5G UPF Dynamic ACLs for Mobile-to-Mobile Traffic Blocking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing 5G mobile core deployments face complexity in managing mobile-to-mobile (M2M) communications, particularly for IoT devices, due to unstructured mobile IP address ranges and the need for extensive Access Control Lists (ACLs, which become cumbersome and time-consuming to maintain.
Innovation Solution
Implementing a dynamic Access Control List (ACL) generation mechanism at the User Plane Function (UPF) using the Network Repository Function (NRF) to manage M2M communications by utilizing mobile IP address subnets, allowing each UPF to dynamically create and apply ACLs based on IP address subnets provided by the NRF.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static Access Control Lists (ACLs) are used to restrict mobile-to-mobile communications, then security requirements are met, but the complexity and time required to maintain ACLs increases significantly
Solution Approach 1:
The patent implements dynamic ACL generation at the UPF by subscribing to NRF notifications about IP address subnet changes. The system automatically updates ACLs in real-time based on network state changes, replacing static manual configuration with dynamic automated management. This resolves the contradiction by maintaining security (reliability) while eliminating the complexity of manual ACL maintenance through automation and real-time adaptation.
Solution Approach 2:
The UPF is configured to autonomously generate and update its own ACLs by subscribing to NRF notifications and automatically processing IP address subnet information. The system performs self-service ACL management without requiring external manual intervention, reducing operational complexity while maintaining security requirements through automated real-time updates.
2Reliability
If extensive Access Control Lists (ACLs) are deployed to block all mobile-to-mobile traffic, then security is enhanced, but operational overhead and maintenance time increase
Solution Approach 1:
The UPF subscribes in advance to NRF notifications about IP address subnet changes. When changes occur, the system automatically generates and applies updated ACLs without manual intervention. This preliminary subscription mechanism ensures security is maintained while eliminating time-consuming manual ACL maintenance, as the system proactively responds to network changes automatically.
Solution Approach 2:
The system establishes a feedback loop where the UPF continuously monitors NRF for IP address subnet changes and automatically updates ACLs in response. This real-time feedback mechanism ensures security requirements are met while eliminating maintenance time, as the system self-corrects and adapts automatically without human intervention.
3Manufacturing precision
If manual ACL configuration is used for each mobile IP address range, then precise control is achieved, but the number of ACLs becomes unmanageable
Solution Approach 1:
The patent merges multiple individual ACL entries into a single dynamic ACL generation process. Instead of manually configuring separate ACLs for each mobile IP address range, the UPF subscribes to NRF notifications and automatically generates comprehensive ACLs that cover all IP address subnets. This merging approach maintains precise traffic control while reducing the number of ACLs from unmanageable to a single automated configuration.
Solution Approach 2:
The UPF implements a universal ACL generation mechanism that handles all mobile IP address ranges through a single subscription to NRF notifications. This multi-functional approach replaces numerous specific manual ACL configurations with one automated system that universally manages all IP address subnets, maintaining precision while eliminating the complexity of managing multiple individual ACLs.
Data Source
AI summary
In one aspect, a method includes generating, using a User Plane Function (UPF) of a core element of a network, a query to retrieve information associated with one or more Data Network Names (DNNs) configured in at least one other UPF in the network; transmitting the query to a Network Repository Function (NRF); receiving a response from the NRF, the response including IP address subnets of the at least one other UPF associated with the one or more DNNs; dynamically generating an Access Control List (ACL) to block mobile-to-mobile communication between User Equipment (UEs) in the network, using the IP address subnets received as part of the response, wherein each of the UEs is assigned an IP address from among the IP address subnets; and blocking M2M communication using the ACL dynamically generated.


