NAT Traversal for SMF and UPF Communication in 5G Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies face challenges in successfully bridging the control plane and user plane functions in mobile networks, particularly when Session Management Function (SMF) or User Plane Function (UPF) are deployed behind Network Address Translation (NAT) firewalls, due to issues with IP addresses and port usage.

Innovation Solution

The proposed solution involves configuring SMF and UPF instances to communicate through NAT services using techniques such as introducing Fully Qualified Domain Names (FQDN) into the Fully-qualified Session Endpoint Identifier (F-SEID), utilizing non-standard ports for PFCP and GTP-U messages, and employing an Application Level Gateway (ALG) to proxy functions across NAT services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If SMF or UPF is deployed behind NAT firewall using standard IP addresses and ports, then deployment flexibility is improved, but communication reliability between control plane and user plane deteriorates

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidcommunication reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a NAT traversal mechanism that acts as an intermediary between the SMF and UPF components deployed behind NAT firewalls. This mechanism enables indirect communication by resolving the IP address mismatch problem caused by NAT translation, allowing the control plane and user plane to communicate reliably despite being separated by NAT boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent modifies the communication parameters by introducing alternative identification methods beyond standard IP addresses and ports. By changing how endpoints are identified and reached (through NAT traversal techniques), the system maintains communication reliability while allowing flexible deployment behind NAT firewalls.

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If F-SEID uses IP address of N4 interface as identifier, then identification simplicity is improved, but NAT traversal capability deteriorates

Engineering Contradiction:
Improveidentification simplicityVSAvoidNAT traversal capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the identification mechanism by separating the logical endpoint identification from the physical IP address. The F-SEID is divided into components that can be independently resolved, allowing the identifier to remain simple while the resolution process handles NAT traversal through multiple stages of address resolution and mapping.

Inventive Principle:
Principle #1Segmentation

3Device complexity

If GTP-U tunnel uses same IP addresses as N4 interface, then configuration simplicity is improved, but communication reliability behind NAT deteriorates

Engineering Contradiction:
Improveconfiguration simplicityVSAvoidcommunication reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent makes the IP address configuration universal by enabling the same IP address to serve multiple functions - both as the N4 interface address and as the GTP-U tunnel endpoint address. The NAT traversal mechanism ensures that this universal address can be reliably resolved and reached regardless of NAT translation, eliminating the need for separate address configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11743230B2Network address translation (NAT) traversal and proxy between user plane function (UPF) and session management function (SMF)
Publication Date: 2023.08.29 CISCO TECHNOLOGY INC
  • US11743230B2 patent drawing
  • US11743230B2 patent drawing
  • US11743230B2 patent drawing

AI summary

A method enables communication between Session Management Function (SMF) and User Plane Function (UPF) instances which are separately deployed behind Network Address Translation (NAT) services. The method includes configuring an SMF or a UPF to initiate an association with a corresponding UPF or SMF. The SMF registers first information with a Network Repository Function (NRF) enabling the remote UPF to communicate with the SMF through a NAT service. The method further includes obtaining second information from the NRF enabling the SMF to communicate with the remote UPF through the NAT service. The method also includes sending an association request to the remote UPF based on the second information and receiving an association response from the remote UPF through the NAT service.