IP Library › Granted Patent US 12,739,625
Granted Patent B2
US 12,739,625 · App. 18/610,030 · Granted Sep 15, 2026

Method and apparatus to deliver multiple NAS containers via a single access stratum message

Inventors: Devaki Chandramouli (Plano, TX); Martin McGrath (Coppell, TX); Sung Hwan Won (Flower Mound, TX)
Assignee: NOKIA TECHNOLOGIES OY
H04W12/037H04W8/26
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,625
App. No.
18/610,030
Granted
Sep 15, 2026
Kind
B2
Abstract

A method includes receiving, at an AS layer of a user equipment (UE), a plurality of NAS payloads, wherein a first NAS payload is received from a first NAS sublayer and a subsequent payload is received from a subsequent NAS sublayer, encrypting, by the UE, the first payload with a first encryption generating a first encrypted payload and the subsequent payload with a subsequent encryption generating a subsequent encrypted payload, wherein the first encryption is associated with a first network function and the subsequent encryption is associated with a subsequent network function, generating, by the UE, a first message that includes a first temporary identifier including of routing information for the first network function and a first container, and a subsequent container, wherein the first container includes the first encrypted payload and the subsequent container includes the subsequent encrypted payload, and transmitting the first message to a first apparatus.

Claims (30)

1 . A method, comprising:

receiving, at an access stratum (AS) layer of a user equipment (UE), a plurality of non access stratum (NAS) payloads, wherein a first NAS payload of the plurality of NAS payloads is received from a first NAS sublayer and a subsequent payload of the plurality of NAS payloads is received from a subsequent NAS sublayer;

encrypting, by the UE, the first payload with a first encryption generating a first encrypted payload and the subsequent payload with a subsequent encryption generating a subsequent encrypted payload, wherein the first encryption is associated with a first network function and the subsequent encryption is associated with a subsequent network function;

generating, by the UE, a first message that includes a first temporary identifier comprising of routing information for the first network function and a first container, and a subsequent container, wherein the first container includes the first encrypted payload and the subsequent container includes the subsequent encrypted payload; and

transmitting, by the UE, the first message to a first apparatus.

2 . The method of claim 1 , wherein the first message includes a flag identifier that identifies that the first apparatus is to forward the first container to the first network function based on the first temporary identifier comprising of the routing information and the subsequent containers to the subsequent network functions based on the subsequent temporary identifiers comprising of routing information for those network functions.

3 . The method of claim 1 , wherein the first message includes a flag identifier that identifies that the first apparatus is to forward the first container to the first network function based on the first routing information and store the subsequent containers.

4 . The method of claim 1 , wherein the first message includes an indicator number that indicates the first apparatus is to forward the indicated number of containers to the first network function and store the other containers until the first apparatus receives further routing information for routing other containers.

5 . The method of claim 4 , wherein the receiving, the encrypting, the generating, and the transmitting are performed while the UE is not in a radio resource control (RRC) connected mode.

6 . The method of claim 1 , wherein the first routing information is included in a first temporary identifier and subsequent routing information is included in a subsequent temporary identifier.

7 . The method of claim 6 , wherein the first temporary identifier is a serving temporary mobile subscriber identifier (S-TMSI) for the first container targeted for the network function and the subsequent temporary identifier is an S-TMSI for the subsequent container targeted for the network function.

8 . The method of claim 1 , wherein the first apparatus is a radio access network (RAN) entity.

9 . The method of claim 1 , wherein the subsequent container includes the encrypted subsequent payload.

10 . A non-transitory processor-readable medium storing instructions which, when executed by at least one processor of a IE, cause the IE at least to perform: receiving, at an access stratum (AS) layer of the IE, a plurality of non access stratum (NAS) payloads, wherein a first NAS payload of the plurality of NAS payloads is received from a first NAS sublayer and a subsequent payload of the plurality of NAS payloads is received from a subsequent NAS sublayer; encrypting, by the IE, the first payload with a first encryption generating a first encrypted payload and the subsequent payload with a subsequent encryption generating a subsequent encrypted payload, wherein the first encryption is associated with a first network function and the subsequent encryption is associated with a subsequent network function; generating, by the IE, a first message that includes a first temporary identifier comprising of routing information for the first network function and a first container, and a subsequent container, wherein the first container includes the first encrypted payload and the subsequent container includes the subsequent encrypted payload; and transmitting, by the UE, the first message to a first apparatus.

11 . The non-transitory processor-readable medium of claim 10 , wherein the first message includes a flag identifier that identifies that the first apparatus is to forward the first container to the first network function based on the first temporary identifier comprising of the routing information and the subsequent containers to the subsequent network functions based on the subsequent temporary identifiers comprising of routing information for those network functions.

12 . A user equipment (UE), comprising:

at least one processor; and

at least one memory storing instructions which, when executed by the at least one processor, cause the UE at least to perform:

receiving, at an access stratum (AS) layer of the UE, a plurality of non access stratum (NAS) payloads, wherein a first NAS payload of the plurality of NAS payloads is received from a first NAS sublayer and a subsequent payload of the plurality of NAS payloads is received from a subsequent NAS sublayer;

encrypting, by the UE, the first payload with a first encryption generating a first encrypted payload and the subsequent payload with a subsequent encryption generating a subsequent encrypted payload, wherein the first encryption is associated with a first network function and the subsequent encryption is associated with a subsequent network function;

generating, by the UE, a first message that includes a first temporary identifier comprising of routing information for the first network function and a first container, and a subsequent container, wherein the first container includes the first encrypted payload and the subsequent container includes the subsequent encrypted payload; and

transmitting, by the UE, the first message to a first apparatus.

13 . The user equipment of claim 12 , wherein the first message includes a flag identifier that identifies that the first apparatus is to forward the first container to the first network function based on the first temporary identifier comprising of the routing information and the subsequent containers to the subsequent network functions based on the subsequent temporary identifiers comprising of routing information for those network functions.

14 . The user equipment of claim 12 , wherein the first message includes a flag identifier that identifies that the first apparatus is to forward the first container to the first network function based on the first routing information and store the subsequent containers.

15 . The user equipment of claim 12 , wherein the first message includes an indicator number that indicates the first apparatus is to forward the indicated number of containers to the first network function and store the other containers until the first apparatus receives further routing information for routing other containers.

16 . The user equipment of claim 15 , wherein the instructions, when executed by the at least one processor, cause the UE to perform the receiving, the encrypting, the generating and the transmitting while the UE is not in a radio resource control (RRC) connected mode.

17 . The user equipment of claim 12 , wherein the first routing information is included in a first temporary identifier and subsequent routing information is included in a subsequent temporary identifier.

18 . The user equipment of claim 17 , wherein the first temporary identifier is a serving temporary mobile subscriber identifier (S-TMSI) for the first container targeted for the network function and the subsequent temporary identifier is an S-TMSI for the subsequent container targeted for the network function.

19 . The user equipment of claim 12 , wherein the first apparatus is a radio access network (RAN) entity.

20 . The user equipment of claim 12 , wherein the subsequent container includes the encrypted subsequent payload.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2024
From: NOKIA OF AMERICA CORPORATION
To: NOKIA TECHNOLOGIES OY
Reel/Frame 067711/0258 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2024
From: CHANDRAMOULI, DEVAKI; MCGRATH, MARTIN; HWAN WON, SUNG
To: NOKIA OF AMERICA CORPORATION
Reel/Frame 067711/0228 →
Continuity (1)
Related Publication 20250301311A1 · Sep 25, 2025
References Cited (17)
US 9155121B2 · Rayavarapu · 2015 [cited by examiner]
US 11917707B2 · Da Silva · 2024 [cited by examiner]
US 20160286600A1 · Faccin et al. · 2016 [cited by applicant]
US 20180213403A1 · Shi · 2018 [cited by examiner]
US 20200177333A1 · Liu · 2020 [cited by applicant]
US 20210211960A1 · Ryu · 2021 [cited by examiner]
US 20230269780A1 · Ravishankar · 2023 [cited by examiner]
WO 2018144175A1 · 2018 [cited by applicant]
WO WO2019092059A1 · 2019 [cited by examiner]
WO WO2019092244A1 · 2019 [cited by examiner]
WO 2023055342A1 · 2023 [cited by applicant]
WO 2024035434A1 · 2024 [cited by applicant]
Miller et al., “Systematic Improvement of Access-Stratum Security in Mobile Networks,” 2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P), Delft, Netherlands, 2023, pp. 542-557, doi: 10.1109/EuroSP57164.… [cited by examiner]
Chandramouli et al., “Modular NAS Protocol Design for 6G,” in IEEE Communications Standards Magazine, doi: 10.1109/MCOMSTD.2026.3657282. (Year: 2026). [cited by examiner]
Li et al., “Micro-service-based radio access network,” in China Communications, vol. 19, No. 3, pp. 1-15, Mar. 2022, doi: 10.23919 JCC.2022.03.001. (Year: 2022). [cited by examiner]
Janakieska et al., “Signaling in 4G/5G with NB-IoT support in 5G Option 3,” 2020 55th International Scientific Conference on Information, Communication and Energy Systems and Technologies (ICEST), Niš, Serbia, 2020, pp.… [cited by examiner]
International Search Report and Written Opinion issued for PCT/EP2025/057494, Jul. 1, 2025, 21 pages. [cited by applicant]