System and method for providing network access to subscriber based on tracking area identity value
The system uses TAI values to manage network access by comparing received TAI values with provisioned data, addressing inefficiencies in conventional methods and ensuring secure, compliant access control.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-01
- Publication Date
- 2026-03-12
AI Technical Summary
Conventional network access control methods, such as IP address and MAC filtering, are inefficient and error-prone, particularly in dynamic environments, and fail to consider device-specific information like security state and user identity, leading to challenges in managing network access for a large number of subscribers.
A system and method that utilizes Tracking Area Identity (TAI) values to manage network access by comparing received TAI values with provisioned TAI values stored in a Subscriber Profile Repository (SPR), allowing real-time validation and enforcement of access policies, ensuring compliance with privacy and security regulations.
Enables precise determination of subscriber location, enhances mobility management, and ensures secure network access by preventing unauthorized access, optimizing network resource allocation, and improving overall network performance and reliability.
Smart Images

Figure IN2025051408_12032026_PF_FP_ABST
Abstract
Description
SYSTEM AND METHOD FOR PROVIDING NETWORK ACCESS TO SUBSCRIBER BASED ON TRACKING AREA IDENTITY VALUERESERVATION OF RIGHTS
[0001] A portion of the disclosure of this patent document contains material, which is subject to intellectual property rights such as, but are not limited to, copyright, design, trademark, Integrated Circuit (IC) layout design, and / or trade dress protection, belonging to Jio Platforms Limited (JPL) or its affiliates (hereinafter referred as owner). The owner has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent files or records, but otherwise reserves all rights whatsoever. All rights to such intellectual property are fully reserved by the owner.TECHNICAL FIELD
[0002] The present disclosure relates generally to the field of telecommunications. In particular, the present disclosure relates to a system and a method for providing network access to a subscriber based on tracking area identity (TAI) value in a network.DEFINITIONS
[0003] As used in the present disclosure, the following terms are generally intended to have the meaning as set forth below, except to the extent that the context in which they are used indicates otherwise.
[0004] The expression “Access and Mobility Management Function (AMF)” used hereinafter in the specification refers to a network function that is responsible for managing user session registration, authentication, and mobility.
[0005] The expression “Policy Control Function (PCF)” used hereinafter in the specification refers to a network function that provides policy rules for control plane functions. The PCF is responsible for managing network policies related to access, quality of service, and resource allocation.
[0006] The expression “Subscriber Profile Repository (SPR)” used hereinafter in the specification refers to a database that stores subscriber-related information, such as subscriber profiles, service configurations, and network preferences. The SPR provides essential data to various network functions to support service delivery, authentication, authorization, and billing.
[0007] The expression “Provisioning Gateway (PGW)” used hereinafter in the specification refers to a component that handles provisioning of the network resources, services, and configurations. The Provisioning Gateway acts as an intermediary between a network management system and the network elements to be provisioned.
[0008] The expression “Tracking Area Identity (TAI)” used hereinafter in the specification refers to a unique identifier assigned to a tracking area within a network. The TAI includes the Mobile Country Code (MCC), Mobile Network Code (MNC), and Tracking area code (TAC).
[0009] The expression “Mobile Country Code (MCC)” used hereinafter in the specification refers to a three-digit code used to identify a country or a specific region within a country in the telecommunications. The MCC is used to distinguish mobile networks and facilitate international roaming.
[0010] The expression “Mobile Network Code (MNC)” used hereinafter in the specification refers to a three-digit code used to identify a specific mobile network operator within a country. The MNC is part of International Mobile SubscriberIdentity (IMSI), which is used for identifying and authenticating mobile subscribers on a network.
[0011] The expression “Tracking Area Code (TAC)” used hereinafter in the specification refers to a unique identifier assigned to a specific type or model of user equipment. The TAC is the initial 8 digits of the IMEI (International Mobile Equipment Identity) number that helps to identify the manufacturer and model of the user equipment.
[0012] The expression “International Mobile Equipment Identity (IMEI)” used hereinafter in the specification refers to a numeric identifier in network used to identify user equipment. The IMEI number helps the service provider and network operators to track and manage user equipment.
[0013] The expression “Customer Premises Equipment (CPE)” used hereinafter in the specification refers to network equipment used for connecting a subscriber’s network to a service provider’s network infrastructure. The CPE supports high-speed data transmission and provides reliable connectivity. It is installed at the customer’s location (home, office, or enterprise) that enables fixed wireless access (FWA) to the wireless broadband network. The CPE in FWA is the subscriber-side device that connects households or enterprises to the operator’s fixed wireless broadband service, functioning like a wireless alternative to a wired broadband modem. The CPE installed outdoor, i.e., ODCPE, such as installed on rooftops, walls, streetlights, or utility poles, close to end-users. Similarly, the CPE installed indoor is called as Indoor Customer Premises Equipment.
[0014] The expression “Subscriber Permanent Identifier (SUPI)” used hereinafter in the specification refers to a global unique identifier that is assigned to each subscriber in the network. The SUPI includes the Mobile Country Code (MCC),the Mobile Network Code (MNC) and a Mobile Subscriber Identification Number (MSIN).
[0015] The expression “Mobile Subscriber Identification Number (MSIN) used hereinafter in the specification refers to a unique numeric code assigned by a network operator to the subscriber.
[0016] These definitions are in addition to those expressed in the art.BACKGROUND
[0017] The following description of related art is intended to provide background information pertaining to the field of the disclosure. This section may include certain aspects of the art that may be related to various features of the present disclosure. However, it should be appreciated that this section be used only to enhance the understanding of the reader with respect to the present disclosure, and not as admissions of prior art.
[0018] In telecommunication, a wide range of user devices connect with each other via a network for seamless and effective communication. The network includes the Internet, private networks and other communication systems. The user devices may establish a connection with the network by setting up a wired connection or a wireless connection. The connection establishment involves setting up network equipment, configuration of network settings, verifying connectivity and troubleshooting issues, setting up network security and network monitoring. The user device may connect to the network using network credentials. The network credentials are used to connect to networks, access resources, and ensure secure communication.
[0019] In a conventional approach, the network access may be controlled by various methods such as network credential authentication, Media Access Control (MAC) filtering, and Internet Protocol (IP) address management. The various methodsfor controlling network access are affected by factors such as manual interventions, complex setup, compatibility issues, scalability issues, and configuration complexity. Also, the network access control through IP address and MAC filtering may be a timeconsuming and error-prone task. The network access control based on an IP address does not consider device-specific information such as security state, user identity, and device health. Further, network access control through MAC filtering may be challenging in maintaining a large set of MAC addresses of various devices in the network. The IP address and MAC filtering-based network access control may be inefficient in a dynamic network environment.
[0020] Further, the proper management and security of the network are crucial for protecting network resources and maintaining a secure network environment. The conventional system for network access control faces difficulty in managing and authorizing the huge user devices. The unauthorized access restriction to the network based on the IP address may have loopholes for bypassing, such as falsifying the IP addresses and misconfiguring IP address rules.
[0021] Further, Fixed Wireless Access (FWA) has emerged as an important solution to deliver broadband connectivity to households and enterprises without the need for wired infrastructure such as fiber or copper lines. In a typical FWA deployment, the user premises are equipped with a Customer Premises Equipment (CPE) device. The CPE connects wirelessly to a base station, such as a 4G eNB or a 5G gNB, and provides broadband access through Wi-Fi or Ethernet to end-user devices. Currently, there are challenges in managing the network access at locations where some CPEs are allowed to access the network whereas others are not allowed such as scenarios of law and regulatory enforcement. Hence, there is a need to provide a method and a system that can address the shortcomings of existing solutions.SUMMARY OF THE DISCLOSURE
[0022] In an exemplary embodiment, a method for managing network access is described. The method comprises receiving, by a policy control function (PCF), at least one policy create request from an access and mobility function (AMF) to create a policy for at least one network device, fetching, by the PCF, a set of data associated with the at least one network device from a subscriber profile repository (SPR), comparing, by the PCF, the received at least one TAI value with the list of provisioned TAI value, and managing, by the PCF, the network access of the at least one network device based on the comparison. The at least one policy create request comprises at least one Tracking Area Identity (TAI) value and one or more parameters. The set of data comprises at least a list of provisioned TAI values.
[0023] In an aspect, fetching the set of data associated with the at least one network device comprises extracting, by the PCF, a subscriber identifier (ID) associated with the at least one network device from the at least one policy control create request and sending, by the PCF, a retrieval request to the SPR for fetching the set of data associated with the at least one network device based on the extracted subscriber ID. The SPR transmits the set of data to the PCF, upon receiving the retrieval request.
[0024] In another aspect, the TAI value comprises a Mobile Country Code (MCC), a Mobile Network Code (MNC), and a Tracking Area Code (TAC). The list of provisioned TAI values corresponds to the at least one network device.
[0025] In one of the aspect, the managing the network access comprises permitting, by the PCF, the network access to the at least one network device, if the received TAI value matches with at least one TAI value present in the list of provisioned TAI values and denying, by the PCF, the network access to the at leastone network device, if the received TAI value does not match with any TAI value present in the list of provisioned TAI values.
[0026] In one of the embodiments, the network device is a customer premises equipment (CPE) in the network.
[0027] In another embodiment, a system for managing network access is described. The system comprises a policy control function (PCF) configured to receive at least one policy create request from an access and mobility function to create a policy for at least one network device, fetch a set of data associated with the at least one network device from a subscriber profile repository (SPR), compare the received at least one TAI value with the list of provisioned TAI values, and manage the network access of the at least one network device based on the comparison. The at least one policy create request comprises at least one Tracking Area Identity (TAI) value and one or more parameters. The set of data comprises a list of provisioned TAI values.
[0028] In another embodiment, the policy control function is configured to extract a subscriber identifier (ID) associated with the at least one network device from the at least one policy control create request, and send a retrieval request to the SPR for fetching the set of data associated with the at least one network device based on the extracted subscriber ID. The SPR transmits the set of data to the PCF upon receiving the retrieval request.
[0029] In one of the embodiment, to manage the network access of the at least one network device, the PCF is configured to permit the network access to the at least one network device, if the received TAI value matches with at least one TAI value present in the list of provisioned TAI values and deny the network access to the at least one network device if the received TAI value does not match with any TAI value present in the list of provisioned TAI values.
[0030] In an embodiment, a user equipment communicatively coupled with a system is described. The coupling comprises receiving, by the system, a connection request from the UE, sending, by the system, an acknowledgment of the connection request to a UE, transmitting by the system, a plurality of signals in response to the connection. Upon receiving a plurality of signals, a method is performed by the system to manage network access.
[0031] In an embodiment, a computer program product comprising a non- transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to execute a method for managing network access. The method comprises receiving, by a policy control function (PCF), at least one policy create request from an access and mobility function (AMF) to create a policy for at least one network device, fetching, by the PCF, a set of data associated with the at least one network device from a subscriber profile repository (SPR), comparing, by the PCF, the received at least one TAI value with the list of provisioned TAI value, and managing, by the PCF, the network access of the at least one network device based on the comparison. The at least one policy create request comprises at least one Tracking Area Identity (TAI) value and one or more parameters. The set of data comprises at least a list of provisioned TAI values.OBJECTIVES OF THE DISCLOSURE
[0032] Some of the objectives of the present disclosure, which at least one embodiment herein satisfies, are as follows:
[0033] An objective of the present disclosure is to provide a system and a method for providing network access to a subscriber based on tracking area identity (TAI) value in a network.
[0034] Another objective of the present disclosure is to provide a system and a method for provisioning a customer premises equipment (CPE) in the network.
[0035] Another objective of the present disclosure is to provide a system and a method for determining a location of a subscriber and comparing the subscriber's location with the provisioned TAI values.
[0036] Another objective of the present disclosure is to provide a system and a method that enables real-time decision-making regarding the network access to the subscriber based on the provisioned TAI values.
[0037] Another objective of the present disclosure is to provide a system and a method for ensuring compliance with privacy and security regulations by restricting network access to unauthorized subscribers.
[0038] Other objective and advantages of the present disclosure will be more apparent from the following description, which is not intended to limit the scope of the present disclosure.BRIEF DESCRIPTION OF THE ACCOMPANYING DRAWING
[0039] The accompanying drawings, which are incorporated herein, and constitute a part of this disclosure, illustrate exemplary embodiments of the disclosed methods and systems in which like reference numerals, refer to the same parts throughout the different drawings. Components in the drawings are not necessarily to scale; emphasis is instead being placed upon clearly illustrating the principles of the present disclosure. Some drawings may indicate the components using block diagrams and may not represent the internal circuitry of each component. It will be appreciated by those skilled in the art that disclosure of such drawings includes disclosure of electrical components, electronic components, or circuitry commonly used to implement such components.
[0040] FIG. 1 illustrates an exemplary network architecture of a system for providing network access to a subscriber based on tracking area identity (TAI) value in a network, in accordance with an embodiment of the present disclosure.
[0041] FIG. 2 illustrates an exemplary block diagram of the system, in accordance with an embodiment of the present disclosure.
[0042] FIG. 3 illustrates an exemplary system architecture, in accordance with an embodiment of the present disclosure.
[0043] FIG. 4 illustrates an exemplary flow diagram of a method for providing network access to the subscriber based on the TAI value, in accordance with an embodiment of the present disclosure.
[0044] FIG. 5 illustrates another exemplary flow diagram of a method for providing network access to the subscriber based on the TAI value, in accordance with an embodiment of the present disclosure.
[0045] FIG. 6 illustrates an example computer system in which or with which the embodiments of the present disclosure may be implemented.
[0046] The foregoing shall be more apparent from the following more detailed description of the disclosure.LIST OF REFERENCE NUMERALS100- Network architecture102- User104- User equipment106- Network108- System110- Customer premises equipment (CPE)200- Block diagram202- Processor(s) 204- Memory206- Interface(s)208- Processing engine210- Database212- Subscriber Profile Repository (SPR) 214- Policy Control Function (PCF)216- Access and Mobility Management Function (AMF)400- Flow diagram402- Provisioning Gateway (PGW)500- Flow diagram 600 - Computer system610 - External Storage Device620 - Bus630 - Main Memory640 - Read Only Memory650 - Mass Storage Device660 - Communication Port670 - ProcessorDETAILED DESCRIPTION
[0047] In the following description, for the purposes of explanation, various specific details are set forth in order to provide a thorough understanding of embodiments of the present disclosure. It will be apparent, however, that embodiments of the present disclosure may be practiced without these specific details. Several features described hereafter can each be used independently of one another or with any combination of other features. An individual feature may not address any of the problems discussed above or might address only some of the problems discussed above. Some of the problems discussed above might not be fully addressed by any of the features described herein. Example embodiments of the present disclosure are described below, as illustrated in various drawings in which like reference numerals refer to the same parts throughout the different drawings.
[0048] The ensuing description provides exemplary embodiments only, and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, the ensuing description of the exemplary embodiments will provide those skilled in the art with an enabling description for implementing an exemplary embodiment. It should be understood that various changes may be made in the function and arrangement of elements without departing from the spirit and scope of the disclosure as set forth.
[0049] Specific details are given in the following description to provide a thorough understanding of the embodiments. However, it will be understood by oneof ordinary skill in the art that the embodiments may be practiced without these specific details. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form in order not to obscure the embodiments in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail in order to avoid obscuring the embodiments.
[0050] Also, it is noted that individual embodiments may be described as a process that is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. Although a flowchart may describe the operations as a sequential process, many of the operations can be performed in parallel or concurrently. In addition, the order of the operations may be re-arranged. A process is terminated when its operations are completed but could have additional steps not included in a figure. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination can correspond to a return of the function to the calling function or the main function.
[0051] The word “exemplary” and / or “demonstrative” is used herein to mean serving as an example, instance, or illustration. For the avoidance of doubt, the subject matter disclosed herein is not limited by such examples. In addition, any aspect or design described herein as “exemplary” and / or “demonstrative” is not necessarily to be construed as preferred or advantageous over other aspects or designs, nor is it meant to preclude equivalent exemplary structures and techniques known to those of ordinary skill in the art. Furthermore, to the extent that the terms “includes,” “has,” “contains,” and other similar words are used in either the detailed description or the claims, such terms are intended to be inclusive like the term “comprising” as an open transition word without precluding any additional or other elements.
[0052] Reference throughout this specification to “one embodiment” or “an embodiment” or “an instance” or “one instance” means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present disclosure. Thus, the appearances of the phrases “in one embodiment” or “in an embodiment” in various places throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0053] The terminology used herein is to describe particular embodiments only and is not intended to be limiting the disclosure. As used herein, the singular forms “a”, “an”, and “the” are intended to include the plural forms as well, unless the context indicates otherwise. It will be further understood that the terms “comprises” and / or “comprising,” when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein, the term “and / or” includes any combinations of one or more of the associated listed items. It should be noted that the terms “mobile device”, “user equipment”, “user device”, “communication device”, “device” and similar terms are used interchangeably for the purpose of describing the invention. These terms are not intended to limit the scope of the invention or imply any specific functionality or limitations on the described embodiments. The use of these terms is solely for convenience and clarity of description. The invention is not limited to any particular type of device or equipment, and it should be understood that other equivalent terms or variations thereof may be used interchangeably without departing from the scope of the invention as defined herein.
[0054] While considerable emphasis has been placed herein on the components and component parts of the preferred embodiments, it will be appreciated that many embodiments can be made and that many changes can be made in the preferred embodiments without departing from the principles of the disclosure. These and other changes in the preferred embodiment, as well as other embodiments of the disclosure, will be apparent to those skilled in the art from the disclosure herein, whereby it is to be distinctly understood that the foregoing descriptive matter is to be interpreted merely as illustrative of the disclosure and not as a limitation.
[0055] Managing and controlling network access for a large number of subscribers in a network presents significant challenges such as handling a high volume of subscribers, each requiring individual attention to ensure proper access management. Traditional network access control mechanisms, such as those based on Media Access Control (MAC) addresses or Internet Protocol (IP) addresses, can be particularly error-prone and complex.
[0056] MAC addresses are hardware identifiers assigned to network interfaces and are used to control access at the data link layer. While the MAC addresses provide a unique identifier for each device associated with the subscriber, relying solely on MAC addresses for network access control is problematic due to the potential for spoofing and the difficulty of managing changes in device addresses. IP address-based control, which operates at the network layer, faces similar issues. IP addresses can be dynamically assigned via protocols like Dynamic Host Configuration Protocol (DHCP), adding another layer of complexity in tracking and enforcing access policies.
[0057] These conventional techniques often demand granular control to prevent unauthorized access and ensure proper network utilization. A system or method is needed to set up detailed rules and policies that govern which subscriber can access which network resources and under what conditions.
[0058] The present disclosure employs a comparison mechanism to validate a subscriber for enabling access to a network. The comparison mechanism allows a realtime validation of network access associated with the subscriber based on a tracking area identity (TAI) value. The comparison mechanism involves comparing the TAI value received in a policy control creation request with a list of provisioned TAI values in a subscriber profile repository (SPR). For example, the list of provisioned TAI values may be pre-stored subscriber data in the SPR. The provisioned TAI values may have one or more columns. Column 1 may indicate the TAI values of the subscriber. Column 2 may indicate the status of network access. A Policy control function (PCF) may promptly allow or reject subscriber access based on the TAI value comparison.
[0059] The present disclosure also restricts network access to unauthorized subscribers within specific tracking areas. The present disclosure helps to mitigate the risk of unauthorized network access and ensures compliance with privacy and security regulations.
[0060] The present disclosure provides a method and system for precisely determining a current location of a subscriber within a network, enhancing mobility management and access control. The system compares the subscriber's current location against the provisioned TAI values stored within a memory. This verification process ensures that the subscriber's location aligns with the predefined TAI values, facilitating accurate enforcement of access policies and robust network security. The present disclosure thus contributes to the efficient operation and integrity of the mobile network by preventing unauthorized access, reducing security vulnerabilities, and optimizing network resource allocation. Consequently, the present disclosure enhances the overall performance and reliability of the network ecosystem by ensuring that subscriber mobility is effectively managed and network access is securely controlled.
[0061] In an embodiment, the present disclosure provides a system and a method for providing network access to a subscriber based on the TAI value in a network. The method includes receiving at least one policy control create request from an access and mobility management function (AMF) by the PCF. The method includes extracting at least one TAI value from the at least one received policy control request by the PCF. The method includes fetching a set of provisioned TAI values associated with the subscriber from the SPR by the PCF. The method includes comparing at least one extracted TAI value with the set of provisioned TAI values for validating the network access of the subscriber by the PCF. The method includes providing the network access to the subscriber based on the comparison by the PCF.
[0062] Hereinafter, exemplary embodiments of the present disclosure will be described with reference to the accompanying drawings.
[0063] The various embodiments throughout the disclosure will be explained in more detail with reference to FIG. 1- FIG. 5.
[0064] FIG. 1 illustrates an exemplary network architecture (100) of a system (108) for providing network access to a subscriber based on tracking area identity (TAI) value, in accordance with an embodiment of the present disclosure.
[0065] As illustrated in FIG. 1, the network architecture (100) may include one or more user equipment (UE) (104-1, 104-2... 104-N) associated with one or more users (102-1, 102-2... 102-N) in an environment. A person of ordinary skill in the art will understand that one or more users (102-1, 102-2... 102-N) may collectively referred to as the users (102). Similarly, a person of ordinary skill in the art will understand that one or more UEs (104-1, 104-2... 104-N) may be collectively referred to as the UE (104). Although only three UEs (104) are depicted in FIG. 1, however, any number of the UE (104) may be included without departing from the scope of the ongoing description.
[0066] In an embodiment, the UE (104) may include smart devices operating in a smart environment, for example, an Internet of Things (loT) system. In such an embodiment, the UE (104) may include, but are not limited to, smartphones, smart watches, smart sensors (e.g., mechanical, thermal, electrical, magnetic, etc.), networked appliances, networked peripheral devices, networked lighting system, communication devices, networked vehicle accessories, networked vehicular devices, smart accessories, tablets, smart television (TV), computers, smart security system, smart home system, other devices for monitoring or interacting with or for the users (102) and / or entities, or any combination thereof. A person of ordinary skill in the art will appreciate that the UE (104) may include, but not limited to, intelligent, multisensing, network- connected devices, that may integrate seamlessly with each other and / or with a central server or a cloud-computing system or any other device that is network-connected. Additionally, in some embodiments, the UE (104) may include, but is not limited to, a handheld wireless communication device (e.g., a mobile phone, a smartphone, a phablet device, and so on), a wearable computer device (e.g., a headmounted display computer device, a head-mounted camera device, a wristwatch computer device, and so on), a Global Positioning System (GPS) device, a laptop computer, a tablet computer, or another type of portable computer, a media playing device, a portable gaming system, and / or any other type of computer device with wireless communication capabilities, and the like. In an embodiment, the UE (104) may include, but are not limited to, any electrical, electronic, electromechanical, or equipment, or a combination of one or more of the above devices, such as virtual reality (VR) devices, augmented reality (AR) devices, laptop, a general-purpose computer, desktop, personal digital assistant, tablet computer, mainframe computer, or any other computing device, wherein the UE (104) may include one or more inbuilt or externally coupled accessories including, but not limited to, a visual aid device such as a camera, an audio aid, a microphone, a keyboard, and input devices for receiving input from the user (102) or the entity such as touchpad, touch-enabledscreen, electronic pen, and the like. A person of ordinary skill in the art will appreciate that the UE (104) may not be restricted to the mentioned devices and various other devices may be used.
[0067] Referring to FIG. 1, the UE (104) may communicate with the system (108) through a network (106) for sending or receiving various types of data. In an embodiment, the network (106) may include at least one of a fifth generation (5G) network, sixth generation (6G) network, or the like. The network (106) may enable the UE (104) to communicate with other devices in the network architecture (100) and / or with the system (108). The network (106) may include a wireless card or some other transceiver connection to facilitate this communication. In another embodiment, the network (106) may be implemented as, or include any of a variety of different communication technologies such as a wide area network (WAN), a local area network (LAN), a wireless network, a mobile network, a Virtual Private Network (VPN), the Internet, the Public Switched Telephone Network (PSTN), or the like.
[0068] In an embodiment, the UE (104) may be connected to a customer premises equipment (CPE) (110) to provide fixed wireless access (FWA) services to the user equipment (104). The CPE (110) may include outdoor CPE (ODCPE). In various embodiments, the CPE (110) refers to a subscriber-side device deployed in Fixed Wireless Access (FWA) scenarios. The CPE (110) comprises a communication module configured to establish a wireless connection. Unlike traditional mobile user equipment (UE), the CPE (110) is typically stationary and is intended to provide broadband access at a fixed premises such as a home, office, or enterprise location. The CPE (110) further includes a routing function to distribute connectivity to enduser devices via wired Ethernet or wireless local area networking (Wi-Fi). From the perspective of the 5G core and radio access network, the CPE (110) may be performs registration, authentication, and policy control. However, due to its stationary nature, specialized policy enforcement may be required to prevent misuse, unauthorizedrelocation, or theft. The CPE devices (110) are managed in wireless communication networks using identifiers such as a Tracking Area Identity (TAI) and a Tracking Area Code (TAC).
[0069] The CPE is provisioned in the network based on specific criteria related to Tracking Area Codes (TACs) and Tracking Area Identities (TAIs) provided in the Subscriber Profile Repository (SPR). This provisioning process may involve configuring or associating the CPE with certain TACs or TAIs to ensure proper network operation and service delivery, for managing network capacity, coverage, or service quality.
[0070] In an embodiment, the network (106) may include, by way of example but not limitation, at least a portion of one or more networks having one or more nodes that transmit, receive, forward, generate, buffer, store, route, switch, process, or a combination thereof, etc. one or more messages, packets, signals, waves, voltage or current levels, some combination thereof, or so forth. The network (106) may also include, by way of example but not limitation, one or more of a wireless network, a wired network, an internet, an intranet, a public network, a private network, a packet- switched network, a circuit-switched network, an ad hoc network, an infrastructure network, a Public-Switched Telephone Network (PSTN), a cable network, a cellular network, a satellite network, a fiber optic network, or some combination thereof.
[0071] In an embodiment, the UE (104) is communicatively coupled with the network (106). The network (106) may receive a connection request from the UE (104). The network (106) may send an acknowledgment of the connection request to the UE (104). The UE (104) may transmit a plurality of signals in response to the connection request.
[0072] Although FIG. 1 shows exemplary components of the network architecture (100), in other embodiments, the network architecture (100) may includefewer components, different components, differently arranged components, or additional functional components than depicted in FIG. 1. Additionally, or alternatively, one or more components of the network architecture (100) may perform functions described as being performed by one or more other components of the network architecture (100).
[0073] FIG. 2 illustrates an exemplary block diagram (200) of the system (108), in accordance with an embodiment of the present disclosure. FIG. 2 is explained in conjunction with FIGS. 1.
[0074] Referring to FIG. 2, in an embodiment, the system (108) may include one or more processor(s) (202). The one or more processor(s) (202) may be implemented as one or more microprocessors, microcomputers, microcontrollers, digital signal processors, central processing units, logic circuitries, and / or any devices that process data based on operational instructions. Among other capabilities, the one or more processor(s) (202) may be configured to fetch and execute computer-readable instructions stored in a memory (204) of the system (108). The memory (204) may be configured to store one or more computer-readable instructions or routines in a non- transitory computer readable storage medium, which may be fetched and executed to create or share data packets over a network service. The memory (204) may include any non-transitory storage device including, for example, volatile memory such as random-access memory (RAM), or non-volatile memory such as erasable programmable read only memory (EPROM), flash memory, and the like.
[0075] In an embodiment, the system (108) may include an interface(s) (206). The interface(s) (206) may include a variety of interfaces, for example, interfaces for data input and output devices (I / O), storage devices, and the like. The interface(s) (206) may facilitate communication through the system (108). The interface(s) (206) may also provide a communication pathway for one or more components of the system(108). Examples of such components include, but are not limited to, a processing engine (208) and a database (210).
[0076] In an embodiment, the system (108) may include a processing engine (208) that may be implemented as a combination of hardware and programming (for example, programmable instructions) to implement one or more functionalities of the processing engine (208). In the examples described herein, such combinations of hardware and programming may be implemented in several different ways. For example, the programming for the processing engine (208) may be processorexecutable instructions stored on a non-transitory machine-readable storage medium and the hardware for the processing engine (208) may comprise a processing resource (for example, one or more processors), to execute such instructions. In the present examples, the machine-readable storage medium may store instructions that, when executed by the processing resource, implement the processing engine (208). In such examples, the system may comprise the machine-readable storage medium storing the instructions and the processing resource to execute the instructions, or the machine- readable storage medium may be separate but accessible to the system and the processing resource. In other examples, the processing engine (208) may be implemented by electronic circuitry. The processing engine (208) may be configured to validate a plurality of network subscribers.
[0077] In an embodiment, the system (108) may include the database (210) that includes data that may be either stored or generated as a result of functionalities implemented by any of the components of the processor (202) or the processing engine (208).
[0078] In an embodiment, the system (108) may include a subscriber profile repository (SPR) (212), a policy control function (PCF) (214) and an access and mobility management function (AMF) (216), an CPE (110). In an aspect, the SPR (212) may be coupled with the PCF (214). The SPR (212) may be configured to storea set of data associated with each of the plurality of subscribers. The set of data may include, but is not limited to, a subscriber profile, a service configuration, and a network preference. In an aspect, the set of data may include, but is not limited to, subscriber identity information, authentication data, subscription data, mobility data, policy data, and security and privacy data. In an aspect, the SPR (212) may store the TAI value corresponding to each of the plurality of subscribers. For example, the SPR (212) may store the TAI value for each of the subscribers in a table format. The table format may have one or more columns. The column 1 may indicate the TAI value. The column 2 may indicate the subscriber ID.
[0079] In an aspect, the PCF (214) may be configured to enforce network policies and rules in the network (106). The PCF (214) may ensure efficient allocation of network resources. The PCF (214) may enforce policies related to quality of service in the network (106). The PCF (214) may interact with the SPR (212) to retrieve the set of data associated with the plurality of subscribers. The set of data may be essential for enforcing network policies based on the subscriber profile.
[0080] In an aspect, the AMF (216) may be coupled with PCF (214). The AMF (216) may be configured to manage subscriber access to the network (106). The AMF (216) may be configured to authenticate the plurality of subscribers requesting to access the network. The AMF (216) may communicate with the PCF (214).
[0081] In an embodiment, the system (108) may be connected with a customer premises unit (CPE) (110). In another embodiment, the system (108) may include the customer premises unit (CPE) (110). The CPE (110) may be configured with the network (106) based on the TAC and the TAI values provided in the SPR (212). The CPE(l lO) may be configured with the network (106) to ensure proper network operation and service delivery. The CPE(110) may manage network capacity, network coverage and service quality of the network (106). The CPE (110) may be configuredto access the network (106) on a specific TAC basis, ensuring policy compliance and effective resource utilization within the network (106).
[0082] In an embodiment, the CPE (110) may be a significant component in the network (106) to establish a connection between the subscriber and the network. The CPE (110) may serve as a gateway or access point for the network. The CPE (110) may enable communication between the user equipment and the network (106). The CPE (110) may be provisioned in the network based on the TAC and the TAI value stored in the SPR (212).
[0083] In an aspect, the PCF (214) may be configured to receive at least one policy control create request from the access and mobility management function (AMF) (216). The at least one policy control create request may include one or more TAI values, along with additional parameters such as policy rules, service requirements, and network access conditions. The PCF (214) may extract at least one TAI value from at least one policy control create request. The at least one extracted TAI values help the PCF (214) to tailor policy enforcement based on specific geographic and tracking areas within the network. The PCF (214) may communicate with the AMF (216) via a network interface. For example, the AMF (216) may interact with PCF (214) through the N15 interface. The N15 interface may be used to configure the service area restriction capability. The N15 interface may be used to track location of the subscriber.
[0084] In an aspect, the PCF (214) may extract a subscriber ID from the at least one policy control create request, and based upon the extracted subscriber ID, the PCF (214) may be configured to send a request to the SPR (212) for fetching a set of data from the SPR (212). In an aspect, the request may include the subscriber ID. The set of data may include, but is not limited to, subscriber identity information, authentication data, subscription details, mobility data, policy information, and security and privacy data. The PCF utilizes this comprehensive set of data toeffectively manage network policies, ensure secure and compliant access control, and optimize service delivery based on individual subscriber profiles and network requirements.
[0085] Upon receiving the request, the SPR (212) may be configured to transmit the set of data with a list of one or more provisioned TAI values corresponding to the subscriber ID to the PCF (214). The TAI values may be stored in a custom field. For example, the list of provisioned TAI values may be stored in a table. The table may have one or more custom fields. The custom field may include a subscriber ID, a subscriber name, an Internet Protocol (IP) address, etc.
[0086] On the receiving the list of one or more provisioned TAI values, the PCF (214) may be configured to perform a comparison between the extracted TAI value from the at least one policy control creates request and the one or more provisioned TAI values for validating the subscriber. The comparison may be performed using a comparison mechanism. The comparison mechanism compares the received TAI with the list of provisioned TAI to validate the subscriber. In an aspect, the SPR (212) may be configured to update the one or more provisioned TAI values in real time. In an aspect, the comparison mechanism involves comparing a current data with a provisioned data. For example, the current data may be the TAI value received from the AMF (216). The provisioned data may be the list of TAI values stored in the SPR (212). The comparison mechanism enables flexible and adaptive access control policies. The comparison mechanism may allow the PCF (214) to promptly decide the subscriber access to the network (106).
[0087] Based on the comparison, the PCF (214) may be configured to enable network access to the subscriber based on the comparison of the TAI value. The PCF (214) may attach customer premises equipment (CPE) of the subscriber attached to the network (106).
[0088] In an aspect, the system may be configured to provision one or more Customer Premises Equipments (CPEs) within the network based on specific Tracking Area Codes (TACs) and Tracking Area Identities (TAIs) as stored in the SPR. The system configures the CPE to be associated with particular TACs and TAIs provided in the SPR (212), thereby ensuring effective network operation and optimal service delivery. This configuration is crucial for managing network capacity, coverage, and quality of service in accordance with the geographic and tracking area specifications. The provisioning of the CPE ensures that the CPE is optimally aligned with the network's geographic and tracking area requirements, facilitating efficient management of network capacity, coverage, and service delivery. By integrating TAC and TAI details with the AMF (216) and the PCF (214) , the system (108) ensures that the CPE (110) supports seamless mobility management, adheres to access control policies, and maximizes resource utilization within the network.
[0089] Additionally, the system integrates TAC and TAI details with the AMF (216) and the PCF (214) to enable precise provisioning of the CPE (110) on a TAC- specific basis. This integration effectively addresses challenges related to mobility management, network access control, subscriber experience, and resource optimization. By aligning CPE provisioning with AMF (216) and PCF (214) functionalities, the system ensures compliance with policy regulations and enhances resource utilization within the 5G network, thereby improving overall network efficiency and service quality.
[0090] FIG. 3 illustrates an exemplary system architecture (300), in accordance with an embodiment of the present disclosure. FIG. 3 is explained in conjunction with FIGS. 1 and 2.
[0091] In an embodiment, the system architecture (300) may include the SPR (212), the PCF (214) and the AMF (216). The SPR (212) may be coupled with the PCF (214). The AMF (216) may be coupled with the PCF (214).
[0092] In an embodiment, the SPR (212) may be a database or repository. The SPR (212) may be configured to store the set of data associated with the plurality of subscribers in the network. The set of data of the plurality of subscribers may include a subscriber profile, a service configuration, and a network preference. In an aspect, the set of data may comprise subscriber identity information, authentication data, subscription data, mobility data, policy data, and security and privacy data.
[0093] In an embodiment, the SPR (212) may store the Tracking area code (TAC) and the tracking area identity (TAI) value of the plurality of subscribers. In an aspect, the TAC may be a unique identifier within a Public Land Mobile Network (PLMN). The TAC may be used to distinguish different tracking area within a network. For example, the tracking area may be a geographic area in the network, where the subscriber is monitored for the purpose of mobility management. In an aspect, the TAI value may be used to identify a specific tracking area within the network. The TAI value may include a Mobile Country Code (MCC), a Mobile Network Code (MNC), and the Tracking area code (TAC). For example, the SPR (212) may be configured to store the TAI value in the custom field. For example, the TAI value may be composed of MCC 310 (United States), MNC 260 (for example, ABC Network), and TAC 12345678 (an International Mobile Equipment Identity (IMEI) number of the user equipment). The SPR (212) may store the list of TAI values. The list may include one or more subscriber details in a table form. The table form may have one or more custom fields to store the TAI value.
[0094] In an embodiment, the present disclosure relates to method and system for managing the network access in Fixed Wireless Access (FWA) services through a Customer Premises Equipment (CPE) device (110) based on network identifiers including a Mobile Country Code (MCC), a Mobile Network Code (MNC), and a Tracking Area Code (TAC). In various embodiments, these identifiers are used notonly for mobility management and registration but also for enforcing operatorspecific, country-specific, and location-specific network policies for the CPE.
[0095] In some embodiments, the MCC associated with the Public Land MobileNetwork (PLMN) provides an indication of the country in which the CPE is attempting to register. The MCC may be utilized by the core network to enforce country-specific regulations. For example, based on the MCC, the CPE may be configured to operate only on frequency bands authorized within a given jurisdiction. In one embodiment, the network policy management function applies transmit power limitations and regulatory compliance features in accordance with the MCC. In another embodiment, the MCC is employed to distinguish between home-country access and international roaming access, thereby enabling or disabling CPE services depending on regulatory or operator policy.
[0096] The MNC identifies the operator within the corresponding MCC. In various embodiments, the MNC is used by the network to determine the operatorspecific subscription policies applicable to the CPE. In one implementation, the CPE is locked to a particular operator by restricting registration to only those PLMNs containing the authorized MNC. This prevents the CPE from operating on competing networks. In another implementation, the MNC is utilized to assign operator-specific Quality of Service (QoS) parameters to the CPE, such as throughput limits, latency targets, or traffic prioritization. In yet another embodiment, the MNC may determine whether a CPE is authorized for full-service access (e.g., data and voice services) or restricted access (e.g., data-only service).
[0097] The TAC identifies a geographical tracking area within the operator’s network. In some embodiments, the TAC is used to enforce location-specific CPE policies. For example, the operator may restrict the operation of the CPE to a designated TAC corresponding to the subscriber’s registered service address. If the CPE attempts to register in a different TAC, the registration may be rejected orrestricted. This enables geofencing control, ensuring that subsidized CPE devices are not relocated outside the intended service area.
[0098] In another embodiment, the TAC is used to differentiate services and network optimization for FWA traffic. For example, one TAC may be designated exclusively for stationary FWA CPEs, while another TAC may be allocated for mobile user equipment (UE). This separation allows the operator to apply distinct paging, signaling, and congestion control policies for stationary high-bandwidth CPEs compared to mobile handsets. In further embodiments, the TAC may trigger differentiated QoS profiles, such as granting higher bandwidth allowances in rural TACs while applying stricter congestion management in dense urban TACs.
[0099] The following use cases illustrate the impact of MCC, MNC, and TAC on CPE network policy in accordance with various embodiments:
[0100] Geofencing Enforcement: The operator restricts a CPE to operate only within a designated TAC. If the CPE is moved outside the allowed TAC, the device is denied network registration, thereby preventing unauthorized relocation.
[0101] Regulatory Compliance: The MCC ensures that CPE operation adheres to national regulatory frameworks, including band allocation, power limits, and lawful interception requirements.
[0102] Operator Locking: By applying policies based on the MNC, the CPE is restricted to operate exclusively on the subscribed operator’s network, ensuring revenue protection and service control.
[0103] QoS Differentiation: The network applies different QoS profiles depending on the MNC or TAC. For example, a rural TAC may provide extended coverage and higher downlink allowances, while an urban TAC applies congestion controls to manage bandwidth-intensive FWA traffic.
[0104] Fraud Prevention: MCC, MNC, and TAC validation prevent unauthorized use of subsidized CPE devices across unapproved regions or on unauthorized operators’ networks.
[0105] Network Optimization: Dedicated TACs are created for FWA devices, enabling the operator to apply specialized paging and signaling strategies optimized for stationary, high-bandwidth traffic, thereby improving network efficiency.
[0106] In an embodiment, the SPR (212) may be configured to dynamically provision TAI values into the custom field in real-time based upon network requirements. The dynamic provisioning involves adding the TAI values of the subscribers in the SPR (212). The dynamic provisioning of TAI value may be initiated by the user (102) via request for connection to the network (106). In an example, the user (102) may be a network operator or a service provider. The request may be a connection request, a data transmission request, a service request and a session request. The request may be initiated via the customer premises equipment (110). The SPR (212) stores the set of data of the requested user (subscriber) in various fields.
[0107] In an embodiment, the AMF (216) may be configured to manage access and mobility aspects for user devices in the network (106). The AMF (216) may be configured to handle access control, mobility management, and connection establishment for the customer premises equipment (110). The AMF (216) may be configured to verify the identity of customer premises equipment (110) seeking to access the network (106). The AMF (216) may be configured to handle registration management, connection management, reachability management, mobility management and access management. In an aspect, the AMF (216) may interact with PCF (214) through the N15 interface. For example, the N15 interface may be used to configure the service area restriction capability. The N15 interface may be used to track the location of the subscriber.
[0108] In an aspect, the AMF (216) may be configured to receive TAI value from a gNodeB (gNodeB). The gNB may select the AMF (216) for a session. The gNB may allocate an identifier for the subscriber in the network (106). For example, the identifier may be “RAN UE NGAP ID”. The “RAN UE NGAP ID” may include a user location information, the TAI value, a list of sessions and a user equipment (UE) capability. The AMF (216) may retrieve the TAI value from the initial message. The AMF (216) may send the TAI value to the PCF (214).
[0109] In an embodiment, the PCF (214) may be configured to enable efficient policy control and network management. The PCF (214) may be configured to fetch the set of data related to the plurality of subscribers from the SPR (212). The PCF (214) may be configured to perform a comparison mechanism. In an aspect, the comparison mechanism involves comparing the TAI value received in an AM policy control create request with the list of provisioned TAI values retrieved from the SPR (212). The comparison mechanism enables flexible and adaptive access control policies. For example, the access policies are rules and configurations that control subscribers in enabling access to the network. The comparison mechanism may allow the PCF (214) to promptly decide the subscriber access to the network (106).
[0110] In an aspect, the PCF (214) may be configured to determine a location of the subscriber within the network. For example, the location may be a current location. The current location of the subscriber may be determined based on the TAI value received from the SPR (212). The PCF (214) may be configured to enable network access to the subscriber based on the location. For example, a specific track area based on TAI value may be blocked by a service operator for security reasons. In such cases, the subscriber may be blocked to use the network at the specific track area.
[0111] FIG. 4 illustrates an exemplary flow diagram of a method for providing network access to a subscriber based on tracking area identity (TAI) value in thenetwork (106), in accordance with an embodiment of the present disclosure. FIG. 4 is explained in conjunction with FIGS. 1, 2, and 3.
[0112] At step 404, a provisioning gateway (402) may create a profile for one or more subscriber in the SPR (212). The provisioning gateway (402) may allocate Internet Protocol (IP) addresses to the CPE (110). The profile for one or more subscribers may be created in the SPR (212). The profile may include but is not limited to, a user identity, a Subscription Permanent Identifier (SUPI), subscriber authentication data, a subscriber status, the Tracking area code (TAC), and the tracking area identity (TAI) value. For example, the TAI value may be stored in the custom field. The custom field may store a string datatype.
[0113] In an aspect, the AMF (216) may receive TAI value from a gNodeB (gNodeB). The gNB may select the AMF (216) for a session. The gNB may allocate an identifier for the subscriber in the network (106). For example, the identifier may be “RAN UE NGAP ID”. The RAN UE NGAP ID may be sent as an initial message to the AMF (216). The gNB may send an initial message to the AMF (216) and comprises the identifier assigned to the subscriber. For example, the initial message may be RAN UE NGAP ID, Non-Access Stratum (NAS) Registration Request = {Registration type, 5G-GUTI, Last TAI, Requested NSSAI, UE Capability, List of protocol data unit (PDU) Sessions}, User Location Information, Radio Resource Control (RRC) Establishment Cause, 5G-S-TMSI, AMF Set ID. The TAI value may be sent to the PCF (214).
[0114] In an aspect, the SPR (212) may be provisioned with the details of list of TAI values in the custom field. The SPR (212) may be provisioned with the TAI values from the provisioning gateway (402) or Service Management Platform (SMP) User Interface (UI). In an aspect, the Service Management Platform (SMP) User Interface (UI) may provide the network users with an intuitive and efficient way to interact with and manage various network services and operations.
[0115] At step 406, the AMF (216) may send an AM policy control create request to the PCF (214). The AM policy control create request may include the tracking area identifier (TAI) value of a subscriber. For example, the AM policy control create request may be “Npcf_AMPolicyControl_Create”. The AMF (216) may send an HTTP POST request to the PCF (214) to request policies. The PCF (214) may send a “created” response to the AMF (216). In an aspect, the AMF may send the AM policy control create request along with TAI value. The TAI value may be the value of a subscriber requesting network access.
[0116] At step 408, the PCF (214) receives the TAI of the requested subscriber via the AM policy control create request from the AMF (216). The PCF (214) may initiate a fetch request to SPR (212). The PCF (214) may request the set of data associated with the plurality of subscribers. For example, the PCF (214) may fetch the set of data from SPR (212) using the Subscription Permanent Identifier (SUPI). The SUPI may be a permanent unique identifier assigned to each of the subscribers in the network (106). The SUPI may be a 15-digit string. The SUPI includes the Mobile Country Code (MCC), the Mobile Network Code (MNC) and a Mobile Subscriber identification number (MSIN).
[0117] At step 410, the SPR (212) may retrieve the set of data of the plurality of subscribers. The SPR (212) may provide the set of data of the subscribers with a list of provisioned TAI value. For example, the list of provisioned TAI value may be retrieved from the custom field.
[0118] In an aspect, a TAC is a unique identifier within a Public Uand Mobile Network (PUMN). The TAC may be used to distinguish different tracking area within a network. In an aspect, the TAI value may be used to identify a specific tracking area within the network. The TAI value may include the Mobile Country Code (MCC), the Mobile Network Code (MNC), and the Tracking area code (TAC). For example, the SPR (212) stores TAI value in the custom field.
[0119] At step 412, the PCF (214) may compare the TAI value received via the AMF (216) with the list of provisioned TAI. The list of provisioned TAI values may be retrieved from the SPR (212). In an aspect, the PCF (214) may perform a dynamic comparison mechanism on the TAI values. The dynamic comparison mechanism involves comparing the TAI value received in the AMF policy control create request with the list of provisioned TAI values retrieved from the SPR (212). The dynamic comparison mechanism enables flexible and adaptive access control policies. The dynamic comparison mechanism may allow the PCF (214) to promptly decide the subscriber access to the network (106).
[0120] At step 414, the PCF (214) may allow the subscriber to latch to the network (106) if the received TAI value matches with the list of provisioned TAI values. In an aspect, the process of latching involves the subscriber via the user equipment (104) connecting to the network (106). In an aspect, the PCF may allow or reject access to the network using the dynamic comparison mechanism.
[0121] At step 416, the PCF (214) may deny the subscriber to latch to the network (106), if the received TAI value does not match with the list of provisioned TAI value. The PCF (214) may reject the subscriber in case the received TAI value via the AM policy control creates a request not found in the list of provisioned TAI values.
[0122] In an aspect, the PCF (214) may determine the subscriber access to the network (106) based on the TAI value. The TAI value may be used to determine the specific tracking area of the subscriber. The PCF (214) may restrict the access to network (106) to the unauthorized subscribers. The PCF (214) ensures compliance with privacy and security regulations.
[0123] In an aspect, the PCF (214) may attach the customer premises equipment (CPE) of the subscriber attached to the network (106) based on the TAI value. ThePCF (214) may perform a comparison between the received TAI value and the list of provisioned TAI. In case, the TAI value matches with the provisioned TAI, the PCF (214) may enable attachment of the CPE.
[0124] FIG. 5 illustrates an exemplary flow diagram of a method (500) for providing network access to a subscriber based on tracking area identity (TAI) value in the network, in accordance with an embodiment of the present disclosure. FIG. 5 is explained in conjunction with FIGS. 1, 2, 3, and 4.
[0125] At step 502, a policy control function (PCF) (214) receives at least one policy create request from an access and mobility function (AMF) (216) to create a policy for at least one network device (110). In an embodiment, the network device (110) is a customer premises equipment. The at least one policy create request comprises at least one Tracking Area Identity (TAI) value and one or more parameters. As an example, the one or more parameters include policy rules, service requirements, and network access conditions. The one or more parameters are not limited only to the parameters as mentioned above, it may include other parameters not mentioned in the present disclosure. The TAI value comprises a Mobile Country Code (MCC), a Mobile Network Code (MNC), and a Tracking Area Code (TAC).
[0126] At step 504, the PCF (214) fetches a set of data associated with the at least one network device (110) from a subscriber profile repository (SPR) (212). For fetching the set of data, the PCF (214) extracts, a subscriber identifier (ID) associated with the at least one network device (110) from the at least one policy control create request and sends a retrieval request to the SPR (212) for fetching the set of data associated with the at least one network device (110) based on the extracted subscriber ID. The SPR (212) transmits the set of data to the PCF (214), upon receiving the retrieval request. The set of data comprises at least a list of provisioned TAI values.
[0127] At step 506, the PCF (214) compares the received at least one TAI value with the list of provisioned TAI value. The list of provisioned TAI values may be prestored subscriber data in the SPR (212). The provisioned and received TAI values may have one or more columns. Column 1 may indicate the TAI values as a Mobile Country Code (MCC), a Mobile Network Code (MNC), and a Tracking Area Code (TAC) of the subscriber / CPE. Column 2 may indicate the status of network access. These values in column 1 of provisioned and received TAI values are compared. The PCF (214) may promptly allow or reject subscriber access based on the TAI value comparison.
[0128] At step 508, the PCF (214) manages the network access of the at least one network device (110) based on the comparison. The PCF (214) permits the network access to the at least one network device (110) if the received TAI value matches with at least one TAI value present in the list of provisioned TAI values and denies the network access to the at least one network device (110), if the received TAI value does not match with any TAI value present in the list of provisioned TAI values.
[0129] FIG. 6 illustrates an exemplary computer system (600) in which or with which embodiments of the present disclosure may be implemented. FIG. 6 is explained in conjunction with FIGS. 1-5.
[0130] As shown in FIG. 6, the computer system (600) may include an external storage device (610), a bus (620), a main memory (630), a read-only memory (640), a mass storage device (650), a communication port (660), and a processor (670). A person skilled in the art will appreciate that the computer system (600) may include more than one processor (670) and communication ports (660). The processor (670) may include various modules associated with embodiments of the present disclosure.
[0131] In an embodiment, the communication port (660) may be any of an RS- 232 port for use with a modem-based dialup connection, a 10 / 100 Ethernet port, aGigabit or 10 Gigabit port using copper or fibre, a serial port, a parallel port, or other existing or future ports. The communication port (660) may be chosen depending on the network (106), such a Local Area Network (LAN), Wide Area Network (WAN), or any network to which the computer system (600) connects.
[0132] In an embodiment, the memory (630) may be Random Access Memory (RAM), or any other dynamic storage device commonly known in the art. Read-only memory (640) may be any static storage device(s) e.g., but not limited to, a Programmable Read Only Memory (PROM) chips for storing static information e.g., start-up or Basic Input / Output System (BIOS) instructions for the processor (670).
[0133] In an embodiment, the mass storage device (650) may be any current or future mass storage solution, which may be used to store information and / or instructions. Exemplary mass storage solutions include, but are not limited to, Parallel Advanced Technology Attachment (PATA) or Serial Advanced Technology Attachment (SATA) hard disk drives or solid-state drives (internal or external, e.g., having Universal Serial Bus (USB) and / or Firewire interfaces), one or more optical discs, Redundant Array of Independent Disks (RAID) storage, e.g., an array of disks (e.g., SATA arrays).
[0134] In an embodiment, the bus (620) communicatively couples the processor(s) (670) with the other memory, storage, and communication blocks. The bus (620) may be, e.g., a Peripheral Component Interconnect (PCI) / PCI Extended (PCLX) bus, Small Computer System Interface (SCSI), Universal Serial Bus (USB) or the like, for connecting expansion cards, drives and other subsystems as well as other buses, such a front side bus (FSB), which connects the processor (670) to the computer system (600).
[0135] Optionally, operator and administrative interfaces, e.g., a display, keyboardjoystick, and cursor control device, may also be coupled to the bus (620) tosupport direct operator interaction with the computer system (600). Other operator and administrative interfaces may be provided through network connections connected through the communication port (660). The components described above are meant only to exemplify various possibilities. In no way should the aforementioned exemplary computer system (600) limit the scope of the present disclosure.
[0136] The present disclosure offers significant technical advancements providing network access to a subscriber based on tracking area identity (TAI) value in a network. These advancements overcome the limitations of existing solutions by integrating TAC and TAI details provisioned in the SPR with the AMF and PCF functionalities. The CPE is efficiently provisioned with a specific TAC while ensuring policy compliance and effective resource utilization within the 5G network. The present disclosure enables to precisely determine a subscriber's location within the network by verifying the subscriber's location against the provisioned tracking area identities. By dynamically provisioning TAI details into custom fields and comparing them with the TAI value received in policy creation requests, the present disclosure ensures real-time validation of subscriber access. This comparison mechanism allows for flexible and adaptive access control policies. The invention enables real-time decision making regarding subscriber network access.TECHNICAL ADVANTAGES
[0137] The present disclosure described herein above has several technical advantages including, but not limited to, the realization of the system and the method that:
[0138] The present disclosure provides a system and a method for validating subscriber network access based on tracking area identity (TAI) value in a network.
[0139] The present disclosure utilizes the Tracking Area Identity (TAI) as a mechanism for detecting and preventing unauthorized relocation or theft of the CPE deployed for Fixed Wireless Access (FWA).
[0140] The present disclosure provides a system and a method to allow access to the subscriber based on region-based network policy.
[0141] The present disclosure provides a system and a method for mobility management using the subscriber location and give the access control to 5G network using the TAI.
[0142] By dynamically provisioning TAI details and comparing them with the TAI value received in policy creation requests, the present disclosure ensures realtime validation of subscriber access. The present disclosure enables real-time decision making regarding subscriber network access.
[0143] The present disclosure includes a comparison mechanism in the system that enables flexible and adaptive access control policies. The comparison mechanism may allow the PCF to promptly decide the subscriber access to the network.
[0144] The present disclosure provides a system and a method for determining the location of a subscriber within the network to ensure proper mobility management and access control.
[0145] The present disclosure provides a system and a method for enforcing access policies to maintain network security and integrity. By restricting network access to authorized subscribers within specific tracking areas, the present disclosure mitigates the risk of unauthorized access and ensures compliance with privacy and security regulations.
[0146] The present disclosure enables the subscribers to connect to the network when they are within the allowed tracking areas, thereby ensures uninterrupted connectivity and enhances subscriber satisfaction.
[0147] The present disclosure provides a system and a method for provisioning customer premises equipment (CPE) on a specific Tracking area code (TAC).
[0148] The present disclosure manages network access control just for CPE which leads to managing access control of many UEs latched to the CPE without using UEs information.
Claims
CLAIMS1. A method (500) for managing network access, the method comprising: receiving, by a policy control function (PCF) (214), at least one policy create request from an access and mobility function (AMF) (216) to create a policy for at least one network device (110), wherein the at least one policy create request comprises at least one Tracking Area Identity (TAI) value and one or more parameters; fetching, by the PCF (214), a set of data associated with the at least one network device (110) from a subscriber profile repository (SPR) (212), wherein the set of data comprises at least a list of provisioned TAI values; comparing, by the PCF (214), the received at least one TAI value with the list of provisioned TAI value; and managing, by the PCF (214), the network access of the at least one network device (110) based on the comparison.
2. The method (500) as claimed in claim 1, wherein fetching the set of data associated with the at least one network device (110) comprises: extracting, by the PCF (214), a subscriber identifier (ID) associated with the at least one network device (110) from the at least one policy control create request; and sending, by the PCF (214), a retrieval request to the SPR (212) for fetching the set of data associated with the at least one network device (110) based on the extracted subscriber ID, wherein the SPR (212) transmits the set of data to the PCF (214), upon receiving the retrieval request.
3. The method (500) as claimed in claim 1, wherein the TAI value comprises a Mobile Country Code (MCC), a Mobile Network Code (MNC), and a Tracking Area Code (TAC).
4. The method (500) as claimed in claim 1, wherein the managing the network access comprises: permitting, by the PCF (214), the network access to the at least one network device (110), if the received TAI value matches with at least one TAI value present in the list of provisioned TAI values.
5. The method (500) as claimed in claim 1, wherein the network device (110) is a customer premises equipment (CPE) in the network (106).
6. The method (500) as claimed in claim 1, wherein the managing the network access comprises: denying, by the PCF (214), the network access to the at least one network device (110), if the received TAI value does not match with any TAI value present in the list of provisioned TAI values.
7. The method (500) as claimed in claim 1, wherein the list of provisioned TAI values corresponds to the at least one network device (110).
8. A system (108) for managing network access, the system comprising: a policy control function (PCF) (214) configured to receive at least one policy create request from an access and mobility function to create a policy for at least one network device (110), wherein the at least one policy create request comprises at least one Tracking Area Identity (TAI) value and one or more parameters; the PCF (214) configured to fetch a set of data associated with the at least one network device (110) from a subscriber profile repository (SPR) (212), wherein the set of data comprises a list of provisioned TAI values;the PCF (214) configured to compare the received at least one TAI value with the list of provisioned TAI values; and the PCF (214) configured to manage the network access of the at least one network device (110) based on the comparison.
9. The system (108) as claimed in claim 8, wherein the PCF (214) configured to: extract a subscriber identifier (ID) associated with the at least one network device (110) from the at least one policy control create request; and send a retrieval request to the SPR (212) for fetching the set of data associated with the at least one network device (110) based on the extracted subscriber ID, wherein the SPR (212) transmits the set of data to the PCF (214), upon receiving the retrieval request.
10. The system (108) as claimed in claim 8, wherein the TAI value comprises a Mobile Country Code (MCC), a Mobile Network Code (MNC), and a Tracking area code (TAC).
11. The system (108) as claimed in claim 8, wherein to manage the network access of the at least one network device (110), the PCF (214) is configured to: permit the network access to the at least one network device (110), if the received TAI value matches with at least one TAI value present in the list of provisioned TAI values.
12. The system (108) as claimed in claim 11, wherein the network device (110) is a customer premises equipment (CPE) in the network (106).
13. The system (108) as claimed in claim 8, wherein to manage the network access of the at least one network device (110), the PCF (214) is further configured to:deny the network access to the at least one network device (110) if the received TAI value does not match with any TAI value present in the list of provisioned TAI values.
14. The system (108) as claimed in claim 8, wherein the list of provisioned TAI values correspond to the at least one network device (110).
15. A customer premises equipment (CPE) (110) communicatively coupled with a system (108), the coupling comprising: receiving, by the system (108), a connection request from the CPE(no); sending, by the system (108), an acknowledgment of the connection request to the CPE(110); and transmitting a plurality of signals in response to the connection, wherein upon receiving the plurality of signals, managing network access by a method(500) as claimed in claim 1.
Citation Information
Patent Citations
Method and apparatus for location based service in 5g system
US20190116486A1
Method for managing tracking area identity list and user equipment using the same and communication system using the same
US9642065B2