In the data network 91, there is a computer-readable medium 94. The computer-readable medium 94 contains instructions that, when downloaded and installed into the memories 75 or 95 of the corresponding apparatus 510 and/or core network element(s) 90, and executed by processor(s) 73 or 93, cause the respective device to perform corresponding actions described herein. The computer-readable medium 94 may be implemented in other forms, such as via a compact disc or memory stick.
[0092] The instructions 72 and 92 may be stored by corresponding one or more memories 75 or 95. These instructions, when executed by the corresponding one or more processors 73 or 93, cause the corresponding apparatus 510 or 90 to perform the operations described herein. The computer readable memories 75 or 95 are circuitry and may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor-based memory devices, flash memory, firmware, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The processors 73 and 93, are circuitry and may be of any type suitable to the local technical environment. For example, these processors may include one or more of general-purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), processors based on a multi-core processor architecture, and may also include specialized circuits such as field-programmable gate arrays (FPGAs), application specific circuits (ASICs), signal processing devices and other devices, or combinations of these devices, as non-limiting examples. The processors 73 and 93 (including any subset processor(s) 93 -x) are circuitry that can be programmed to perform functions via software, firmware or the like (including microcode), but are not solely software.
[0093] The cellular network 1 may implement network virtualization, which is the process of combining circuitry and software network resources and network functionality into a single, software-based administrative entity, a virtual network. Network virtualization involves platform virtualization, often combined with resource virtualization. Network virtualization is categorized as either external, combining many networks, or parts of networks, into a virtual unit, or internal, providing network-like functionality to software containers on a single system. Note that the virtualized entities (such as network functions 99/199) that result from the network virtualization are still implemented, at some level, using circuitry such as processors 73 and/or 93 and memories 75 and/or 95, and also such virtualized entities create technical effects.
[0094] Without in any way limiting the scope, interpretation, or application of the claims appearing below, a technical effect and/or advantage of one or more of the example embodiments disclosed herein includes optimization of signaling flow because CAG verification happens at an early stage, and UE authentication, NAS security context, AS security context establishment signaling can be avoided if UE is not a member of a CAG list. Another technical effect and/or advantage of one or more of the example embodiments disclosed herein is that the functionality of UE access control is also achieved.
[0095] The following are additional examples.
[0096] Example 1. A method, comprising: based on a femtocell in a serving network supporting closed access, performing by an access and mobility management function in the serving network for a user equipment signaling comprising: sending, to a unified data management in a home network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; receiving, from the unified data management, the list of closed access groups the user equipment is allowed to access; and performing, by the access and mobility management function, verification of whether a provided closed access group identification is in the list of closed access groups the user equipment is allowed to access; and performing one of the following: based on the verification being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell; or based on the verification not being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell.
[0097] Example 2. The method according to example 1, further comprising: receiving, at an access and mobility management function in the serving network for a user equipment, an indication of cell access mode and an identifier for the femtocell; determining, by the access and mobility management function using the identifier for the femtocell, the femtocell; and determining, by the access and mobility management function using the indicated cell access mode, that the femtocell supports closed access.
[0098] Example 3. The method according to example 2, wherein the identifier for the femtocell comprises an HgNB identification.
[0099] Example 4. The method according to example 2 or 3, wherein determining, by the access and mobility management function using the indicated cell access mode, that the femtocell supports only closed access.
[00100] Example 5. The method according to any of examples 1 to 4, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell; and participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
[00101] Example 6. The method according to example 1 or 2, further comprising: prior to sending, to the unified data management in the home network for the user equipment, the request comprising the identifier for the user equipment, participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell.
[00102] Example 7. The method according to example 6, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
[00103] Example 8. The method according to example 1 or 2, further comprising, prior to sending, to the unified data management in the home network for the user equipment, the request comprising the identifier for the user equipment: sending, by the access and 1 mobility management function to an authentication server function in the home network, an authentication request with an identifier of the user equipment, a network name indicating the serving network, and indication of a cell access mode; and receiving, by the access and mobility management function from the authentication server function, a closed access group verification challenge.
[00104] Example 9. The method according to example 8, further comprising: based on the verification being successful, sending by the access and mobility management function to the authentication server function a closed access group challenge response message indicating success.
[00105] Example 10. The method according to example 9, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell; and participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
[00106] Example 11. The method according to example 8, wherein the verification was a failure, and the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to an authentication server function, a message indicating there was a closed access group challenge failure; and receiving, by the access and mobility management function from the authentication server function, an authentication response indicating a failure due to unauthorized closed access group access.
[00107] Example 12. The method according to example 11, wherein the verification was a failure, and the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to the user equipment, a rejection with a cause of closed access group verification failure. [00108] Example 13. The method according to any of examples 1 to 4, 6, and 8 wherein the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to the user equipment, a rejection with a cause of unauthorized closed access group access.
[00109] Example 14. The method according to any of examples 1 to 13, wherein the femtocell communicates with the access and mobility management function of the serving network via a femto gateway.
[00110] Example 15. A method, comprising: receiving, by a unified data management in a home network for a user equipment and from an access and mobility management function in a serving network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access; and sending, by the unified data management to the access and mobility management function, the list of closed access groups the user equipment is allowed to access.
[00111] Example 16. The method according to example 15, wherein the retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access comprises retrieving by the unified data management the list of closed access groups the user equipment is allowed to access from a database.
[00112] Example 17. A method, comprising: responsive to a user equipment sending a radio resource control connection complete message with non-access stratum registration request to a serving network for the user equipment, sending by a femtocell toward the serving network a message including an indicator for a cell access mode for the femtocell, a closed access group identification, and an identifier of the femtocell by the femtocell.
[00113] Example 18. The method according to example 17, wherein: the method further comprises, prior to sending the message: establishing, by a femtocell with a user equipment, a radio resource control connection; and receiving, by the femtocell from the user equipment, a non-access stratum registration request; the message is sent toward an access and mobility management function in the serving network. [00114] Example 19. The method according to example 17 or 18, wherein: the radio resource control connection complete message with non-access stratum registration request requests the user equipment to be provided with access to a closed access group corresponding to the closed access group identification for the femtocell that is indicated by the identifier; and the method further comprises participating, by the femtocell, in one or more additional processes to provide the user equipment with access to the closed access group for the femtocell.
[00115] Example 20. An apparatus, comprising means for: based on a femtocell in a serving network supporting closed access, performing by an access and mobility management function in the serving network for a user equipment signaling comprising: sending, to a unified data management in a home network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; receiving, from the unified data management, the list of closed access groups the user equipment is allowed to access; and performing, by the access and mobility management function, verification of whether a provided closed access group identification is in the list of closed access groups the user equipment is allowed to access; and performing one of the following: based on the verification being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell; or based on the verification not being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell.
[00116] Example 21. The apparatus according to example 20, wherein the means are further configured for: receiving, at an access and mobility management function in the serving network for a user equipment, an indication of cell access mode and an identifier for the femtocell; determining, by the access and mobility management function using the identifier for the femtocell, the femtocell; and determining, by the access and mobility management function using the indicated cell access mode, that the femtocell supports closed access.
[00117] Example 22. The apparatus according to example 21, wherein the identifier for the femtocell comprises an HgNB identification.
[00118] Example 23. The apparatus according to example 21 or 22, wherein determining, by the access and mobility management function using the indicated cell access mode, that the femtocell supports only closed access.
[00119] Example 24. The apparatus according to any of examples 20 to 23, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell; and participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
[00120] Example 25. The apparatus according to example 20 or 21, wherein the means are further configured for: prior to sending, to the unified data management in the home network for the user equipment, the request comprising the identifier for the user equipment, participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell.
[00121] Example 26. The apparatus according to example 25, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
[00122] Example 27. The apparatus according to example 20 or 21, wherein the means are further configured for, prior to sending, to the unified data management in the home network for the user equipment, the request comprising the identifier for the user equipment: sending, by the access and mobility management function to an authentication server function in the home network, an authentication request with an identifier of the user equipment, a network name indicating the serving network, and indication of a cell access mode; and receiving, by the access and mobility management function from the authentication server function, a closed access group verification challenge.
[00123] Example 28. The apparatus according to example 27, wherein the means are further configured for: based on the verification being successful, sending by the access and mobility management function to the authentication server function a closed access group challenge response message indicating success.
[00124] Example 29. The apparatus according to example 28, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell; and participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
[00125] Example 30. The apparatus according to example 27, wherein the verification was a failure, and the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to an authentication server function, a message indicating there was a closed access group challenge failure; and receiving, by the access and mobility management function from the authentication server function, an authentication response indicating a failure due to unauthorized closed access group access.
[00126] Example 31. The apparatus according to example 30, wherein the verification was a failure, and the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to the user equipment, a rejection with a cause of closed access group verification failure.
[00127] Example 32. The apparatus according to any of examples 20 to 23, 25, and 27 wherein the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to the user equipment, a rejection with a cause of unauthorized closed access group access.
[00128] Example 33. The apparatus according to any of examples 20 to 32, wherein the femtocell communicates with the access and mobility management function of the serving network via a femto gateway.
[00129] Example 34. An apparatus, comprising means for: receiving, by a unified data management in a home network for a user equipment and from an access and mobility management function in a serving network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access; and sending, by the unified data management to the access and mobility management function, the list of closed access groups the user equipment is allowed to access.
[00130] Example 35. The apparatus according to example 34, wherein the retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access comprises retrieving by the unified data management the list of closed access groups the user equipment is allowed to access from a database.
[00131] Example 36. An apparatus, comprising means for: responsive to a user equipment sending a radio resource control connection complete message with non-access stratum registration request to a serving network for the user equipment, sending by a femtocell toward the serving network a message including an indicator for a cell access mode for the femtocell, a closed access group identification, and an identifier of the femtocell by the femtocell.
[00132] Example 37. The apparatus according to example 36, wherein: the means are further configured for, prior to sending the message: establishing, by a femtocell with a user equipment, a radio resource control connection; and receiving, by the femtocell from the user equipment, a non-access stratum registration request; the message is sent toward an access and mobility management function in the serving network.
[00133] Example 38. The apparatus according to example 36 or 37, wherein: the radio resource control connection complete message with non-access stratum registration request requests the user equipment to be provided with access to a closed access group corresponding to the closed access group identification for the femtocell that is indicated by the identifier; and the means are further configured for participating, by the femtocell, in one or more additional processes to provide the user equipment with access to the closed access group for the femtocell.
[00134] Example 39. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: based on a femtocell in a serving network supporting closed access, performing by an access and mobility management function in the serving network for a user equipment signaling comprising: sending, to a unified data management in a home network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; receiving, from the unified data management, the list of closed access groups the user equipment is allowed to access; and performing, by the access and mobility management function, verification of whether a provided closed access group identification is in the list of closed access groups the user equipment is allowed to access; and performing one of the following: based on the verification being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell; or based on the verification not being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell.
[00135] Example 40. The apparatus according to example 39, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, at an access and mobility management function in a serving network for a user equipment, an indication of cell access mode and an identifier for the femtocell; determining, by the access and mobility management function using the identifier for the femtocell, the femtocell; and determining, by the access and mobility management function using the indicated cell access mode, that the femtocell supports closed access.
[00136] Example 41. The apparatus according to example 40, wherein the identifier for the femtocell comprises an HgNB identification.
[00137] Example 42. The apparatus according to example 40 or 41, wherein determining, by the access and mobility management function using the indicated cell access mode, that the femtocell supports only closed access.
[00138] Example 43. The apparatus according to any of examples 39 to 42, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell; and participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
[00139] Example 44. The apparatus according to example 39 or 40, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform: prior to sending, to the unified data management in the home network for the user equipment, the request comprising the identifier for the user equipment, participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell.
[00140] Example 45. The apparatus according to example 44, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
[00141] Example 46. The apparatus according to example 39 or 40, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform, prior to sending, to the unified data management in the home network for the user equipment, the request comprising the identifier for the user equipment: sending, by the access and mobility management function to an authentication server function in the home network, an authentication request with an identifier of the user equipment, a network name indicating the serving network, and indication of a cell access mode; and receiving, by the access and mobility management function from the authentication server function, a closed access group verification challenge.
[00142] Example 47. The apparatus according to example 46, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform: based on the verification being successful, sending by the access and mobility management function to the authentication server function a closed access group challenge response message indicating success.
[00143] Example 48. The apparatus according to example 47, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell; and participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
[00144] Example 49. The apparatus according to example 46, wherein the verification was a failure, and the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to an authentication server function, a message indicating there was a closed access group challenge failure; and receiving, by the access and mobility management function from the authentication server function, an authentication response indicating a failure due to unauthorized closed access group access.
[00145] Example 50. The apparatus according to example 49, wherein the verification was a failure, and the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to the user equipment, a rejection with a cause of closed access group verification failure.
[00146] Example 51. The apparatus according to any of examples 39 to 42, 44, and 46 wherein the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to the user equipment, a rejection with a cause of unauthorized closed access group access.
[00147] Example 52. The apparatus according to any of examples 39 to 51, wherein the femtocell communicates with the access and mobility management function of the serving network via a femto gateway.
[00148] Example 53. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, by a unified data management in a home network for a user equipment and from an access and mobility management function in a serving network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access; and sending, by the unified data management to the access and mobility management function, the list of closed access groups the user equipment is allowed to access.
[00149] Example 54. The apparatus according to example 53, wherein the retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access comprises retrieving by the unified data management the list of closed access groups the user equipment is allowed to access from a database.
[00150] Example 55. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: responsive to a user equipment sending a radio resource control connection complete message with non-access stratum registration request to a serving network for the user equipment, sending by a femtocell toward the serving network a message including an indicator for a cell access mode for the femtocell, a closed access group identification, and an identifier of the femtocell by the femtocell. [00151] Example 56. The apparatus according to example 55, wherein: the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform, prior to sending the message: establishing, by a femtocell with a user equipment, a radio resource control connection; and receiving, by the femtocell from the user equipment, a non-access stratum registration request; the message is sent toward an access and mobility management function in the serving network.
[00152] Example 57. The apparatus according to example 55 or 56, wherein: the radio resource control connection complete message with non-access stratum registration request requests the user equipment to be provided with access to a closed access group corresponding to the closed access group identification for the femtocell that is indicated by the identifier; and the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform participating, by the femtocell, in one or more additional processes to provide the user equipment with access to the closed access group for the femtocell.
[00153] Example 58. A computer program, comprising instructions which, when the program is executed by an apparatus, cause the apparatus to carry out the methods of any of examples 1 to 19.
[00154] Example 59. The computer program according to example 58, wherein the computer program is a computer program product comprising a computer-readable medium bearing the instructions embodied therein for use with the apparatus.
[00155] Example 60. The computer program according to example 58, wherein the computer program is directly loadable into an internal memory of the apparatus.
[00156] Example 61. A system, comprising: an apparatus according to any of examples 20 to 33; an apparatus according to examples 34 or 35; and an apparatus according to any of examples 36 to 38.
[00157] As used in this application, the term “circuitry” may refer to one or more or all of the following:
[00158] (a) hardware-only circuit implementations (such as implementations in only analog and/or digital circuitry) and
[00159] (b) combinations of hardware circuits and software, such as (as applicable):
(i) a combination of analog and/or digital hardware circuit(s) with software/firmware and (ii) any portions of hardware processor(s) (including digital signal processor(s)) with software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and
[00160] (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[00161] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and/or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[00162] Embodiments herein may be implemented in software (executed by one or more processors), hardware (e.g., an application specific integrated circuit), or a combination of software and hardware. In an example embodiment, the software (e.g., application logic, an instruction set) is maintained on any one of various conventional computer-readable media. In the context of this document, a “computer-readable medium” may be any media or means that can contain, store, communicate, propagate or transport the instructions for use by or in connection with an instruction execution system, apparatus, or device, such as a computer, with one example of a computer described and depicted, e.g., in FIG. 5. A computer-readable medium may comprise a computer-readable storage medium (e.g., memories 75 and 95 or other device) that may be any media or means that can contain, store, and/or transport the instructions for use by or in connection with an instruction execution system, apparatus, or device, such as a computer. A computer-readable storage medium does not comprise propagating signals, and therefore may be considered to be non-transitory. The term “non- transitory”, as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM, random access memory, versus ROM, read-only memory). [00163] If desired, the different functions discussed herein may be performed in a different order and/or concurrently with each other. Furthermore, if desired, one or more of the above-described functions may be optional or may be combined.
[00164] Although various aspects of the invention are set out in the independent claims, other aspects of the invention comprise other combinations of features from the described embodiments and/or the dependent claims with the features of the independent claims, and not solely the combinations explicitly set out in the claims.
[00165] It is also noted herein that while the above describes example embodiments of the invention, these descriptions should not be viewed in a limiting sense. Rather, there are several variations and modifications which may be made without departing from the scope of the present invention as defined in the appended claims.
[00166] The following abbreviations that may be found in the specification and/or the drawing figures are defined as follows:
[00167] 3GPP third generation partnership project
[00168] 4G fourth generation
[00169] 5G fifth generation
[00170] 5G-GUTI 5G Globally Unique Temporary Identifier
[00171] AMF access and mobility management function
[00172] AS Access Stratum
[00173] AUSF authentication server function
[00174] CAG closed access group
[00175] CSG closed subscriber group
[00176] CSS CSG Subscriber Server
[00177] eNB (or eNodeB) evolved Node B (e.g., an LTE base station)
[00178] GPRS General Packet Radio Service
[00179] gNB (or gNodeB) base station for 5G/NR
[00180] HeNB home eNB (or eNodeB)
[00181] HgNB home gNB (or gNodeB)
[00182] HPLMN home PLMN [00183] ID or Id identification
[00184] IMSI International Mobile Subscriber Identity
[00185] IP Internet protocol
[00186] LTE long term evolution
[00187] MME mobility management entity
[00188] NAS non-access stratum
[00189] NF network function
[00190] ng or NG next generation
[00191] NR new radio
[00192] NRF Network Repository Function
[00193] PLMN public land mobile network
[00194] PNI-NPN Public network integrated non-public network
[00195] RAN radio access network
[00196] Rel or Rel. release
[00197] RRC radio resource control
[00198] Rx receiver
[00199] SA3 3GPP Technical Specification Group Service and System Aspects (TSG SA), working group 3
[00200] SEAF security anchor function
[00201] SGSN Serving GPRS Support Node
[00202] SGW serving gateway
[00203] SUCI Subscription Concealed Identifier
[00204] SUPI Subscription Permanent Identifier
[00205] TSG Technical Specification Group
[00206] Tx transmitter
[00207] UDM unified data management
[00208] UDR unified data repository
[00209] UE user equipment (e.g., a wireless, typically mobile device) [00210] UL uplink (from UE to network)
[00211] USIM Universal Subscriber Identity Module
[00212] UTRAN Universal Terrestrial Radio Access Network
[00213] VLR Visitor Location Register [00214] VPLMN visiting PLMN

Claims

What is claimed is:
1. A method, comprising: based on a femtocell in a serving network supporting closed access, performing by an access and mobility management function in the serving network for a user equipment signaling comprising: sending, to a unified data management in a home network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; receiving, from the unified data management, the list of closed access groups the user equipment is allowed to access; and performing, by the access and mobility management function, verification of whether a provided closed access group identification is in the list of closed access groups the user equipment is allowed to access; and performing one of the following: based on the verification being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell; or based on the verification not being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell.
2. The method according to claim 1, further comprising: receiving, at an access and mobility management function in the serving network for a user equipment, an indication of cell access mode and an identifier for the femtocell; determining, by the access and mobility management function using the identifier for the femtocell, the femtocell; and determining, by the access and mobility management function using the indicated cell access mode, that the femtocell supports closed access.
3. The method according to claim 2, wherein the identifier for the femtocell comprises an HgNB identification.
4. The method according to claim 2 or 3, wherein determining, by the access and mobility management function using the indicated cell access mode, that the femtocell supports only closed access.
5. The method according to any of claims 1 to 4, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell; and participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
6. The method according to claim 1 or 2, further comprising: prior to sending, to the unified data management in the home network for the user equipment, the request comprising the identifier for the user equipment, participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell.
7. The method according to claim 6, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
8. The method according to claim 1 or 2, further comprising, prior to sending, to the unified data management in the home network for the user equipment, the request comprising the identifier for the user equipment: sending, by the access and mobility management function to an authentication server function in the home network, an authentication request with an identifier of the user equipment, a network name indicating the serving network, and indication of a cell access mode; and receiving, by the access and mobility management function from the authentication server function, a closed access group verification challenge.
9. The method according to claim 8, further comprising: based on the verification being successful, sending by the access and mobility management function to the authentication server function a closed access group challenge response message indicating success.
10. The method according to claim 9, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell; and participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
11. The method according to claim 8, wherein the verification was a failure, and the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to an authentication server function, a message indicating there was a closed access group challenge failure; and receiving, by the access and mobility management function from the authentication server function, an authentication response indicating a failure due to unauthorized closed access group access.
12. The method according to claim 11, wherein the verification was a failure, and the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to the user equipment, a rejection with a cause of closed access group verification failure.
13. The method according to any of claims 1 to 4, 6, and 8 wherein the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to the user equipment, a rejection with a cause of unauthorized closed access group access.
14. The method according to any of claims 1 to 13, wherein the femtocell communicates with the access and mobility management function of the serving network via a femto gateway.
15. A method, comprising: receiving, by a unified data management in a home network for a user equipment and from an access and mobility management function in a serving network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access; and sending, by the unified data management to the access and mobility management function, the list of closed access groups the user equipment is allowed to access.
16. The method according to claim 15, wherein the retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access comprises retrieving by the unified data management the list of closed access groups the user equipment is allowed to access from a database.
17. A method, comprising: responsive to a user equipment sending a radio resource control connection complete message with non-access stratum registration request to a serving network for the user equipment, sending by a femtocell toward the serving network a message including an indicator for a cell access mode for the femtocell, a closed access group identification, and an identifier of the femtocell by the femtocell.
18. The method according to claim 17, wherein: the method further comprises, prior to sending the message: establishing, by a femtocell with a user equipment, a radio resource control connection; and receiving, by the femtocell from the user equipment, a non-access stratum registration request; the message is sent toward an access and mobility management function in the serving network.
19. The method according to claim 17 or 18, wherein: the radio resource control connection complete message with non-access stratum registration request requests the user equipment to be provided with access to a closed access group corresponding to the closed access group identification for the femtocell that is indicated by the identifier; and the method further comprises participating, by the femtocell, in one or more additional processes to provide the user equipment with access to the closed access group for the femtocell.
20. An apparatus, comprising means for: based on a femtocell in a serving network supporting closed access, performing by an access and mobility management function in the serving network for a user equipment signaling comprising: sending, to a unified data management in a home network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; receiving, from the unified data management, the list of closed access groups the user equipment is allowed to access; and performing, by the access and mobility management function, verification of whether a provided closed access group identification is in the list of closed access groups the user equipment is allowed to access; and performing one of the following: based on the verification being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell; or based on the verification not being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell.
21. The apparatus according to claim 20, wherein the means are further configured for: receiving, at an access and mobility management function in the serving network for a user equipment, an indication of cell access mode and an identifier for the femtocell; determining, by the access and mobility management function using the identifier for the femtocell, the femtocell; and determining, by the access and mobility management function using the indicated cell access mode, that the femtocell supports closed access.
22. The apparatus according to claim 21, wherein the identifier for the femtocell comprises an HgNB identification.
23. The apparatus according to claim 21 or 22, wherein determining, by the access and mobility management function using the indicated cell access mode, that the femtocell supports only closed access.
24. The apparatus according to any of claims 20 to 23, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell; and participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
25. The apparatus according to claim 20 or 21, wherein the means are further configured for: prior to sending, to the unified data management in the home network for the user equipment, the request comprising the identifier for the user equipment, participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell.
26. The apparatus according to claim 25, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
27. The apparatus according to claim 20 or 21, wherein the means are further configured for, prior to sending, to the unified data management in the home network for the user equipment, the request comprising the identifier for the user equipment: sending, by the access and mobility management function to an authentication server function in the home network, an authentication request with an identifier of the user equipment, a network name indicating the serving network, and indication of a cell access mode; and receiving, by the access and mobility management function from the authentication server function, a closed access group verification challenge.
28. The apparatus according to claim 27, wherein the means are further configured for: based on the verification being successful, sending by the access and mobility management function to the authentication server function a closed access group challenge response message indicating success.
29. The apparatus according to claim 28, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell; and participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
30. The apparatus according to claim 27, wherein the verification was a failure, and the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to an authentication server function, a message indicating there was a closed access group challenge failure; and receiving, by the access and mobility management function from the authentication server function, an authentication response indicating a failure due to unauthorized closed access group access.
31. The apparatus according to claim 30, wherein the verification was a failure, and the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to the user equipment, a rejection with a cause of closed access group verification failure.
32. The apparatus according to any of claims 20 to 23, 25, and 27 wherein the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to the user equipment, a rejection with a cause of unauthorized closed access group access.
33. The apparatus according to any of claims 20 to 32, wherein the femtocell communicates with the access and mobility management function of the serving network via a femto gateway.
34. An apparatus, comprising means for: receiving, by a unified data management in a home network for a user equipment and from an access and mobility management function in a serving network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access; and sending, by the unified data management to the access and mobility management function, the list of closed access groups the user equipment is allowed to access.
35. The apparatus according to claim 34, wherein the retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access comprises retrieving by the unified data management the list of closed access groups the user equipment is allowed to access from a database.
36. An apparatus, comprising means for: responsive to a user equipment sending a radio resource control connection complete message with non-access stratum registration request to a serving network for the user equipment, sending by a femtocell toward the serving network a message including an indicator for a cell access mode for the femtocell, a closed access group identification, and an identifier of the femtocell by the femtocell.
37. The apparatus according to claim 36, wherein: the means are further configured for, prior to sending the message: establishing, by a femtocell with a user equipment, a radio resource control connection; and receiving, by the femtocell from the user equipment, a non-access stratum registration request; the message is sent toward an access and mobility management function in the serving network.
38. The apparatus according to claim 36 or 37, wherein: the radio resource control connection complete message with non-access stratum registration request requests the user equipment to be provided with access to a closed access group corresponding to the closed access group identification for the femtocell that is indicated by the identifier; and the means are further configured for participating, by the femtocell, in one or more additional processes to provide the user equipment with access to the closed access group for the femtocell.
39. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: based on a femtocell in a serving network supporting closed access, performing by an access and mobility management function in the serving network for a user equipment signaling comprising: sending, to a unified data management in a home network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; receiving, from the unified data management, the list of closed access groups the user equipment is allowed to access; and performing, by the access and mobility management function, verification of whether a provided closed access group identification is in the list of closed access groups the user equipment is allowed to access; and performing one of the following: based on the verification being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell; or based on the verification not being successful that the provided closed access group identification is in the list of closed access groups the user equipment is allowed to access, participating by the access and mobility management function in one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell.
40. The apparatus according to claim 39, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, at an access and mobility management function in the serving network for a user equipment, an indication of cell access mode and an identifier for the femtocell; determining, by the access and mobility management function using the identifier for the femtocell, the femtocell; and determining, by the access and mobility management function using the indicated cell access mode, that the femtocell supports closed access.
41. The apparatus according to claim 40, wherein the identifier for the femtocell comprises an HgNB identification.
42. The apparatus according to claim 40 or 41, wherein determining, by the access and mobility management function using the indicated cell access mode, that the femtocell supports only closed access.
43. The apparatus according to any of claims 39 to 42, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell; and participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
44. The apparatus according to claim 39 or 40, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform: prior to sending, to the unified data management in the home network for the user equipment, the request comprising the identifier for the user equipment, participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell.
45. The apparatus according to claim 44, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
46. The apparatus according to claim 39 or 40, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform, prior to sending, to the unified data management in the home network for the user equipment, the request comprising the identifier for the user equipment: sending, by the access and mobility management function to an authentication server function in the home network, an authentication request with an identifier of the user equipment, a network name indicating the serving network, and indication of a cell access mode; and receiving, by the access and mobility management function from the authentication server function, a closed access group verification challenge.
47. The apparatus according to claim 46, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform: based on the verification being successful, sending by the access and mobility management function to the authentication server function a closed access group challenge response message indicating success.
48. The apparatus according to claim 47, wherein there was a successful verification, and the one or more additional processes to provide the user equipment with access to a closed access group corresponding to the provided closed access group identification for the femtocell comprise: participating by the access and mobility management function in an authentication process to authenticate the user equipment for access to the femtocell; and participating by the access and mobility management function in a non-access stratum security context establishment and an access stratum security context establishment to allow the user equipment to access the femtocell.
49. The apparatus according to claim 46, wherein the verification was a failure, and the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to an authentication server function, a message indicating there was a closed access group challenge failure; and receiving, by the access and mobility management function from the authentication server function, an authentication response indicating a failure due to unauthorized closed access group access.
50. The apparatus according to claim 49, wherein the verification was a failure, and the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to the user equipment, a rejection with a cause of closed access group verification failure.
51. The apparatus according to any of claims 39 to 42, 44, and 46 wherein the one or more additional processes to reject access by the user equipment to the closed access group corresponding to the provided closed access group identification for the femtocell comprise: sending, by the access and mobility management function to the user equipment, a rejection with a cause of unauthorized closed access group access.
52. The apparatus according to any of claims 39 to 51, wherein the femtocell communicates with the access and mobility management function of the serving network via a femto gateway.
53. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: receiving, by a unified data management in a home network for a user equipment and from an access and mobility management function in a serving network for the user equipment, a request comprising an identifier for the user equipment, the request for a list of closed access groups the user equipment is allowed to access; retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access; and sending, by the unified data management to the access and mobility management function, the list of closed access groups the user equipment is allowed to access.
54. The apparatus according to claim 53, wherein the retrieving, by the unified data management, the list of closed access groups the user equipment is allowed to access comprises retrieving by the unified data management the list of closed access groups the user equipment is allowed to access from a database.
55. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: responsive to a user equipment sending a radio resource control connection complete message with non-access stratum registration request to a serving network for the user equipment, sending by a femtocell toward the serving network a message including an indicator for a cell access mode for the femtocell, a closed access group identification, and an identifier of the femtocell by the femtocell.
56. The apparatus according to claim 55, wherein: the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform, prior to sending the message: establishing, by a femtocell with a user equipment, a radio resource control connection; and receiving, by the femtocell from the user equipment, a non-access stratum registration request; the message is sent toward an access and mobility management function in the serving network.
57. The apparatus according to claim 55 or 56, wherein: the radio resource control connection complete message with non-access stratum registration request requests the user equipment to be provided with access to a closed access group corresponding to the closed access group identification for the femtocell that is indicated by the identifier; and the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform participating, by the femtocell, in one or more additional processes to provide the user equipment with access to the closed access group for the femtocell.
58. A computer program, comprising instructions which, when the program is executed by an apparatus, cause the apparatus to carry out the methods of any of claims 1 to 19.
59. The computer program according to claim 58, wherein the computer program is a computer program product comprising a computer-readable medium bearing the instructions embodied therein for use with the apparatus.
60. The computer program according to claim 58, wherein the computer program is directly loadable into an internal memory of the apparatus.
61. A system, comprising: an apparatus according to any of claims 20 to 33; an apparatus according to claims 34 or 35; and an apparatus according to any of claims 36 to 38.
PCT/EP2025/061347 2024-05-13 2025-04-25 Cag verification for 5g nr femtocell Pending WO2025237653A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
IN202441037576 2024-05-13
IN202441037576 2024-05-13

Publications (1)

Publication Number Publication Date
WO2025237653A1 true WO2025237653A1 (en) 2025-11-20

Family

ID=95583470

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/EP2025/061347 Pending WO2025237653A1 (en) 2024-05-13 2025-04-25 Cag verification for 5g nr femtocell

Country Status (1)

Country Link
WO (1) WO2025237653A1 (en)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20210020696A (en) * 2019-08-16 2021-02-24 삼성전자주식회사 Apparatus and method for access control, protection and management in wireless communication system
US20220086705A1 (en) * 2019-03-29 2022-03-17 Samsung Electronics Co., Ltd. Method for supporting access to closed network, ue, base station and readable storage medium
US20230156566A1 (en) * 2020-04-03 2023-05-18 Samsung Electronics Co., Ltd. Method and apparatus for managing cag related procedure in wireless communication network

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20220086705A1 (en) * 2019-03-29 2022-03-17 Samsung Electronics Co., Ltd. Method for supporting access to closed network, ue, base station and readable storage medium
KR20210020696A (en) * 2019-08-16 2021-02-24 삼성전자주식회사 Apparatus and method for access control, protection and management in wireless communication system
US20230156566A1 (en) * 2020-04-03 2023-05-18 Samsung Electronics Co., Ltd. Method and apparatus for managing cag related procedure in wireless communication network

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
NTT DOCOMO, NEW SID: STUDY ON SYSTEM ASPECTS OF 5G NR FEMTO, TSG SA MEETING #102, 11 December 2023 (2023-12-11)

Similar Documents

Publication Publication Date Title
TWI482506B (en) Method and arrangement in a communication network
KR101385612B1 (en) Provisioning communication nodes
US8811987B2 (en) Method and arrangement for creation of association between user equipment and an access point
EP3769487B1 (en) Wireless communication network authentication
US12284604B2 (en) User equipment onboarding and network congestion control in standalone non-public network deployments
CN116491213A (en) Radio Access Network Connectivity Enhancements for Network Slicing
KR101489882B1 (en) Informing a user equipment of a cell and a radio base station serving the cell about access rights granted to the user equipment
CN101291249A (en) A method of configuring and displaying femtocell names, internal user group names
US20130157673A1 (en) Network operator-neutral provisioning of mobile devices
CN115412901B (en) On-device physical SIM to eSIM conversion
CN101626623A (en) User access control method
CN118803614A (en) Communication method and communication device
EP2742706B1 (en) Communication system
US20250063471A1 (en) Communication method and apparatus
WO2025208638A1 (en) Security solutions mitigating bidding-down attacks when decommissioning 2g/3g networks
US20260107139A1 (en) Authentication and Key Management for Applications (AKMA) for Roaming Scenarios
US20260032561A1 (en) Regulating non-cellular connectivity from external cellular subscribers
WO2026024798A1 (en) Support for roaming ues under disaster conditions
Wu et al. uLIPA: A universal local IP access solution for 3GPP mobile networks
WO2026032585A1 (en) Detection of malicious closed access group (cag) cells
WO2026032584A1 (en) Detection of malicious closed access group (cag) cells
WO2026032583A1 (en) Detection of malicious closed access group (cag) cells
WO2026092933A1 (en) Security management for local service access in femtocells
WO2026092934A1 (en) Security management for local service access in femtocells
KR101819201B1 (en) Method for providing service of internet protocol phone based mobile communication and mobile communication system

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 25722538

Country of ref document: EP

Kind code of ref document: A1