Traffic monitoring in network nodes
By exchanging packet detection rules between network nodes of 5G networks, the problem of inaccurate traffic identification and classification in the prior art is solved, and more efficient and accurate traffic monitoring is achieved.
Patent Information
- Application Number
- CN201980099085.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-07-26
- Filing Date
- 2019-09-13
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2039-09-13
AI Technical Summary
In 5G networks, it is difficult for the prior art to accurately identify and classify traffic, especially in an environment with high encrypted packets and variable protocols, which leads to inaccurate protocol identification and increases the probability of error detection.
Traffic monitoring is realized by exchanging packet detection rules between network nodes. The specific method includes receiving a packet, determining that it matches the multiple packet detection rules, and sending a corresponding indication to the second network node. Meanwhile, a plurality of packet detection rules are sent to the first network node, and an indication that the packets received therein match the plurality of packet detection rules is received.
By exchanging packet detection rules, traffic can be more accurately identified and classified, the probability of error detection can be reduced, and the accuracy and efficiency of traffic monitoring can be improved.
Smart Images

Figure CN114270788B_ABST
Abstract
Description
Technical Field
[0001] Examples of the present disclosure relate to traffic monitoring in a network node. Background Art
[0002] In the 3GPP standardization forum, a reference architecture for 5G wireless communication networks is defined, for example in Section 4.2.3 of 3GPP TS 23.501 V0.5.0 (2017-05), which is incorporated herein by reference. Figure 1 An example of a 5G network architecture 100 is shown. The 5G network architecture 100 includes the following entities and interfaces.
[0003] Packet Flow Description Function (PFDF) 102: In the 5G architecture 100, this is included in the Network Open Function (NEF) 104, for example to reduce the number of network functions in 5G. The PFDF 102 processes the Packet Flow Description (PFD) associated with (one or more) application identifiers and transmits them to the Session Management Function (SMF) 106 via the NG GW interface. The SMF 106 transmits these PFDs to the User Plane Function (UPF) 108 through the N4 interface and the PFD management process to enable the UPF 108 to perform accurate application detection when the PFD is managed by a third-party service provider.
[0004] The Policy and Charging Rules Function (PCF) 112 is a functional unit that performs policy control decisions and flow-based charging control. The PCF provides network control with respect to service data flow detection.
[0005] The session management function (SMF) 106 performs NAS processing for SM, user equipment (UE) IP address allocation and management, sending quality of service (QoS) and policy NG2 information to AN via the access and mobility management function (AMF) 114, idle / active awareness, policy and offline / online charging i / f termination, policy enforcement control part, lawful interception (CP and interface with LI system), UP selection and termination of NG4 interface.
[0006] User plane function (UPF) 108 (e.g., policy control execution function) includes service data flow detection, policy execution and flow-based charging functions. Anchor point for intra-RAT / inter-RAT mobility (when applicable), external IP interconnection point, packet routing and forwarding, QoS processing for user plane, packet inspection and PCC rule execution, legal interception (UP collection), roaming interface (UP), traffic counting and reporting. The deep packet inspection (DPI) technology embedded in UPF 108 supports packet inspection and service classification, which can classify IP packets according to the configured rule tree so that they are assigned to service sessions. DPI technology provides two types of analysis. First, shallow packet inspection extracts basic protocol information, such as IP address (source, destination) and other low-level connection states. This information usually resides in the packet header itself, thus revealing the main communication intention. Secondly, deep packet inspection (DPI) provides application awareness. This is achieved by analyzing the content in both the packet header and the payload over a series of packet transactions. There are several possible analysis methods for identifying and classifying applications and protocols that are grouped as signatures. One of these approaches is heuristic signatures related to behavioral analysis of user traffic. Heuristic traffic analyzers make best guess classifications, but the recognition accuracy cannot be guaranteed to be 100%. This limitation is inherent in heuristic methods. This type of analysis, which considers behavioral analysis of packets, can consume a lot of processing resources because more than one packet may be considered for analysis.
[0007] In 3GPP TS 29.244, which is incorporated herein by reference, the interface between the user plane and the control plane in the network is defined. Once a session is established between, for example, UPF 108 and SMF 106, they can exchange some information, such as, for example, Packet Detection Rules (PDR). According to the standard, upon receiving a user plane packet, the UPF shall perform a lookup of a temporary PDR and:
[0008] First identify the PFCP session to which the packet corresponds; and
[0009] Among all PDRs provided for this PFCP session, find the first PDR that matches the incoming packet, starting with the PDR with the highest priority and then continuing the PDRs in descending order of priority. Only the highest priority PDR that matches the packet should be selected, i.e., the UP function should stop the PDR search once a matching PDR is found.
[0010] In other words, currently in the control plane and user plane separation (CUPS) architecture, UPF classifies traffic according to the priority parameter of PDR. It defines the relative priority of PDR among all PDRs provided within the PFCP session and matches the packet to the first matching PDR in the order of the priority of PDR.
[0011] DPI technology uses a heuristic analyzer that detects and identifies protocols used by UEs (e.g., applications within those UEs) based on, for example, binary signature patterns, metrics, or connection patterns. The difficulty in correctly identifying this type of traffic means that protocol identification accuracy cannot be guaranteed. The higher the percentage of encrypted packets, the lower the detection rate. In addition, the continued increase in the number of applications and protocols connected in typical UE devices may increase the probability of incorrect protocol detection because new protocols and applications are added every year. For this reason, content providers (e.g., Over The Top (OTT) providers) have increased their cooperation with operators to provide good methods for detecting their applications. For example, a content provider can send rules (e.g., PDRs) to an operator for matching traffic corresponding to the content provider, for example using a T8 interface. Summary of the invention
[0012] One aspect of the present disclosure provides a method for traffic monitoring in a first network node. The method includes: receiving a packet, and determining that the packet matches a plurality of packet detection rules. The method also includes: sending an indication to a second network node that the packet matches the plurality of packet detection rules.
[0013] Another aspect of the present disclosure provides a method of traffic monitoring in a second network node. The method includes: sending a plurality of packet detection rules to a first network node; and receiving an indication that a packet received at the first network node matches the plurality of packet detection rules.
[0014] Another aspect of the present disclosure provides a method for traffic monitoring. The method includes: receiving an indication that a packet received at a first network node matches a plurality of packet detection rules; and sending a modification to at least one of the packet detection rules to the first network node.
[0015] Additional aspects of the present disclosure provide an apparatus for traffic monitoring in a first network node. The apparatus includes a processor and a memory. The memory contains instructions executable by the processor so that the apparatus is operable to: receive a packet, determine that the packet matches a plurality of packet detection rules, and send an indication to a second network node that the packet matches the plurality of packet detection rules.
[0016] Another aspect of the present disclosure provides an apparatus for traffic monitoring in a second network node. The apparatus includes a processor and a memory. The memory contains instructions executable by the processor so that the apparatus is operable to: send a plurality of packet detection rules to a first network node, and receive an indication that a packet received at the first network node matches the plurality of packet detection rules.
[0017] Another aspect of the present disclosure provides an apparatus for traffic monitoring. The apparatus includes a processor and a memory. The memory contains instructions executable by the processor so that the apparatus is operable to: receive an indication that a packet received at a first network node matches a plurality of packet detection rules, and send a modification to at least one of the packet detection rules to the first network node.
[0018] Another aspect of the present disclosure provides an apparatus for traffic monitoring in a first network node. The apparatus is configured to: receive a packet, determine that the packet matches a plurality of packet detection rules, and send an indication that the packet matches the plurality of packet detection rules to a second network node.
[0019] Another aspect of the present disclosure provides an apparatus for traffic monitoring in a second network node. The apparatus is configured to: send a plurality of packet detection rules to a first network node, and receive an indication that a packet received at the first network node matches the plurality of packet detection rules.
[0020] Additional aspects of the present disclosure provide an apparatus for traffic monitoring. The apparatus is configured to receive an indication that a packet received at a first network node matches a plurality of packet detection rules, and send a modification to at least one of the packet detection rules to the first network node. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to better understand examples of the present disclosure and to more clearly show how the examples may be implemented, reference will now be made, by way of example only, to the following drawings, in which:
[0022] Figure 1 An example of a 5G network architecture is shown;
[0023] Figure 2 is a flow chart of an example of a method of traffic monitoring in a first network node;
[0024] Figure 3 is a flow chart of an example of a method of traffic monitoring in a second network node;
[0025] Figure 4 is a flow chart of an example of a method of flow monitoring;
[0026] Figure 5is a schematic diagram of an example of an apparatus for traffic monitoring in a first network node;
[0027] Figure 6 is a schematic diagram of an example of an apparatus for traffic monitoring in a second network node;
[0028] Figure 7 is a schematic diagram of an example of an apparatus for flow monitoring;
[0029] Figure 8 illustrates an example of communications between network entities; and
[0030] Fig. 9 Another example of communication between network entities is shown. DETAILED DESCRIPTION
[0031] Specific details, such as specific embodiments or examples, are described in detail below for the purpose of explanation and not limitation. It will be appreciated by those skilled in the art that, in addition to these specific details, other examples may be used. In some instances, a detailed description of well-known methods, nodes, interfaces, circuits and devices is omitted so as not to obscure the description with unnecessary details. It will be appreciated by those skilled in the art that hardware circuits (e.g., analog and / or discrete logic gates, ASICs, PLAs, etc., interconnected to perform special functions) and / or software programs and data may be used in conjunction with one or more digital microprocessors or general-purpose computers to implement the described functions in one or more nodes. The node communicating using an air interface also has a suitable radio communication circuit. Moreover, in appropriate cases, technology may be additionally considered to be fully embodied in any form of computer-readable memory, such as a solid-state memory, a disk, or an optical disk comprising a suitable computer instruction set that causes a processor to perform technology described herein.
[0032] Hardware implementations may include or encompass, but are not limited to, digital signal processor (DSP) hardware, reduced instruction set processors, hardware (e.g., digital or analog) circuits, including but not limited to (one or more) application specific integrated circuits (ASICs) and / or (one or more) field programmable gate arrays (FPGAs) capable of performing such functions, and (where appropriate) state machines.
[0033] According to standards, such as 3GPP TS 29.244, PDR must comply with the following rules:
[0034] For the same PFCP session, there is only one PDR in the corresponding packet detection information (PDI)
[0035] have the same matching fields in the same table, that is, have the same set of matching fields and the same values.
[0036] For the same PFCP session, there may be some overlapping rules. For example, the difference between two PDRs may be that a match field is set to a specific value in one PDR, while the same match field is not included in the other PDR.
[0037] Different PFCP sessions should have at least one PDR that differs by at least one different matching field.
[0038] With these principles defined by the standard, there may be situations where a packet may potentially match multiple PDRs. Therefore, the packet is matched with the PDR with the highest priority among the potentially matching PDRs. In these situations, if there is a conflict between PDRs and the packet is matched with a PDR with a higher priority, it is difficult for the operator to know whether this is the correct behavior, such as the packet has been matched to the correct PDR (e.g., the most preferred PDR, regardless of priority).
[0039] In some examples described herein, a packet may match multiple PDRs in a first network node (e.g., UPF), and this may be reported to a second network node (e.g., SMF). The SMF may take appropriate action, such as, for example, updating the PDRs in the UPF. In some examples, this may be done by the SMF consulting a third network node (e.g., PCF).
[0040] Figure 2 200 is a flow chart of an example of a method 200 for traffic monitoring in a first network node (such as, for example, a UPF, a packet gateway (PGW), or a packet gateway-user plane (PGW-U)). The first network node (and other nodes described herein) may be a node in a 5G network, although the node may also be in another network, such as an LTE network or a network with a mixed standard type. The method includes: in step 202, receiving a packet (e.g., an IP packet). In some examples, the packet may be received from the Internet (e.g., a downlink) or from a UE (e.g., an uplink). Step 204 of method 200 includes determining that the packet matches a plurality of packet detection rules. That is, for example, once it is determined that the packet matches a PDR, the method 200 may continue to determine whether the packet matches more PDRs. Determining that the packet matches the PDR may include, for example, determining that the packet matches the corresponding packet detection information (PDI) associated with the PDR. If the packet matches a plurality of PDRs, step 206 of method 200 includes sending an indication that the packet matches the plurality of packet detection rules to a second network node (e.g., an SMF or a packet gateway-control plane PGW-C). Thus, for example, the first network node may report to the second network node that there is a conflict in a PDR configured in the first network node because the packet matches multiple PDRs.
[0041] In some examples, the indication sent to the second network node may identify the PDR (eg, using a PDR ID), or the indication may contain multiple packet detection rules so that, for example, the second network node (or any other network node) may identify conflicting PDRs.
[0042] In some examples, method 200 may include, in response to determining that the packet matches multiple packet detection rules, sending the packet to the second network node. Thus, the second network node (or any other network node) may identify the packet that has caused or identified a conflict in the PDR.
[0043] In some examples, the method 200 may include: after sending an indication to the second network node, receiving a modification to one or more of the packet detection rules (e.g., from the second network node), and modifying the one or more packet detection rules to generate a modified packet detection rule according to the modification. Thus, for example, the PDR may be modified so that the packet does not match all modified packet detection rules (although other PDRs configured in the first network node may already exist in step 204 that do not match the packet). In some cases, the packet may only match one modified PDR. In some examples, the method 200 may also include executing a corresponding action associated with each modified packet detection rule matched by the packet. The corresponding action may be one or more of a forwarding action rule FAR, a buffering action rule BAR, a quality execution rule QER, a usage reporting rule URR, and / or a policy control and charging PCC rule. Thus, after the PDR has been modified, an action may be performed on the packet. In other examples, an action may be taken before the modification-e.g., an action associated with the highest priority matching PDR, or an action associated with all matching PDRs. The modification may include, for example, one or more of the following: adding one or more new PDRs, deleting one or more existing PDRs, and / or changing one or more parameters of one or more existing PDRs.
[0044] In some examples, sending the indication to the second network node includes sending an indication that a threshold number of packets or bytes have matched a plurality of packet detection rules.
[0045] In some examples, each packet detection rule is associated with a corresponding further indication indicating whether a packet matched with the packet detection rule is allowed to match with one or more other packet detection rules. Therefore, for example, some PDRs may be allowed to match packets that also match with one or more other PDRs. Therefore, in some examples, sending an indication to the second network node includes sending an indication that the packet matches with at least one packet detection rule, wherein the at least one packet detection rule is associated with a further indication that the packet is not allowed to match with any other packet detection rule. In these cases, for example, if all of the multiple matching PDRs are allowed to be multiple matching PDRs, i.e., the packet matches with these multiple PDRs, then the indication is not sent to the second network node. In some examples, further indications (that (one or more) PDRs may be allowed to match packets that also match with (one or more) other PDRs) may be received from the second network node. Additionally or alternatively, the packet detection rule may be received from the second network node.
[0046] Figure 3 Flowchart of an example of a method 300 for traffic monitoring in a second network node (such as, for example, a session management function SMF or a packet gateway-control plane PGW-C). The method 300 includes: in step 302, sending a plurality of packet detection rules to a first network node (such as, for example, a user plane function UPF, a packet gateway PGW or a packet gateway-user plane PGW-U). In some examples, the first network node may implement the method 200 described above. Step 304 of the method 300 includes receiving (e.g., from the first network node) an indication that a packet received at the first network node matches the plurality of packet detection rules. Thus, for example, the second network node may determine that there is a conflict in a PDR configured in the first network node.
[0047] In some examples, the indication identifies or includes multiple packet detection rules. Additionally or alternatively, method 300 includes receiving a packet from a first network node. Thus, for example, the second network node (or another network node if the information is forwarded to another network node) can determine the conflicting PDR.
[0048] In some examples, method 300 may include sending an indication to a third network node (such as, for example, a PCF), receiving a modification to one or more packet detection rules (e.g., from the third network node), and sending the modification to the first network node. Thus, for example, the PDR configured in the first network node may be modified so that the packet matches fewer (e.g., only one) modified PDRs.
[0049] In some examples, each packet detection rule is associated with a corresponding further indication indicating whether a packet matching the packet detection rule is allowed to match one or more other packet detection rules. Thus, in some examples, receiving an indication includes receiving an indication that the packet matches at least one packet detection rule, wherein the at least one packet detection rule is associated with a further indication that the packet is not allowed to match any other packet detection rule. Thus, an indication is received only if one or more conflicting PDRs are not allowed to be multi-match PDRs, i.e., PDRs in a group that matches the packet.
[0050] In some examples, the second network node may send the packet detection rule to the first network node prior to receiving the indication.
[0051] Figure 4 4 is a flow chart of an example of a method 400 for traffic monitoring. In some examples, the method 400 may be implemented in a PCF. The method 400 includes: in step 402, receiving an indication that a packet received at a first network node matches a plurality of packet detection rules. The indication may be received from a second network node (e.g., a session management function SMF or a packet gateway-control plane PGW-C). Step 404 of the method 400 includes sending a modification to at least one packet detection rule to the first network node. In some examples, the modification is sent via the second network node. In some examples, the first network node may include a UPF, a PGW, or a PGW-U. In some examples, the first network node may perform the method 200 described above, and / or the second network node may perform the method 300 described above.
[0052] Figure 5 is a schematic diagram of an example of an apparatus 500 for traffic monitoring in a first network node. The apparatus 500 includes a processing circuit 502 (e.g., one or more processors) and a memory 504 in communication with the processing circuit 502. The memory 504 contains instructions that can be executed by the processing circuit 502. The apparatus 500 also includes an interface 506 in communication with the processing circuit 502. Although the interface 506, the processing circuit 502, and the memory 504 are shown as being connected in series, they may alternatively be connected to each other in any other manner, such as via a bus.
[0053] In one embodiment, memory 504 includes instructions executable by processing circuit 502 so that apparatus 500 is operable to receive a packet, determine that the packet matches a plurality of packet detection rules, and send an indication to a second network node that the packet matches the plurality of packet detection rules. In some examples, memory 504 includes instructions executable by processing circuit 502 so that apparatus 500 is operable to perform method 200 described above.
[0054] Figure 6 6 is a schematic diagram of an example of an apparatus 600 for traffic monitoring in a second network node. The apparatus 600 includes a processing circuit 602 (e.g., one or more processors) and a memory 604 in communication with the processing circuit 602. The memory 604 contains instructions that can be executed by the processing circuit 602. The apparatus 600 also includes an interface 606 in communication with the processing circuit 602. Although the interface 606, the processing circuit 602, and the memory 604 are shown as being connected in series, they may alternatively be connected to each other in any other manner, such as via a bus.
[0055] In one embodiment, memory 604 includes instructions executable by processing circuit 602 so that apparatus 600 is operable to send a plurality of packet detection rules to a first network node, and receive an indication that a packet received at the first network node matches the plurality of packet detection rules. In some examples, memory 604 includes instructions executable by processing circuit 602 so that apparatus 600 is operable to perform method 300 described above.
[0056] Figure 7 is a schematic diagram of an example of an apparatus 700 for traffic monitoring (e.g., in a third network node such as a PCF). The apparatus 700 includes a processing circuit 702 (e.g., one or more processors) and a memory 704 in communication with the processing circuit 702. The memory 704 contains instructions that can be executed by the processing circuit 702. The apparatus 700 also includes an interface 706 in communication with the processing circuit 702. Although the interface 706, the processing circuit 702, and the memory 704 are shown as being connected in series, they may alternatively be connected to each other in any other manner, such as via a bus.
[0057] In one embodiment, memory 704 contains instructions executable by processing circuit 702 such that apparatus 700 is operable to receive an indication that a packet received at a first network node matches a plurality of packet detection rules, and to send a modification to at least one packet detection rule to the first network node.
[0058] Additional specific example embodiments will now be described.
[0059] Embodiments of the present disclosure may be based on a scenario consisting of a UE appropriately connected to a mobile network, where there will be a node with deep packet inspection and service classification capabilities (UPF) and an SMF that sends PDR rules to the UPF.
[0060] - UPF: User plane function with deep packet inspection and service classification requires updated rules from PFDF to correctly classify traffic from UE and apply e.g. desired QoS or charging.
[0061] -SMF: Session Management Function. Responsible for selecting the corresponding UPF for the PDU session and responsible for controlling UPF capabilities, such as traffic detection, traffic reporting, QoS enforcement and / or traffic routing.
[0062] -UE: User Equipment.
[0063] -PCF: Policy and Charging Rules Function. This is the functional unit that performs policy control decision making and flow-based charging control. PCF provides network control with respect to service data flow detection.
[0064] Figure 8 An example of communication 800 between network entities is shown, for example in an embodiment where the PCF does not support real-time multi-classification (i.e., the PCF does not support the case where a packet is matched to multiple PDRs), for example, when establishing and / or performing traffic monitoring. The communication includes the following (which may also be steps of a method).
[0065] Step 802: The end user (eg, UE) establishes a PDU session
[0066] • Step 804: The SMF creates a PFCP session towards the UPF. It sends a PDR for the end user with information on how to classify the traffic.
[0067] Step 806: UPF indicates to SMF that it can provide multiple classifications.
[0068] Step 808: The SMF indicates to the PCF that the UPF can provide multi-classification information.
[0069] Step 810: The PCF indicates that it cannot process multi-class information in real time. Therefore, it cannot provide modifications. It may optionally indicate which PDRs they want to track do not have multi-class (i.e., for example, which PDR or PDRs are to be associated with an indication that they cannot match packets that also match other PDRs).
[0070] Step 812: The SMF indicates to the UPF which PDRs cannot have multi-classification. In this example, PDR X and PDR Z.
[0071] Step 814: UPF confirms the previous message. Then, UPF checks all traffic.
[0072] Step 816: The end user generates traffic.
[0073] • Step 818: UPF reports the usage of each PDR. For those rules that are multi-classified in the PDR defined in step 812, it may report those PDRs with multiple matches, for example after reaching a certain threshold.
[0074] Step 820: SMF replies with a response. SMF sends this information to PCF.
[0075] Step 822: The PCF replies to the SMF.
[0076] Step 824: The end user disconnects the session.
[0077] Step 826: SMF sends a request to delete the PFCP session.
[0078] Step 828: UPF sends a PDR with multiple categories in the same format as in step 818.
[0079] Step 830: SMF sends information to PCF.
[0080] Fig. 9 Another example of communication 900 between network entities is shown, in a scenario where the PCF may modify the PDR configured in the UPF, for example in real time, for example when establishing and / or performing traffic monitoring. The communication includes the following (which may also be steps of a method).
[0081] Step 902: The end user establishes a PDU session
[0082] • Step 904: The SMF creates a PFCP session towards the UPF. It sends a PDR for the end user with information on how to classify the traffic.
[0083] Step 906: The UPF indicates to the SMF that it can provide multiple classifications.
[0084] Step 908: The SMF indicates to the PCF that the UPF can provide multi-classification information.
[0085] Step 910: The PCF indicates that it can handle multi-classification information in real time. Therefore, it can provide modifications. It can optionally send which PDRs they want to track that do not have multi-classification.
[0086] Step 912: The SMF indicates to the UPF which PDRs cannot have multiple classifications.
[0087] Step 914: UPF confirms the previous message. Then, UPF checks all traffic.
[0088] Step 916: The end user generates traffic.
[0089] • Step 918: UPF reports the usage of each PDR. For those rules that are multi-classified in the PDR defined in step 912, it may report those PDRs with multiple matches, for example after reaching a certain threshold.
[0090] Step 920: SMF replies with a response. SMF sends this information to PCF.
[0091] Step 922: PCF replies to SMF. PCF processes information about PDR multi-classification. PCF (e.g., based on the rating group of PDR with multi-classification) can decide whether it should provide new rules (i.e., modifications to existing PDR) to SMF. PCF sends the modification of PDR to SMF, which indicates how PDR should be updated.
[0092] Step 924: The SMF modifies the PDR of the PFCP session according to the information received in the PCC rules of the PCF (ie according to the modification).
[0093] Step 926: UPF confirms the message and starts classification according to the modification.
[0094] It should be noted that the examples mentioned above illustrate rather than limit the present invention, and those skilled in the art will be able to design many alternative examples without departing from the scope of the appended claims. The word "comprising" does not exclude the existence of units or steps other than those listed in the claims, "one" or "an" does not exclude multiple, and a single processor or other unit can implement the functions of several units recorded in the following statements. In the case of using the terms "first", "second", etc., they should only be understood as labels for convenient identification of specific features. In particular, unless otherwise expressly stated, they should not be interpreted as describing the first or second feature (i.e., the first or second such feature occurring in time or space) of multiple such features. Unless otherwise expressly stated, the steps in the method disclosed herein can be performed in any order. Any figure mark in the claims should not be interpreted as limiting its scope.
Claims
1. A method for traffic monitoring in a first network node, the method comprising: receiving a plurality of packet detection rules from a second network node; Receive packets; detecting a packet detection rule conflict, the packet matching more than one packet detection rule of the plurality of packet detection rules in the first network node; sending an indication of the packet detection rule conflict to the second network node; as well as After sending the indication to the second network node, receiving a modification to one or more of the packet detection rules, the modification comprising one or more of a packet detection rule addition, a packet detection rule deletion, or a packet detection rule change; as well as According to the modification, the one or more packet detection rules in the packet detection rules are modified to obtain modified packet detection rules.
2. The method according to claim 1, wherein: The indication identifier may include the multiple group detection rules.
3. The method according to claim 1, comprising: In response to determining that the packet matches the plurality of packet detection rules, the packet is sent to the second network node.
4. The method according to claim 1, comprising: The modification is received from the second network node.
5. The method according to claim 1, wherein: The packet does not match all modified packet detection rules.
6. The method according to claim 1, comprising: A respective action associated with each of the modified packet detection rules matched by the packet is performed.
7. The method according to claim 6, wherein: The actions associated with each matched modified packet detection rule include one or more of: a forwarding action rule FAR, a buffering action rule BAR, a quality enforcement rule QER, a usage reporting rule URR, and / or a policy control and charging PCC rule.
8. The method according to claim 1, comprising: A corresponding action associated with each of the packet detection rules is performed.
9. The method according to claim 8, wherein: The actions associated with each packet detection rule include one or more of: forwarding action rules FAR, buffering action rules BAR, quality enforcement rules QER, usage reporting rules URR, and / or policy control and charging PCC rules.
10. The method according to claim 1, wherein: Sending the indication to the second network node includes sending an indication that a threshold number of packets or bytes have matched a plurality of packet detection rules.
11. The method according to claim 1, wherein: Each of the packet detection rules is associated with a corresponding indication indicating whether a packet matching the packet detection rule is allowed to match one or more other packet detection rules, and sending the indication to the second network node includes: sending an indication that the packet matches at least one packet detection rule, and the at least one packet detection rule is associated with an indication that the packet is not allowed to match any other packet detection rule.
12. The method according to claim 11, comprising: The indication is received from the second network node.
13. The method according to claim 1, comprising: The packet detection rule is received from the second network node.
14. The method according to claim 1, wherein: The second network node comprises a session management function SMF or a packet gateway-control plane PGW-C.
15. The method according to claim 1, wherein: The method is performed by a user plane function UPF, a packet gateway PGW, or a packet gateway-user plane PGW-U.
16. The method according to claim 1, wherein: Determining that the packet matches the plurality of packet detection rules includes: for each packet detection rule, determining that the packet matches corresponding packet detection information PDI associated with the packet detection rule.
17. A method according to any one of the preceding claims, wherein: The packet is received from a user equipment UE or the Internet.
18. A method for traffic monitoring in a second network node, the method comprising: sending a plurality of packet detection rules to a first network node; receiving an indication of a packet detection rule conflict at the first network node, wherein the packet matches more than one packet detection rule of a plurality of packet detection rules in the first network node; sending the indication to a third network node; receiving, from a third network node, a modification to one or more of the packet detection rules; the modification comprising one or more of a packet detection rule addition, a packet detection rule deletion, or a packet detection rule change; as well as The modification is sent to the first network node to trigger the first network node to modify the packet detection rule to obtain a modified packet detection rule.
19. The method according to claim 18, comprising: The indication is received from the first network node.
20. The method according to claim 18, wherein: The indication identifier may include the multiple group detection rules.
21. The method according to claim 18, comprising: The packet is received from the first network node.
22. The method according to claim 18, comprising: The modification is received from the third network node.
23. The method according to claim 18, wherein: The packet does not match any packet detection rules to which the modification is applied.
24. The method according to claim 18, wherein: The third network node comprises a Packet Control Function PCF.
25. The method according to claim 24, wherein: Each of the packet detection rules is associated with a corresponding action for the first network node.
26. The method according to claim 25, wherein: The actions associated with each packet detection rule include one or more of: forwarding action rules FAR, buffering action rules BAR, quality enforcement rules QER, usage reporting rules URR, and / or policy control and charging PCC rules.
27. The method according to claim 18, wherein: Receiving the indication includes receiving an indication that a threshold number of packets or bytes have matched a plurality of packet detection rules at the first network node.
28. The method of claim 18, wherein: Each of the packet detection rules is associated with a corresponding indication indicating whether a packet matching the packet detection rule is allowed to match one or more other packet detection rules, and receiving the indication includes: receiving an indication that the packet matches at least one packet detection rule, and the at least one packet detection rule is associated with an indication that the packet is not allowed to match any other packet detection rule.
29. The method of claim 18, comprising: The packet detection rule is sent to the first network node prior to receiving the indication.
30. The method of claim 18, wherein: The second network node comprises a session management function SMF or a packet gateway-control plane PGW-C.
31. The method according to any one of claims 18 to 30, wherein: The first network node includes a user plane function UPF, a packet gateway PGW, or a packet gateway-user plane PGW-U.
32. A method for flow monitoring, the method comprising: receiving, via the second network node, an indication that a packet received at the first network node conflicts with a plurality of packet detection rules, wherein the packet matches more than one of the plurality of packet detection rules in the first network node; After receiving the indication, determining a modification to the packet detection rule; the modification includes one or more of adding a packet detection rule, deleting a packet detection rule, or changing a packet detection rule; as well as The modification is sent to the first network node to trigger the first network node to modify the packet detection rule to obtain a modified packet detection rule.
33. The method of claim 32, wherein: Sending the modification includes sending the modification via a second network node.
34. The method of claim 33, wherein: The second network node comprises a session management function SMF or a packet gateway-control plane PGW-C.
35. The method of claim 32, wherein: The first network node includes a user plane function UPF, a packet gateway PGW, or a packet gateway-user plane PGW-U.
36. The method of claim 32, wherein: The method is performed by a group control function.
37. The method of claim 32, wherein: The packet does not match any packet detection rules to which the modification is applied.
38. A computer program product comprising instructions which, when executed on at least one processor, cause the at least one processor to perform the method according to any one of claims 1 to 37.
39. A computer-readable storage medium comprising instructions which, when executed on at least one processor, cause the at least one processor to perform the method of any one of claims 1 to 37.
40. An apparatus for traffic monitoring in a first network node, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor such that the apparatus is operable to: receiving a plurality of packet detection rules from a second network node; Receive packets; detecting a packet detection rule conflict, the packet matching more than one packet detection rule of the plurality of packet detection rules in the first network node; sending an indication of the packet detection rule conflict to the second network node; as well as After sending the indication to the second network node, receiving a modification to one or more of the packet detection rules, the modification comprising one or more of a packet detection rule addition, a packet detection rule deletion, or a packet detection rule change; as well as According to the modification, the one or more packet detection rules in the packet detection rules are modified to obtain modified packet detection rules.
41. The device according to claim 40, wherein The memory contains instructions executable by the processor such that the apparatus is operable to perform a method according to any one of claims 2 to 17.
42. An apparatus for traffic monitoring in a second network node, the apparatus comprising a processor and a memory, the memory containing instructions executable by the processor such that the apparatus is operable to: sending a plurality of packet detection rules to a first network node; receiving an indication that a packet received at the first network node conflicts with the plurality of packet detection rules, wherein the packet matches more than one of the plurality of packet detection rules in the first network node; sending the indication to a third network node; receiving, from a third network node, a modification to one or more of the packet detection rules; the modification comprising one or more of a packet detection rule addition, a packet detection rule deletion, or a packet detection rule change; as well as The modification is sent to the first network node to trigger the first network node to modify the packet detection rule to obtain a modified packet detection rule.
43. The device according to claim 42, wherein: The memory contains instructions executable by the processor such that the apparatus is operable to perform a method according to any one of claims 19 to 31.
Citation Information
Patent Citations
Incremental Update Heuristics
US20130282766A1