---
title: "(m,k)-Firm Elevation Policy in 5G-TSN"
url: https://www.emergentmind.com/topics/m-k-firm-elevation-policy
type: topic
---

# (m,k)-Firm Elevation Policy in 5G-TSN

Searching arXiv for the specified paper to ground the article and confirm bibliographic details.
The **\((m,k)\)-firm Elevation Policy** is a fallback mechanism for **time-driven TSN schedules deployed over converged 5G-TSN networks**. It is proposed to address a specific robustness problem: schedules are synthesized under simplified or percentile-based delay assumptions, whereas actual 5G delays are **probabilistic, variable, and occasionally exhibit abrupt outliers**. In that setting, a nominally correct time-driven schedule can lose its real-time validity when an unforeseen delay outlier causes a frame to miss the transmission window assumed by the schedule. The policy augments an existing primary schedule with a **dynamic priority-driven scheme** that elevates the priority of selected delayed frames so as to preserve a meaningful minimum level of service under unstable conditions, while limiting interference to other traffic [2508.09769].

## 1. Problem setting in 5G-TSN time-driven scheduling

The policy is formulated for **time-driven TSN schedules** in which forwarding behavior is tightly coordinated in time, especially through the **Time-Aware Shaper (TAS)** and **Per-Stream Filtering and Policing (PSFP)**. A centralized network controller (CNC) computes a schedule based on assumptions about frame release times and traversal delays. This model is effective in wired TSN, where delays are small and nearly deterministic, but it becomes fragile when a **5G system is integrated as a logical TSN bridge** [2508.09769].

The underlying problem is a mismatch between the **idealized or bounded delay models** used during schedule synthesis and the **actual 5G delay process**, which is described as statistical, nonstationary, and prone to outliers. Representative assumptions identified for schedule synthesis are:

- **(A1)** every frame \(f\) is available for transmission exactly at time \(f.release\),
- **(A2)** wired per-link transmission delays can be represented by fixed slots,
- **(A3)** 5G delays are bounded by \([d_{\min}, d_{\max}]\) with probability \(\alpha\).

These assumptions may be violated by unexpected compute delays, time synchronization errors, abrupt 5G delay anomalies such as **line-of-sight blockage** or **handover**, and longer-term changes in channel or load conditions. The consequence is not merely that some frames become late. Delay outliers can cause an affected frame to miss its own deadline, and they can also invalidate the synchronized schedule in ways that may harm other real-time streams if mishandled [2508.09769].

This issue is particularly acute for time-driven schedules because they are brittle. If a frame misses the time window expected by the schedule, it may be **discarded by PSFP** even though it might still have been useful to the application. The paper further argues that runtime reconfiguration is too slow for abrupt disturbances, since it requires recomputing delay confidence intervals, recomputing the TSN schedule, and deploying new GCL and PSFP configurations across the network. That process can take **seconds** and may cause downtime. The Elevation Policy is therefore positioned as a **light-weight fallback mechanism** that can be preconfigured and activated immediately during unstable conditions [2508.09769].

## 2. Weakly hard real-time semantics and the \((m,k)\)-firm model

The policy is grounded in **weakly hard real-time guarantees** rather than a strict requirement that every frame satisfy its deadline. A stream \(F\) has an **\((m,k)\)-firm latency requirement** if **at least \(m\) out of any \(k\) consecutive frames must arrive before their deadline** [2508.09769].

For the \(i\)-th frame \(f^{(i)} \in F\), the release time is defined as

\[
f^{(i)}.release := F.phase + (i - 1) \times F.period
\]

and the latency requirement \(F.lat\) is satisfied iff

\[
f^{(i)} \text{ arrives at the listener before } f^{(i)}.release + F.lat. \tag{1}
\]

The \((m,k)\)-firm condition constrains the pattern of deadline satisfactions over every sliding window of \(k\) consecutive frames. This is stronger than a long-term percentage guarantee and weaker than a hard real-time guarantee for every frame [2508.09769].

Within this framework, **hard real-time** corresponds conceptually to the strongest case, effectively requiring every frame to meet its deadline; the paper notes that some traffic is modeled with \(\mu = 1\), which corresponds to a per-frame hard requirement. **Best effort** lies at the opposite end: misses may occur without structural restriction. The \((m,k)\)-firm model occupies the intermediate regime by allowing some misses while bounding the local clustering of failures. The examples given are:

- \((1,2)\)-firm: in every pair of consecutive frames, at least one must succeed.
- \((1,3)\)-firm: among any three consecutive frames, at least one must succeed.
- If an application tolerates at most \(n\) consecutive faults, this can be expressed as \((1,n+1)\)-firm.

The paper argues that this is more aligned with industrial notions such as **survival time** than asymptotic reliability metrics like “99% of frames meet their deadline.” A percentage metric can still admit a burst of many consecutive losses, whereas an \((m,k)\)-firm requirement explicitly constrains such bursts [2508.09769]. This suggests that the policy is intended not merely to improve average performance, but to preserve application-relevant temporal structure in failure patterns.

## 3. Policy architecture and operational mechanism

The policy is designed to complement, rather than replace, a primary time-driven schedule. Under normal conditions, the **primary TAS/PSFP schedule** operates as usual. Under abnormal conditions, a **dynamic priority-driven fallback** is used. The key intervention is selective: only certain delayed frames are “rescued” by elevating their priority, while others are discarded so that the rest of the schedule remains protected [2508.09769].

The primary schedule is written as

\[
C = (R, S_{\mathrm{GCL}})
\]

where \(R\) denotes **PSFP arrival windows** and \(S_{\mathrm{GCL}}\) denotes **TAS gate control lists**. The augmentation introduced by the policy adds new PSFP behavior that distinguishes between **on-time**, **late-but-salvageable**, and **too-late** frames, and it also adds new GCL timing that leaves room for interference from elevated late frames. The result is a fallback layer around a primary time-driven schedule rather than a resynthesis of the schedule from scratch [2508.09769].

Activation occurs when a frame arrives later than what the primary schedule expects, meaning outside the nominal arrival interval for ordinary forwarding, but still early enough that forwarding it with high priority could preserve useful timing. The paper highlights deployment especially at bridges following segments prone to unpredictable delay, such as after the talker when release jitter is possible, or at the NW-TT after 5G transport [2508.09769].

The runtime fallback mechanism is implemented through **extended PSFP stream-gate states**. Standard PSFP can forward or discard. The policy adds a third state:

- **forward**
- **discard**
- **elevate**

In the **elevate** state, PSFP overwrites the frame’s PCP to the highest priority,

\[
111_2 = 7
\]

after which the frame retains that elevated priority on subsequent hops. TAS then prefers it over lower-priority traffic, which minimizes additional queuing delay. However, not every late frame is elevated. Elevation is restricted to late frames selected by the stream’s \((m,k)\)-firm configuration [2508.09769].

At each relevant bridge, the CNC preconfigures PSFP windows for each frame \(f_i\). Three cases are distinguished:

1. **Normal forwarding window**: if the frame arrives in the expected interval, it is forwarded with its original PCP.
2. **Elevation window**: if it arrives after the expected interval but before it becomes useless, it is elevated.
3. **Late discard**: if it arrives too late, it is discarded.

Formally, the normal forwarding interval for \(f_i\) at hop \((u,v)\) is

\[
[o_i + d_{\min}((u,v), f_i),\; \theta_i + d_{\max}((u,v), f_i)) \tag{2}
\]

where \(o_i\) is the scheduled opening time of the transmission slot, \(\theta_i\) is the latest possible transmission start after accounting for elevated-traffic interference, and \(d_{\min}((u,v), f_i)\) and \(d_{\max}((u,v), f_i)\) are lower and upper bounds on transmission-plus-processing delay under stable conditions. If the frame is eligible for elevation, PSFP elevates it when it arrives in

\[
[\theta_i + d_{\max}((u,v), f_i),\; f_i.release + f_i.lat) \tag{3}
\]

A frame is therefore elevated if it arrives later than expected by the primary schedule but still has a chance to reach the listener before its deadline; frames arriving later than that are discarded [2508.09769].

## 4. The \(\mu\)-pattern and coordinated eligibility for elevation

A central feature of the policy is that elevation decisions are not made by a purely reactive local rule. The paper explicitly rejects the rule “elevate frame \(f^{(i)}\) whenever losing it would violate the \((m,k)\)-firm requirement,” because local devices have only a **restricted local view**. If delays occur in different segments, different devices could make inconsistent decisions and inadvertently violate the intended guarantee [2508.09769].

The paper illustrates this with a \((1,2)\)-firm stream having elevation points at a bridge \(B_1\) after release-time uncertainty and at a bridge \(B_{NW}\) after 5G delay uncertainty. If \(f^{(i-1)}\) is acceptable at \(B_1\) but later lost at \(B_{NW}\) because of an unexpected 5G delay, and \(f^{(i)}\) is delayed at release and considered at \(B_1\), then \(B_1\) may incorrectly discard \(f^{(i)}\) if it does not know that \(f^{(i-1)}\) was already lost later. Both consecutive frames may then be lost, violating the \((1,2)\)-firm guarantee [2508.09769].

To avoid such inconsistency, the policy uses a predetermined **\(\mu\)-pattern**. For an \((m,k)\)-firm latency requirement, the paper defines a \(k\)-bit word

\[
\mu = \mu_0 \cdots \mu_{k-1}, \qquad \mu_i \in \{0,1\}
\]

with

\[
\mu_0 + \cdots + \mu_{k-1} \ge m
\]

The interpretation is position-based and periodic:

- \(\mu_j = 1\): the frame whose index falls in position \(j \bmod k\) is eligible for elevation if delayed.
- \(\mu_j = 0\): delayed frames at that position are not protected and may be discarded.

The formal rule is that when the \(i\)-th frame \(f^{(i)} \in F\) is delayed, its priority may be elevated iff

\[
\mu_{i \bmod k} = 1
\]

Because the \(\mu\)-pattern contains at least \(m\) ones in each \(k\)-periodic block, at least those \(m\) positions in every block of length \(k\) are designated for protection or elevation. Operationally, if one of these protected frames becomes late, it is elevated instead of dropped; if an unprotected frame becomes late, it is discarded to protect the rest of the schedule [2508.09769].

The running example for a \((1,2)\)-firm requirement chooses \(\mu = 01\), so every second frame position is eligible for elevation. The paper also uses \((1,3)\)-firm examples with

\[
\mu \in \{001,010,100\}
\]

and recommends choosing patterns that **spread elevated traffic evenly**. The runtime logic is not presented as an adaptive counter-based state machine. Instead, it is encoded statically in the periodic \(\mu\)-pattern, PSFP stream-gate intervals, and TAS slot augmentation. The effective automaton is thus a periodic gate schedule whose intervals are labeled **forward**, **elevate**, or **discard** [2508.09769].

## 5. Formal model and schedule augmentation

The network is modeled as a directed graph

\[
G = (V, E)
\]

where \(u \in V\) are network devices visible to the CNC and \((u,v) \in E\) are full-duplex Ethernet or 5G links. Each time-triggered stream \(F \in \mathcal{F}\) specifies a route \(F.route = (v_1^F, v_2^F, \dots, v_{n_F}^F)\), PCP priority \(F.pcp\), period \(F.period\), phase \(F.phase\), and size \(F.size\). The hypercycle is

\[
H = \operatorname{lcm}_{F \in \mathcal{F}} (F.period)
\]

and the deadline condition remains Equation (1) above [2508.09769].

For a stream \(F\), the paper defines \(N_F([t_1,t_2])\) to count the number of frames that can be elevated in the interval \([t_1,t_2]\). Using \(\mu = \mu_0 \cdots \mu_{k-1}\),

\[
N_F([t_1,t_2]) = \mu_{l \bmod k} + \cdots + \mu_{h \bmod k},
\]

with

\[
l = \frac{t_1 - F.lat}{F.period} + 1, \qquad h = \frac{t_2}{F.period}
\]

where \(l\) and \(h\) determine the lowest and highest frame indices that can be elevated during the interval. The semantics of the function are described as counting eligible frame indices in the interval [2508.09769].

To upper-bound elevated traffic on a link \((u,v)\), the policy introduces a token bucket \(TB_{(u,v)}\) for the set of streams \(\mathcal{F}_{(u,v)} \subseteq \mathcal{F}\) traversing that link. The bucket size is

\[
b_{(u,v)} = \max \left\{ \sum_{F \in \mathcal{F}_{(u,v)}} F.size \times N_F([t,t]) \;\middle|\; 0 \le t < H \right\}
\]

and the token rate is

\[
r_{(u,v)} = \max \left\{ \frac{ \sum_{F \in \mathcal{F}_{(u,v)}} F.size \times N_F([t_1,t_2]) - b_{(u,v)} }{ t_2 - t_1 } \;\middle|\; 0 \le t_1 < t_2 < 2H \right\}
\]

These quantify worst-case burstiness and sustainable arrival rate of elevated traffic, with the range \(2H\) needed to capture overflow across consecutive hypercycles [2508.09769].

Given a port \((u,v)\), the initial schedule specifies a sequence of scheduled transmissions

\[
(f_i, [o_i, c_i])_{i=1}^N
\]

ordered by

\[
o_1 \le o_2 \le \cdots \le o_N
\]

The augmented intervals are denoted \([\tilde{o}_i, \tilde{c}_i]\). A frame \(f_i\) may be delayed directly by elevated traffic arriving when its gate opens, with worst-case delay

\[
\theta_i^{1} = \tilde{o}_i + \frac{b_{(u,v)}}{(u,v).bitrate - r_{(u,v)}}
\]

A second case arises when the previous frame \(f_{i-1}\) is prolonged and token bucket refill during its transmission causes additional delay:

\[
\theta_i^{2} = \tilde{c}_{i-1} + \frac{ \left(f_{i-1}.size/(u,v).bitrate\right)\times r_{(u,v)} }{ (u,v).bitrate - r_{(u,v)} }
\]

The actual prolongation is

\[
\theta_i = \max\{\theta_i^{1}, \theta_i^{2}\}
\]

and the transmission completion time is updated as

\[
\tilde{c}_i \leftarrow \theta_i + \frac{f_i.size}{(u,v).bitrate}
\]

If \(f_{i+1}\) has higher priority than \(f_i\), prolongation could let \(f_{i+1}\) overtake \(f_i\). To preserve the original transmission order, the deferment rule is

\[
\Delta_i \leftarrow \Delta_{i-1} + \max\{0, \tilde{c}_i - \tilde{o}_{i+1}\}
\]

and

\[
\tilde{o}_{i+1} \leftarrow \tilde{o}_{i+1} + \Delta_i
\]

This preserves the initial schedule ordering while creating space for elevated traffic. At each step, the augmented GCL opens the gate associated with \(f_i.pcp\) during \([\tilde{o}_i,\tilde{c}_i]\), and the PSFP forwarding and elevation intervals are then derived by Equations (2) and (3) [2508.09769].

Appendix B generalizes this augmentation with a **Transmission Graph** \(G_C = (V,E,w)\), inspired by disjunctive graph models from job-shop scheduling. It includes operation vertices \(O_f^i\), source and sink vertices, conjunctive edges for route and order dependencies, disjunctive edges for link contention, and FIFO edges for queue order. The generalized algorithm maintains a **critical cost** \(C(O_f^i)\) and a per-link **prolongation delay** \(\theta(v_i^f, v_{i+1}^f)\), and updates these using bucket burst, rate, deferment, and overlap handling [2508.09769]. A plausible implication is that the policy is intended to remain analyzable under multi-hop contention rather than being confined to single-hop intuition.

## 6. System model, deployment assumptions, and operational tradeoffs

The traffic model consists of a **fixed set of time-triggered streams** \(\mathcal{F}\), each with a fixed route, period, phase, frame size, latency requirement, and PCP. The focus is on **time-triggered traffic**, which the paper treats as especially relevant for industrial settings with stringent timing requirements [2508.09769].

The scheduling model combines **PSFP** on ingress and **TAS/GCL** on egress. Under nominal operation, periodic traffic is admitted only when it arrives within its expected interval. For 5G integration, the architecture assumes a 3GPP-style arrangement in which the **5G system behaves as a logical 5G-TSN bridge**. Devices visible to the CNC include wired TSN bridges, DS-TTs, NW-TTs, and TSN end devices. The architectural assumption is that 5G hides internal resource allocation and session details from TSN control while exposing bridge-like TSN behavior through translators [2508.09769].

The unstable network conditions of interest are epochs during which the delay assumptions used by the primary schedule do not hold for every frame. Examples include release-time anomalies, abrupt 5G delay outliers due to blockage or handover, and changing load that makes prior percentile models outdated. The paper explicitly states that the policy is not designed for arbitrary infinite delays; if the outlier already exceeds the frame deadline \(f.release + f.lat\), then no real-time guarantee is possible [2508.09769].

Enforcement is split between centralized synthesis and distributed runtime behavior. The CNC computes the \(\mu\)-patterns, PSFP forward/elevate/discard windows, and GCL augmentation, while each TSN bridge enforces those rules locally. This design is therefore **centralized synthesis/configuration** combined with **distributed runtime enforcement** [2508.09769].

The policy is deliberately complementary to the primary schedule. During normal operation, if frames arrive in their expected windows, the primary schedule forwards them normally and no priority elevation occurs. Quality of service remains close to that of the original schedule. However, because the schedule must reserve room for possible elevated traffic, the augmented schedule can introduce a small overhead even in stable conditions through prolonged slots, deferred later slots, and slightly increased latency or jitter for nominal traffic. During degraded conditions, selected delayed frames are elevated to PCP 7, unselected delayed frames are discarded, and the schedule remains valid because it was augmented in advance to tolerate the modeled elevated-traffic interference [2508.09769].

The principal tradeoff is explicit: the policy exchanges **a little extra overhead under nominal conditions** for **substantial robustness under unstable conditions**, and it protects selected weakly hard guarantees by intentionally dropping some delayed frames to shield other traffic. This suggests a design philosophy in which controlled sacrifice of some traffic is preferable to uncontrolled disruption of the schedule as a whole.

## 7. Evaluation context and significance

The paper reports three evaluation parts and lists performance metrics including **schedulability: number of feasible schedules**, **maximum latency of sporadic streams**, **maximum jitter of isochronous streams**, **end-to-end latency under 5G delay outliers**, and, in control experiments, **median and maximum absolute pole-angle error \(|\alpha|\)** [2508.09769].

One evaluation component is a physical TSN testbed controlling an inverted pendulum over a network. The setup includes a talker and listener implemented as Linux machines with Intel I210 NICs, two Kontron TSN bridges, LinuxPTP synchronization, and ETF qdisc for precise transmission timing. The first link emulates 5G delays using histograms measured in prior work. The paper distinguishes **stable epochs**, in which 5G delays are upper-bounded by \(7.71\text{ ms}\) (90th percentile), from **unstable epochs**; the supplied data truncates before the complete description of the unstable-epoch parameterization, but it explicitly states that the evaluations demonstrate two main findings: **weakly hard real-time guarantees are essential to uphold the quality of control within a networked control system**, and **only a small overhead is imposed when the primary schedule can provide stronger quality of service guarantees** [2508.09769].

Within that framing, the \((m,k)\)-firm Elevation Policy is significant because it offers a preconfigured fallback for environments where 5G-induced delay uncertainty cannot be fully captured by the assumptions used during schedule synthesis. It does not attempt to guarantee strict hard real-time behavior under all disturbances. Instead, it seeks to preserve a structured minimum guarantee that remains meaningful for control and cyber-physical applications when nominal timing assumptions break down [2508.09769]. A common misconception would be to view the policy as a general-purpose reactive priority boost for any late frame; the paper’s formulation is narrower and more disciplined, since elevation eligibility is predetermined, analytically bounded, and coordinated across bridges through the \(\mu\)-pattern.

Source: https://www.emergentmind.com/topics/m-k-firm-elevation-policy