System and method for segregating network traffic
By using separate VLAN IDs for MDU and HGW traffic, the system addresses the challenge of traffic differentiation in telecommunication networks, ensuring efficient routing and improved service quality through differentiated QoS policies.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- JIO PLATFORMS LTD
- Filing Date
- 2025-11-24
- Publication Date
- 2026-06-04
AI Technical Summary
Existing telecommunication networks fail to effectively segregate traffic originating from Multiple Dwelling Units (MDUs) and Home Gateways (HGWs), leading to inefficient routing, increased latency, and compromised service quality due to the inability of User Plane Functions (UPF) to differentiate between these devices.
Implementing separate Virtual Local Area Network Identifiers (VLAN IDs) for MDU and HGW traffic in both uplink and downlink directions to enable precise traffic segregation and routing, allowing differentiated Quality of Service (QoS) policies and resource allocation.
Ensures accurate traffic management, optimized resource utilization, and improved service quality by distinguishing MDU and HGW traffic, preventing performance degradation and enhancing network efficiency and scalability.
Smart Images

Figure IN2025051926_04062026_PF_FP_ABST
Abstract
Description
SYSTEM AND METHOD FOR SEGREGATING NETWORK TRAFFICRESERVATION OF RIGHTS
[0001] A portion of the disclosure of this patent document contains material, which is subject to intellectual property rights such as, but are not limited to, copyright, design, trademark, Integrated Circuit (IC) layout design, and / or trade dress protection, belonging to Jio Platforms Limited (JPL) or its affiliates (hereinafter referred as owner). The owner has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent files or records, but otherwise reserves all rights whatsoever. All rights to such intellectual property are fully reserved by the owner.TECHNICAL FIELD
[0002] The present disclosure relates generally to the field of communication systems. More particularly, the present disclosure relates to systems and methods for segregating network traffic.DEFINITION
[0003] As used in the present disclosure, the following terms are generally intended to have the meaning as set forth below, except to the extent that the context in which they are used to indicate otherwise.
[0004] The term ‘CPE’, as used herein, refers to a customer premise equipment. The CPE is a networking equipment or device that is installed at a customer’s premises. The CPE includes devices such as routers, modems, antennas, or other equipment deployed either indoors or outdoors of the customer premises to facilitate connectivity or telecommunications services for customers.
[0005] The term ‘Home Gateway (HGW)’, as used herein, refers to a device that serves as an interface between a local area network (LAN) within a home or small office and the internet. The HGW plays a crucial role in providing internet access,managing network traffic, ensuring security, and enabling connectivity for various devices within a household or small office environment. It serves as a central hub for network communication and control within the premises.
[0006] The term ‘DHCP server’, as used herein, refers to a server that provides Dynamic Host Configuration Protocol (DHCP) services. The DHCP server dynamically assigns IP addresses and other network configuration parameters (e.g., default gateway, subnet mask, and DNS servers) to devices within a network, enabling them to communicate on the network without requiring manual configuration.
[0007] The term ‘VLAN’, as used herein, refers to Virtual Local Area Network. The VLAN is a logical subgroup within a physical network that partitions and isolates traffic for specific devices or services. VLANs allow administrators to segregate network traffic to improve performance, enhance security, and provide efficient management of network resources.
[0008] The term ‘Uplink data’, as used herein, refers to data transmitted from a user device (e.g., user equipment) to the network. Uplink data represents the flow of information originating from the user's devices to the network, supporting various services such as file uploads, voice calls, video calls, and other data-intensive applications that require upstream communication.
[0009] The term ‘Downlink data’, as used herein, refers to data that is transmitted from the network to a user device (e.g., user equipment). The downlink data represents the flow of information from the network to the user devices, supporting various services and applications essential for modern communication and internet access.
[0010] The term ‘SMF’, as used herein, refers to Session Management Function. The SMF is responsible for managing the session setup, modification, and release procedures for user equipment (UE) accessing the network.
[0011] The term ‘UPF’, as used herein, refers to User Plane Function. The UPF is a network function in a 5G network responsible for handling user-plane packet processing. The UPF performs operations such as packet routing and forwarding, traffic steering, Quality of Service (QoS) enforcement, lawful intercept support, and usage reporting.
[0012] The term ‘BNG’, as used herein, refers to Broadband Network Gateway.The BNG is a crucial network component responsible for managing subscriber sessions, IP address allocation, authentication, and traffic routing in broadband networks. It acts as a central aggregation point for subscriber connections and facilitates communication between the subscriber's premises and the service provider’s network.
[0013] The term “UPF-BNG”, as used herein, refers to an integrated network function that combines the functionalities of the UPF and the BNG into a single platform. The UPF-BNG performs user-plane data processing as defined in 5G networks while simultaneously executing broadband gateway functions, including subscriber session management, IP address allocation (e.g., via DHCP), VLAN-based traffic segregation, and routing of subscriber traffic toward external networks. The UPF-BNG enables unified handling of 5G user-plane traffic and broadband access traffic, eliminating the need for separate UPF and BNG devices and optimizing resource utilization and traffic management in converged networks.
[0014] The term ‘AMF’, as used herein, refers to Access and Mobility Management Function. The AMF is responsible for managing network access and mobility for user equipment (UE).
[0015] The term ‘MDU’, as used herein, refers to Multiple Dwelling Unit. MDUs are buildings, such as apartment complexes, residential towers, or housing blocks that contain multiple living units to facilitate the distribution of networkconnectivity, such as optical fiber, to the end users.
[0016] The term ‘PCF’, as used herein, refers to Policy Control Function. The PCF is responsible for managing and enforcing policy decisions related to network resources, quality of service (QoS), and access control.
[0017] The term ‘GTP tunnel’, as used herein, refers to General packet radio service (GPRS) Tunneling Protocol tunnel. The GTP tunnel is a logical connection established between two endpoints in a mobile network to transmit user data or signaling messages.
[0018] The term ‘N3’, as used herein, refers to an interface that connects the UPF to the gNB in the 5G core network architecture. The N3 interface facilitates the transfer of user plane data packets between the radio access network (RAN) and the core network, supporting data routing, forwarding, and Quality of Service (QoS) enforcement. The N3 interface operates using the GTP tunnel and is a critical for ensuring low latency, high throughput, and efficient delivery of user data in 5G networks.
[0019] The term ‘N4’, as used herein, refers to an interface that connects the SMF and UPF in a network. N4 session management procedures are used to control the functionality of the UPF. The SMF can create, update, and remove the N4 session context in the UPF.
[0020] The term ‘N7’, as used herein, refers to an interface that provides a communication session between the PCF and SMF. The N7 interface enables the PCF to exchange policy information, apply policy decisions based on real-time network conditions and subscriber profiles, and manage QoS parameters for data sessions.
[0021] The term ‘N40’, as used herein, refers to an interface that enables the communication and interaction that occurs between the SMF and the CHF via the N40interface. This session enables the SMF to coordinate with the CHF to set up and manage the quota management and charging, ensuring that data flows efficiently between UEs and external networks or services while maintaining Quality of Service (QoS) requirements.
[0022] The term ‘CHF’, as used herein, refers to a charging function. The CHF is responsible for handling charging and billing functions for subscriber services. The CHF supports service providers in implementing flexible billing models, enforcing charging policies, and maintaining transparency in subscriber billing and usage. The CHF is essential for operators to effectively monetize their services while providing customers with clear and reliable billing information.
[0023] The term ‘EoGRE’, as used herein, refers to Ethernet over Generic Routing Encapsulation. The EoGRE enables customer premises equipment (CPE) devices to bridge the Ethernet traffic from an end host and encapsulate the traffic in Ethernet packets over an IP GRE tunnel. The IP GRE tunnel terminates on a service provider broadband network gateway, which then terminates the end host traffic and manages the subscriber session for the end host.BACKGROUND
[0024] The following description of related art is intended to provide background information pertaining to the field of the disclosure. This section may include certain aspects of the art that may be related to various features of the present disclosure. However, it should be appreciated that this section be used only to enhance the understanding of the reader with respect to the present disclosure, and not as admissions of prior art.
[0025] In modern telecommunication networks, ensuring efficient and accurate traffic management is essential for delivering high-quality services. Devices such as Multiple Dwelling Units (MDUs) and Home Gateways (HGWs) have become essentialdevices for enabling internet access and connectivity for multiple users. An MDU is commonly deployed in multi-unit residential buildings to distribute network access across multiple households. At the same time, an HGW serves as a central hub for internet connectivity within a single household or office. The interconnectivity between these devices and network functions, such as a User Plane Function- Broadband Network Gateway (UPF-BNG), relies on precise traffic segregation to maintain performance and service quality.
[0026] However, existing techniques fail to distinguish traffic originating from the MDU and the HGW. Without proper segregation, network resources are prone to mismanagement, resulting in performance degradation, inefficient data handling, and compromised service delivery to end-users.
[0027] Thus, there is a need for a method and system that can overcome the limitations of current UPF implementations by enabling effective segregation of MDU and HGW traffic.OBJECTIVE OF THE PRESENT DISCLOSURE
[0028] Some of the objectives of the present disclosure, which at least one embodiment herein satisfies, are as follows:
[0029] An objective of the present is to enable a User Plane Function (UPF) or a combined User Plane Function-Broadband Network Gateway (UPF-BNG) to differentiate traffic originating from a Multiple Dwelling Unit (MDU) and a Home Gateway (HGW), thereby facilitating efficient, accurate, and independent traffic management for each type of device.
[0030] Another objective of the present disclosure is to introduce the use of separate Virtual Local Area Network Identifiers (VLAN IDs) for the MDU traffic and the HGW traffic in both uplink (UL) and downlink (DL) directions, ensuring accuratesegregation and routing of traffic.
[0031] Another objective of the present disclosure is to enable implementation of differentiated Quality of Service (QoS) for MDU and HGW traffic, supporting optimized resource allocation and improved service quality across subscriber segments.
[0032] Yet another objective of the present disclosure is to improve network performance by optimizing traffic handling, enabling accurate policy enforcement, and enhancing routing efficiency for UL and DL flows.
[0033] Other objects and advantages of the present disclosure will be more apparent from the following description, which is not intended to limit the scope of the present disclosure.SUMMARY
[0034] In an exemplary embodiment, the present disclosure provides a method for segregating network traffic. The method includes receiving, by a network function, a solicit message from each device of a set of devices over a corresponding Virtual Local Area Network (VLAN) identifier (ID). The set of devices includes one or more Multiple Dwelling Units (MDUs) and one or more Home Gateways (HGWs). The method further includes determining, by the network function, an identity of each device. Upon determining the identity, the method includes transmitting, by the network function, a first advertise message to at least one MDU over a first VLAN ID and a second advertise message to at least one HGW over a second VLAN ID. The first advertise message includes an Internet Protocol (IP) address allocated to the at least one MDU and the second advertise message includes the IP address allocated to the at least one HGW. The method further includes receiving, by the network function, a set of data packets from the at least one MDU and the at least one HGW, and segregating the received data packets based on the respective IP addresses associated with each ofthe devices.
[0035] In an embodiment, the solicit message is received using a Dynamic HostConfiguration Protocol (DHCP), and the solicit message includes a Media Access Control (MAC) address associated with a respective device.
[0036] In an embodiment, determining the identity includes analyzing, by the network function, the MAC address associated with each device of the set of devices, wherein the identity determination indicates that the solicit message received over the first VLAN ID corresponds to the at least one MDU and that the solicit message received over the second VLAN ID corresponds to the at least one HGW.
[0037] In an embodiment, the method further includes routing, by the network function, the segregated set of data packets to one of a server and the Internet.
[0038] In an embodiment, a data packet of the set of data packets received from the at least one MDU is routed to the server over the first VLAN ID.
[0039] In an embodiment, a data packet of the set of data packets received from the at least one HGW is routed to the Internet over the second VLAN ID.
[0040] In an embodiment, the network function comprises at least one of a UserPlane Function (UPF) and a combined User Plane Function and Broadband Network Gateway (UPF-BNG).
[0041] In an embodiment, the network function further includes a Session Management Function (SMF) and a Policy Control Function (PCF). The SMF and the PCF are configured to communicate with the UPF to determine the identity of each device.
[0042] In another exemplary embodiment, a system for segregating network traffic is disclosed. The system includes a network function configured to receive asolicit message from each device of a set of devices over a corresponding Virtual Local Area Network (VLAN) identifier (ID). The set of devices includes one or more Multiple Dwelling Units (MDUs) and one or more Home Gateways (HGWs). The network function is further configured to determine an identity of each device. Upon determining the identity, the network function is further configured to transmit a first advertise message to at least one MDU over a first VLAN ID and a second advertise message to at least one HGW over a second VLAN ID. The first advertise message includes an Internet Protocol (IP) address allocated to the at least one MDU and the second advertise message includes the IP address allocated to the at least one HGW. The network function is further configured to receive a set of data packets from the at least one MDU and the at least one HGW. The network function is further configured to segregate the received data packets based on the respective IP addresses associated with each of the devices.
[0043] In yet another exemplary embodiment, the present disclosure provides a computer program product comprising a non-transitory computer-readable medium having instructions stored thereon, which when executed by one or more processors, cause the one or more processors to execute a method for segregating network traffic. The method includes receiving, by a network function, a solicit message from each device of a set of devices over a corresponding Virtual Local Area Network (VLAN) identifier (ID). The set of devices includes one or more Multiple Dwelling Units (MDUs) and one or more Home Gateways (HGWs). The method further includes determining, by the network function, an identity of each device. Upon determining the identity, the method includes transmitting, by the network function, a first advertise message to at least one MDU over a first VLAN ID and a second advertise message to at least one HGW over a second VLAN ID. The first advertise message includes an Internet Protocol (IP) address allocated to the at least one MDU and the second advertise message includes the IP address allocated to the at least one HGW. The method further includes receiving, by the network function, a set of data packets fromthe at least one MDU and the at least one HGW. The method further includes segregating the received data packets based on the respective IP addresses.BRIEF DESCRIPTION OF THE ACCOMPANYING DRAWING
[0044] The accompanying drawings, which are incorporated herein, and constitute a part of this disclosure, illustrate exemplary embodiments of the disclosed methods and systems in which like reference numerals refer to the same parts throughout the different drawings. Components in the drawings are not necessarily to scale, emphasis instead being placed upon clearly illustrating the principles of the present disclosure. Some drawings may indicate the components using block diagrams and may not represent the internal circuitry of each component. It will be appreciated by those skilled in the art that disclosure of such drawings includes disclosure of electrical components, electronic components or circuitry commonly used to implement such components.
[0045] FIG. 1 illustrates an exemplary network architecture implementing a system for segregating network traffic, in accordance with an embodiment of the present disclosure.
[0046] FIG. 2 illustrates an exemplary block diagram of the system, in accordance with an embodiment of the present disclosure.
[0047] FIG. 3 illustrates an exemplary system architecture configured for segregating network traffic, in accordance with an embodiment of the present disclosure.
[0048] FIG. 4A illustrates an exemplary process flow for segregating network traffic, in accordance with an embodiment of the present disclosure.
[0049] FIG. 4B illustrates another exemplary process flow for segregating network traffic, in accordance with an embodiment of the present disclosure.
[0050] FIG. 5 illustrates an exemplary flow diagram of a method for segregating network traffic, in accordance with an embodiment of the present disclosure
[0051] FIG. 6 illustrates an exemplary block diagram of a computer system in which or with which embodiments of the present disclosure may be implemented.
[0052] The foregoing shall be more apparent from the following more detailed description of the disclosure.List of reference numerals100 - Network Architecture102 - User(s)104 - User Equipment (UE)106 - Network108 - System200 - Block diagram202 - Processor(s)204 - Memory206 -Interface(s)208 - Network function210 - Database300 - System Architecture302, 402a - Home Gateway (HGW)304, 402b - Multiple Dwelling Unit (MDU)306 - Customer Premise Equipment (CPE)308 - Base Station 310, 404a, 404b - User Plane Function (UPF)312, 406a, 406b - Session Management Function (SMF)314 - Access and Mobility Management Function (AMF)316 - Unified Data Management (UDM)318 - Policy Control Function (PCF) 320 - Charging Function-Protocol converter (CHF-PC)322 - Online Charging System (OCS)324 - PCF Broadband Network Gateway (BNG)326 - CHF328, 408b - Internet 400 A, 400B - Process Flow500 - Method Flow Diagram600 - Computer System610 - External Storage Device620 - Bus630 - Main Memory640 - Read Only Memory650 - Mass Storage Device660 - Communication Port670 - ProcessorDETAILED DESCRIPTION
[0053] In the following description, for the purposes of explanation, various specific details are set forth in order to provide a thorough understanding of embodiments of the present disclosure. It will be apparent, however, that embodiments of the present disclosure may be practiced without these specific details. Several features described hereafter can each be used independently of one another or with any combination of other features. An individual feature may not address any of the problems discussed above or might address only some of the problems discussed above. Some of the problems discussed above might not be fully addressed by any of the features described herein. Example embodiments of the present disclosure are described below, as illustrated in various drawings in which like reference numerals refer to the same parts throughout the different drawings.
[0054] The ensuing description provides exemplary embodiments only, and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, the ensuing description of the exemplary embodiments will provide those skilled in the art with an enabling description for implementing an exemplary embodiment. It should be understood that various changes may be made in the function and arrangement of elements without departing from the spirit and scope of the disclosure as set forth.
[0055] Specific details are given in the following description to provide a thorough understanding of the embodiments. However, it will be understood by one of ordinary skill in the art that the embodiments may be practiced without these specific details. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form in order not to obscure the embodiments in unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail in order to avoid obscuring the embodiments.
[0056] Also, it is noted that individual embodiments may be described as a process that is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. Although a flowchart may describe the operations as a sequential process, many of the operations can be performed in parallel or concurrently. In addition, the order of the operations may be re-arranged. A process is terminated when its operations are completed but could have additional steps not included in a figure. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination can correspond to a return of the function to the calling function or the main function.
[0057] The word “exemplary” and / or “demonstrative” is used herein to mean serving as an example, instance, or illustration. For the avoidance of doubt, the subject matter disclosed herein is not limited by such examples. In addition, any aspect or design described herein as “exemplary” and / or “demonstrative” is not necessarily to be construed as preferred or advantageous over other aspects or designs, nor is it meant to preclude equivalent exemplary structures and techniques known to those of ordinary skill in the art. Furthermore, to the extent that the terms “includes,” “has,” “contains,” and other similar words are used in either the detailed description or the claims, such terms are intended to be inclusive like the term “comprising” as an open transition word without precluding any additional or other elements.
[0058] Reference throughout this specification to “one embodiment” or “an embodiment” or “an instance” or “one instance” means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present disclosure. Thus, the appearances of the phrases “in one embodiment” or “in an embodiment” in various places throughout this specification are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0059] The terminology used herein is to describe particular embodiments only and is not intended to be limiting the disclosure. As used herein, the singular forms “a”, “an”, and “the” are intended to include the plural forms as well, unless the context indicates otherwise. It will be further understood that the terms “comprises” and / or “comprising,” when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein, the term “and / or” includes any combinations of one or more of the associated listed items. It should be noted that the terms “mobile device”, “user equipment”, “user device”, “communication device”, “device” and similar terms are used interchangeably for the purpose of describing the invention. These terms are not intended to limit the scope of the invention or imply any specific functionality or limitations on the described embodiments. The use of these terms is solely for convenience and clarity of description. The invention is not limited to any particular type of device or equipment, and it should be understood that other equivalent terms or variations thereof may be used interchangeably without departing from the scope of the invention as defined herein.
[0060] While considerable emphasis has been placed herein on the components and component parts of the preferred embodiments, it will be appreciated that manyembodiments can be made and that many changes can be made in the preferred embodiments without departing from the principles of the disclosure. These and other changes in the preferred embodiment, as well as other embodiments of the disclosure, will be apparent to those skilled in the art from the disclosure herein, whereby it is to be distinctly understood that the foregoing descriptive matter is to be interpreted merely as illustrative of the disclosure and not as a limitation.
[0061] Wireless communication technology has rapidly evolved over the past few decades. The first generation of wireless communication technology was analog, offering only voice services. Further, text messaging and data services became possible when the second-generation (2G) technology was introduced. The third generation (3G) technology marked the introduction of high-speed internet access, mobile video calling, and location-based services. The fourth generation (4G) technology revolutionized the wireless communication with faster data speeds, improved network coverage, and security. Currently, fifth generation (5G) technology is being deployed, offering significantly faster data speeds, lower latency, and the ability to connect many devices simultaneously. Further, 6G successor to 5G is expected to provide significantly high data speed with reduced latency, which may offer improved connectivity for a vast number of devices concurrently. The capabilities of 6G enable new types of applications and services, such as advanced augmented reality (AR) and virtual reality (VR), holographic communications, and more immersive digital experiences. These advancements represent a significant leap forward from previous generations, enabling enhanced mobile broadband, improved Internet of Things (loT) connectivity, and more efficient use of network resources. The sixth generation (6G) technology promises to build upon these advancements, pushing the boundaries of wireless communication even further. While the 5G technology is still being rolled out globally, research and development into the 6G are rapidly progressing, with the aim of revolutionizing the way of connecting and interacting with technology.
[0062] In modern telecommunication networks, such as Fourth Generation (4G), Fifth Generation (5G), and Sixth Generation (6G) networks, managing and differentiating traffic has become increasingly critical due to the diverse nature of devices and services. A Multiple Dwelling Unit (MDU) and a Home Gateway (HGW) are integral components of modern telecommunication networks, providing connectivity to multiple customer premises. While the MDU manages multiple HGWs under a single Customer Premises Equipment (CPE) session, the inability of a network function, such as a User Plane Function (UPF), to differentiate traffic originating from the MDU and the HGW has posed significant challenges in efficient network traffic handling.
[0063] At present, the UPF lacks the capability to effectively segregate MDU traffic from HGW traffic. This limitation leads to inefficient routing, increased latency, and potential degradation of service quality for end-users. As the MDU aggregates traffic from multiple HGW, proper differentiation of traffic at the UPF level is crucial for accurate resource allocation, network optimization, and service delivery.
[0064] To address these challenges, the present disclosure provides a method and a system for segregating traffic at the UPF by using separate Virtual Local Area Network Identifiers (VLAN IDs) for the MDU and the HGW. The present disclosure introduces the allocation of separate VLAN IDs for MDU and HGW traffic in both uplink (UL) and downlink (DL) directions. This solution ensures precise traffic segregation at the UPF, enabling efficient routing to appropriate destinations.
[0065] The present disclosure enables the UPF or the combination of User Plane Function and Broadband Network Gateway (UPF-BNG) to accurately distinguish MDU-originated traffic from HGW-originated traffic, a capability that is not available in existing systems. By utilizing separate VLAN IDs in both UL and DL directions, the disclosure ensures precise traffic separation, allowing the network to apply differentiated Quality of Service (QoS) policies, routing rules, and resourceallocation for MDU and HGW traffic. This technical enhancement prevents performance degradation of HGW traffic when MDU traffic increases, supports policy enforcement, and significantly improves overall network efficiency, scalability, and service reliability.
[0066] Hereinafter, exemplary embodiments of the present disclosure will be described with reference to the accompanying drawings.
[0067] FIG. 1 illustrates an exemplary network architecture (100) implanting a system (108) for segregating network traffic, in accordance with an embodiment of the present disclosure.
[0068] As illustrated in FIG. 1, the network architecture (100) may include one or more user equipments (UEs) (104-1, 104-2, .... 104-N) associated with one or more users (102-1, 102-2, ...., 102 -N) in an environment. A person of ordinary skill in the art will understand that one or more users (102-1, 102-2, ... 102-N) may be individually referred to as the user (102) and collectively referred to as the users (102). Similarly, a person of ordinary skill in the art will understand that one or more UEs (104-1, 104-2, ... .104-N) may be individually referred to as the UE (104) and collectively referred to as the UEs (104). Although three UEs (104) are depicted in FIG. 1, however, any number of the user equipments (104) may be included without departing from the scope of the ongoing description. In an embodiment, each UE (104) may have a unique identifier attribute associated therewith. In an embodiment, the unique identifier attribute may be indicative of at least one of a Mobile Station International Subscriber Directory Number (MSISDN), International Mobile Equipment Identity (IMEI) number, an International Mobile Subscriber Identity (IMSI), a Subscriber Permanent Identifier (SUPI), and the like.
[0069] In an embodiment, the UE (104) may include smart devices operating in a smart environment, such as an Internet of Things (loT) system. In such anembodiment, the UE (104) may include, but is not limited to, smartphones, smart watches, smart sensors (e.g., mechanical, thermal, electrical, magnetic, etc.), networked appliances, networked peripheral devices, networked lighting system, communication devices, networked vehicle accessories, networked vehicular devices, smart accessories, tablets, smart television (TV), computers, a smart security system, a smart home system, other devices for monitoring or interacting with or for the users (102) and / or entities, or any combination thereof. A person of ordinary skill in the art will appreciate that the UE (104) may include, but is not limited to, intelligent, multisensing, network- connected devices that can integrate seamlessly with each other and / or with a central server or a cloud- computing system or any other device that is network-connected.
[0070] In an embodiment, the UE (104) may include, but is not limited to, a handheld wireless communication device (e.g., a mobile phone, a smart phone, a phablet device, and so on), a wearable computer device (e.g., a head-mounted display computer device, a head-mounted camera device, a wristwatch computer device, and so on), a Global Positioning System (GPS) device, a laptop computer, a tablet computer, or another type of portable computer, a media playing device, a portable gaming system, and / or any other type of computer device with a wireless communication capabilities, and the like. In an embodiment, the UE (104) may include, but is not limited to, any electrical, electronic, electro-mechanical, or an equipment, or a combination of one or more of the above devices, such as virtual reality (VR) devices, augmented reality (AR) devices, a laptop, a general-purpose computer, a desktop, a personal digital assistant, a tablet computer, a mainframe computer, or any other computing device. In addition, the UE (104) may include one or more in-built or externally coupled accessories including, but not limited to, a visual aid device such as a camera, an audio aid, a microphone, a keyboard, and input devices for receiving input from the user (102) or an entity such as touch pad, a touch enabled screen, an electronic pen, and the like. A person of ordinary skill in the art will appreciate that the UE (104)may not be restricted to the mentioned devices and various other devices may be used.
[0071] In FIG. 1, the UE (104) may communicate with the system (108) via a network (106) to send data packets (e.g., traffic) to the system (108). The system (108) is configured to segregate the traffic received from the UE (104) based on the source of the traffic, such as whether the traffic originated from the MDU or the HGW. By employing VLAN IDs, the system (108) ensures that the traffic is correctly segregated and routed to its appropriate destination in the network (106), such as a server or the Internet, enhancing network efficiency and ensuring proper traffic management.
[0072] In an embodiment, the network (106) may include at least one of a Fifth Generation (5G) network, a Sixth Generation (6G) network, or the like. The network (106) may enable the UEs (104) to communicate with other devices in the network architecture (100) and / or with the system (108). The network (106) may include a wireless card or some other transceiver connection to facilitate this communication. In another embodiment, the network (106) may be implemented as or include any of a variety of different communication technologies such as a wide area network (WAN), a local area network (LAN), a wireless network, a mobile network, a Virtual Private Network (VPN), the Internet, the Public Switched Telephone Network (PSTN), or the like.
[0073] In an embodiment, the network (106) may include, by way of example but not limitation, at least a portion of one or more networks having one or more nodes that transmit, receive, forward, generate, buffer, store, route, switch, process, or a combination thereof, etc. one or more messages, packets, signals, waves, voltage or current levels, some combination thereof, or so forth. In an embodiment, the UE (104) may be communicatively coupled with the network (106). The system (108) may receive a connection request from the UE (104). The system (108) may send an acknowledgment of the connection request to the UE (104). The UE (104) may transmit a plurality of signals in response to the connection request. Once the connection isestablished, the system (108) may perform traffic segregation in the network (106). A process of traffic segregation is explained in greater detail in conjunction with the FIGS. 2 - 6.
[0074] Although FIG. 1 shows exemplary components of the network architecture (100), in other embodiments, the network architecture (100) may include fewer components, different components, differently arranged components, or additional functional components than depicted in FIG. 1. Additionally, or alternatively, one or more components of the network architecture (100) may perform functions described as being performed by one or more other components of the network architecture (100).
[0075] FIG. 2 illustrates an exemplary block diagram (200) of the system (108) for segregating network traffic, in accordance with an embodiment of the present disclosure. FIG. 2 is explained in conjunction with FIG. 1.
[0076] In an embodiment, the network traffic may be any data transmitted between the set of devices, such as the at least one Multiple Dwelling Unit (MDU) and the at least one HGW via the network (106). Such network traffic may include uplink data originating from the devices toward the network (106) and downlink data transmitted from the network (106) toward the devices. In modern broadband and 5G- based architectures, the network traffic generated by MDUs and HGWs may vary significantly in volume, priority, and service requirements. Accordingly, segregating network traffic based on the identity and type of device is essential for ensuring accurate routing, efficient bandwidth utilization, and proper application of quality of service (QoS) policies. Segregation further enables the network to prevent MDU traffic from adversely impacting HGW traffic, facilitates optimized handling of uplink and downlink flows, and supports improved service quality and reliability for end-users.
[0077] In an embodiment, the system (108) may be implemented in a networkfunction (208). The network function (208) may include at least one of a User Plane Function (UPF) and a combined User Plane Function and Broadband Network Gateway (UPF-BNG) configured to segregate network traffic. Additionally, in some embodiments, the network function may also include a Session Management Function (SMF) and a Policy Control Function (PCF). The SMF and the PCF may be configured to communicate with the UPF to determine the identity of each of the set of devices.
[0078] Referring to FIG. 2, in an embodiment, the system 108 may include one or more processor(s) (202). The one or more processor(s) (202) may be implemented as one or more microprocessors, microcomputers, microcontrollers, digital signal processors, central processing units, logic circuitries, and / or any devices that process data based on operational instructions. Among other capabilities, the one or more processor(s) (202) may be configured to fetch and execute computer-readable instructions stored in a memory (204) of the system (108). The memory (204) may be configured to store one or more computer-readable instructions or routines in a non- transitory computer-readable storage medium, which may be fetched and executed to create or share data packets over a network service. The memory (204) may include any non-transitory storage device, including, for example, volatile memory such as a Random-Access Memory (RAM), or a non-volatile memory such as an Erasable Programmable Read Only Memory (EPROM), a flash memory, and the like.
[0079] In an embodiment, the one or more processor(s) (202) may be implemented as a combination of hardware and programming (for example, programmable instructions) to implement one or more functionalities of the one or more processor(s) (202). Among other capabilities, the one or more processor(s) (202) may be configured to fetch and execute computer-readable instructions stored in the memory (204) of the system (108). In the examples described herein, such combinations of hardware and programming may be implemented in several different ways. For example, the programming for the one or more processor(s) (202) may beprocessor-executable instructions stored on a non-transitory machine-readable storage medium, and the hardware for the one or more processor(s) (202) may comprise a processing resource (for example, one or more processors) to execute such instructions. In the present examples, the machine-readable storage medium may store instructions that, when executed by the processing resource, implement the one or more processor(s) (202). In such examples, the system may comprise the machine-readable storage medium storing the instructions and the processing resource to execute the instructions, or the machine-readable storage medium may be separate but accessible to the system and the processing resource. In other examples, the processing engine (208) may be implemented by electronic circuitry.
[0080] In an embodiment, the system (108) may include an interface(s) (206). The interface(s) (206) may include a variety of interfaces, for example, interfaces for data input and output devices (I / O), storage devices, and the like. The interface(s) (206) may facilitate communication through the system (108). The interface(s) (206) may also provide a communication pathway for one or more components of the system (108). Examples of such components include, but are not limited to, one or more processor(s) (202) and a database (210).
[0081] In an embodiment, the network function (208) is configured to segregate network traffic. In an aspect, the network function (208) may be configured to segregate traffic from devices, such as the MDU and the HGW. The MDUs are installed in buildings and distribute optical fiber to the end users. In contrast, the HGW is a device that serves as an interface between a local area network (LAN) within a home or small office and the Internet. The MDU and the HGW are sources of the traffic.
[0082] In an embodiment, the UPF or the UPF-BNG is the primary network function (208) for traffic forwarding and handling one or more data packets between the MDUs and the HGW. In an embodiment, the UPF segregates traffic originatingfrom the MDU and the HGW by assigning distinct VLAN IDs. The SMF manages session setup, modification, and release for the UE within the network. Additionally, the PCF is responsible for managing and enforcing policy decisions related to traffic handling, QoS, and access control. In an embodiment, these network functions work together to effectively segregate the traffic originating from MDU and HGW devices.
[0083] In an embodiment, in order to segregate the traffic (e.g., data packets originating from the MDU and the HGW), the network function (208) first receives a solicit message from each device of a set of devices, namely the MDU and the HGW, over their respective VLAN IDs. In an embodiment, the solicit message is received through the Dynamic Host Configuration Protocol (DHCP). The DHCP server dynamically assigns IP addresses and other network configuration parameters (e.g., default gateway, subnet mask, and DNS servers) to devices within a network, enabling them to communicate on the network without requiring manual configuration. In an embodiment, the solicit message includes a Media Access Control (MAC) address associated with the MDU and the HGW.
[0084] Thereafter, the network function (208) determines the identity of each device. In particular, to determine the identity, the SMF and the PCF are configured to communicate with the UPF to analyze the MAC address associated with each of the set of devices. The process of determining the identity is explained in greater detail in conjunction with FIG. 4A and 4B. In an embodiment, the determined identity indicates that the solicit message received over the first VLAN ID (e.g., VLAN ID - 960) originates from the MDU, and the solicit message received over the second VLAN ID (e.g., VLAN ID - 1015) originates from the HGW. For example, upon identity determination, the traffic from the MDU is tagged with a first VLAN ID (e.g., VLAN ID - 960), while traffic from the HGW is tagged with a second VLAN ID (e.g., VLAN ID - 1015). This tagging allows the system (108) to distinguish between traffic sources.
[0085] Once the identity of each device is determined, the network function(208) allocates respective Internet Protocol (IP) addresses and transmits advertise message to each device. For example, a first advertise message, containing the IP address allocated to the MDU, is transmitted over the first VLAN ID. Similarly, a second advertise message, containing the IP address allocated to the HGW, is transmitted over the second VLAN ID. This ensures that both devices are uniquely identifiable within the network (106) and may communicate effectively.
[0086] After the IP address allocation and transmission of the respective advertise messages to the MDU and the HGW, the network function (208) subsequently receives a set of data packets from the at least one MDU and the at least one HGW. Upon receiving the data packets, the network function (208) segregates the data packets originating from each device based on the respective IP addresses allocated during the advertise exchange. The VLAN ID associated with each device facilitates segregation.
[0087] The network function (208) further routes the segregated data packets received from the MDU and HGW to one of a server and Internet based on the segregation. The respective IP addresses and the VLAN IDs determine the routing of the data packets. For example, once the identity of each device is determined (e.g., the solicit message received over the VLAN ID - 960 corresponds to the MDU, and the solicit message received over the VLAN ID - 1015 corresponds to the HGW), whenever the network function (208) receives the data packets from the MDU, these data packets are segregated and routed to the server (e.g., an Automatic Configuration Server (ACS)) over the first VLAN ID based on the IP address, ensuring that traffic from MDU is managed separately. The ACS is a management server typically used for remote provisioning, configuration, monitoring, and firmware management of network devices deployed in the field. Additionally, whenever the network function (208) receives the data packets from the HGW, these data packets are routed to the internet over the second VLAN ID based on the IP address, ensuring proper handling ofresidential gateway traffic.
[0088] In an embodiment, the traffic originating from the MDU is routed to the ACS because the MDU generally requires periodic configuration updates, parameter synchronization, management commands, and monitoring operations performed by the service provider. Routing the MDU traffic to the ACS over the first VLAN ID ensures that management-related communication is isolated from regular subscriber traffic, thereby preventing any interference with end-user services. In contrast, the HGW primarily generates subscriber data traffic intended for public Internet services, such as web browsing or streaming. Therefore, traffic originating from the HGW is routed to the Internet over the second VLAN ID based on the allocated IP address. This separation ensures that customer Internet usage remains unaffected by MDU management activities and enables the network to apply appropriate policies and QoS parameters for residential gateway traffic.
[0089] In an exemplary embodiment, consider a scenario in which an MDU and an HGW are connected to the network through a common Customer Premises Equipment (CPE). The MDU initiates a DHCP Solicit message over a first VLAN ID, for example, VLAN ID - 960, while the HGW transmits its DHCP Solicit message over a second VLAN ID, for example, VLAN ID - 1015. The network function (208) receives both Solicit messages and extracts the respective MAC addresses. Based on the VLAN ID and the MAC address, the SMF and the PCF interact with the UPF-BNG to determine that the device transmitting over VLAN ID-960 is the MDU and the device transmitting over VLAN ID-1015 is the HGW.
[0090] Upon determining the identity, the UPF-BNG allocates a first IP address (for example, 10.10.10.5) to the MDU and transmits a first Advertise message with this IP address over VLAN ID-960. Similarly, the UPF-BNG allocates a second IP address (for example, 192.168.1.20) to the HGW and transmits a second Advertise message over VLAN ID-1015. Once IP allocation is completed, uplink traffic from each devicebegins to flow toward the network. When the MDU sends a data packet, for example, a configuration request destined for the ACS, the UPF-BNG identifies the packet using the MDU’s allocated IP address (10.10.10.5) and segregates it as MDU-originated traffic. The segregated packet is then routed to the server (e.g., ACS) via VLAN ID- 960.
[0091] In contrast, when the HGW transmits an Internet-bound data packet, for example, a web request destined for an external website, the UPF-BNG identifies the packet using the HGW’s allocated IP address (192.168.1.20) and segregates it as HGW-originated traffic. The segregated packet is then forwarded to the Internet via VLAN ID-1015. The present example demonstrates that even though both the MDU and HGW operate under a shared CPE session, the use of distinct VLAN IDs and IPbased segregation allows the UPF-BNG to accurately isolate uplink and downlink traffic, ensuring correct routing paths, preventing cross-impact between devices, and enabling differentiated QoS and policy enforcement.
[0092] The segregation mechanism ensures accurate routing of data packets by isolating traffic flows based on their respective VLAN IDs and associated IP addresses. By receiving the data packets, segregating them according to device-specific identities, and routing them to the appropriate destination (e.g., a server for MDU traffic or the Internet for HGW traffic), the present disclosure optimizes overall network performance and reliability. Furthermore, the collaboration between the UPF-BNG, SMF, and PCF enables the system (108) to analyze device identities, allocate IP addresses, and route traffic in a scalable and efficient manner, thereby addressing the challenges of traffic differentiation and management in modern telecommunication networks.
[0093] In an embodiment, the database (210) may store data (e.g., device identifiers, VLAN identifiers, MAC addresses, IP address allocations, routing information, configured policies, etc.) that may be generated as a result offunctionalities implemented by any of the components of the processors (202). In an embodiment, the database (210) may be indicative of including, but not limited to, a relational database, a distributed database, a cloud-based database, or the like.
[0094] Although FIG. 2 shows exemplary components of the system (108), in other embodiments, the system (108) may include fewer components, different components, differently arranged components, or additional functional components than depicted in FIG. 2. Additionally, or alternatively, one or more components of the system (108) may perform functions described as being performed by one or more other components of the system (108).
[0095] FIG. 3 illustrates an exemplary system architecture (300) of the system (108), in accordance with an embodiment of the present disclosure. FIG. 3 is explained in conjunction with FIG. 1 and FIG. 2.
[0096] The system architecture (300) may include a plurality of home gateways (HGWs) (302-1, ,302-N), a multiple dwelling unit (MDU) (304), a customer premise equipment (CPE) (306), a base station (308), and a plurality of network functions. The base station (308) facilitates connectivity between the CPE (306) and the network's core components through an N3 interface and a GTP tunnel.
[0097] The plurality of network functions may include a User Plane Function (UPF) (310), a Session Management Function (SMF) (312), an Access Management and Mobility Function (AMF) (314), a Unified Data Management (UDM) (316), a Policy Control Function (PCF) (318), a Charging Function-Protocol converter (CHF- PC) (320), an Online Charging System (OCS) (322), a PCF Broadband Network Gateway (BNG) (324), and a CHF (326).
[0098] The CPE (306) establishes an Ethernet over GRE (EoGRE) tunnel with the BNG-UP, facilitating communication for multiple IP PDU sessions. The first CPE session is created as the parent session, while subsequent sessions for HGWs and MDUare established as child sessions. Distinct N7 and N40 sessions are created between the SMF (312) and the PCF (318), and the SMF (312) and CHF-PC (320), respectively, to manage policies and charging for the CPE and connected devices.
[0099] In an aspect, the termination of the EoGRE tunnel at the BNG-UP (310) acts as the DHCP server for HGW devices. This enables the enforcement of policies and charging specific to the HGW sessions. Data packets from the MDU (304) are routed to the Internet / IMS (328) through the UPF (310), while traffic segregation between HGWs and the MDU (304) is managed via VLAN IDs and IP address allocations.
[0100] The primary functionality of the system architecture (300) is the segregation and routing of traffic from HGWs and the MDU, ensuring policy enforcement and accurate charging mechanisms for each session. For instance, the first CPE session functions as the anchor point, while the child sessions handle individual data flows for connected devices.
[0101] In an aspect, the plurality of HGWs (302-1, ... ,302-N) connects individual residential users to the broader network, such as the Internet, service provider network, or private enterprise network. The connection between the plurality of HGWs (302-1,... , 302 -N) and the CPE (306) is established using Power over Ethernet (PoE) cables. In an aspect, the PoE cables are Ethernet cables that carry data and electrical power, allowing devices (e.g., wireless access points) to receive power and data over the cable connection.
[0102] In an aspect, the MDU (304) acts as a central hub for multiple users within a residential complex. The MDU (304) connects through the CPE (306) and routes traffic via the network functions. The data packets are managed and routed with appropriate VLAN IDs and IP address allocations to distinguish traffic between the HGWs (302-1,... ,302-N) and MDU (304).
[0103] In an aspect, the UPF (310) handles the routing of data packets from the CPE (306) to external destinations such as the Internet / IMS (328). It also enforces Quality of Service (QoS) and charging rules as received from the SMF (312) and CHF components. In an aspect, the SMF (312) is responsible for creating, modifying, and managing the IP PDU sessions. It interacts with the UPF (310) via the N4 interface for session establishment and traffic management, and with the PCF (318) via the N7 interface to enforce policies related to these sessions. In an aspect, the AMF (314) handles mobility and registration management for the connected devices. It ensures proper handover and session continuity for devices moving between cells or networks.
[0104] In an aspect, the UDM (316) provides subscription data, authentication credentials, and policy information required by other network functions. It ensures that the connected devices are authenticated and authorized to access the network (106). In an aspect, the PCF (318) manages policies for the CPE (306) and its child devices, such as the HGWs (302-1, ... ,302-N) and the MDU (304). It interacts with the SMF (312) via the N7 interface to apply policies such as bandwidth allocation, service prioritization, and data limits.
[0105] In an aspect, the CHF-PC (320) serves as an intermediary between the CHF (326) and the OCS (322). It converts the session-based charging data from the CHF (326) into a format compatible with the OCS (322) for real-time credit control and balance updates. In an aspect, the OCS (322) handles the real-time charging and quota management for the devices connected to the network (106).
[0106] In an aspect, the BNG (324) provides broadband access for the HGWs (302-1, ... ,302-N) and the MDU (304). It also acts as the DHCP server, assigning IP addresses to connected devices and ensuring that individual traffic flows are appropriately managed.
[0107] In an aspect, the CHF (326) is a charging function co-located within theBNG. It processes session-based data usage locally and communicates with the CHF- PC (320) for reporting this data to the OCS (322). This reduces the latency and overhead associated with charging data synchronization. The N4 interface facilitates communication between the SMF (312) and the UPF (310) for session management and control. It ensures that traffic flows are routed correctly according to the policies defined by the PCF (318) and the charging rules from the CHF -PC (320).
[0108] The present disclosure addresses the technical challenge where the UPF (310) is unable to differentiate traffic originating from the MDU (304) and traffic originating from the HGW (302) when both operate under a single CPE session (306). Since the MDU (304) provides connectivity to multiple HGWs (302-1,... , 302 -N), accurate traffic differentiation at the UPF (310) becomes essential to ensure proper routing, policy enforcement, charging, and service isolation. To overcome this limitation, the present disclosure introduces a mechanism for allocating separate VEAN identifiers for MDU traffic and HGW traffic in both uplink (UL) and downlink (DL) directions. When a solicit or request message is received from either the MDU (304) or the HGW (302) over DHCP at the UPF (310), the UPF (310) transmits a Session Report Request (SRR) to the SMF (312) carrying a MAC-address-detected information element (IE). The SMF (312), after verifying the MAC-to-IMSI provisioning with the PCF (318), sends a Session Modification Request (SMR) to the UPF (310), including device-specific Packet Detection Rules (PDRs). This enables the UPF (310) to correctly identify subsequent UL / DL packets and map them to their respective VLAN paths. In the case of the MDU (304), the SMF (312) includes in the SMR a c-tag information element containing the VLAN ID used for communication, enabling the UPF (310) to respond to DHCP messages and apply the appropriate forwarding rules. Proper identification of the device and enforcement of uplink and downlink packet routing over the respective VLAN IDs form the core technical contribution of the present disclosure.
[0109] FIGS. 4A and 4B illustrate exemplary process flows (400A and 400B) for segregating the traffic. Currently, the UPF lacks the capability to effectively segregate MDU traffic from HGW traffic. To address these issues, assigning unique VLAN IDs for each MDU and HGW traffic has emerged as a promising solution. By allocating separate VLAN IDs for MDU traffic in uplink (UL) and downlink (DL) directions, it becomes possible to differentiate and manage traffic flows efficiently. The disclosed approach ensures that MDU traffic is processed and routed independently of HGW traffic, enabling improved network resource allocation, enhanced security, and better user experience.
[0110] FIG. 4A illustrates an exemplary process flow (400A) for segregating network traffic, in accordance with an embodiment of the present disclosure. In an embodiment, the process flow (400A) shows the traffic originating from the HGW. The present FIG. 4A depicts the interaction between various network entities, including an HGW (402a), a UPF (404a) (also referred to as UPF-BNG), an SMF (406a), and an Internet (408a).
[0111] At step 410a, the UPF (404a) receives a DHCP Solicit message from the HGW (402a) over a predefined VLAN ID (e.g., the VLAN ID - 1015). At this stage, the UPF (404a) is unaware of the device or source of traffic from which it originated. The solicit message may include a Media Access Control (MAC) address associated with the device. In an aspect, the UPF (404a) is responsible for detecting the traffic source.
[0112] To determine the identity of the device (e.g., the HGW) from which the traffic originated, at step 412a, the UPF (404a) initiates a Session Report Request to the SMF (406a). This request includes a MAC address detection Information Element (IE) to identify the originating device. The SMF (406a) processes the request and communicates with the PCF (not shown in the present FIG. 4A) to authenticate the MAC address against the corresponding IMSI and provisioning data. In someembodiments, the IMSI and provisioning data may be retrieved from a subscriber database (such as the UDM or Subscriber Profile Repository (SPR)), which stores the necessary subscriber information. At step 414a, upon successful verification, the SMF (406a) sends a Session Report Response back to the UPF (404a).
[0113] To enable traffic segregation, at step, 416a, the SMF (406a) issues a Session Modification Request to the UPF (404a). This request contains one or more Packet Detection Rules (PDRs) tailored for the HGW (402a). For HGW-specific traffic, no customer VLAN (c-tag) is required in the Session Modification Request. In particular, the one or more PDRs define how UL and DL traffic for the HGW (402a) should be processed by the UPF (404a).
[0114] At step 418a, the UPF (404a) acknowledges the request by sending a Session Modification Response to the SMF (406a). At this stage, the UPF (404a) is configured to handle traffic for the HGW (402a) according to the established one or more PDRs.
[0115] At step 420a, the UPF (402a) responds to the HGW’s initial DHCP Solicit by sending a DHCP Advertise message over the same VLAN ID (1015). Subsequently, at step 422a, the HGW (402a) sends a DHCP Request, and the UPF (404a) completes the process by replying with a DHCP Reply, at step 424a.
[0116] After the session is established, the Uplink (UL) and Downlink (DL) packets (e.g., traffic) flows are processed by the UPF (404a) based on the configured one or more PDRs. For example, at steps 426a and 428a, the Uplink packets from the HGW (402a) are tagged and then routed through the UPF (404a) to the intended destination, i.e., on the Internet (408a), at step 428a.
[0117] Further, at steps 430a and 432a, the DL packets from the Internet (408a) through the UPF (404a) are routed to the HGW (402a) based on the established PDRs and respective VLAN ID.
[0118] FIG. 4B illustrates another exemplary process flow (400B) for segregating network traffic, in accordance with an embodiment of the present disclosure. The present FIG. 4B depicts the interaction between various network entities, including an MDU (402b), a UPF (404b), an SMF (406b), and an ACS (408b). In an embodiment, the flow diagram (400B) illustrates the traffic originating from the MDU (402b).
[0119] At step 410b, the UPF (404b) receives a DHCP Solicit message from the MDU (402b) over a predefined VLAN ID (e.g., the VLAN ID - 960). At this stage, the UPF (404b) is unaware of the device or source of traffic from which it originated. The solicit message may include a Media Access Control (MAC) address associated with that device. In an aspect, the UPF (404b) is responsible for detecting the traffic source or identifying the device from which the traffic originates.
[0120] To determine the identity of the device (e.g., the MDU) from which the traffic originated, at step 412b, the UPF (404b) initiates a Session Report Request to the SMF (406b). This request includes a MAC address detection Information Element (IE) to identify the originating MDU device. The SMF (406b) processes the request and communicates with the PCF (not shown in the present FIG. 4B) to authenticate the MAC address against the corresponding IMSI and provisioning data. At step 414b, upon successful verification, the SMF (406b) sends a Session Report Response back to the UPF (404b).
[0121] To enable traffic segregation, at step 416b, the SMF (406b) issues a Session Modification Request to the UPF (404b). This request contains one or more PDRs, along with a c-tag IE (which contains the VLAN ID for communication) in the Session Modification Request. The VLAN ID 960 is specified in the Session Modification Request to indicate traffic segmentation at the UPF (404b) for the MDU (402b). This c-tagging allows the UPF (404b) to process MDU-specific traffic independently of other devices, such as HGWs.
[0122] At step 418b, the UPF (404b) acknowledges the request by sending a Session Modification Response to the SMF (406b). At this stage, the UPF (404b) is configured to handle traffic for the MDU (402b) according to the established one or more PDRs.
[0123] At step 420b, the UPF (402b) responds to the MDU’s initial DHCP Solicit by sending a DHCP Advertise message over the same VUAN ID - 960. Subsequently, at step 422b, the MDU (402b) sends a DHCP Request, and the UPF (404b) completes the process by replying with a DHCP Reply, at step 424b.
[0124] After the session is established, the Uplink (UL) and Downlink (DU) packets (e.g., traffic) flows are processed by the UPF (404b) based on the configured one or more PDRs and VUAN tagging. For example, at steps 426b and 428b, the UL Packets from the MDU (402b) are tagged with VUAN ID - 960 and routed through the UPF (404b) to the intended destination i.e., the ACS (408b), at step 428b. Further, at steps 430b and 432b, the DU packets from the ACS (408b) are routed to the MDU (402b) with the specified VUAN ID - 960, ensuring traffic is properly segregated and routed.
[0125] In an overall aspect, to segregate the network traffic, the present disclosure may consider the following statements:• The UPF-BNG (e.g., DHCP server) receives a solicit message from the MDU (e.g., DHCP Client) over VUAN - 960 using a DHCP protocol.• The UPF-BNG (e.g., DHCP server) receives a solicit message from the HGW (DHCP Client) over VUAN -1015 using the DHCP protocol.• The UPF-BNG authenticates the MDU and HGW, respectively, at the network.• The UPF-BNG sends an Advertise message to the MDU and HGW, and in the message, it sends the respective IP address allocated.The Advertise message for MDU is over VLAN - 960, and for the HGW is over VLAN - 1015.• Further, any message / data packet transmission for the MDU and HGW happens over respective VLANs, keeping the traffic discreet for each device.
[0126] FIG. 6 illustrates an exemplary flow chart of a method (600) for segregating network traffic, in accordance with an embodiment of the present disclosure. FIG. 6 is explained in conjunction with FIG. 1, FIG. 2, FIG. 3, FIG. 4, and FIG. 5.
[0127] At step 602, the network function (208) (e.g., a UPF or a combined UPF- BNG) is configured to receive a solicit message from each device of a set of devices over a corresponding Virtual Local Area Network (VLAN) identifier (ID). The set of devices includes one or more Multiple Dwelling Units (MDUs) and one or more Home Gateways (HGWs). In an embodiment, the solicit message may be received using a Dynamic Host Configuration Protocol (DHCP). The solicit message may include a MAC address associated with the respective device. The reception of the solicit message through different VLAN IDs enables the network function (208) to initially distinguish the physical ingress path of each device.
[0128] At step 604, the network function (208) is further configured to determine an identity of each of the set of devices. In an embodiment, to determine the identity, the network function (208) analyzes the MAC address associated with each device of the set of devices. The analyzed information indicates that the solicit message received over the first VLAN ID (e.g., VLAN ID-960) corresponds to at least one MDU (402b) , while the solicit message received over the second VLAN ID (e.g., VLAN ID-1015) corresponds to at least one HGW (402a). In some embodiments, the network function (208) may include an SMF and a PCF, which communicate with the UPF to assist in determining the identity of each device by validating the MAC address1 and device type information.
[0129] At step 606, upon determining the identity of each device, the network function (208) transmits a first advertise message to the at least one MDU (402b) over the first VLAN ID and a second advertise message to the at least one HGW (402a) over the second VLAN ID. In an embodiment, the first advertise message includes the IP address allocated to the at least one MDU (402b), and the second advertise message includes the IP address allocated to the at least one HGW (402a). This ensures that each device receives a unique IP address associated with its respective VLAN path, enabling accurate subsequent segregation of uplink and downlink traffic.
[0130] At step 608, the network function (208) receives a set of data packets originating from the at least one MDU (402b) and the at least one HGW (402a). The received data packets may include uplink traffic, management traffic, or subscriber traffic transmitted toward the network. The distinct VLAN IDs and IP addresses associated with each device enable the network function (208) to distinguish between MDU-originated packets and HGW-originated packets.
[0131] At step 610, the network function (208) segregates the set of data packets received from the at least one MDU (402b) and the at least one HGW (402a) based on their respective IP addresses. The segregation enables the method (600) to differentiate data paths, apply appropriate policies, and route each traffic flow to the correct destination.
[0132] Following the segregation, the network function (208) further routes the set of segregated data packets to one of a server or the Internet based on the segregation. In particular, any data packet received from the at least one MDU (402b) is routed to the server, such as an Automatic Configuration Server (ACS) (408b), over the first VLAN ID, based on the IP address allocated to the MDU (402b). This ensures that management-related or provisioning traffic from the MDU (402b) is handled separatelyand securely.
[0133] Similarly, any data packet received from the at least one HGW (402a) is routed to the Internet (408a) over the second VLAN ID based on the IP address allocated to the HGW (402a). This ensures that subscriber-generated traffic, such as browsing or application data, is forwarded directly to external networks without interfering with MDU management traffic.
[0134] In an exemplary embodiment, the present disclosure provides a computer program product comprising a non-transitory computer-readable medium having instructions stored thereon, which when executed by one or more processors, cause the one or more processors to execute a method for segregating network traffic. The method includes receiving, by a network function, a solicit message from each device of a set of devices over a corresponding Virtual Local Area Network (VLAN) identifier (ID). The set of devices includes one or more Multiple Dwelling Units (MDUs) and one or more Home Gateways (HGWs). The method further includes determining, by the network function, an identity of each device. Upon determining the identity, the method includes transmitting, by the network function, a first advertise message to at least one MDU over a first VLAN ID and a second advertise message to at least one HGW over a second VLAN ID. The first advertise message includes an Internet Protocol (IP) address allocated to the at least one MDU and the second advertise message includes the IP address allocated to the at least one HGW. The method further includes receiving, by the network function, a set of data packets from the at least one MDU and the at least one HGW. The method further includes segregating the received data packets based on the respective IP addresses.
[0135] FIG. 6 illustrates an exemplary computer system (600) in which or with which embodiments of the present disclosure may be implemented.
[0136] As shown in FIG. 6, the computer system (600) may include an externalstorage device (610), a bus (620), a main memory (630), a read-only memory (640), a mass storage device (650), communication port(s) (660), and a processor (670). A person skilled in the art will appreciate that the computer system may include more than one processor and communication ports. The processor (670) may include various modules associated with embodiments of the present disclosure. The communication port(s) (660) may be any of an RS-232 port for use with a modem-based dialup connection, a 10 / 100 Ethernet port, a Gigabit or 10 Gigabit port using copper or fiber, a serial port, a parallel port, or other existing or future ports. The communication port(s) (660) may be chosen depending on a network, such as a Local Area Network (LAN), Wide Area Network (WAN), or any network to which the computer system connects.
[0137] The main memory (630) may be random access memory (RAM), or any other dynamic storage device commonly known in the art. The read-only memory (640) may be any static storage device(s) e.g., but not limited to, Programmable Read Only Memory (PROM) chips for storing static information e.g., start-up or Basic Input / Output System (BIOS) instructions for the processor (670). The mass storage device (650) may be any current or future mass storage solution, which can be used to store information and / or instructions. Exemplary mass storage device (650) includes, but is not limited to, Parallel Advanced Technology Attachment (PATA) or Serial Advanced Technology Attachment (SATA) hard disk drives or solid-state drives (internal or external, e.g., having Universal Serial Bus (USB) and / or Lirewire interfaces), one or more optical discs, Redundant Array of Independent Disks (RAID) storage, e.g., an array of disks.
[0138] The bus (620) communicatively couples the processor (670) with the other memory, storage, and communication blocks. The bus (620) may be, e.g., a Peripheral Component Interconnect (PCI) / PCI Extended (PCI-X) bus, Small Computer System Interface (SCSI), Universal Serial Bus (USB), or the like, for connecting expansion cards, drives, and other subsystems as well as other buses, such as a front-side bus (FSB), which connects the processor (670) to the computer system.
[0139] Optionally, operator and administrative interfaces, e.g., a display, keyboard, joystick, and a cursor control device, may also be coupled to the bus (620) to support direct operator interaction with the computer system. Other operator and administrative interfaces can be provided through network connections connected through the communication port(s) (660). Components described above are meant only to exemplify various possibilities. In no way should the aforementioned exemplary computer system limit the scope of the present disclosure.
[0140] While the foregoing describes various embodiments of the invention, other and further embodiments of the disclosure may be devised without departing from the basic scope thereof. The scope of the disclosure is determined by the claims that follow. The invention is not limited to the described embodiments, versions or examples, which are included to enable a person having ordinary skill in the art to make and use the invention when combined with information and knowledge available to the person having ordinary skill in the art.
[0141] The method and system of the present disclosure may be implemented in a number of ways. For example, the methods and systems of the present disclosure may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above-described order for the steps of the method is for illustration only, and the steps of the method of the present disclosure are not limited to the order specifically described above unless specifically stated otherwise. Further, in some embodiments, the present disclosure may also be embodied as programs recorded in a recording medium, the programs including machine-readable instructions for implementing the methods according to the present disclosure. Thus, the present disclosure also covers a recording medium storing a program for executing the method according to the present disclosure.
[0142] While considerable emphasis has been placed herein on the preferred embodiments, it will be appreciated that many embodiments can be made and that many changes can be made in the preferred embodiments without departing from the principles of the disclosure. These and other changes in the preferred embodiments of the disclosure will be apparent to those skilled in the art from the disclosure herein, whereby it is to be distinctly understood that the foregoing descriptive matter is to be implemented merely as illustrative of the disclosure and not as a limitation.
[0143] The present disclosure offers significant technical advancements in enabling accurate, scalable, and efficient segregation of network traffic originating from different types of subscriber devices, such as MDUs and HGWs, within modern broadband and 5G-based telecommunication networks. Existing systems lack the capability to differentiate traffic from the MDU and HGW when both operate under a common session, such as a CPE connection, resulting in inefficient routing, congestion, and degraded performance for residential users. The present disclosure overcomes these limitations by introducing a mechanism wherein a network function (e.g., UPF or UPF-BNG) receives solicit messages over distinct VLAN identifiers (VLAN IDs), determines device identity using MAC-based analysis, and allocates device-specific IP addresses. The disclosure further provides a robust packet-segregation process in which uplink and downlink data packets are distinguished based on their allocated IP addresses and routed over dedicated VLAN paths. A key technical enhancement lies in enabling the network to implement separate VLAN IDs for MDU and HGW traffic in both uplink and downlink directions, thereby isolating management-plane traffic associated with MDUs from subscriber-plane traffic originating from HGWs. This facilitates differentiated handling of traffic flows, such as routing MDU traffic to an Automatic Configuration Server (ACS) for provisioning while routing HGW traffic to the Internet without interference. By enabling device-specific segregation at the UPF layer, the disclosure allows the application of differentiated Quality of Service (QoS) policies, prevents resource contention between aggregated MDU traffic and individualHGW traffic, and enhances routing precision.
[0144] These improvements collectively reduce latency, prevent performance degradation for residential subscribers, eliminate cross-traffic interference, and optimize end-to-end packet handling. The disclosed mechanism provides a scalable architecture for traffic differentiation, allows seamless integration with SMF / PCF- based policy control, enhances overall network reliability, and significantly improves service quality in converged broadband and 5G deployments.ADVANTAGES OF THE PRESENT DISCLOSURE
[0145] The present disclosure provides a method and system for efficient traffic segregation and management at the network function, such as a UPF or a UPF-BNG, by segregating MDU traffic from HGW traffic in both uplink (UL) and downlink (DL) directions. This ensures no impact on HGW traffic during the handling of MDU traffic, preserving the integrity and performance of both traffic types.
[0146] The present disclosure enables the implementation of differentiated Quality of Service (QoS) policies for traffic originating from the MDU and the HGW. By employing separate VLAN IDs and IP address allocations, the network function may apply device-specific QoS profiles, ensuring optimized network performance and tailored service delivery for both traffic types.
[0147] The present disclosure enhances traffic management capabilities by utilizing VLAN-based tagging to ensure precise identification and segregation of packets originating from different devices. This prevents misrouting, reduces interference between traffic flows, and improves overall network efficiency, particularly in scenarios where multiple devices are aggregated under a single CPE session.
[0148] The present disclosure provides improved device identity determinationthrough analysis of MAC addresses and device-specific VLAN information at the network function. This enables the system to accurately classify devices such as MDUs and HGWs, thereby enhancing traffic differentiation reliability and supporting correct routing decisions.
[0149] The present disclosure enables scalable session handling and resource management by supporting automated installation of Packet Detection Rules (PDRs) and policy updates through interaction among the UPF, SMF, and PCF. This reduces manual configuration efforts, minimizes operational errors, and facilitates seamless integration with existing network infrastructures.
[0150] The present disclosure provides operational flexibility by integrating with DHCP procedures for dynamic IP address allocation and device provisioning. By associating each allocated IP address with a corresponding VLAN ID, the system enables accurate packet segregation and simplifies network configuration.
Claims
CLAIMS1. A method (600) for segregating network traffic, the method (600) comprising: receiving (602), by a network function (208), a solicit message from each device of a set of devices over a corresponding virtual local area network (VLAN) identifier (ID), wherein the set of devices comprises one or more Multiple Dwelling Units (MDUs) and one or more Home Gateways (HGWs); determining (604), by the network function (208), an identity of each of the set of devices; upon determining the identity of each device, transmitting (606), by the network function (208), a first advertise message to at least one MDU (402b) over a first VLAN ID and a second advertise message to at least one HGW (402a) over a second VLAN ID, wherein the first advertise message comprises an Internet Protocol (IP) address allocated to the at least one MDU (402b), and wherein the second advertise message comprises the IP address allocated to the at least one HGW (402a); receiving (608), by the network function (208), a set of data packets from the at least one MDU (402b) and the at least one HGW (402a); and segregating (610), by the network function (208), the set of data packets received from each of the at least one MDU (402b) and the at least one HGW (402a) based on their respective IP addresses.
2. The method (600) as claimed in claim 1, wherein the solicit message is received using a Dynamic Host Configuration Protocol (DHCP), and wherein the solicit message comprises a Media Access Control (MAC) address associated with a respective device.
3. The method (600) as claimed in claim 1, wherein determining the identity comprises:analyzing, by the network function (208), the MAC address associated with each device of the set of devices, wherein the determined identity indicates that the solicit message received over the first VLAN ID corresponds to the at least one MDU (402b) and the solicit message received over the second VLAN ID corresponds to the at least one HGW (402a).
4. The method (600) as claimed in claim 1, further comprising: routing, by the network function (208), the set of segregated data packets to one of a server and Internet (408a) based on the segregation.
5. The method (600) as claimed in claim 4, wherein a data packet of the set of data packets received from the at least one MDU (402b) is routed to the server over the first VLAN ID.
6. The method (600) as claimed in claim 4, wherein a data packet of the set of data packets received from the at least one HGW (402a) is routed to the Internet (408a) over the second VLAN ID.
7. The method (600) as claimed in claim 1, wherein the network function (208) comprises at least one of a User Plane Function (UPF) (404a, 404b), and a combined User Plane Function and Broadband Network Gateway (UPF-BNG).
8. The method (600) as claimed in claim 7, wherein the network function (208) further comprises a Session Management Function (SMF) (406a, 406b) and a Policy Control Function (PCF), and wherein the SMF (406a, 406b) and the PCF are configured to communicate with the UPF (404a, 404b) to determine the identity of each of the set of devices.
9. A system (108) for segregating network traffic, the system (108) comprising:a network function (208), wherein the network function (208) is configured to: receive a solicit message from each device of a set of devices over a corresponding virtual local area network (VLAN) identifier (ID), wherein the set of devices comprises one or more Multiple Dwelling Units (MDUs) and one or more Home Gateways (HGWs); determine an identity of each of the set of devices; upon determining the identity of each device, transmit a first advertise message to at least one MDU (402b) over a first VLAN ID and a second advertise message to at least one HGW (402a) over a second VLAN ID, wherein the first advertise message comprises an Internet Protocol (IP) address allocated to the at least one MDU (402b), and wherein the second advertise message comprises the IP address allocated to the at least one HGW (402a); receive a set of data packets from the at least one MDU (402b) and the at least one HGW (402a); and segregate the set of data packets received from each of the at least one MDU (402b) and the at least one HGW (402a) based on their respective IP addresses.
10. The system (108) as claimed in claim 9, wherein the solicit message is received using a Dynamic Host Configuration Protocol (DHCP), and wherein the solicit message comprises a Media Access Control (MAC) address associated with a respective device.
11. The system (108) as claimed in claim 9, wherein to determine the identity, the network function (208) is configured to analyze the MAC address associated with each device of the set of devices, and wherein the determined identity indicates that the solicit message received over the first VLAN ID corresponds to the at least one MDU(402b) and the solicit message received over the second VLAN ID corresponds to the at least one HGW (402a).
12. The system (108) as claimed in claim 9, wherein the network function (208) is further configured to: route the set of segregated data packets to one of a server and Internet (408a) based on the segregation.
13. The system (108) as claimed in claim 12, wherein a data packet of the set of data packets received from the at least one MDU (402b) is routed to the server over the first VLAN ID.
14. The system (108) as claimed in claim 12, wherein a data packet of the set of data packets received from the at least one HGW (402a) is routed to the Internet (408a) over the second VLAN ID.
15. The system (108) as claimed in claim 9, wherein the network function (208) comprises at least one of a User Plane Function (UPF) (404a, 404b), and a combined User Plane Function and Broadband Network Gateway (UPF-BNG).
16. The system (108) as claimed in claim 15, wherein the network function (208) further comprises a Session Management Function (SMF) (406a, 406b) and a Policy Control Function (PCF), and wherein the SMF (406a, 406b) and the PCF are configured to communicate with the UPF (404a, 404b) to determine the identity of each of the set of devices.
17. A computer program product comprising a non-transitory computer- readable medium comprising instructions that, when executed by one or more processors, causethe one or more processors to execute a method (600) for segregating network traffic, the method (600) comprising: receiving, by a network function (208), a solicit message from each device of a set of devices over a corresponding virtual local area network (VLAN) identifier (ID), wherein the set of devices comprises one or more Multiple Dwelling Units (MDUs) and one or more Home Gateways (HGWs); determining, by the network function (208), an identity of each of the set of devices; upon determining the identity of each device, transmitting, by the network function (208), a first advertise message to at least one MDU (402b) over a first VLAN ID and a second advertise message to at least one HGW (402a) over a second VLAN ID, wherein the first advertise message comprises an Internet Protocol (IP) address allocated to the at least one MDU (402b), and wherein the second advertise message comprises the IP addresses allocated to the at least one HGW (402a); receiving, by the network function (208), a set of data packets from the at least one MDU (402b) and the at least one HGW (402a); and segregating, by the network function (208), the set of data packets received from each of the at least one MDU (402b) and the at least one HGW (402a) based on their respective IP addresses.