云原生5G核心网边缘的线速GTP-U准入控制:面向Kubernetes托管用户面功能的基于XDP的设计
Line-Rate GTP-U Admission Control at the Edge of a Cloud-Native 5G Core: An XDP-Based Design for Kubernetes-Hosted User Plane Functions
浏览论文内容
中文总结 AI 辅助
针对5G核心网迁移至Kubernetes和公有云后UPF面临的GTP-U流量安全挑战,提出基于XDP的GTP-Guard设计,通过六阶段有序准入控制实现线速非法流量丢弃,并形式化阶段排序优化,为云原生5G用户面提供高效防护方案。
中文摘要 AI 辅助
5G独立组网核心网的用户面功能(UPF)终止从无线接入网到达的每一个GPRS隧道协议用户面(GTP-U)数据包,这使得其N3接口成为移动数据路径中最繁忙且暴露面最大的点。随着运营商将核心网迁移到Kubernetes和公有云,UPF日益与其它工作负载共享通用Linux内核,而DPDK等内核旁路框架变得难以运维。本文提出GTP-Guard,一种基于Linux内核eXpress Data Path(XDP)钩子的线速GTP-U准入控制设计。GTP-Guard在网络驱动中、套接字缓冲区分配之前丢弃非法隧道流量,采用六个有序阶段:对端白名单、GTP-U头验证、基于从分组转发控制协议(PFCP)派生的会话状态的隧道端点标识符(TEID)准入、有界扩展头解析、带GTP-in-GTP检测的内层数据包防欺骗,以及每会话策略。我们将阶段排序形式化为成本最小化问题,并表明按每包成本与拒绝概率之比对阶段排序可使期望每包工作量最小化,这促使在攻击下流量混合变化时通过尾调用程序数组进行运行时重排序。我们进一步描述了一种基于节点级DaemonSet的Kubernetes部署模型,该模型使用在代理升级后仍存活的固定eBPF映射,讨论了公有云虚拟NIC特有的约束,并定义了一种可复现的评估方法,包含明确的假设,用于吞吐量、延迟、CPU效率和攻击韧性。本文介绍设计与方法;实验结果将在后续版本中报告。
英文摘要
The User Plane Function (UPF) of a 5G Standalone core terminates every GPRS Tunnelling Protocol user-plane (GTP-U) packet arriving from the radio access network, which makes its N3 interface both the busiest and the most exposed point of the mobile data path. As operators migrate the core onto Kubernetes and public cloud, the UPF increasingly shares a general-purpose Linux kernel with other workloads, and kernel-bypass frameworks such as DPDK become harder to operate. This paper presents GTP-Guard, a design for line-rate GTP-U admission control built on the eXpress Data Path (XDP) hook of the Linux kernel. GTP-Guard drops illegitimate tunnel traffic in the network driver, before socket-buffer allocation, using six ordered stages: peer allow-listing, GTP-U header validation, Tunnel Endpoint Identifier (TEID) admission against session state derived from the Packet Forwarding Control Protocol (PFCP), bounded extension-header parsing, inner-packet anti-spoofing with GTP-in-GTP detection, and per-session policing. We formalize stage ordering as a cost-minimization problem and show that sorting stages by the ratio of per-packet cost to rejection probability minimizes expected per-packet work, which motivates run-time reordering through tail-call program arrays when traffic mix shifts under attack. We further describe a Kubernetes deployment model based on a node-level DaemonSet with pinned eBPF maps that survive agent upgrades, discuss constraints specific to public-cloud virtual NICs, and define a reproducible evaluation methodology, with explicit hypotheses, for throughput, latency, CPU efficiency and attack resilience. This paper presents the design and methodology; experimental results will be reported in a subsequent version.