System and method for managing one or more home gateways in a network

The enhanced UPF system addresses the limitations of current 5G networks by authenticating and authorizing individual HGWs through unique identifiers, enabling secure, scalable, and efficient management and billing for multiple HGWs connected via a CPE.

WO2026038261A1PCT designated stage Publication Date: 2026-02-19JIO PLATFORMS LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/IN2025/051252
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-14
Filing Date
2025-08-13
Publication Date
2026-02-19

AI Technical Summary

Technical Problem

Current 5G network architectures lack the ability to manage individual Home Gateways (HGWs) connected through a single Customer Premises Equipment (CPE), leading to inadequate authentication, authorization, and accounting, which results in security vulnerabilities and inability to offer differentiated service plans or enforce data caps on a per-device basis.

Method used

A system and method that enhances the User Plane Function (UPF) to perform Authentication, Authorization, and Accounting (AAA) for multiple HGWs by using a Policy Control Function (PCF) to authenticate and authorize HGWs based on their unique MAC addresses and International Mobile Subscriber Identity (IMSI), and monitor data usage against Usage Reporting Rules (URR) to enable individual charging and granular control.

Benefits of technology

Enables per-HGW AAA, enhances security, allows differentiated service plans, and improves scalability and resource allocation efficiency by managing each HGW individually, facilitating precise billing and service differentiation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IN2025051252_19022026_PF_FP_ABST
    Figure IN2025051252_19022026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a system (108) and a method (500) for managing network establishment by a User Plane Function (UPF) (218) for one or more Home Gateways (HGWs) (212) in a network (106). The method (500) comprises receiving, by a receiving unit (230), at least one initialization message from the one or more HGWs (212). The method (500) comprises authenticating, by an authentication unit (240), the one or more HGWs (212) based on at least one parameter. The method (500) comprises authorizing, by an authorization unit (242), the one or more HGWs (212). The method (500) comprises establishing, by a session management unit (244), at least one network session for the one or more HGWs (212). The method (500) comprises monitoring, by an accounting unit (246), data usage for the one or more HGWs (212).
Need to check novelty before this filing date? Find Prior Art

Description

SYSTEM AND METHOD FOR MANAGING ONE OR MORE HOME GATEWAYS IN A NETWORKRESERVATION OF RIGHTS

[0001] A portion of the disclosure of this patent document contains material, which is subject to intellectual property rights such as, but are not limited to, copyright, design, trademark, Integrated Circuit (IC) layout design, and / or trade dress protection, belonging to Jio Platforms Limited (JPL) or its affiliates (hereinafter referred as owner). The owner has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent files or records, but otherwise reserves all rights whatsoever. All rights to such intellectual property are fully reserved by the owner.FIELD OF DISCLOSURE

[0002] The embodiments of the present disclosure generally relate to communication networks. In particular, the present disclosure relates to a system and a method for managing network establishment and charging by a User Plane Function (UPF) for one or more HGWs in a network.DEFINITIONS

[0003] As used in the present disclosure, the following terms are generally intended to have the meaning as set forth below, except to the extent that the context in which they are used indicates otherwise.

[0004] The term ‘Customer Premise Equipment (CPE)’ used hereinafter in the specification refers to a network equipment deployed indoors or outdoors, depending on the network design and signal requirements. The CPE is wirelessly connected to base station or gNodeB.

[0005] The term ‘Home Gateway (HGW)’ used hereinafter in the specification refers to a type of Residential Gateway (RG), which is a device configured to provide communication services such as voice, data, broadcast video, and video on demand to other devices within a home. The HGW acts as an interface between the Wide Area Network (WAN) and the Local Area Network (LAN) IP environment for a consumer broadband customer, capable of routing or bridging traffic depending on its configuration. In the context of the 5G Core Network, the HGW device may function as a User Equipment (UE) or communicate via the CPE, holding a secure element and exchanging Non-Access Stratum (NAS) signalling with the core network (e.g., 5G or 4G) to establish connectivity.

[0006] The expression ‘session’ used hereinafter in the specification refers to a connection established between the HGW and the network. This session allows data to flow between the HGW and the network.

[0007] The expression ‘ethernet session’ used hereinafter in the specification refers to a type of data connection established over an ethernet cable for communication between the HGW and the network.

[0008] The expression ‘International Mobile Subscriber Identity (IMSI)’ used hereinafter in the specification refers to a unique identifier associated with the HGWon a network.

[0009] The expression ‘User Plane Function (UPF)’ used hereinafter in the specification refers to a core network function responsible for processing user data traffic. The UPF includes functionalities such as packet forwarding, routing, a Dynamic Host Configuration Protocol (DHCP) server, and policy enforcement. It may also involve Quality of Service (QoS) management and security features.

[0010] The expression ‘Session Management Function (SMF)’ used hereinafter in the specification refers to a network function responsible for managing user sessions, including session establishment, modification, andtermination. The SMF handles mobility management and resource allocation for user sessions.

[0011] The expression ‘Policy Control Function (PCF)’ used hereinafter in the specification refers to a network function responsible for defining and enforcing network policies. The PCF determines authorized services, resource allocations, and traffic prioritization.

[0012] The expression ‘gNodeB’ used hereinafter in the specification refers to a 5G network base station that provides connectivity between the CPE and the core network. The gNodeB handles radio resource management and radio interface protocols.

[0013] The expression ‘Broadband Network Gateway (BNG)’ used hereinafter in the specification refers to a network device that connects broadband customers to the internet. It handles tasks like user authentication, assigning IP addresses, managing network traffic, and ensuring service quality.

[0014] The expression ‘Dynamic Host Configuration Protocol (DHCP) server’ used hereinafter in the specification refers to a network component that automatically assigns IP addresses and other network settings to devices connected to a network. It simplifies network administration by eliminating the need for manual configuration.

[0015] The expression ‘General Packet Radio Service (GPRS) Tunnelling Protocol (GTP)’ used hereinafter in the specification refers to a group of IP -based communication protocols used to carry data traffic within 3G, 4G, and 5G mobile networks. The GTP encapsulates and transports user data between network elements, enabling seamless communication and mobility.

[0016] The expression ‘HGW (Home Gateway) sessions’ refers to the network communication sessions established and managed by the Home Gateway within a local network environment. These sessions facilitate the interactionbetween user devices (such as computers, smartphones, smart TVs, and loT devices) and the external internet or service provider networks.

[0017] The expression ‘CPE sessions’ used hereinafter refers to the network communication sessions established and managed by the CPE, which serves as an interface between the customer’s external network equipment and the service provider's core network.

[0018] The term “Authentication, Authorization and Accounting (AAA)” used hereinafter in the specification refers to a framework for controlling access to computer resources, enforcing policies, and auditing usage.

[0019] The term “Usage Reporting Rule (URR)” used hereinafter in the specification refers to a rule that defines how a network function should report data usage for a specific session or device.

[0020] The term “Session Report Request (SRR)” used hereinafter in the specification refers to a message sent from the UPF to the SMF to report data usage and session status.

[0021] The term “Session Modification Request (SMR)” used hereinafter in the specification refers to a message sent from the SMF to the UPF to modify an existing session's parameters, such as adding or changing rules.

[0022] These definitions are in addition to those expressed in the art.BACKGROUND OF DISCLOSURE

[0023] The following description of related art is intended to provide background information pertaining to the field of the disclosure. This section may include certain aspects of the art that may be related to various features of the present disclosure. However, it should be appreciated that this section be used only to enhance the understanding of the reader with respect to the present disclosure, and not as admissions of prior art.

[0024] In modern telecommunications systems, high-speed broadband services are delivered to end-users through a variety of access technologies and network topologies. A conventional broadband deployment architecture includes a Customer Premises Equipment (CPE) device situated at the subscriber’s premises, typically responsible for facilitating connectivity between the Home Gateways (HGW) and the 5G core network. In traditional implementations, each customer or household is provisioned with a dedicated CPE device, which in turn connects to a centralized Broadband Network Gateway (BNG). The BNG handles essential control plane and user plane functions, including Authentication, Authorization, and Accounting (AAA).

[0025] Current 5G network architectures face a significant limitation in this scenario, as they are not designed to manage individual devices behind the HGW. This single-point management approach means the network cannot differentiate between devices and is thus unable to provide individual authentication, authorization, or accounting for each separate HGW. This limitation presents several drawbacks in network operations and service offerings.

[0026] As all traffic is treated as a single stream from the CPE, the network is incapable of applying different policies or Quality-of-Service (QoS) levels to individual HGWs. For instance, traffic from a specific HGW used for a home office cannot be prioritized over traffic from another HGW used for entertainment, thereby limiting service flexibility. Furthermore, the lack of individual device authentication introduces security vulnerabilities, as an unauthorized HGW may connect to the network through a legitimate CPE.

[0027] Moreover, with a single charging rule applied to all aggregated traffic from the CPE, it is technically infeasible to accurately bill a subscriber based on the specific data usage of each individual HGW. This excludes service providers from offering differentiated service plans or enforcing data caps on a per-device basis.

[0028] Accordingly, there exists a need in the art for an enhanced system that extends the capabilities of a User Plane Function (UPF) to provide a more granular, device-level solution for authentication, authorization, and accounting. Such a system must be capable of distinguishing between a plurality of HGWs connected through a single CPE and managing each HGW individually.

[0029] Therefore, there is a need for a system and method that overcomes the limitations of the existing state of the art. Such a solution would enable per- HGW AAA and distinguishing between a plurality of HGWs connected through a single CPE and managing each HGW individually.OBJECTS OF THE PRESENT DISCLOSURE

[0030] Some of the objects of the present disclosure, which at least one embodiment herein satisfies are as listed herein below.

[0031] An objective of the present disclosure is to provide a system and a method for enabling a User Plane Function (UPF) to perform an Authentication, Authorization, and Accounting (AAA) method to support multiple Home Gateways (HGWs) connected to a 5G core network via a single Customer Premises Equipment (CPE).

[0032] Another objective of the present disclosure is to provide a system and a method for authenticating and authorizing an individual HGW based on its unique MAC address by interacting with a Policy Control Function (PCF).

[0033] Another objective of the present disclosure is to provide a system and a method for authorizing a specific HGW by verifying a binding between its MAC address and an International Mobile Subscriber Identity (IMSI).

[0034] Another objective of the present disclosure is to provide a system and a method that provides individual charging for each HGW by reporting its data usage against a unique Usage Reporting Rule ID (URR ID).

[0035] Another objective of the present disclosure is to provide a system and a method for offering granular control and enhanced security for devices operating behind a Customer Premises Equipment (CPE) in the network.

[0036] Another objective of the present disclosure is to provide a system and a method that enhances scalability and resource allocation efficiency in broadband networks.

[0037] Another objective of the present disclosure is to provide a system and a method that simplifies network architecture by reducing the number of required network elements and interfaces.SUMMARY

[0038] In an exemplary embodiment, a method for managing network establishment of a plurality of network entities in a network is described. The method includes receiving, by a receiving unit, at least one initialization message from the one or more HGWs over a tunnel. The method includes authenticating, by an authentication unit, the one or more HGWs based on at least one parameter obtained from the at least one received initialization message. The method includes authorizing, by an authorization unit, the one or more HGWs by a Session Management Function (SMF), wherein the SMF interacts with a Policy Control Function (PCF) to determine authorization status, wherein the authorization unit receives a positive acknowledgment from the SMF upon successful authorization. The method includes establishing, by a session management unit, at least one network session for the one or more HGWs upon receiving the successful authorization. The method includes monitoring, by an accounting unit, data usage for the one or more HGWs corresponding to the established network session based on one or more usage reporting rules.

[0039] In an embodiment, the one or more HGWs, upon powering on, sends the at least one initialization message via a gNodeB to the UPF.

[0040] In an embodiment, the tunnel comprises an Ethernet over Generic Routing Encapsulation (EoGRE) tunnel within a General Packet Radio Service (GPRS) Tunnelling Protocol (GTP) tunnel, and wherein the GTP tunnel is transmitted via the gNodeB and terminated at the UPF.

[0041] In an embodiment, the initialization message is at least one of a Dynamic Host Configuration Protocol (DHCPv4) Discover message or a DHCPv6 Solicit message.

[0042] In an embodiment, the at least one parameter comprises a Media Access Control (MAC) address of the one or more HGWs.

[0043] In an embodiment, the authentication includes verifying, by the UPF that the MAC address included in a client-identifier field of the at least one initialization message matches with a source MAC address of a received Ethernet frame encapsulating the initialization message received from the one or more HGWs. The authentication includes transmitting, by the UPF, a Session Report Request (SRR) message to the SMF, the SRR message including the verified MAC address and a usage report corresponding to the one or more HGWs.

[0044] In an embodiment, the authorization includes determining, by the SMF, whether the MAC address of the one or more HGWs is authorized based on a preconfigured MAC-to-IMSI association for a Customer Premises Equipment (CPE). The authorization includes transmitting, by the SMF, a Session Modification Request (SMR) message to the UPF upon successful authorization. The SMR message includes at least one of: an Internet Protocol (IP) address assigned to the one or more HGWs, a Packet Detection Rule (PDR), a Forwarding Action Rule (FAR), a Quality of Experience Rule (QER) and a Usage Reporting Rule (URR) corresponding to the one or more HGWs.

[0045] In an exemplary embodiment, a method for charging one or more HGWs in a network is disclosed. The method includes monitoring, by an accounting unit, data usage for each of the one or more HGWs based on a UsageReporting Rule (URR) identifier associated with a Media Access Control (MAC) address of each of the one or more HGWs. The method includes generating, by the accounting unit, a usage report for each of the one or more HGWs based on the monitored data usage. The method includes sending, by the accounting unit, the usage report to a Session Management Function (SMF) in a Session Report Request (SRR) message, the SRR message including the usage report and the corresponding MAC address. The method includes forwarding, by the SMF, the usage report to a charging unit for generation of billing records for each of the one or more HGWs.

[0046] In an embodiment, the URR identifier for each of the one or more HGW configured by the SMF in a Session Modification Request (SMR) message, the SMR message including the MAC address of the one or more HGWs.

[0047] In an embodiment, the accounting unit maintains a mapping of each of the one or more HGW with a corresponding IP address and the URR identifier.

[0048] In an embodiment, the usage report comprises a volume measurement Information Element (IE) including uplink and downlink data usage associated with the URR identifier, and the SRR message includes the MAC address of the one or more HGWs.

[0049] In an exemplary embodiment, a system for managing network establishment by a User Plane Function (UPF) for one or more Home Gateways (HGWs) in a network is disclosed. The system includes a receiving unit configured to receive at least one initialization message from the one or more HGWs over a tunnel. The system includes an authentication unit configured to authenticate the one or more HGWs based on at least one parameter obtained from the at least one received initialization message. The system includes an authorization unit configured to authorize the one or more HGWs by a Session Management Function (SMF), wherein the SMF is configured to interact with a Policy Control Function (PCF) to determine authorization status, and to receive a positive acknowledgment from the SMF upon successful authorization. The system includes a session management unit configured to establish at least one network session for the one ormore HGWs upon receiving the successful authorization. The system includes an accounting unit configured to monitor data usage for the one or more HGWs corresponding to the established network session based on one or more usage reporting rules.

[0050] In an exemplary embodiment, a computer program product comprising a non-transitory computer-readable medium is disclosed. The medium includes instructions that, when executed by one or more processors, cause the one or more processors to execute a method for managing network establishment of a plurality of network entities in a network is described. The method includes receiving, by a receiving unit, at least one initialization message from the one or more HGWs over a tunnel. The method includes authenticating, by an authentication unit, the one or more HGWs based on at least one parameter obtained from the at least one received initialization message. The method includes authorizing, by an authorization unit, the one or more HGWs by a Session Management Function (SMF), wherein the SMF interacts with a Policy Control Function (PCF) to determine authorization status, wherein the authorization unit receives a positive acknowledgment from the SMF upon successful authorization. The method includes establishing, by a session management unit, at least one network session for the one or more HGWs upon receiving the successful authorization. The method includes monitoring, by an accounting unit, data usage for the one or more HGWs corresponding to the established network session based on one or more usage reporting rules.

[0051] In an exemplary embodiment, a computer program product comprising a non-transitory computer-readable medium is disclosed. The medium includes instructions that, when executed by one or more processors, cause the one or more processors to execute a method for charging one or more HGWs in a network is disclosed. The method includes monitoring, by an accounting unit, data usage for each of the one or more HGWs based on a Usage Reporting Rule (URR) identifier associated with a Media Access Control (MAC) address of each of the one or more HGWs. The method includes generating, by the accounting unit, ausage report for each of the one or more HGWs based on the monitored data usage. The method includes sending, by the accounting unit, the usage report to a Session Management Function (SMF) in a Session Report Request (SRR) message, the SRR message including the usage report and the corresponding MAC address. The method includes forwarding, by the SMF, the usage report to a charging unit for generation of billing records for each of the one or more HGWs.BRIEF DESCRIPTION OF DRAWINGS

[0052] The accompanying drawings, which are incorporated herein, and constitute a part of this disclosure, illustrate exemplary embodiments of the disclosed methods and systems in which like reference numerals refer to the same parts throughout the different drawings. Components in the drawings are not necessarily to scale, emphasis instead being placed upon clearly illustrating the principles of the present disclosure. Some drawings may indicate the components using block diagrams and may not represent the internal circuitry of each component. It will be appreciated by those skilled in the art that disclosure of such drawings includes the disclosure of electrical components, electronic components or circuitry commonly used to implement such components.

[0053] FIG. 1 illustrates an exemplary network architecture for implementing a system for managing network establishment by a User Plane Function (UPF) for one or more Home Gateways (HGWs) in a network, in accordance with embodiments of the present disclosure.

[0054] FIG. 2A illustrates an exemplary system architecture for managing network establishment by the UPF for the one or more HGWs in the network, in accordance with embodiments of the present disclosure.

[0055] FIG. 2B illustrates an exemplary block diagram of the system for managing network establishment by the UPF for the one or more HGWs in the network, in accordance with embodiments of the present disclosure.

[0056] FIG. 3 illustrates a flowchart of a method for managing network establishment by the UPF for the one or more HGWs in the network, in accordance with embodiments of the present disclosure.

[0057] FIG. 4 illustrates an exemplary flow diagram of a method for charging the one or more HGWs in the network, in accordance with embodiments of the present disclosure.

[0058] FIG. 5 illustrates an exemplary computer system in which or with which embodiments of the present disclosure may be implemented.

[0059] The foregoing shall be more apparent from the following more detailed description of the disclosure.LIST OF REFERENCE NUMERALS100 - Network Architecture102-1, 102-2, 102-N - Users104-1, 104-2, 104-N - User Equipments (UEs)112-1, 112-2, 112-N - Base stations106 - Network108 - System200A - System architecture212-1, 212-2 - One or more Home Gateways (HGWs)214 - Customer Premise Equipment (CPE)218 - User Plane Function (UPF)220 - Session Management Function (SMF)222 - Policy Control Function (PCF)226 - gNodeB228 - Internet200B - Block diagram230 - Receiving unit232 - Memory234 - Interface(s)236 - Processing engine240 - Authentication unit242 - Authorization unit244 - Session management unit246 - Accounting unit248 - Database300 - Flow diagram400 - Method flow diagram500 - Computer system510 - External storage device520 - Bus530 - Main memory540 - Read only memory550 - Mass storage device560 - Communication port(s)570 - ProcessorDETAILED DESCRIPTION OF DISCLOSURE

[0060] In the following description, for the purposes of explanation, various specific details are set forth in order to provide a thorough understanding of embodiments of the present disclosure. It will be apparent, however, that embodiments of the present disclosure may be practiced without these specific details. Several features described hereafter can each be used independently of one another or with any combination of other features. An individual feature may not address all of the problems discussed above or might address only some of the problems discussed above. Some of the problems discussed above might not be fully addressed by any of the features described herein.

[0061] The ensuing description provides exemplary embodiments only, and is not intended to limit the scope, applicability, or configuration of the disclosure.Rather, the ensuing description of the exemplary embodiments will provide those skilled in the art with an enabling description for implementing an exemplary embodiment. It should be understood that various changes may be made in the function and arrangement of elements without departing from the spirit and scope of the disclosure as set forth.

[0062] Specific details are given in the following description to provide a thorough understanding of the embodiments. However, it will be understood by one of ordinary skill in the art that the embodiments may be practiced without these specific details. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form in order not to obscure the embodiments in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail in order to avoid obscuring the embodiments.

[0063] Also, it is noted that individual embodiments may be described as a process which is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. Although a flowchart may describe the operations as a sequential process, many of the operations can be performed in parallel or concurrently. In addition, the order of the operations may be re-arranged. A process is terminated when its operations are completed but could have additional steps not included in a figure. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination can correspond to a return of the function to the calling function or the main function.

[0064] The word “exemplary” and / or “demonstrative” is used herein to mean serving as an example, instance, or illustration. For the avoidance of doubt, the subject matter disclosed herein is not limited by such examples. In addition, any aspect or design described herein as “exemplary” and / or “demonstrative” is not necessarily to be construed as preferred or advantageous over other aspects or designs, nor is it meant to preclude equivalent exemplary structures and techniquesknown to those of ordinary skill in the art. Furthermore, to the extent that the terms “includes,” “has,” “contains,” and other similar words are used in either the detailed description or the claims, such terms are intended to be inclusive in a manner similar to the term “comprising” as an open transition word without precluding any additional or other elements.

[0065] Reference throughout this specification to “one embodiment” or “an embodiment” or “an instance” or “one instance” means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present disclosure. Thus, the appearances of the phrases “in one embodiment” or “in an embodiment” in various places throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0066] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the disclosure. As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises” and / or “comprising,” when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein, the term “and / or” includes any and all combinations of one or more of the associated listed items.

[0067] The present disclosure relates to a system and a method for improving communication in a network by managing one or more Home Gateways (HGWs). Various embodiments throughout the disclosure will be explained in more detail with reference to FIGS. 1-5.

[0068] FIG. 1 illustrates an exemplary network architecture (100) for implementing a system (108) for managing network establishment by a User PlaneFunction (UPF) (218) for one or more Home Gateways (HGWs) (212) in a network (106), in accordance with embodiments of the present disclosure.

[0069] Referring to FIG. 1, the network architecture (100) may include one or more computing devices or user equipments (104-1, 104-2. . . 104-N) associated with one or more users (102-1, 102-2. .. 102-N) in an environment. The network architecture (100) may be applied on Fixed Wireless Access (FWA) deployments, where wireless cellular technology provides broadband connectivity to fixed subscriber locations. A person of ordinary skill in the art will understand that one or more users (102-1, 102-2. .. 102-N) may be individually referred to as the user (102) and collectively referred to as the users (102). Similarly, a person of ordinary skill in the art will understand that one or more user equipments (UE) (104-1, 104- 2... 104-N) may be individually referred to as the user equipment (104) and collectively referred to as the user equipment (104). A person of ordinary skill in the art will appreciate that the terms “computing device(s)” and “user equipment” may be used interchangeably throughout the disclosure. Although three user equipments (104) are depicted in FIG. 1, however, any number of the user equipments (104) may be included without departing from the scope of the ongoing description. In an embodiment, each of the user equipment (104) may have a unique identifier attribute associated therewith. In an embodiment, the unique identifier attribute may be indicative of Mobile Station International Subscriber Directory Number (MSISDN), International Mobile Equipment Identity (IMEI) number, International Mobile Subscriber Identity (IMSI), Subscriber Permanent Identifier (SUPI) and the like.

[0070] In an embodiment, the user equipment (104) may include smart devices operating in a smart environment, for example, an Internet of Things (loT) system. In such an embodiment, the user equipment (104) may include, but is not limited to, smartphones, smart watches, smart sensors (e.g., mechanical, thermal, electrical, magnetic, etc.), networked appliances, networked peripheral devices, networked lighting system, communication devices, networked vehicle accessories, networked vehicular devices, smart accessories, tablets, smart television (TV),computers, smart security system, smart home system, other devices for monitoring or interacting with or for the users (102) and / or entities, or any combination thereof. A person of ordinary skill in the art will appreciate that the user equipment (104) may include, but is not limited to, intelligent, multi-sensing, network-connected devices that can integrate seamlessly with each other and / or with a central server or a cloud-computing system or any other device that is network-connected.

[0071] In an embodiment, the user equipment (104) may include, but is not limited to, a handheld wireless communication device (e.g., a mobile phone, a smartphone, a phablet device, and so on), a wearable computer device (e.g., a headmounted display computer device, a head-mounted camera device, a wristwatch computer device, and so on), a Global Positioning System (GPS) device, a laptop computer, a tablet computer, or another type of portable computer, a media playing device, a portable gaming system, and / or any other type of computer device with wireless communication capabilities, and the like. In an embodiment, the user equipment (104) may include but is not limited to, any electrical, electronic, electromechanical, or an equipment, or a combination of one or more of the above devices such as virtual reality (VR) devices, augmented reality (AR) devices, laptop, a general -purpose computer, desktop, personal digital assistant, tablet computer, mainframe computer, or any other computing device, wherein the user equipment (104) may include one or more in-built or externally coupled accessories including, but not limited to, a visual aid device such as a camera, an audio aid, a microphone, a keyboard, and input devices for receiving input from the user (102) or the entity such as touchpad, touch-enabled screen, electronic pen, and the like. A person of ordinary skill in the art will appreciate that the user equipment (104) may not be restricted to the mentioned devices and various other devices may be used.

[0072] Referring to FIG. 1, the user equipment (104) may communicate with the system (108) via the network (106). The UE (104) may be communicatively coupled with the network (106). The communicative coupling comprises receiving, from the UE (104), a connection request by the network (106), sending an acknowledgment of the connection request to the UE (104), andtransmitting a plurality of signals in response to the connection request. In an embodiment, the network (106) may include at least one of a Fourth Generation (4G) network, a Fifth Generation (5G) network, a Sixth Generation (6G) network, or the like. The network (106) may enable the user equipment (104) to communicate with other devices in the network architecture (100) and / or with the system (108). The network (106) may include a wireless card or another transceiver connection to facilitate this communication. In another embodiment, the network (106) may be implemented as or include any of a variety of different communication technologies such as a wide area network (WAN), a local area network (LAN), a wireless network, a mobile network, a Virtual Private Network (VPN), the Internet, the Public Switched Telephone Network (PSTN), or the like.

[0073] In an embodiment, the UE (104) may be deployed as a home gateway device (HGW) connected to a customer premise equipment (CPE) for use in a Fixed Wireless Access (FWA) environment. In an example, the UE (104) may be statically located at a fixed customer premises and connected to the core network via a wireless access network.

[0074] Although FIG. 1 shows exemplary components of the network architecture (100), in other embodiments, the network architecture (100) may include fewer components, different components, differently arranged components, or additional functional components than depicted in FIG. 1. Additionally, or alternatively, one or more components of the network architecture (100) may perform functions described as being performed by one or more other components of the network architecture (100).

[0075] FIG. 2A illustrates a system architecture (200A) for implementing a system (108) for managing network establishment by the User Plane Function (UPF) (218) for the one or more Home Gateways (HGWs) (212) in the network (106), in accordance with embodiments of the present disclosure.

[0076] In an embodiment, the system architecture (200A) further comprises the one or more HGWs (212-1, 212-1), a Customer Premises Equipment (CPE)(214), gNodeB (226) a User Plane Function (UPF) (218), a Session Management Function (SMF) (220), and a Policy Control Function (PCF) (222) and the internet (228). A person of ordinary skill in the art will understand that the one or more HGWs (212-1, 212-1) may be individually referred to as the HGW (212) and collectively referred to as the HGWs (212).

[0077] In an aspect, the HGW (212) represents the end-user device, such as a router or modem, within residential or commercial premises. The HGW (212) is the interface between the UE (104) and the network (106). The HGW (212) represents an end-user device within residential or commercial premises, such as a router or modem. For instance, a home router is a common example of the HGW (212).

[0078] In an aspect, the CPE (214) may be installed externally to connect with the HGW (212). The CPE (214) may be a central point for connecting the HGW (212) to the core network. The CPE (214) may include hardware for signal amplification, modulation, and multiplexing to efficiently handle the combined traffic from the HGW (212). The traffic originating from the HGW (212) residing at individual customer premises passes through the CPE (214). The CPE (214) creates the EoGRE tunnel with the core network and encapsulates the HGW traffic sent to the core network.

[0079] In an aspect, the gNodeB (226) supports both the CPE (214) and the HGW (212) sessions and manages the radio connection and initial processing of data traffic. From the CPE (214), the traffic reaches the gNodeB (226), creating the GTP tunnel for the packets and sending them towards the UPF (218) via a N3 interface endpoint. The N3 interface connects the UPF (218) to the Radio Access Network (RAN), specifically the gNodeB (226), which is the 5G base station. As part of the attach procedure, the gNodeB (226) learns the N3 interface endpoint gNodeB (226) learns the N3 interface endpoint and the associated GTP tunnel-ID. The GTP tunnel-ID is a unique identifier for a tunnel established between the gNodeB (226) and the UPF (218). The GTP tunnel encapsulates user data packets,allowing them to travel through the network while maintaining session information. This is similar to how a base station in a cellular network manages data traffic from the one or more UEs (104) and ensures it is correctly routed through the network (106). The gNodeB (226) ensures the data packets are appropriately formatted and transmitted, maintaining a stable connection between the CPE (214) and the core network.

[0080] In an aspect, the UPF (218) serves as the anchor point for all user data traffic. The UPF (218) is configured with additional functionality, referred to as Broadband Network Gateway (BNG) functionality, which enables it to perform Authentication, Authorization, and Accounting (AAA) of subscriber sessions, policy management, and Quality of Service (QoS) enforcement on a per-HGW basis. This is a key feature of the invention that allows the UPF (218) to manage individual HGWs (212) even though they connect through a single CPE (214).

[0081] In an aspect, the UPF (218) communicates with the SMF (220) to manage session states and data reporting. The SMF (220) is configured for establishing and managing sessions for the HGW (212). The SMF (220) communicates with the PCF (222) to enforce policies and the UPF (218) to manage session states and data reporting. The SMF (220) may also ensure that data usage is accurately tracked and reported for billing purposes. For instance, the UPF (218) sends session modification requests to the SMF (220) to facilitate the authentication of an HGW (212) based on its MAC address. The SMF (220) in turn communicates with the PCF (222) to enforce network policies. The PCF (222) is responsible for providing policy decisions, including the authentication and authorization of the HGWs (212) by verifying their MAC addresses and associated bindings. The UPF (218) also reports data usage to the SMF (220) for individual HGWs (212), which enables precise charging.

[0082] In an aspect, the Internet (228) may provide external network connectivity, allowing the HGW (212) to access online resources and services. Once the HGW (212) is authenticated and authorized, it can access the internet(228) through the UPF (218), which routes the traffic appropriately. For example, when the user (102) browses a website on the UE (104), the HGW (212) may send a request to the UPF (218), which then routes it to the internet (228), retrieving the necessary data and delivering it back to the UE (104).

[0083] FIG. 2B illustrates an exemplary block diagram (200B) of the system (108) for managing network establishment by the User Plane Function (UPF) (218) for the one or more Home Gateways (HGWs) (212) in the network (106), in accordance with embodiments of the present disclosure.

[0084] The system (108) is configured for supporting a plurality of network equipment including one or more Home Gateways (HGWs) (212) connected via the Customer Premises Equipment (CPE) (214) and further comprises a User Plane Function (UPF) (218), a Session Management Function (SMF) (220), and a Policy Control Function (PCF) (222). The system (108) is adapted to receive, retrieve, and process encapsulated data packets associated with the HGWs (212), in accordance with a method and architecture that supports the integration of the Broadband Network Gateway (BNG) functionalities into the UPF (218).

[0085] Referring to FIG. 2, the system (108) may include an interface(s) (234) that may include a variety of interfaces, for example, interfaces for data input and output devices, referred to as I / O devices, storage devices, and the like. The interface(s) (234) may facilitate communication to / from the system (108). The interface(s) (234) may also provide a communication pathway for one or more components of the system (108). Examples of such components include, but are not limited to, a processing engine (236) and a database (248).

[0086] In an embodiment, the processing engine (236) may be implemented as a combination of hardware and programming (for example, programmable instructions) to implement one or more functionalities of the processing engine (236). In the examples described herein, such combinations of hardware and programming may be implemented in several different ways. For example, the programming for the processing engine (236) may be processor-executableinstructions stored on a non-transitory machine-readable storage medium, and the hardware for the processing engine (236) may include a processing resource (for example, one or more processors) to execute such instructions. In the present examples, the machine-readable storage medium may store instructions that, when executed by the processing resource, implement the processing engine (236). In such examples, the system (108) may include the machine-readable storage medium storing the instructions and the processing resource to execute the instructions, or the machine-readable storage medium may be separate but accessible to the system (108) and the processing resource. In other examples, the processing engine (236) may be implemented by electronic circuitry.

[0087] Among other capabilities, the processing engine (236) may be configured to fetch and execute computer-readable instructions stored in a memory (232) of the system (108). The memory (232) may be configured to store one or more computer-readable instructions or routines in a non-transitory computer- readable storage medium, which may be fetched and executed to create or share data packets over a network service. The memory (232) may include any non- transitory storage device, including, for example, volatile memory such as Random Access Memory (RAM), or non-volatile memory such as Erasable Programmable Read-Only Memory (EPROM), flash memory, and the like.

[0088] In an embodiment, the database (248) may include data that may be either stored or generated as a result of functionalities implemented by the processing engine (236). In an embodiment, the database (248) may be separate from the system (108). In an embodiment, the database (248) may be indicative of including, but not limited to, a relational database, a distributed database, a cloudbased database, or the like.

[0089] In an embodiment, the processing engine (236) may further comprise other modules. The processing engine (208) may include multiple subcomponents responsible for different functionalities related to managing the one or more HGWs (212). The other modules include an authentication unit (240), anauthorization unit (242), a session management unit (244), and an accounting unit (246).

[0090] In an embodiment, the CPE (214) may be configured to connect to the one or more HGWs (212). The CPE (214) serves as the intermediary between the HGWs (212) and the core network, facilitating their interaction. The CPE (214) connects to multiple HGWs (212), aggregating their data and managing their connections to the network. The CPE (214) handles the combined data traffic by performing signal amplification, modulation, and multiplexing. This aggregation and management capability ensures that the HGWs (212) can communicate effectively with the core network, optimizing the overall network performance.

[0091] In an embodiment, the traffic originating from the HGWs (212) residing at individual customer premises passes through the CPE (214). The CPE (214) creates the EoGRE tunnel and encapsulates the HGW traffic sent to the core network. In an example, the EoGRE tunnel performs generic routing encapsulation (GRE) on an Ethernet protocol-based packet so that a packet obtained through encapsulation can be transmitted in a network that uses another network layer protocol. EoGRE tunnel uses a tunnelling protocol that encapsulates Ethernet frames. This enables the transport of Ethernet frames over IP networks, allowing for the extension of Ethernet networks across geographically dispersed locations. From the CPE (214), the traffic reaches the gNodeB (226), creating the GPRS Tunnelling protocol (GTP) tunnel for the packets.

[0092] In an aspect, the system (108) comprises a receiving unit (230) configured to receive at least one initialization message from the one or more HGWs (212) over a tunnel. The network establishment process is initiated when the one or more HGWs (212) are powered on. Upon powering on, the HGW (212) sends the at least one initialization message to the UPF (218) via the gNodeB (226). The receiving unit (230) is configured to receive this initialization message over the tunnel. The tunnel is an Ethernet over Generic Routing Encapsulation (EoGRE) tunnel encapsulated within a General Packet Radio Service (GPRS) TunnellingProtocol (GTP) tunnel. The GTP tunnel is transmitted via the gNodeB (226) and is terminated by the UPF (218), allowing the UPF (218) to access the underlying EoGRE and initialization messages. The initialization message is at least one of a Dynamic Host Configuration Protocol (DHCPv4) Discover message or a DHCPv6 Solicit message. The at least one parameter comprises the unique Media Access Control (MAC) address of the HGW (212). The authentication unit (240) is then configured to authenticate the one or more HGWs (212) based on the at least one parameter. The authentication process is the first step in ensuring that the network session is only established for a recognized device.

[0093] In an embodiment, following authentication, the authorization unit (242) is configured to initiate the authorization of the one or more HGW (212) based on the at least one parameter obtained from the at least one received initialization message. To do so, the UPF (218) sends a request to the SMF (220). The SMF (220) is configured to interact with a Policy Control Function (PCF) (222) to determine an authorization status of the HGW (212). The SMF (220) and PCF (222) work in conjunction to determine whether the MAC address of the HGW (212) is authorized based on a preconfigured MAC-to-IMSI association for the CPE (214). The preconfigured MAC-to-IMSI association for the CPE (214) is stored in the database (248) of the system (108). This ensures that the HGW (212) is not only recognized but is also connecting through a legitimate and authorized CPE (214). Upon successful authorization, the UPF (218) receives a positive acknowledgment from the SMF (220). Upon receiving this acknowledgment, the session management unit (244) of the UPF (218) is configured to establish a network session for the HGW (212), thereby enabling it to access network services.

[0094] In an embodiment, the system includes the session management unit (244). The session management unit (244) is configured to establish at least one network session for the one or more HGWs (212). The establishment of the at least one session is a critical step that occurs only after the system (108) receives a successful authorization from the SMF (220). The session management unit (244) uses the parameters and rules provided by the SMF (220) in the SessionModification Request (SMR) message to properly configure the network session for the one or more HGWs (212), ensuring it is ready to handle data traffic according to the prescribed policies.

[0095] In an embodiment, upon successful authorization, the SMF (220) transmits a Session Modification Request (SMR) message to the UPF (218). The SMR message is crucial as it contains the necessary policy rules and session parameters for the newly authorized HGW (212), including at least one of an Internet Protocol (IP) address assigned to the HGW, a Packet Detection Rule (PDR), a Forwarding Action Rule (FAR), a Quality of Experience Rule (QER), and a Usage Reporting Rule (URR). The UPF (218) uses these rules to manage the HGW's session, including directing its traffic, enforcing QoS, and, importantly, preparing for individual charging.

[0096] In an embodiment, as part of the established session, the accounting unit (246) of the UPF (218) is configured to monitor data usage for the one or more HGW (212). The accounting unit (246) monitors usage based on a unique Usage Reporting Rule (URR) identifier that is associated with the MAC address of the one or more HGWs (212). The URR identifier is configured by the SMF (220) and is sent to the UPF (218) in the SMR message during authorization. To facilitate this process, the accounting unit (246) maintains a mapping of each of the one or more HGW (212) with its corresponding IP address and URR identifier.

[0097] In an embodiment, the charging system continues its operation. The accounting unit (246) generates a usage report for each HGW (212) based on the data it has monitored. The UPF (218) then sends the usage report to the SMF (220) in a Session Report Request (SRR) message. The SRR message comprises a volume measurement Information Element (IE) including detailed uplink and downlink data usage associated with URR identifier of the one or more HGWs (212) and also includes the MAC address of the one or more HGWs (212) to ensure correct attribution. Finally, the SMF (220) is configured to forward the usage report to acharging unit (e.g., a Charging Function) for the generation of accurate billing records for each of the one or more HGWs (212).

[0098] In an embodiment, an additional security verification step is performed by the UPF (218). The UPF (218) is configured to verify that the MAC address included in a client-identifier field of the initialization message (e.g., a DHCP message) matches with the source MAC address of the received Ethernet frame that encapsulates the message. This dual verification provides an enhanced security measure to prevent spoofing and ensure that identity of the one or more HGWs (212) is genuine from the physical layer up to the application layer, further strengthening the integrity of the authentication process.

[0099] In an illustrative working example, a UPF (218) receives a data packet from a new, unauthorized HGW (212). To authenticate and authorize the HGW (212), the UPF (218) communicates with the SMF (220), which interacts with the PCF (222). The PCF (222) verifies a preconfigured MAC-to-IMSI binding for the associated CPE (214). Upon successful authorization, the SMF (220) sends an SMR message to the UPF (218), which includes an IP address and a unique URR ID.

[0100] With the HGW (212) session established, the accounting unit (246) begins its charging function. It monitors all data usage from the HGW (212) against the specific URR ID. When the session ends, the UPF (218) generates a usage report and sends it in an SRR message to the SMF (220). The SMF (220) forwards this report to the charging unit, which can then generate a separate billing record for that specific HGW (212).

[0101] FIG. 3 illustrates an exemplary flow diagram of the method (300) for managing network establishment by the User Plane Function (UPF) (218) for the one or more Home Gateways (HGWs) (212) in the network (106), in accordance with embodiments of the present disclosure.

[0102] At step 302, the method (300) involves receiving, by the receiving unit (230) of the UPF (218), at least one initialization message from the one or more HGWs (212) over the tunnel. The HGW (212), upon powering on, sends the at least one initialization message via the gNodeB (226) to the UPF (218). The tunnel comprises the Ethernet over Generic Routing Encapsulation (EoGRE) tunnel within the General Packet Radio Service (GPRS) Tunnelling Protocol (GTP) tunnel. The GTP tunnel is transmitted via the gNodeB (226) and is terminated at the UPF (218). The at least one initialization message is at least one of the Dynamic Host Configuration Protocol (DHCPv4) Discover message or the DHCPv6 Solicit message. The receiving unit (230) is configured to handle the termination of this GTP tunnel and the decapsulation of the contained messages.

[0103] The at least one initialization message is parsed to retrieve the at least one parameter. The at least one parameter is the unique Media Access Control (MAC) address of the HGW (212). The at least one parameter may also include client identifier, or other unique identifiers embedded in DHCP messages.

[0104] At step 304, the method (300) involves authenticating, by the authentication unit (240) of the UPF (218), the one or more HGWs (212) based on the at least one parameter. The authentication unit (240) is configured to verify the identity of the HGW (212) based on predetermined criteria. In this embodiment, the UPF (218) verifies that the MAC address present in the client-identifier field of the DHCP message matches the source MAC address from the Ethernet frame. This step ensures message integrity and device legitimacy. Upon verification, the UPF (218) transmits a Session Report Request (SRR) message to the Session Management Function (SMF) (220), containing the verified MAC address and optionally, a preliminary usage report. After this verification, the UPF (218) can proceed with the authorization process.

[0105] At step 306, the method (300) includes authorizing, by the authorization unit (242) of the UPF (218), the one or more HGWs (212) via the Session Management Function (SMF) (220). The SMF (220) determines whetherthe MAC address of the one or more HGWs (212) is authorized based on a preconfigured MAC-to-IMSI association for the CPE (214). This binding policy ensures that only authorized the one or more HGWs (212) can connect through a specific CPE (214). Upon receiving a positive acknowledgment of successful authorization from the SMF (220), the authorization unit (242) signals to the UPF (218) that the process can proceed. The SMF (220) then transmits the Session Modification Request (SMR) message to the UPF (218), including at least one of the IP address, the Packet Detection Rule (PDR), the Forwarding Action Rule (FAR), the Quality of Experience Rule (QER), and the Usage Reporting Rule (URR).

[0106] At step 308, the method (300) involves establishing, by the session management unit (244) of the UPF (218), the network session for the one or more HGWs (212). This step occurs upon receiving the successful authorization from the SMF (220). The session management unit (244) uses the rules received in the SMR message to configure the data flow for the HGW (212), effectively granting it network access.

[0107] At step 310, the method (300) involves monitoring, by the accounting unit (246) of the UPF (218), data usage for the one or more HGWs (212). The monitoring is performed on the established network session based on the URRs that were configured by the SMF (220) in the SMR message. The accounting unit (246) uses the configured URRs to track uplink and downlink traffic volumes. The accounting unit (246) generates usage reports based on URR identifiers mapped to MAC addresses and session contexts. After monitoring, the UPF (218) transmits the Session Report Request (SRR) message to the SMF (220), including a usage report for the HGW (212). The usage reports are periodically transmitted to the SMF (220) as part of the SRR messages, aiding in billing and charging procedures.

[0108] In an embodiment, the present disclosure provides a method (400) for charging the one or more Home Gateways (HGWs) (212) in the network (106), in accordance with embodiments of the present disclosure.

[0109] At step 402, the method (400) involves monitoring, by an accounting unit (246), data usage for each of the one or more HGWs (212). The accounting unit (246) performs the monitoring function based on a unique Usage Reporting Rule (URR) identifier. The URR identifier is uniquely associated with the Media Access Control (MAC) address of each of the one or more HGW (212). The URR identifier is configured by the Session Management Function (SMF) (220) during the session establishment process, specifically in the Session Modification Request (SMR) message which includes the MAC address of the one or more HGWs (212). To effectively perform this monitoring, the accounting unit (246) maintains a mapping of each HGW (212) with its corresponding IP address and the URR identifier. This mapping enables consistency between dynamically allocated IP addresses and persistent identifiers like MAC and URR IDs. In scenarios involving network address translation or reallocation of IP addresses, the use of MAC and URR allows the accounting unit (246) to reliably track data usage for each of the one or more HGWs (212).

[0110] At step 404, the method (400) involves generating, by the accounting unit (246), a usage report for each of the one or more HGWs (212). This step occurs after the data usage has been monitored for a specific period or when a session is terminated. The accounting unit (246) uses the information it has collected based on the URR identifier to compile a comprehensive report of the data consumption for each of the one or more HGWs (212), such as the total volume of data used.

[0111] At step 406, the method (400) involves sending, by the accounting unit (246), the usage report to the SMF (220) in the Session Report Request (SRR) message. The SRR message includes the usage report and the corresponding MAC address. The usage report comprises the volume measurement Information Element (IE) including detailed uplink and downlink data usage associated with the URRidentifier. The SRR message itself also includes the MAC address of the corresponding HGW (212), which ensures that the report can be correctly attributed.

[0112] At step 408, the method (400) includes forwarding, by the SMF (220), the usage report to the charging unit for generation of billing records for each of the one or more HGW (212). The SMF (220) forwards the usage report to the charging unit (e.g., a Charging Function (CHF)) for the generation of billing records. This final action completes the charging flow by providing the billing system with the necessary, granular data to create accurate billing records for each each of the one or more HGWs (212).

[0113] FIG. 5 illustrates an example computer system (500) in which or with which the embodiments of the present disclosure may be implemented.

[0114] As shown in FIG. 5, the computer system (500) may include an external storage device (510), a bus (520), a main memory (530), a read-only memory (540), a mass storage device (550), a communication port(s) (560), and a processor (570). A person skilled in the art will appreciate that the computer system (500) may include more than one processor and communication ports. The processor (570) may include various modules associated with embodiments of the present disclosure. The communication port(s) (560) may be any of an RS-232 port for use with a modem -based dialup connection, a 10 / 100 Ethernet port, a Gigabit or 10 Gigabit port using copper or fiber, a serial port, a parallel port, or other existing or future ports. The communication ports(s) (560) may be chosen depending on a network, such as a Local Area Network (LAN), Wide Area Network (WAN), or any network to which the computer system (500) connects.

[0115] In an embodiment, the main memory (530) may be Random Access Memory (RAM), or any other dynamic storage device commonly known in the art. The read-only memory (540) may be any static storage device(s) e.g., but not limited to, a Programmable Read Only Memory (PROM) chip for storing static information e.g., start-up or basic input / output system (BIOS) instructions for theprocessor (570). The mass storage device (550) may be any current or future mass storage solution, which can be used to store information and / or instructions. Exemplary mass storage solutions include, but are not limited to, Parallel Advanced Technology Attachment (PATA) or Serial Advanced Technology Attachment (SATA) hard disk drives or solid-state drives (internal or external, e.g., having Universal Serial Bus (USB) and / or Firewire interfaces).

[0116] In an embodiment, the bus (520) may communicatively couple the processor(s) (570) with the other memory, storage, and communication blocks. The bus (520) may be, e.g. a Peripheral Component Interconnect PCI) / PCI Extended (PCI-X) bus, Small Computer System Interface (SCSI), Universal Serial Bus (USB), or the like, for connecting expansion cards, drives, and other subsystems as well as other buses, such a front side bus (FSB), which connects the processor (570) to the computer system (500).

[0117] In another embodiment, operator and administrative interfaces, e.g., a display, keyboard, and cursor control device may also be coupled to the bus (520) to support direct operator interaction with the computer system (500). Other operator and administrative interfaces can be provided through network connections connected through the communication port(s) (560). The components described above are meant only to exemplify various possibilities. In no way should the aforementioned exemplary computer system (500) limit the scope of the present disclosure.

[0118] In an exemplary embodiment, a system for managing network establishment by a User Plane Function (UPF) for one or more Home Gateways (HGWs) in a network is disclosed. The system includes a receiving unit configured to receive at least one initialization message from the one or more HGWs over a tunnel. The system includes an authentication unit configured to authenticate the one or more HGWs based on at least one parameter obtained from the at least one received initialization message. The system includes an authorization unit configured to authorize the one or more HGWs by a Session Management Function(SMF), wherein the SMF is configured to interact with a Policy Control Function (PCF) to determine authorization status, and to receive a positive acknowledgment from the SMF upon successful authorization. The system includes a session management unit configured to establish at least one network session for the one or more HGWs upon receiving the successful authorization. The system includes an accounting unit configured to monitor data usage for the one or more HGWs corresponding to the established network session based on one or more usage reporting rules.

[0119] In an exemplary embodiment, a computer program product comprising a non-transitory computer-readable medium is disclosed. The medium includes instructions that, when executed by one or more processors, cause the one or more processors to execute a method for managing network establishment of a plurality of network entities in a network is described. The method includes receiving, by a receiving unit, at least one initialization message from the one or more HGWs over a tunnel. The method includes authenticating, by an authentication unit, the one or more HGWs based on at least one parameter obtained from the at least one received initialization message. The method includes authorizing, by an authorization unit, the one or more HGWs by a Session Management Function (SMF), wherein the SMF interacts with a Policy Control Function (PCF) to determine authorization status, wherein the authorization unit receives a positive acknowledgment from the SMF upon successful authorization. The method includes establishing, by a session management unit, at least one network session for the one or more HGWs upon receiving the successful authorization. The method includes monitoring, by an accounting unit, data usage for the one or more HGWs corresponding to the established network session based on one or more usage reporting rules.

[0120] In an exemplary embodiment, a computer program product comprising a non-transitory computer-readable medium is disclosed. The medium includes instructions that, when executed by one or more processors, cause the one or more processors to execute a method for charging one or more HGWs in anetwork is disclosed. The method includes monitoring, by an accounting unit, data usage for each of the one or more HGWs based on a Usage Reporting Rule (URR) identifier associated with a Media Access Control (MAC) address of each of the one or more HGWs. The method includes generating, by the accounting unit, a usage report for each of the one or more HGWs based on the monitored data usage. The method includes sending, by the accounting unit, the usage report to a Session Management Function (SMF) in a Session Report Request (SRR) message, the SRR message including the usage report and the corresponding MAC address. The method includes forwarding, by the SMF, the usage report to a charging unit for generation of billing records for each of the one or more HGWs.

[0121] While considerable emphasis has been placed herein on the preferred embodiments, it will be appreciated that many embodiments can be made and that many changes can be made in the preferred embodiments without departing from the principles of the disclosure. These and other changes in the preferred embodiments of the disclosure will be apparent to those skilled in the art from the disclosure herein, whereby it is to be distinctly understood that the foregoing descriptive matter to be implemented merely as illustrative of the disclosure and not as limitation.

[0122] The present disclosure provides a technical advancement in the Authentication, Authorization, and Accounting (AAA) method for Home Gateways (HGWs) the networks by extending the capabilities of the User Plane Function (UPF) to manage individual HGWs connected through a single Customer Premises Equipment (CPE). Unlike conventional network architectures, which are limited to managing a single session at the CPE level, the present disclosure enables the UPF to autonomously differentiate and manage each HGW, thus overcoming the limitations of per-device AAA and charging. This provides a security measure that prevents unauthorized devices from accessing the network. Furthermore, the invention allows for individual HGW charging by enabling the UPF to monitor and report data usage for each HGW against a unique Usage Reporting Rule (URR) identifier. This allows service providers to offer flexible, per-device service plansand accurately enforce data caps. This is a significant improvement over the conventional single point charging model, which is unable to distinguish between devices.ADVANTAGES OF THE PRESENT DISCLOSURE

[0123] The present disclosure provides the system and the method that ensure seamless support for Authentication, Authorization, and Accounting (AAA) for the each one or more Home Gateways (HGWs) behind the single Customer Premise Equipment (CPE), even when a common session is shared.

[0124] The present disclosure provides the system and the method that allow the User Plane Function (UPF) to maintain uninterrupted service continuity for the one or more HGWs despite changes in the operative state of the CPE or the connected devices.

[0125] The present disclosure provides the system and the method that enable dynamic charging per HGW based on traffic flow classification, allowing accurate billing in multi-device scenarios.

[0126] The present disclosure provides the system and the method that reduce session setup overhead by avoiding full session re-establishment for each device behind the CPE, thereby improving signalling efficiency and overall user experience.

Claims

CLAIMS1. A method (300) for managing network establishment by a User Plane Function (UPF) (218) for one or more Home Gateways (HGWs) (212) in a network (106), the method (300) comprising of steps: receiving (302), by a receiving unit (230), at least one initialization message from the one or more HGWs (212) over a tunnel; authenticating (306), by an authentication unit (240), the one or more HGWs (212) based on at least one parameter obtained from the at least one received initialization message; authorizing (308), by an authorization unit (242), the one or more HGWs (212) by a Session Management Function (SMF) (220), wherein the SMF (220) interacts with a Policy Control Function (PCF) (222) to determine authorization status, wherein the authorization unit (242) receives a positive acknowledgment from the SMF (220) upon successful authorization; establishing (310), by a session management unit (244), at least one network session for the one or more HGWs (212) upon receiving the successful authorization; and monitoring (312), by an accounting unit (246), data usage for the one or more HGWs (212) corresponding to the established network session based on one or more usage reporting rules.

2. The method as claimed in claim 1, wherein: the one or more HGWs (212), upon powering on, sends the at least one initialization message via a gNodeB (226) to the UPF (218), wherein the initialization message is at least one of a Dynamic Host Configuration Protocol (DHCPv4) Discover message or a DHCPv6 Solicit message.

3. The method as claimed in claim 1 , wherein the tunnel comprises an Ethernet over Generic Routing Encapsulation (EoGRE) tunnel within a General Packet Radio Service (GPRS) Tunnelling Protocol (GTP) tunnel, andwherein the GTP tunnel is transmitted via the gNodeB (226) and terminated at the UPF (218).

4. The method as claimed in claim 1, wherein the initialization message is at least one of a Dynamic Host Configuration Protocol (DHCPv4) Discover message or a DHCPv6 Solicit message.

5. The method as claimed in claim 1, wherein the at least one parameter comprises a Media Access Control (MAC) address of the one or more HGWs (212).

6. The method as claimed in claim 1, wherein the authentication comprises: verifying, by the UPF (218), that the MAC address included in a client-identifier field of the at least one initialization message matches with a source MAC address of a received Ethernet frame encapsulating the initialization message received from the one or more HGWs (212); and transmitting, by the UPF (218), a Session Report Request (SRR) message to the SMF (220), the SRR message including the verified MAC address and a usage report corresponding to the one or more HGWs (212).

7. The method as claimed in claim 1, wherein the authorization comprises: determining, by the SMF (220), whether the MAC address of the one or more HGWs (212) is authorized based on a preconfigured MAC-to- IMSI association for a Customer Premises Equipment (CPE) (214); and upon successful authorization, transmitting, by the SMF (220), a Session Modification Request (SMR) message to the UPF (218), the SMR message including at least one of: an Internet Protocol (IP) address assigned to the one or more HGWs (212), a Packet Detection Rule (PDR), a Forwarding Action Rule (FAR), a Quality of Experience Rule (QER) and a Usage Reporting Rule (URR) corresponding to the one or more HGWs (212).

8. A method (400) for charging one or more Home Gateways (HGWs) (212) in a network (106), the method (400) comprising: monitoring (402), by an accounting unit (246), data usage for each of the one or more HGW (212) based on a Usage Reporting Rule (URR)identifier associated with a Media Access Control (MAC) address of each of the one or more HGW (212); generating (404), by the accounting unit (246), a usage report for each of the one or more HGW (212) based on the monitored data usage; sending (406), by the accounting unit (246), the usage report to a Session Management Function (SMF) (220) in a Session Report Request (SRR) message, the SRR message including the usage report and the corresponding MAC address; and forwarding (408), by the SMF (220), the usage report to a charging unit for generation of billing records for each of the one or more HGW (212).

9. The method as claimed in claim 8, wherein: the URR identifier for each of the one or more HGW (212) is configured by the SMF (220) in a Session Modification Request (SMR) message, the SMR message including the MAC address of the each of the one or more HGW (212); accounting unit (246) maintains a mapping of each of the one or more HGW (212) with a corresponding IP address and the URR identifier; and the usage report comprises a volume measurement Information Element (IE) including uplink and downlink data usage associated with the URR identifier, and the SRR message includes the MAC address of the one or more HGWs (212).

10. A system (108) for managing network establishment by a User Plane Function (UPF) (218) for one or more Home Gateways (HGWs) (212) in a network (106), the system (108) comprising: a receiving unit (230) configured to receive at least one initialization message from the one or more HGWs (212) over a tunnel; an authentication unit (240) configured to authenticate the one or more HGWs (212) based on at least one parameter obtained from the at least one received initialization message;an authorization unit (242) configured to authorize the one or more HGWs (212) by a Session Management Function (SMF) (220), wherein the SMF (220) is configured to interact with a Policy Control Function (PCF) (222) to determine authorization status, and to receive a positive acknowledgment from the SMF (220) upon successful authorization; a session management unit (244) configured to establish at least one network session for the one or more HGWs (212) upon receiving the successful authorization; and an accounting unit (246) configured to monitor data usage for the one or more HGWs (212) corresponding to the established network session based on one or more usage reporting rules.

11. The system as claimed in claim 10, wherein: the one or more HGWs (212) is configured to, upon powering on, send the at least one initialization message via a gNodeB (226) to the UPF (218), wherein the initialization message is at least one of a Dynamic Host Configuration Protocol (DHCPv4) Discover message or a DHCPv6 Solicit message.

12. The system as claimed in claim 10, wherein the tunnel comprises an Ethernet over Generic Routing Encapsulation (EoGRE) tunnel within a General Packet Radio Service (GPRS) Tunnelling Protocol (GTP) tunnel, and wherein the GTP tunnel is transmitted via the gNodeB (226) and terminated at the UPF (218).

13. The system as claimed in claim 10, wherein the at least one parameter comprises a Media Access Control (MAC) address of the one or more HGWs (212).

14. The system as claimed in claim 10, wherein the UPF (218) is configured to: verify that the MAC address included in a client-identifier field of the at least one initialization message matches with a source MAC address of a received Ethernet frame encapsulating the initialization message received from the one or more HGWs (212); andtransmit a Session Report Request (SRR) message to the SMF (220), the SRR message including the verified MAC address and a usage report corresponding to the one or more HGWs (212).

15. The system as claimed in claim 10, wherein the SMF (220) is configured to: determine whether the MAC address of the one or more HGWs (212) is authorized based on a preconfigured MAC-to-IMSI association for a Customer Premises Equipment (CPE) (214); and upon successful authorization, transmit a Session Modification Request (SMR) message to the UPF (218), the SMR message including at least one of an Internet Protocol (IP) address assigned to the one or more HGWs (212), a Packet Detection Rule (PDR), a Forwarding Action Rule (FAR), a Quality of Experience Rule (QER) and a Usage Reporting Rule (URR) corresponding to the one or more HGWs (212).

16. A system (108) for charging one or more Home Gateways (HGWs) (212) in a network (106), the system (108) comprising: an accounting unit (246) configured to: monitor data usage for each of the one or more HGW (212) based on a Usage Reporting Rule (URR) identifier associated with a Media Access Control (MAC) address of the each HGW (212); generate a usage report for each of the one or more HGW (212) based on the monitored data usage; send the usage report to a Session Management Function (SMF) (220) in a Session Report Request (SRR) message, the SRR message including the usage report and the corresponding MAC address; and the SMF (220) configured to forward the usage report to a charging unit for generation of billing records for each of the one or more HGWs (212).

17. The system as claimed in claim 16, wherein: the URR identifier for each of the one or more HGWs (212) is configured by the SMF (220) in a Session Modification Request (SMR)message, the SMR message including the MAC address of each of the one or more HGWs (212); the accounting unit (246) maintains a mapping of each of the one or more HGWs (212) with a corresponding IP address and the URR identifier; and the usage report comprises a volume measurement Information Element (IE) including uplink and downlink data usage associated with the URR identifier, and the SRR message includes the MAC address of the one or more HGWs (212).

18. A computer program product comprising a non -transitory computer- readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to execute a method (300) for managing network establishment by a User Plane Function (UPF) (218) for one or more Home Gateways (HGWs) (212) in a network (106), the method (300) comprising: receiving (302), by a receiving unit (230), at least one initialization message from the one or more HGWs (212) over a tunnel; authenticating (304), by an authentication unit (240), the one or more HGWs (212) based on at least one parameter obtained from the at least one received initialization message; authorizing (304), by an authorization unit (242), the one or more HGWs (212) by a Session Management Function (SMF) (220), wherein the SMF (220) interacts with a Policy Control Function (PCF) (222) to determine authorization status, wherein the authorization unit (242) receives a positive acknowledgment from the SMF (220) upon successful authorization; establishing (306), by a session management unit (244), at least one network session for the one or more HGWs (212) upon receiving the successful authorization; andmonitoring (308), by an accounting unit (246), data usage for the one or more HGWs (212) corresponding to the established network session based on one or more usage reporting rules.

19. A computer program product comprising a non -transitory computer- readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to execute a method for charging one or more Home Gateways (HGWs) (212) in a network (106), the method (400) comprising: monitoring (402), by an accounting unit (246), data usage for each of the one or more HGW (212) based on a Usage Reporting Rule (URR) identifier associated with a Media Access Control (MAC) address of each of the one or more HGW (212); generating (404), by the accounting unit (246), a usage report for each of the one or more HGW (212) based on the monitored data usage; sending (406), by the accounting unit (246), the usage report to a Session Management Function (SMF) (220) in a Session Report Request (SRR) message, the SRR message including the usage report and the corresponding MAC address; and forwarding (408), by the SMF (220), the usage report to a charging unit for generation of billing records for each of the one or more HGW (212).

Citation Information

Patent Citations

  • Method for processing PDU session establishment procedure and AMF node

    WO2018194315A1

  • Extended 5g local area network interworking with a home network and change of access network for 5g LAN connected devices

    WO2021202891A1