Method and apparatus for managing allowed media access control address in a wireless communication system
Patent Information
- Application Number
- PCT/KR2026/003701
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-04-25
- Filing Date
- 2026-03-09
- Publication Date
- 2026-10-01
Smart Images

Figure KR2026003701_01102026_PF_FP_ABST
Abstract
Description
METHOD AND APPARATUS FOR MANAGING ALLOWED MEDIA ACCESS CONTROL ADDRESS IN A WIRELESS COMMUNICATION SYSTEM
[0001] This application is based on and derives the benefit of Indian Provisional Applications 202541027703 filed on 25thMarch 2025, and 202541040051 filed on 25thApril 2025 the contents of which are incorporated herein by reference. The present disclosure relates to the field of wireless communication. More specifically, the present disclosure relates to a method and apparatus for managing allowed Media Access Control (MAC) addresses in a telecommunication network.
[0002] 5G mobile communication technologies define broad frequency bands such that high transmission rates and new services are possible, and can be implemented not only in “Sub 6GHz” bands such as 3.5GHz, but also in “Above 6GHz” bands referred to as mmWave including 28GHz and 39GHz. In addition, it has been considered to implement 6G mobile communication technologies (referred to as Beyond 5G systems) in terahertz (THz) bands (for example, 95GHz to 3THz bands) in order to accomplish transmission rates fifty times faster than 5G mobile communication technologies and ultra-low latencies one-tenth of 5G mobile communication technologies.
[0003] At the beginning of the development of 5G mobile communication technologies, in order to support services and to satisfy performance requirements in connection with enhanced Mobile BroadBand (eMBB), Ultra Reliable Low Latency Communications (URLLC), and massive Machine-Type Communications (mMTC), there has been ongoing standardization regarding beamforming and massive MIMO for mitigating radio-wave path loss and increasing radio-wave transmission distances in mmWave, supporting numerologies (for example, operating multiple subcarrier spacings) for efficiently utilizing mmWave resources and dynamic operation of slot formats, initial access technologies for supporting multi-beam transmission and broadbands, definition and operation of BWP (BandWidth Part), new channel coding methods such as a LDPC (Low Density Parity Check) code for large amount of data transmission and a polar code for highly reliable transmission of control information, L2 pre-processing, and network slicing for providing a dedicated network specialized to a specific service.
[0004] Currently, there are ongoing discussions regarding improvement and performance enhancement of initial 5G mobile communication technologies in view of services to be supported by 5G mobile communication technologies, and there has been physical layer standardization regarding technologies such as V2X (Vehicle-to-everything) for aiding driving determination by autonomous vehicles based on information regarding positions and states of vehicles transmitted by the vehicles and for enhancing user convenience, NR-U (New Radio Unlicensed) aimed at system operations conforming to various regulation-related requirements in unlicensed bands, NR UE Power Saving, Non-Terrestrial Network (NTN) which is UE-satellite direct communication for providing coverage in an area in which communication with terrestrial networks is unavailable, and positioning.
[0005] Moreover, there has been ongoing standardization in air interface architecture / protocol regarding technologies such as Industrial Internet of Things (IIoT) for supporting new services through interworking and convergence with other industries, IAB (Integrated Access and Backhaul) for providing a node for network service area expansion by supporting a wireless backhaul link and an access link in an integrated manner, mobility enhancement including conditional handover and DAPS (Dual Active Protocol Stack) handover, and two-step random access for simplifying random access procedures (2-step RACH for NR). There also has been ongoing standardization in system architecture / service regarding a 5G baseline architecture (for example, service based architecture or service based interface) for combining Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) for receiving services based on UE positions.
[0006] As 5G mobile communication systems are commercialized, connected devices that have been exponentially increasing will be connected to communication networks, and it is accordingly expected that enhanced functions and performances of 5G mobile communication systems and integrated operations of connected devices will be necessary. To this end, new research is scheduled in connection with eXtended Reality (XR) for efficiently supporting AR (Augmented Reality), VR (Virtual Reality), MR (Mixed Reality) and the like, 5G performance improvement and complexity reduction by utilizing Artificial Intelligence (AI) and Machine Learning (ML), AI service support, metaverse service support, and drone communication.
[0007] Furthermore, such development of 5G mobile communication systems will serve as a basis for developing not only new waveforms for providing coverage in terahertz bands of 6G mobile communication technologies, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), array antennas and large-scale antennas, metamaterial-based lenses and antennas for improving coverage of terahertz band signals, high-dimensional space multiplexing technology using OAM (Orbital Angular Momentum), and RIS (Reconfigurable Intelligent Surface), but also full-duplex technology for increasing frequency efficiency of 6G mobile communication technologies and improving system networks, AI-based communication technology for implementing system optimization by utilizing satellites and AI (Artificial Intelligence) from the design stage and internalizing end-to-end AI support functions, and next-generation distributed computing technology for implementing services at levels of complexity exceeding the limit of UE operation capability by utilizing ultra-high-performance communication and computing resources.
[0008] The Fifth Generation System (5GS) has introduced a Protocol Data Unit (PDU) session type designed to transport Ethernet frames between User Equipment (UE) and a Data Network (DN). This Ethernet PDU session type facilitates UE connectivity to a Layer-2 Ethernet data network, enabling various deployment scenarios such as interconnection of remote offices with enterprise networks, attachment of industrial equipment to factory Local Area Networks (LANs), and delivery of fixed wireless access services. In fixed wireless access deployments, a Residential Gateway (RG) provides bridged Layer-2 Ethernet services to fixed wireless broadband subscribers.
[0009] The Third Generation Partnership Project (3GPP) Technical Specification (TS) 23501, Clause 566, specifies that a Session Management Function (SMF) may receive a list of permitted Media Access Control (MAC) addresses for an Ethernet PDU session from a Data Network Authentication Authorization and Accounting (DN-AAA) server. This permitted MAC address list may contain up to sixteen MAC addresses. Additionally, Clause 5612 of TS 23501 specifies the configuration of filter rules by the SMF for a User Plane Function (UPF) through the provisioning of the permitted MAC addresses. Based on this configuration, the UPF discards user traffic when a source MAC address does not match a permitted MAC address.
[0010] However, existing implementations exhibit multiple technical limitations and operational inefficiencies. A first limitation arises from the dependency on secondary authentication and authorization procedures. Under current mechanisms, provisioning of permitted MAC addresses from the DN-AAA server to the SMF occurs only when secondary authentication and authorization are enabled for a subscriber associated with a Data Network Name (DNN) selected during PDU session establishment. Activation of secondary authentication and authorization requires execution of a detailed signaling exchange between the UE and the DN-AAA server to acquire the permitted MAC addresses. This signaling introduces additional latency, increases signaling overhead, and consumes network resources, resulting in operational inefficiency.
[0011] A second limitation concerns the handling of non-3GPP devices connected to a UE or a Fifth-Generation Residential Gateway (5G-RG). When a non-3GPP device attaches to the UE or 5G-RG, the UE may associate a Non-3GPP Device Identifier with the non-3GPP device for traffic requiring differentiated Quality of Service (QoS). For Ethernet PDU sessions, the UE provides the Non-3GPP Device Identifier and may additionally provide a corresponding MAC address and / or MAC address identifier to the SMF during a PDU session modification procedure.
[0012] Upon receiving a PDU session establishment request or modification request for an Ethernet PDU session containing a MAC address, the SMF performs validation of the MAC address against the permitted MAC address list received from the DN-AAA server. When the MAC address falls outside the permitted values, the SMF nonetheless accepts the PDU session procedure. The SMF then proceeds to invoke Session Management policy creation or update with a Policy Control Function (PCF) and initiates N4 session establishment or modification with the UPF, instructing packet discard at the user plane. Such processing results in avoidable signaling exchanges, unnecessary control-plane and user-plane resource utilization, and inefficient use of radio resources.
[0013] Accordingly, existing mechanisms for Ethernet PDU session management introduce avoidable complexity, signaling overhead, and inefficient resource consumption in Fifth Generation (5G) systems. Thus, it is desired to address the above-mentioned disadvantages, issues, or other shortcomings, or at least provide a useful alternative.
[0014] The principal object of the invention herein is to manage allowed MAC addresses in a telecommunication network.
[0015] Yet another object of the invention is to enable management and enforcement of allowed MAC addresses for the UE or 5G-RG for Ethernet PDU sessions, thereby ensuring controlled Layer-2 Ethernet connectivity within the telecommunication system.
[0016] Yet another object of the invention is to streamline handling of allowed MAC addresses and to improve efficiency in managing traffic associated with non-3GPP devices connected to the UE or a 5G-RG during Ethernet PDU sessions in the 5GS while reducing unnecessary control-plane and user-plane resource utilization.
[0017] Yet another object of the invention is to configure allowed MAC addresses for a subscriber in the UDM, thereby enabling per-subscriber MAC address handling for Ethernet PDU Sessions.
[0018] Yet another object of the invention is to enable per-subscriber MAC address handling independently of whether secondary authentication is enabled for the DNN, by storing the allowed MAC addresses in session management subscription data within the UDM.
[0019] Yet another object of the invention is to provide the allowed MAC addresses from the UDM to the SMF during the PDU session establishment, thereby enabling the SMF to instruct UPF to allow or discard traffic based on the allowed MAC addresses.
[0020] The method and device provided in the application improve the performance of CSI, improving the scheduling efficiency of the communication system.
[0021] Aspects of the present disclosure provide efficient communication methods in a wireless communication system.
[0022] These and other features, aspects, and advantages of the presentinventionare illustrated in the accompanying drawings, throughout which like reference letters indicate corresponding parts in the various figures. The embodiments herein will be better understood from the following description with reference to the drawings, in which:
[0023] FIG. 1A is a block diagram that illustrates a Unified Data Management (UDM) managing allowed Media Access Control (MAC) addresses in a telecommunication network according to embodiments disclosed herein
[0024] FIG. 1B is a block diagram that illustrates a Session Management Function (SMF) managing allowed MAC addresses in a telecommunication network according to embodiments disclosed herein.
[0025] FIG. 2A is a flow diagram that illustrates a method for managing allowed MAC addresses in the telecommunication network by a UDM apparatus according to embodiments disclosed herein.
[0026] FIG. 2B is a flow diagram that illustrates a method for managing allowed MAC addresses in the telecommunication network by SMF apparatus according to embodiments disclosed herein.
[0027] FIG. 3 is a sequence diagram that illustrates managing allowed MAC addresses by the SMF when the received MAC address does not match the allowed MAC addresses (Alternative 1) according to embodiments disclosed herein.
[0028] FIG. 4 illustrates a sequence diagram of a method for managing allowed MAC addresses by the SMF when the received MAC address does not match the allowed MAC addresses (Alternative 2) according to embodiments disclosed herein.
[0029] FIG. 5 is a sequence diagram that illustrates a method for managing MAC address mismatch according to embodiments disclosed herein.
[0030] FIG. 6 is a sequence diagram that illustrates a method for managing MAC address mismatch with selective device acceptance based on allowed MAC address validation for Ethernet PDU sessions according to embodiments disclosed herein.
[0031] FIG. 7 is a block diagram of a terminal or user equipment (UE) according to an embodiment of the disclosure.
[0032] FIG. 8 is a block diagram of a base station (BS) according to an embodiment of the disclosure.
[0033] FIG. 9 is a block diagram of a network entity according to an embodiment of the disclosure.
[0034] Hereinafter, embodiments of the disclosure will be described in detail with reference to the accompanying drawings.
[0035] In describing the embodiments, while numerous details are set forth for the purpose of illustration, it is understood that some aspects of the disclosure may be practiced with less than all of these details. Numerous variations and alternatives to the details provided herein are possible and are considered within the scope of the disclosure. In some instances, descriptions related to technical contents well-known in the art may be omitted so as to not obscure an understanding of the disclosure, and such omitted descriptions are understood to be within the scope of the disclosure.
[0036] For the same reason, in the accompanying drawings, some elements may be exaggerated, omitted, or schematically illustrated. Further, the size of each element does not completely reflect the actual size. In the drawings, identical or corresponding elements are provided with identical reference numerals or different reference numerals.
[0037] The advantages and features of the disclosure and ways to achieve them will be apparent by making reference to embodiments as described herein in detail in conjunction with the accompanying drawings. However, the disclosure is not limited to the embodiments set forth herein, but may be implemented in various different forms. Other features, aspects, and advantages of the subject matter described herein will become apparent from the disclosure. The following embodiments are merely examples to aid in an understanding of the disclosure and should not be construed to narrow the scope or spirit of the subject matter described herein in any way, but on the contrary, the disclosure covers all modifications, equivalents and alternatives falling within the spirit and scope of the subject matter as defined by the appended claims and equivalents thereof. Throughout the specification, the same or like reference numerals designate the same or like elements. Furthermore, terms which will be described herein are terms defined in consideration of the functions in the disclosure, and may be different according to users, intentions of the operators, or customs. Therefore, the definitions of the terms should be made based on the contents throughout the specification.
[0038] Herein, it will be understood that each block of flowchart illustrations, and combinations of blocks in the flowchart illustrations, may be performed based on computer program instructions. These computer program instructions may be loaded collectively onto at least one processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which perform through any one of, or in any combination of, the at least one processor of the computer or other programmable data processing apparatus, create means for performing the functions specified in the flowchart block(s). These computer program instructions may also be stored in a non-transitory computer usable or computer-readable memory that may direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer usable or computer-readable memory produce an article of manufacture including instruction means that perform the function specified in the flowchart block(s). The computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable data processing apparatus to produce a computer executed process such that the instructions that perform on the computer or other programmable data processing apparatus provide steps for executing the functions specified in the flowchart block(s).
[0039] Further, each block may represent a module, segment, or portion of code, which includes one or more executable instructions for executing the specified logical function(s). It should also be noted that in some alternative implementations, the functions noted in the blocks may occur out of the order. For example, two blocks(or functions) shown in succession may in fact be performed substantially concurrently or the blocks may sometimes be performed in the reverse order, depending upon the functionality involved.
[0040] As used in embodiments of the disclosure, a “~unit / module” may refer to a software element or a hardware element, such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC), which performs a predetermined function. However, the term including the word “~unit / module” does not always have a meaning limited to software or hardware. The “~unit / module” may be constructed either to be stored in an addressable storage medium or to execute one or more processors. Therefore, the “~unit / module” includes, for example, software elements, object-oriented software elements, components such as class elements and task elements, processes, functions, properties, procedures, sub-routines, segments of a program code, drivers, firmware, micro-codes, circuits, data, database, data structures, tables, arrays, and parameters. The components and functions provided by the “~unit / module” may be either combined into a smaller number of components and a “~unit / module,” or divided into additional components and a “~unit / module.” Moreover, the components and “~units / modules” may be implemented to reproduce one or more central processing units (CPUs) within a device or a security multimedia card. Further, in the embodiments, the “~unit / module” may include one or more processors.
[0041] The entirety of the one or more computer programs may be stored in a single memory device or the one or more computer programs may be divided with different portions stored in different multiple memory devices.
[0042] Any of the functions or operations described herein can be processed by one processor or a combination of processors. The one processor or the combination of processors is circuitry performing processing and includes circuitry like an application processor (AP, e.g. a CPU), a communication processor (CP, e.g., a modem), a graphics processing unit (GPU), a neural processing unit (NPU) (e.g., an artificial intelligence (AI) chip), a Wi-Fi chip, a Bluetooth® chip, a global positioning system (GPS) chip, a near field communication (NFC) chip, connectivity chips, a sensor controller, a touch controller, a finger-print sensor controller, a display driver integrated circuit (IC), an audio CODEC chip, a universal serial bus (USB) controller, a camera controller, an image processing IC, microprocessors, microcontrollers, digital signal processors, FPGA, ASIC, a microprocessor unit (MPU), a system on chip (SoC), an IC, or the like. The one processor or the combination of processors executes instructions that can be stored in a memory, such as the operating system, in order to control the overall operation of the device. Also, the one processor or the combination of processors is also capable of executing other processes and programs resident in the memory, such as processes for the disclosure.
[0043] It will be appreciated that various embodiments of the disclosure according to the claims and description in the specification can be realized in the form of hardware, software or a combination of hardware and software.
[0044] Any such software may be stored in non-transitory computer readable storage media. The non-transitory computer readable storage media store one or more computer programs (software modules), the one or more computer programs include computer-executable instructions that, when executed by one or more processors of an electronic device individually or collectively, cause the electronic device to perform a method of the disclosure. Additionally, or alternatively, such software may be a computer program [product] comprising instructions which, when executed by one or more processors of an electronic device individually or collectively, cause the electronic device to perform a method of the disclosure.
[0045] Any such software may be stored in the form of volatile or non-volatile storage such as, for example, a storage device like read only memory (ROM), whether erasable or rewritable or not, or in the form of memory such as, for example, random access memory (RAM), memory chips, device or integrated circuits or on an optically or magnetically readable medium such as, for example, a compact disk (CD), digital versatile disc (DVD), magnetic disk or magnetic tape or the like. It will be appreciated that the storage devices and storage media are various embodiments of non-transitory machine-readable storage that are suitable for storing a computer program or computer programs comprising instructions that, when executed, implement various embodiments of the disclosure. Accordingly, various embodiments of the present disclosure may provide a program comprising code for implementing apparatus or a method as claimed in any one of the claims of this specification and a non-transitory machine-readable storage storing such a program.
[0046] Hereinafter, the determination of priority between A and B in the present disclosure may refer to various actions such as selecting the one having a higher priority based on a predefined priority rule and performing an operation corresponding thereto, or omitting or dropping an operation corresponding to the one having a lower priority.
[0047] Hereinafter, "A or B" as described in the present disclosure may be understood as "A and / or B," which may include A, or B, or both A and B.
[0048] In addition, "at least one of A, B, and C" as described in the present disclosure may be understood to include A, or B, or C, or any combination of A, B, and C.
[0049] In addition, "at least one of A, B, or C" as described in the present disclosure may be understood to include A, or B, or C, or any combination of A, B, and C.
[0050] Furthermore, "A / B" as described in the present disclosure may be understood as "A and / or B," which may include A, or B, or both A and B.
[0051] Furthermore, "A, B" as described in the present disclosure may be understood as "A and / or B," which may include A, or B, or both A and B.
[0052] Furthermore, "A and B" as described in the present disclosure may be understood as "A and / or B," which may include A, or B, or both A and B.
[0053] Furthermore, “if condition A and condition B are satisfied,” as described in the present disclosure, may not be limited to a case where both condition A and condition B are satisfied, but may be understood to include a case where either condition A or condition B is individually satisfied, both condition A and condition B are satisfied, or one or more additional conditions are satisfied in combination.
[0054] Furthermore, throughout this disclosure, ordinal terms such as "first," "second," "third," etc., (and similar qualifiers) are used merely to distinguish between different instances, occurrences, configurations, messages, stages, elements or aspects of elements, operations, or information as described herein. Unless the context clearly dictates otherwise, the use of such ordinal terms does not itself require that the elements, operations, or information distinguished by these terms be structurally different, numerically distinct, or substantively dissimilar. For example, a "first signal" and a "second signal" may refer to instances of the same signal transmitted at different times or containing the same core information despite minor variations, or they may refer to signals with different content or characteristics, depending on the specific context. Similarly, a "first value" and a "second value" may represent the same magnitude but measured or applied in different circumstances, or they may represent different magnitudes. The interpretation should be guided by the specific technical context, function, and relationship described in the relevant portion of the specification and claims.
[0055] Furthermore, the terms “first ~”, “second ~”, etc., as described in the present disclosure with respect to various elements (e.g., information, objects, operation, sequences, or the like), should not limit those elements. These terms may only be intended to distinguish one element from another, and may not be intended to indicate a specific order. For example, a first element could be termed a second element, and, similarly, a second element could be termed a first element.
[0056] Furthermore, even if “first ~” and “second ~” are described in the present disclosure, it may be understood that element(s) referred to by “first ~” and “second ~” may be the same or different. For example, in case of element(s) being information, first information and second information may both be same information and, in some cases, are separate and different information.
[0057] In addition, the terms “if ~” and “in case that ~” as used in the disclosure or claims may be interpreted to include the meanings of “when (or upon) ~,” “in response to ~,” “based on ~,” or “according to ~,” and may be used interchangeably with these expressions. In addition, expressions other than those exemplified herein may also be used, as long as they have substantially the same meaning and do not impair the technical features of the present disclosure. If a method step (e.g. transmit a signal) is performed according to the disclosure of the application in connection with one of the above terms (such as “in case that ~” or the like), it may be interpreted to include the meanings (disclosure) of a prior determination that a feature has a specific state “~” (e.g. a bit length is above X), and then perform the method step in response to said determination.
[0058] For example, the physical layer signaling may be referred to as Layer 1 (L1) signaling and may include downlink control information (DCI). In addition, the higher layer signaling may include a medium access control (MAC) control message, a radio resource control (RRC) signaling message, a non-access stratum (NAS) signaling message, or an application layer message. The RRC signaling message may be referred to as L3 (layer 3) signaling. It should be noted, however, that the higher layer signaling is not limited to the aforementioned examples.
[0059] In addition, the term "not perform" as used in the present disclosure or claims may, in context, be understood to mean that the corresponding step is omitted or skipped. Such a term may be replaced with other terms having the same or substantially equivalent meaning.
[0060] In addition, "transmitting a message including A and B" as described in the present disclosure, may be understood as encompassing both (i) transmitting A and B in a single message, and (ii) transmitting A and B separately via multiple messages (e.g., transmitting a first message including A and a second message including B). This interpretation may also apply to messages that include two or more items (e.g., A, B, C), transmitted either together or separately.
[0061] In addition, "transmitting a message including A and transmitting a message including B" may also be interpreted as transmitting a message including A and B in a single message.
[0062] In the embodiments of the present disclosure described herein, terms or components included in the disclosure may be expressed in singular or plural form depending on the specific embodiments presented. However, such singular or plural expressions are selected appropriately for convenience of description, and the present disclosure is not limited to a singular or plural number of components. A component expressed in the plural form may be implemented as a single component, and a component expressed in the singular form may be implemented as multiple components.
[0063] The drawings or flowcharts described herein illustrate example methods that may be implemented according to the principles of the present disclosure, and various modifications may be made to the methods illustrated in the flowcharts of the present disclosure. For example, although illustrated as a series of steps, various steps in each drawing or flowchart may overlap, occur in parallel, occur in a different order, or be repeated. In other examples, any step may be omitted or replaced with another step.
[0064] The process of the flowchart may be performed by a device. One or more of the steps of the flowchart can be implemented by one or more processors / computer programs executing instructions to perform the noted functions.
[0065] The methods and apparatuses proposed in the embodiments of the present disclosure may be disclosed in connection with drawings disclosing flowcharts to illustrate example methods that may be implemented according to the principles of the present disclosure. Such flowcharts may contain different branches and / or sub-branches. It is understood that the principles of the present disclosure do not only contain the combination of all branches / sub-branches disclosed in the embodiment, but the present disclosure also contains at least one isolated branch / isolated sub-branch, in particular to a single branch / single sub-branch.
[0066] The methods and apparatuses proposed in the embodiments of the present disclosure are not limited to each embodiment individually, but may also be applied in combination of all or some of the embodiments proposed in the disclosure. Therefore, the embodiments of the present disclosure may be modified and applied without significantly departing from the scope of the present disclosure, as would be understood by those skilled in the art.
[0067] In this case, even if certain wordings are described differently across embodiments, they may be used interchangeably or in substitution or in combination if their underlying concepts are equivalent. For example, for the same or equivalent concept, even if one embodiment uses the expression "A" and another embodiment uses the expression "B", such expressions may be understood interchangeably, in substitution, or in combination.
[0068] The terms used in the following description to refer to access nodes, network entities, messages, interfaces between network entities, various types of identification information, and the like, are provided merely for the convenience of explanation by way of example. Therefore, the present disclosure is not limited to the terms describedherein, and other terms having equivalent technical meanings may also be used. Such terms may also be interchangeable with terms defined in any 3rd generation partnership project (3GPP) technical specifications (TS) or similar technical specifications, e.g., from the European telecommunications standards institute (ETSI), where appropriate.
[0069] Hereinafter, a base station (BS) is an entity that allocates resources to terminals, and may be at least one of a gNode B, an eNode B, a Node B, a wireless access unit, a BS controller, or a node on a network.
[0070] Furthermore, the base station of the present disclosure may include a split architecture comprising a central unit (CU) and a distributed unit (DU). In this structure, the CU is configured to process the higher layers of the control and user planes, while the DU is configured to process lower-layer radio resource functions. The embodiments of the present disclosure may be equally applicable to 5th generation (5G) base station architectures in which such CU and DU functional splits are implemented.
[0071] A terminal may include a user equipment (UE), a mobile station (MS), a cellular phone, a smartphone, a computer, a tablet, a wearable device, an Internet of Things (IoT) device, or any other device / system capable of performing communication functions.
[0072] In the disclosure, a downlink (DL) refers to a radio link through which a BS transmits a signal to a terminal, and an uplink (UL) refers to a radio link through which a terminal transmits a signal to a BS.
[0073] Furthermore, hereinafter, 5G mobile communication technologies (e.g., 5G new radio (NR)), 6th generation (6G) mobile communication technologies may be described by way of example, but the embodiments of the present disclosure may also be applied to other communication systems having similar technical backgrounds or channel types. For example, newly evolved mobile communication systems developed after 5G and 6G may be included. Furthermore, based on determinations by those skilled in the art, the embodiments of the present disclosure may also be applied to other communication systems (e.g., Wi-Fi systems) through some modifications without significantly departing from the scope of the present disclosure
[0074] In the following description, the terms physical channel and signal may be used interchangeably with data or control signal. For example, the term physical downlink shared channel (PDSCH) refers to a physical channel through which data is transmitted, but the term PDSCH may also be used to refer to the data itself. That is, in the present disclosure, the expression "transmit a physical channel" may be interpreted as being equivalent to the expression "transmit data or a signal via a physical channel."
[0075] Hereinafter, in the context of the present disclosure, higher layer signaling may refer to signaling corresponding to at least one or any combination of the following: master information block (MIB), system information block (SIB) or SIB M (M = 1, 2, ...), RRC, or MAC control element (CE), or a non-access stratum (NAS) signaling message, or an application layer message. The RRC signaling message may be referred to as Layer 3 (L3) signaling.
[0076] In addition, L1 signaling may refer to signaling corresponding to at least one or any combination of signaling techniques using the at least one or any combination of the following physical layer channels or signaling: physical downlink control channel (PDCCH), DCI, UE-specific DCI, group-common DCI, common DCI, scheduling DCI (e.g., DCI used for scheduling downlink or uplink data), non-scheduling DCI (e.g., DCI not used for scheduling downlink or uplink data) physical uplink control channel (PUCCH), or uplink control information (UCI). The L1 signaling message may be referred to as a physical layer signaling.
[0077] Hereinafter, the expression that information is configured by the BS, as used in the present disclosure or claims, may, in context, be understood to mean that the terminal receives the corresponding information from the BS via a physical layer signaling or a higher layer signaling. Such an expression may be replaced with other terms having the same or substantially equivalent meaning.
[0078] Hereinafter, the operational principle of the present disclosure will be described in detail with reference to the accompanying drawings.
[0079] The embodiments herein and the various features and advantageous details thereof are explained more fully with reference to the non-limiting embodiments that are illustrated in the accompanying drawings and detailed in the following description. Descriptions of well-known components and processing techniques are omitted so as to not unnecessarily obscure the embodiments herein. Also, the various embodiments described herein are not necessarily mutually exclusive, as some embodiments can be combined with one or more other embodiments to form new embodiments. The term “or” as used herein, refers to a non-exclusiveor, unless otherwise indicated. The examples used herein are intended merely to facilitate an understanding of ways in which the embodiments herein can be practiced and to further enable those skilled in the art to practice the embodiments herein. Accordingly, the examples are not be construed as limiting the scope of the embodiments herein.
[0080] As is traditional in the field, embodiments are described and illustrated in terms of blocks that carry out a described function or functions. These blocks, which referred to herein as managers, units, modules, hardware components or the like, are physically implemented by analog and / or digital circuits such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits and the like, and optionally be driven by firmware and software. The circuits, for example, be embodied in one or more semiconductor chips, or on substrate supports such as printed circuit boards and the like. The circuits constituting a block be implemented by dedicated hardware, or by a processor (e.g., one or more programmed microprocessors and associated circuitry), or by a combination of dedicated hardware to perform some functions of the block and a processor to perform other functions of the block. Each block of the embodiments be physically separated into two or more interacting and discrete blocks without departing from the scope of the proposed method. Likewise, the blocks of the embodiments be physically combined into more complex blocks without departing from the scope of the proposed method.
[0081] The accompanying drawings facilitate understanding of various technical features. The embodiments are not limited by these drawings and extend to any alterations, equivalents, and substitutes. Terms like first, second, etc., are used for distinction and do not limit the elements.
[0082] In an aspect, the objectives are achieved by providing a method for managing allowed Media Access Control (MAC) addresses in telecommunication network. Further, the method includes configuring, by a Unified Data Management (UDM) apparatus, allowed MAC addresses for a subscriber in session management (SM) subscription data. The allowed MAC addresses are stored in a subscription profile within the UDM apparatus for the subscriber. The allowed MAC addresses apply to Protocol Data Unit (PDU) sessions of Ethernet PDU Session type.Further, the method includes providing, by the UDM apparatus, the allowed MAC addresses from the subscription profile to a Session Management Function (SMF) during a PDU session establishment for the subscriber, wherein the allowed MAC addresses are provided when the PDU session type is determined to be the Ethernet type. Further, the method may include enabling, by the UDM apparatus, per-subscriber MAC address handling for Ethernet PDU Sessions independently of whether secondary authentication is enabled for a Data Network Name (DNN).
[0083] In an aspect, the objectives are achieved by providing a method for managing allowed MAC addresses in a telecommunication network. Further, the method includes receiving, by a Session Management Function (SMF) apparatus, the PDU session establishment request message during PDU session establishment. Further, the method includes determining, by the SMF apparatus, that a PDU session type of the PDU session establishment request message is an Ethernet type. Further, the method includes retrieving, by the SMF apparatus, one or more allowed MAC addresses for the PDU session when the PDU session type is determined to be the Ethernet type. Further, the method includes instructing, by the SMF apparatus, a User Plane Function (UPF) to allow or discard traffic received from the UE based on the one or more allowed MAC addresses.
[0084] In another aspect, the objectives are achieved by providing the SMF apparatus managing allowed MAC addresses in a telecommunication network. Further, the SMF apparatus includes a memory, a processor, and a network function controller. Further, the network function controller is coupled to the memory and the processor. The network function controller receives the PDU session establishment request message during PDU session establishment. Further, the network function controller determines that a PDU session type of the PDU session establishment request message is the Ethernet type. Further, the network function controller retrieves one or more allowed MAC addresses for the PDU session when the PDU session type is determined to be the Ethernet type. Further, the network function controller instructs the UPF to allow or discard traffic received from the UE based on the one or more allowed MAC addresses.
[0085] In another aspect, the objectives are achieved by providing UDM apparatus managing allowed MAC addresses in telecommunication network. Further, the UDM apparatus includes a memory, a processor and a network function controller. Further, the network function controller coupled to the memory and the processor. The network function controller configures allowed MAC addresses for a subscriber in SM subscription data. The allowed MAC addresses are stored in a subscription profile within the UDM apparatus for the subscriber. The allowed MAC addresses apply to PDU sessions of Ethernet PDU Session type. The network function controller provides the allowed MAC addresses from the subscription profile the SMF during a PDU session establishment for the subscriber. The allowed MAC addresses are provided when the PDU session type is determined to be the Ethernet type. Further, network function controller enables per-subscriber MAC address handling for Ethernet PDU Sessions independently of whether secondary authentication is enabled for the DNN.
[0086] These and other aspects of the embodiments herein will be better appreciated and understood when considered in conjunction with the following description and the accompanying drawings. It should be understood, however, that the following descriptions, while indicating preferred embodiments and numerous specific details thereof, are given by way of illustration and not of limitation. Many changes and modifications may be made within the scope of the embodiments herein, and the embodiments herein include all such modifications.
[0087] Further consider a scenario in which the UE initiates the PDU session towards a data network identified by a Data Network Name (DNN1) and associated with a network slice identified by S-NSSAI1. In such a scenario, the SMF may invoke the DNN-AAA server when secondary authentication and authorization for DNN1 is enabled for the UE. Upon successful secondary authentication and authorization, the DNN-AAA server provides information such as one or more allowed MAC addresses for the PDU session. In this manner, per-subscriber control of MAC address usage can be achieved. However, it is not necessary that all data networks, such as DNN1, are always configured to require secondary authentication and authorization.
[0088] Further, in deployments for e.g., Fixed Wireless Access (FWA) or wholesale Ethernet services, there is a need for operators to decide which subscribers require per-subscriber MAC address handling. Once the operator makes this determination, the allowed MAC addresses need to be configured appropriately in the network. This enables per-subscriber MAC address control without requiring secondary authentication and authorization to be enabled for all data networks.
[0089] Accordingly, it is proposed that allowed Media Access Control (MAC) addresses for a subscriber be configured in a Unified Data Management (UDM) entity. Similarly, a list of allowed Virtual Local Area Network (VLAN) tags for the subscriber may also be configured in the UDM entity. The SMF receives this information as part of Session Management subscription data while processing a PDU session establishment request triggered by the UE. Below is an example of a table for UE subscription data types in UDM to configure Allowed MAC address as per embodiment:
[0090]
[0091]
[0092]
[0093]
[0094]
[0095]
[0096]
[0097]
[0098]
[0099]
[0100] FIG. 1A is a block diagram that illustrates an UDM apparatus (101) managing allowed MAC addresses in a telecommunication network according to embodiments disclosed herein.
[0101] Examples of the UDM apparatus (101) can include, but are not limited to, Network Function Virtualization Infrastructure (NFVI) nodes, Cloud-based Network Functions, Virtualized Network Functions (VNFs), Physical Network Function appliances, Containerized Network Functions running on Container Orchestration Platforms (such as Kubernetes clusters), Edge Computing Nodes, Dedicated Subscriber Data Management Servers, 5G Core Network Elements deployed on Commercial Off-The-Shelf (COTS) hardware, Multi-access Edge Computing (MEC) hosts, Software-Defined Networking (SDN) controllers with data management capabilities, Network Slicing Management Functions, Telco Cloud Infrastructure components, Distributed Cloud Computing resources, On-premises Data Center appliances, Hybrid Cloud deployments combining private and public cloud resources, Bare-metal servers running Unified Data Management software, Virtual Machines (VMs) hosted on hypervisors (such as KVM, VMware, Hyper-V, etc.), Microservices-based architectures deployed on service mesh platforms, 5G Standalone (SA) core network functions, Network Equipment Provider appliances (such as Ericsson, Nokia, Huawei, Samsung network elements, etc.), Open-source network function implementations (such as Open5GS, free5GC, etc.), Centralized Subscription Data Repository systems, Home Subscriber Server (HSS) evolution platforms, Authentication Server Function (AUSF) integrated systems, Unified Data Repository (UDR) front-end functions, Cloud-native database management systems for subscriber data, Distributed ledger systems for subscription management, Policy Control Function (PCF) integrated data management nodes, and Customer Identity and Access Management (CIAM) integrated platforms.
[0102] Examples of the UE can include, but are not limited to, Consumer Electronics (such as Mobile Phones and Smartphones), Tablets, Wearable Devices, Television Computing Devices (such as Laptops, Notebooks, Desktops, Workstations, etc.), IoT Devices, Automotive Systems (such as connected cars, Autonomous Vehicles, Vehicle-to-Everything (V2X) communication devices, etc.), Enterprise Devices such as robotics, Specialized Equipment (such as Medical Devices, Public Safety Devices, etc.), Media Devices (such as Gaming Consoles, Streaming Devices, etc.).
[0103] Examples of the wireless communication network system include, but are not limited to, Cellular Networks (such as 2G, 3G, 4G, 5G, Beyond 5G (B5G) / 6G or advanced cellular networks), Local Area Networks (LANs) (such as Wi-Fi, Li-Fi, etc.), Personal Area Networks (PANs) (such as Bluetooth, Zigbee, Z-Wave, etc.), Wide Area Networks (WANs) (such as Satellite Communication Networks, Long Range Wide Area Network, Narrowband IoT, Low-bandwidth communication for IoT, etc.), Metropolitan Area Networks (MANs), Machine-to-Machine (M2M), Ad Hoc and Mesh Networks, Emerging and Advanced Networks. Examples of the UE can include, but are not limited to, Consumer Electronics (such as Mobile Phones and Smartphones), Tablets, Wearable Devices, Computing Devices (such as Laptops, Notebooks, Desktops, Workstations, etc.), IoT Devices, Automotive Systems (such as connected cars, Autonomous Vehicles, Vehicle-to-Everything (V2X) communication devices, etc.), Enterprise Devices such as robotics, Specialized Equipment (such as Medical Devices, Public Safety Devices, etc.), Media Devices (such as Gaming Consoles, Streaming Devices, etc.).
[0104] The UDM apparatus (101) includes the processor (102), the memory (104), an I / O interface (103), and a network function controller (105). The processor (1072) of the UDM apparatus (101) communicates with the memory (104), the I / O interface (103), and the network function controller (105). The processor (102) is configured to execute instructions stored in the memory (104) and to perform various processes. The processor (102) can include one or a plurality of processors, can be a general-purpose processor such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an Artificial Intelligence (AI) dedicated processor such as a neural processing unit (NPU).
[0105] Further, the memory (104) of the UDM apparatus (101) includes storage locations to be addressable through the processor (102). The memory (104) is not limited to a volatile memory and / or a non-volatile memory. Further, the memory (104) can include one or more computer-readable storage media. The memory (104) can include non-volatile storage elements. For example, non-volatile storage elements can include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. The memory (104) can store subscription profiles for subscribers including allowed MAC addresses, allowed VLAN tags, static IP address information, and Data Network Name (DNN) configurations. The memory (104) can further store session management subscription data associated with subscriber identifiers, Protocol Data Unit (PDU) session type information including Ethernet PDU Session type parameters, and Single Network Slice Selection Assistance Information (S-NSSAI) data. Additionally, the memory (104) can store VLAN handling information for VLAN tag insertion or removal operations, per-subscriber MAC address handling policies and configurations, and secondary authentication status information for Data Network Names (DNNs). The memory (104) can also store subscriber authentication and authorization credentials, subscription data retrieval protocols and procedures, and communication interfaces for Session Management Function (SMF) interactions.
[0106] The I / O interface (103) transmits the information between the memory (104) and external peripheral devices. . The peripheral devices are the input-output devices associated with the UDM apparatus (101). The I / O interface (103) receives several information from the UDM apparatus (101) and communicates with other network functions and entities within the 5G core network and external networks.
[0107] The network function controller (105) is coupled to the memory (104) and the processor (102). This coupling allows for efficient data transfer and communication between the components, ensuring that the Network Function Controller (105) can access and process subscription management data in real-time. The Network Function Controller (105) is an innovative integrated circuit that is implemented in the UDM apparatus (101). In an embodiment, the structure of such innovative integrated circuit includes a multi-core architecture that enables dynamic configuration of allowed MAC addresses for subscribers in session management subscription data, provisioning of allowed MAC addresses to SMF during PDU session establishment, and enabling of per-subscriber MAC address handling for Ethernet PDU sessions independently of secondary authentication requirements in the 5G network. Each core is optimized for specific tasks such as subscription profile creation and management, allowed MAC addresses configuration within subscription profiles, session management subscription data storage, SMF service request processing, allowed MAC addresses retrieval and provisioning, Ethernet PDU session type parameter handling, subscription data validation and consistency checking, DNN-specific allowed MAC addresses management, S-NSSAI-based subscription data organization, and per-subscriber MAC address handling enablement independent of secondary authentication status, etc. The innovative integrated circuit for the management of allowed Media Access Control (MAC) addresses in telecommunication network is made of a combination of analog and digital components designed to optimize the power consumption and performance of the subscription data management mechanism. The analog components include a low-noise amplifier and a high-precision analog-to-digital converter to ensure accurate signal processing. The digital components include a microcontroller unit (MCU) and a digital signal processor (DSP) that work in tandem to dynamically configure allowed MAC addresses for subscribers in session management subscription data stored in subscription profiles within the UDM apparatus, provide the allowed MAC addresses from the subscription profile to the Session Management Function (SMF) during PDU session establishment for the subscriber thereby enabling the SMF to retrieve the allowed MAC addresses when the PDU session type is determined to be the Ethernet type, enable per-subscriber MAC address handling for Ethernet PDU Sessions independently of whether secondary authentication is enabled for a Data Network Name (DNN), manage lists of allowed MAC addresses for PDU Sessions, store and provide static IP address information for DNNs and S-NSSAI, manage allowed VLAN tags for PDU Sessions, and handle operator configuration parameters for per-subscriber MAC address management.
[0108] Further, the Network Function Controller (105) configures allowed MAC addresses for a subscriber in session management (SM) subscription data. The allowed MAC addresses are stored in a subscription profile within the UDM apparatus (101) for the subscriber. The allowed MAC addresses apply exclusively to Protocol Data Unit (PDU) sessions of Ethernet PDU Session type. Further, the network function controller (105) provides the allowed MAC addresses from the subscription profile to a Session Management Function (SMF) during a PDU session establishment for the subscriber, thereby enabling the SMF to retrieve the allowed MAC addresses when the PDU session type is determined to be the Ethernet type. Further, the network function controller (105) enables per-subscriber MAC address handling for Ethernet PDU Sessions independently of whether secondary authentication is enabled for a Data Network Name (DNN).
[0109] Further, the network function controller (105) manages the allowed MAC addresses that comprise a list of allowed MAC addresses for the PDU Session.
[0110] Further, the network function controller (105) manages the subscription profile that further includes static IP address information for the DNN and Single Network Slice Selection Assistance Information (S-NSSAI). Further, the network function controller (105) manages allowed VLAN tags for the PDU Session, or VLAN handling information for VLAN tag insertion or removal in a User Plane Function (UPF).
[0111] Further, the network function controller (105) configures the allowed MAC addresses based on operator configuration parameters to provide per-subscriber MAC address handling.
[0112] FIG. 1B is a block diagram that illustrates an SMF apparatus (106) managing allowed MAC addresses in a telecommunication network according to embodiments disclosed herein. Examples of the SMF apparatus (106) can include, but are not limited to, Network Function Virtualization Infrastructure (NFVI) nodes, Cloud-based Network Functions, Virtualized Network Functions (VNFs), Physical Network Function appliances, Containerized Network Functions running on Container Orchestration Platforms (such as Kubernetes clusters), Edge Computing Nodes, Dedicated Session Management Servers, 5G Core Network Elements deployed on Commercial Off-The-Shelf (COTS) hardware, Multi-access Edge Computing (MEC) hosts, Software-Defined Networking (SDN) controllers with session management capabilities, Network Slicing Management Functions, Telco Cloud Infrastructure components, Distributed Cloud Computing resources, On-premises Data Center appliances, Hybrid Cloud deployments combining private and public cloud resources, Bare-metal servers running Session Management software, Virtual Machines (VMs) hosted on hypervisors (such as KVM, VMware, Hyper-V, etc.), Microservices-based architectures deployed on service mesh platforms, 5G Standalone (SA) core network functions, Network Equipment Provider appliances (such as Ericsson, Nokia, Huawei, Samsung network elements, etc.), Open-source network function implementations (such as Open5GS, free5GC, etc.), and Integrated Access and Backhaul (IAB) nodes with session management capabilities.
[0113] The SMF apparatus (106) includes the processor (107) , the memory (109) , an I / O interface (108), and a network function controller (110). The processor (107) of the SMF apparatus (106) communicates with the memory (109) , the I / O interface (108), and the network function controller (110) . The processor (107) is configured to execute instructions stored in the memory (109) and to perform various processes. The processor (107) can include one or a plurality of processors, can be a general-purpose processor such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an Artificial Intelligence (AI) dedicated processor such as a neural processing unit (NPU).
[0114] Further, the memory (109) of the SMF apparatus (106) includes storage locations to be addressable through the processor (107). The memory (109) is not limited to a volatile memory and / or a non-volatile memory. Further, the memory (109) can include one or more computer-readable storage media. The memory (109) can include non-volatile storage elements. For example, non-volatile storage elements can include magnetic hard discs, optical discs, floppy discs, flash memories, or forms of electrically programmable memories (EPROM) or electrically erasable and programmable (EEPROM) memories. The memory (109) may store various data structures, databases, lookup tables, session state information, allowed MAC address lists, subscription profile data, PDU session type information, Ethernet session configuration data, DN-AAA server authentication data, policy rules for MAC address filtering, Quality of Service (QoS) parameters, network slice information, subscriber data, and executable instructions for implementing the session management functionalities including MAC address validation and traffic filtering control of the SMF apparatus (106).
[0115] The I / O interface (108) transmits the information between the memory (109) and external peripheral devices. The peripheral devices are the input-output devices associated with the SMF apparatus (106). The I / O interface (108) receives several information from the SMF apparatus (106) and communicates with other network functions and entities within the 5G core network and external networks.
[0116] The Network function controller (110) is coupled to the memory (109) and the processor (107) . This coupling allows for efficient data transfer and communication between the components, ensuring that the Network function controller (110) can access and process session management data in real-time. The Network function controller (110) is an innovative integrated circuit that is implemented in the SMF apparatus (106). In an embodiment, the structure of such innovative integrated circuit includes a multi-core architecture that enables dynamic management of PDU session establishment, modification, and MAC address validation for Ethernet PDU sessions in the 5G network. Each core is optimized for specific tasks such as PDU session type identification, Ethernet type determination, allowed MAC address retrieval, MAC address comparison and validation, traffic filtering decision-making, UPF instruction generation, PDU session rejection handling, and policy enforcement for Ethernet traffic control, etc. The innovative integrated circuit for the management of MAC address-based session control in Ethernet PDU sessions in the 5G network is made of a combination of analog and digital components designed to optimize the power consumption and performance of the session management mechanism. The analog components include a low-noise amplifier and a high-precision analog-to-digital converter to ensure accurate signal processing. The digital components include a microcontroller unit (MCU) and a digital signal processor (DSP) that work in tandem to dynamically manage the PDU session requests, determine Ethernet PDU session types, and perform MAC address validation based on allowed MAC address lists obtained from the UDM function subscription profile, DN-AAA server authorization data, or locally configured data, and instruct the UPF apparatus to allow or discard traffic based on the MAC address filtering rules.
[0117] In an embodiment, the network function controller (110) receives the PDU session establishment request message during PDU session establishment. Further, the network function controller (110) determines that a PDU session type of the PDU session establishment request message is the Ethernet type. The determination may involve parsing the session establishment request to identify the session type field and verifying its value against predefined Ethernet type identifiers. Further, the network function controller (110) retrieves one or more allowed MAC addresses for the PDU session when the PDU session type is determined to be the Ethernet type. The retrieval process may involve querying a database or a network function that stores subscriber-specific MAC address information. Further, the network function controller (110) instructs the UPF (304) to allow or discard traffic received from the UE based on the one or more allowed MAC addresses. This instruction may be implemented through a policy enforcement mechanism within the UPF, which filters traffic based on the provided MAC address list.
[0118] Further, the Network function controller (110) retrieves the one or more allowed MAC addresses that are configured in a subscription profile within a Unified Data Management (UDM) function for a subscriber. The subscription profile may include various parameters such as QoS settings, service restrictions, and allowed MAC addresses. The one or more allowed MAC addresses are applied exclusively to PDU sessions of the Ethernet PDU Session type. This ensures that only authorized devices can participate in Ethernet-based PDU sessions, enhancing network security and resource management.
[0119] Further, the Network function controller (110) retrieves the one or more allowed MAC addresses that are associated with a subscriber and are configured in a subscription profile of the subscriber within the UDM function. The retrieval process may involve secure communication protocols to ensure data integrity and confidentiality. The one or more allowed MAC addresses being applicable only to PDU sessions of an Ethernet PDU Session type. This selective applicability helps in maintaining a clear distinction between different types of PDU sessions and their respective security policies.
[0120] Further, the Network function controller (110) accesses the one or more allowed MAC addresses that are associated with a subscriber and are configured in a subscription profile of the subscriber within the UDM function. The access mechanism may include authentication and authorization checks to prevent unauthorized access to sensitive subscriber data. The one or more allowed MAC addresses being applicable only to PDU sessions of an Ethernet PDU Session type. This targeted approach ensures that the security measures are specifically tailored to the requirements of Ethernet PDU sessions.
[0121] Further, the Network function controller (110) utilizes the one or more allowed MAC addresses that are configured in the subscription profile to enable subscriber-specific control of Ethernet traffic for the PDU session. This control mechanism may involve dynamic updates to the allowed MAC address list based on real-time network conditions and subscriber activity. The use of subscriber-specific MAC addresses helps in providing personalized network services and enhances the overall user experience.
[0122] In an embodiment, the Network function controller (110) is used for retrieving the one or more allowed MAC addresses. The retrieval process may involve multiple network functions and databases to ensure comprehensive and up-to-date information. Further, the Network function controller (110) receives first allowed MAC addresses from the UDM function. These MAC addresses are typically part of the subscriber's profile and are used for initial authentication and authorization. Further, the Network function controller (110) receives second allowed MAC addresses from the DN-AAA server in response to retrieving allowed MAC addresses information from both the UDM entity and the DN-AAA server. The DN-AAA server may provide additional MAC addresses based on dynamic network policies and secondary authentication procedures. In response to retrieving allowed MAC addresses information from both the UDM function and the DN-AAA server, the Network function controller (110) gives precedence to the allowed MAC addresses information received from the DN-AAA server. This precedence ensures that the most current and context-specific MAC address information is used for traffic management.
[0123] In an embodiment, the Network function controller (110) determines that the PDU session establishment request message is from the UE or a 5G Residential Gateway (5G-RG). This determination may involve analyzing the source identifiers and network context of the request message. Further, the Network function controller (110) identifies that the PDU session is for traffic of one or more non-3GPP devices connected to the UE or the 5G-RG. This identification may involve inspecting the payload of the request message to detect non-3GPP device identifiers. In an embodiment, the Network function controller (110) recognizes that the one or more non-3GPP devices require differentiated QoS. This recognition may be based on predefined QoS profiles associated with the non-3GPP devices, ensuring that their specific service requirements are met.
[0124] In an embodiment, the Network function controller (110) receives a MAC address from the UE or the 5G-RG in the PDU session establishment request message or in a PDU session modification request message. The MAC address may be included in a specific field within the request message, following a standardized format. Further, the Network function controller (110) compares the MAC address received from the UE or the 5G-RG with the one or more allowed MAC addresses. This comparison may involve a lookup operation in a local or remote database to verify the MAC address against the allowed list.
[0125] In an embodiment, the Network function controller (110) rejects the PDU session establishment request message or the PDU session modification request message when the MAC address received from the UE or the 5G-RG is not within the one or more allowed MAC addresses. The rejection process may involve sending a response message to the UE or 5G-RG, indicating the reason for rejection and any corrective actions that can be taken. This ensures that only authorized devices can establish or modify PDU sessions, enhancing network security.
[0126] In an embodiment, the Network function controller (110) receives the second allowed MAC addresses from the DN-AAA server when secondary authentication is enabled for the DNN. The secondary authentication process may involve additional security checks and validation steps to ensure the authenticity of the MAC addresses. This layered authentication approach provides an extra level of security for the network.
[0127] In an embodiment, the Network function controller (110) receives the first allowed MAC addresses from the UDM function as part of subscription data. The subscription data may include various attributes related to the subscriber's service plan and network access permissions. In an embodiment, the Network function controller (110) receives the second allowed MAC addresses from the DN-AAA server as part of authorization data. The authorization data may be dynamically generated based on real-time network policies and the subscriber's current activity, ensuring that the most relevant MAC addresses are used for traffic management.
[0128] Further, rejecting the PDU session establishment request message or the PDU session modification request message by the SMF apparatus (106) includes sending a reject message with a cause code to the UE or the 5G-RG. The cause code indicates that the MAC address is not within the one or more allowed MAC addresses. The cause code informs the UE or the 5G-RG that the MAC address is not allowed for the UE or the 5G-RG.
[0129] Further, the network function controller (110) configured in the SMF apparatus (106) sends the cause code that informs the UE or the 5G-RG that the MAC address is not allowed for the UE or the 5G-RG.
[0130] Further, the SMF apparatus (106) transmits the one or more allowed MAC addresses to the UE (301) or the 5G-RG while rejecting the PDU session establishment request message or the PDU session modification request message.
[0131] Further, the SMF apparatus (106) refrains from invoking a Policy Control Function (PCF) for Session Management (SM) policy creation or update and refrains from invoking the User Plane Function (UPF) (304) for N4 session establishment or modification when rejecting the PDU session establishment request message or the PDU session modification request message.
[0132] FIG. 2A is a flow diagram that illustrates a method for managing allowed MAC addresses in the telecommunication network by a UDM apparatus according to embodiments disclosed herein.
[0133] According to an embodiment, an operator may decide to provide per-subscriber MAC address handling for certain subscribers based on deployment requirements such as Fixed Wireless Access (FWA) services, wholesale Ethernet services, or vertical industry applications. Based on this operator decision, the UDM apparatus configures allowed MAC addresses in the subscription profile for the subscriber.
[0134] At step 201, the method includes configuring, by the UDM apparatus (101), allowed MAC addresses for the subscriber in the SM subscription data. The allowed MAC addresses are stored in a subscription profile within the UDM apparatus for the subscriber. The allowed MAC addresses apply to PDU sessions of Ethernet PDU Session type.
[0135] At step 202, the method includes providing, by the UDM apparatus (101), the allowed MAC addresses from the subscription profile to the SMF during the PDU session establishment for the subscriber. The allowed MAC addresses are provided when the PDU session type is determined to be the Ethernet type.
[0136] At step 203, the method includes enabling, by the UDM apparatus (101), per-subscriber MAC address handling for Ethernet PDU Sessions independently of whether secondary authentication is enabled for the DNN.
[0137] FIG. 2B is a flow diagram that illustrates a method for managing allowed MAC addresses in the telecommunication network according to embodiments disclosed herein.
[0138] At step 204, the method includes the SMF apparatus (106) receiving the PDU session establishment request message during PDU session establishment.
[0139] At step 205, the method includes the SMF apparatus (106) determining that a PDU session type of the PDU session establishment request message is an Ethernet type. The SMF apparatus (106) identifies that the PDU session is configured for handling Ethernet frames between the UE and the Data Network (DN).
[0140] At step 206, the method includes the SMF apparatus (106) retrieving one or more allowed MAC addresses for the PDU session when the PDU session type is determined to be the Ethernet type. The one or more allowed MAC addresses are retrieved from at least one of the UDM function as part of subscription data configured in a subscription profile of the subscriber or the DN-AAA server as part of authorization data when secondary authentication and authorization are enabled for the corresponding DNN. The SMF apparatus (106) stores the retrieved allowed MAC addresses in the Session Management (SM) context.
[0141] At step 207, the method includes the SMF apparatus (106) instructing the UPF (304) to allow or discard traffic received from the UE based on the one or more allowed MAC addresses. The SMF apparatus (106) (the term 'SMF apparatus' interchangeably referred as 'SMF') sets filter rules for the UPF (304) by providing the allowed MAC addresses, whereby the UPF (304) discards UE traffic if the source MAC address does not match the allowed MAC addresses.
[0142] FIG. 3 is a sequence diagram illustrating the management of allowed MAC addresses by the SMF when the received MAC address does not match the allowed MAC addresses (Alternative 1) according to embodiments disclosed herein. In one embodiment, the allowed MAC addresses are configured in the subscription profile within the UDM (101) function for the subscriber, as illustrated in FIG. 3. In another embodiment, when the SMF (106) receives the allowed MAC addresses from both the UDM function and the DN-AAA server (if secondary authentication is enabled for the DNN), the SMF prioritizes the allowed MAC addresses received from the DN-AAA server over those received from the UDM (101) function.
[0143] Consider a scenario where one or more non-3GPP devices are connected behind the UE (301) or 5G-RG. The UE (301) or 5G-RG initiates the PDU session establishment or modification procedure with the PDU session type set to Ethernet type for handling traffic from the non-3GPP devices that require differentiated QoS. The UE (301) or 5G-RG may transmit a MAC address to the SMF (106) during the PDU session establishment or modification request. The SMF (106) already possesses the allowed MAC addresses for the UE (301) or 5G-RG, which may be received from the DN-AAA server, the UDM (101) function, or obtained through other available means. When the SMF determines that the MAC address provided by the UE (301) or 5G-RG is not within the allowed MAC addresses, the SMF (106) rejects the PDU session establishment or modification procedure. Further, the traffic may also originate directly from the UE (301) or the 5G-RG, even when no non-3GPP devices are connected.
[0144] In another embodiment, the SMF (106) provides a suitable cause code to the UE or 5G-RG to inform that the PDU session establishment or modification has been rejected due to a mismatch between the received MAC address and the allowed MAC addresses. Additionally, the SMF (106) may provide the allowed MAC addresses to the UE (301) or 5G-RG while rejecting the PDU session establishment or modification procedure. Subsequently, if the UE (301) or 5G-RG desires, it can retry the PDU session establishment or modification procedure using an acceptable MAC address from among the allowed MAC addresses received from the SMF (106).
[0145] In another embodiment, the SMF (106) may not invoke the Policy Control Function (PCF) for any Session Management (SM) policy creation or update and does not invoke the UPF (304) for N4 session establishment or modification when rejecting the PDU session establishment or modification procedure due to MAC address mismatch.
[0146] At step S1, the UE (301) or 5G-RG initiates the PDU session establishment for the Ethernet PDU session. The SMF (106) has already received the allowed MAC address for the UE (301) or 5G-RG from the DN-AAA server, the Unified Data Management (UDM) (101), or by any other means and stored it in the Session Management (SM) context. At step S2, at least one non-3GPP device connected behind the UE (301) or 5G-RG needs differentiated QoS. The UE (301) or 5G-RG triggers PDU session modification and sends Device Identifier (Device ID), user plane information (user plane info), and MAC address identifier (MAC address ID) to the Access and Mobility Management Function (AMF) (303). At step S3, the AMF (303) invokes the SMF (106) and sends the PDU session modification request. At step S4, the SMF (106) identifies that the received MAC address from the UE (301) or 5G-RG is not within the allowed MAC address(es). At step S5, the SMF (106) rejects the PDU session modification by providing a suitable cause to the UE (301). It may also provide the allowed MAC address(es). The suitable cause code may indicate that the user plane info / MAC address provided by the UE (301) is not allowed for the UE (301). Alternatively, the SMF (106) may decide not to report the Non-3GPP Device Identifier information (Device ID, user plane info, and MAC address ID) by invoking SM policy update to the Policy Control Function (PCF) (305) and send PDU session modification accept. At step S6, the AMF (303) sends the PDU session modification reject message received from the SMF (106) to the UE (301).
[0147] FIG. 4 illustrates a sequence diagram of a method for managing allowed MAC addresses by the SMF (106) when the received MAC address does not match the allowed MAC addresses (Alternative 2) according to embodiments disclosed herein. At step S1, the UE (301) or 5G-RG initiates the PDU session establishment procedure for an Ethernet PDU session. The SMF (106) receives and stores the allowed MAC address for the UE (301) or 5G-RG from at least one of the DN-AAA servers, the UDM (101), or by any other available means in the SM context. At step S2, the non-3GPP device connected behind the UE (301) or 5G-RG requires differentiated Quality of Service (QoS). The UE (301) or 5G-RG triggers a PDU session modification request including Device Identifier (Device ID), user plane information, and MAC address identifier (MAC address ID) and transmits the request to the Access and Mobility Management Function (AMF) (303). At step S3, the AMF (303) invokes the SMF (106) by transmitting the PDU session modification request to update the SM context. The PDU session modification request includes the Device ID, user plane information, and MAC address ID. At step S4, the SMF (106) transmits a Session Management Policy modification request to the PCF (305). The request includes the Device ID, user plane information, and MAC address ID. The PCF (305) verifies whether the Device ID is subscribed for the UE's Subscription Permanent Identifier (SUPI) by retrieving subscription information from a User Data Repository (UDR) and transmits updated policies to the SMF (106). At step S5, the SMF (106) checks the allowed MAC address and determines that the MAC address received in the PDU session modification request (Step S2) is not within the allowed MAC addresses. The SMF (106) determines not to bind the Policy and Charging Control (PCC) rules to new or existing QoS flows associated with said MAC address, notwithstanding the indication from the PCF (305) that the Device ID is allowed for the UE (301). Accordingly, the SMF (106) determines not to update QoS rules to the UE (301) or Packet Detection Rules (PDR) / QoS Enforcement Rules (QER) to the UPF (304) associated with the MAC address ID that is not allowed. At step S6, the SMF (106) transmits a PDU session modification response to the AMF (303). The PDU Session Modification response includes the PDU Session Modification Command with no change to QoS rules for the Device ID and MAC address requested by the UE (301). At step S7, the AMF (303) transmits the PDU session modification command received from the SMF (106) to the UE (301). The PDU session modification command indicates no change in QoS rules.
[0148] In another scenario, when one or more non-3GPP devices are connected behind the UE (301) or 5G-RG, and the UE (301) or 5G-RG makes the PDU session establishment or modification with PDU session type set to Ethernet for the traffic of the non-3GPP devices that require differentiated QoS, the UE (301) or 5G-RG may send one or more MAC addresses to the Session Management Function (SMF) (106). The SMF (106) already has the allowed MAC addresses for the UE (301) or 5G-RG received from the UDM (101) or the DN-AAA server or by any other means. During this time, the SMF (106) checks and identifies that some of the non-3GPP device identifier associated MAC addresses are not within the allowed MAC addresses, whereas the remaining non-3GPP device identifier associated MAC addresses are within the allowed MAC addresses. Further, the SMF (106) provides only those non-3GPP Device Identifiers for which the MAC address is matched to the PCF (305) by invoking SM Policy update to get PCC rules. In another embodiment, the SMF (106) provides the PDU session modification command to the UE (301) by adding non-3GPP device identifier details for which QoS flow is added and also the non-3GPP device identifier where QoS flow is not added with a suitable cause that the associated MAC address is not within the allowed MAC address value. Also, the SMF (106) may provide the updated allowed MAC addresses to the UE (301) or 5G-RG.
[0149] FIG. 5 is a sequence diagram illustrating a method for managing MAC address mismatch according to embodiments disclosed herein. At step S1a, the UE (301) or 5G-RG initiates the PDU session establishment for the Ethernet PDU session. The UE (301) or 5G-RG communicates with the AMF (303) through the RAN (302) to establish the PDU session for handling Ethernet frames between the UE (301) and the DN. At step S1b, the SMF (106) has already received the allowed MAC address for the UE (301) or 5G-RG either from the DN-AAA server, the UDM (101), or by any other means and stored the allowed MAC address in the SM context. At step S2, the non-3GPP devices connected behind the UE (301) or 5G-RG need differentiated QoS. Thus, the UE (301) or 5G-RG triggers PDU session modification and sends device ID1, MAC address-1, and Device ID2, MAC address-2 to the AMF (303) (i.e., for two non-3GPP devices). The PDU session modification request is transmitted through the RAN (302) to the AMF (303) and includes user plane information associated with each Device Identifier to enable QoS differentiation for traffic from the respective non-3GPP devices. At step S3, the SMF (106) identifies that MAC address-2 is not within the allowed MAC address value. At step S4, the SMF (106) invokes the PCF (305) by sending SM Policy Update and provides only device ID-1 and receives Policy and Charging Control (PCC) rules from the PCF (305). The SMF (106) selectively provides only device ID-1 (for which MAC address-1 is within the allowed MAC addresses) to the PCF (305), thereby excluding Device ID-2 from policy establishment. The PCF (305) may verify the Device ID-1 subscription information from the User Data Repository (UDR) and returns updated PCC rules specifying QoS parameters, charging policies, and traffic handling rules for Device ID-1. At step S5, the SMF (106) invokes the UPF (304) by sending N4 session modification to allow packets for Device ID-1. The N4 session modification includes Packet Detection Rules (PDRs) to identify and filter traffic associated with Device ID-1 and MAC address-1 and QERs to apply the appropriate QoS treatment. The UPF (304) configures its packet forwarding and filtering mechanisms accordingly to handle traffic for Device ID-1 while blocking or not processing traffic for Device ID-2. At step S6, the SMF (106) sends a PDU session modification command with QoS rules for the device ID-1 and information about the device ID-2 with a suitable cause code that MAC address-2 is not within the allowed MAC address. The SMF (106) may also send an updated allowed MAC address value. The PDU session modification command includes QoS Flow Identifiers (QFIs), QoS parameters for Device ID-1, and explicitly indicates that no QoS flow is established for Device ID-2. The suitable cause code may be a standardized error code indicating that the user plane information or MAC address provided for Device ID-2 is not permitted for the UE (301). By providing the updated allowed MAC address values, the UE (301) or 5G-RG can retry the PDU session modification for Device ID-2 using an acceptable MAC address from the allowed list. At step S7, the AMF (303) sends a PDU session modification command to the UE (301). The AMF (303) forwards the PDU session modification command received from the SMF (106) to the UE (301) through the RAN (302) via Non-Access Stratum (NAS) signaling, completing the PDU session modification procedure.
[0150] The present invention relates to handling Ethernet PDU Sessions, specifically managing the allowed MAC address for the UE (301) in the 5GC.
[0151] FIG. 6 is a sequence diagram illustrating a method for managing MAC address mismatch with selective device acceptance based on allowed MAC address validation for Ethernet PDU sessions according to embodiments disclosed herein. At steps S1a and S1b, the UE (301) or 5G Residential Gateway (5G-RG) initiates the PDU session establishment for the Ethernet PDU session. The SMF (106) has already received the allowed MAC address for the UE (301) or 5G-RG either from the DN-AAA server, the UDM (101), or by any other means and stored it in the Session Management (SM) context. At step S2, the non-3GPP devices connected behind the UE (301) or 5G-RG need differentiated Quality of Service (QoS). Thus, the UE (301) or 5G-RG triggers PDU session modification and sends device ID1, MAC address-1, and Device ID2, MAC address-2 to the AMF (303) (i.e., for two non-3GPP devices). At step S3, the SMF (106) identifies that MAC address-2 is not within the allowed MAC address value. Further, at step S3a (option 1), the SMF (106) sends a PDU Session Modification Rejected message. At step S3b (option 1), the AMF (303) forwards the PDU Session Modification Rejected message to the UE (301). At step S4a (option 2), the SMF (106) invokes the PCF (305) by sending SM Policy Update and provides only Device ID-1. At step S4b (option 2), the PCF (305) sends the response with updated PCC rules to the SMF (106). At step S5, the SMF (106) invokes the UPF (304) by sending N4 session modification (PDRs to allow / block MAC address, updated QERs) to allow packets for device ID-1. At step S6, the SMF (106) sends the PDU session modification command to the AMF (303) with QoS rules for Device ID-1 (for which MAC address-1 is within the allowed MAC addresses) and information about Device ID-2 with a suitable cause code that MAC address-2 is not within the allowed MAC address. The suitable cause code indicates that the user plane information or MAC address provided for Device ID-2 is not permitted for the UE (301) or 5G-RG. The SMF (106) may also send an updated allowed MAC address value to enable the UE (301) or 5G-RG to retry the PDU session modification for Device ID-2 using an acceptable MAC address from the allowed list. At step S7, the AMF (303) sends the PDU session modification command to the UE (301) with QoS flows for the accepted non-3GPP device identifier (Device ID-1) and also includes the non-3GPP device identifier (Device ID-2) for which QoS flow is not added with a suitable cause of the associated MAC address not matching with the allowed MAC address. The command may also include the updated allowed MAC address values provided by the SMF (106).
[0152] FIG. 7 is a block diagram of a terminal or user equipment (UE) 700 according to an embodiment of the disclosure.
[0153] The terminal is an electronic device capable of wireless communication and having various form factors, examples of the terminal may include a UE, a mobile station (MS), a cellular phone, a smartphone, a computer, a tablet, a wearable device, an Internet of Things (IoT) device, or any other device / system capable of performing wireless communication with a base station (BS) and / or another terminal through a wireless channel.
[0154] Referring to FIG. 7, the UE 700 may include at least one transceiver (hereinafter, referred to as simply “transceiver”) 701, at least one processor (hereinafter, referred to as simply “processor”) 702, and at least one memory (hereinafter, referred to as simply “memory”) 703. According to at least one or a combination of methods corresponding to the embodiments described in the present disclosure, the transceiver 701, the processor 702, and the memory 703 of the UE 700 may operate. However, components of the UE 700 are not limited to the example components illustrated in FIG. 7. In another embodiment, the UE 700 may further include additional components in addition to the above-mentioned components, or some components may be omitted. Further, in some embodiments, any combination of the transceiver 701, the processor 702, or the memory 703 may be integrated in the form of one component.
[0155] The transceiver 701 may be a communication circuit or communication circuitry that enables the UE 700 to perform wireless communication with a node or an entity of a network. For example, the transceiver 701 may enable the UE 700 to transmit or receive a signal to or from a BS through cellular communication, or to transmit or receive a signal to or from another UE through cellular communication. For example, the transceiver 701 may support at least one of various cellular communication technologies including 3rd generation (3G), 4th generation (4G), long term evolution (LTE), 5th generation (5G) NR, 6th generation (6G), and various cellular wireless communication technologies supported by the transceiver (701) may include all subsequent generations of evolved wireless communications.
[0156] According to an embodiment, the UE 700 may include a plurality of transceivers. For example, in the case of supporting evolved-universal terrestrial radio access-new radio (E-UTRA-NR) dual connectivity (EN-DC), the UE 700 may include a first transceiver supporting the 4G LTE wireless communication and a second transceiver supporting the 5G NR wireless communication. According to another embodiment, in the case of supporting NR-dual connectivity (NR-DC), the UE 700 may include a plurality of transceivers supporting the 5G NR wireless communication. According to still another embodiment, in the case of supporting near field wireless communication, the UE 700 may separately include a transceiver supporting at least one standard in the group of wireless communication protocol standards as defined in the protocol standards for Bluetooth®, wireless local area network (WLAN) network (including institute of electrical and electronics engineers (IEEE) 802.11-2016 standard or its amendments, e.g., 802.11ah, 802.11ad, 802.11ay, 802.11ax, 802.11az, 802.11ba, and 802.11be, without being limited thereto).
[0157] According to an embodiment, the transceiver 701 may include various circuit structures used to transmit or receive signals to or from a BS through a wireless channel. The signals may include control information and data. For example, the transceiver 701 may include a radio frequency (RF) transmitter for up-converting and amplifying the frequency of a transmitted signal and an RF receiver for low-noise-amplifying a received signal and down-converting the frequency thereof. The transceiver 701 may output a signal received through a wireless channel to the processor 702 and may transmit, through a wireless channel, a signal output from the processor 702.
[0158] The processor 702 may control general operations of the UE 700 according to embodiments of the disclosure. The processor 702 may be implemented by one or more integrated circuit (or circuitry) (IC) chips and may execute various data processing operations. The processor 702 may include at least one electric circuit, and may execute instructions (or a program, codes, data, etc.) stored in the memory 703, individually, collectively or in any combination thereof. Further, the processor 702 may include a single-core processor or multi-core processor, and may include a processor assembly including a plurality of processing circuits (circuitry) according to a specific implementation scheme.
[0159] The processor 702 may be electrically, operatively, and / or communicatively coupled to the transceiver 701 to control the transceiver 701.
[0160] The processor 702 may include at least one processor (or processing circuitry), and the at least one processor may perform the following operations individually, collectively or in any combination thereof. For example, the processor 702 may include a communication processor (CP) configured to control communication operations and an application processor (AP) configured to control execution of an upper layer (for example, an application layer). In a specific embodiment, at least a part of the processor 702 may be included in one chip (or IC) and the other part of the processor 702 may be included in another chip (or IC). Otherwise, at least one processor may be included in another component, for example, the transceiver 701 or the memory 703.
[0161] The processor 702 may perform or control or cause an operation of the UE 700 for executing at least one or a combination of methods according to embodiments of the disclosure. For example, the processor 702 may control operations of the UE 700 for processing a downlink signal received from a BS or generating and transmitting an uplink signal to a BS. To this end, the processor 702 may execute a computer program, codes, or instructions stored in the memory 703, so as to control other components of the UE 700 to enable execution of various operations.
[0162] The memory 703 corresponds to a hardware storage device capable of temporarily or permanently storing information and may include one or more storage media. For example, the memory 703 may include a memory assembly including one or more storage media. For example, the one or more storage media may include permanent memory, such as a hard drive, flash memory, or read-only memory (ROM), semipermanent memory, such as random access memory (RAM), cache memory, or a combination thereof.
[0163] The memory 703 may be electrically, operatively, and / or communicatively coupled to the processor 702 and may be accessed by the processor 702.
[0164] The memory 703 may store a computer program, codes, or instructions executable by the processor 702. According to an embodiment, a computer program, codes, or instructions executable by the processor 702 may be either stored in a single memory device or separated and distributedly stored in two or more memory devices. By executing the instructions stored in the memory 703, the processor 702 may perform various functions according to an embodiment of the disclosure.
[0165] According to an embodiment of the disclosure, operations of the UE 700 may be caused to be performed based on execution of instructions (or a computer program or codes) stored in the memory 703 by at least one processor (or processing circuitry) configured to execute the same individually, collectively, or in any combination thereof, based on processing circuitry that is not configured to execute instructions, and / or based on components of processing circuitry that is not configured to execute instructions.
[0166] FIG. 8 is a block diagram of a base station (BS) 800 according to an embodiment of the disclosure.
[0167] The BS 800 may perform wireless communication with at least one user equipment (UE) located within the area of the BS 800 through a wireless channel. The BS 800 may perform communication with a node or an entity of a network through wired or wireless communication.
[0168] Referring to FIG. 8, the BS 800 may include at least one transceiver (hereinafter, referred to as simply “transceiver”) 801, at least one processor (hereinafter, referred to as simply “processor”) 802, and at least one memory (hereinafter, referred to as simply “memory”) 803. According to at least one or a combination of methods corresponding to the embodiments described in the present disclosure, the transceiver 801, the processor 802, and the memory 803 of the BS 800 may operate. However, components of the BS 800 are not limited to the example components illustrated in FIG. 8. In another embodiment, the BS 800 may further include additional components in addition to the above-mentioned components, or some components may be omitted. Further, in some embodiments, any combination of the transceiver 801, the processor 802, or the memory 803 may be integrated in the form of one component.
[0169] The transceiver 801 may be a communication circuit or communication circuitry that enables the BS 800 to perform wireless communication with a node or an entity of a network. For example, the transceiver 801 may enable the BS 800 to transmit or receive a signal to or from the UE X00 through cellular communication, or to transmit or receive a signal to or from another network entity through wireless communication. For example, the transceiver 801 may support various cellular communication technologies including 3rd generation (3G), 4th generation (4G), long term evolution (LTE), 5th generation (5G) NR, 6th generation (6G), and various cellular wireless communication technologies supported by the transceiver (801) may include all subsequent generations of evolved wireless communications. According to an embodiment, the transceiver 801 may include various circuit structures used to transmit or receive signals to or from a UE through a wireless channel. The signals may include control information and data. For example, the transceiver 801 may include a radio frequency (RF) transmitter for up-converting and amplifying the frequency of a transmitted signal and an RF receiver for low-noise-amplifying a received signal and down-converting the frequency thereof. The transceiver 801 may output a signal received through a wireless channel to the processor 802 and may transmit, through a wireless channel, a signal output from the processor 802.
[0170] Meanwhile, according to an embodiment of the present disclosure, the BS 800 may perform communication with a node or an entity of a network through wired or wireless communication. For example, the BS 800 may perform wired or wireless communication with an adjacent BS, or a node or an entity of a core network through a backhaul network. Although not illustrated in FIG. 8, when the BS 800 performs wired communication, the BS 800 may further include a separate network interface for wired communication in addition to the transceiver 801. The network interface may be referred to as network interface circuitry or communication interface circuitry.
[0171] The processor 802 may control general operations of the BS 800 according to embodiments of the disclosure. The processor 802 may be implemented by one or more integrated circuit (or circuitry) (IC) chips and may execute various data processing operations. The processor 802 may include at least one electric circuit, and may execute instructions (or a program, codes, data, etc.) stored in the memory 803, individually, collectively or in any combination thereof. Further, the processor 802 may include a single-core processor or multi-core processor, and may include a processor assembly including a plurality of processing circuits (circuitry) according to a specific implementation scheme.
[0172] The processor 802 may be electrically, operatively, and / or communicatively coupled to the transceiver 801 to control the transceiver 801.
[0173] The processor 802 may include at least one processor (or processing circuitry), and the at least one processor may perform the following operations individually, collectively or in any combination thereof. In a specific embodiment, at least a part of the processor 802 may be included in one chip (or IC) and the other part of the processor 802 may be included in another chip (or IC). Otherwise, at least one processor may be included in another component, for example, the transceiver 801 or the memory 803.
[0174] The processor 802 may perform or control or cause an operation of the BS 800 for executing at least one or a combination of methods according to embodiments of the disclosure. For example, the processor 802 may control operations of the BS 800 for generating and transmitting a downlink signal to a UE or processing an uplink signal received from a UE. Otherwise, the BS 800 may transmit or receive a signal to or from a neighboring BS, transfer a signal received from a UE to an upper node of the network, or transmit a signal transferred from an upper node of the network to a UE. To this end, the processor 802 may execute a computer program, codes, or instructions stored in the memory 803, so as to control other components of the BS 800 to enable execution of various operations.
[0175] The memory 803 corresponds to a hardware storage device capable of temporarily or permanently storing information and may include one or more storage media. For example, the memory 803 may include a memory assembly including one or more storage media. For example, the one or more storage media may include permanent memory, such as a hard drive, flash memory, or read-only memory (ROM), semipermanent memory, such as random access memory (RAM), cache memory, or a combination thereof.
[0176] The memory 803 may be electrically, operatively, and / or communicatively coupled to the processor 802 and may be accessed by the processor 802.
[0177] The memory 803 may store a computer program, codes, or instructions executable by the processor 802. According to an embodiment, a computer program, codes, or instructions executable by the processor 802 may be either stored in a single memory device or separated and distributedly stored in two or more memory devices. By executing the instructions stored in the memory 803, the processor 802 may perform various functions according to an embodiment of the disclosure.
[0178] According to an embodiment of the disclosure, operations of the BS 800 may be caused to be performed based on execution of instructions (or a computer program or codes) stored in the memory 803 by at least one processor (or processing circuitry) configured to execute the same individually, collectively, or in any combination thereof, based on processing circuitry that is not configured to execute instructions, and / or based on components of processing circuitry that is not configured to execute instructions.
[0179] The UE or the base station may perform various communication procedures related to the control plane or the user plane by cooperating with one or more network entities based on wireless communication. For example, the UE may communicate with a network entity (for example, an Access and Mobility Management Function (AMF), a Session Management Function (SMF), rtc.) via the base station, or the base station may perform at least one communication procedure by directly transmitting and receiving signals to / from, or relaying signals between, the network entities.
[0180] The structure of the above-described network entity will be described in more detail with reference to the drawings.
[0181] FIG. 9 is a block diagram of a network entity 900 according to an embodiment of the disclosure. The network entity 900 of FIG. 9 may correspond to the UDM apparatus of FIG. 1A or the SMF apparatus of FIG. 1B.
[0182] The network entity 900 may include an entity (apparatus, device, or server, etc.) that performs one or more network functions (NFs) or a part of a network function constituting a core network (e.g., a 5th generation (5G) core (5GC)) in a communication system. In this case, multiple NFs may be implemented within a single network entity, or a single NF may be distributed and implemented across a plurality of network entities. In addition, when an NF is implemented within the network entity, the NF may be implemented in the form of software, and in such a case, a program for operating the NF may be stored in memory of the network entity 900.
[0183] A single NF may be implemented by one or more instances, which may be deployed on the same network entity or distributed across multiple network entities to operate. The instance may be a software unit that logically executes a specific network function, and may be implemented in a form that is decoupled from physical hardware resources. Further, one or more NFs may be implemented in the form of one network slice to operate to satisfy specifications required by a particular service.
[0184] The NF may include at least one of an access and mobility management function (AMF), a session management function (SMF), a local session management function (L-SMF), a user plane function (UPF), a local user plane function (L-UPF), a policy control function (PCF), a unified data management (UDM), a unified data repository (UDR), a network exposure function (NEF), a network repository function (NRF), an application function (AF), a network slice selection function (NSSF), a network data analytics function (NWDAF), a network slice admission control function (NSACF), an authentication server function (AUSF), or a data network (DN), etc.
[0185] Referring to FIG. 9, the network entity 900 may include at least one network interface 901, at least one processor 902 (hereinafter, “processor”), and at least one memory 903 (hereinafter, “memory”). As described above, a NF may be implemented in the form of a physical device such as the network entity 900, or may be virtualized and executed in the form of an instance. When implemented as an instance, the NF need not necessarily include physical components as illustrated in FIG. 9. In such a case, the instance may be logically represented as comprising one or more logical functional elements.
[0186] According to at least one or a combination of methods corresponding to the embodiments described in the present disclosure, the network interface 901, the processor 902, and the memory 903 of the network entity 900 may operate. However, components of the network entity 900 are not limited to the example components illustrated in FIG. 9. In another embodiment, the network entity 900 may further include additional components in addition to the above-mentioned components, or some components may be omitted. Further, in an embodiment, the network interface 901, the processor 902, or the memory 903 may be integrated in the form of one component.
[0187] The network interface 901 is a collective term for a transmitter part of the network entity 900 and a receiver part of the network entity 900, and may be a communication circuit for transmitting or receiving a signal to or from a user equipment (UE), a base station (BS), or another network entity. Here, the communication circuit may include both a communication circuit for wireless communication and a communication circuit for a wired communication. For example, the network interface 901 may include a circuit, logic, hardware, etc., configured to exchange a control plane message or a user plane message with a UE, a BS, or other core network entities through wireless communication or wired communication. The network interface 901 may operate using various protocols (e.g., non-access stratum (NAS) protocol). The network interface 901 may also be referred to, for convenience of description or depending on implementation, as communication circuitry, network interface circuitry, or a communication interface circuitry.
[0188] The processor 902 may control general operations of the network entity 900 according to embodiments of the disclosure. The processor 902 may be implemented by one or more integrated circuit (or circuitry) (IC) chips and may execute various data processing operations. The processor 902 may include at least one electric circuit, and may execute instructions (or a program, codes, data, etc.) stored in the memory 903, individually, collectively or in any combination thereof. Further, the processor 902 may include a single-core processor or multi-core processor, and may include a processor assembly including a plurality of processing circuits (circuitry) according to a specific implementation scheme. Further, it should be noted that, according to another embodiment, in a case where NF is implemented in the form of an instance, the network function may be not necessarily configured by physical hardware.
[0189] According to an embodiment, the processor 902 may be electrically, operatively, and / or communicatively coupled to the network interface 901 to control the network interface 901.
[0190] The processor 902 may include at least one processor (or processing circuitry), and the at least one processor may perform the following operations individually, collectively or in any combination thereof. In a specific embodiment, at least a part of the processor 902 may be included in one chip (or IC) and the other part of the processor 902 may be included in another chip (or IC). Otherwise, at least one processor may be included in another component, for example, the network interface 901 or the memory 903.
[0191] The processor 902 may perform or control or cause an operation of the network entity 900 for executing at least one or a combination of methods according to embodiments of the disclosure. For example, the processor 902 may control operations of the network entity 900 for exchanging a control plane message or a user plane message with a UE, a BS, or other core network entities through wireless or wired communication, using various protocols (e.g., NAS protocol). To this end, the processor 902 may execute a computer program, codes, or instructions stored in the memory 903, so as to control other components of the network entity 900 to enable execution of various operations.
[0192] The memory 903 corresponds to a hardware storage device capable of temporarily or permanently storing information and may include one or more storage media. For example, the memory 903 may include a memory assembly including one or more storage media. For example, the one or more storage media may include permanent memory, such as a hard drive, flash memory, or read-only memory (ROM), semipermanent memory, such as random access memory (RAM), cache memory, or a combination thereof.
[0193] The memory 903 may be electrically, operatively, and / or communicatively coupled to the processor 902 and may be accessed by the processor 902.
[0194] The memory 903 may store a computer program, codes, or instructions executable by the processor 902. According to an embodiment, a computer program, codes, or instructions executable by the processor 902 may be either stored in a single memory device or separated and distributedly stored in two or more memory devices. By executing the instructions stored in the memory 903, the processor 902 may perform various functions according to an embodiment of the disclosure.
[0195] According to an embodiment of the disclosure, operations of the network entity 900 may be caused to be performed based on execution of instructions (or a computer program or codes) stored in the memory 903 by at least one processor (or processing circuitry) configured to execute the same individually, collectively, or in any combination thereof, based on processing circuitry that is not configured to execute instructions, and / or based on components of processing circuitry that is not configured to execute instructions.
[0196] Meanwhile, although specific embodiments of the present disclosure have been described in detail, various modifications may be made without departing from the scope of the present disclosure. Therefore, the scope of the present disclosure should not be limited to the described embodiments, but should be defined by the claims and equivalents thereof.
[0197] The foregoing description of the specific embodiments will so fully reveal the general nature of the embodiments herein that others can, by applying current knowledge, readily modify and / or adapt for various applications such specific embodiments without departing from the generic concept, and, therefore, such adaptations and modificationsshouldand are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Therefore, while the embodiments herein have been described in terms of preferred embodiments, those skilled in the art will recognize that the embodiments herein can be practiced with modification within the scope of the embodiments as described herein.
Claims
1.A method performed by a session management function (SMF) entity, the method comprising:receiving, from a unified data management (UDM) entity, a first list of allowed medium access control (MAC) addresses for a protocol data unit (PDU) session,wherein the first list of allowed MAC addresses applies only for PDU sessions of ethernet PDU session.2.The method of claim 1, further comprising:receiving, from a data network (DN)-authentication authorization and accounting (AAA) server, a second list of allowed MAC addresses.3.The method of claim 2, wherein the second list of allowed MAC addresses takes precedence over the first list of allowed MAC addresses.4.The method of claim 1, wherein the first list of allowed MAC addresses is included in subscription data.5.The method of claim 2, further comprising:receiving, from a user equipment (UE), a request message for a PDU session type set to ethernet, wherein the request message includes a MAC address.6.The method of claim 5, further comprising:identifying that the MAC address is not within allowed MAC address in the first list and the second list.7.The method of claim 6, further comprising:transmitting, to the UE, a response message for rejecting the request message.8.A session management function (SMF) entity comprising:at least one processor; andat least one memory, communicatively coupled to the at least one processor, storing instructions executable by the at least one processor individually or in any combination to cause the SMF entity toreceive, from a unified data management (UDM) entity, a first list of allowed medium access control (MAC) addresses for a protocol data unit (PDU) session,wherein the first list of allowed MAC addresses applies only for PDU sessions of ethernet PDU session.9.The SMF entity of claim 8, wherein the instructions further cause the SMF entity to:receive, from a data network (DN)-authentication authorization and accounting (AAA) server, a second list of allowed MAC addresses.10.The SMF entity of claim 9, wherein the second list of allowed MAC addresses takes precedence over the first list of allowed MAC addresses.11.The SMF entity of claim 8, wherein the first list of allowed MAC addresses is included in subscription data.12.The SMF entity of claim 9, wherein the instructions further cause the SMF entity to:receive, from a user equipment (UE), a request message for a PDU session type set to ethernet, wherein the request message includes a MAC address.13.The SMF entity of claim 12, wherein the instructions further cause the SMF entity to:identify that the MAC address is not within allowed MAC address in the first list and the second list.14.The SMF entity of claim 13, wherein the instructions further cause the SMF entity to:transmit, to the UE, a response message for rejecting the request message.15.One or more non-transitory computer-readable storage media storing computer-executable instructions that, when executed by at least one processor of a session management function (SMF) entity individually or collectively, cause the SMF entity to perform operations, the operations comprising:receiving, from a unified data management (UDM) entity, a first list of allowed medium access control (MAC) addresses for a protocol data unit (PDU) session,wherein the first list of allowed MAC addresses applies only for PDU sessions of ethernet PDU session.