Methods and systems for handling ethernet PDU sessions

By configuring VLAN tags at UDM and DN-AAA servers with SMF precedence, the system addresses the challenge of managing VLAN tags per subscriber in 5G networks, enhancing flexibility and connectivity for various user equipment scenarios.

WO2026075421A1PCT designated stage Publication Date: 2026-04-09SAMSUNG ELECTRONICS CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-25
Publication Date
2026-04-09

AI Technical Summary

Technical Problem

Existing 5G networks lack the ability to manage Virtual Local Area Network (VLAN) tags per subscriber, leading to inconsistent and inflexible handling of Ethernet PDU sessions, which is necessary for scenarios like remote offices and industrial devices connecting to corporate networks.

Method used

Implementing a system where allowed VLAN tags are configured at a Unified Data Management (UDM) and/or DN-AAA server, with the Session Management Function (SMF) giving precedence to these tags over local configurations, enabling per-subscriber control.

Benefits of technology

Enables flexible and tailored management of VLAN tags per user, ensuring appropriate packet handling and connectivity for diverse user equipment scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025015138_09042026_PF_FP_ABST
    Figure KR2025015138_09042026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments herein disclose systems and methods for handling Ethernet Protocol Data Unit (PDU) sessions, specifically how the Virtual Local Area Network (VLAN) tags per subscriber can be controlled in Fifth Generation (5G) Core (5GC). Embodiments herein disclose allowed VLAN tag(s) having different values per UE, wherein the allowed VLAN tag(s) can be configured at a Unified Data Management (UDM) and / or a DN - Authentication, Authorization, and Accounting (DN-AAA) server, wherein the Session Management Function (SMF) gives precedence to the allowed VLAN tag(s) received from the DN-AAA server, over a local configuration, and the allowed VLAN tag(s) received from the UDM.
Need to check novelty before this filing date? Find Prior Art

Description

METHODS AND SYSTEMS FOR HANDLING ETHERNET PDU SESSIONS

[0001] Embodiments disclosed herein relate to wireless communication networks, and more particularly to systems and methods for handling Ethernet Protocol Data Unit (PDU) sessions, specifically how Virtual Local Area Network (VLAN) tags per subscriber can be managed in Fifth Generation (5G) Core (5GC).

[0002] A Protocol Data Unit (PDU) session is a logical connection using which the messages get exchanged between a User Equipment (UE) and a Data Network (DN). Fifth Generation (5G) network functions (for example, Session Management Function (SMF), User Plane Function (UPF), and so on) ensure that the UE and the DN can successfully exchange packets through 5G networks.

[0003] When it comes to IP, 5G System supports the same set of PDU Session types as 4G EPS; i.e., IPv4, IPv6 and IPv4v6. However, especially for IPv6, more features (for example, IPv6 multi-homing) are supported for 5GS compared to EPS. As the name implies, these PDU Session types provide respectively IPv4, or IPv6, or both IPv4 and IPv6 services to the UE. These PDU Session types also support the full range of Quality of Service (QoS) features.

[0004] The Ethernet PDU Session is a new type of PDU Session in 5G System (5GS), wherein the Ethernet PDU Session carries Ethernet frames between the UE and the DN. The use of this PDU session type is to provide the UE with connectivity to a Layer 2 Ethernet Data network. The Ethernet PDU Session can be used in scenarios, wherein the UE is connecting a remote office to a corporate network, the UE is an industrial device connecting to the Local Area Network (LAN) of a factory, a fixed wireless access service where a Residential Gateway is providing bridged Layer 2 services to a fixed wireless broadband customer, and so on.

[0005] As per TS 23.501 Clause 5.6.10.2, the SMF may receive a list of allowed VLAN tags from a DN - Authentication, Authorization, and Accounting (DN-AAA) server (for a maximum of 16 VLAN tags). The VLAN tag is an identifier of an Ethernet frame (Layer 2 packet); i.e., it is an Internet Protocol (IP) address of an IP packet. VLAN tags play an important role for enabling the SMF and the UPF to help in mapping the ethernet frames (packet from the UE and the DN) to transport over 5G from the UE to the DN and vice-versa.

[0006] The SMF may be locally configured with allowed VLAN tag values. The SMF may also be configured with instructions on VLAN handling (for example, the VLAN tag to be inserted or removed, S-TAG to be inserted or removed). Taking this into account, the SMF determines the VLAN handling for the PDU Session, and instructs the UPF to accept or discard the UE traffic based on the allowed VLAN tags, as well as to handle VLAN tags (addition / removal) via Packet Delivery Ratio (PDR) (Outer header removal) and Forwarding Action Rule (FAR) (UPF applying Outer header creation of a Forwarding policy). For example:

[0007] - The UPF may insert (for uplink traffic) and remove (for downlink traffic) a S-TAG on N6 or N19 or internal interface ("5G VN internal") for the traffic from and to the UE.

[0008] - The UPF may insert (for uplink traffic) and remove (for downlink traffic) a VLAN tag on the N6 interface while there is no VLAN in the traffic to and from the UE.

[0009] - The UPF may discard any UE traffic that does not contain any allowed VLAN tag when the UPF handles the UE uplink or downlink traffic.

[0010] At present, the SMF receives the allowed VLAN tag either from the DN-AAA server or may be locally configured at the SMF itself. Also, the VLAN instructs whether the VLAN tag (like C-tag or S-tag to be removed or added) is only configured at the SMF. This local configuration is possible per DNN & Single Network Slice Selection Assistance Information (S-NSSAI) level, but when there is a need for per subscriber control for the operator, there is no solution provided as the DN-AAA server is only invoked when there is secondary authentication, and authorization is enabled for the subscriber for the corresponding Data Network Name (DNN) which the UE uses while making the PDU Session.

[0011] FIG. 1 depicts a scenario, wherein the allowed VLAN tag is configured at a DNN / S-NSSAI level (allowed VLAN tag per DNN / S-NSSAI), i.e., the UPF will only allow packets from the UE when the VLAN tag used by the UE is marked as 'Allowed' in the SMF. It means this treatment is applied equally for all the UEs that use the same DNN / S-NSSAI. In step 1, the SMF has a local configuration of allowed VLAN tags (for example, VLAN1 to VLAN16 per DNN1 / S-NSSAI2). In step 2, the UE1 triggers a PDU session for DNN1 / S-NSSAI1 with PDU session type 'Ethernet'. In step 3, the SMF provides the allowed VLAN tag of VLAN1 to VLAN16 to the UPF. In step 4, UE1 sends user plane traffic over VLAN3 to the UPF. In step 5, the UPF forwards the received packet to the DN as the VLAN tag of VLAN3 falls within the range of the allowed VLAN tag of VLAN1 to VLAN16. Consider that a PDU session is established for UE2 (i.e., a second UE). In step 6, UE2 sends user plane traffic over VLAN20 to the UPF. In step 7, the UPF drops the packet to the DN because the VLAN tag of VLAN20 does not fall within the range of the allowed VLAN tag of VLAN1 to VLAN16. In the example flow depicted in FIG. 1, the allowed VLAN tag is applicable for both UE1 and UE2 because the allowed VLAN tag was configured per DNN1 / S-NSSAI1. But there are use cases where this kind of treatment is needed for individual UEs (for example, FWA deployment). It means there is a need for a different allowed VLAN tag per UE instead of per DNN / S-NSSAI

[0012] Hence, there is a need in the art for solutions which will overcome the above mentioned drawback(s), among others.

[0013] The principal object of embodiments herein is to disclose systems and methods for handling Ethernet Protocol Data Unit (PDU) sessions, specifically how the Virtual Local Area Network (VLAN) tags per subscriber can be controlled in Fifth Generation (5G) Core (5GC).

[0014] Another object of embodiments herein is to disclose allowed VLAN tag(s) having different values per UE, wherein the allowed VLAN tag(s) can be configured at a Unified Data Management (UDM) and / or a DN - Authentication, Authorization, and Accounting (DN-AAA) server, wherein the Session Management Function (SMF) gives precedence to the allowed VLAN tag(s) received from the DN-AAA server, over a local configuration, and the allowed VLAN tag(s) received from the UDM.

[0015] These and other aspects of the embodiments herein will be better appreciated and understood when considered in conjunction with the following description and the accompanying drawings. It should be understood, however, that the following descriptions, while indicating at least one embodiment and numerous specific details thereof, are given by way of illustration and not of limitation. Many changes and modifications may be made within the scope of the embodiments herein without departing from the spirit thereof, and the embodiments herein include all such modifications.

[0016] Embodiments herein are illustrated in the accompanying drawings, throughout which like reference letters indicate corresponding parts in the various figures. The embodiments herein will be better understood from the following description with reference to the following illustratory drawings. Embodiments herein are illustrated by way of examples in the accompanying drawings, and in which:

[0017] FIG. 1 depicts a scenario, wherein the allowed VLAN tag is configured at a DNN / S-NSSAI level (allowed VLAN tag per DNN / S-NSSAI), according to existing arts;

[0018] FIG. 2 is an example call-flow depicting the procedure to address allowed VLAN tag control per subscriber, according to embodiments as disclosed herein;

[0019] FIGs. 3A and 3B are example flow diagrams depicting the procedure to address allowed VLAN tag control per subscriber, according to embodiments as disclosed herein;

[0020] FIG. 4 is a block diagram of a UDM, according to embodiments as disclosed herein;

[0021] FIG. 5 is a flowchart depicting the process of the UDM providing the allowed VLAN tag and VLAN handling information, according to embodiments as disclosed herein;

[0022] FIG. 6 is a block diagram of the DN-AAA server, according to embodiments as disclosed herein;

[0023] FIG. 7 is a flowchart depicting the process of the DN-AAA server providing the allowed VLAN tag and VLAN handling information, according to embodiments as disclosed herein;

[0024] FIG. 8 is a block diagram of a SMF, according to embodiments as disclosed herein;

[0025] FIG. 9 is a flowchart depicting the process of handling Ethernet PDU sessions (when secondary authentication and authorization is enabled), according to embodiments as disclosed herein;

[0026] FIG. 10 is a flowchart depicting the process of handling Ethernet PDU sessions (when secondary authentication and authorization is not enabled), according to embodiments as disclosed herein;

[0027] FIGs. 11A and 11B are flowcharts depicting the process for handling Ethernet Protocol Data Unit (PDU) sessions (when secondary authentication and authorization is enabled), according to embodiments as disclosed herein; and

[0028] FIGs. 12A and 12B are flowcharts depicting the process for handling Ethernet Protocol Data Unit (PDU) sessions (when secondary authentication and authorization is not enabled) , according to embodiments as disclosed herein.

[0029] Terms used in the present disclosure are used to describe various example embodiments, and are not intended to limit a scope of the disclosure. A singular expression may include a plural expression unless the context clearly means otherwise. Terms used herein, including a technical or a scientific term, may have the same meaning as those generally understood by a person with ordinary skill in the art described in the present disclosure. Among the terms used in the present disclosure, terms defined in a general dictionary may be interpreted as identical or similar meaning to the contextual meaning of the relevant technology and are not interpreted as ideal or excessively formal meaning unless explicitly defined in the present disclosure. In some cases, even terms defined in the present disclosure may not be interpreted to exclude embodiments of the present disclosure.

[0030] In various embodiments of the present disclosure described below, a hardware approach will be described as an example. However, since the various embodiments of the present disclosure include technology that uses both hardware and software, the various embodiments of the present disclosure do not exclude a software-based approach.

[0031] The embodiments herein and the various features and advantageous details thereof are explained more fully with reference to the non-limiting embodiments that are illustrated in the accompanying drawings and detailed in the following description. Descriptions of well-known components and processing techniques are omitted so as to not unnecessarily obscure the embodiments herein. The examples used herein are intended merely to facilitate an understanding of ways in which the embodiments herein may be practiced and to further enable those of skill in the art to practice the embodiments herein. Accordingly, the examples should not be construed as limiting the scope of the embodiments herein.

[0032] For the purposes of interpreting this specification, the definitions (as defined herein) will apply and whenever appropriate the terms used in singular will also include the plural and vice versa. It is to be understood that the terminology used herein is for the purposes of describing particular embodiments only and is not intended to be limiting. The terms "comprising", "having" and "including" are to be construed as open-ended terms unless otherwise noted.

[0033] The words / phrases "exemplary", "example", "illustration", "in an instance", "and the like", "and so on", "etc.", "etcetera", "e.g.," , "i.e.," are merely used herein to mean "serving as an example, instance, or illustration." Any embodiment or implementation of the present subject matter described herein using the words / phrases "exemplary", "example", "illustration", "in an instance", "and the like", "and so on", "etc.", "etcetera", "e.g.," , "i.e.," is not necessarily to be construed as preferred or advantageous over other embodiments.

[0034] Embodiments herein may be described and illustrated in terms of blocks which carry out a described function or functions. These blocks, which may be referred to herein as managers, units, modules, hardware components or the like, are physically implemented by analog and / or digital circuits such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits and the like, and may optionally be driven by a firmware. The circuits may, for example, be embodied in one or more semiconductor chips, or on substrate supports such as printed circuit boards and the like. The circuits constituting a block may be implemented by dedicated hardware, or by a processor (e.g., one or more programmed microprocessors and associated circuitry), or by a combination of dedicated hardware to perform some functions of the block and a processor to perform other functions of the block. Each block of the embodiments may be physically separated into two or more interacting and discrete blocks without departing from the scope of the disclosure. Likewise, the blocks of the embodiments may be physically combined into more complex blocks without departing from the scope of the disclosure.

[0035] It should be noted that elements in the drawings are illustrated for the purposes of this description and ease of understanding and may not have necessarily been drawn to scale. For example, the flowcharts / sequence diagrams illustrate the method in terms of the steps required for understanding of aspects of the embodiments as disclosed herein. Furthermore, in terms of the construction of the device, one or more components of the device may have been represented in the drawings by conventional symbols, and the drawings may show only those specific details that are pertinent to understanding the present embodiments so as not to obscure the drawings with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein. Furthermore, in terms of the system, one or more components / modules which comprise the system may have been represented in the drawings by conventional symbols, and the drawings may show only those specific details that are pertinent to understanding the present embodiments so as not to obscure the drawings with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein.

[0036] The accompanying drawings are used to help easily understand various technical features and it should be understood that the embodiments presented herein are not limited by the accompanying drawings. As such, the present disclosure should be construed to extend to any modifications, equivalents, and substitutes in addition to those which are particularly set out in the accompanying drawings and the corresponding description. Usage of words such as first, second, third etc., to describe components / elements / steps is for the purposes of this description and should not be construed as sequential ordering / placement / occurrence unless specified otherwise.

[0037] The embodiments herein achieve systems and methods for Ethernet Protocol Data Unit (PDU) sessions, specifically how the Virtual Local Area Network (VLAN) tags per subscriber can be controlled in Fifth Generation (5G) Core (5GC). Embodiments herein disclose allowed VLAN tag(s) having different values per UE, wherein the allowed VLAN tag(s) can be configured at a Unified Data Management (UDM) and / or a DN - Authentication, Authorization, and Accounting (DN-AAA) server, wherein the Session Management Function (SMF) gives precedence to the allowed VLAN tag(s) received from the DN-AAA server, over a local configuration, and the allowed VLAN tag(s) received from the UDM. Referring now to the drawings, and more particularly to FIGS. 2 through 12, where similar reference characters denote corresponding features consistently throughout the figures, there are shown embodiments.

[0038] Hereinafter, embodiments of the disclosure will be described in detail with reference to the accompanying drawings.

[0039] In describing the embodiments, descriptions related to technical contents well-known in the art and not associated directly with the disclosure will be omitted. Such an omission of unnecessary descriptions is intended to prevent obscuring of the embodiments disclosed herein and more clearly transfer the embodiments disclosed herein.

[0040] For the same reason, in the accompanying drawings, some elements may be exaggerated, omitted, or schematically illustrated. Further, the size of each element does not completely reflect the actual size. In the drawings, identical or corresponding elements are provided with identical reference numerals or different reference numerals.

[0041] The advantages and features of the disclosure and ways to achieve them will be apparent by making reference to embodiments as described below in detail in conjunction with the accompanying drawings. However, the disclosure is not limited to the embodiments set forth below, but may be implemented in various different forms. The following embodiments are provided only to completely disclose the disclosure and inform those skilled in the art of the scope of the disclosure, and the disclosure is defined only by the scope of the appended claims. Throughout the specification, the same or like reference numerals designate the same or like elements. Furthermore, in describing the disclosure, a detailed description of known functions or constitution incorporated herein will be omitted in the case that it is determined that the description may make the subject matter of the disclosure unnecessarily unclear. The terms which will be described below are terms defined in consideration of the functions in the disclosure, and may be different according to users, intentions of the operators, or customs. Therefore, the definitions of the terms should be made based on the contents throughout the specification.

[0042] Herein, it will be understood that each block of the flowchart illustrations, and combinations of blocks in the flowchart illustrations, may be performed based on computer program instructions. These computer program instructions may be loaded individually or collectively onto at least one processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which perform through any one of, or in any combination of, the at least one processor of the computer or other programmable data processing apparatus, create means for performing the functions specified in the flowchart block(s). These computer program instructions may also be stored in a non-transitory computer usable or computer-readable memory that may direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer usable or computer-readable memory produce an article of manufacture including instruction means that perform the function specified in the flowchart block(s). The computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable data processing apparatus to produce a computer executed process such that the instructions that perform on the computer or other programmable data processing apparatus provide steps for executing the functions specified in the flowchart block(s).

[0043] Further, each block may represent a module, segment, or portion of code, which includes one or more executable instructions for executing the specified logical function(s). It should also be noted that in some alternative implementations, the functions noted in the blocks may occur out of the order. For example, two blocks (or functions) shown in succession may in fact be performed substantially concurrently or the blocks may sometimes be performed in the reverse order, depending upon the functionality involved.

[0044] As used in embodiments of the disclosure, a "~unit / module" may refer to a software element or a hardware element, such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC), which performs a predetermined function. However, the term including the word "~unit / module" does not always have a meaning limited to software or hardware. The "~unit / module" may be constructed either to be stored in an addressable storage medium or to execute one or more processors. Therefore, the "~unit / module" includes, for example, software elements, object-oriented software elements, components such as class elements and task elements, processes, functions, properties, procedures, sub-routines, segments of a program code, drivers, firmware, micro-codes, circuits, data, database, data structures, tables, arrays, and parameters. The components and functions provided by the "~unit / module" may be either combined into a smaller number of components and a "~unit / module," or divided into additional components and a "~unit / module." Moreover, the components and "~units / module" may be implemented to reproduce one or more central processing units (CPUs) within a device or a security multimedia card. Further, in the embodiments, the "~unit / module" may include one or more processors.

[0045] The entirety of the one or more computer programs may be stored in a single memory device, or the one or more computer programs may be divided with different portions stored in different multiple memory devices.

[0046] Any of the functions or operations described herein can be processed by one processor or a combination of processors. The one processor or the combination of processors is circuitry performing processing and includes circuitry like an application processor (AP, e.g. a CPU), a communication processor (CP, e.g., a modem), a graphics processing unit (GPU), a neural processing unit (NPU) (e.g., an artificial intelligence (AI) chip), a Wi-Fi chip, a Bluetooth® chip, a global positioning system (GPS) chip, a near field communication (NFC) chip, connectivity chips, a sensor controller, a touch controller, a finger-print sensor controller, a display driver integrated circuit (IC), an audio CODEC chip, a universal serial bus (USB) controller, a camera controller, an image processing IC, microprocessors, microcontrollers, digital signal processors, FPGA, ASIC, a microprocessor unit (MPU), a system on chip (SoC), an IC, or the like. The one processor or the combination of processors executes instructions that can be stored in a memory, such as the operating system, in order to control the overall operation of the device. Also, the one processor or the combination of processors is also capable of executing other processes and programs resident in the memory, such as processes for the disclosure.

[0047] It will be appreciated that various embodiments of the disclosure according to the claims and description in the specification can be realized in the form of hardware, software or a combination of hardware and software.

[0048] Any such software may be stored in non-transitory computer readable storage media. The non-transitory computer readable storage media store one or more computer programs (software modules), the one or more computer programs include computer-executable instructions that, when executed by one or more processors of an electronic device individually or collectively, cause the electronic device to perform a method of the disclosure. Additionally, or alternatively, such software may be a computer program [product] comprising instructions which, when executed by one or more processors of an electronic device individually or collectively, cause the electronic device to perform a method of the disclosure.

[0049] Any such software may be stored in the form of volatile or non-volatile storage such as, for example, a storage device like read only memory (ROM), whether erasable or rewritable or not, or in the form of memory such as, for example, random access memory (RAM), memory chips, device or integrated circuits or on an optically or magnetically readable medium such as, for example, a compact disk (CD), digital versatile disc (DVD), magnetic disk or magnetic tape or the like. It will be appreciated that the storage devices and storage media are various embodiments of non-transitory machine-readable storage that are suitable for storing a computer program or computer programs comprising instructions that, when executed, implement various embodiments of the disclosure. Accordingly, various embodiments of the present disclosure may provide a program comprising code for implementing apparatus or a method as claimed in any one of the claims of this specification and a non-transitory machine-readable storage storing such a program.

[0050] Hereinafter, the determination of priority between A and B in the present disclosure may refer to various actions such as selecting the one having a higher priority based on a predefined priority rule and performing an operation corresponding thereto, or omitting or dropping an operation corresponding to the one having a lower priority.

[0051] Hereinafter, "A or B" as described in the present disclosure may be understood as "A and / or B," which may include A, or B, or both A and B.

[0052] In addition, "at least one of A, B, and C" as described in the present disclosure may be understood to include A, or B, or C, or any combination of A, B, and C.

[0053] In addition, "at least one of A, B, or C" as described in the present disclosure may be understood to include A, or B, or C, or any combination of A, B, and C.

[0054] Furthermore, "A / B" as described in the present disclosure may be understood as "A and / or B," which may include A, or B, or both A and B.

[0055] Furthermore, "A, B" as described in the present disclosure may be understood as "A and / or B," which may include A, or B, or both A and B.

[0056] Furthermore, "A and B" as described in the present disclosure may be understood as "A and / or B," which may include A, or B, or both A and B.

[0057] Furthermore, "if condition A and condition B are satisfied," as described in the present disclosure, may not be limited to a case where both condition A and condition B are satisfied, but may be understood to include a case where either condition A or condition B is individually satisfied, both condition A and condition B are satisfied, or one or more additional conditions are satisfied in combination.

[0058] Furthermore, throughout this disclosure, ordinal terms such as "first," "second," "third," etc., (and similar qualifiers) are used merely to distinguish between different instances, occurrences, configurations, messages, stages, elements or aspects of elements, operations, or information as described herein. Unless the context clearly dictates otherwise, the use of such ordinal terms does not itself require that the elements, operations, or information distinguished by these terms be structurally different, numerically distinct, or substantively dissimilar. For example, a "first signal" and a "second signal" may refer to instances of the same signal transmitted at different times or containing the same core information despite minor variations, or they may refer to signals with different content or characteristics, depending on the specific context. Similarly, a "first value" and a "second value" may represent the same magnitude but measured or applied in different circumstances, or they may represent different magnitudes. The interpretation should be guided by the specific technical context, function, and relationship described in the relevant portion of the specification and claims.

[0059] Furthermore, the terms "first ~", "second ~", etc., as described in the present disclosure with respect to various elements (e.g., information, objects, operation, sequences, or the like), should not limit those elements. These terms may only be intended to distinguish one element from another, and may not be intended to indicate a specific order. For example, a first element could be termed a second element, and, similarly, a second element could be termed a first element.

[0060] Furthermore, even if "first ~" and "second ~" are described in the present disclosure, it may be understood that element(s) referred to by "first ~" and "second ~" may be the same or different. For example, in case of element(s) being information, first information and second information may both be the same information, and, in some cases, are separate and different information.

[0061] In addition, the terms "if ~" and "in case that ~" as used in the disclosure or claims may be interpreted to include the meanings of "when (or upon) ~," "in response to ~," "based on ~," or "according to ~," and may be used interchangeably with these expressions. In addition, expressions other than those exemplified herein may also be used, as long as they have substantially the same meaning and do not impair the technical features of the present disclosure. If a method step (e.g., transmit a signal) is performed according to the disclosure of the application in connection with one of the above terms (such as "in case that ~" or the like), it may be interpreted to include the meanings (disclosure) of a prior determination that a feature has a specific state "~" (e.g., a bit length is above X), and then perform the method step in response to said determination.

[0062] In addition, the term "not perform" as used in the present disclosure or claims may, in context, be understood to mean that the corresponding step is omitted or skipped. Such a term may be replaced with other terms having the same or substantially equivalent meaning.

[0063] In addition, "transmitting a message including A and B" as described in the present disclosure, may be understood as encompassing both (i) transmitting A and B in a single message, and (ii) transmitting A and B separately via multiple messages (e.g., transmitting a first message including A and a second message including B). This interpretation may also apply to messages that include two or more items (e.g., A, B, C), transmitted either together or separately.

[0064] In addition, "transmitting a message including A and transmitting a message including B" may also be interpreted as transmitting a message including A and B in a single message.

[0065] In the specific embodiments of the present disclosure described below, terms or components included in the disclosure may be expressed in singular or plural form depending on the specific embodiments presented. However, such singular or plural expressions are selected appropriately for convenience of description, and the present disclosure is not limited to a singular or plural number of components. A component expressed in the plural form may be implemented as a single component, and a component expressed in the singular form may be implemented as multiple components.

[0066] The drawings or flowcharts described below illustrate example methods that may be implemented according to the principles of the present disclosure, and various modifications may be made to the methods illustrated in the flowcharts of the present disclosure. For example, although illustrated as a series of steps, various steps in each drawing or flowchart may overlap, occur in parallel, occur in a different order, or be repeated. In other examples, any step may be omitted or replaced with another step.

[0067] The process of the flowchart may be performed by a device. One or more of the steps of the flowchart can be implemented by one or more processors / computer programs executing instructions to perform the noted functions.

[0068] The methods and apparatuses proposed in the embodiments of the present disclosure may be disclosed in connection with drawings disclosing flowcharts to illustrate example methods that may be implemented according to the principles of the present disclosure. Such flowcharts may contain different branches and / or sub-branches. It is understood that the principles of the present disclosure do not only contain the combination of all branches / sub-branches disclosed in the embodiment, but the present disclosure also contains at least one isolated branch / isolated sub-branch, in particular to a single branch / single sub-branch.

[0069] The methods and apparatuses proposed in the embodiments of the present disclosure are not limited to each embodiment individually, but may also be applied in combination of all or some of the embodiments proposed in the disclosure. Therefore, the embodiments of the present disclosure may be modified and applied without significantly departing from the scope of the present disclosure, as would be understood by those skilled in the art.

[0070] In this case, even if certain wordings are described differently across embodiments, they may be used interchangeably or in substitution or in combination if their underlying concepts are equivalent. For example, for the same or equivalent concept, even if one embodiment uses the expression "A" and another embodiment uses the expression "B", such expressions may be understood interchangeably, in substitution, or in combination.

[0071] The terms used in the following description to refer to access nodes, network entities, messages, interfaces between network entities, various types of identification information, and the like, are provided merely for the convenience of explanation by way of example. Therefore, the present disclosure is not limited to the terms described below, and other terms having equivalent technical meanings may also be used. Such terms may also be interchangeable with terms defined in any 3rd generation partnership project (3GPP) technical specifications (TS) or similar technical specifications, e.g., from ETSI, where appropriate.

[0072] Hereinafter, a base station (BS) is an entity that allocates resources to terminals, and may be at least one of a gNode B, an eNode B, a Node B, a wireless access unit, a BS controller, or a node on a network.

[0073] Furthermore, the base station of the present disclosure may include a split architecture comprising a central unit (CU) and a distributed unit (DU). In this structure, the CU is configured to process the higher layers of the control and user planes, while the DU is configured to process lower-layer radio resource functions. The embodiments of the present disclosure may be equally applicable to 5G base station architectures in which such CU and DU functional splits are implemented.

[0074] A terminal may include a UE, a mobile station (MS), a cellular phone, a smartphone, a computer, a tablet, a wearable device, an Internet of Things (IoT) device, or any other device / system capable of performing communication functions.

[0075] In the disclosure, a downlink (DL) refers to a radio link through which a BS transmits a signal to a terminal, and an uplink (UL) refers to a radio link through which a terminal transmits a signal to a BS.

[0076] Furthermore, hereinafter, 5th generation (5G) mobile communication technologies (e.g., 5G new radio (NR)), 6th generation (6G) mobile communication technologies may be described by way of example, but the embodiments of the present disclosure may also be applied to other communication systems having similar technical backgrounds or channel types. For example, newly evolved mobile communication systems developed after 5G and 6G may be included. Furthermore, based on determinations by those skilled in the art, the embodiments of the present disclosure may also be applied to other communication systems (e.g., Wi-Fi systems) through some modifications without significantly departing from the scope of the present disclosure

[0077] In the following description, the terms physical channel and signal may be used interchangeably with data or control signal. For example, the term physical downlink shared channel (PDSCH) refers to a physical channel through which data is transmitted, but the term PDSCH may also be used to refer to the data itself. That is, in the present disclosure, the expression "transmit a physical channel" may be interpreted as being equivalent to the expression "transmit data or a signal via a physical channel."

[0078] Hereinafter, in the context of the present disclosure, higher layer signaling may refer to signaling corresponding to at least one or any combination of the following: master information block (MIB), system information block (SIB) or SIB M (M = 1, 2, ...), radio resource control (RRC), or medium access control (MAC) control element (CE), or a non-access stratum (NAS) signaling message, or an application layer message. The RRC signaling message may be referred to as Layer 3 (L3) signaling.

[0079] In addition, Layer 1 (L1) signaling may refer to signaling corresponding to at least one or any combination of signaling techniques using the at least one or any combination of the following physical layer channels or signaling: physical downlink control channel (PDCCH), downlink control information (DCI), user equipment (UE)-specific DCI, group-common DCI, common DCI, scheduling DCI (e.g., DCI used for scheduling downlink or uplink data), non-scheduling DCI (e.g., DCI not used for scheduling downlink or uplink data) physical uplink control channel (PUCCH), or uplink control information (UCI). The L1 signaling message may be referred to as a physical layer signaling.

[0080] For example, the physical layer signaling (i.e., L1 signaling) may include downlink control information (DCI). In addition, the higher layer signaling may include a medium access control (MAC) control message, a radio resource control (RRC) signaling message, a non-access stratum (NAS) signaling message, or an application layer message. The RRC signaling message may be referred to as L3 signaling. It should be noted, however, that the higher layer signaling is not limited to the aforementioned examples.

[0081] Hereinafter, the expression that information is configured by the BS, as used in the present disclosure or claims, may, in context, be understood to mean that the terminal receives the corresponding information from the BS via a physical layer signaling or a higher layer signaling. Such an expression may be replaced with other terms having the same or substantially equivalent meaning.

[0082] Hereinafter, the operational principle of the present disclosure will be described in detail with reference to the accompanying drawings.

[0083] Consider the scenario wherein a UE making a PDU session for a one data network using Data Network Name1 (DNN1) and some slice Single Network Slice Selection Assistance Information1 (S-NSSAI1). Then, the SMF can invoke the DNN-AAA server, if the secondary authentication and authorization for DNN1 is enabled for the UE and then only the DN-AAA server can provide the allowed VLAN tag. In this way, per subscriber control is achieved, otherwise the SMF provides the allowed VLAN tag for all UEs, which have initiated PDU session like DNN2 and S-NSSAI2 as the local configuration of the allowed VLAN tag can be configured per DNN2 and S-NSSAI2. The list of allowed VALN tags for the subscriber is configured at the UDM, wherein the SMF will receive the list of allowed VALN tags as part of the SM subscription data while processing the PDU session triggered from the UE and using the available VLAN instruction, the UPF can be instructed as per TS 23.501 Clause 5.6.10.2.

[0084] FIG. 2 is an example call-flow depicting the procedure to address allowed VLAN tag control per subscriber. In step 1, the allowed VLAN tag is configured in the UDM 105 under DNN1 in a subscription. Also, secondary authentication and authorization is enabled for DNN1 at the UDM 105. In step 2, the UE 101 triggers a PDU session for DNN1 / S-NSSAI1 with PDU session type "Ethernet". In step 3, the SMF 102 receives the allowed VLAN tag as part of the SM subscription download from the UDM 105. In step 4, the SMF 102 invokes the DN-AAA server for secondary PDU authentication and authorization. On successfully performing secondary PDU authentication and authorization, in step 5, the DN-AAA server 104 provides an indication to the UE 101 that the secondary PDU authentication and authorization has been completed successfully. In step 6, the DN-AAA server 104 provides the allowed VLAN tags to the SMF 102. In step 7, the SMF 102 gives precedence to the received allowed VLAN tag from the DN-AAA server 104 (in step 6) over the allowed VLAN tag received from the UDM 105 (in step 3), and the local configuration (at the SMF 102).

[0085] Table 1 depicts UE subscription data types in the UDM 105.

[0086]

[0087]

[0088]

[0089] In an embodiment herein, when the SMF 102 receives the allowed VLAN tag from the UDM 105 and the DN-AAA server 104, then the SMF 102 gives precedence to the value received from the DN-AAA server 104 and supersedes the value received from the UDM 105. In an embodiment herein, the SMF 102 receives the allowed VLAN tag from the DN-AAA server 104, if secondary authentication and authorization is enabled for the DNN. In an embodiment herein, the allowed VLAN tag comprises subscription data and information.

[0090] In an embodiment herein, consider that for the same DNN, an allowed VLAN tag is present locally at the SMF 102; i.e., a local configuration, which can be an allowed VLAN tag configured for the same DNN at the SMF 102, with which the UE is establishing the PDU session. On the SMF 102 receiving the allowed VLAN tag from the UDM 105, the SMF 102 gives precedence to the allowed VLAN tag received from the UDM 105 and supersedes the local configuration. On the SMF 102 receiving the allowed VLAN tag from the DN-AAA server 104, the SMF 102 gives precedence to the allowed VLAN tag received from the DN-AAA server 104 and supersedes the local configuration.

[0091] In an embodiment herein, when there is a local configuration at the SMF 102, subscription data received from the UDM 105 related to the allowed VLAN tag, and / or allowed VLAN tag received from the DN-AAA server 104, the SMF 102 gives precedence to the allowed VLAN tag received from the DN-AAA server 104; i.e., the information from the DN-AAA server 104 supersedes the subscription data and the information received from the UDM 105 and local configuration.

[0092] In an embodiment herein, when a new or updated list of allowed VLAN tag is received / configured at the SMF 102, the SMF 102 inform the UPF 103 in a Packet Forwarding Control Protocol (PFCP) session modification request. The UPF 103 can perform a VLAN tag instruction accordingly, which can include dropping of packets from the UE (if the VLAN used by the UE for sending user plane traffic is not in the allowed VLAN tag), forwarding the packets to the DN (if the VLAN used by the UE for sending user plane traffic is present in the allowed VLAN tag), and so on. In an embodiment herein, the allowed VLAN tag can be received from the DN-AAA server 104 during secondary re-authentication and reauthorization procedure. In an embodiment herein, the allowed VLAN tag can be received from the UDM 105, on the UDM 105 being modified. In an embodiment herein, the allowed VLAN tag can be locally updated at the SMF 105; i.e., local configuration is updated.

[0093] FIGs. 3A and 3B are example flow diagrams depicting the procedure to address allowed VLAN tag control per subscriber. Consider that there are 2 UEs in the network, UE1 101A, and UE2 101B. In step 301A, a first allowed VLAN tag (VLAN1 to VLAN16) is configured at the UDM 105 for UE1 101A, and a third allowed VLAN tag (VLAN20 to VLAN36) is configured at the UDM 105 for UE2 101B. In step 301B, a second allowed VLAN tag (VLAN1 to VLAN16) is configured at the DN-AAA server 104 for UE1 101A, and a fourth allowed VLAN tag (VLAN24 to VLAN40) is configured at the DN-AAA server 104 for UE2 101B. In step 302, the UE1 101A triggers a PDU session for DNN1 / S-NSSAI1 with a PDU session type 'Ethernet'. In step 303, the SMF 102 receives the first allowed VLAN tag from the UDM 105. In step 304, the SMF 102 receives the second allowed VLAN tag from the DN-AAA server 104. In step 305, the SMF 102 provides the second allowed VLAN tag to the UPF 103, as the second allowed VLAN tag (as received from the DN-AAA server 104) takes precedence over the first allowed VLAN tag (as received from the UDM 105). In step 306, the UE1 101A sends user plane traffic to the UPF 103 over VLAN3. In step 307, the UPF 103 forwards the user plane traffic received from the UE1 101A to the DN, as the VLAN tag of VLAN3 is within the range as specified in the second allowed VLAN tag (i.e., VLAN1 to VLAN16) for UE1 101A.

[0094] Consider that a PDU session is established for UE2 101B. In step 308, the SMF 102 receives the third allowed VLAN tag from the UDM 105. In step 309, the SMF 102 receives the fourth allowed VLAN tag from the DN-AAA server 104. In step 310, the SMF 102 provides the fourth allowed VLAN tag to the UPF 103, as the fourth allowed VLAN tag (as received from the DN-AAA server 104) takes precedence over the third allowed VLAN tag (as received from the UDM 105). In step 311, the UE2 101B sends user plane traffic to the UPF 103 over VLAN 41. In step 312, the UPF 103 drops the user plane packets received from the UE2 101B, as the VLAN tag of VLAN 41 is not within the range as specified in the third allowed VLAN tag (i.e., VLAN1 to VLAN16) for UE2 101B.

[0095] The terminal or the base station may perform various communication procedures related to the control plane or the user plane by cooperating with one or more network entities based on wireless communication. For example, the terminal (i.e., the UDM 105) may communicate with a network entity (for example, an Access and Mobility Management Function (AMF), a Session Management Function (SMF), etc.) via the base station, or the base station may perform at least one communication procedure by directly transmitting and receiving signals to / from, or relaying signals between, the network entities.

[0096] The structure of the above-described network entity (i.e., the UDM 105) will be described in more detail with reference to the drawings.

[0097] FIG. 4 is a block diagram of a UDM 105 according to an embodiment of the disclosure.

[0098] The UDM 105 may include an entity (apparatus, device, or server, etc.) that performs one or more network functions (NFs) or a part of a network function constituting a core network (e.g., a 5th generation (5G) core (5GC)) in a communication system. In this case, multiple NFs may be implemented within a single network entity, or a single NF may be distributed and implemented across a plurality of network entities. In addition, when an NF is implemented within the network entity, the NF may be implemented in the form of software, and in such a case, a program for operating the NF may be stored in memory of the UDM 105.

[0099] A single NF may be implemented by one or more instances, which may be deployed on the same network entity or distributed across multiple network entities to operate. The instance may be a software unit that logically executes a specific network function, and may be implemented in a form that is decoupled from physical hardware resources. Further, one or more NFs may be implemented in the form of one network slice to operate to satisfy specifications required by a particular service.

[0100] The NF may include at least one of an access and mobility management function (AMF), a session management function (SMF), a local session management function (L-SMF), a user plane function (UPF), a local user plane function (L-UPF), a policy control function (PCF), a unified data management (UDM), a unified data repository (UDR), a network exposure function (NEF), a network repository function (NRF), an application function (AF), a network slice selection function (NSSF), a network data analytics function (NWDAF), a network slice admission control function (NSACF), an authentication server function (AUSF), a data network (DN), etc..

[0101] Referring to FIG. 4, the UDM 105 may include at least one network interface 401, at least one processor 402 (hereinafter, "processor"), and at least one memory 403 (hereinafter, "memory"). As described above, a NF may be implemented in the form of a physical device such as the UDM 105, or may be virtualized and executed in the form of an instance. When implemented as an instance, the NF need not necessarily include physical components as illustrated in FIG. 4. In such a case, the instance may be logically represented as comprising one or more logical functional elements.

[0102] According to at least one or a combination of methods corresponding to the embodiments described in the present disclosure, the network interface 401, the processor 402, and the memory 403 of the UDM 105 may operate. However, components of the UDM 105 are not limited to the example components illustrated in FIG. 4. In another embodiment, the UDM 105 may further include additional components in addition to the above-mentioned components, or some components may be omitted. Further, in an embodiment, the network interface 401, the processor 402, or the memory 403 may be integrated in the form of one component.

[0103] The network interface 401 is a collective term for a transmitter part of the UDM 105 and a receiver part of the UDM 105, and may be a communication circuit for transmitting or receiving a signal to or from a terminal, a base station (BS), or another network entity. Here, the communication circuit may include both a communication circuit for wireless communication and a communication circuit for a wired communication. For example, the network interface 401 may include a circuit, logic, hardware, etc., configured to exchange a control plane message or a user plane message with a terminal, a BS, or other core network entities through wireless communication or wired communication. The network interface 401 may operate using various protocols (e.g., non-access stratum (NAS) protocol). The network interface 401 may also be referred to, for convenience of description or depending on implementation, as communication circuitry, network interface circuitry, or a communication interface circuitry.

[0104] The processor 402 may control general operations of the UDM 105 according to embodiments of the disclosure. The processor 402 may be implemented by one or more integrated circuit (or circuitry) (IC) chips and may execute various data processing. The processor 402 may include at least one electric circuit, and may execute instructions (or a program, codes, data, etc.) stored in the memory 403, individually, collectively or in any combination thereof. Further, the processor 402 may include a single-core processor or multi-core processor, and may include a processor assembly including a plurality of processing circuits (circuitry) according to a specific implementation scheme. Further, it should be noted that, according to another embodiment, in a case where NF is implemented in the form of an instance, the network function may be not necessarily configured by physical hardware.

[0105] According to an embodiment, the processor 402 may be electrically, operatively, and / or communicatively coupled to the network interface 401 to control the network interface 401.

[0106] The processor 402 may include at least one processor (or processing circuitry), and the at least one processor may perform the following operations individually, collectively or in any combination thereof. In a specific embodiment, at least a part of the processor 402 may be included in one chip / IC and the other part of the processor 402 may be included in another chip. Otherwise, at least one processor may be included in another component, for example, the network interface 401 or the memory 403.

[0107] The processor 402 may perform or control or cause an operation of the UDM 105 for executing at least one or a combination of methods according to embodiments of the disclosure. For example, the processor 402 may control operations of the UDM 105 for exchanging a control plane message or a user plane message with a terminal, a BS, or other core network entities through wireless or wired communication, using various protocols (e.g., NAS protocol). To this end, the processor 402 may execute a computer program, codes, or instructions stored in the memory 403, so as to control other components of the UDM 105 to enable execution of various operations.

[0108] The memory 403 corresponds to a hardware storage device capable of temporarily or permanently storing information and may include one or more storage media. For example, the memory 403 may include a memory assembly including one or more storage media. For example, the one or more storage media may include permanent memory, such as a hard drive, flash memory, or read-only memory (ROM), semipermanent memory, such as random access memory (RAM), cache memory, or a combination thereof.

[0109] The memory 403 may be electrically, operatively, and / or communicatively coupled to the processor 402 and may be accessed by the processor 402.

[0110] The memory 403 may store a computer program, codes, or instructions executable by the processor 402. According to an embodiment, a computer program, codes, or instructions executable by the processor 402 may be either stored in a single memory device or separated and stored in a distributed manner in two or more memory devices. By executing the instructions stored in the memory 403, the processor 402 may perform various functions according to an embodiment of the disclosure.

[0111] According to an embodiment of the disclosure, operations of the UDM 105 may be caused to be performed based on execution of instructions (or a computer program or codes) stored in the memory 403 by at least one processor (or processing circuitry) configured to execute the same individually, collectively, or in any combination thereof, based on processing circuitry that is not configured to execute instructions, and / or based on components of processing circuitry that is not configured to execute instructions.

[0112] The UDM 105 can be configured with a first list of at least one allowed VLAN tag and a first VLAN handling information per user subscription. The processor 402 can receive a request for Session Management (SM) information from the SMF 102, via the network interface 401. The processor 402 can provide the first list of the at least one allowed VLAN tag and the first VLAN handling information for the UE 101 to the SMF 102 in the SM information, via the network interface 401.

[0113] FIG. 5 is a flowchart depicting the process of the UDM providing the allowed VLAN tag and VLAN handling information. Consider that the UDM 105 is configured with the first list of at least one allowed VLAN tag and the first VLAN handling information per user subscription. In step 501, the UDM 105 receives a request for SM information from the SMF 102. In step 502, the UDM 105 provides the first list of the at least one allowed VLAN tag and the first VLAN handling information to the SMF 102 (which can be included in the SM information). The various actions in method 500 may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIG. 5 may be omitted.

[0114] FIG. 6 is a block diagram of the DN-AAA server. The DN-AAA server 104 may include an entity (apparatus, device, or server, etc.) that performs one or more network functions (NFs) or a part of a network function constituting a core network (e.g., a 5th generation (5G) core (5GC)) in a communication system. In this case, multiple NFs may be implemented within a single network entity, or a single NF may be distributed and implemented across a plurality of network entities. In addition, when an NF is implemented within the network entity, the NF may be implemented in the form of software, and in such a case, a program for operating the NF may be stored in memory of the DN-AAA server 104.

[0115] A single NF may be implemented by one or more instances, which may be deployed on the same network entity or distributed across multiple network entities to operate. The instance may be a software unit that logically executes a specific network function, and may be implemented in a form that is decoupled from physical hardware resources. Further, one or more NFs may be implemented in the form of one network slice to operate to satisfy specifications required by a particular service.

[0116] The NF may include at least one of an access and mobility management function (AMF), a session management function (SMF), a local session management function (L-SMF), a user plane function (UPF), a local user plane function (L-UPF), a policy control function (PCF), a unified data management (UDM), a unified data repository (UDR), a network exposure function (NEF), a network repository function (NRF), an application function (AF), a network slice selection function (NSSF), a network data analytics function (NWDAF), a network slice admission control function (NSACF), an authentication server function (AUSF), a data network (DN), etc..

[0117] Referring to FIG. 6, the DN-AAA server 104 may include at least one network interface 601, at least one processor 602 (hereinafter, "processor"), and at least one memory 603 (hereinafter, "memory"). As described above, a NF may be implemented in the form of a physical device such as the DN-AAA server 104, or may be virtualized and executed in the form of an instance. When implemented as an instance, the NF need not necessarily include physical components as illustrated in FIG. 6. In such a case, the instance may be logically represented as comprising one or more logical functional elements.

[0118] According to at least one or a combination of methods corresponding to the embodiments described in the present disclosure, the network interface 601, the processor 602, and the memory 603 of the DN-AAA server 104 may operate. However, components of the DN-AAA server 104 are not limited to the example components illustrated in FIG. 6. In another embodiment, the DN-AAA server 104 may further include additional components in addition to the above-mentioned components, or some components may be omitted. Further, in an embodiment, the network interface 601, the processor 602, or the memory 603 may be integrated in the form of one component.

[0119] The network interface 601 is a collective term for a transmitter part of the DN-AAA server 104 and a receiver part of the DN-AAA server 104, and may be a communication circuit for transmitting or receiving a signal to or from a terminal, a base station (BS), or another network entity. Here, the communication circuit may include both a communication circuit for wireless communication and a communication circuit for a wired communication. For example, the network interface 601 may include a circuit, logic, hardware, etc., configured to exchange a control plane message or a user plane message with a terminal, a BS, or other core network entities through wireless communication or wired communication. The network interface 601 may operate using various protocols (e.g., non-access stratum (NAS) protocol). The network interface 601 may also be referred to, for convenience of description or depending on implementation, as communication circuitry, network interface circuitry, or a communication interface circuitry.

[0120] The processor 602 may control general operations of the DN-AAA server 104 according to embodiments of the disclosure. The processor 602 may be implemented by one or more integrated circuit (or circuitry) (IC) chips and may execute various data processing. The processor 602 may include at least one electric circuit, and may execute instructions (or a program, codes, data, etc.) stored in the memory 603, individually, collectively or in any combination thereof. Further, the processor 602 may include a single-core processor or multi-core processor, and may include a processor assembly including a plurality of processing circuits (circuitry) according to a specific implementation scheme. Further, it should be noted that, according to another embodiment, in a case where NF is implemented in the form of an instance, the network function may be not necessarily configured by physical hardware.

[0121] According to an embodiment, the processor 602 may be electrically, operatively, and / or communicatively coupled to the network interface 601 to control the network interface 601.

[0122] The processor 602 may include at least one processor (or processing circuitry), and the at least one processor may perform the following operations individually, collectively or in any combination thereof. In a specific embodiment, at least a part of the processor 602 may be included in one chip / IC and the other part of the processor 602 may be included in another chip. Otherwise, at least one processor may be included in another component, for example, the network interface 601 or the memory 603.

[0123] The processor 602 may perform or control or cause an operation of the DN-AAA server 104 for executing at least one or a combination of methods according to embodiments of the disclosure. For example, the processor 602 may control operations of the DN-AAA server 104 for exchanging a control plane message or a user plane message with a terminal, a BS, or other core network entities through wireless or wired communication, using various protocols (e.g., NAS protocol). To this end, the processor 602 may execute a computer program, codes, or instructions stored in the memory 603, so as to control other components of the DN-AAA server 104 to enable execution of various operations.

[0124] The memory 603 corresponds to a hardware storage device capable of temporarily or permanently storing information and may include one or more storage media. For example, the memory 603 may include a memory assembly including one or more storage media. For example, the one or more storage media may include permanent memory, such as a hard drive, flash memory, or read-only memory (ROM), semipermanent memory, such as random access memory (RAM), cache memory, or a combination thereof.

[0125] The memory 603 may be electrically, operatively, and / or communicatively coupled to the processor 602 and may be accessed by the processor 602.

[0126] The memory 603 may store a computer program, codes, or instructions executable by the processor 602. According to an embodiment, a computer program, codes, or instructions executable by the processor 602 may be either stored in a single memory device or separated and stored in a distributed manner in two or more memory devices. By executing the instructions stored in the memory 603, the processor 602 may perform various functions according to an embodiment of the disclosure.

[0127] According to an embodiment of the disclosure, operations of the DN-AAA server 104 may be caused to be performed based on execution of instructions (or a computer program or codes) stored in the memory 603 by at least one processor (or processing circuitry) configured to execute the same individually, collectively, or in any combination thereof, based on processing circuitry that is not configured to execute instructions, and / or based on components of processing circuitry that is not configured to execute instructions

[0128] Consider that secondary authentication and authorization is enabled. The DN-AAA server 104 can be configured with a second list of at least one allowed VLAN tag and a second VLAN handling information per user subscription. Consider that the secondary authentication and authorization is successful. The processor 602 can then provide the DN authorized data to the SMF 102. The DN authorized data can include the second list of the at least one allowed VLAN tag and the second VLAN handling information for the UE 101.

[0129] FIG. 7 is a flowchart depicting the process of the DN-AAA server providing the allowed VLAN tag and VLAN handling information. Consider that secondary authentication and authorization is enabled. Consider that the DN-AAA server 104 is configured with the second list of at least one allowed VLAN tag and the second VLAN handling information per user subscription. In step 701, the secondary authentication and authorization has been completed successfully. In step 702, the DN-AAA server 104 provides the DN authorized data to the SMF 102, wherein rhe DN authorized data includes the second list of the at least one allowed VLAN tag and the second VLAN handling information. The various actions in method 700 may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIG. 7 may be omitted.

[0130] FIG. 8 is a block diagram of a SMF 102. The SMF 102 may include an entity (apparatus, device, or server, etc.) that performs one or more network functions (NFs) or a part of a network function constituting a core network (e.g., a 5th generation (5G) core (5GC)) in a communication system. In this case, multiple NFs may be implemented within a single network entity, or a single NF may be distributed and implemented across a plurality of network entities. In addition, when an NF is implemented within the network entity, the NF may be implemented in the form of software, and in such a case, a program for operating the NF may be stored in memory of the SMF 102.

[0131] A single NF may be implemented by one or more instances, which may be deployed on the same network entity or distributed across multiple network entities to operate. The instance may be a software unit that logically executes a specific network function, and may be implemented in a form that is decoupled from physical hardware resources. Further, one or more NFs may be implemented in the form of one network slice to operate to satisfy specifications required by a particular service.

[0132] The NF may include at least one of an access and mobility management function (AMF), a session management function (SMF), a local session management function (L-SMF), a user plane function (UPF), a local user plane function (L-UPF), a policy control function (PCF), a unified data management (UDM), a unified data repository (UDR), a network exposure function (NEF), a network repository function (NRF), an application function (AF), a network slice selection function (NSSF), a network data analytics function (NWDAF), a network slice admission control function (NSACF), an authentication server function (AUSF), a data network (DN), etc..

[0133] Referring to FIG. 8, the SMF 102 may include at least one network interface 801, at least one processor 802 (hereinafter, "processor"), and at least one memory 803 (hereinafter, "memory"). As described above, a NF may be implemented in the form of a physical device such as the SMF 102, or may be virtualized and executed in the form of an instance. When implemented as an instance, the NF need not necessarily include physical components as illustrated in FIG. 8. In such a case, the instance may be logically represented as comprising one or more logical functional elements.

[0134] According to at least one or a combination of methods corresponding to the embodiments described in the present disclosure, the network interface 801, the processor 802, and the memory 803 of the SMF 102 may operate. However, components of the SMF 102 are not limited to the example components illustrated in FIG. 8. In another embodiment, the SMF 102 may further include additional components in addition to the above-mentioned components, or some components may be omitted. Further, in an embodiment, the network interface 801, the processor 802, or the memory 803 may be integrated in the form of one component.

[0135] The network interface 801 is a collective term for a transmitter part of the SMF 102 and a receiver part of the SMF 102, and may be a communication circuit for transmitting or receiving a signal to or from a terminal, a base station (BS), or another network entity. Here, the communication circuit may include both a communication circuit for wireless communication and a communication circuit for a wired communication. For example, the network interface 801 may include a circuit, logic, hardware, etc., configured to exchange a control plane message or a user plane message with a terminal, a BS, or other core network entities through wireless communication or wired communication. The network interface 801 may operate using various protocols (e.g., non-access stratum (NAS) protocol). The network interface 801 may also be referred to, for convenience of description or depending on implementation, as communication circuitry, network interface circuitry, or a communication interface circuitry.

[0136] The processor 802 may control general operations of the SMF 102 according to embodiments of the disclosure. The processor 802 may be implemented by one or more integrated circuit (or circuitry) (IC) chips and may execute various data processing. The processor 802 may include at least one electric circuit, and may execute instructions (or a program, codes, data, etc.) stored in the memory 803, individually, collectively or in any combination thereof. Further, the processor 802 may include a single-core processor or multi-core processor, and may include a processor assembly including a plurality of processing circuits (circuitry) according to a specific implementation scheme. Further, it should be noted that, according to another embodiment, in a case where NF is implemented in the form of an instance, the network function may be not necessarily configured by physical hardware.

[0137] According to an embodiment, the processor 802 may be electrically, operatively, and / or communicatively coupled to the network interface 801 to control the network interface 801.

[0138] The processor 802 may include at least one processor (or processing circuitry), and the at least one processor may perform the following operations individually, collectively or in any combination thereof. In a specific embodiment, at least a part of the processor 802 may be included in one chip and the other part of the processor 802 may be included in another chip. Otherwise, at least one processor may be included in another component, for example, the network interface 801 or the memory 803.

[0139] The processor 802 may perform or control or cause an operation of the SMF 102 for executing at least one or a combination of methods according to embodiments of the disclosure. For example, the processor 802 may control operations of the SMF 102 for exchanging a control plane message or a user plane message with a terminal, a BS, or other core network entities through wireless or wired communication, using various protocols (e.g., NAS protocol). To this end, the processor 802 may execute a computer program, codes, or instructions stored in the memory 803, so as to control other components of the SMF 102 to enable execution of various operations.

[0140] The memory 803 corresponds to a hardware storage device capable of temporarily or permanently storing information and may include one or more storage media. For example, the memory 803 may include a memory assembly including one or more storage media. For example, the one or more storage media may include permanent memory, such as a hard drive, flash memory, or read-only memory (ROM), semipermanent memory, such as random access memory (RAM), cache memory, or a combination thereof.

[0141] The memory 803 may be electrically, operatively, and / or communicatively coupled to the processor 802 and may be accessed by the processor 802.

[0142] The memory 803 may store a computer program, codes, or instructions executable by the processor 802. According to an embodiment, a computer program, codes, or instructions executable by the processor 802 may be either stored in a single memory device or separated and stored in a distributed manner in two or more memory devices. By executing the instructions stored in the memory 803, the processor 802 may perform various functions according to an embodiment of the disclosure.

[0143] According to an embodiment of the disclosure, operations of the SMF 102 may be caused to be performed based on execution of instructions (or a computer program or codes) stored in the memory 803 by at least one processor (or processing circuitry) configured to execute the same individually, collectively, or in any combination thereof, based on processing circuitry that is not configured to execute instructions, and / or based on components of processing circuitry that is not configured to execute instructions.

[0144] The processor 802 can receive the PDU session establishment request from the UE 101, via the network interface 801. In an embodiment herein, the PDU session establishment type can be Ethernet. On receiving the PDU session establishment from the UE 101, the processor 802 can retrieve the first list of at least one allowed VLAN tag and the first VLAN handling information from the UDM 105 for a UE via the network interface 801. If secondary authentication and authorization are enabled, the processor 802 can further retrieve the second list of at least one allowed VLAN tag and the second VLAN handling information from the DN-AAA server 104 via the network interface 801. Consider that secondary authentication and authorization are enabled. The processor 802 can give precedence to the second list of at least one allowed VLAN tag and the second VLAN handling information over the first list of at least one allowed VLAN tag and the first VLAN handling information, and a third configuration (i..e, an allowed list of VLAN tag and VLAN handling information configured locally at the SMF); i.e., the processor 802 can select the second list of at least one allowed VLAN tag and the second VLAN handling information. If secondary authentication and authorization is not enabled, the processor 802 can give precedence to the first list of at least one allowed VLAN tag and the first VLAN handling information over the third configuration; i.e., the processor 802 can select the first list of at least one allowed VLAN tag and the first VLAN handling information. The processor 802 can send the selected list of at least one allowed VLAN tag and the selected VLAN handling information to the UPF 103.

[0145] FIG. 9 is a flowchart depicting the process of handling Ethernet PDU sessions (when secondary authentication and authorization is enabled). Consider that secondary authentication and authorization is enabled. In step 901, the SMF 102 receives the PDU session establishment request from the UE 101, wherein the PDU session establishment type can be Ethernet In step 902, the SMF 102 retrieves the first list of at least one allowed VLAN tag and the first VLAN handling information from the UDM 105 for the UE. In step 903, the SMF 102 retrieves the second list of at least one allowed VLAN tag and the second VLAN handling information from the DN-AAA server 104. In step 904, the SMF 102 selects the second list of at least one allowed VLAN tag and the second VLAN handling information; i.e., the SMF 102 gives precedence to the second list of at least one allowed VLAN tag and the second VLAN handling information over the first list of at least one allowed VLAN tag and the first VLAN handling information, and the third configuration. In step 905, the SMF 102 sends the second list of at least one allowed VLAN tag and the second VLAN handling information to the UPF 103. The various actions in method 900 may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIG. 9 may be omitted.

[0146] FIG. 10 is a flowchart depicting the process of handling Ethernet PDU sessions (when secondary authentication and authorization is not enabled). Consider that secondary authentication and authorization is not enabled. In step 1001, the SMF 102 receives the PDU session establishment request from the UE 101, wherein the PDU session establishment type can be Ethernet. In step 1002, the SMF 102 retrieves the first list of at least one allowed VLAN tag and the first VLAN handling information from the UDM 105 for the UE. In step 1003, the SMF 102 selects the first list of at least one allowed VLAN tag and the first VLAN handling information; i.e., the SMF 102 gives precedence to the first list of at least one allowed VLAN tag and the first VLAN handling information over the third configuration. In step 1004, the SMF 102 sends the selected first list of at least one allowed VLAN tag and the first VLAN handling information to the UPF 103. The various actions in method 1000 may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIG. 10 may be omitted.

[0147] FIGs. 11A and 11B are flowcharts depicting the process for handling Ethernet Protocol Data Unit (PDU) sessions (when secondary authentication and authorization is enabled). In step 1101, the UDM 105 is configured with a first list of at least one allowed VLAN tag and the first VLAN handling information per user subscription. In step 1102, the DN-AAA server 104 is configured with the second list of at least one allowed VLAN tag and the second VLAN handling information per user subscription. In step 1103, the SMF 102 receives the PDU session establishment request from UE 101, wherein the PDU session establishment type is Ethernet. In step 1104, the SMF 102 retrieves the configured first list of at least one allowed VLAN tag and the first VLAN handling information for the UE 101 from the UDM 105. Consider that secondary authentication and authorization is enabled. In step 1105, the SMF 102 retrieves the configured second list of at least one allowed VLAN tag and a second VLAN handling information for the UE 101 from the DN-AAA server 104. In step 1106, the SMF 102 selects the second list of at least one allowed VLAN tag and the second VLAN handling information over the first list of at least one allowed VLAN tag and the first VLAN handling information, and the third configuration. In step 1107, the SMF 102 sends the selected list of at least one allowed VLAN tag and the selected VLAN handling information to the UPF 103. In step 1108, the UE 101 transmits user plane traffic to the DN, via the UPF 103, using a VLAN. On receiving the user plane traffic from the UE 101, in step 1109, the UPF 103 checks if the VLAN being used by the UE 101 for transmitting the user plane traffic is in the selected list of at least one allowed VLAN tag and the selected VLAN handling information. If the VLAN being used by the UE 101 for transmitting the user plane traffic is in the selected list of at least one allowed VLAN tag and the selected VLAN handling information, in step 1110, the UPF 103 forwards the user plane traffic received from the UE 101 to the DN. If the VLAN being used by the UE 101 for transmitting the user plane traffic is not in the selected list of at least one allowed VLAN tag and the selected VLAN handling information, in step 1111, the UPF 103 drops the user plane traffic received from the UE 101 (i.e., the UPF 103 does not forward the user plane traffic to the DN). The various actions in method 1100 may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIGs. 11A and 11B may be omitted.

[0148] FIGs. 12A and 12B are flowcharts depicting the process for handling Ethernet Protocol Data Unit (PDU) sessions (when secondary authentication and authorization is not enabled). Consider that secondary authentication and authorization is not enabled. In step 1201, the UDM 105 is configured with a first list of at least one allowed VLAN tag and the first VLAN handling information per user subscription. In step 1202, the DN-AAA server 104 is configured with the second list of at least one allowed VLAN tag and the second VLAN handling information per user subscription. In step 1203, the SMF 102 receives the PDU session establishment request from UE 101, wherein the PDU session establishment type is Ethernet. In step 1204, the SMF 102 retrieves the configured first list of at least one allowed VLAN tag and the first VLAN handling information for the UE 101 from the UDM 105. In step 1205, the SMF 102 selects the first list of at least one allowed VLAN tag and the first VLAN handling information over the third configuration. In step 1206, the SMF 102 sends the selected list of at least one allowed VLAN tag and the selected VLAN handling information to the UPF 103. In step 1207, the UE 101 transmits user plane traffic to the DN, via the UPF 103, using a VLAN. On receiving the user plane traffic from the UE 101, in step 1208, the UPF 103 checks if the VLAN being used by the UE 101 for transmitting the user plane traffic is in the selected list of at least one allowed VLAN tag and the selected VLAN handling information. If the VLAN being used by the UE 101 for transmitting the user plane traffic is in the selected list of at least one allowed VLAN tag and the selected VLAN handling information, in step 1209, the UPF 103 forwards the user plane traffic received from the UE to the DN. If the VLAN being used by the UE 101 for transmitting the user plane traffic is not in the selected list of at least one allowed VLAN tag and the selected VLAN handling information, in step 1210, the UPF 103 drops the user plane traffic received from the UE to the DN (i.e., the UPF 103 does not forward the user plane traffic to the DN). The various actions in method 1200 may be performed in the order presented, in a different order or simultaneously. Further, in some embodiments, some actions listed in FIGs. 12A and 12B may be omitted.

[0149] The embodiments disclosed herein can be implemented through at least one software program running on at least one hardware device and performing network management functions to control the network elements. The elements include blocks which can be at least one of a hardware device, or a combination of hardware device and software module.

[0150] Meanwhile, although specific embodiments of the present disclosure have been described in detail, various modifications may be made without departing from the scope of the present disclosure. Therefore, the scope of the present disclosure should not be limited to the described embodiments, but should be defined by the claims and equivalents thereof.

[0151] The embodiments disclosed herein describe systems and methods for handling Ethernet Protocol Data Unit (PDU) sessions, specifically how the Virtual Local Area Network (VLAN) tags per subscriber can be controlled in Fifth Generation (5G) Core (5GC).. Therefore, it is understood that the scope of the protection is extended to such a program and in addition to a computer readable means having a message therein, such computer readable storage means contain program code means for implementation of one or more steps of the method, when the program runs on a server or mobile deviceor any suitable programmable device. The method is implemented in at least one embodiment through or together with a software program written in e.g., Very high speed integrated circuit Hardware Description Language (VHDL) another programming language, or implemented by one or more VHDL or several software modules being executed on at least one hardware device. The hardware device can be any kind of portable device that can be programmed. The device may also include means which could be e.g., hardware means like e.g., an ASIC, or a combination of hardware and software means, e.g., an ASIC and an FPGA, or at least one microprocessor and at least one memory with software modules located therein. The method embodiments described herein could be implemented partly in hardware and partly in software. Alternatively, the invention may be implemented on different hardware devices, e.g., using a plurality of CPUs.

[0152] According to various embodiments, a method for handling Ethernet Protocol Data Unit (PDU) sessions is provided., the method comprises configuring a Unified Data Management (UDM) with a first list of at least one allowed Virtual Local Area Network (VLAN) tag and VLAN handling information per user subscription; configuring a Data Network - Authentication, Authorization, and Accounting (DN-AAA) server with a second list of at least one allowed VLAN tag and VLAN handling information per user subscription; receiving, by a Session Management Function (SMF), a PDU session establishment request from a User Equipment (UE), wherein a PDU session establishment type is Ethernet; retrieving, by the SMF, the configured first list of at least one allowed Virtual Local Area Network (VLAN) tag and VLAN handling information for the UE from the UDM; retrieving, by the SMF, the configured second list of at least one allowed VLAN tag and a second VLAN handling information for the UE from the DN-AAA server; and selecting, by the SMF, the second list of at least one allowed VLAN tag and the second VLAN handling information over the first list of at least one allowed VLAN tag and the first VLAN handling information and a third allowed list of VLAN tag and a third VLAN handling information configured locally at the SMF.

[0153] For example, the method comprises retrieving, by the SMF, the second list of at least one allowed VLAN tag and the second VLAN handling information from the DN-AAA server, if secondary authentication and authorization is enabled.

[0154] For example, the method comprises sending, by the SMF, the selected list of at least one allowed VLAN tag and the selected VLAN handling information to a User Plane Function (UPF).

[0155] For example, the method comprises forwarding, by the UPF, user plane traffic received from the UE to a DN, if a VLAN used by the UE for sending the user plane traffic is in the selected list of at least one allowed VLAN tag and the selected VLAN handling information; and dropping, by the UPF, user plane traffic received from the UE, if a VLAN used by the UE for sending the user plane traffic is not in the selected list of at least one allowed VLAN tag and the selected VLAN handling information.

[0156] For example, a network is provided. The network comprises a Unified Data Management (UDM), wherein the UDM is configured with a first list of at least one allowed Virtual Local Area Network (VLAN) tag and VLAN handling information per user subscription; a Data Network - Authentication, Authorization, and Accounting (DN-AAA) server, wherein the DN-AAA server is configured with a second list of at least one allowed VLAN tag and VLAN handling information per user subscription; a User Plane Function (UPF); and a Session Management Function (SMF). The SMF comprises a processor; a network interface; and a memory. The processor is coupled with the network interface and the memory, and the processor is configured to receive a Protocol Data Unit (PDU) session establishment request from a User Equipment (UE), wherein a PDU session establishment type is Ethernet; retrieve the configured first list of at least one allowed Virtual Local Area Network (VLAN) tag and VLAN handling information for the UE from the UDM; retrieve the configured second list of at least one allowed VLAN tag and a second VLAN handling information for the UE from the DN-AAA server; and select the second list of at least one allowed VLAN tag and the second VLAN handling information over the first list of at least one allowed VLAN tag and the first VLAN handling information and a third allowed list of VLAN tag and a third VLAN handling information configured locally at the SMF.

[0157] For example, the processor is further configured to retrieve the second list of at least one allowed VLAN tag and the second VLAN handling information from the DN-AAA server, if secondary authentication and authorization is enabled.

[0158] For example, the processor is further configured to send the selected list of at least one allowed VLAN tag and the selected VLAN handling information to the UPF.

[0159] For example, the UPF is further configured to forward user plane traffic received from the UE to a DN, if a VLAN used by the UE for sending the user plane traffic is in the selected list of at least one allowed VLAN tag and the selected VLAN handling information; and drop user plane traffic received from the UE, if a VLAN used by the UE for sending the user plane traffic is not in the selected list of at least one allowed VLAN tag and the selected VLAN handling information.

[0160] According to embodiments, a method performed by a session management function (SMF) is provided. The method comprises receiving, from an unified data management (UDM), subscription data including a first list of one or more allowed virtual local area network (VLAN) tags for a packet data unit (PDU) session associated with an ethernet PDU session type; receiving, from a data network authentication, authorization, and accounting (DN-AAA) server; a second list of one or more allowed VLAN tags for the PDU session; and based on the second list of the one or more allowed VLAN tags received from the DN-AAA server being taking precedence over the first list of the one or more allowed VLAN tags received from the UDM, transmitting, to a user plane function (UPF), instructions to accept or discard user equipment (UE) traffic and to handle one or more VLAN tags.

[0161] For example, the one or more allowed VLAN tags included in the first list received from the UDM and the one or more allowed VLAN tags included in the second list received from the DN-AAA server take precedence over local configuration of the SMF.

[0162] For example, the subscription data is needed for PDU session establishment.

[0163] For example, the subscription data includes VLAN handling information. VLAN handing information received from the DN-AAA server takes precedence over the VLAN handling information in the subscription data received from the UDM.

[0164] For example, the instructions cause the UPF to at least one of insert a S-TAG on N6 or N19 or internal interface for uplink traffic from a UE and remove a S-TAG on N6 or N19 or internal interface for downlink traffic to the UE; insert a VLAN tag on N6 interface while there is no VLAN in uplink traffic from the UE and remove a VLAN tag on N6 interface while there is no VLAN in downlink traffic to the UE; or discard any UE traffic does not contain any allowed VLAN tag when the UPF handles uplink traffic from the UE or downlink traffic to the UE.

[0165] For example, the one or more VLAN tags are handled based on an outer header removal and an outer header creation.

[0166] For example, the one or more VLAN tags are handled based on an outer header removal and an outer header creation.

[0167] According to embodiments, a device configured to perform functions of session management function (SMF) is provided. The device comprises at least one processor configured to obtain, from an unified data management (UDM), subscription data including a first list of one or more allowed virtual local area network (VLAN) tags for a packet data unit (PDU) session associated with an ethernet PDU session type; obtain, from a data network authentication, authorization, and accounting (DN-AAA) server; a second list of one or more allowed VLAN tags for the PDU session; and based on the second list of the one or more allowed VLAN tags received from the DN-AAA server being taking precedence over the first list of the one or more allowed VLAN tags received from the UDM, provide, to a user plane function (UPF), instructions to accept or discard user equipment (UE) traffic and to handle one or more VLAN tags.

[0168] For example, the one or more allowed VLAN tags included in the first list received from the UDM and the one or more allowed VLAN tags included in the second list received from the DN-AAA server take precedence over local configuration of the SMF.

[0169] For example, the subscription data is needed for PDU session establishment.

[0170] For example, the subscription data includes VLAN handling information. VLAN handing information received from the DN-AAA server takes precedence over the VLAN handling information in the subscription data received from the UDM.

[0171] For example, the instructions cause the UPF to at least one of insert a S-TAG on N6 or N19 or internal interface for uplink traffic from a UE and remove a S-TAG on N6 or N19 or internal interface for downlink traffic to the UE; insert a VLAN tag on N6 interface while there is no VLAN in uplink traffic from the UE and remove a VLAN tag on N6 interface while there is no VLAN in downlink traffic to the UE; or discard any UE traffic does not contain any allowed VLAN tag when the UPF handles uplink traffic from the UE or downlink traffic to the UE.

[0172] For example, the one or more VLAN tags are handled based on an outer header removal and an outer header creation.

[0173] According to embodiments, a method performed by an unified data management (UDM) is provided. The method comprises generating subscription data including a first list of one or more allowed virtual local area network (VLAN) tags for a packet data unit (PDU) session associated with an ethernet PDU session type; and transmitting, to a session management function (SMF), the subscription data. A second list of one or more allowed VLAN tags from the DN-AAA server to the SMF take precedence over the first list of the one or more allowed VLAN tags from the UDM to the SMF.

[0174] For example, the one or more allowed VLAN tags included in the first list and the one or more allowed VLAN tags included in the second list take precedence over local configuration of the SMF.

[0175] For example, the subscription data is needed for PDU session establishment.

[0176] The foregoing description of the specific embodiments will so fully reveal the general nature of the embodiments herein that others can, by applying current knowledge, readily modify and / or adapt for various applications such specific embodiments without departing from the generic concept, and, therefore, such adaptations and modifications should and are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Therefore, while the embodiments herein have been described in terms of embodiments and examples, those skilled in the art will recognize that the embodiments and examples disclosed herein can be practised with modification within the scope of the embodiments as described herein.

[0177] Any of embodiments described above may be combined with any other embodiment (or a combination of an embodiment) unless otherwise explicitly stated. The above-described description of one or more implementations provides an example and a description, but is not intended to limit or tighten a scope of an embodiment in a precise form disclosed. Modification and deformation may be made in light of the above teachings or may be obtained from an embodiment of various embodiments.

[0178] The electronic device according to various embodiments may be one of various types of electronic devices. The electronic devices may include, for example, a portable communication device (e.g., a smartphone), a computer device, a portable multimedia device, a portable medical device, a camera, a wearable device, a home appliance, or the like. According to an embodiment of the disclosure, the electronic devices are not limited to those described above.

[0179] It should be appreciated that various embodiments of the present disclosure and the terms used therein are not intended to limit the technological features set forth herein to particular embodiments and include various changes, equivalents, or replacements for a corresponding embodiment. With regard to the description of the drawings, similar reference numerals may be used to refer to similar or related elements. It is to be understood that a singular form of a noun corresponding to an item may include one or more of the things unless the relevant context clearly indicates otherwise. As used herein, each of such phrases as "A or B," "at least one of A and B," "at least one of A or B," "A, B, or C," "at least one of A, B, and C," and "at least one of A, B, or C," may include any one of or all possible combinations of the items enumerated together in a corresponding one of the phrases. As used herein, such terms as "1st" and "2nd," or "first" and "second" may be used to simply distinguish a corresponding component from another, and does not limit the components in other aspect (e.g., importance or order). It is to be understood that if an element (e.g., a first element) is referred to, with or without the term "operatively" or "communicatively", as "coupled with," or "connected with" another element (e.g., a second element), the element may be coupled with the other element directly (e.g., wiredly), wirelessly, or via a third element.

[0180] As used in connection with various embodiments of the disclosure, the term "module" may include a unit implemented in hardware, software, or firmware, or any combination thereof, and may interchangeably be used with other terms, for example, "logic," "logic block," "part," or "circuitry". A module may be a single integral component, or a minimum unit or part thereof, adapted to perform one or more functions. For example, according to an embodiment, the module may be implemented in a form of an application-specific integrated circuit (ASIC).

[0181] Various embodiments as set forth herein may be implemented as software including one or more instructions that are stored in a storage medium (e.g., memory 803) that is readable by a machine. For example, a processor (e.g., the processor 802) of the machine may invoke at least one of the one or more instructions stored in the storage medium, and execute it, with or without using one or more other components under the control of the processor. This allows the machine to be operated to perform at least one function according to the at least one instruction invoked. The one or more instructions may include a code generated by a compiler or a code executable by an interpreter. The machine-readable storage medium may be provided in the form of a non-transitory storage medium. Wherein, the "non-transitory" storage medium is a tangible device, and may not include a signal (e.g., an electromagnetic wave), but this term does not differentiate between a case in which data is semi-permanently stored in the storage medium and a case in which the data is temporarily stored in the storage medium.

[0182] According to an embodiment, a method according to various embodiments of the disclosure may be included and provided in a computer program product. The computer program product may be traded as a product between a seller and a buyer. The computer program product may be distributed in the form of a machine-readable storage medium (e.g., compact disc read only memory (CD-ROM)), or be distributed (e.g., downloaded or uploaded) online via an application store (e.g., PlayStore™), or between two user devices (e.g., smart phones) directly. If distributed online, at least part of the computer program product may be temporarily generated or at least temporarily stored in the machine-readable storage medium, such as memory of the manufacturer's server, a server of the application store, or a relay server.

[0183] According to various embodiments, each component (e.g., a module or a program) of the above-described components may include a single entity or multiple entities, and some of the multiple entities may be separately disposed in different components. According to various embodiments, one or more of the above-described components may be omitted, or one or more other components may be added. Alternatively or additionally, a plurality of components (e.g., modules or programs) may be integrated into a single component. In such a case, according to various embodiments, the integrated component may still perform one or more functions of each of the plurality of components in the same or similar manner as they are performed by a corresponding one of the plurality of components before the integration. According to various embodiments, operations performed by the module, the program, or another component may be carried out sequentially, in parallel, repeatedly, or heuristically, or one or more of the operations may be executed in a different order or omitted, or one or more other operations may be added.

[0184] While the disclosure has been illustrated and described with reference to various example embodiments, it will be understood that the various example embodiments are intended to be illustrative, not limiting. It will be further understood by those skilled in the art that various modifications, alternatives and / or variations of the various example embodiments may be made without departing from the true technical spirit and full technical scope of the disclosure, including the appended claims and their equivalents. It will also be understood that any of the embodiment(s) described herein may be used in conjunction with any other embodiment(s) described herein.

Claims

1.A method performed by a session management function (SMF), the method comprising:receiving, from an unified data management (UDM), subscription data including a first list of one or more allowed virtual local area network (VLAN) tags for a packet data unit (PDU) session associated with an ethernet PDU session type;receiving, from a data network authentication, authorization, and accounting (DN-AAA) server; a second list of one or more allowed VLAN tags for the PDU session; andbased on the second list of the one or more allowed VLAN tags received from the DN-AAA server being taking precedence over the first list of the one or more allowed VLAN tags received from the UDM, transmitting, to a user plane function (UPF), instructions to accept or discard user equipment (UE) traffic and to handle one or more VLAN tags.2.The method of claim 1,wherein the one or more allowed VLAN tags included in the first list received from the UDM and the one or more allowed VLAN tags included in the second list received from the DN-AAA server take precedence over local configuration of the SMF.3.The method of claim 1, wherein the subscription data is needed for PDU session establishment.4.The method of claim 1,wherein the subscription data includes VLAN handling information, andwherein VLAN handing information received from the DN-AAA server takes precedence over the VLAN handling information in the subscription data received from the UDM.5.The method of claim 1, wherein the instructions cause the UPF to at least one of:insert a S-TAG on N6 or N19 or internal interface for uplink traffic from a UE and remove a S-TAG on N6 or N19 or internal interface for downlink traffic to the UE;insert a VLAN tag on N6 interface while there is no VLAN in uplink traffic from the UE and remove a VLAN tag on N6 interface while there is no VLAN in downlink traffic to the UE; ordiscard any UE traffic does not contain any allowed VLAN tag when the UPF handles uplink traffic from the UE or downlink traffic to the UE.6.The method of claim 1, wherein the one or more VLAN tags are handled based on an outer header removal and an outer header creation.7.A device configured to perform functions of session management function (SMF), the device comprising:at least one processor configured to:obtain, from an unified data management (UDM), subscription data including a first list of one or more allowed virtual local area network (VLAN) tags for a packet data unit (PDU) session associated with an ethernet PDU session type;obtain, from a data network authentication, authorization, and accounting (DN-AAA) server; a second list of one or more allowed VLAN tags for the PDU session; andbased on the second list of the one or more allowed VLAN tags received from the DN-AAA server being taking precedence over the first list of the one or more allowed VLAN tags received from the UDM, provide, to a user plane function (UPF), instructions to accept or discard user equipment (UE) traffic and to handle one or more VLAN tags.8.The device of claim 7,wherein the one or more allowed VLAN tags included in the first list received from the UDM and the one or more allowed VLAN tags included in the second list received from the DN-AAA server take precedence over local configuration of the SMF.9.The device of claim 7, wherein the subscription data is needed for PDU session establishment.10.The device of claim 7,wherein the subscription data includes VLAN handling information, andwherein VLAN handing information received from the DN-AAA server takes precedence over the VLAN handling information in the subscription data received from the UDM.11.The device of claim 7,wherein the instructions cause the UPF to at least one of:insert a S-TAG on N6 or N19 or internal interface for uplink traffic from a UE and remove a S-TAG on N6 or N19 or internal interface for downlink traffic to the UE;insert a VLAN tag on N6 interface while there is no VLAN in uplink traffic from the UE and remove a VLAN tag on N6 interface while there is no VLAN in downlink traffic to the UE; ordiscard any UE traffic does not contain any allowed VLAN tag when the UPF handles uplink traffic from the UE or downlink traffic to the UE.12.The device of claim 7, wherein the one or more VLAN tags are handled based on an outer header removal and an outer header creation.13.A method performed by an unified data management (UDM), the method comprising:generating subscription data including a first list of one or more allowed virtual local area network (VLAN) tags for a packet data unit (PDU) session associated with an ethernet PDU session type; andtransmitting, to a session management function (SMF), the subscription data,wherein a second list of one or more allowed VLAN tags from the DN-AAA server to the SMF take precedence over the first list of the one or more allowed VLAN tags from the UDM to the SMF.14.The method of claim 13, wherein the one or more allowed VLAN tags included in the first list and the one or more allowed VLAN tags included in the second list take precedence over local configuration of the SMF.15.The method of claim 13, wherein the subscription data is needed for PDU session establishment.

Citation Information

Patent Citations

  • Data transmission method and network device

    CN111628957A

  • PROVISIONING OF VLAN IDs IN 5G SYSTEMS

    US20210345113A1

  • Methods and Apparatus Supporting Dynamic Ethernet VLAN Configuration in a Fifth Generation System

    US20240235891A1