5G UPF Dynamic ACLs for Mobile-to-Mobile Traffic Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G mobile core deployments face complexity in managing mobile-to-mobile (M2M) communications, particularly for IoT devices, due to unstructured mobile IP address ranges and the need for extensive Access Control Lists (ACLs, which become cumbersome and time-consuming to maintain.

Innovation Solution

Implementing a dynamic Access Control List (ACL) generation mechanism at the User Plane Function (UPF) using the Network Repository Function (NRF) to manage M2M communications by utilizing mobile IP address subnets, allowing each UPF to dynamically create and apply ACLs based on IP address subnets provided by the NRF.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static Access Control Lists (ACLs) are used to restrict mobile-to-mobile communications, then security requirements are met, but the complexity and time required to maintain ACLs increases significantly

Engineering Contradiction:
Improvesecurity requirementVSAvoidACL management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic ACL generation at the UPF by subscribing to NRF notifications about IP address subnet changes. The system automatically updates ACLs in real-time based on network state changes, replacing static manual configuration with dynamic automated management. This resolves the contradiction by maintaining security (reliability) while eliminating the complexity of manual ACL maintenance through automation and real-time adaptation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The UPF is configured to autonomously generate and update its own ACLs by subscribing to NRF notifications and automatically processing IP address subnet information. The system performs self-service ACL management without requiring external manual intervention, reducing operational complexity while maintaining security requirements through automated real-time updates.

Inventive Principle:
Principle #25Self-service

2Reliability

If extensive Access Control Lists (ACLs) are deployed to block all mobile-to-mobile traffic, then security is enhanced, but operational overhead and maintenance time increase

Engineering Contradiction:
ImprovesecurityVSAvoidmaintenance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The UPF subscribes in advance to NRF notifications about IP address subnet changes. When changes occur, the system automatically generates and applies updated ACLs without manual intervention. This preliminary subscription mechanism ensures security is maintained while eliminating time-consuming manual ACL maintenance, as the system proactively responds to network changes automatically.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes a feedback loop where the UPF continuously monitors NRF for IP address subnet changes and automatically updates ACLs in response. This real-time feedback mechanism ensures security requirements are met while eliminating maintenance time, as the system self-corrects and adapts automatically without human intervention.

Inventive Principle:
Principle #23Feedback

3Manufacturing precision

If manual ACL configuration is used for each mobile IP address range, then precise control is achieved, but the number of ACLs becomes unmanageable

Engineering Contradiction:
Improvetraffic control precisionVSAvoidnumber of ACLs
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent merges multiple individual ACL entries into a single dynamic ACL generation process. Instead of manually configuring separate ACLs for each mobile IP address range, the UPF subscribes to NRF notifications and automatically generates comprehensive ACLs that cover all IP address subnets. This merging approach maintains precise traffic control while reducing the number of ACLs from unmanageable to a single automated configuration.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The UPF implements a universal ACL generation mechanism that handles all mobile IP address ranges through a single subscription to NRF notifications. This multi-functional approach replaces numerous specific manual ACL configurations with one automated system that universally manages all IP address subnets, maintaining precision while eliminating the complexity of managing multiple individual ACLs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250301396A1Restrict mobile to mobile communication dynamically in 5g user plane function
Publication Date: 2025.09.25 CISCO TECHNOLOGY INC
  • US20250301396A1 patent drawing
  • US20250301396A1 patent drawing
  • US20250301396A1 patent drawing

AI summary

In one aspect, a method includes generating, using a User Plane Function (UPF) of a core element of a network, a query to retrieve information associated with one or more Data Network Names (DNNs) configured in at least one other UPF in the network; transmitting the query to a Network Repository Function (NRF); receiving a response from the NRF, the response including IP address subnets of the at least one other UPF associated with the one or more DNNs; dynamically generating an Access Control List (ACL) to block mobile-to-mobile communication between User Equipment (UEs) in the network, using the IP address subnets received as part of the response, wherein each of the UEs is assigned an IP address from among the IP address subnets; and blocking M2M communication using the ACL dynamically generated.