System and method for supporting a plurality of services in a network

The system addresses the challenge of managing multiple VLANs within a CPE EoGRE tunnel by assigning separate VLAN tags to MDU and HGW services, ensuring secure and efficient network communication.

WO2026033542A1PCT designated stage Publication Date: 2026-02-12JIO PLATFORMS LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/IN2025/051186
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-08
Filing Date
2025-08-05
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

Existing technologies fail to effectively manage multiple service VLANs within a single Customer Premises Equipment (CPE) Ethernet over Generic Routing Encapsulation (EoGRE) tunnel, lacking robust network-controlled VLAN tagging to ensure network security and prevent unauthorized access.

Method used

A system and method that assigns separate VLAN tags to Multiple Dwelling Unit (MDU) and Home Gateway (HGW) services during session creation, using network operator-defined tags to ensure secure communication.

Benefits of technology

Enables secure and efficient management of multiple service VLANs within a single CPE EoGRE tunnel, preventing unauthorized access and maintaining network security through controlled VLAN tagging.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IN2025051186_12022026_PF_FP_ABST
    Figure IN2025051186_12022026_PF_FP_ABST
Patent Text Reader

Abstract

A system (102) and a method (300) for supporting a plurality of services in a network (104) is disclosed. A user plane function (UPF) (214) receives a request message from a first network element (204) (e.g., Multiple Dwelling Unit (MDU)) connected with a second network element (206) (e.g., Customer Premises Equipment (CPE)) and communicates a session report request towards a session management function (SME) (216). The SME (216) communicates an authorization request towards a policy control function (PCF) (218). Upon receiving an authorization response from the PCF (218), the SMF (216) triggers a session modification procedure based on the received authorization response. At least one tag associated with at least one service is assigned to the first network element based on the triggered session modification procedure and establishes at least one session between the first network element and the network.
Need to check novelty before this filing date? Find Prior Art

Description

SYSTEM AND METHOD FOR SUPPORTING A PLURALITY OF SERVICES IN A NETWORKRESERVATION OF RIGHTS

[0001] A portion of the disclosure of this patent document contains material, which is subject to intellectual property rights such as, but are not limited to, copyright, design, trademark, Integrated Circuit (IC) layout design, and / or trade dress protection, belonging to Jio Platforms Limited (JPL) or its affiliates (hereinafter referred as owner). The owner has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent files or records, but otherwise reserves all rights whatsoever. All rights to such intellectual property are fully reserved by the owner.TECHNICAL FIELD

[0002] The present disclosure relates generally to the field of telecommunications. The present disclosure relates to a system and a method for supporting a plurality of services in a network. More particularly, the present disclosure relates to a system and method for supporting multiple service Virtual Local Area Networks (VLANs) inside a single Customer Premises Equipment (CPE) Ethernet over Generic Routing Encapsulation (EoGRE) tunnel.DEFINITIONS

[0003] As used in the present disclosure, the following terms are generally intended to have the meaning as set forth below, except to the extent that the context in which they are used indicates otherwise.

[0004] The expression ‘Virtual Local Area Network (VLAN)’ is a subgroup within a network. VLANs manage different types of traffic (e.g., internet, voice, or management) between Customer Premises Equipment (CPE) and Home Gateways (HGWs).

[0005] The expression “Service VLANs” are the VLANs used to separate and identify different types of services (e.g., Internet access, internet protocol television (IPTV), voice over internet protocol (VoIP), or network management) within the communication link between the CPE and the HGWs. Each service VLAN is assigned a unique VLAN ID, allowing multiple services to be transported over the Ethernet interface while keeping the traffic logically isolated.

[0006] The expression ‘Customer Premises Equipment (CPE)’ used hereinafter in the specification refers to equipment located at the subscriber's premises that provides connectivity to a network. The CPE is installed indoors or outdoors, depending on the network design and signal requirements. It connects to multiple Home Gateways (HGWs) and facilitates communication between the HGWs and the core network.

[0007] The expression ‘Home Gateway (HGW)’ used hereinafter in the specification refers to a type of Residential Gateway (RG), which is a device configured to provide communication services such as voice, data, broadcast video, and video on demand to other devices within a home. The HGW acts as an interface between the Wide Area Network (WAN) and the Local Area Network (LAN) IP environment for a consumer broadband customer, capable of routing or bridging traffic depending on its configuration. In the context of the 5G Core Network, the HGW device may function as a User Equipment (UE) or communicate via the CPE, holding a secure element and exchanging Non-Access Stratum (NAS) signalling with the core network (e.g., 5G or 4G) to establish connectivity.

[0008] The expression ‘User Plane Function (UPF)’ used hereinafter in the specification refers to a fundamental component of a 5G core network that handles data traffic routing and forwarding, policy enforcement, and Quality of Service (QoS) management for user data packets.

[0009] The expression ‘Dynamic Host Configuration Protocol (DHCP)’ used hereinafter in the specification refers to a network management protocol used to dynamically assign Internet Protocol (IP) addresses and other network configuration parameters to devices on a network, enabling them to communicate effectively.

[0010] The expression ‘Protocol Data Unit (PDU) Session’ used hereinafter in the specification refers to a session established in a 5G network that provides a user with IP connectivity for data transfer. It involves the transmission of data packets between the CPE and HGWs in the core network.

[0011] The term ‘SMF’ as used herein, refers to Session Management Function. The SMF is responsible for managing the session setup, modification, and release procedures for user equipment (UE) accessing the network.

[0012] The term ‘AMF’ as used herein, refers to Access and Mobility Management Function. The AMF is responsible for managing network access and mobility for user equipment (UE).

[0013] The term ‘PCF’ as used herein, refers to policy control function. The PCF is responsible for managing and enforcing policy decisions related to network resources, quality of service (QoS), and access control.

[0014] The term ‘CHF’ as used herein, refers to charging function. The CHF is responsible for handling charging and billing functions for subscriber services. The CHF supports service providers in implementing flexible billing models, enforcing charging policies, and maintaining transparency in subscriber billing and usage. The CHF is essential for operators to effectively monetize their services while providing customers with clear and reliable billing information.

[0015] The term ‘EoGRE tunnel’ as used herein, refers to Ethernet over Generic Routing Encapsulation. The EoGRE tunnel enables Customer Premises Equipment(CPE) devices to bridge the Ethernet traffic from an end host and encapsulate the traffic in Ethernet packets over a GRE tunnel. The GRE tunnel terminates on a service provider broadband network gateway, which then terminates the end host traffic and manages the subscriber session for the end host.

[0016] The term ‘PoE’ as used herein, refers to Power over Ethernet, is a technology for implementing wired Ethernet local area networks (LANs) that enables the electrical current necessary for operating each device to be carried by Ethernet data cables instead of standard electrical power cords and wiring.

[0017] The term ‘MDU’ as used herein, refers to Multiple Dwelling Unit. The MDU is installed in residential buildings and facilitates network connectivity to the end users. The residential building or complex contains multiple separate housing units, such as apartments, condominiums, or dormitories. The deployment of MDU may involve centralized or per-unit CPE, with shared access infrastructure like fiber splitters or Ethernet switches.

[0018] The term ‘5GCN’ as used herein, refers to a fifth generation (5G) core network. The 5GCN provides connectivity and services to end-users (such as mobile devices and loT devices). It is designed to support higher data rates, lower latency, and massive connectivity compared to previous generations (e.g., 4G / LTE).

[0019] The term ‘N4 session’ as used herein, is a bridge between the control plane and the user plane in a network. N4 session management procedures are used to control the functionality of the UPF. The SMF creates, updates, and removes the N4 session context in the UPF.

[0020] The term ‘N7 session’ as used herein, refers to establishment and management of a communication session between the PCF and SMF. N7 session enables the PCF to exchange policy information, apply policy decisions based on real-time network conditions and subscriber profiles, and manage QoS parameters for data sessions with SMF.

[0021] The term ‘N40 session’ as used herein, refers to the communication and interaction that occurs between the SMF and the CHF via the N40 interface. This session enables the SMF to coordinate with the CHF to set up and manage data sessions, ensuring that data flows efficiently between UEs and external networks or services while maintaining Quality of Service (QoS) requirements.

[0022] The term ‘Ethernet session’ as used herein, refers to a period during which devices communicate over an Ethernet network, adhering to established protocols and transmitting data packets between connected devices. Ethernet is a widely used standard for connecting devices in a local area network (LAN).

[0023] These definitions are in addition to those expressed in the art.BACKGROUND

[0024] The following description of related art is intended to provide background information pertaining to the field of the disclosure. This section may include certain aspects of the art that may be related to various features of the present disclosure. However, it should be appreciated that this section be used only to enhance the understanding of the reader with respect to the present disclosure, and not as admissions of prior art.

[0025] As internet usage expanded and broadband services became more prevalent, there was a growing demand for efficient and reliable management of multiple Home Gateway (HGW) sessions in a network. The HGW is a device that connects a local home network to the internet. It typically serves as a central hub for various network services, including routing, firewall protection, and network address translation (NAT). The HGW allows multiple devices within a home, such ascomputers, smartphones, smart TVs, and loT devices, to access the Internet through a single IP address provided by the Internet service provider (ISP). The HGW manages local network traffic and ensures secure and efficient communication between devices within the home network and external networks.

[0026] In modem networking environments, multiple HGWs may be connected behind a single Customer Premises Equipment (CPE) Internet Protocol (IP) Protocol Data Unit (PDU) session. The CPE refers to network equipment that is installed outside / inside the customer’s premises. The CPE is used to connect the customer network to the network infrastructure of the service provider. With the advent of 5G technology, supporting multiple service Virtual Local Area Networks (VLANs) within a single CPE Ethernet over Generic Routing Encapsulation (EoGRE) tunnel has become a critical requirement. The EoGRE is a tunneling protocol that allows Ethernet frames to be encapsulated and transmitted over an IP network, facilitating the creation of virtual point-to-point links.

[0027] The primary challenge in such scenarios is the management of multiple service VLANs for different services inside a single CPE EoGRE tunnel. Each service, such as HGW service and Multiple Dwelling Unit (MDU) service, requires distinct VLAN tags to ensure proper separation and security. VLAN tagging allows for the segregation of network traffic, providing enhanced security and efficient network management. Network security is retained with network-controlled VLAN tags, which prevent unauthorized access and ensure that only operator-defined VLAN tags are used in the network.

[0028] In scenarios involving multiple HGW Ethernet sessions behind a single CPE IP PDU session, supporting multiple service VLANs for different services inside a single CPE EoGRE tunnel is essential. The 5G core network supports CPE, HGW and MDU sessions. Multiple HGWs are connected to the CPE using MDU, which usesPower over Ethernet (PoE) cables, allowing both the MDU and CPE to draw power from the HGWs connected to their LAN interfaces.

[0029] The network must ensure that VLAN tags are controlled and managed effectively to maintain network security. Existing technologies do not adequately address the need for network-controlled VLAN tagging for separate services, which is crucial for preventing unauthorized access and ensuring secure communication.

[0030] There is, therefore, a need in the art to provide a method and system that effectively manages multiple service VLANs within a single CPE EoGRE tunnel while ensuring network security through controlled VLAN tagging.OBJECTIVES OF THE PRESENT DISCLOSURE

[0031] Some of the objectives of the present disclosure, which at least one embodiment herein satisfies, are as follows:

[0032] An objective of the present disclosure is to provide a system and a method that supports multiple service Virtual Local Area Network(s) (VLANs) for different services inside a single Customer Premises Equipment (CPE) Ethernet over Generic Routing Encapsulation (EoGRE) tunnel.

[0033] Another objective of the present disclosure is to enable remote management of the Multiple Dwelling Unit (MDU).

[0034] Another objective of the present disclosure is to assign separate VLAN tags to the MDU and the HGWs during session creation.

[0035] Another objective of the present disclosure is to ensure network security by using network operator-defined VLAN tags to the MDU and the HGWs.

[0036] Another objective of the present disclosure is to implement network-controlled VLAN tagging for separate services such as Home Gateway (HGW) service and Multiple Dwelling Unit (MDU) service.

[0037] Another objective of the present disclosure is to support different service VLANs for the HGW service and the MDU service within the same CPE EoGRE tunnel.

[0038] Other objectives and advantages of the present disclosure will be more apparent from the following description, which is not intended to limit the scope of the present disclosure.SUMMERY

[0039] In an exemplary embodiment, a method for supporting a plurality of services in a network is disclosed. The method comprises receiving, by a user plane function (UPF), a request message from a first network element connected with a second network element. The method comprises communicating, by the UPF, a session report request (SRR) towards a session management function (SMF). The method comprises communicating, by the SMF, an authorization request towards a policy control function (PCF). The method comprises receiving, by the SMF, an authorization response from the PCF. The method comprises triggering, by the SMF, a session modification procedure based on the received authorization response. The method comprises assigning, by the UPF, at least one Virtual Local Area Network (VLAN) tag associated with at least one service to the first network element based on the triggered session modification procedure. The method comprises establishing, by the UPF, at least one Ethernet session between the first network element and the network based on the at least one assigned VLAN tag.

[0040] In some embodiments, the first network element is a Multiple Dwelling Unit (MDU) and the second network element is a Customer Premises Equipment (CPE).

[0041] In some embodiments, the method comprises retrieving, by the PCF, mapping information associated with the first network element and the second network element in response to receiving the authorization request from the SMF. The method comprises identifying, by the PCF, the at least one VLAN tag based on the retrieved mapping information. The method comprises transmitting, by the PCF, the at least one identified VLAN tag in the authorization response to the SMF.

[0042] In some embodiments, the method comprises creating at least one Home Gateway (HGW) session between the network and at least one HGW device over an Internet Protocol (IP) Protocol Data Unit (PDU) session of the second network element based on at least one HGW session request received by the UPF from the at least one HGW device. The at least HGW device is connected to the second network element through the first network element.

[0043] In some embodiments, the method comprises assigning, by the UPF, a default VLAN tag to each of the at least one HGW device based on the established at least one HGW session.

[0044] In some embodiments, the request message received by the UPF from the first network element includes at least one of a Dynamic Host Configuration Protocol version 4 (DHCPv4) discover message and a DHCPv6 solicit message.

[0045] In another exemplary embodiment, a system for supporting a plurality of services in a network is disclosed. The system comprises a user plane function (UPF). The UPF comprising a processing engine configured to receive a request message from a first network element connected with a second network element and communicate a session report request (SRR) towards a session management function (SMF). The SMF is configured to communicate an authorization request towards a policy control function (PCF), receive an authorization response from the PCF and trigger a session modification procedure based on the received authorization response. The processingengine is configured to assign at least one Virtual Local Area Network (VLAN) tag associated with at least one service to the first network element based on the triggered session modification procedure and establish at least one Ethernet session between the first network element and the network based on the at least one assigned VLAN tag.

[0046] In yet another exemplary embodiment, a computer program product comprising a non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to execute a method for supporting a plurality of services in a network is disclosed. The method comprises receiving, by a user plane function (UPF), a request message from a first network element connected with a second network element. The method comprises communicating, by the UPF, a session report request (SRR) towards a session management function (SMF). The method comprises communicating, by the SMF, an authorization request towards a policy control function (PCF). The method comprises receiving, by the SMF, an authorization response from the PCF. The method comprises triggering, by the SMF, a session modification procedure based on the received authorization response. The method comprises assigning, by the UPF, at least one Virtual Local Area Network (VLAN) tag associated with at least one service to the first network element based on the triggered session modification procedure. The method comprises establishing, by the UPF, at least one Ethernet session between the first network element and the network based on the at least one assigned VLAN tag.BRIEF DESCRIPTION OF THE ACCOMPANYING DRAWING

[0047] The accompanying drawings, which are incorporated herein, and constitute a part of this disclosure, illustrate exemplary embodiments of the disclosed methods and systems in which like reference numerals refer to the same parts throughout the different drawings. Components in the drawings are not necessarily to scale; emphasis is instead being placed upon clearly illustrating the principles of the present disclosure.Some drawings may indicate the components using block diagrams and may not represent the internal circuitry of each component. It will be appreciated by those skilled in the art that disclosure of such drawings includes disclosure of electrical components, electronic components, or circuitry commonly used to implement such components.

[0048] FIG. 1A illustrates an exemplary network architecture of a system for supporting a plurality of services in a network, in accordance with an embodiment of the present disclosure.

[0049] FIG. IB illustrates an exemplary block diagram of the system for supporting the plurality of services in the network, in accordance with an embodiment of the present disclosure.

[0050] FIG. 2A illustrates an exemplary system architecture of the system for supporting the plurality of services in the network, in accordance with an embodiment of the present disclosure.

[0051] FIG. 2B illustrates an exemplary flow diagram of a method for supporting the plurality of services in the network, in accordance with an embodiment of the present disclosure.

[0052] FIG. 3 illustrates another exemplary flow diagram of a method for supporting the plurality of services in the network, in accordance with an embodiment of the present disclosure.

[0053] FIG. 4 illustrates an exemplary computer system in which or with which the embodiments of the present disclosure may be implemented.

[0054] The foregoing shall be more apparent from the following more detailed description of the disclosure.LIST OF REFERENCE NUMERALS100 A - Network Architecture102 -System104 -Network106 - Centralized Server108-1, 108-2... 108-N - Computing devices / User Equipments110-1, 110-2... 110-N - Users100B - Block diagram112 - Processor(s)114 - Memory116 - Interface(s)118 - Processing Engine120 - Database200A - System Architecture202-1, 202-2, ... 202-N - Home Gateways (HGWs)204 - Multiple Dwelling Unit (MDU)206 - Customer Premises Equipment (CPE)208 - Access and Mobility Management Function (AMF)210 - Authentication Server Function (AUSF)212 - Unified Data Management (UDM)214 - User Plane Function (UPF)216 - Session Management Function (SMF)218 - Policy Control Function (PCF)219 - Internet220 - Charging Function (CHF)200B - Method Flow Diagram222 - Other Fifth generation (5G) core network (5GCN)300 - Method Flow Diagram400 - A computer system410 - External Storage Device420 - Bus430 - Main Memory440 - Read Only Memory450 - Mass Storage Device460 - Communication Port470 - ProcessorDETAILED DESCRIPTION

[0055] In the following description, for the purposes of explanation, various specific details are set forth in order to provide a thorough understanding of embodiments of the present disclosure. It will be apparent, however, that embodiments of the present disclosure may be practiced without these specific details. Several features described hereafter can each be used independently of one another or with any combination of other features. An individual feature may not address any of the problems discussed above or might address only some of the problems discussed above. Some of the problems discussed above might not be fully addressed by any of the features described herein. Example embodiments of the present disclosure are described below, as illustrated in various drawings in which like reference numerals refer to the same parts throughout the different drawings.

[0056] The ensuing description provides exemplary embodiments only, and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, the ensuing description of the exemplary embodiments will provide those skilled in the art with an enabling description for implementing an exemplary embodiment. It should be understood that various changes may be made in the function and arrangement of elements without departing from the spirit and scope of the disclosure as set forth.

[0057] Specific details are given in the following description to provide a thorough understanding of the embodiments. However, it will be understood by one of ordinary skill in the art that the embodiments may be practiced without these specific details. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form in order not to obscure the embodiments in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail in order to avoid obscuring the embodiments.

[0058] Also, it is noted that individual embodiments may be described as a process that is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. Although a flowchart may describe the operations as a sequential process, many of the operations can be performed in parallel or concurrently. In addition, the order of the operations may be re-arranged. A process is terminated when its operations are completed but could have additional steps not included in a figure. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination can correspond to a return of the function to the calling function or the main function.

[0059] The word “exemplary” and / or “demonstrative” is used herein to mean serving as an example, instance, or illustration. For the avoidance of doubt, the subject matter disclosed herein is not limited by such examples. In addition, any aspect or design described herein as “exemplary” and / or “demonstrative” is not necessarily to be construed as preferred or advantageous over other aspects or designs, nor is it meant to preclude equivalent exemplary structures and techniques known to those of ordinary skill in the art. Furthermore, to the extent that the terms “includes,” “has,” “contains,” and other similar words are used in either the detailed description or the claims, such terms are intended to be inclusive like the term “comprising” as an open transition word without precluding any additional or other elements.

[0060] Reference throughout this specification to “one embodiment” or “an embodiment” or “an instance” or “one instance” means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present disclosure. Thus, the appearances of the phrases “in one embodiment” or “in an embodiment” in various places throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0061] The terminology used herein is to describe particular embodiments only and is not intended to be limiting the disclosure. As used herein, the singular forms “a”, “an”, and “the” are intended to include the plural forms as well, unless the context indicates otherwise. It will be further understood that the terms “comprises” and / or “comprising,” when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein, the term “and / or” includes any combinations of one or more of the associated listed items. It should be noted that the terms “mobile device”, “user equipment”, “user device”, “communication device”, “device” and similar terms are used interchangeably for the purpose of describing the invention. These terms are not intended to limit the scope of the invention or imply any specific functionality or limitations on the described embodiments. The use of these terms is solely for convenience and clarity of description. The invention is not limited to any particular type of device or equipment, and it should be understood that other equivalent terms or variations thereof may be used interchangeably without departing from the scope of the invention as defined herein.

[0062] While considerable emphasis has been placed herein on the components and component parts of the preferred embodiments, it will be appreciated that manyembodiments can be made and that many changes can be made in the preferred embodiments without departing from the principles of the disclosure. These and other changes in the preferred embodiment, as well as other embodiments of the disclosure, will be apparent to those skilled in the art from the disclosure herein, whereby it is to be distinctly understood that the foregoing descriptive matter is to be interpreted merely as illustrative of the disclosure and not as a limitation.

[0063] As Internet usage and broadband availability grew, managing multiple Home Gateway (HGW) sessions efficiently became increasingly important, especially as HGWs serve as key access points between home networks and the Internet. In modern networks in 5G deployment, multiple HGWs may operate behind a single Customer Premises Equipment (CPE) IP session, which connects customer networks to the service provider. To support different services such as the HGWs and Multiple Dwelling Unit (MDU) services, the use of Virtual LANs (VLANs) within a single Ethernet over Generic Routing Encapsulation (EoGRE) tunnel has become essential, allowing separation and secure transmission of network traffic. However, existing technologies fall short in enabling strict network-controlled VLAN tagging, which is crucial for preventing unauthorized access and maintaining secure communication. Therefore, there is a growing need for a system that manages multiple service VLANs within a single CPE EoGRE tunnel while ensuring robust, operator-defined control over VLAN tags.

[0064] In an embodiment, the present disclosure provides a system and a method for supporting multiple services for the MDU and the HGWs in a network. The present disclosure overcomes the aforementioned limitations by assigning separate VLAN tags to the MDU and the HGWs. The VLAN tags are informed to the UPF during session creation for the MDU and the HGWs. In this way, network security is ensured as only network operator-defined VLAN tags are allowed to support multiple services for the MDU and the HGWs in the network.

[0065] The various embodiments throughout the disclosure will be explained in more detail with reference to FIG. 1 A- FIG. 4.

[0066] FIG. 1A illustrates an exemplary network architecture (100A) of a system (102) for supporting a plurality of services in a network (104), in accordance with an embodiment of the present disclosure.

[0067] Referring to FIG. 1A, the network architecture (100 A) is implemented to support the plurality of services in the network (104). The network architecture 100 may be applied on Fixed Wireless Access (FWA) deployments, where wireless cellular technology provides broadband connectivity to fixed subscriber locations. In an embodiment, the system (102) is connected to the network (104), which is further connected to at least one user equipment (108-1, 108-2, ... 108-N) (collectively referred to as user equipment (108)) associated with one or more users (110-1, 110-2, ... 110- N) (collectively referred to as users (110)). The user equipment (108) may be personal computers, laptops, tablets, wristwatches, or any custom-built computing device integrated within a modern diagnostic machine that connects to a network as an loT (Internet of Things) device. In an embodiment, the user equipment (108) may be referred to as User Equipment (UE) or user device. Accordingly, the terms “user equipment” and “User Equipment” may be used interchangeably throughout the disclosure. In an embodiment, each of the UE (108) may have a unique identifier attribute associated therewith. In an embodiment, the unique identifier attribute may be indicative of at least one of a Mobile Station International Subscriber Directory Number (MSISDN), International Mobile Equipment Identity (IMEI) number, an International Mobile Subscriber Identity (IMSI), a Subscriber Permanent Identifier (SUPI), and the like.

[0068] In an embodiment, the UE (108) may include smart devices operating in a smart environment, for example, an Internet of Things (loT) system. In such anembodiment, the UE (108) may include, but is not limited to, smart phones, smart watches, smart sensors (e.g., mechanical, thermal, electrical, magnetic, etc.), networked appliances, networked peripheral devices, a networked lighting system, communication devices, networked vehicle accessories, networked vehicular devices, smart accessories, tablets, smart television (TV), computers, a smart security system, a smart home system, other devices for monitoring or interacting with or for the users and / or entities, or any combination thereof. A person of ordinary skill in the art will appreciate that the UE (108) may include, but is not limited to, intelligent, multisensing, network- connected devices, that integrates seamlessly with each other and / or with a central server or a cloud-computing system or any other device that is network- connected.

[0069] In an embodiment, the UE (108) may include, but is not limited to, a handheld wireless communication device (e.g., a mobile phone, a smart phone, a phablet device, and so on), a wearable computer device (e.g., a head-mounted display computer device, a head-mounted camera device, a wristwatch computer device, and so on), a Global Positioning System (GPS) device, a laptop computer, a tablet computer, or another type of portable computer, a media playing device, a portable gaming system, and / or any other type of computer device with a wireless communication capabilities, and the like. In an embodiment, the UE (108) may include, but is not limited to, any electrical, electronic, electro-mechanical, or an equipment, or a combination of one or more of the above devices such as virtual reality (VR) devices, augmented reality (AR) devices, a laptop, a general-purpose computer, a desktop, a personal digital assistant, a tablet computer, a mainframe computer, or any other computing device. In addition, the UE (108) may include one or more in-built or externally coupled accessories including, but not limited to, a visual aid device such as a camera, an audio aid, a microphone, a keyboard, and input devices for receiving input from the user (110) or an entity such as touch pad, a touch enabled screen, an electronic pen, and the like. A person of ordinary skill in the art will appreciate that the UE (108)may not be restricted to the mentioned devices and various other devices may be used.

[0070] As will be appreciated, the Home Gateway (HGW) may correspond to the UE (108). In an aspect, the users (110) are network operators or field engineers. Further, with each CPE, a set of HGW devices may be connected. A person of ordinary skill in the art will appreciate that the terms “CPE” and “UE” may be used interchangeably throughout the disclosure. As will be appreciated, the CPE is a specialized network device that may be installed outdoors and indoors at customer locations to facilitate connectivity and network services. In an embodiment, examples of the CPE include a Fifth Generation (5G) or a Fourth Generation (4G) outdoor customer premise equipment which can provide a high throughput broadband connectivity to end users. The CPE can also have a functionality to connect to the 5G Non-Terrestrial Network (NTN). In this context the CPE is no longer dedicated to customer premises but the set of HGWs in individual customers premise (i.e., homes) connects to a single CPE using a Multiple Dwelling Unit (MDU). In that sense the CPE is shared across multiple homes, and the CPE becomes a network element for an FWA deployment serving multiple subscribers. In an embodiment, the UE 104 may be deployed as a home gateway device (HGW) connected to a customer premise equipment (CPE) for use in a FWA environment. In an example, the UE 104 may be statically located at a fixed customer premises and connected to the core network via a wireless access network.

[0071] Further, the network (104) may be configured with a centralized server (106) that stores compiled data. In an embodiment, the system (102) may receive at least one input data from the users (110) via the at least one UE (108). In an embodiment, the UE (108) may involve the collection, analysis, and sharing of data received from the system (102) via the network (104).

[0072] In FIG. 1A, the UE (108) may communicate with the system (102) via thenetwork (104). In an embodiment, the network (104) may include at least one of a Fifth Generation (5G) network, a Sixth Generation (6G) network, or the like. The network (104) may enable the UEs (108) to communicate with other devices in the network architecture (100A) and / or with the system (102). The network (104) may include a wireless card or some other transceiver connection to facilitate this communication. In another embodiment, the network (104) may be implemented as, or include any of a variety of different communication technologies such as a wide area network (WAN), a local area network (LAN), a wireless network, a mobile network, a Virtual Private Network (VPN), the Internet, the Public Switched Telephone Network (PSTN), or the like. In an embodiment, the network (104) may include, by way of example but not limitation, at least a portion of one or more networks having one or more nodes that transmit, receive, forward, generate, buffer, store, route, switch, process, or a combination thereof, etc. one or more messages, packets, signals, waves, voltage or current levels, some combination thereof, or so forth. In an embodiment, the network 106 includes at least one of the 4G network, the 5G network, the 6G network, or the like, providing wireless access for FWA services.

[0073] In an embodiment, the UE (108) (i.e., CPE) may be communicatively coupled with the system (102) over the network (104). The system (102) may receive a connection request from the UE (108). The system (102) may send an acknowledgment of the connection request to the UE (108). The UE (108) may transmit a plurality of signals in response to the connection request to the system (102). The system (102) is configured to support a plurality of services in the network (104), as explained in detail in FIG. IB.

[0074] Although FIG. 1A shows exemplary components of the network architecture (100A), in other embodiments, the network architecture (100A) may include fewer components, different components, differently arranged components, or additional functional components than depicted in FIG. 1A. Additionally, oralternatively, one or more components of the network architecture (100A) may perform functions described as being performed by one or more other components of the network architecture (100 A).

[0075] FIG. IB illustrates an example block diagram (100B) of the system (102) for supporting the plurality of services in the network (104), in accordance with an embodiment of the present disclosure. FIG. IB is explained in conjunction with FIG. 1A.

[0076] Referring to FIG. IB, in an embodiment, the system (102) may include one or more processor(s) (112). The one or more processor(s) (112) may be implemented as one or more microprocessors, microcomputers, microcontrollers, digital signal processors, central processing units, logic circuitries, and / or any devices that process data based on operational instructions. Among other capabilities, the one or more processor(s) (112) may be configured to fetch and execute computer-readable instructions stored in a memory (114) of the system (102). The memory (114) may be configured to store one or more computer-readable instructions or routines in a non- transitory computer-readable storage medium, which may be fetched and executed to create or share data packets over a network service. The memory (114) may comprise any non-transitory storage device including, for example, volatile memory such as random-access memory (RAM), or non-volatile memory such as erasable programmable read-only memory (EPROM), flash memory, and the like.

[0077] In an embodiment, the system (102) may include an interface(s) (116). The interface(s) (116) may comprise a variety of interfaces, for example, interfaces for data input and output devices (I / O), storage devices, and the like. The interface(s) (116) may facilitate communication through the system (102). The interface(s) (116) may also provide a communication pathway for one or more components of the system (102). Examples of such components include, but are not limited to, processing engine(s)(118) and a database (120).

[0078] In an embodiment, the processing engine(s) (118) may be implemented as a combination of hardware and programming, for example, programmable instructions, to implement one or more functionalities of the processing engine(s) (118). In examples described herein, such combinations of hardware and programming may be implemented in several different ways. For example, the programming for the processing engine(s) (118) may be processor-executable instructions stored on a non- transitory machine-readable storage medium and the hardware for the processing engine(s) (118) may comprise a processing resource, for example, one or more processors, to execute such instructions. In the present examples, the machine-readable storage medium may store instructions that, when executed by the processing resource, implement the processing engine(s) (118). In such examples, the system (102) may comprise the machine-readable storage medium storing the instructions and the processing resource to execute the instructions, or the machine-readable storage medium may be separate but accessible to the system (102) and the processing resource. In other examples, the processing engine(s) (118) may be implemented by electronic circuitry.

[0079] In an embodiment, database (120) may comprise data that may be either stored or generated as a result of functionalities implemented by any of the components of the processor (112) or the processing engine (118). In an embodiment, the database (120) may be separate from the system (102).

[0080] A block diagram (100B) of the system (102), as described in detail with reference to FIG. IB, for supporting multiple services in the network (104), as it may be implemented.

[0081] A Customer Premises Equipment (CPE) (i.e., second network element) (i.e., CPE (206) as shown in FIG. 2) establishes an Internet Protocol (IP) Protocol DataUnit (PDU) session in the network (e.g., 5G core network) (104). In an aspect, the CPE is a fixed wireless device installed outside a customer's home or business to provide high-speed internet access using networks in fixed wireless access (FWA) deployments. In an aspect, the fixed wireless access (FWA) is a method of providing broadband internet to homes or businesses using wireless technology instead of physical cables (e.g., fiber or digital subscriber line (DSL)). In an embodiment, the CPE may be referred to as the second network element. Accordingly, the terms “CPE” and “Second network element” may be used interchangeably throughout the disclosure. In an embodiment, the second network element is connected with the network (104) via the IP PDU session. The IP PDU session of the CPE functions as a parent session.

[0082] A Multiple Dwelling Unit (MDU) is connected to the CPE. In an aspect, the MDU refers to a network unit responsible for providing internet access to residents. The MDU is designed to accommodate multiple separate housing units (e.g., Home Gateways (HGWs)), and wireless networks within the buildings aim to deliver secure and reliable connectivity to each unit (e.g., each HGW). In an embodiment, the MDU may be referred to as the first network element. Accordingly, the terms “MDU” and “First network element” may be used interchangeably throughout the disclosure.

[0083] An Ethernet session is created for the MDU over the established IP PDU session of the CPE. The IP PDU session acts as a parent transport bearer over which the Ethernet session for the MDU is created. The Ethernet session of the MDU functions as a child session for the IP PDU session. The child session is uniquely identified by Packet Detection Rule (PDR) ID and is managed independently over the same N4 session between a User Plane Function (UPF) and a Session Management Function (SMF).

[0084] One or more Home Gateways (HGWs) are connected to the CPE through the MDU. One or more Ethernet sessions corresponding to the one or more HGWs arecreated over the established IP PDU session of the CPE. The one or more Ethernet sessions corresponding to the one or more HGWs function as child sessions for the parent session (i.e., the IP PDU session) of the CPE. The child sessions are uniquely identified by the PDR IDs and are managed independently over the same N4 session between the UPF and the SMF. The child Ethernet sessions provide individualized IP connectivity for each HGW behind the CPE.

[0085] In an embodiment, the PDU session between the CPE and the network (104) is considered the parent session, and each Ethernet session created for the HGW is considered the child session of the PDU session. The child sessions are uniquely identified by Packet Detection Rule (PDR) IDs and are managed independently over the same N4 session between a user plane function (UPF) and a Session Management Function (SMF).

[0086] In an aspect, the system may comprise the UPF (i.e., UPF (214) as shown in FIG. 2A). The UPF (214) comprises the processing engine (118).

[0087] In an aspect, the processing engine (118) is configured to support a plurality of services in the network (104). In an aspect, the plurality of services comprises HGW services and MDU services. The HGW services comprise services corresponding to the users. The MDU services comprise self-management services. The HGW services comprise, but are not limited to, internet access for providing wired (Ethernet) and wireless (Wi-Fi) internet connectivity, wireless- fidelity (wi-fi) services for providing Wi-Fi coverage for home devices, voice services such as telephone service, internet protocol television (IPTV) / video streaming services for integration with set-top boxes or direct streaming to smart TVs, smart home / internet of things (loT) services for management of smart home devices, user interface for configuration such as web-based or app-based access to configure and monitor the gateway, security services such as basic firewall, intrusion detection, and secure guest networks,firmware upgrades for automatic or manual updates to maintain performance and security. In an aspect, the self-management services of the MDU comprise, but are not limited to, internal management and operational services that help maintain, monitor, and control the MDU itself. The management and operational services comprise, but are not limited to, internal components (e.g., memory usage, processing unit load, etc.) monitoring, fault detection and monitoring, remote configuration management, firmware upgrade, security management and power management.

[0088] The processing engine (118) may be configured to receive a request message from a first network element (i.e., MDU) connected with the second network element (i.e., CPE). In an aspect, the UPF is a network function responsible for handling data traffic (e.g., real-time charging, usage monitoring, etc.).

[0089] In an embodiment, the request message received by the UPF from the first network element includes at least one of a Dynamic Host Configuration Protocol version 4 (DHCPv4) discover message and a DHCPv6 solicit message. In an embodiment, the DHCPv4 discover message is a message sent by the MDU to the UPF to locate the CPE and request IPv4 configurations in the network. In an aspect, the DHCPv6 solicit message is a message sent by the MDU to discover the CPE and request IPv6 configuration parameters.

[0090] The processing engine (118) may be configured to communicate a session report request (SRR) towards the SMF (i.e., SMF (216) as shown in FIG. 2B). In an aspect, the SMF is a network function responsible for managing PDU sessions (data sessions), IP address assignment, selecting and controlling UPFs, enforcing quality of service (QoS) and session policies, and charging support. In an aspect, the session report request (SRR) is a message sent by the UPF to inform the SMF about the detection of an MDU-related event (e.g., initiation of a new MDU session or the appearance of associated service traffic). The session report request (SRR) comprises,but is not limited to, an MDU identifier (MDU ID), a session endpoint identifier referencing the active IP PDU session of the CPE, a report type (e.g., event trigger, start of service, unknown VLAN detection), and an event identifier (ID) (e.g., service start, unknown VLAN, or media access control (MAC) address change, etc.).

[0091] The SMF may be configured to communicate an authorization request towards a policy control function (PCL) (e.g., PCL (218) as shown in PIG. 2A). In an aspect, the PCF is a network function responsible for traffic prioritization and enforcement of plans and policies. In an aspect, upon receiving the session report request from the UPF, the SMF is configured to send the authorization request to the PCF to authorize the MDU for the network services and apply policies to access the network services. The PCF performs the authorization of the MDU. In an aspect, the authorization request may be a policy create request communicated by the SMF to the PCF to perform authorization of the MDU and apply policies to the MDU.

[0092] To perform the authorization, the PCF is configured to map information associated with the first network element (i.e., MDU) and the second network element (e.g., CPE) in response to receiving the authorization request from the SMF. In an aspect, the PCF maps information of the MDU with the CPE. The mapping comprises, but is not limited to, device identifier mapping (e.g., media access control (MAC) address, device identifier, etc.) and service requirement mapping (e.g., quality of service (QoS), policies, rules). Based on the mapping, the PCF determines whether the device type is the MDU or the HGW.

[0093] Further, the PCF is configured to identify at least one VLAN tag based on the retrieved mapping information. In an aspect, upon determining that the device is the MDU, the PCF is configured to identify the VLAN tag (e.g., VLAN tag = Y). In an aspect, VLAN tag = Y is an operator-defined VLAN tag for the MDU. In an aspect, upon determining that the device is the HGW, the PCF is configured to identify a1 default tag as the VLAN tag for the HGW.

[0094] After performing the authorization, the PCF transmits the at least one identified VLAN tag in the authorization response to the SMF. In an aspect, the VLAN tag refers to a metadata field inserted into an Ethernet frame to identify and differentiate network devices (e.g., MDU or Home Gateway (HGW)). In an aspect, after identifying the VLAN tag, the PCF is configured to send the authorization response. The authorization response comprises the device type = MDU and the VLAN tag = Y. In this way, the device type and the VLAN tag provided in the authorization response are used to manage service VLANs for multiple services associated with the devices (e.g., MDU or HGW). In an aspect, the authorization response may be a policy create response comprising policy information for the MDU.

[0095] The SMF may be configured to receive an authorization response from the PCF. In an embodiment, the authorization response received from the PCF includes at least one of device type of the first network element and the at least one VLAN tag associated with the at least one service. For example, the authorization response comprises the device type = MDU and the VLAN tag = Y. In an aspect, the at least one service comprises a service corresponding to the MDU or the HGW. For example, VLAN tag = Y1 for security management service of the MDU, VLAN tag = Y2 for configuration management service of the MDU, VLAN tag = Y3 for firmware update service of the MDU.

[0096] In an aspect, the SMF may be configured to communicate a session report response to the UPF. In an aspect, upon receiving the authorization response from the PCF, the SMF is configured to communicate the session report response to the UPF. The session report response comprises, but is not limited to, an outcome of the session report request (e.g., request accepted, request rejected, etc.), forwarding action rules (FARs) for directing how MDU traffic is forwarded, quality of service (QoS)enforcement rules for specifying bandwidth, delay handling, etc., for the MDU session, event acknowledgement, etc.

[0097] The SMF may be configured to trigger a session modification procedure based on the received authorization response. In an aspect, the session modification procedure between the SMF and the UPF is used to update or modify the PDU session context, such as when new MDU service traffic is detected or when policy / QoS rules change.

[0098] The processing engine (118) may be configured to assign at least one VLAN tag associated with at least one service to the first network element based on the triggered session modification procedure. In an aspect, the MDU is provisioned with the VLAN tag. The VLAN tag is provided to the UPF during MDU session creation. Based on the triggered session modification procedure, the UPF is configured to assign the VLAN tag associated with the service to the first network element (i.e., MDU). In this way, network security is ensured as only operator-defined VLAN tags are allowed in the network.

[0099] The processing engine (118) may be configured to establish at least one session between the first network element and the network (104) based on the at least one assigned VLAN tag. In an aspect, the session (i.e., Ethernet session) is established between the first network element (i.e., MDU) and the network (104).

[0100] In an embodiment, the processing engine (118) may be configured to create at least one Home Gateway (HGW) session between the network (104) and at least one HGW device (e.g., HGW (202) as shown in FIG. 2A) over the IP PDU session of the second network element (i.e., CPE) based on at least one HGW session request received by the UPF from the at least one HGW device. In an aspect, upon receiving the HGW session request from the HGW device, authorization of the at least one HGW is performed by the PCF. During the session creation, the UPF is configured to assigna default VLAN tag (e.g., VLAN tag = X) to the HGW device. In an aspect, VLAN tag = X is an operator- defined tag for the HGW device. The UPF is configured to create the HGW session between the network and the HGW device over the IP PDU session of the CPE. The at least HGW device is connected to the second network element (i.e., CPE) through the first network element (i.e., MDU).

[0101] In this way, different VLAN tags are assigned based on the device types (i.e., default VLAN tag =X for the HGW and VLAN tag = Y for the MDU). Different VLAN tags help in supporting the plurality of services associated with the devices (i.e., MDUs and HGWs). For example, different services corresponding to the MDU comprise an internet service, a voice call service, a video streaming service, a traffic and security management. Different services corresponding to the HGWs comprise a broadband / internet service, a voice call service, a video service, a home network management, a smart home service, an internet of things (loT) service, and a security service. So, VLAN tag assignment for the MDU, for example, VLAN tag = Y1 for security services of the MDU, VLAN tag = Y2 for configuration management of the MDU, VLAN tag = Y3 for fault detection services of the MDU, and VLAN tag = Y4 for internal component management services (e.g., central processing unit (CPU) load, memory usage). VLAN tag assignment for the HGWs, for example, VLAN tag = XI for broadband / internet service to users, VLAN tag = X2 for voice call service to users, VLAN tag = X3 for home network management service to users, VLAN tag = X4 for smart home service to users, VLAN tag = X5 for loT service to users, and VLAN tag = X6 for security service to users.

[0102] Thus, the various embodiments of the present disclosure ensure network security by using network-controlled VLAN tags and enables remote management of the MDU. The system (102) supports different service VLANs for HGW and MDU within the same CPE EoGRE tunnel, thereby enhancing network efficiency and security.

[0103] FIG. 2A illustrates an exemplary system architecture (200A) of the system (102) for supporting the plurality of services in the network (104), in accordance with an embodiment of the present disclosure. FIG. 2A is explained in conjunction with FIG. 1A and FIG. IB.

[0104] The system (102) includes multiple Home Gateways (HGWs) (202-1, 202- 2, ... 202 -N), a Multiple Dwelling Unit (MDU) (204), and a Customer Premises Equipment (CPE) (206). The CPE (206) is mounted outdoors (e.g., rooftop or wall), equipped with high-gain antennas and designed for stationary, always-on broadband service. The HGWs (202-1, 202-2, ... 202 -N) connect user devices (e.g., phones, TVs, laptops, and loT systems) to the Internet.

[0105] In an embodiment, the HGWs (202-1, 202-2, ... 202-N) are connected to the MDU (204) using Power over Ethernet (PoE) cables. The MDU (204) aggregates the connections from multiple HGWs (202) and connects them to the CPE (206) using a PoE cable. A person of ordinary skill in the art will understand that multiple HGWs (202-1, 202-2, ... 202-N) may be collectively referred to as the HGWs (202) or the HGW (202). Although only four HGWs (202) are depicted in FIG. 2, however, any number of the HGWs (202) may be included without departing from the scope of the ongoing description.

[0106] The CPE (206) is connected to a 5G core network via a base station which includes various network functions, such as Access and Mobility Management Function (AMF) (208), Authentication Server Function (AUSF) (210), Unified Data Management (UDM) (212), User Plane Function (UPF) (214), session management function (SMF) (216), Policy Control Function (PCF) (218), and Charging Function (CHF) (220). In an aspect, the AMF (208) is a network function responsible for managing access control and registration, mobility management, connection and session handling between devices (e.g., CPEs) and the network (e.g., core network). Inan aspect, the AUST (210) is a network function responsible for handling authentication procedures of the devices (e.g., CPEs). In an aspect, the UDM (212) is a network function responsible for managing subscription and network policies associated with the CPE. The UDM (212) serves as the primary database for user- related data. In an aspect, the UPF (214) is a network function responsible for handling data traffic (e.g., real-time charging, usage monitoring, etc.). In an aspect, the SMF (216) is a network function responsible for managing PDU sessions (data sessions), IP address assignment, selecting and controlling UPFs, enforcing quality of service (QoS) and session policies, and charging support. The PCF (218) is a network function responsible for traffic prioritization and enforcement of data plans and subscriberspecific policies. In an aspect, the CHF (220) is a network function responsible for accurate tracking of high data volumes and enforcement of data quotas, support for tiered billing, QoS-based pricing, or flat-rate plans.

[0107] These network functions are interconnected and enable communication between the CPE (206), the HGWs (202), and the Internet (219).

[0108] In an embodiment, the system (102) supports both the CPE and the HGW sessions. Initially, an CPE IP Protocol Data Unit (PDU) session is created in the network (i.e., core network). Over the parent CPE IP PDU session, multiple child Ethernet sessions of HGWs (202) and the MDU are created using separate Packet Detection Rule (PDR) IDs over the same N4 session between the UPF (214) and the Session Management Function (SMF) (216). This is achieved using Ethernet over GRE (EoGRE) tunnels between the CPE (206) and the UPF (214). In an aspect, the EoGRE tunnel is a tunneling method that encapsulates Ethernet frames within GRE tunnels, enabling the transparent transmission of Ethernet traffic over the network (e.g., IP network). The EoGRE is useful for aggregating wireless traffic from hotspots to a central gateway (i.e., UPF (214)) and is used to connect the CPE (206) to the network (104).

[0109] Furthermore, the SMF (216) creates distinct N7 and N40 sessions with the PCF (218) and the CHF (220) for the CPE (206) and each child HGW (202) session. There is a need to support different service VLANs for HGW and MDU inside the same CPE EoGRE tunnel.

[0110] According to the present disclosure, the HGW may use a default tag, however, the MDU is provisioned with a separate tag and the VLAN identifiers (IDs) for sending downlink (DL) traffic in the PCF (218). This separate VLAN tag is informed to UPF (214) during MDU session creation. Thus, in this way network security is ensured as only operator defined VLAN tags are allowed in the network (104).

[0111] FIG. 2B illustrates an exemplary flow diagram (200B) of a method for supporting the plurality of services in the network (104), in accordance with an embodiment of the present disclosure. FIG. 2B is explained in conjunction with FIG. 1 A, FIG. IB and FIG. 2 A.

[0112] At step (224), the method (200B) includes establishing an CPE IP Protocol Data Unit (PDU) session between the CPE and the 5G core network (5GCN). The IP PDU session allows data to be exchanged between the CPE (206) and the other elements of the 5G core network (222) using an Ethernet over GRE (EoGRE) tunnel.

[0113] At step (226), the method (200B) includes communicating the Dynamic Host Configuration Protocol version 4 (DHCPv4) discovery message or a DHCP version 6 (DHCPv6) solicit message from the HGW (202) to the UPF (214). In an aspect, the HGW (202) sends the DHCPv4 discovery message / DHCPv6 solicit message to the UPF (214) to establish the session (i.e., HGW session) over the established IP PDU session of the CPE (206). In an aspect, the session (i.e., HGW session) is an Ethernet session.

[0114] At step (228), the method (200B) includes sending a session report request from the UPF (214) to the SMF (216). In an aspect, the session report request, comprising details of the HGW (202), is used to inform the SMF (216) about the attempt of the HGW (202) to establish a session and provide identity for subsequent session management and policy association. The details of the HGW (202) comprise, but are not limited to, a Home Gateway identifier (HGW ID), etc. In an aspect, the HGW ID may correspond to the Media Access Control (MAC) address, its unique serial number, or a logical identifier of the HGW (202) assigned by the network operator. The HGW ID enables the SMF (216) to track and manage the session details of the HGW (202). The session report request helps the SMF (216) maintain records of all active sessions of the HGW (202) and ensures efficient session management and resource allocation in the network (e.g., 5G core network).

[0115] At step (230), the method (200B) includes sending an authorization request from the SMF (216) to the PCF (218). In an aspect, the SMF (216) sends the authorization request comprising the HGW ID to the PCF (218) to perform authorization of the HGW (202) corresponding to the HGW ID. The authorization request facilitates the authorization of HGW (202) for network services. This step ensures that the HGW (202) complies with network policies and is authorized to access the network services.

[0116] At step (232), the method (200B) includes returning an authorization response from the PCF (218) to the SMF (216). In an aspect, the PCF (218) processes the authorization request. Based on the processing, the PCF (218) performs the authorization of the HGWs using the HGW IDs. After performing the authorization, the PCF (218) sends the HGW authorization response to the SMF (216), including successful establishment of policy rules and permissions and authorization for the HGW session, if the HGW (202) is authorized successfully. In an aspect, if the HGW (202) is not authorized, then the PCF (218) sends the HGW authorization responseindicating that authorization of the HGW (202) is unsuccessful.

[0117] At step (234), the method (200B) includes sending a session report response from the SMF (216) to the UPF (214). In an aspect, upon receiving the authorization response from the PCF (218), the SMF (216) sends the session report response to the UPF (214). The session report response indicates whether the session report request is successfully processed (e.g., request accepted or request rejected). Upon performing the policies establishment, the SMF (216) sends the session report response back to the UPF (214).

[0118] At step (236), the method (200B) includes establishing the HGW (202) session in the network in a session modification procedure between the SMF (216) and the UPF (214) and assigning a default VLAN tag (e.g., “X”) to the HGW (202). The session modification procedure informs the UPF (214) of the successful session establishment and the associated policies for the HGW (202). In an aspect, upon receiving the session report response indicating successful processing of the session report request, the HGW session is established between the SMF (216) and the UPF (214). For the HGW session, the UPF (214) assigns the default VLAN tag = X.

[0119] At step (238), the method (200B) includes exchanging the DHCPv4 offer, request, acknowledgment, and DHCPv6 advertise, request, and reply messages between the UPF (214) and the HGW (202). In an aspect, the DHCPv4 offer, request, and acknowledgment are exchanged to assign IPv4 address for DHCPv4. The DHCPv6 advertise, request and reply messages are exchanged to assign IPv6 address for DHCPv6. In an aspect, the UPF (214) sends the DHCPv4 offer and the DHCPv6 advertise to the HGW (202) as a response to the DHCPv4 discovery message and the DHCPv6 solicit message, respectively.

[0120] At step (240), the method (200B) includes establishing the HGW Ethernet session in the network (104) between the HGW (202) and the 5GCN (222) using thedefault VLAN tag. In an aspect, upon assigning the IP address (i.e., IPv4 or IPv6), the HGW Ethernet session is established for the HGW (202) in the network (104) using the default VLAN tag.

[0121] At step (242), the method (200B) includes communicating a DHCPv4 discovery message or a DHCPv6 solicit message from the MDU (204) to the UPF (214). The MDU (204) sends the DHCPv4 discover message or DHCPv6 solicit message to discover the CPE (206) and establish a session for the MDU (204) over the established IP PDU session for the CPE (206).

[0122] At step (244), the method (200B) includes, upon receiving the DHCP message (e.g., DHCPv4 discover message or DHCPv6 solicit message) from MDU (204) at the UPF (214), a session report request is sent from the UPF (214) to the SMF (216). The session report request includes a MDU identifier (MDU ID), which may correspond to a unique serial number or a logical identifier of the MDU (204) assigned by the network operator. The session report request includes the MDU ID of the MDU (204), informing the SMF (216) about the attempt of the MDU (204) to establish a session and provide identity for subsequent session management and policy association. For example, the session report request helps the SMF (216) maintain an updated record of all active sessions, ensuring efficient session management and resource allocation within the network (104).

[0123] At step (246), the method (200B) includes sending an authorization request from the SMF (216) to the PCF (218). In an aspect, the authorization request comprising the MDU ID is sent by the SMF (216) to the PCF (218) to perform authorization of the MDU (204) for network services. This step ensures that the MDU (204) complies with network policies and is authorized to access the network services.

[0124] At step (248), the method (200B) includes returning by the PCF (218) an authorization response to the SMF (216), which includes the VLAN tags (e.g., ‘Y’) andthe device type (e.g., MDU). In an aspect, upon receiving the authorization request for the MDU (204), the PCF (218) performs the authorization of the MDU (204) and sends the authorization response comprising the VLAN tags = ‘Y’ and the device type = MDU to the SMF (216). The VLAN tags used for the MDU (204) are provisioned in the PCF (218) and are informed to the UPF (214) during the MDU session creation. This ensures network security as only operator-defined VLAN tags are allowed in the network (104).

[0125] At step (250), the method (200B) includes sending a session report response from the SMF (216) to the UPF (214). In an aspect, upon receiving the authorization response from the PCF (218), the SMF (216) sends the session report response to the UPF (214). The session report response indicates the successful processing of the session report request. The session report response confirms the successful establishment of policies and authorization for the MDU (204) to access the network services.

[0126] At step (252), the method (200B) includes initiating the session modification procedure by the SMF (216) results in the establishment of the MDU session in the network. In an embodiment, upon receiving the successful processing in the session report response, the SMF (216) initiates the session modification procedure for MDU session establishment in the network (104). The session modification procedure may include the tag “Y” for the MDU sessions (e.g., child MDU sessions). In an aspect, the MDU session is an Ethernet session for the MDU (204).

[0127] At step (254), the method (200B) includes after execution of the session modification procedure, exchanging the DHCPv4 offer, request, acknowledgment as a response to the DHCPv4 discover message, and DHCPv6 advertise, request, and reply messages to the DHCPv6 solicit message between the MDU (204) and the UPF (214).

[0128] At step (256), the method (200B) includes establishing the MDU Ethernetsession between the HGW (202) and the 5GCN (222). Thus, the HGW (202) may use a default tag, however, the MDU (204) is provisioned with a separate tag and the VLAN identifiers (IDs) for sending the DL traffic in the PCF (218). The separate VLAN tag is informed to UPF (214) during the MDU session creation. Thus, in this way, network security is ensured as only operator-defined VLAN tags are allowed in the network. This results in ensuring network security through controlled VLAN tagging and enabling remote management of the MDU (204). This method enhances the reliability and efficiency of network services.

[0129] FIG. 3 illustrates another exemplary flow diagram of a method (300) for supporting a plurality of services in the network (104), in accordance with an embodiment of the present disclosure. FIG. 3 is explained in conjunction with FIG. 1 A, FIG. IB, FIG. 2A and FIG. 2B.

[0130] At step (302), the method includes receiving, by a user plane function (UPF) (214), a request message from a first network element (204) connected with a second network element (206). The first network element (204) is a Multiple Dwelling Unit (MDU), and the second network element (206) is a Customer Premises Equipment (CPE). The request message received by the UPF (214) from the first network element (204) includes at least one of a Dynamic Host Configuration Protocol version 4 (DHCPv4) discover message and a DHCPv6 solicit message. In an aspect, the first network element (204) (i.e., MDU) sends the DHCPv4 or DHCPv6 to the UPF to obtain Internet Protocol (IP) configuration.

[0131] At step (304), the method includes communicating, by the UPF (214), a session report request (SRR) towards a session management function (SMF) (216). The SSR provides details of the first network element (204) for which the session is to be initiated. The details of the first network element (i.e., MDU) (204) comprise a MDU identifier (ID). The UPF (214) sends the SSR to the SMF (216) to performauthorization and session creation for the first network element (i.e., MDU) (204).

[0132] At step (306), the method includes communicating, by the SMF (216), an authorization request towards a policy control function (PCF) (218). The authorization request comprises the MDU ID, to facilitate authorization of the MDU and network policies. In an aspect, the method (300) includes, in response to receiving the authorization request from the SMF (216), the PCF (218) retrieves mapping information associated with the first network element (204) and the second network element (206). The PCF (218) identifies the device type based on the retrieved mapping information. The PCF (218) identifies the at least one VLAN tag based on the device type. For example, upon identifying the device type is MDU, the PCF (218) identifies the VLAN tag = Y for the MDU. Upon identified the at least one VLAN tag, the PCF (218) transmits the at least one identified VLAN tag in the authorization response to the SMF (216). For example, the PCF (218) sends the authorization response comprising the device type = MDU and the VLAN tag = Y.

[0133] At step (308), the method includes receiving, by the SMF (216), an authorization response from the PCF (218). The authorization response includes the necessary authorizations and any VLAN tags to be used for the session. In an embodiment, the authorization response received from the PCF (218) includes at least one of device type of the first network element (204) and the at least one tag associated with the at least one service. In an example, the authorization response comprises the device = MDU and the VLAN tag = Y.

[0134] At step (310), the method includes triggering, by the SMF (216), a session modification procedure based on the received authorization response. The session modification procedure informs the UPF (214) of the successful session establishment and the associated policies for the MDU (204). This step ensures that the session parameters are updated as per the authorization response.

[0135] At step (312), the method includes assigning, by the UPF (214), at least one Virtual Local Area Network (VLAN) tag associated with at least one service to the first network element (204) based on the triggered session modification procedure. The VLAN tags are essential for differentiating between various services and ensuring proper VLAN segregation. For example, the VLAN tag = Y is assigned for the MDU (204).

[0136] At step (314), the method includes establishing, by the UPF (214), at least one Ethernet session between the first network element (204) and the network (104) based on the at least one assigned VLAN tag. This step ensures that the network handles multiple services efficiently and securely through VLAN tagging.

[0137] In an embodiment, the method (300) includes creating at least one Home Gateway (HGW) session between the network (104) and at least one HGW device (202) over an Internet Protocol (IP) Protocol Data Unit (PDU) session of the second network element (206) based on at least one HGW session request received by the UPF (214) from the at least one HGW device (202). The at least HGW device (202) is connected to the second network element (206) through the first network element (204). The UPF (214) is configured to assign a default VLAN tag to each of the at least one HGW device (202) based on the established at least one HGW session.

[0138] In an embodiment, a method for supporting multiple service VLAN inside a single CPE EoGRE Tunnel. An CPE IP PDU session is created with the network (e.g., 5G core network). Over the created PDU session, multiple child Ethernet sessions of the HGWs and the MDU are created. The HGW use a default VLAN tag for performing communication in the established session. The MDU (e.g., L2 Switch) use operator defined VLAN tag for communication with the network (104). The VLAN tags used by the MDU are provisioned in the PCF (218) and are informed to the UPF (214) during MDU session creation. Different service VLANs (e.g. multicast, VoIP)are supported by the HGWs and the MDU inside the same CPE EoGRE tunnel.

[0139] FIG. 4 illustrates an exemplary computer system (400) in which or with which the embodiments of the present disclosure may be implemented.

[0140] As shown in FIG. 4, the computer system (400) may include an external storage device (410), a bus (420), a main memory (430), a read-only memory (440), a mass storage device (450), a communication port(s) (460), and a processor (470). A person skilled in the art will appreciate that the computer system (400) may include more than one processor and communication ports. The processor (470) may include various modules associated with embodiments of the present disclosure. The communication port(s) (460) may be any of an RS-232 port for use with a modembased dialup connection, a 10 / 100 Ethernet port, a Gigabit or 10 Gigabit port using copper or fiber, a serial port, a parallel port, or other existing or future ports. The communication ports(s) (460) may be chosen depending on a network, such as a Local Area Network (LAN), Wide Area Network (WAN), or any network to which the computer system (400) connects.

[0141] In an embodiment, the main memory (430) may be Random Access Memory (RAM), or any other dynamic storage device commonly known in the art. The read-only memory (440) may be any static storage device(s) e.g., but not limited to, a Programmable Read Only Memory (PROM) chip for storing static information e.g., start-up or basic input / output system (BIOS) instructions for the processor (470). The mass storage device (450) may be any current or future mass storage solution, which may be used to store information and / or instructions. Exemplary mass storage solutions include, but are not limited to, Parallel Advanced Technology Attachment (PATA) or Serial Advanced Technology Attachment (SATA) hard disk drives or solid-state drives (internal or external, e.g., having Universal Serial Bus (USB) and / or Firewire interfaces).

[0142] In an embodiment, the bus (420) may communicatively couple the processor(s) (470) with the other memory, storage, and communication blocks. The bus (420) may be, e.g. a Peripheral Component Interconnect PCI) / PCI Extended (PCI- X) bus, Small Computer System Interface (SCSI), Universal Serial Bus (USB), or the like, for connecting expansion cards, drives, and other subsystems as well as other buses, such a front side bus (FSB), which connects the processor (470) to the computer system (400).

[0143] In another embodiment, operator, and administrative interfaces, e.g., a display, keyboard, and cursor control device may also be coupled to the bus (420) to support direct operator interaction with the computer system (400). Other operator and administrative interfaces can be provided through network connections connected through the communication port(s) (460). Components described above are meant only to exemplify various possibilities. In no way should the aforementioned exemplary computer system (400) limit the scope of the present disclosure.

[0144] The exemplary computer system (400) is configured to execute a computer program product comprising a non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform a method for supporting a plurality of services in a network is disclosed. The method comprises receiving, by a user plane function (UPF), a request message from a first network element connected with a second network element. The method comprises communicating, by the UPF, a session report request (SRR) towards a session management function (SMF). The method comprises communicating, by the SMF, an authorization request towards a policy control function (PCF). The method comprises receiving, by the SMF, an authorization response from the PCF. The method comprises triggering, by the SMF, a session modification procedure based on the received authorization response. The method comprises assigning, by the UPF, at least one Virtual Local Area Network (VLAN) tag associated with at least one service to thefirst network element based on the triggered session modification procedure. The method comprises establishing, by the UPF, at least one Ethernet session between the first network element and the network based on the at least one assigned VLAN tag.

[0145] The present disclosure provides technical advancements related to supporting the plurality of services in the network. The advancement addresses the limitations of existing solutions by facilitating network-controlled VLAN tagging to segregate traffic for Home Gateways (HGWs) and the Multiple Dwelling Unit (MDU) services. This ensures that each service operates within its designated VLAN, thereby reducing the risk of interference and improving network performance. The network security is ensured through the use of network-controlled VLAN tags. By defining and controlling VLAN tags at the network end, unauthorized access is prevented, and only operator-defined VLAN tags are permitted, enhancing the overall security of the network.TECHNICAL ADVANTAGES OF THE PRESENT DISCLOSURE

[0146] The present disclosure described herein above has several technical advantages including, but not limited to, the realization of the system and the method that:

[0147] The present disclosure facilitates the support of multiple service Virtual Local Area Network(s) (VLANs) for different services inside a single Customer Premises Equipment (CPE) Ethernet over Generic Routing Encapsulation (EoGRE) tunnel. This approach allows for the efficient management of various services, such as Home Gateway (HGW) and Multiple Dwelling Unit (MDU), over the same network infrastructure.

[0148] The present disclosure enables remote management of the MDU. This feature enhances the flexibility and control of network administrators, allowing themto manage network elements remotely without requiring physical access.

[0149] The present disclosure ensures network security through the use of network-controlled VLAN tags. By defining and controlling VLAN tags at the network end, unauthorized access is prevented, and only operator-defined VLAN tags are permitted, enhancing the overall security of the network.

[0150] The present disclosure provides a method for network-controlled VLAN tagging for separate services. This capability allows for the segregation of traffic for HGW and MDU services, ensuring that each service operates within its designated VLAN, thereby reducing the risk of interference and improving network performance.

[0151] The present disclosure optimizes the use of network resources by managing the establishment and maintenance of multiple Ethernet sessions for HGW and MDU over a single CPE IP Protocol Data Unit (PDU) Session. This optimization reduces the overhead and complexity associated with session management in a 5G core network environment.

[0152] The present disclosure is scalable and handles multiple HGW sessions simultaneously. This scalability makes the system suitable for both residential and enterprise environments, adapting to various network configurations and requirements.

Claims

We Claim:

1. A method (300) for supporting a plurality of services in a network (104), the method (300) comprising: receiving (302), by a user plane function (UPF) (214), a request message from a first network element (204) connected with a second network element (206); communicating (304), by the UPF (214), a session report request (SRR) towards a session management function (SMF) (216); communicating (306), by the SMF (216), an authorization request towards a policy control function (PCF) (218); receiving (308), by the SMF (216), an authorization response from the PCF (218); triggering (310), by the SMF (216), a session modification procedure based on the received authorization response; assigning (312), by the UPF (214), at least one Virtual Uocal Area Network (VLAN) tag associated with at least one service to the first network element (204) based on the triggered session modification procedure; and establishing (314), by the UPF (214), at least one Ethernet session between the first network element (204) and the network (104) based on the at least one assigned VLAN tag.

2. The method (300) as claimed in claim 1, wherein the first network element (204) is a Multiple Dwelling Unit (MDU), and the second network element (206) is a Customer Premises Equipment (CPE).

3. The method (300) as claimed in claim 1, comprising:retrieving, by the PCF (218), mapping information associated with the first network element (204) and the second network element (206) in response to receiving the authorization request from the SMF (216); identifying, by the PCF (218), the at least one VLAN tag based on the retrieved mapping information; and transmitting, by the PCF (218), the at least one identified VLAN tag in the authorization response to the SMF (216).

4. The method (300) as claimed in claim 1, comprising: creating at least one Home Gateway (HGW) session between the network (104) and at least one HGW device (202) over an Internet Protocol (IP) Protocol Data Unit (PDU) session of the second network element (206) based on at least one HGW session request received by the UPF (214) from the at least one HGW device (202), wherein the at least HGW device (202) is connected to the second network element (206) through the first network element (204).

5. The method (300) as claimed in claim 4, comprising: assigning, by the UPF (214), a default VLAN tag to each of the at least one HGW device (202) based on the established at least one HGW session.

6. The method (300) as claimed in claim 1 , wherein the request message received by the UPF (214) from the first network element (204) includes at least one of a Dynamic Host Configuration Protocol version 4 (DHCPv4) discover message and a DHCPv6 solicit message.

7. A system (102) for supporting a plurality of services in a network (104), the system (102) comprising a user plane function (UPF) (214), the UPF (214) comprising a processing engine (118) configured to:receive a request message from a first network element (204) connected with a second network element (206); and communicate a session report request (SRR) towards a session management function (SMF) (216), wherein the SMF (216) is configured to: communicate an authorization request towards a policy control function (PCF) (218); receive an authorization response from the PCF (218); and trigger a session modification procedure based on the received authorization response; the processing engine (118) configured to: assign at least one Virtual Local Area Network (VLAN) tag associated with at least one service to the first network element (204) based on the triggered session modification procedure; and establish at least one Ethernet session between the first network element (204) and the network (104) based on the at least one assigned VLAN tag.

8. The system (102) as claimed in claim 7, wherein the first network element (204) is a Multiple Dwelling Unit (MDU), and the second network element (206) is a Customer Premises Equipment (CPE).

9. The system (102) as claimed in claim 7, wherein the PCF (218) configured to: retrieve mapping information associated with the first network element (204) and the second network element (206) in response to receiving the authorization request from the SMF (216);identify the at least one VLAN tag based on the retrieved mapping information; and transmit the at least one identified VLAN tag in the authorization response to the SMF (216).

10. The system (102) as claimed in claim 7, wherein at least one Home Gateway (HGW) session is created between the network (104) and at least one HGW device (202) over an Internet Protocol (IP) Protocol Data Unit (PDU) session of the second network element (206) based on at least one HGW session request received by the UPF (214) from the at least one HGW device (202), wherein the at least HGW device (202) is connected to the second network element (206) through the first network element (204).

11. The system ( 102) as claimed in claim 10, wherein the processing engine (118) is configured to assign a default VLAN tag to each of the at least one HGW device (202) based on the established at least one HGW session.

12. The system ( 102) as claimed in claim 7, wherein the request message received by the UPF (214) from the first network element (204) includes at least one of a Dynamic Host Configuration Protocol version 4 (DHCPv4) discover message and a DHCPv6 solicit message.

13. A computer program product comprising a non- transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform a method (300) for supporting a plurality of services in a network (104), the method (300) comprising:receiving (302), by a user plane function (UPF) (214), a request message from a first network element (204) connected with a second network element (206); communicating (304), by the UPF (214), a session report request (SRR) towards a session management function (SMF) (216); communicating (306), by the SMF (216), an authorization request towards a policy control function (PCF) (218); receiving (308), by the SMF (216), an authorization response from the PCF (218); triggering (310), by the SMF (216), a session modification procedure based on the received authorization response; assigning (312), by the UPF (214), at least one Virtual Uocal Area Network (VLAN) tag associated with at least one service to the first network element (204) based on the triggered session modification procedure; and establishing (314), by the UPF (214), at least one Ethernet session between the first network element (204) and the network (104) based on the at least one assigned VLAN tag.

Citation Information

Patent Citations

  • Control Plane Based Configuration For Time Sensitive Networking

    US20210219357A1

  • Apparatus and method for applying service-based interface for user traffic processing in wireless communication system

    US20230247101A1