Searcharxiv⌕ Search

arXiv · 2610.02296

Line-Rate GTP-U Admission Control at the Edge of a Cloud-Native 5G Core: An XDP-Based Design for Kubernetes-Hosted User Plane Functions

Abstract

The User Plane Function (UPF) of a 5G Standalone core terminates every GPRS Tunnelling Protocol user-plane (GTP-U) packet arriving from the radio access network, which makes its N3 interface both the busiest and the most exposed point of the mobile data path. As operators migrate the core onto Kubernetes and public cloud, the UPF increasingly shares a general-purpose Linux kernel with other workloads, and kernel-bypass frameworks such as DPDK become harder to operate. This paper presents GTP-Guard, a design for line-rate GTP-U admission control built on the eXpress Data Path (XDP) hook of the Linux kernel. GTP-Guard drops illegitimate tunnel traffic in the network driver, before socket-buffer allocation, using six ordered stages: peer allow-listing, GTP-U header validation, Tunnel Endpoint Identifier (TEID) admission against session state derived from the Packet Forwarding Control Protocol (PFCP), bounded extension-header parsing, inner-packet anti-spoofing with GTP-in-GTP detection, and per-session policing. We formalize stage ordering as a cost-minimization problem and show that sorting stages by the ratio of per-packet cost to rejection probability minimizes expected per-packet work, which motivates run-time reordering through tail-call program arrays when traffic mix shifts under attack. We further describe a Kubernetes deployment model based on a node-level DaemonSet with pinned eBPF maps that survive agent upgrades, discuss constraints specific to public-cloud virtual NICs, and define a reproducible evaluation methodology, with explicit hypotheses, for throughput, latency, CPU efficiency and attack resilience. This paper presents the design and methodology; experimental results will be reported in a subsequent version.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Simhadri Podala Narasimha. 2026-10-01. Line-Rate GTP-U Admission Control at the Edge of a Cloud-Native 5G Core: An XDP-Based Design for Kubernetes-Hosted User Plane Functions. https://arxiv.org/abs/2610.02296

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

A Token Service Interface for AI-Native RANs

Generative and embodied AI services exchange token streams within continuing inference and control loops. Their communication requirements depend on each token set's purpose, useful timing, and execution context. This article organizes these properties into service, temporal, and stateful semantics and proposes a token service interface (TSI) between applications, radio access networks (RANs), and edge runtimes. TSI binds delivery requirements, readiness forecasts, and execution-state references to each schedulable token set, specifying field ownership, versioned updates, and admission feedback. A drone inspection case study over a decoupled RAN illustrates importance-aware radio allocation, advance preparation for timely delivery, and selective state migration that balances interruption against forwarding delay.

cs.NI↗

Performance Evaluation of Emerging Networks of Quantum Repeaters: Analysis and Simulation

Emerging experimental quantum network deployments are based on collaborations between research institutions and rely on telecommunications fiber infrastructure. Currently, such networks consist of mostly Dual Input Repeaters (DIRs) and can be viewed as composed of (mostly) line graphs. In order to evaluate the performance of such networks (e.g., in terms of Entangled Pair Rate, EPR, and average Fidelity) we developed a custom quantum network simulation platform that takes into account both the quantum and classical network components. To support the verification of the simulation results, we develop a novel approach for performance analysis of DIRs. We compare the simulation results to the analytical results for DIRs and to prior results for repeaters with more than two inputs. We observe that although the expected memory utilization cannot be bounded, \emph{a small DIR memory size is sufficient and leads to minimal performance degradation}. For line networks with a single repeater and $3$ repeaters, we explore the dependency of incoming and outgoing memory size requirements on the number of nodes (network size), their connectivity (fiber length) and various quantum error settings (amplitude damping and phase flip channels). We evaluate the \emph{EPR} and the \emph{average Fidelity} for a sub-network of a deployed network with $3$ repeaters, using two alternative paths. We show that as the number of nodes increases or when the fiber lengths between nodes differ significantly, additional node memory is needed to maintain the same EPR (qubits are stored for longer duration to allow completion of entanglement across the network). We also show that the memory size should be above some minimum threshold to allow EP creation (EPR $>0$) as pair selection and swapping completion propagate across the network.

cs.NI↗

Mobility Enhancement of Patients Body Monitoring based on WBAN with Multipath Routing

One of the promising applications of wireless sensor networks (WSNs) is monitoring of the human body for health concerns. For this purpose, a large number of small sensors are implanted in the human body. These sensors altogether provide a network of wireless sensors (WBANs) and monitor the vital signs and signals of the human body; these sensors will then send this information to the doctor. The most important application of the WBAN is the implementation of the monitoring network for patient safety in the hospital environment. In this case, supporting patients' mobility is one of the basic needs, which has been underestimated in recent studies. The problem that involves providing the required energy for the units used in this type of network is challenging; for this reason, sent/received units with very low power consumption and with a very small radius are used in order to save energy. The resulting small sending range leads to the lack of support for patients' mobility. In this paper, the ad hoc mode is suggested for use to establish a network and a multipath routing algorithm for the purpose of supporting patients' mobility in a hospital setting. The results of the simulation show that, in addition to supporting patients' mobility, the use of the proposed idea instead of previously presented protocols reduces delays in data transmission and energy consumption; it also increases the delivery rate depending on the destination and the lifetime of the network, while increasing routing overhead.

cs.NI↗