System and method for managing communication sessions in a network

The system temporarily blacklists unauthorized HGWs in 5G core networks, addressing signaling overload and DDoS threats by selectively managing communication sessions, enhancing network security and user convenience.

WO2026033560A1PCT designated stage Publication Date: 2026-02-12JIO PLATFORMS LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/IN2025/051213
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-09
Filing Date
2025-08-07
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

Unauthorized Home Gateways (HGWs) in 5G core networks cause signaling overload and increased network load through repeated session creation requests, posing security threats like DDoS attacks, while conventional blocking methods affect legitimate users.

Method used

A system and method where the User Plane Function (UPF) temporarily blacklists unauthorized HGWs based on responses from the Policy Control Function (PCF), preventing further session requests and reducing signaling overload.

Benefits of technology

This approach effectively prevents unauthorized access, optimizes network traffic, reduces DDoS risks, and balances security with user convenience by selectively restricting unauthorized HGWs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IN2025051213_12022026_PF_FP_ABST
    Figure IN2025051213_12022026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a system (108) and a method (600) for managing one or more communication sessions in a network (106). A User Plane Function (UPF) (322) receives session establishment requests from HGWs and forwards them to a Policy Control Function (PCF) (308). The PCF (308) verifies whether the MAC address of the HGW exists in its database and responds with either a positive or negative message, marking the HGW as authorized or unauthorized, respectively. Based on this status, the UPF (322) either allows or restricts the session creation. In case of an unauthorized HGW, the UPF (322) rejects repeated requests for a configurable time period. This mechanism prevents unauthorized devices from establishing network sessions, enhances network security, and enables policy-driven session control.
Need to check novelty before this filing date? Find Prior Art

Description

SYSTEM AND METHOD FOR MANAGING COMMUNICATION SESSIONS IN A NETWORKRESERVATION OF RIGHTS

[0001] A portion of the disclosure of this patent document contains material, which is subject to intellectual property rights such as, but are not limited to, copyright, design, trademark, Integrated Circuit (IC) layout design, and / or trade dress protection, belonging to JIO PLATFORMS LIMITED or its affiliates (hereinafter referred as owner). The owner has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent files or records, but otherwise reserves all rights whatsoever. All rights to such intellectual property are fully reserved by the owner.TECHNICAL FIELD

[0002] The present disclosure relates generally to the field of telecommunications. More particularly, the present disclosure relates to a system and method for managing one or more communication sessions in a network.DEFINITION

[0003] The term ‘Customer Premise Equipment (CPE)’ used hereinafter in the specification refers to a specialized network device that may be deployed outdoors or indoors, depending on the network design and signal requirements at customer locations, to facilitate connectivity and network services.

[0004] The term “Home Gateway (HGW) device” used hereinafter in the specification refers to refers to a type of Residential Gateway (RG), which is a device configured to provide communication services such as voice, data, broadcast video, and video on demand to other devices within a customer premises. The HGW acts as an interface between the Wide Area Network (WAN) and the Local Area Network (LAN) IP environment for a consumer broadband customer, capable of routing or bridging traffic depending on its configuration. In the context of the 5G Core Network,the HGW device may function as a User Equipment (UE) or communicate via the CPE holding a secure element and exchanging Non-Access Stratum (NAS) signalling with the core network (e.g., 5G or 4G) to establish connectivity.

[0005] The term ‘Multiple Dwelling Unit (MDU)’ used hereinafter in the specification refers to a device or system deployed in a residential building or complex to facilitate network connectivity. The residential building or complex contains multiple separate housing units, such as apartments, condominiums, or dormitories. The deployment of MDU may involve centralized or per-unit CPE, with shared access infrastructure like fiber splitters or Ethernet switches.

[0006] The term ‘EoGRE’ as used hereinafter in the specification refers to an Ethernet over Generic Routing Encapsulation. The EoGRE is an advanced tunneling protocol that allows an encapsulation of Ethernet frames within GRE tunnels, enabling a transmission of Ethernet headers across Internet Protocol (IP) networks.

[0007] The term ‘Communication session’ used hereinafter in the specification refers to a connection established between the HGW and the network. This session allows data to flow between the HGW and the network.

[0008] The term ‘Ethernet session’ used hereinafter in the specification refers to a network session that provides Layer 2 (Data Link Layer) connectivity, enabling transmission of Ethernet frames between devices. For instance, an Ethernet session is established between the HGW device and the core network to facilitate data communication over an encapsulated tunnel such as the EoGRE.

[0009] The term ‘Internet Protocol (IP) Address’, as used in this specification, refers to a unique identifier assigned to a device on a network that allows devices to locate and communicate with each other.

[0010] The term ‘Power over Ethernet (PoE) used hereinafter in the specification refers to a technology that allows network cables to carry electrical power to devices.

[0011] The term ‘Dynamic Host Configuration Protocol (DHCP)’ used hereinafter in the specification refers to a network management protocol used to dynamically assign IP addresses and other communication parameters to devices connected to a network.

[0012] The term ‘Packet Detection Rule (PDR)’ used hereinafter in the specification refers to a rule used in a UPF to identify and classify packets for specific handling in a 5G core network.

[0013] The term ‘Forwarding Action Rule (FAR)’ used hereinafter in the specification refers to instructions on how packets identified by a PDR should be handled, including forwarding, dropping, or applying QoS parameters.

[0014] The term ‘QoS Enforcement Rule (QER)’ used hereinafter in the specification refers to rules that enforce quality of service policies for a network session, such as bandwidth limitations and latency requirements.

[0015] The term ‘Usage Reporting Rule (URR)’ used hereinafter in the specification refers to guidelines for collecting and reporting usage data for a network session, including metrics like data volume and session duration.

[0016] These definitions are in addition to those expressed in the art.BACKGROUND

[0017] The following description of related art is intended to provide background information pertaining to the field of the disclosure. This section may include certain aspects of the art that may be related to various features of the presentdisclosure. However, it should be appreciated that this section be used only to enhance the understanding of the reader with respect to the present disclosure, and not as admissions of prior art.

[0018] The ever-growing demand for high-speed and reliable internet access has driven the advancement of mobile network technology. Mobile networks offer significantly faster data rates and lower latency than previous generations, enabling a wider range of applications and services. However, managing these complex networks efficiently presents challenges, particularly when dealing with multiple connected devices within a household.

[0019] The 5G core network supports various devices and sessions, including those for Customer Premises Equipment (CPE) and Home Gateways (HGWs). Typically, multiple HGWs are connected to the CPE through a Residential Multiple Dwelling Unit (RMDU) using Power over Ethernet (PoE) cables. This setup enables efficient network resources and power supply sharing among multiple devices.

[0020] However, a challenge arises when unauthorized HGWs attempt to connect to the network. These unauthorized HGWs can flood the core network with repeated session creation requests. This situation leads to several problems, including signalling overload and increased network load. Additionally, unauthorized HGWs can be exploited by malicious users to launch Distributed Denial of Service (DDoS) attacks, further compromising network security, stability and performance.

[0021] Conventional techniques for addressing unauthorized HGW access involve permanently blocking the media access control (MAC) addresses of unauthorized HGWs. However, this approach can inadvertently affect legitimate users whose network provisioning is delayed, leading to user dissatisfaction and operational inefficiencies.

[0022] There is, therefore, a need in the art to provide a method and a system that can mitigate the disadvantages of the prior art.SUMMARY OF THE DISCLOSURE

[0023] In an exemplary embodiment, a system for managing one or more communication sessions in a network is described. The system includes a user plane function (UPF). The UPF includes a receiving unit, a transmitting unit and a processing unit. The receiving unit is configured to receive at least one request for establishing at least one communication session in the network from at least one home gateway (HGW). The transmitting unit is configured to forward the at least one received request to a Policy Control Function (PCF). The receiving unit is configured to receive at least one response message corresponding to the at least one received request from the PCF. The processing unit is configured to determine a status of the at least one HGW based on the at least one received response message and perform one or more operations associated with the at least one HGW based on the determined status. The one or more operations comprises creation of the at least one communication session or restricting the creation of the at least one communication session in the network.

[0024] In some embodiments, the status of the at least one HGW comprises an authorized status or an unauthorized status.

[0025] In some embodiments, the at least one request comprises at least a Media Access Control (MAC) address corresponding to the at least one HGW.

[0026] In some embodiments, the at least one response message comprises a negative response or a positive response.

[0027] In some embodiments, the PCF is configured to determine whether the MAC address corresponding to the at least one HGW is present in a database of the PCF. Upon determining the MAC address corresponding to the at least one HGW isnot present in the database, the PCF is configured to mark the status of the at least one HGW as the unauthorized status for a configurable time period and send the at least one response message as the negative response to the UPF. Further, the processing unit is configured to reject at least one subsequent request received from the at least one HGW for the configurable time period based on the at least one negative response message.

[0028] In some embodiments, upon determining the MAC address corresponding to the at least one HGW is present in the database, the PCF is configured to mark the status of the at least one HGW as the authorized status and send the at least one response message as the positive response to the UPF. The positive response provides an indication to create the at least one communication session for the at least one HGW in the network.

[0029] In another exemplary embodiment, a method for managing one or more communication sessions in a network is described. The method includes receiving, at a user plane function (UPF), at least one request for establishing at least one communication session in the network from at least one home gateway (HGW). The method further includes forwarding, by the UPF, the at least one received request to a Policy Control Function (PCF). The method further includes receiving, by the UPF, at least one response message corresponding to the at least one received request from the PCF. The method further includes determining, by the UPF, a status of the at least one HGW based on the at least one received response message and performing, by the UPF, one or more operations associated with the at least one HGW based on the determined status. The one or more operations comprises creation of the at least one communication session or restricting the creation of the at least one communication session in the network.

[0030] In another exemplary embodiment, the present disclosure discloses a user equipment (UE). The UE is communicatively coupled with a network, thecoupling includes receiving, by the network, a connection request from UE, sending, by the network, an acknowledgment of the connection request to the UE and transmitting a plurality of signals in response to the connection request. The one or more communication sessions in the network are managed by a system. The system includes a user plane function (UPF). The UPF includes a receiving unit, a transmitting unit and a processing unit. The receiving unit is configured to receive at least one request for establishing at least one communication session in the network from at least one home gateway (HGW. The transmitting unit is configured to forward the at least one received request to a Policy Control Function (PCF). The receiving unit is configured to receive at least one response message corresponding to the at least one received request from the PCF. The processing unit is configured to determine a status of the at least one HGW based on the at least one received response message and perform one or more operations associated with the at least one HGW based on the determined status. The one or more operations comprises creation of the at least one communication session or restricting the creation of the at least one communication session in the network.

[0031] In an exemplary embodiment, the present disclosure discloses a computer program product comprising a non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform a method for managing one or more communication sessions in a network is described. The method includes receiving, at a user plane function (UPF), at least one request for establishing at least one communication session in the network from at least one home gateway (HGW). The method further includes forwarding, by the UPF, the at least one received request to a Policy Control Function (PCF). The method further includes receiving, by the UPF, at least one response message corresponding to the at least one received request from the PCF. The method further includes determining, by the UPF, a status of the at least one HGW based on the at least one received response message and performing, by the UPF, one or moreoperations associated with the at least one HGW based on the determined status. The one or more operations comprises creation of the at least one communication session or restricting the creation of the at least one communication session in the network.

[0032] The foregoing general description of the illustrative embodiments and the following detailed description thereof are merely exemplary aspects of the teachings of this disclosure, and are not restrictive.OBJECTIVES OF THE PRESENT DISCLOSURE

[0033] Some of the objectives of the present disclosure, which at least one embodiment herein satisfies, are as follows:

[0034] An objective of the present disclosure is to provide a system and a method to prevent unauthorized access of home gateways (HGWs) and repeated session creation requests in a network.

[0035] Another objective of the present disclosure is to provide the system and the method for selectively restricting unauthorized HGWs within the network, thereby optimizing network traffic and preventing DDoS attacks

[0036] Another objective of the present disclosure is to provide the system and the method that balances network security with user convenience.

[0037] Another objective of the present disclosure is to provide the system and the method for reducing signalling overhead within the network.

[0038] Another objective of the present disclosure is to provide the system and the method for optimizing signaling flow within the network.BRIEF DESCRIPTION OF THE ACCOMPANYING DRAWING

[0039] The accompanying drawings, which are incorporated herein, and constitute a part of this disclosure, illustrate exemplary embodiments of the disclosed methods and systems in which like reference numerals refer to the same parts throughout the different drawings. Components in the drawings are not necessarily to scale; emphasis is instead being placed upon clearly illustrating the principles of the present disclosure. Some drawings may indicate the components using block diagrams and may not represent the internal circuitry of each component. It will be appreciated by those skilled in the art that disclosure of such drawings includes disclosure of electrical components, electronic components, or circuitry commonly used to implement such components.

[0040] FIG. 1 illustrates an exemplary network architecture in which or with a system configured for managing one or more communication sessions in a network may be implemented, in accordance with embodiments of the present disclosure.

[0041] FIG. 2 illustrates a block diagram of the system configured for managing the one or more communication sessions in the network, in accordance with an embodiment of the present disclosure.

[0042] FIG. 3 illustrates an exemplary network architecture of the system for managing the one or more communication sessions in the network, in accordance with an embodiment of the present disclosure.

[0043] FIG. 4 illustrates an exemplary process flow for managing the one or more communication session in the network in accordance with embodiments of the present disclosure.

[0044] FIG. 5 illustrates another exemplary process flow for managing the one or more communication session in the network in accordance with embodiments of the present disclosure.

[0045] FIG. 6 illustrates an exemplary flowchart of a method for managing the one or more communication sessions in the network, in accordance with an embodiment of the present disclosure.

[0046] FIG. 7 illustrates an exemplary computer system in which or with which the embodiments of the present disclosure may be implemented.

[0047] The foregoing shall be more apparent from the following more detailed description of the disclosure.LIST OF REFERENCE NUMERALS100 - Network Architecture102 - User(s)104 - User Equipments (UEs)106 - Network108 - System200 -Block Diagram202 - Receiving Unit204 - Memory206 - Interface(s)208 - Transmitting Unit210 - Processing Unit212 - Database300 -System Architecture302 - One or more Home Gateways (HGWs)304 - Multiple Dwelling Unit (MDU)306 - Customer Premise Equipment (CPE) 308 - Policy Control Function (PCF)310 - Charging Function (CHF)312 - Session Management Function (SMF)314 - Unified Data Management (UDM)316 - Access and Mobility Management Function (AMF) 318 - Authentication Server Function (AUSF)320 - 5G Core Network (CN)322 - User Plane Function (UPF)324 - Internet400 - Process Flow 402 - other elements of the 5G core network (5GCN)500 - Process Flow502 - Unauthorized HGW600 - Method Flowchart700 - Computer System710 - External Storage Device720 - Bus730 - Main Memory740 - Read Only Memory750 - Mass Storage Device760 - Communication Port(S)770 - ProcessorDETAILED DESCRIPTION

[0048] In the following description, for the purposes of explanation, various specific details are set forth in order to provide a thorough understanding of embodiments of the present disclosure. It will be apparent, however, that embodiments of the present disclosure may be practiced without these specific details. Several features described hereafter can each be used independently of one another or with any combination of other features. An individual feature may not address any of the problems discussed above or might address only some of the problems discussed above. Some of the problems discussed above might not be fully addressed by any of the features described herein. Example embodiments of the present disclosure are described below, as illustrated in various drawings in which like reference numerals refer to the same parts throughout the different drawings.

[0049] The ensuing description provides exemplary embodiments only, and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, the ensuing description of the exemplary embodiments will provide those skilled in the art with an enabling description for implementing an exemplary embodiment. It shouldbe understood that various changes may be made in the function and arrangement of elements without departing from the spirit and scope of the disclosure as set forth.

[0050] Specific details are given in the following description to provide a thorough understanding of the embodiments. However, it will be understood by one of ordinary skill in the art that the embodiments may be practiced without these specific details. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form in order not to obscure the embodiments in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail in order to avoid obscuring the embodiments.

[0051] Also, it is noted that individual embodiments may be described as a process that is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. Although a flowchart may describe the operations as a sequential process, many of the operations can be performed in parallel or concurrently. In addition, the order of the operations may be re-arranged. A process is terminated when its operations are completed but could have additional steps not included in a figure. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination can correspond to a return of the function to the calling function or the main function.

[0052] The word “exemplary” and / or “demonstrative” is used herein to mean serving as an example, instance, or illustration. For the avoidance of doubt, the subject matter disclosed herein is not limited by such examples. In addition, any aspect or design described herein as “exemplary” and / or “demonstrative” is not necessarily to be construed as preferred or advantageous over other aspects or designs, nor is it meant to preclude equivalent exemplary structures and techniques known to those of ordinary skill in the art. Furthermore, to the extent that the terms “includes,” “has,” “contains,” and other similar words are used in either the detailed description or the claims, suchterms are intended to be inclusive like the term “comprising” as an open transition word without precluding any additional or other elements.

[0053] Reference throughout this specification to “one embodiment” or “an embodiment” or “an instance” or “one instance” means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present disclosure. Thus, the appearances of the phrases “in one embodiment” or “in an embodiment” in various places throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0054] The terminology used herein is to describe particular embodiments only and is not intended to be limiting the disclosure. As used herein, the singular forms “a”, “an”, and “the” are intended to include the plural forms as well, unless the context indicates otherwise. It will be further understood that the terms “comprises” and / or “comprising,” when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein, the term “and / or” includes any combinations of one or more of the associated listed items. It should be noted that the terms “mobile device”, “user equipment”, “user device”, “communication device”, “device” and similar terms are used interchangeably for the purpose of describing the invention. These terms are not intended to limit the scope of the invention or imply any specific functionality or limitations on the described embodiments. The use of these terms is solely for convenience and clarity of description. The invention is not limited to any particular type of device or equipment, and it should be understood that other equivalent terms or variations thereof may be used interchangeably without departing from the scope of the invention as defined herein.

[0055] While considerable emphasis has been placed herein on the components and component parts of the preferred embodiments, it will be appreciated that many embodiments can be made and that many changes can be made in the preferred embodiments without departing from the principles of the disclosure. These and other changes in the preferred embodiment as well as other embodiments of the disclosure will be apparent to those skilled in the art from the disclosure herein, whereby it is to be distinctly understood that the foregoing descriptive matter is to be interpreted merely as illustrative of the disclosure and not as a limitation.

[0056] In 5G core networks, when multiple Home Gateways (HGWs) are connected to a single Customer Premises Equipment (CPE), a critical issue arises when unauthorized HGW s attempt to connect to the network. Such unauthorized HGW s may continuously send session creation requests, which can flood the core network and result in excessive signaling traffic and increased processing load. Additionally, these unauthorized HGWs may serve as vectors for malicious activity, such as Distributed Denial of Service (DDoS) attacks, thereby threatening the security, performance, and reliability of the network.

[0057] Conventional solutions for preventing unauthorized access generally involve permanently blocking Media Access Control (MAC) addresses of suspicious HGWs. However, this method can inadvertently impact legitimate users particularly in scenarios where provisioning is delayed or incomplete leading to service disruptions, user dissatisfaction, and increased operational burden.

[0058] To overcome these challenges, the present disclosure introduces a system and method where, despite repeated session creation attempts by the unauthorized HGW, the network abstains from triggering any internal service operations for a configurable duration. During this time, the MAC address of the unauthorized HGW is temporarily blacklisted at the User Plane Function (UPF) node. The method optimizes signaling procedures by eliminating unnecessary processing andpreventing signaling overload caused by unauthorized HGWs. Further, the method significantly reduces the risk of DDoS attacks by suppressing repeated and malicious session attempts from untrusted HGWs.

[0059] Hereinafter, exemplary embodiments of the present disclosure will be described with reference to the accompanying drawings.

[0060] FIG. 1 illustrates an exemplary network architecture (100) in which or with a system (108) configured for managing one or more communication sessions in a network (106) may be implemented, in accordance with embodiments of the present disclosure.

[0061] As illustrated in FIG. 1, the network architecture (100) may include one or more User Equipment (UEs) (104-1, 104-2... 104-N) associated with one or more users (102-1, 102-2... 102 -N) in an environment. A person of ordinary skill in the art will understand that one or more users (102-1, 102-2... 102-N) may be collectively referred to as the users (102). Similarly, a person of ordinary skill in the art will understand that one or more UEs (104-1, 104-2... 104-N) may be collectively referred to as the UE (104) or the UEs (104). Although only three UE 104 are depicted in FIG. 1, however, any number of the UE (104) may be included without departing from the scope of the ongoing description.

[0062] In an embodiment, the UE (104) may include smart devices operating in a smart environment, for example, an Internet of Things (loT) system. In such an embodiment, the UE (104) may include, but are not limited to, smartphones, smart watches, smart sensors (e.g., a mechanical, a thermal, an electrical, a magnetic, etc.), networked appliances, networked peripheral devices, networked lighting system, communication devices, networked vehicle accessories, networked vehicular devices, smart accessories, tablets, a smart television (TV), computers, a smart security system, a smart home system, other devices for monitoring or interacting with or for the usersY1(102) and / or entities, or any combination thereof. A person of ordinary skill in the art will appreciate that the UE (104) may include, but not limited to, intelligent, multisensing, network- connected devices, that may integrate seamlessly with each other and / or with a central server or a cloud- computing system or any other device that is network-connected.

[0063] Additionally, in some embodiments, the UE (104) may include, but not limited to, a handheld wireless communication device (e.g., a mobile phone, a smartphone, a phablet device, and so on), a wearable computer device (e.g., a headmounted display computer device, a head-mounted camera device, a wristwatch computer device, and so on), a Global Positioning System (GPS) device, a laptop computer, a tablet computer, or another type of portable computer, a media playing device, a portable gaming system, and / or any other type of computer device with wireless communication capabilities, and the like. In an embodiment, the UE (104) may include, but are not limited to, any electrical, electronic, electromechanical, or equipment, or a combination of one or more of the above devices, such as virtual reality (VR) devices, augmented reality (AR) devices, a laptop, a general-purpose computer, a desktop, a personal digital assistant, a tablet computer, a mainframe computer, or any other computing device. Further, the UE (104) may include one or more in-built or externally coupled accessories including, but not limited to, a visual aid device such as a camera, an audio aid, a microphone, a keyboard, and input devices for receiving input from the user (102) or an entity such as a touchpad, a touch-enabled screen, an electronic pen, and the like. A person of ordinary skill in the art will appreciate that the UE (104) may not be restricted to the mentioned devices, and various other devices may be used.

[0064] In an exemplary implementation, the UE 104 may be deployed as a Home Gateway Device (HGW) in a residential or enterprise network environment. In an example, when operating as the HGW, the UE 104 is connected to a CustomerPremises Equipment (CPE) via a Multi-Dwelling Unit (MDU), typically using a Power over Ethernet (PoE) cable. In another exemplary implementation, the UE 104 may be deployed as the HGW connected to the CPE for use in a Fixed Wireless Access (FWA) environment. In an aspect, the CPE may be an outdoor customer premise equipment (ODCPE). In FIG. 1, the UE (104) may communicate with the system (108) through the CPE. The system (108) may comprise a User Plane Function (UPF). In an example, the UE 104 initiates a request to establish a communication session by transmitting a session creation request. The session creation request may include an identity of the UE 104, such as a Media Access Control ID (MAC ID). Upon receiving the request, the system (108) forwards the session creation request, including the MAC ID of the UE 104 as well as its own identity, such as an International Mobile Subscriber Identity (IMSI) and a Subscription Permanent Identifier (SUPI), to a Policy Control Function (PCF). The PCF evaluates the MAC ID of the UE 104 and determines whether a mapping of the MAC ID of the UE 104 and the CPE ID is present in its database. Based on the determination, the PCF transmits a response message back to the UPF. The response message may be a negative response or a positive response. Based on the response message from the PCF, the system (108) determines the status of the requesting UE 104, e.g., whether the HGW is authorized or unauthorized to create a session in the core network.

[0065] Depending on the determined status, the system (108) performs one or more operations. For an authorized UE 104 (i.e., HGW), the system (108) allows the creation of the communication session and establishes the corresponding child Ethernet session over an existing CPE Internet Protocol (IP) protocol data unit (PDU) session using EoGRE tunneling. Conversely, for an unauthorized HGW, the system (108) enforces a restriction by temporarily blacklisting the UE 104 for a configurable duration. During this blacklist period, any further session requests from the same UE 104 (i.e., HGW) are dropped at the system (108) without forwarding them to the core network, thereby mitigating signaling overload.

[0066] In an embodiment, the network (106) may include at least one of a Fourth Generation (4G) network, a Fifth Generation (5G) network, a Sixth Generation (6G) network, or the like. The network 106 may enable the UE (104) to communicate with other devices in the network architecture 100 and / or with the system (108). The network (106) may include a wireless card or some other transceiver connection to facilitate this communication. In another embodiment, the network (106) may be implemented as, or include any of a variety of different communication technologies such as a wide area network (WAN), a local area network (LAN), a wireless network, a mobile network, a Virtual Private Network (VPN), the Internet, the Public Switched Telephone Network (PSTN), or the like.

[0067] In an embodiment, the UE (104) is communicatively coupled with the network (106). The network (106) may receive a connection request from the UE (104). The network (106) may send an acknowledgment of the connection request to the UE (104). The UE (104) may transmit a plurality of signals in response to the connection request.

[0068] In an embodiment, the network (106) may include, by way of example but not limitation, at least a portion of one or more networks having one or more nodes that transmit, receive, forward, generate, buffer, store, route, switch, process, or a combination thereof, etc. one or more messages, packets, signals, waves, voltage or current levels, some combination thereof, or so forth. The network (106) may also include, by way of example but not limitation, a wireless network, a wired network, an internet, an intranet, a public network, a private network, a packet-switched network, a circuit-switched network, an ad hoc network, an infrastructure network, a Public- Switched Telephone Network (PSTN), a cable network, a cellular network, a satellite network, a fiber optic network, or some combination thereof.

[0069] Although FIG. 1 shows exemplary components of the network architecture (100), in other embodiments, the network architecture (100) may includefewer components, different components, differently arranged components, or additional functional components than depicted in FIG. 1.

[0070] FIG. 2 illustrates an exemplary block diagram (200) of the system (108) configured for managing the one or more communication sessions in the network (106), in accordance with embodiments of the present disclosure. FIG. 2 is explained in conjunction with FIG. 1. In an aspect, the system (108) may be embedded or implemented at the User Plane Function (UPF).

[0071] In an embodiment, the system (108) may include a receiving unit (202), a memory (204), an interface (s) (206), a transmitting unit (208), a processing unit (210) and a database (212).

[0072] In an embodiment, the memory (204) may be configured to store one or more computer-readable instructions or routines in a non-transitory computer readable storage medium, which may be fetched and executed to create or share data packets over a network service. The memory (204) may include any non-transitory storage device including, for example, volatile memory such as a Random- Access Memory (RAM), or a non-volatile memory such as an Erasable Programmable Read Only Memory (EPROM), a flash memory, and the like.

[0073] In an embodiment, the interface(s) (206) may include a variety of interfaces, for example, interfaces for data input and output devices (VO), storage devices, and the like. The interface(s) (206) may facilitate communication through the system (108). The interface(s) (206) may also provide a communication pathway for one or more components of the system (108). Examples of such components include, but are not limited to, the receiving unit (202), the transmitting unit (208), the processing unit (210), the database (212).

[0074] In an embodiment, the processing unit (210) may be implemented as a combination of hardware and programming (for example, programmable instructions)to implement one or more functionalities of the processing unit (210). In examples described herein, such combinations of hardware and programming may be implemented in several different ways. For example, the programming for the processing unit (210) may be processor-executable instructions stored on a non- transitory machine-readable storage medium, and the hardware for the processing unit (210) may comprise a processing resource (for example, one or more processors), to execute such instructions. In the present examples, the machine-readable storage medium may store instructions that, when executed by the processing resource, implement the processing unit (210). In such examples, the system (108) may comprise the machine-readable storage medium storing the instructions and the processing resource to execute the instructions, or the machine-readable storage medium may be separate but accessible to the system (108) and the processing resource. In other examples, the processing unit (210) may be implemented by electronic circuitry. In yet other examples, the processing unit (210) may be implemented by each network node of the first cluster. In an example, each network node of the first cluster is the Network Repository Function (NRF). In an aspect, the processing unit (210) is configured to cooperate with the receiving unit (202) and the transmitting unit (208).

[0075] In an embodiment, the receiving unit (202) is configured to receive at least one request for establishing at least one communication session in the network (106) from at least one home gateway (HGW). Establishing the at least one communication session involves setting up an Internet Protocol (IP) protocol data unit (PDU) session in the network (106). The at least one request also allows the system (108) (i.e., the UPF) to verify whether the at least one HGW is authorized to access the network resources. In an aspect, the at least one request includes at least a Media Access Control (MAC) address corresponding to the at least one HGW. The MAC address is a unique hardware identifier assigned to the at least one HGW within the network (106). The MAC address is utilized by the UPF to distinguish one HGW from another HGW within the network (106).

[0076] In an exemplary implementation, a plurality of HGWs are connected to a single customer premise equipment (CPE) via a Multiple Dwelling Unit (MDU). Further, the CPE is connected to the UPF via an Ethernet over Generic Routing Encapsulation (EoGRE) tunnel over the network 106. The CPE may be configured to allow the plurality of HGWs to connect to one or more core network components (such as an Authentication and Management function , a Session Management Function (SMF) etc.), to access the broadband service. To access the broadband service, the MAC ID of each HGW among the plurality of HGWs is mapped to a CPE ID. In an aspect, the CPE ID is one of an International Mobile Subscriber Identity (IMSI) and a Subscription Permanent Identifier (SUPI).

[0077] In an example, when the at least one HGW attempts to access the core network, the at least one HGW transmits the at least one request, including the corresponding MAC ID, to the CPE via a local Ethernet or LAN segment. The CPE then encapsulates the request, including the MAC ID of the HGW and CPE ID, into an EoGRE tunnel packet, and forwards the encapsulated EoGRE tunnel packet to the UPF over the EoGRE tunnel.

[0078] In an embodiment, the transmitting unit (208) at the UPF is configured to forward the at least one received request to a Policy Control Function (PCF). In particular, upon receiving the encapsulated Ethernet frame via the EoGRE tunnel from the CPE, the UPF decapsulates the packet to extract the request and corresponding MAC ID or traffic identifier. The UPF then triggers a policy association procedure by sending a Policy Control Request to the PCF, typically over an N7 interface, The PCF is a network function within the 5G core network responsible for performing policy evaluation, charging control decisions, and authorization of the at least one Home Gateway (HGW) based on subscription data, current network conditions, and predefined policy rules. In an aspect, the PCF may store the mapping of the plurality of HGW ID and the CPE ID in its database, such as database (212). Upon receiving theat least one request, the PCF is configured to determine whether a mapping of the MAC address corresponding to the at least one HGW and the CPE ID is present in its database (212). To perform this determination, the PCF extracts the at least one MAC address from the received at least one request and initiates a lookup operation within the database (212). The lookup operation involves a matching process where the PCF compares the received mapping against a list of pre-authorized mappings of the MAC addresses to the CPE ID existing in the database (212).

[0079] In an embodiment, the receiving unit (202) is configured to receive at least one response message corresponding to the at least one received request from the PCF. The at least one response message includes a negative response or a positive response.

[0080] In an embodiment, the processing unit (210) is configured to determine a status of the at least one HGW based on the at least one received response message. The status of the at least one HGW refers to an indication of the authorization state of the at least one HGW as evaluated by the PCF. The status of the at least one HGW may be an authorized status or an unauthorized status.

[0081] In an aspect, upon determining the MAC address corresponding to the at least one HGW is not present in the database (212), the PCF marks the status of the at least one HGW as the unauthorized status for a configurable time period. The configurable time period refers to a predefined duration during which the unauthorized HGW is restricted from initiating any further requests within the network (106). The configurable time period may be dynamically set by a network operator or administrator based on network policy, security requirements, or system load conditions, and through network management interfaces or policy provisioning systems. In an example, if the at least one HGW fails authorization, the PCF may mark its status as unauthorized and apply the configurable time period of 30 minutes. Further, the PCF is configured to send the at least one response message as the negativeresponse to the UPF. Based on the at least one negative response the processing unit (210) is configured to reject at least one subsequent request received from the at least one HGW for the configurable time period. For example, during the 30 minutes, any further requests from the same MAC address are dropped by the UPF without further querying the core network thereby mitigating unauthorized access attempts and reducing signaling load on the core network.

[0082] In an aspect, upon determining that the mapping of the MAC address corresponding to the at least one HGW and the CPE ID is present in the database (212), the PCF is configured to mark the status of the at least one HGW as the authorized status. In an example, upon performing a successful lookup in the database (212) the PCF determines that the MAC address of the requesting at least one HGW is present in the list of pre-authorized MAC addresses. Based on this determination, the PCF identifies that the requesting HGW is authorized and accordingly marks the HGW as an authorized HGW for establishing the at least one communication session in the network ( 106). Further, the PCF is configured to send the at least one response message as the positive response to the UPF. The positive response provides an indication to create the at least one communication session for the at least one HGW in the network.

[0083] In an exemplary embodiment, the PCF performs a policy association establishment procedure by exchanging an Npcf SMPolicyControl Create message with the SMF, including policy control request triggers for PDU session creation. Upon verifying that the HGW MAC address is pre-authorized, the PCF generates a policy decision and returns an Npcf_SMPolicyControl_Update message carrying policy control rules to the SMF, explicitly authorizing the communication session. The SMF then applies the received policy rules to the UPF through an N4 Session Modification procedure, ensuring the authorized HGW is granted the required QoS and traffic steering rules for the PDU session.

[0084] In an embodiment, the processing unit (210) is configured to performone or more operations associated with the at least one HGW based on the determined status. The one or more operations includes creation of the at least one communication session or restricting the creation of the at least one communication session in the network. In an example, when the status of the at least one HGW is the authorized status, the processing unit (210) initiates the creation of a child Ethernet communication session for the at least one HGW over an existing parent Internet Protocol (IP) Protocol Data Unit (PDU) session established by a customer premise equipment (CPE) in the core network. The at least one communication session is created using an EoGRE tunnel between the CPE and the UPF, enabling the at least one HGW to access network services. The authorized HGW is then assigned an IP address, and corresponding network policies are applied as per the configuration received from the PCF.

[0085] In an exemplary embodiment, when the status of the at least one HGW is authorized status, the session establishment process begins when the at least one authorized HGW initiates a PDU Session Establishment Request, which is received by the AMF through the Radio Access Network (RAN). Upon receiving the request, the AMF selects an appropriate Session Management Function (SMF) instance based on predefined selection criteria, such as load balancing, network slicing configuration, and subscription-specific parameters. The AMF then sends an Nsmf PDUSession CreateSMContext Request to the selected SMF, thereby initiating the creation of a Session Management context. Upon receiving the request, the SMF communicates with a Unified Data Management (UDM) function to retrieve relevant subscription information and registers for any policy updates associated with the requesting HGW. The SMF subsequently responds to the AMF with the Nsmf PDUSession CreateSMContext Response, which includes parameters necessary for continuing the session establishment process. The AMF then proceeds with authentication and authorization of the HGW, ensuring compliance with the network's security and policy framework. In some cases, the SMF performs selectionof a suitable Policy Control Function (PCF) to enforce policy rules. Accordingly, the SMF initiates a policy association establishment or modification procedure with the PCF by sending a corresponding request message. After this, the SMF selects a User Plane Function (UPF) based on network topology, policy rules, and subscription data to handle the user plane traffic for the session. Subsequently, the SMF sends a session establishment or modification request (N4 Session Establishment / Modifi cation Request) to the selected UPF, which then allocates the required resources and responds with an acknowledgment message. The SMF then triggers a Namf_Communication_NlN2MessageTransfer procedure to instruct the AMF to resume NAS signaling with the HGW. Following this, the AMF sends an N2 PDU Session Request NAS message to the RAN. The RAN performs necessary access nodespecific resource configuration and responds with a PDU Session Establishment Accept message, confirming successful allocation of radio and transport resources. Finally, the AMF sends an N2 PDU Session Response to the RAN, thereby completing the session establishment workflow between the HGW and the core network.

[0086] Conversely, when the status of the at least one HGW is the unauthorized status, the processing unit (210) is configured to restrict the creation of the at least one communication session by rejecting the request at the UPF level. The MAC address of the unauthorized HGW is temporarily blacklisted for the configurable time period, and any further requests received from the same HGW during this period are dropped without querying the core network. This prevents signaling overload and mitigates potential misuse or denial-of-service attempts while allowing legitimate retries after the blacklist duration expires.

[0087] FIG. 3 illustrates an exemplary system architecture (300) for managing the one or more communication sessions in the network (106), in accordance with an embodiment of the present disclosure. FIG. 3 is explained in conjunction with FIGs. 1, and 2.

[0088] In an embodiment, the system architecture (300) includes one or more HGWs (302), a Multiple Dwelling Unit (MDU) (304), a Customer Premise Equipment (CPE) (306), a Policy Control Function (PCF) (308), a Charging Function (CHF) (310), ), a Session Management Function (SMF) (312), a Unified Data Management (UDM)(314), an Access and Mobility Management Function (AMF) (316), an Authentication Server Function (AUSF) (318), a User Plane Function (UPF) (322), and an internet (334).

[0089] In an embodiment the 5G CN (320) supports both CPE and HGW sessions. The one or more HGWs (302) are connected to the CPE (306) using the MDU (304). The connection may be established using Power over Ethernet (PoE) cables, which provide power and data connectivity through a single cable. This connection may ensure that both the MDU (304) and the CPE (306) may draw power from the HGW (302) connected to their LAN interfaces.

[0090] In one aspect, the 5GCN (320) provides 5G radio access. The UE (104) capable of 5G may connect to the 5G CN (320). The 5G CN (320) may include various components such as Next Generation Node B (gNodeB), 5G (Open Distributed Sub Carrier) ODSC, and 5G Integrated Distributed Sub Carrier (IDSC).

[0091] In an embodiment, the initial step involves creating an CPE IP PDU session within the 5G CN (320). The CPE IP PDU session is the base for establishing multiple child ethernet sessions for the HGWs (302). The communication between the CPE (306) and the UPF (322) may be facilitated through the EoGRE tunnel, ensuring secure and efficient data transmission.

[0092] In an embodiment, the SMF (312) may manage the sessions. The SMF (312) may create distinct sessions with the PCF (308) and the CHF (310) for the CPE (306). The PCF (308) may handle policy control, ensuring compliance with networkpolicies, while the CHF (310) may manage billing and charging functions essential for network monetization.

[0093] In an embodiment, the system architecture (300) may also include components such as the AUSF (318), the UDM (314), and the AMF (316). The AUSF (318) is connected to both the UDM (314) and the AMF (316), handling authentication processes to ensure secure network access. The UDM (314) may manage subscriber data and profiles, facilitating user authentication and session management. The AMF (316) may interact with the UDM (314) to retrieve user subscription information and with the AUSF (318) for user authentication. The AMF (316) may be connected to the 5G CN (320) and the SMF (312). The AMF (316) may oversee access and mobility functions, ensuring connectivity for mobile devices (104).

[0094] In an aspect, the UPF (322) may facilitate communication between the CPE (306) and 5G CN (320), including the SMF (312) and the PCF (308). The UPF (322) may handle the data packets transmitted over the 5G CN (320), ensuring efficient and secure data flow.

[0095] In an embodiment, the PCF (308) may maintain a mapping in the database (212) that associates the CPE ID with the at least one MAC address. During the provisioning phase or initial registration, the CPE (306) transmits its unique identifier (CPE ID) along with the MAC addresses of the HGWs connected behind it the PCF (308) database accordingly.

[0096] In an embodiment, the UPF (322) is configured to receive the at least one request for establishing the at least one communication session in the network (106) from the at least one HGW. The UPF (322) forwards the at least one received request to the PCF (308). Upon receiving the at least one request, the PCF (308) is configured to determine whether the mapping of the CPE ID with the MAC address corresponding to the at least one HGW is present in the database (212). Based on thisdetermination, the PCF (308) generates and transmits the at least one response message to the UPF (322). In an exemplary aspect, prior to sending the at least one response message, the PCF (308) performs a verification operation by comparing the received MAC address against the list of pre-authorized MAC addresses stored in the database (212). If the MAC address corresponding to the at least one HGW is not found in the database (212), the PCF (308) marks the status of the at least one HGW as the unauthorized status and associates it with the configurable time period, such as 30 minutes. The PCF (308) then transmits the at least one response message as the negative response to the UPF (322). Conversely, if the MAC address corresponding to the at least one HGW is present in the database (212), the PCF (308) marks the status of the HGW as the authorized status and transmits the at least one response message as the positive response to the UPF (322).

[0097] Upon receiving the at least one response message, the UPF (322) is configured to perform the one or more operations associated with the at least one HGW based on the determined status included in the response message. In an example, if the determined status of the at least one HGW is the unauthorized status, the UPF (322) is configured to reject the at least one subsequent request received from the same HGW for the duration of the configurable time period. Further, the UPF (322) restricts the creation of the at least one communication session in the network (106) during that time. Conversely, if the determined status of the at least one HGW is an authorized status, the UPF (322) proceeds with the creation of the at least one communication session in the network (106), thereby enabling the at least one HGW to access network services.

[0098] FIG. 4 illustrates an exemplary process flow (400) for managing the one or more communication sessions in the network (106), in accordance with an embodiment of the present disclosure. FIG. 4 is explained in conjunction with the FIG 1, 2 and 3.

[0099] At step (404), the CPE (306) establishes an IP PDU session with the 5G CN (320), including key components such as the AMF (316), the UPF (322), the SMF (312), the PCF (308), and other elements of the 5G core network (402). This session allows data to be exchanged between the CPE (306) and the other elements of the 5G core network (CN) (402). In an aspect, the other 5GCN (402) refers to the 5G core network functions (NFs) which are involved in HGW or UE attach, like AUSF (318), the UDM (314), AMF (316), CHF (310), etc. The CPE (306) also creates the EoGRE tunnel with the UPF (322). The EoGRE tunnel is established to transport Ethernet frames encapsulated over IP networks. Upon successful IP PDU session establishment, the SMF (312) provides tunnel parameters (e.g., tunnel destination IP, tunnel ID) to the CPE (306) through control-plane signaling. The CPE (306) utilizes these parameters to initiate the EoGRE tunnel setup, enabling Layer 2 (Ethernet) traffic from the at least one HGW.

[0100] At step (406), the one or more HGWs (302) (i.e., the authorized HGW) send a DHCP Discover or DHCPv6 Solicit message to the UPF (322). The communication between the CPE (306) and the UPF (322) may be facilitated through the EoGRE tunnel, ensuring secure and efficient data transmission and all the Ethernet frames of the one or more HGWs (302) are transported through this tunnel. This message requests an IP address assignment, essential for the one or more HGWs (302) to establish network connectivity.

[0101] At step (408), the UPF (322) sends a session report request to the SMF (312). This request includes the HGW Identifier (ID), enabling the SMF (312) to learn a new MAC address of the one or more HGWs (302) detected by the UPF (322).

[0102] At step (410), the SMF (312) may send a Service Management (SM) policy association establishment request to the PCF (308). This request may contain both the HGW ID and the CPE ID, facilitating the authorization of the one or more HGWs (302) for network services. For example, this step ensures that the one or moreHGWs (302) comply with network policies and are authorized to access specific services, such as the internet or voice calls.

[0103] At step (412), the PCF (308) may respond to the SMF (312) with the SM policy association establishment response. This response confirms establishing policies and authorization for the one or more HGWs (302) to access network services such as internet connectivity, online gaming, cloud storage access, VPN (Virtual Private Network) connectivity, smart home automation etc. For example, the PCF (308) may verify that the one or more HGWs (302) have been authorized to access certain bandwidth or priority levels, ensuring quality of service for the user (102).

[0104] At step (414), following the establishment of policies, the SMF (312) may send a session report response to the UPF (322).

[0105] At step (416), a session modification procedure is executed between the SMF (312) and the UPF (322) where unique Packet Detection Rules (PDR), Forwarding Action Rule (FAR), QoS Enforcement Rule (QER) and Usage Reporting Rule (URR) are applied by the SMF (312) in the UPF (322) for each individual HGW session. This procedure informs the UPF (322) of the successful session establishment and the associated policies for the one or more HGWs (302). This step may update the UPF (322) on the current session status and the policies that need to be enforced, ensuring that the session operates within the defined parameters.

[0106] At step (418), following the SMF (312) sends a session report response back to the UPF (322). The UPF (322) may send a DHCP Offer or DHCPv6 Advertise message to the one or more HGWs (302). This message includes the offered IP address, enabling the one or more HGWs (302) to complete its session setup within the 5G CN (320). This step may update the UPF (322) on the current session status and the policies that must be enforced, ensuring that the session operates within the defined parameters.

[0107] At step (420), the one or more HGWs (302) send a DHCP Request or DHCPv6 Request message to the UPF (322), accepting the offered IP address. The one or more HGWs (302) request the IP address offered by the UPF (322), indicating its acceptance and readiness to establish the network session.

[0108] At step (422), the UPF (322) may send a DHCP Acknowledgment or DHCPv6 Reply message back to the one or more HGWs (302), confirming the assignment of the IP address. The UPF (322) may confirm the IP address assignment to the one or more HGWs (302), finalizing the session setup.

[0109] Finally, at step (424), the one or more HGW s (302) ethernet session may be established between the UPF (322), the SMF (312), the PCF (308) and the other elements of the 5G core network (402). This step allows the one or more HGWs (302) to communicate with other network devices, allowing data exchange and communication with other network elements of the 5G core network (402).

[0110] In an exemplary embodiment, once the PCF (308) successfully verifies the MAC address of the HGW against the list of pre-authorized entries, each mapped to a corresponding CPE ID, it marks the HGW as authorized and may generate a Policy Control Decision by transmitting a PCF Decision Message (e.g., N7 Policy Control Request / Answer) to the SMF (312). This message includes policy and charging rules associated with the authorized HGW session, such as QoS enforcement parameters, session-specific policy rules, and traffic steering information. Upon receipt, the SMF (312) selects an appropriate UPF (322) and establishes a PDU session by provisioning session management rules via the N4 Session Establishment Request towards the UPF (322). This includes creating Packet Detection Rules (PDRs), Forwarding Action Rules (FARs), QoS Enforcement Rules (QERs), and usage reporting rules (URRs), as required for the session. The UPF (322), upon successful configuration, allocates the necessary resources, establishes the data path, and responds with a Session Establishment Response, thereby enabling traffic flow for the HGW. Concurrently, theSMF (312) interacts with the UDM (314) to fetch subscriber-related session data, including the subscribed QoS profiles and policy associations. The SMF (312) and AMF (316) then collaborate to transmit the final session acceptance and configuration messages back to the one or more HGWs (302), via the CPE (306).

[0111] FIG. 5 illustrates another exemplary process flow (500) for managing the one or more communication sessions in the network (106), in accordance with an embodiment of the present disclosure. FIG. 5 is explained in conjunction with FIG 1, 2, 3 and 4.

[0112] At step (504), the CPE (306) establishes the IP PDU session in the network (106) such as the UPF (322), the SMF (312), the PCF (308), and other elements of the 5G core network (402). This session allows the CPE (306) to communicate with the other 5G CN (402) and establish necessary connections for data exchange.

[0113] In an aspect, the traffic originating from the HGW (302) residing at individual customer premises passes through the CPE (306). The CPE (306) creates the EoGRE tunnel and encapsulates the unauthorized HGW (502) traffic being sent towards the UPF (322).

[0114] At step (506), a DHCP discover message or DHCPv6 solicit message is sent from the unauthorized HGW (502) to the UPF (322). This message is the attempt of the unauthorized HGW (502) to obtain the IP address and establish a communication session within the 5G CN (320).

[0115] At step (508), the UPF (322) sends the session report request to the SMF (312). The session report request may include the HGW ID, enabling the SMF (312) to identify and manage the session details of the one or more HGWs (302).

[0116] At step (510), the SMF (312) sends an SM policy association establishment request to the PCF (308) to identify the unauthorized HGW (502) is authorized for services or not. This request may contain both the HGW ID and the CPE ID, facilitating the authorization check for the unauthorized HGW (501). For example, the SMF (312) requests the PCF (308) to verify the unauthorized HGW (502) credentials and establish policy associations, identifying them as unauthorized based on the network’s service policies. The unauthorized HGW (502) identified with the associated CPE ID are provisioned in the PCF (308) during customer onboarding in the network. So, if during SM policy association establishment, the PCF (308) is unable to find the requested HGW MAC to CPE ID mapping in its provisioned database, the PCF (308) may mark the HGW as unauthorized to access the operator’s provided services.

[0117] At step (512), the PCF (308) may respond to the SMF (312) with the SM policy association establishment response, confirming the unauthorized HGW (502). This response informs the SMF (312) that the unauthorized HGW (502) is not authorized to access network services. For example, the PCF (308) confirms the unauthorized HGW (502), allowing the SMF (312) to proceed with appropriate actions, such as blacklisting or restricting.

[0118] At step (514), following the confirmation of unauthorized status, the SMF (312) sends a session report response back to the UPF (322), indicating that the one or more HGWs (302) is the unauthorized HGW (502). This step leads to the restriction of the unauthorized HGW (502) for X minutes. In an example, the unauthorized HGW (502) may be blacklisted for a ‘30 minute’ predefined time to prevent repeated unauthorized attempts. For example, the SMF (312) may inform the UPF (322) about the unauthorized HGW (501), and the UPF (322) may take steps to blacklist the unauthorized HGW (502) for a X minutes or a predefined duration, preventing further network access attempts.

[0119] At step (516), after being restricted, the unauthorized HGW (502) might attempt to resend the DHCP discover or DHCPv6 solicit message to the UPF (322) in a retry effort to obtain an IP address. Despite being restricted, the unauthorized HGW (502) attempts to send another DHCP request to the 5G CN (320) to bypass the restriction.

[0120] Further, any further IP assignment requests from the unauthorized HGW (502) are dropped by the UPF (322) without querying the PCF (308) again. This ensures the 5G CN (320) is protected from unnecessary load and potential DDoS attacks from unauthorized devices. The UPF (322), having restricted the unauthorized HGW (502), ignores further DHCP requests from the similar mapping i.e., the HGW ID and the CPE ID mapping, preventing it from consuming network resources or causing disruptions.

[0121] FIG. 6 illustrates an exemplary flowchart of a method (500) for managing the one or more communication sessions in the network (106), in accordance with an embodiment of the present disclosure. FIG. 6 is explained in conjunction with FIG. 2.

[0122] At step (602), the method (600) includes receiving, by a receiving unit (202) at a user plane function (UPF), at least one request for establishing at least one communication session in the network from at least one home gateway (HGW). The at least one request comprising at least a Media Access Control (MAC) address corresponding to the at least one HGW.

[0123] At step (604), the method (600) includes forwarding, by a transmitting unit (208) at the UPF, the at least one received request to a Policy Control Function (PCF).

[0124] At step (606), the method (600) includes receiving, by the receiving unit (202), at least one response message corresponding to the at least one received requestfrom the PCF. The at least one response message includes a negative response or a positive response.

[0125] The method (600) further includes determining, by the PCF, whether the MAC address corresponding to the at least one HGW is present in a database of the PCF. Upon determining the MAC address corresponding to the at least one HGW is not present in the database, marking, by the PCF, the status of the at least one HGW as the unauthorized status for a configurable time period and send at least one negative response message to the UPF. The method further includes rejecting, by the UPF, at least one subsequent request received from the at least one HGW for the configurable time period based on the at least one negative response message.

[0126] The method (600) further includes, upon determining the MAC address corresponding to the at least one HGW is present in the database, marking, by the PCF, the status of the at least one HGW as the authorized status and sending, by the PCF, at least one positive response to the UPF, wherein the positive response provides an indication to create the at least one communication session for the at least one HGW in the network.

[0127] At step (608), the method (600) includes determining, by a processing unit (210) at the UPF, a status of the at least one HGW based on the at least one received response message. The status of the at least one HGW includes an authorized status or an unauthorized status.

[0128] At step (610), the method (600) includes performing, by the processing unit (210), one or more operations associated with the at least one HGW based on the determined status, wherein the one or more operations comprises creation of the at least one communication session or restricting the creation of the at least one communication session in the network.

[0129] FIG. 7 illustrates an example computer system (700) in which or with which the embodiments of the present disclosure may be implemented.

[0130] As shown in FIG. 7, the computer system (700) may include an external storage device (710), a bus (720), a main memory (730), a read-only memory (740), a mass storage device (750), a communication port(s) (760), and a processor (770). A person skilled in the art will appreciate that the computer system (700) may include more than one processor and communication ports. The processor (770) may include various modules associated with embodiments of the present disclosure. The communication port(s) (760) may be any of an RS-232 port for use with a modembased dialup connection, a 10 / 100 Ethernet port, a Gigabit or 10 Gigabit port using copper or fiber, a serial port, a parallel port, or other existing or future ports. The communication ports(s) (760) may be chosen depending on a network, such as a Local Area Network (LAN), Wide Area Network (WAN), or any network to which the computer system (700) connects.

[0131] In an embodiment, the main memory (730) may be Random Access Memory (RAM), or any other dynamic storage device commonly known in the art. The read-only memory (740) may be any static storage device(s) e.g., but not limited to, a Programmable Read Only Memory (PROM) chip for storing static information e.g., start-up or basic input / output system (BIOS) instructions for the processor (770). The mass storage device (750) may be any current or future mass storage solution, which can be used to store information and / or instructions. Exemplary mass storage solutions include, but are not limited to, Parallel Advanced Technology Attachment (PATA) or Serial Advanced Technology Attachment (SATA) hard disk drives or solid-state drives (internal or external, e.g., having Universal Serial Bus (USB) and / or Firewire interfaces).

[0132] In an embodiment, the bus (720) may communicatively couple the processor(s) (770) with the other memory, storage, and communication blocks. Thebus (720) may be, e.g. a Peripheral Component Interconnect PCI) / PCI Extended (PCI- X) bus, Small Computer System Interface (SCSI), Universal Serial Bus (USB), or the like, for connecting expansion cards, drives, and other subsystems as well as other buses, such a front side bus (FSB), which connects the processor (770) to the computer system (700).

[0133] In another embodiment, operator, and administrative interfaces, e.g., a display, keyboard, and cursor control device may also be coupled to the bus (720) to support direct operator interaction with the computer system (700). Other operator and administrative interfaces can be provided through network connections connected through the communication port(s) (760). Components described above are meant only to exemplify various possibilities. In no way should the aforementioned exemplary computer system (700) limit the scope of the present disclosure.

[0134] In an exemplary embodiment, the present disclosure discloses a computer program product comprising a non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform a method for managing one or more communication sessions in a network is described. The method includes receiving, at a user plane function (UPF), at least one request for establishing at least one communication session in the network from at least one home gateway (HGW). The method further includes forwarding, by the UPF, the at least one received request to a Policy Control Function (PCF). The method further includes receiving, by the UPF, at least one response message corresponding to the at least one received request from the PCF. The method further includes determining, by the UPF, a status of the at least one HGW based on the at least one received response message and performing, by the UPF, one or more operations associated with the at least one HGW based on the determined status. The one or more operations comprises creation of the at least one communication session or restricting the creation of the at least one communication session in the network.

[0135] In another exemplary embodiment, the present disclosure discloses a user equipment (UE). The UE is communicatively coupled with a network, the coupling includes receiving, by the network, a connection request from UE, sending, by the network, an acknowledgment of the connection request to the UE and transmitting a plurality of signals in response to the connection request. The one or more communication sessions in the network are managed by a system. The system includes a user plane function (UPF). The UPF includes a receiving unit, a transmitting unit and a processing unit. The receiving unit is configured to receive at least one request for establishing at least one communication session in the network from at least one home gateway (HGW. The transmitting unit is configured to forward the at least one received request to a Policy Control Function (PCF). The receiving unit is configured to receive at least one response message corresponding to the at least one received request from the PCF. The processing unit is configured to determine a status of the at least one HGW based on the at least one received response message and perform one or more operations associated with the at least one HGW based on the determined status. The one or more operations comprises creation of the at least one communication session or restricting the creation of the at least one communication session in the network.

[0136] The present disclosure provides a technical advancement in the field of broadband session management and network access control, particularly in scenarios involving unauthorized Home Gateways (HGWs) attempting to access the network. By introducing a MAC address-based validation mechanism integrated within the Policy Control Function (PCF), the disclosed system enables real-time authorization checks for HGWs attempting to establish communication sessions. This approach ensures that only pre-registered or whitelisted HGWs are permitted to access the network, thereby enhancing network security and preventing unauthorized usage. The PCF performs dynamic lookup and matching operations against a secure database of authorized MAC addresses and communicates the corresponding authorization status to the User PlaneFunction (UPF). This enables the UPF to make informed session control decisions either allowing or rejecting communication sessions based on the authorization result. Furthermore, the system introduces a configurable time-bound status marking feature for unauthorized HGWs, ensuring controlled retry mechanisms and reducing the risk of repeated unauthorized access attempts. The centralized decision-making at the PCF and distributed enforcement at the UPF provides a scalable and policy-driven approach to session control. This not only optimizes resource utilization in the core network but also strengthens operational integrity by ensuring compliance with predefined authorization policies. The disclosed method further facilitates seamless integration into existing 5G core architecture without requiring significant changes to session management procedures. As a result, the solution significantly contributes to robust network access control, service reliability, and enhanced user and operator trust in high-speed broadband environments.

[0137] While the foregoing describes various embodiments of the invention, other and further embodiments of the invention may be devised without departing from the basic scope thereof. The scope of the invention is determined by the claims that follow. The invention is not limited to the described embodiments, versions or examples, which are included to enable a person having ordinary skill in the art to make and use the invention when combined with information and knowledge available to the person having ordinary skill in the art.

[0138] The method and system of the present disclosure may be implemented in a number of ways. For example, the methods and systems of the present disclosure may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above-described order for the steps of the method is for illustration only, and the steps of the method of the present disclosure are not limited to the order specifically described above unless specifically stated otherwise. Further, in some embodiments, the present disclosure may also be embodied as programsrecorded in a recording medium, the programs including machine-readable instructions for implementing the methods according to the present disclosure. Thus, the present disclosure also covers a recording medium storing a program for executing the method according to the present disclosure.

[0139] While considerable emphasis has been placed herein on the preferred embodiments, it will be appreciated that many embodiments can be made and that many changes can be made in the preferred embodiments without departing from the principles of the disclosure. These and other changes in the preferred embodiments of the disclosure will be apparent to those skilled in the art from the disclosure herein, whereby it is to be distinctly understood that the foregoing descriptive matter to be implemented merely as illustrative of the disclosure and not as limitation.ADVANCEMENTS OF THE PRESENT DISCLOSURE

[0140] The present disclosure described herein above has several technical advantages as follows:

[0141] The present disclosure provides a system and a method for optimizing signalling in a network by effectively managing unauthorized home gateways (HGWs).

[0142] The present disclosure provides the system and the method that restricts unauthorized HGWs for a predefined time and prevents repeated and unnecessary signalling, thus reducing the overall signalling load on the network.

[0143] The present disclosure provides the system and the method that protects the network from potential distributed denial of service (DDoS) attacks.

[0144] The present disclosure provides the system and the method that enhances network efficiency and reliability. By avoiding unnecessary session creationand deletion and ensuring that only authorized HGWs can establish sessions, the present disclosure maintains optimal performance and stability in the network.

Claims

CLAIMS1. A system (108) for managing one or more communication sessions in a network (106), the system (108) comprising a user plane function (UPF) (322), the UPF (322) comprising: a receiving unit (202) configured to receive at least one request for establishing at least one communication session in the network from at least one home gateway (HGW); a transmitting unit (208) configured to forward the at least one received request to a Policy Control Function (PCF) (308); the receiving unit (202) configured to receive at least one response message corresponding to the at least one received request from the PCF (308); a processing unit (210) configured to: determine a status of the at least one HGW based on the at least one received response message; and perform one or more operations associated with the at least one HGW based on the determined status, wherein the one or more operations comprises creation of the at least one communication session or restricting the creation of the at least one communication session in the network.

2. The system (108) as claimed in claim 1, wherein the status of the at least one HGW comprises an authorized status or an unauthorized status.

3. The system (108) as claimed in claim 1, wherein the at least one request comprises at least a Media Access Control (MAC) address corresponding to the at least one HGW.

4. The system (108) as claimed in claim 1, wherein the at least one response message comprises a negative response or a positive response.

5. The system (108) as claimed in claim 3, wherein the PCF (308) is configured to: determine whether the MAC address corresponding to the at least one HGW is present in a database (212) of the PCF (308); upon determining the MAC address corresponding to the at least one HGW is not present in the database (212), mark the status of the at least one HGW as the unauthorized status for a configurable time period; send the at least one response message as the negative response to the UPF (322), wherein the processing unit is configured to reject at least one subsequent request received from the at least one HGW for the configurable time period based on the at least one negative response message.

6. The system (108) as claimed in claim 5, wherein upon determining the MAC address corresponding to the at least one HGW is present in the database (212), the PCF (308) is configured to: mark the status of the at least one HGW as the authorized status; and send the at least one response message as the positive response to the UPF (322), wherein the positive response provides an indication to create the at least one communication session for the at least one HGW in the network (106).

7. A method (600) for managing one or more communication sessions in a network (106), the method comprising:receiving (602), at a user plane function (UPF) (322), at least one request for establishing at least one communication session in the network from at least one home gateway (HGW); forwarding (604), by the UPF (322), the at least one received request to a Policy Control Function (PCF) (308); receiving (606), by the UPF (322), at least one response message corresponding to the at least one received request from the PCF (308); determining (608), by the UPF (322), a status of the at least one HGW based on the at least one received response message; and performing (610), by the UPF (322), one or more operations associated with the at least one HGW based on the determined status, wherein the one or more operations comprises creation of the at least one communication session or restricting the creation of the at least one communication session in the network.

8. The method (600) as claimed in claim 7, wherein the status of the at least one HGW comprises an authorized status or an unauthorized status.

9. The method (600) as claimed in claim 7, wherein the at least one request comprising at least a Media Access Control (MAC) address corresponding to the at least one HGW.

10. The method (600) as claimed in claim 7, wherein the at least one response message comprises a negative response or a positive response.

11. The method (600) as claimed in claim 9, further comprising:determining, by the PCF (308), whether the MAC address corresponding to the at least one HGW is present in a database (212) of the PCF (308); upon determining the MAC address corresponding to the at least one HGW is not present in the database (212), marking, by the PCF (308), the status of the at least one HGW as the unauthorized status for a configurable time period; sending, by the PCF (308), at least one negative response message to the UPF (322); and rejecting, by the UPF (322), at least one subsequent request received from the at least one HGW for the configurable time period based on the at least one negative response message.

12. The method (600) as claimed in claim 11, wherein upon determining the MAC address corresponding to the at least one HGW is present in the database (212), the method (600) further comprising: marking, by the PCF (308), the status of the at least one HGW as the authorized status; and sending, by the PCF (308), at least one positive response to the UPF (322), wherein the positive response provides an indication to create the at least one communication session for the at least one HGW in the network (106).

13. A user equipment (UE) (104) communicatively coupled with a network (106), the coupling comprises of: receiving, by the network (106), a connection request from the UE (104); sending, by the network (106), an acknowledgment of the connection request to the UE (104); andtransmitting a plurality of signals in response to the connection request, wherein one or more communication sessions in the network (106) is managed by a system (108) as claimed in claim 1.

14. A computer program product comprising a non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform a method for managing one or more communication sessions in a network, the method comprising: receiving (602), at a user plane function (UPF) (322), at least one request for establishing at least one communication session in the network from at least one home gateway (HGW); forwarding (604), by the UPF (322), the at least one received request to a Policy Control Function (PCF) (308); receiving (606), by the UPF (322), at least one response message corresponding to the at least one received request from the PCF (308); determining (608), by the UPF (322), a status of the at least one HGW based on the at least one received response message; and performing (610), by the UPF (322), one or more operations associated with the at least one HGW based on the determined status, wherein the one or more operations comprises creation of the at least one communication session or restricting the creation of the at least one communication session in the network.

Citation Information

Patent Citations

  • Tsc-5g QOS mapping with consideration of assistance traffic information and pcc rules for tsc traffic mapping and 5g QOS flows binding

    EP4088434A1

  • Authentication support for an electronic device to connect to a telecommunications network

    EP4203392A1

  • Apparatus and method for supporting UPF event exposure service in wireless communication system

    US20210281658A1