Search arXiv⌕ Search

arXiv · 2610.02296

Line-Rate GTP-U Admission Control at the Edge of a Cloud-Native 5G Core: An XDP-Based Design for Kubernetes-Hosted User Plane Functions

Abstract

The User Plane Function (UPF) of a 5G Standalone core terminates every GPRS Tunnelling Protocol user-plane (GTP-U) packet arriving from the radio access network, which makes its N3 interface both the busiest and the most exposed point of the mobile data path. As operators migrate the core onto Kubernetes and public cloud, the UPF increasingly shares a general-purpose Linux kernel with other workloads, and kernel-bypass frameworks such as DPDK become harder to operate. This paper presents GTP-Guard, a design for line-rate GTP-U admission control built on the eXpress Data Path (XDP) hook of the Linux kernel. GTP-Guard drops illegitimate tunnel traffic in the network driver, before socket-buffer allocation, using six ordered stages: peer allow-listing, GTP-U header validation, Tunnel Endpoint Identifier (TEID) admission against session state derived from the Packet Forwarding Control Protocol (PFCP), bounded extension-header parsing, inner-packet anti-spoofing with GTP-in-GTP detection, and per-session policing. We formalize stage ordering as a cost-minimization problem and show that sorting stages by the ratio of per-packet cost to rejection probability minimizes expected per-packet work, which motivates run-time reordering through tail-call program arrays when traffic mix shifts under attack. We further describe a Kubernetes deployment model based on a node-level DaemonSet with pinned eBPF maps that survive agent upgrades, discuss constraints specific to public-cloud virtual NICs, and define a reproducible evaluation methodology, with explicit hypotheses, for throughput, latency, CPU efficiency and attack resilience. This paper presents the design and methodology; experimental results will be reported in a subsequent version.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Simhadri Podala Narasimha. 2026-10-01. Line-Rate GTP-U Admission Control at the Edge of a Cloud-Native 5G Core: An XDP-Based Design for Kubernetes-Hosted User Plane Functions. https://arxiv.org/abs/2610.02296

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Edge-Assisted Multi-View Localization for Low-Altitude Economy under GPS-Challenged Environments

Unmanned aerial vehicles (UAVs) serving the low-altitude economy require reliable localization in urban canyons, indoor facilities, and other GPS-challenged environments. Visual matching with a geo-tagged database provides an alternative source for absolute positioning, but onboard computation and energy limits motivate offloading the database and matching pipeline to an edge server. The resulting localization quality depends on what visual information can reach the edge in time under varying wireless-communication and edge-computing resources. In this paper, we propose a network-adaptive edge-assisted multi-view localization framework that combines scalable orthogonality-regularized variational information bottleneck (O-VIB) encoding, value-of-information (VOI)-guided request control, and value-aware edge scheduling. We design an O-VIB model that supports nested latent prefixes from 8 to 128 dimensions and four UAV view modes. Each UAV requests edge assistance when the predicted localization-risk reduction exceeds the communication and service costs. On CARLA multi-view UAV data, VOI-guided control can lower the mean and 95th-percentile (p95) route errors by 24.8% and 31.0%, respectively, relative to budgeted periodic offloading under a matched per-route traffic budget. In indoor UAV experiments with motion-capture ground truth, our design can lower the mean position error by 28.0% relative to uncompressed all-view CLIP retrieval while cutting the descriptor traffic by 98.6%, using a 0.145 KB semantic representation. Under high congestion, a VOI-weighted scheduler with waiting-age and deadline shaping can lower the edge-side p95 latency of the top-10% high-value requests from 137.7 ms to 32.8 ms.

cs.NI↗

Intent Interpretation at RIC Timescales: Jev Decision Models versus Large Language Models in 6G Open RAN

Intent-based Open RAN needs an interpreter that turns intents into A1 policies within the loop of the RAN intelligent controller (RIC). Decision models such as Jev-1.13.0 return typed policy fields, whereas generative large language models (LLMs) produce the policy token by token. We ask whether the extra delay of LLMs costs control deadlines, RIC capacity, or radio performance. We compare Jev-1.13.0 and two other decision models with LLMs on the RANIntent v1 benchmark, in closed-loop ns-3 simulation and on a real A1 and E2 path. Median interpretation takes 0.286 to 2.35 s, against under 25 ms for A1 and E2 transfer. Jev-1.13.0 meets the 1 s near-real-time budget on 99.8% of calls, while two hosted LLMs meet it on 17.9% and 0%. In the radio network, ideal enforcement moves the affected-class service-level agreement (SLA) violation by 3.96 percentage points in the direction each intent requests, against no update at the base point. No hosted LLM showed a resolved increase over Jev-1.13.0 at that point. At the same point, per-second direct control gave no resolved SLA reduction over a numerical xApp. Slow interpreters miss the 1 s budget, and two interpreters saturate their queues at 2 intents/s, whereas no radio penalty of slow interpreters was resolved at the base point.

cs.NI↗

A Token Service Interface for AI-Native RANs

Generative and embodied AI services exchange token streams within continuing inference and control loops. Their communication requirements depend on each token set's purpose, useful timing, and execution context. This article organizes these properties into service, temporal, and stateful semantics and proposes a token service interface (TSI) between applications, radio access networks (RANs), and edge runtimes. TSI binds delivery requirements, readiness forecasts, and execution-state references to each schedulable token set, specifying field ownership, versioned updates, and admission feedback. A drone inspection case study over a decoupled RAN illustrates importance-aware radio allocation, advance preparation for timely delivery, and selective state migration that balances interruption against forwarding delay.

cs.NI↗