System and method for managing sessions in a telecommunication network
By validating HGW devices using pre-provisioned mapping information and the PCF, unauthorized access of HGW devices to unauthorized CPEs is prevented, enhancing network security and compliance.
Patent Information
- Application Number
- PCT/IN2025/051142
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-08
- Filing Date
- 2025-07-26
- Publication Date
- 2026-02-12
AI Technical Summary
Existing systems fail to prevent Home Gateway (HGW) devices from unauthorized movement and access network services through unauthorized Customer Premise Equipment (CPE), leading to security vulnerabilities, service disruptions, and non-compliance with regulatory requirements.
Implementing HGW and CPE association within the core network by retrieving pre-provisioned mapping information and validating HGW devices using the Policy Control Function (PCF) to authorize sessions only for authorized CPEs.
Enhances network security by preventing unauthorized HGW mobility, ensuring uninterrupted service availability, and adhering to regulatory compliance through robust authentication and authorization mechanisms.
Smart Images

Figure IN2025051142_12022026_PF_FP_ABST
Abstract
Description
SYSTEM AND METHOD FOR MANAGING SESSIONS IN A TELECOMMUNICATION NETWORKRESERVATION OF RIGHTS
[0001] A portion of the disclosure of this patent document contains material, which is subject to intellectual property rights such as, but are not limited to, copyright, design, trademark, Integrated Circuit (IC) layout design, and / or trade dress protection, belonging to Jio Platforms Limited (JPL) or its affiliates (hereinafter referred as owner). The owner has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent files or records, but otherwise reserves all rights whatsoever. All rights to such intellectual property are fully reserved by the owner.FIELD OF DISCLOSURE
[0002] The embodiments of the present disclosure generally relate to communication networks. In particular, the present disclosure relates to a system and a method for managing sessions in a telecommunication network.DEFINITIONS
[0003] As used in the present disclosure, the following terms are generally intended to have the meaning as set forth below, except to the extent that the context in which they are used to indicate otherwise.
[0004] The term “Customer Premise Equipment (CPE)” used hereinafter in the specification refers to a specialized network device installed in indoors or outdoors, depending on the network design and signal requirements. The CPE is wirelessly connected to base station or gNodeB.
[0005] The term “Home Gateway (HGW)” used hereinafter in the specification refers to a type of Residential Gateway (RG), which is a device configured to provide communication services such as voice, data, broadcast video, and video on demand to other devices within a home. The HGW acts as an interface between the Wide Area Network (WAN) and the Local Area Network (LAN) IPenvironment for a consumer broadband customer, capable of routing or bridging traffic depending on its configuration. In the context of the 5G Core Network, the HGW device may function as a User Equipment (UE) or communicate via the CPE, holding a secure element and exchanging Non-Access Stratum (NAS) signalling with the core network (e.g., 5G or 4G) to establish connectivity.
[0006] The term “Multiple Dwelling Unit (MDU)” used hereinafter in the specification refers to a device or system deployed in a residential building or complex to facilitate network connectivity. The residential building or complex contains multiple separate housing units, such as apartments, condominiums, or dormitories. The deployment of MDU may involve centralized or per-unit CPE, with shared access infrastructure like fiber splitters or Ethernet switches.
[0007] The term “N4 interface” as used herein refers to an interface between a Session Management Function (SMF) and a User Plane Function (UPF) in the 5G core network as defined by a 3rd Generation Partnership Project (3GPP). This interface is used for creating and managing data sessions.
[0008] The term “N7 interface” as used herein refers to an interface between the SMF and a Policy Control Function (PCF) in the 5G core network as defined by the 3GPP. This interface is utilized for a policy control and an enforcement related to session management.
[0009] The term “N40 interface” as used herein refers to an interface between the SMF and a Charging Function (CHF) in the 5G core network as defined by the 3GPP. This interface is used for managing charging data related to network usage.
[0010] The term “EoGRE” as used herein refers to an Ethernet over Generic Routing Encapsulation. It is an advanced tunnelling protocol that allows an encapsulation of Ethernet frames within GRE tunnels, enabling a transmission of Ethernet headers across Internet Protocol (IP) networks.
[0011] The term “Power over Ethernet (PoE)” used hereinafter in the specification refers to a technology that allows network cables to carry electrical power to devices.
[0012] The term “PDU” as used herein refers to a Protocol Data Unit. It is a unit of data specified in a protocol of a given layer and represents an information delivered as a unit among peer entities of the 5G core network.
[0013] The term “SMF” as used herein refers to a Session Management Function in the 5G core network. It is responsible for session management, including session establishment, modification, and release.
[0014] The term “UPF” as used herein refers to a User Plane Function in the 5G core network. It handles data traffic and routing between end devices (i.e., the electronic devices) and the 5G core network.
[0015] The term “PCF” as used herein refers to a Policy Control Function in the 5G core network. It manages policy rules for controlling network behaviour and ensuring compliance with service requirements.
[0016] The term “CHF” as used herein refers to a Charging Function in the 5G core network. It handles a collection and a processing of charging data for billing and accounting purposes.
[0017] The term “Unified Data Management (UDM)” as used hereinafter in the specification refers to a network function in the 5G core network that handles user subscription data and authentication.
[0018] The term “Authentication Server Function (AUSF)” as used hereinafter in the specification refers to a network function in the 5G core network responsible for authentication.
[0019] These definitions are in addition to those expressed in the art.BACKGROUND OF DISCLOSURE
[0020] The following description of related art is intended to provide background information pertaining to the field of the disclosure. This section may include certain aspects of the art that may be related to various features of the present disclosure. However, it should be appreciated that this section be used only to enhance the understanding of the reader with respect to the present disclosure, and not as admissions of prior art.
[0021] Wireless communication technology has rapidly evolved over the past few decades. The first generation of wireless communication technology was analog technology that offered only voice services. Further, when the second- generation (2G) technology was introduced, text messaging and data services became possible. The 3 G technology marked the introduction of high-speed internet access, mobile video calling, and location-based services. The fourth-generation (4G) technology revolutionized wireless communication with faster data speeds, improved network coverage, and security. Currently, the fifth-generation (5G) technology is being deployed, with even faster data speeds, low latency, and the ability to connect multiple devices simultaneously. The sixth generation (6G) technology promises to build upon these advancements, pushing the boundaries of wireless communication even further.
[0022] In telecommunications and broadband services, the deployment and management of Home Gateway (HGW) devices play a critical role in delivering seamless connectivity and service delivery to residential customers. The HGW devices serve as a bridge between a customer premises and a service provider network (e.g., a Fifth Generation (5G) core network), facilitating internet access, Voice over Internet Protocol (VoIP) services, and various other applications. One common deployment scenario involves the HGW devices operating behind a single Customer Premise Equipment (CPE) IP Protocol Data Unit (PDU) session. In this specific deployment, the CPE acts as a consolidated gateway between various customer premises HGWs and the broader service provider network. This setup is advantageous as it consolidates network access points and simplifies infrastructure management for network service providers.
[0023] However, the multiple HGW Ethernet session behind a single CPE IP PDU session scenario introduces various challenges, particularly concerning the restriction of unauthorized movement of an HGW device between the CPEs. Specifically, there exists a potential risk that an HGW device, which has been registered and enabled for service behind a particular CPE by the network operator, could attempt to access network services through a different, unauthorized CPE if proper controls are not enforced in the core network. Such unauthorized movement or replacement of an HGW device can lead to several operational and security issues. The security issues include, but are not limited to, unauthorized service access, potential service disruption for legitimate users, security risks due to unmanaged connections, and complications related to billing and regulatory compliance. To address these critical challenges, there is a clear requirement for a robust solution that enforces strict control over the association of HGW devices with their designated CPEs, ensuring stringent authentication and authorization mechanisms are in place.
[0024] There is, therefore, a need in the art to provide a method and a system that can overcome the shortcomings of the existing prior arts.OBJECTIVES OF THE PRESENT DISCLOSURE
[0025] Some of the objectives of the present disclosure, which at least one embodiment herein satisfies, are as listed herein below.
[0026] An objective of the present disclosure is to enhance security by mitigating risks associated with an unauthorized movement of Home Gateway (HGW) devices and potential security breaches.
[0027] Another objective of the present disclosure is to improve service reliability by ensuring uninterrupted network connectivity and service availability for residential customers associated with the HGW devices.
[0028] Another objective of the present disclosure is to allow network service providers to perform network management by simplifying the HGW devices provisioning, management, and troubleshooting processes.
[0029] Another objective of the present disclosure is to enable the network service providers to adhere to regulatory requirements and maintain accurate billing practices corresponding to the HGW devices connected to the telecommunication network.
[0030] Other objectives and advantages of the present disclosure will be more apparent from the following description, which is not intended to limit the scope of the present disclosure.SUMMARY
[0031] In an exemplary embodiment, a method for managing sessions in a telecommunication network is disclosed. The method includes receiving, by a receiving unit, a Home Gateway (HGW) session request corresponding to a HGW session from a HGW device to access the telecommunication network via a Customer Premise Equipment (CPE). The method includes a set of HGW devices that are connected to the CPE through a Multiple Dwelling Unit (MDU). The method further includes retrieving, by a processing engine, an HGW to CPE mapping information associated with the HGW device, from a database, in response to receiving the HGW session request. The method further includes validating, by a validating unit, the HGW device based on the retrieved HGW to CPE mapping information. The method further includes that the validation is one of a successful validation and an unsuccessful validation. The method includes authorizing, by the validating unit, the HGW device to establish the HGW session with the CPE, upon the successful validation of the HGW device.
[0032] In some embodiments, the receiving unit receives the HGW to CPE mapping information corresponding to each HGW device as an input from a network operator. The transmitting unit transmits the HGW to CPE mapping information to a Policy Control Function (PCF).
[0033] In some embodiments, the HGW to CPE mapping information corresponding to each HGW device is provisioned in a network core during an onboarding of each HGW device.
[0034] In some embodiments, the receiving unit receives a CPE Internet Protocol (IP) Protocol Data Unit (PDU) session request corresponding to a CPE IP PDU session. The processing engine establishes the CPE IP PDU session in the telecommunication network in response to receiving the CPE IP PDU session request. The processing engine creates an HGW child session corresponding to each HGW device over the CPE IP PDU session by assigning a unique Packet Detection Rule (PDR) Identifier (ID) to each of the HGW child session.
[0035] In some embodiments, the PCF stores the HGW to CPE mapping information in the database associated with the PCF.
[0036] In some embodiments, the validating unit allows the HGW device to access the telecommunication network via the CPE in response to authorization.
[0037] In some embodiments, the HGW device is allowed to access the telecommunication network by the validating unit assigning an Internet protocol address to the HGW device.
[0038] In some embodiments, the HGW device is allowed to access the telecommunication network including assigning an Internet protocol address to the HGW device by the validating unit.
[0039] In some embodiments, the validating unit restricts the HGW device from establishing the HGW session with the CPE, upon the unsuccessful validation of the HGW device.
[0040] In an exemplary embodiment, a system for managing sessions in a telecommunication network. The system includes a receiving unit configured to receive a Home Gateway (HGW) session request corresponding to a HGW session from a HGW device to access the telecommunication network via a Customer Premise Equipment (CPE). The system includes a set of HGW devices areconnected to the CPE through a Multiple Dwelling Unit (MDU. The system further includes a processing engine configured to retrieve an HGW to CPE mapping information associated with the HGW device, from a database, in response to receiving the HGW session request. The system further includes a validating unit configured to validate the HGW device based on the retrieved HGW to CPE mapping information. The system further includes the validation that includes a successful validation and an unsuccessful validation. The system further includes the validating unit is configured to authorize the HGW device to establish the HGW session with the CPE, upon the successful validation of the HGW device.
[0041] In an exemplary embodiment, a computer program product comprising a non-transitory computer-readable medium is disclosed. The medium includes instructions that, when executed by one or more processors, cause the one or more processors to execute a method for managing sessions in a telecommunication network. The method includes receiving, by a receiving unit, a Home Gateway (HGW) session request corresponding to a HGW session from a HGW device to access the telecommunication network via a Customer Premise Equipment (CPE). The method includes a set of HGW devices that are connected to the CPE through a Multiple Dwelling Unit (MDU). The method further includes retrieving, by a processing engine, an HGW to CPE mapping information associated with the HGW device, from a database, in response to receiving the HGW session request. The method further includes validating, by a validating unit, the HGW device based on the retrieved HGW to CPE mapping information. The method further includes that the validation is one of a successful validation and an unsuccessful validation. The method includes authorizing, by the validating unit, the HGW device to establish the HGW session with the CPE, upon the successful validation of the HGW device.
[0042] The foregoing general description of the illustrative embodiments and the following detailed description thereof are merely exemplary aspects of the teachings of this disclosure and are not restrictive.BRIEF DESCRIPTION OF DRAWINGS
[0043] The accompanying drawings, which are incorporated herein, and constitute a part of this disclosure, illustrate exemplary embodiments of the disclosed methods and systems in which like reference numerals refer to the same parts throughout the different drawings. Components in the drawings are not necessarily to scale, emphasis instead being placed upon clearly illustrating the principles of the present disclosure. Some drawings may indicate the components using block diagrams and may not represent the internal circuitry of each component. It will be appreciated by those skilled in the art that disclosure of such drawings includes the disclosure of electrical components, electronic components or circuitry commonly used to implement such components.
[0044] FIG. 1 illustrates an exemplary network architecture for managing sessions in a telecommunication network, in accordance with embodiments of the present disclosure.
[0045] FIG. 2 illustrates a block diagram of a system for managing the sessions in the telecommunication network, in accordance with embodiments of the present disclosure.
[0046] FIG. 3 illustrates an exemplary architecture of the system for managing the sessions in the telecommunication network, in accordance with embodiments of the present disclosure.
[0047] FIG. 4 illustrates an exemplary flow diagram of performing a method for managing the sessions in the telecommunication network, in accordance with embodiments of the present disclosure.
[0048] FIG. 5 illustrates another exemplary flow diagram of performing the method for managing the sessions in the telecommunication network, in accordance with embodiments of the present disclosure.
[0049] FIG. 6 illustrates an exemplary computer system in which or with which the system may be implemented in accordance with an embodiment of the present disclosure.
[0050] The foregoing shall be more apparent from the following more detailed description of the disclosure.LIST OF REFERENCE NUMERALS100 - Network Architecture102-1, 102-2, 102-N - One or more Users104-1, 104-2, 104-3, 104-N - One or more computing devices106 - Network / Telecommunication network108 - System200 - Block diagram202 - Receiving unit204 - Memory206 - Interface(s)208 - Processing engine209 - Validating unit210 - Database300 - System Architecture302-1, 302-2, 302-3, 302 -N - A set of Home Gateway (HGW) devices304 -Multiple Dwelling Unit (MDU)306 - Customer Premise Equipment (CPE)308 - Base station310 - User Plane Function (UPF)312 - Internet314 - Session Management Function (SMF)316 - Policy Control Function (PCF)318 - Charging Function (CHF)320 - Access and Mobility management Function (AMF)322 - Unified Data Management (UDM)324 - Authentication Server Function (AUSF)400 - Process flow404 - Fifth Generation (5G) core network500 - Flow diagram600 - Computing system610 - External Storage Device620 - Bus630 - Main Memory640 - Read Only Memory650 - Mass Storage Device660 - Communication Port670 - ProcessorDETAILED DESCRIPTION OF DISCLOSURE
[0051] In the following description, for the purposes of explanation, various specific details are set forth in order to provide a thorough understanding of embodiments of the present disclosure. It will be apparent, however, that embodiments of the present disclosure may be practiced without these specificdetails. Several features described hereafter can each be used independently of one another or with any combination of other features. An individual feature may not address all of the problems discussed above or might address only some of the problems discussed above. Some of the problems discussed above might not be fully addressed by any of the features described herein.
[0052] The ensuing description provides exemplary embodiments only, and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, the ensuing description of the exemplary embodiments will provide those skilled in the art with an enabling description for implementing an exemplary embodiment. It should be understood that various changes may be made in the function and arrangement of elements without departing from the spirit and scope of the disclosure as set forth.
[0053] Specific details are given in the following description to provide a thorough understanding of the embodiments. However, it will be understood by one of ordinary skill in the art that the embodiments may be practiced without these specific details. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form in order not to obscure the embodiments in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail in order to avoid obscuring the embodiments.
[0054] Also, it is noted that individual embodiments may be described as a process which is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. Although a flowchart may describe the operations as a sequential process, many of the operations can be performed in parallel or concurrently. In addition, the order of the operations may be re-arranged. A process is terminated when its operations are completed but could have additional steps not included in a figure. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to afunction, its termination can correspond to a return of the function to the calling function or the main function.
[0055] The word “exemplary” and / or “demonstrative” is used herein to mean serving as an example, instance, or illustration. For the avoidance of doubt, the subject matter disclosed herein is not limited by such examples. In addition, any aspect or design described herein as “exemplary” and / or “demonstrative” is not necessarily to be construed as preferred or advantageous over other aspects or designs, nor is it meant to preclude equivalent exemplary structures and techniques known to those of ordinary skill in the art. Furthermore, to the extent that the terms “includes,” “has,” “contains,” and other similar words are used in either the detailed description or the claims, such terms are intended to be inclusive in a manner similar to the term “comprising” as an open transition word without precluding any additional or other elements.
[0056] Reference throughout this specification to “one embodiment” or “an embodiment” or “an instance” or “one instance” means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present disclosure. Thus, the appearances of the phrases “in one embodiment” or “in an embodiment” in various places throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0057] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the disclosure. As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises” and / or “comprising,” when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / orgroups thereof. As used herein, the term “and / or” includes any and all combinations of one or more of the associated listed items.
[0058] In an embodiment, within modem telecommunication networks, particularly in scenarios involving multiple Home Gateway (HGW) devices establishing Ethernet sessions behind a single Customer Premise Equipment (CPE) Internet Protocol (IP) Protocol Data Unit (PDU) session, a significant challenge arises. Conventional systems may not adequately prevent an HGW device from attempting to access network services through a CPE other than its authorized one. Such unchecked movement or reconnection can lead to potential security vulnerabilities, service misuse, and non-compliance with regulatory requirements.
[0059] In an embodiment, the present disclosure provides a system and a method for securely managing sessions in a telecommunication network by effectively addressing the aforementioned limitations. The present disclosure overcomes the above-mentioned challenges by implementing HGW and CPE association within the core network, specifically leveraging the Policy Control Function (PCF). This is achieved by retrieving pre-provisioned HGW to CPE mapping information for every HGW session request and performing a validation. Upon successful validation, the HGW device is authorized to establish its session; otherwise, its session establishment is restricted. The present disclosure significantly enhances network security by preventing unauthorized HGW mobility.
[0060] The various embodiments throughout the disclosure will be explained in more detail with reference to FIG. 1- FIG. 6.
[0061] FIG. 1 illustrates an exemplary network architecture 100 for managing sessions in a telecommunication network 106, in accordance with embodiments of the present disclosure.
[0062] FIG. 1 illustrates an exemplary network architecture 100 for implementing a system 108 for managing sessions in a telecommunication network 106, in accordance with an embodiment of the present disclosure. The networkarchitecture 100 may be applied on Fixed Wireless Access (FWA) deployments, where wireless cellular technology provides broadband connectivity to fixed subscriber locations. In an embodiment, the network architecture 100 may include one or more user equipments (UEs) 104-1, 104-2... 104-N associated with one or more users 102-1, 102-2... 102-N in an environment. A person of ordinary skill in the art will understand that one or more users 102-1, 102-2... 102-N may be individually referred to as the user 102 and collectively referred to as the users 102. Similarly, a person of ordinary skill in the art will understand that one or more UEs 104-1, 104-2... 104-N may be individually referred to as the UE 104 and collectively referred to as the UEs 104. Although three UEs 104 are depicted in FIG. 1, however, any number of the UEs 104 may be included without departing from the scope of the ongoing description.
[0063] As will be appreciated, the Home Gateway (HGW) may correspond to an UE Further, the user 102 may correspond to a network administrator or a network service provider. Further, with each CPE, a set of HGW devices may be connected. A person of ordinary skill in the art will appreciate that the terms “CPE” and “UE” may be used interchangeably throughout the disclosure. As will be appreciated, the CPE is a specialized network device that may be installed outdoors and indoors at customer locations to facilitate connectivity and network services. In an embodiment, examples of the CPE includes a Fifth Generation (5G) or a Fourth Generation (4G) outdoor customer premise equipment which can provide a high throughput broadband connectivity to end users. The CPE can also have a functionality to connect to the 5G Non-Terrestrial Network (NTN). In this context the CPE is no more dedicated to a customer premises but the set of HGWs in individual customers premise (i.e., homes) connects to a single CPE using a Multiple Dwelling Unit (MDU). In that sense the CPE is shared across multiple homes and the CPE becomes a network element for an FWA deployment serving multiple subscribers. In an embodiment, the UE 104 may be deployed as a home gateway device (HGW) connected to a customer premise equipment (CPE) for use in a FWA environment. In an example, the UE 104 may be statically located at afixed customer premises and connected to the core network via a wireless access network.
[0064] In an embodiment, the UE 104 includes smart devices operating in a smart environment, for example, an Internet of Things (loT) system. In such an embodiment, the UE 104 may include, but is not limited to, smart phones, smart watches, smart sensors (e.g., a mechanical sensor, a thermal senor, an electrical sensor, a magnetic sensor, etc.), networked appliances, networked peripheral devices, networked lighting system, communication devices, networked vehicle accessories, networked vehicular devices, smart accessories, tablets, smart televisions (TVs), computers, smart security systems, smart home systems, other devices for monitoring or interacting with or for the user 102 and / or entities, or any combination thereof. A person of ordinary skill in the art will appreciate that the UE 104 may include, but is not limited to, intelligent, multi-sensing, network- connected devices, that can integrate seamlessly with each other and / or with a central server or a cloud-computing system or any other device that is network- connected. In an embodiment, the UE 104 may include, but is not limited to, any electrical, electronic, electro-mechanical device, or an equipment, or a combination of one or more of the above devices. A person of ordinary skill in the art will appreciate that the UE 104 may not be restricted to the mentioned devices and various other devices may be used.
[0065] In FIG. 1, the user equipment 104 (i.e., the CPE) may communicate with the system 108 through the telecommunication network 106. In order to establish communication, initially, the network 106 is configured to receive a communication request from the user equipment 104. In response to receiving the communication request, the network 106 is configured to send an acknowledgment of the connection request to the user equipment 104. Further, a plurality of signals is transmitted in response to the connection request. Based on the connection request, managing of the session is performed in the telecommunication network (i.e., the network 106). In an embodiment, the network 106 includes at least one ofthe 4G network, the 5G network, the 6G network, or the like, providing wireless access for FWA services.
[0066] The network 106 may enable the UE 104 to communicate with other devices in the network architecture 100 and / or with the system 108. The network 106 may include a wireless card or some other transceiver connection to facilitate this communication. In another embodiment, the network 106 may be implemented as, or include any of a variety of different communication technologies such as a wide area network (WAN), a local area network (LAN), a wireless network, a mobile network, a Virtual Private Network (VPN), the Internet, the Public Switched Telephone Network (PSTN), a cable network, a cellular network, a satellite network, a fiber optic network, or some combination thereof. In another embodiment, the network 106 includes, by way of example but not limitation, at least a portion of one or more networks having one or more nodes that transmit, receive, forward, generate, buffer, store, route, switch, process, or a combination thereof, etc. one or more messages, packets, signals, waves, voltage or current levels, some combination thereof, or so forth.
[0067] Although FIG. 1 shows exemplary components of the network architecture 100, in other embodiments, the network architecture 100 may include fewer components, different components, differently arranged components, or additional functional components than depicted in FIG. 1. Additionally, or alternatively, one or more components of the network architecture 100 may perform functions described as being performed by one or more other components of the network architecture 100. In order to manage the sessions in the telecommunication network (e.g., the network (106)), the system (108) is configured to authenticate an HGW device to establish an HGW session with the CPE. This is further explained in conjunction with FIGS. 2 - 6
[0068] FIG. 2 illustrates an example block diagram 200 of the system 108 configured for managing sessions in the telecommunication network 106, in accordance with an embodiment of the present disclosure. FIG. 2 is explained inconjunction with FIG. 1. In particular, the system 108 is implemented for managing the sessions in the telecommunication network 106. The telecommunication network 106 corresponds to the network 106. Examples of the telecommunication network includes, but are not limited to, the 4G network, the 5G network, the 6G network, and the like.
[0069] The system 108 includes a memory 204 that is configured to store one or more computer-readable instructions or routines in a non-transitory computer readable storage medium, which may be fetched and executed to manage the sessions in the telecommunication network 106. The memory 204 may include any non-transitory storage device including, for example, a volatile memory such as a random-access memory (RAM), or a non-volatile memory such as an erasable programmable read only memory (EPROM), a flash memory, and the like.
[0070] In an embodiment, the system 108 may include an interface(s) 206. The interface(s) 206 may include a variety of interfaces, for example, interfaces for data input and output devices (RO), storage devices, and the like. The interface(s) 206 may facilitate communication through the system 108. The interface(s) 206 may also provide a communication pathway for one or more components of the system 108. Examples of such components include, but are not limited to, the processing engine(s) 208 and a database 210.
[0071] In an embodiment, the processing engine(s) 208 may be implemented as a combination of hardware and programming (for example, programmable instructions) to implement one or more functionalities of the processing engine(s) 208. In examples described herein, such combinations of hardware and programming may be implemented in several different ways. For example, the programming for the processing engine(s) 208 may be processorexecutable instructions stored on a non-transitory machine-readable storage medium and the hardware for the processing engine(s) 208 may comprise a processing resource (for example, one or more processors), to execute such instructions. In the present examples, the machine-readable storage medium maystore instructions that, when executed by the processing resource, implement the processing engine(s) 208. In such examples, the system 108 may comprise the machine-readable storage medium storing the instructions and the processing resource to execute the instructions, or the machine-readable storage medium may be separate but accessible to the system and the processing resource. In other examples, the processing engine(s) 208 may be implemented by electronic circuitry.
[0072] In an embodiment, the receiving unit 202 is initially configured to receive a CPE Internet Protocol (IP) Protocol Data Unit (PDU) session request corresponding to a CPE IP PDU session, from the CPE. In response to receiving the CPE IP PDU session request, the CPE IP PDU session is established in the telecommunication network 106. The telecommunication network 106, for example, corresponds to the 5G core network. Once the CPE IP PDU session is established, a HGW child session corresponding to each HGW device 302 is established over the CPE IP PDU session. The creation of individual HGW child sessions is crucial because, while multiple HGW devices share the single CPE IP PDU session for their collective connectivity, each HGW device requires its own distinct logical session for independent management, policy application, and unique identification within the shared CPE PDU session. The processing engine 208 is further configured to create an HGW child session corresponding to each HGW device 302 over the CPE IP PDU session by assigning a unique Packet Detection Rule (PDR) Identifier (ID) to each of the HGW child session.
[0073] In an embodiment, the receiving unit 202 is configured to receive the HGW to CPE mapping information corresponding to each HGW device 302 as an input from the user (102), e.g., the network service provider (also referred as an Internet Service Provider (ISP)) during onboarding. The input signifies the configuration of authorized HGW-CPE pairings by the user (102). The processing engine 208 is configured to transmit the HGW to CPE mapping information to a Policy Control Function (PCF). The PCF is configured to store the HGW to CPE mapping information in the database 210 associated with the PCF. In anembodiment, the HGW to CPE mapping information corresponding to each HGW device 302 is provisioned in a network core (i.e., the 5G core network) during the onboarding of each HGW device 302.
[0074] In an embodiment, once the HGW to CPE mapping information is stored and each of the HGW child session is created, the receiving unit 202 is configured to receive an HGW session request corresponding to the HGW session from the HGW device to access the telecommunication network 106 via a CPE. Further a set of HGW devices are connected to the CPE through a Multiple Dwelling Unit (MDU). The CPE is the specialized network device (e.g., the WAPs) installed outdoors or indoor at the customer locations to facilitate connectivity and network services. The HGW device corresponds to a hardware unit typically used in residential premises to connect multiple electronic devices (such as a tablet, a laptop, a desktop, etc.) within a home network to an external network (e.g., the 5G network). The 5G network may also be referred to as a 5G core network. An example of the HGW device may include, but is not limited to, a wireless fidelity (Wi-Fi) router. Further, the MDU corresponds to a device to connect HGWs of multiple separate residential units, e.g., apartments in a building.
[0075] In an embodiment, the processing engine 208 is configured to retrieve an HGW to CPE mapping information associated with the HGW device, from the database 210, in response to receiving the HGW session request. This HGW to CPE mapping information comprises a predefined pairing between a unique identifier of the HGW device (e.g., its MAC address or serial number) and a unique identifier of the authorized CPE (e.g., its MAC address or serial number). In an embodiment, the HGW to CPE mapping information corresponding to each HGW device is received as an input from the user. The user may correspond to the network administrator or the network service provider.
[0076] In an embodiment, the HGW to CPE mapping information corresponding to each HGW device 302 is provisioned in a network core during an onboarding of each HGW device 302.
[0077] In an embodiment, a validating unit 209 is configured to validate the HGW device based on the retrieved HGW to CPE mapping information. In an embodiment, the validation is one of a successful validation or an unsuccessful validation. The validation is the successful validation when the HGW device from which the HGW session request is received is mapped to or is associated with the CPE corresponding to which the connection needs to be established. Further, the validation is the unsuccessful validation, when the HGW device from which the HGW session request is received is not mapped to or is not associated with the CPE corresponding to which connection needs to be established. In other words, if the HGW to CPE mapping information contains information depicting that the HGW device from which the HGW session request is received, is mapped to the CPE, then the validation is the successful validation. For instance, if the HGW to CPE mapping information, stored in the database 210, contains a record explicitly linking “HGW ID 123” with “CPE Serial XYZ”, and an HGW session request is received from HGW ID 123 attempting to connect via CPE Serial XYZ, then the validation is successful. Further, if the HGW to CPE mapping information does not contain information depicting that the HGW device from which the HGW session request is received, is mapped to the CPE, then the validation is the unsuccessful validation. In an example, if an HGW device identified as “HGW ID 456” attempts to establish a session through “CPE Serial UVW”, but the HGW to CPE mapping information specifies that HGW ID 456 is only authorized to connect via “CPE Serial PQR”, then the validation is unsuccessful.
[0078] In an embodiment, the validating unit 209 is configured to authorize the HGW device to establish the HGW session with the CPE, upon the successful validation of the HGW device for accessing network services. In an embodiment, the validating unit 209 is configured to allow the HGW device to access the telecommunication network 106 via the CPE in response to authorization.
[0079] In an embodiment, the validating unit 209 is configured to assign an Internet protocol address to the HGW device in response to allowing the HGW device to access the telecommunication network 106. The assignment occurs inresponse to allowing the HGW device to access the telecommunication network 106, providing it with the necessary network identity for communication.
[0080] Furthermore, upon the unsuccessful validation of the HGW device, the validating unit 209 may restrict the HGW device from establishing the HGW session with the CPE. This restriction is automatically enforced upon the unsuccessful validation of the HGW device, thereby upholding the security and policy constraints imposed by the HGW to CPE mapping. This is further explained in conjunction with FIG. 3 - FIG. 6.
[0081] FIG. 3 illustrates an exemplary architecture 300 for managing the sessions in the telecommunication network 106, in accordance with an embodiment of the disclosure. FIG. 3 is explained in conjunction with FIGS. 1 and 2.
[0082] As depicted in FIG. 3, a set of HGW devices, i.e., an HGW - 1 device, an HGW - 2 device, an HGW - 3 device, up to an HGW - N device may be connected to a CPE 306 through a MDU 304. It should be noted that, ‘N’ may be any number of an HGW device (for example: an HGW - 10 device) that gets connected to the CPE 306 based on a requirement of the network service provider. In other words, the set of HGW devices 302-1, 302-2, 302-3, 302-N that get connected to the CPE 306 may include 10 HGW devices. In an embodiment, may collectively be referred to as the set of HGW devices 302. It should be noted that the network service provider decides how many HGW devices will be connected with which CPE during the onboarding of the HGW devices. Further, as depicted in FIG. 3, each HGW device 302 may be connected with the MDU 304 via a Power over Ethernet (PoE) cable. Further, the MDU 304 may be connected with the CPE 306 via the PoE cable. As will be appreciated, the PoE cable is a technology that passes an electric power over a twisted pair ethemet cable to powered devices (PD), i.e., the MDU 304 and the CPE 306. In other words, the MDU 304 and the CPE 306 draws power from the set of HGW devices 302 that are connected in an associated Local Area Network (LAN) interface, via the PoE cable.
[0083] Further, the CPE 306 may be configured to establish a CPE Internet Protocol (IP) Protocol Data Unit (PDU) session with a 5G core network for an internet 312 connectivity, i.e., the telecommunication network 106. For this, the CPE 306 may send a CPE IP PDU session request corresponding to the CPE IP PDU session to a User Plane Function (UPF) 310 and an Access and Mobility Management Function (AMF) 320. In an embodiment, a base station 308 is configured to receive the CPE IP PDU session request from the CPE 306 and transmit the CPE IP PDU session request to the UPF 310 and the AMF 320. In an embodiment, the processing engine 208 of the system 108 may include the UPF 310, the AMF 320, a Session Management Function (SMF) 314, a Policy Control Function (PCF) 316, a Charging Function (CHF) 318, a Unified Data Management (UDM) 322, and an Authentication Server Function (AUSF) 324.
[0084] The UPF 310 is configured for interacting with the SMF 314, and vice versa. The SMF 314 is configured for interacting with the PCF 316, the CHF 318, the AMF 320 and the UDM 322, and vice versa. The AMF 320 is configured for interacting with the UDM 322 and the AUSF 324, and vice versa. The AUSF 324 is configured for interacting with the UDM 322 and vice versa.
[0085] Once the CPE IP PDU session is created, multiple HGW child sessions may be created corresponding to the set of HGW devices, i.e., the HGW- 1 device, the HGW-2 device, the HGW- 3 device, up to, the HGW -10 device. Each of the HGW child session corresponding to the set of HGW devices 302 are created over the CPE IP PDU session, e.g., an N4 interface. In an embodiment, the N4 interface refers to an interface between the SMF 314 and the UPF 310 in the 5G network (i.e., the internet 312). The N4 interface interface is used for creating and managing data sessions. Further, the multiple HGW child sessions are created to enable each HGW device 302 to interact with the internet 312 over the CPE IP PDU session, upon a successful validation. In an embodiment, the multiple HGW child sessions are created by assigning a unique Packet Detection Rule (PDR) Identifier (ID) to each of the HGW child session.
[0086] Further, the SMF 314 creates distinct N7 and N40 interfaces with the PCF 316 and the CHF 318, respectively, forthe CPE 306 and each ofthe HGW child session. In an embodiment, the N7 interface refers to an interface between the SMF 314 and the PCF 316 in the 5G network as defined by the 3GPP. This N7 interface interface is utilized for policy control and enforcement related to session management. Further, the N40 interface as used herein refers to an interface between the SMF 314 and the CHF 318 in the 5G network as defined by the 3GPP. This N40 interface interface is used for managing charging data related to network usage.
[0087] In an embodiment, in addition to creation of the multiple HGW child sessions forthe set of HGW devices 302 over the CPE IP PDU session forthe CPE 306, an HGW to CPE mapping information corresponding to each HGW device 302 is stored in a database associated with the PCF 316. The HGW to CPE mapping information corresponding to each HGW device 302 is received as an input from a user, e.g., the network service provider (i.e., the user 102). The HGW to CPE mapping information corresponding to each HGW device 302 is provisioned in a network core, i.e., the 5G core network at atime of onboarding of each HGW device 302.
[0088] Once the multiple HGW child sessions are created for the set of HGW device and the HGW to CPE mapping information is provisioned, the HGW session request corresponding to the HGW session (i.e., a new HGW session) may be received by the processing engine 208 from the HGW device 302. Upon receiving the HGW session request, the processing engine 208 may be configured to validate the HGW device based on the HGW to CPE mapping information. The set of HGW devices refers to the multiple HGW devices (e.g., HGW-1 to HGW-N as depicted in FIG. 3) that are collectively connected to the CPE 306 through the Multiple Dwelling Unit (MDU). The HGW session request may be received, for instance, upon an initial connection with the HGW device, a reboot event, or an attempt by the HGW device to establish connectivity, even if it is attempting to connect via the CPE other than its registered one. Upon receiving the HGW sessionrequest, the processing unit 208 may be configured to validate the HGW device 302 based on the HGW to CPE mapping information. The validation is performed to enable only those HGW devices that are authorized and are present in the predefined HGW to CPE mapping information to establish the HGW session with the CPE 306 to access the internet 312 or network services. The validation is one of a successful validation or an unsuccessful validation. For example, suppose the HGW device corresponds to the HGW - 1 device. In one embodiment, the successful validation is when the HGW device (i.e., the HGW - 1 device) from which the HGW session request is received in mapped to the CPE 306. In other words, an information associated with the HGW - 1 device is present in the HGW to CPE mapping information. In case of the successful validation, the HGW - 1 device is authorized to establish the HGW session with the CPE 306. In another embodiment, the unsuccessful validation is when the HGW device (e.g., an HGW - 12 device) from which the HGW session request is received in not mapped to the CPE 306. In other words, an information associated with the HGW - 12 device is not present in the HGW to CPE mapping information. In case of the unsuccessful validation, the HGW - 12 device is restricted from establishing the HGW session with the CPE 306. This is done to allow only the set of HGW devices 302 to connect with the CPE 306 as designated by the internet service provider for accessing the internet 312 (or the network services).
[0089] Although FIG. 3 shows exemplary components of the system 108, in other embodiments, the system 108 may include fewer components, different components, differently arranged components, or additional functional components than depicted in FIG. 3. Additionally, or alternatively, one or more components of the system 108 may perform functions described as being performed by one or more other components of the system 108.
[0090] FIG. 4 illustrates an exemplary process flow 400 for managing the sessions in the telecommunication network 106, in accordance with an embodiment of the disclosure. FIG. 4 is explained in conjunction with FIGS. 1, 2, and 3.
[0091] At step 406, the HGW to CPE mapping information (also referred as an HGW to CPE identity mapping) may be provisioned in the database associated with the PCF 316. In other words, during the onboarding of each HGW device 302, the user, e.g., the network service provider stores the HGW to CPE mapping information in the database associated with the PCF 316. The mapping information forms the basis for subsequent HGW validation.
[0092] At step 408, the CPE 306 may be configured to establish the CPE IP PDU session with the telecommunication network 106, i.e., a 5G core network 404. Once the CPE IP PDU session is established, a HGW child session request is sent by an HGW device 402 (e.g., the HGW -1) to CPE 306. The CPE 306 is configured to establish the HGW child session over the N4 interface (i.e., the CPE IP PDU session) using an Ethernet over Generic Routing Encapsulation (EoGRE) tunnel 410 at step 410. The EoGRE is an unencrypted stateless layer 2 tunnelling technology. In other words, the EoGRE is an advanced tunnelling protocol that allows an encapsulation of Ethernet frames within GRE tunnels, enabling a transmission of Ethernet headers across Internet Protocol (IP) networks.
[0093] At step 412, an IP address assignment request may be sent by the HGW device 402 to the UPF 310. The IP address assignment request is sent because the HGW device requires an IP address to gain full network connectivity and access telecommunication services. The UPF 310 may be configured to report the HGW device 402 identity over session report request message to the SMF 314.
[0094] At step 414, following the IP address assignment request, the UPF 310 is configured to send a session report request to the SMF 314. The session report request includes the HGW ID (Home Gateway Identifier) of the HGW device 402, informing the SMF 314 about the attempt of the HGW to establish a session and provide identity for subsequent session management and policy association.
[0095] At step 416, the SMF 314 may be configured to send a session management (SM) policy association establishment request along with the HGW ID and CPE ID to the PCF 316. The SM policy association establishment requestmay be sent to perform establishment of the HGW device 402 policy session (i.e., the HGW session) along with an associated CPE 306 permanent Identifier (ID) (a Subscription Permanent Identifier (SUPI) and a Generic Public Subscription Identifier (GPSI)) inserted in a request message (i.e., the SM policy association establishment request). The key identity check is performed at the PCF 316 end, where the association of the HGW device 402 (identified, for example, by its unique Packet Detection Rule (PDR) ID from the child session) with the CPE ID is validated against the pre-provisioned HGW to CPE mapping information stored in the database. This validation is based on the policy provisioned by the network service provider during the HGW device 402 onboarding.
[0096] At step 418, the HGW device 402 is authorized by the PCF 316 for accessing network services associated with the 5G core network 404 via the CPE 306 during the CPE IP PDU session based on the SM policy association and an identity check result at the PCF 316 end. In case of a mismatch of the identity association, the HGW device 402 would not be authorized to access the network services.
[0097] At step 420, once the HGW 402 is authorized, an SM policy association establishment response may be sent by the PCF 316 to the SMF 314. The SM policy association establishment response depicts that the HGW 402 is authorized to access the network services via the CPE 306 during the CPE IP PDU session.
[0098] At step 422, the SMF 314 may be configured to send a session report response to the UPF 310.
[0099] At step 424, the UPF 310 and the SMF 314 may be configured to perform session modification procedure corresponding to the HGW device 402. The session modification procedure is performed for applying specific session rules such as applying or assigning the unique PDR, Quality of Services (QoS) Enforcement Rules (QERs), Forwarding Action Rules (FARs), and Usage Reporting Rules (URRs) to the authorized HGW child session.
[0100] At step 426, the IP address assignment response may be sent by the UPF 310 to the HGW device 402, providing the HGW device with the necessary network address.
[0101] At step 428, the HGW device 402 may be able to establish the HGW session with the 5G core network 404 based on the successful authorization received, the assigned IP address, and the applied session modification procedures. In case of a mismatch of the identity association, the PCF 316 would reject the SM policy session establishment to the SMF 314, and a negative session report response would be sent from the SMF 314 to the UPF 310 so that the UPF 310 does not assign any IP address to the HGW device 402.
[0102] FIG. 5 illustrates an exemplary flow diagram of a method 500 for managing the sessions in the telecommunication network 106, in accordance with an embodiment of the present disclosure. FIG. 5 is explained in conjunction with FIGS. 1, 2, 3, and 4. Each step of the method 500 may be performed by the processing engine 208 of the system 108.
[0103] In order to manage the sessions in the telecommunication network 106, initially, the CPE Internet Protocol (IP) Protocol Data Unit (PDU) session request corresponding to the CPE IP PDU session is received from the CPE (for example, the CPE 306). In response to receiving the CPE IP PDU session request, the CPE IP PDU session is established in the telecommunication network 106. The telecommunication network 106, for example, corresponds to the 5G core network 404. Once the CPE IP PDU session is established, the Home Gateway (HGW) child session corresponding to each HGW device 302 is established over the CPE IP PDU session. Each HGW child session is established by assigning the unique PDR ID to each of the HGW child session.
[0104] In addition to creation of each of the HGW child session over the CPE IP PDU session, the HGW to CPE mapping information corresponding to each HGW device 302 is received as the input from the user, e.g., the network service provider (also referred as an Internet Service Provider (ISP)) during onboarding.The received HGW to CPE mapping information is provided to a PCF (i.e., the PCF 316). Further, the received HGW to CPE mapping information is stored in the database associated with the PCF. In an embodiment, the HGW to CPE mapping information corresponding to each HGW device 302 is provisioned in a network core (i.e., the 5G core network) during the onboarding of each HGW device 302.
[0105] At step 502, the method 500 begins with receiving by the receiving unit 202, the HGW session request corresponding to the HGW session from the HGW device to access the telecommunication network 106 via the Customer Premise Equipment (CPE). A set of HGW devices 302 are connected to the CPE through the Multiple Dwelling Unit (MDU). The HGW session request corresponds to the HGW session originating from the HGW device, which seeks to access the telecommunication network 106 via the CPE. As previously described, a set of HGW devices 302 is connected to the CPE through the Multiple Dwelling Unit (MDU).
[0106] At step 504, the method 500 retrieves, by the processing engine 208, an HGW to CPE mapping information associated with the HGW device, from a database, in response to receiving the HGW session request. The HGW to CPE mapping information associated with the specific HGW device that initiated the session request is fetched from a database (for example, the database 210, as shown in FIG. 2, which is associated with the PCF). The retrieval is a direct response to the incoming HGW session request, providing the necessary data for the subsequent validation. The mapping information includes identifiers linking each HGW device with its corresponding authorized CPE. The retrieval enables validation and policy decisions before session establishment, ensuring that only authorized HGW devices can communicate via specific CPE.
[0107] At step 506, the method 500 validates, by the validating unit 209, the HGW device based on the retrieved HGW to CPE mapping information. The validation is based on the previously retrieved HGW to CPE mapping information. This step determines whether the HGW device is authorized to establish the HGWsession through the specific CPE it is attempting to connect to, according to the predefined network operator policies. The validation may result in one of two outcomes. In an embodiment the validation is one of the successful validation and the unsuccessful validation. If the HGW to CPE mapping information confirms that the HGW device is associated with the CPE from which the session request was received, the validation is considered successful. If the retrieved mapping information does not indicate a valid association between the requesting HGW device and the identified CPE, the validation is considered unsuccessful. This prevents unauthorized or misconfigured devices from initiating sessions.
[0108] At step 508, the method 500 authorizes, by the validating unit 209, the HGW device to establish the HGW session with the CPE, upon the successful validation of the HGW device. Authorization enables the HGW device to gain access to network services via the 5G core network.
[0109] In one embodiment, following authorization, the processing engine 208 may also be configured to assign an Internet Protocol (IP) address to the HGW device, enabling it to transmit and receive data over the established session. If the validation fails, the processing engine 208 is configured to restrict the HGW device from establishing the HGW session with the CPE, thereby enforcing access control policies and maintaining network integrity.
[0110] FIG. 6 illustrates an exemplary computer system 600 in which or with which embodiments of the present disclosure may be implemented.
[0111] As shown in FIG. 6, the system 108 may include an external storage device 610, a bus 620, amain memory 630, a read-only memory 640, amass storage device 650, a communication port 660, and a processor 670. A person skilled in the art will appreciate that the system 108 may include more than one processor 670 and communication ports 660. Processor 670 may include various modules associated with embodiments of the present disclosure.
[0112] In an embodiment, the communication port 660 is any of an RS-232 port for use with a modem-based dialup connection, a 10 / 100 Ethernet port, aGigabit or 10 Gigabit port using copper or fiber, a serial port, a parallel port, or other existing or future ports. The communication port 660 is chosen depending on a network, such a Local Area Network (LAN), Wide Area Network (WAN), or any network to which the system 108 connects.
[0113] In an embodiment, the memory 630 is Random Access Memory (RAM), or any other dynamic storage device commonly known in the art. Readonly memory 640 is any static storage device(s) e.g., but not limited to, a Programmable Read Only Memory (PROM) chips for storing static information e.g., start-up or Basic Input / Output System (BIOS) instructions for the processor 670.
[0114] In an embodiment, the mass storage 650 is any current or future mass storage solution, which is used to store information and / or instructions. Exemplary mass storage solutions include, but are not limited to, Parallel Advanced Technology Attachment (PATA) or Serial Advanced Technology Attachment (SATA) hard disk drives or solid-state drives (internal or external, e.g., having Universal Serial Bus (USB) and / or Firewire interfaces), one or more optical discs, Redundant Array of Independent Disks (RAID) storage, e.g., an array of disks (e.g., SATA arrays).
[0115] In an embodiment, the bus 620 communicatively couples the processor(s) (670) with the other memory, storage, and communication blocks. The bus 620 is, e.g., a Peripheral Component Interconnect (PCI) / PCI Extended (PCI-X) bus, Small Computer System Interface (SCSI), Universal Serial Bus (USB) or the like, for connecting expansion cards, drives and other subsystems as well as other buses, such a Front Side Bus (FSB), which connects the processor 670 to the system 108.
[0116] Optionally, operator and administrative interfaces, e.g., a display, keyboard, joystick, and a cursor control device, may also be coupled to the bus 620 to support direct operator interaction with the system 108. Other operators and administrative interfaces are provided through network connections connectedthrough the communication port 660. The components described above are meant only to exemplify various possibilities. In no way should the aforementioned exemplary illustration 600 limit the scope of the present disclosure.
[0117] In an exemplary embodiment, a system for managing sessions in a telecommunication network. The system includes a receiving unit configured to receive a Home Gateway (HGW) session request corresponding to a HGW session from a HGW device to access the telecommunication network via a Customer Premise Equipment (CPE). The system includes a set of HGW devices are connected to the CPE through a Multiple Dwelling Unit (MDU. The system further includes a processing engine configured to retrieve an HGW to CPE mapping information associated with the HGW device, from a database, in response to receiving the HGW session request. The system further includes a validating unit configured to validate the HGW device based on the retrieved HGW to CPE mapping information. The system further includes the validation that includes a successful validation and an unsuccessful validation. The system further includes the validating unit is configured to authorize the HGW device to establish the HGW session with the CPE, upon the successful validation of the HGW device.
[0118] In an exemplary embodiment, a computer program product comprising a non-transitory computer-readable medium is disclosed. The medium includes instructions that, when executed by one or more processors, cause the one or more processors to execute a method for managing sessions in a telecommunication network. The method includes receiving, by a receiving unit, a Home Gateway (HGW) session request corresponding to a HGW session from a HGW device to access the telecommunication network via a Customer Premise Equipment (CPE). The method includes a set of HGW devices that are connected to the CPE through a Multiple Dwelling Unit (MDU). The method further includes retrieving, by a processing engine, an HGW to CPE mapping information associated with the HGW device, from a database, in response to receiving the HGW session request. The method further includes validating, by a validating unit, the HGW device based on the retrieved HGW to CPE mapping information. Themethod further includes that the validation is one of a successful validation and an unsuccessful validation. The method includes authorizing, by the validating unit, the HGW device to establish the HGW session with the CPE, upon the successful validation of the HGW device.
[0119] While considerable emphasis has been placed herein on the preferred embodiments, it will be appreciated that many embodiments can be made, and many changes can be made in the preferred embodiments without departing from the principles of the disclosure. These and other changes in the preferred embodiments of the disclosure will be apparent to those skilled in the art from the disclosure herein, whereby it is to be distinctly understood that the foregoing descriptive matter is to be implemented merely as illustrative of the disclosure and not as a limitation.
[0120] The present disclosure provides a technical advancement in telecommunication network security and session management by enabling the Policy Control Function (PCF) to intelligently validate Home Gateway (HGW) devices based on pre-provisioned HGW-to-Customer Premise Equipment (CPE) mapping information. Unlike conventional methods that might allow HGWs to connect through any CPE, the present disclosure introduces a mechanism to restrict unauthorized HGW mobility. This is achieved by the PCF retrieving specific HGW- CPE mapping information and authorizing HGW session establishment only upon successful validation against this mapping. The present disclosure significantly enhances network security by preventing unauthorized HGW access, ensures regulatory compliance by restricting device mobility, and optimizes network resource allocation by limiting service access to designated HGW-CPE pairings in multi -HGW deployments behind a single CPE IP Protocol Data Unit (PDU) session.ADVANTAGES OF THE PRESENT DISCLOSURE
[0121] The present disclosure provides a method and a system for managing sessions in a telecommunication network (e.g., a 5G core network).
[0122] The present disclosure enhances security by mitigating risks associated with an unauthorized movement of Home Gateway (HGW) devices and potential security breaches.
[0123] The present disclosure improves service reliability by ensuring uninterrupted network connectivity and service availability for residential customers associated with the HGW devices.
[0124] The present disclosure allows network service providers to efficiently perform network management by simplifying the HGW devices provisioning, management, and troubleshooting processes.
[0125] The present disclosure enables the network service providers to adhere to regulatory requirements and maintain accurate billing practices corresponding to the HGW devices connected with the telecommunication network.
Claims
CLAIMS1. A method (500) for managing sessions in a telecommunication network (106), the method (500) comprising: receiving (502), by a receiving unit (202), a Home Gateway (HGW) session request corresponding to a HGW session from a HGW device (402) to access the telecommunication network (106) via a Customer Premise Equipment (CPE) (306), wherein a set of HGW devices (302) are connected to the CPE (306) through a Multiple Dwelling Unit (MDU) (304); retrieving (504), by a processing engine (208), an HGW to CPE mapping information associated with the HGW device (402), from a database (210), in response to receiving the HGW session request; validating (506), by a validating unit (209), the HGW device (402) based on the retrieved HGW to CPE mapping information, wherein the validation is one of a successful validation and an unsuccessful validation; and authorizing (508), by the validating unit (209), the HGW device (402) to establish the HGW session with the CPE (306), upon the successful validation of the HGW device (402).
2. The method (500) as claimed in claim 1, further comprising: receiving, by the receiving unit (202), the HGW to CPE mapping information corresponding to each HGW device (302) as an input from a network operator; and transmitting, by the processing engine (208), the HGW to CPE mapping information to a Policy Control Function (PCF) (316).
3. The method (500) as claimed in claim 2, wherein the HGW to CPE mapping information corresponding to each HGW device (302) is provisioned in a network core during an onboarding of each HGW device (302).
4. The method (500) as claimed in claim 3, wherein the onboarding of each of the HGW device (302) comprises:receiving, by the receiving unit (202), a CPE Internet Protocol (IP) Protocol Data Unit (PDU) session request corresponding to a CPE IP PDU session, from the CPE (306); establishing, by the processing engine (208), the CPE IP PDU session in the telecommunication network (106), in response to receiving the CPE IP PDU session request; and creating, by the processing engine (208), a HGW child session corresponding to each HGW device (302) over the CPE IP PDU session by assigning a unique Packet Detection Rule (PDR) Identifier (ID) to each of the HGW child session.
5. The method (500) as claimed in claim 3, further comprising: storing, by the PCF (316), the HGW to CPE mapping information in the database (210) associated with the PCF (316).
6. The method (500) as claimed in claim 1, wherein the authorization comprises: allowing, by the validating unit (209), the HGW device (402) to access the telecommunication network (106) via the CPE (306) in response to authorization.
7. The method (500) as claimed in claim 6, wherein allowing the HGW device (402) to access the telecommunication network (106) comprises: assigning, by the validating unit (209), an Internet Protocol address to the HGW device (402).
8. The method (500) as claimed in claim 1, wherein upon the unsuccessful validation of the HGW device (402), restricting, by the validating unit (209), the HGW device (402) from establishing the HGW session with the CPE (306).
9. A system (108) for managing sessions in a telecommunication network (106), the system (108) comprising: a receiving unit (202) configured to receive a Home Gateway (HGW) session request corresponding to a HGW session from a HGW device (402) to access the telecommunication network (106) via a Customer Premise Equipment (CPE) (306), wherein a set of HGW devices (302) are connected to the CPE (306) through a Multiple Dwelling Unit (MDU) (304); a processing engine (208) configured to retrieve an HGW to CPE mapping information associated with the HGW device (402), from a database (210), in response to receiving the HGW session request; a validating unit (209) configured to validate the HGW device (402) based on the retrieved HGW to CPE mapping information, wherein the validation is one of a successful validation and an unsuccessful validation; and the validating unit (209) configured to authorize the HGW device (402) to establish the HGW session with the CPE (306), upon the successful validation of the HGW device (402).
10. The system (108) as claimed in claim 9, wherein: the receiving unit (202) is configured to receive the HGW to CPE mapping information corresponding to each HGW device (302) as an input from a network operator, and the processing engine (208) is configured to transmit the HGW to CPE mapping information to a Policy Control Function (PCF) (316).
11. The system (108) as claimed in claim 10, wherein the HGW to CPE mapping information corresponding to each HGW device (302) is provisioned in a network core during an onboarding of each HGW device (302).
12. The system (108) as claimed in claim 11, wherein during the onboarding of each of the HGW device (302): the receiving unit (202) is configured to receive a CPE Internet Protocol (IP) Protocol Data Unit (PDU) session request corresponding to a CPE IP PDU session, from the CPE (306); the processing engine (208) is configured to establish the CPE IP PDU session in the telecommunication network (106), in response to receiving the CPE IP PDU session request; and the processing engine (208) is configured to create a HGW child session corresponding to each HGW device (302) over the CPE IP PDU session by assigning a unique Packet Detection Rule (PDR) Identifier (ID) to each of the HGW child session.
13. The system (108) as claimed in claim 11, wherein: the PCF (316) is configured to store the HGW to CPE mapping information in the database (210) associated with the PCF (316).
14. The system (108) as claimed in claim 9, wherein: the validating unit (209) is configured to allow the HGW device (402) to access the telecommunication network (106) via the CPE (306) in response to authorization.
15. The system (108) as claimed in claim 14, wherein: the validating unit (209) is configured to assign an Internet Protocol address to the HGW device (402) in response to allowing the HGW device (402) to access the telecommunication network (106).
16. The system as claimed in claim 9, wherein: the validating unit (209) is configured to restrict the HGW device (402) from establishing the HGW session with the CPE (306), upon the unsuccessful validation of the HGW device (402).
17. A computer program product comprising a non-transitory computer- readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to execute a method (500) for managing sessions in a telecommunication network (106), the method (500) comprising: receiving (502), by a receiving unit (202), a Home Gateway (HGW) session request corresponding to a HGW session from a HGW device (402) to access the telecommunication network (106) via a Customer Premise Equipment (CPE) (306), wherein a set of HGW devices (302) are connected to the CPE (306) through a Multiple Dwelling Unit (MDU) (304); retrieving (504), by a processing engine (208), an HGW to CPE mapping information associated with the HGW device (402), from a database (210), in response to receiving the HGW session request; validating (506), by a validating unit (209), the HGW device (402) based on the retrieved HGW to CPE mapping information, wherein the validation is one of a successful validation and an unsuccessful validation; and authorizing (508), by the validating unit (209), the HGW device (402) to establish the HGW session with the CPE (306), upon the successful validation of the HGW device (402).
Citation Information
Patent Citations
Methods and devices for facilitating a connection between devices
US20150074245A1
Enhanced residential gateway for 5g
WO2023081395A1