A service awareness method, communication apparatus and communication system
By working together with the session management function network element and the user plane function network element, and by utilizing detection rules and packet detection feature information, the problem of difficulty in distinguishing encrypted packets or packets with the same header is solved, achieving highly accurate application detection and resource conservation.
Patent Information
- Application Number
- CN202110929598.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-08-13
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2041-08-13
AI Technical Summary
Existing technologies cannot effectively distinguish between encrypted messages or messages from different application services with the same header, resulting in insufficient accuracy in application detection.
The session management function network element sends detection rules and packet detection feature information, and the user plane function network element performs application detection, which is combined with flow description information to improve accuracy.
It enables effective differentiation of different application service messages, improves the accuracy of application detection, and reduces the amount of data transmission of network resources.
Smart Images

Figure CN115942362B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communication technology, and in particular to a service sensing method, communication device and communication system. Background Technology
[0002] In existing technologies, application detection for business flows mainly relies on pre-configuring the plaintext domain name information (such as IP triples, domain names, fully qualified domain names (FQDNs)) carried in the packet header corresponding to the application identifier, and performing application detection based on the plaintext domain name information carried in the packet header to identify which application's business flow the packet belongs to.
[0003] However, in real-world scenarios, the application messages transmitted by terminal devices may be encrypted messages, or the same message header may actually correspond to multiple different services. In such cases, existing technologies cannot effectively distinguish between messages from different application services. Summary of the Invention
[0004] This application provides a service awareness method, communication device, and communication system for effectively distinguishing messages from different application services.
[0005] In a first aspect, embodiments of this application provide a service awareness method, which can be executed by a session management function network element or a module (such as a chip) applied in the session management function network element.
[0006] The method includes: a session management function network element sending a first request message to a user plane function network element, the first request message including detection rules and usage reporting rules, the detection rules including an application service identifier and packet detection feature information, the detection rules being used to detect the service flow of the application service in the session, the packet detection feature information being used to indicate the matching features of the service flow of the application service, the usage reporting rules including a first event identifier, the first event identifier being used to indicate an event for reporting the service flow of the application service, the event being an application start event or an application end event; the session management function network element receiving a first event report from the user plane function network element, the first event report being used to indicate the event of the service flow of the application service.
[0007] The above technical solution allows the session management function network element to request the user plane function network element to perform application detection by sending a request message, and to provide packet detection feature information of the application service. The user plane function network element can then perform application detection on received packets based on this packet detection feature information. This effectively distinguishes packets of different application services and significantly improves the accuracy of application detection.
[0008] In one possible design of the first aspect, the method further includes: a session management function network element receiving a second request message from a policy control function network element, the second request message being used to subscribe to the event, the second request message including an identifier of the application service, packet detection feature information, and a second event identifier, the second event identifier being used to indicate reporting the event; and the session management function network element sending a second event report to the policy control function network element, the second event report being used to indicate the event.
[0009] In one possible design of the first aspect, the packet detection feature information includes statistical features and / or header features of packets in the service flow of the application service.
[0010] The above technical solution can solve the problem that the limited capacity of plaintext domain name information in the packet header makes it impossible to determine the business flow to which the packet belongs and to accurately identify the type of application service. For example, it can accurately identify packets from different application services even when encrypted packets or packets from different application services have the same packet header.
[0011] In one possible design of the first aspect, the detection rule further includes flow description information, which is used to indicate the service flow to which the packet detection feature information applies; the second request message includes the flow description information.
[0012] The above technical solution combines packet detection feature information with flow description information for application detection, which can effectively improve the accuracy of application detection.
[0013] In one possible design of the first aspect, the first event report includes an identifier of the application service and a first event identifier, and the second event report includes an identifier of the application service and a second event identifier.
[0014] Secondly, embodiments of this application provide a service awareness method, which can be executed by a user plane function network element or a module (such as a chip) applied in the user plane function network element.
[0015] The method includes: a user plane function network element receiving a first request message from a session management function network element, the first request message including detection rules and usage reporting rules, the detection rules including an application service identifier and packet detection feature information, the detection rules being used to detect the service flow of the application service in the session, the packet detection feature information being used to indicate the matching features of the service flow of the application service, the usage reporting rules including a first event identifier, the first event identifier being used to indicate an event for reporting the service flow of the application service, the event being an application start event or an application end event; the user plane function network element performing application detection on the received packets in the session according to the packet detection feature information; if an event of the service flow of the application service is detected, the user plane function network element sending a first event report to the session management function network element, the first event report being used to indicate the event.
[0016] In one possible design of the second aspect, the packet detection feature information includes statistical features and / or header features of packets in the service flow of the application service.
[0017] In one possible design of the second aspect, the detection rule includes flow description information, which is used to indicate the service flow to which the packet detection feature information applies; the user plane function network element performs application detection on the received packets according to the packet detection feature information, including: the user plane function network element performs application detection on the packets in the session that match the flow description information according to the packet detection feature information.
[0018] In one possible design of the second aspect, the first event report includes the identifier of the application service and the identifier of the first event.
[0019] Thirdly, embodiments of this application provide a service awareness method, which can be executed by a policy control function network element or applied to a module (such as a chip) in the policy control function network element.
[0020] The method includes: a policy control function network element receiving a third request message from an application function network element, the third request message including an identifier of an application service, packet detection feature information, and a third event identifier, the packet detection feature information indicating the matching characteristics of the service flow of the application service, and the third event identifier indicating an event for reporting the service flow of the application service, the event being an application start event or an application end event; the policy control function network element sending a second request message to a session management function network element, the second request message requesting subscription to the event, the second request message including the identifier of the application service, packet detection feature information, and a second event identifier, the second event identifier indicating reporting the event; the policy control function network element receiving a second event report from the session management function network element, the second event report indicating the event; and the policy control function network element sending a third event report to the application function network element, the second event report indicating the event.
[0021] In one possible design of the third aspect, the packet detection feature information includes statistical features and / or header features of packets in the service flow of the application service.
[0022] In one possible design of the third aspect, the second request message and the third request message also include flow description information, which is used to indicate the service flow to which the packet detection feature information applies.
[0023] In one possible design of the third aspect, the second event report includes the identifier of the application service and the second event identifier, and the third event report includes the identifier of the application service and the third event identifier.
[0024] Fourthly, embodiments of this application provide a service awareness method, which can be executed by an application function network element or applied to a module (such as a chip) within the application function network element.
[0025] The method includes: an application function network element sending a third request message to a policy control function network element, the third request message including an identifier of the application service, packet detection feature information, and a third event identifier, the packet detection feature information being used to indicate the matching characteristics of the service flow of the application service, and the third event identifier being used to indicate an event that reports the service flow of the application service, the event being an application start event or an application end event; the application function network element receiving a third event report from the policy control function network element, the third event report being used to indicate the event.
[0026] In one possible design of the fourth aspect, the packet detection feature information includes statistical features and / or header features of packets in the service flow of the application service.
[0027] In one possible design of the fourth aspect, the third request message also includes flow description information, which is used to indicate the service flow to which the packet detection feature information applies.
[0028] In one possible design of the fourth aspect, the third event report includes the identifier of the application service and the third event identifier.
[0029] In one possible design of the fourth aspect, the application start event is used to trigger the policy control function network element to initiate a configuration update process to the terminal device.
[0030] The beneficial effects of any of the possible designs in the second to fourth aspects mentioned above can be referred to the corresponding description in the first aspect, and the repeated parts will not be repeated.
[0031] Fifthly, embodiments of this application provide a service awareness method, which can be executed by a network data analysis function network element or a module (such as a chip) applied in the network data analysis function network element.
[0032] The method includes: a network data analysis function network element receiving a fourth request message from an application function network element, the fourth request message being used to request analysis of events related to the service flow of an application service, the event being an application start event or an application end event, the fourth request message including the identifier of the application service and packet detection feature information, the packet detection feature information being used to indicate the matching features of the service flow of the application service; the network data analysis function network element sending a fifth request message to a session management function network element, the fifth request message being used to request mirroring of packets in a session of a forwarding terminal device; the network data analysis function network element performing application detection on the mirrored packets received from the session management function network element or the user plane function network element based on the packet detection feature information; if an event related to the service flow of the application service is detected, the network data analysis function network element sending an event report to the application function network element, the event report being used to indicate the event.
[0033] In the above technical solution, the network data analysis function network element can obtain the image of the packets in the session of the terminal device from the user plane function network element through the session management function network element. Based on the packet detection feature information provided by the application function network element, it performs application detection on the received packet image and returns the corresponding event report to the application function network element. This effectively distinguishes packets from different application services and significantly improves the accuracy of application detection.
[0034] In one possible design of the fifth aspect, the packet detection feature information includes statistical features and / or header features of packets in the service flow of the application service.
[0035] The above technical solution can solve the problem that the limited capacity of plaintext domain name information in the packet header makes it impossible to determine the business flow to which the packet belongs and to accurately identify the type of application service. For example, it can accurately identify packets from different application services even when encrypted packets or packets from different application services have the same packet header.
[0036] In one possible design of the fifth aspect, the fourth request message further includes flow description information, which is used to indicate the service flow to which the packet detection feature information applies; the fifth request message further includes flow description information, which is used to indicate the mirror image of a packet in the session of the forwarding terminal device that matches the flow description information.
[0037] The above technical solution combines packet detection feature information and flow description information for application detection, which can effectively improve the accuracy of application detection. Furthermore, the network data analysis function network element can request mirror images of packets in the terminal device's session that match the flow description information, eliminating the need to forward mirror images of all packets. This reduces the amount of data transmitted between network elements and fully utilizes network resources.
[0038] In one possible design of the fifth aspect, the fifth request message further includes a mirror destination address, which is the address in the network data analysis function network element that receives the mirror image. This facilitates the forwarding of mirrored service flows from the terminal device's session to the network data analysis function network element by the session management function network element or the user plane function network element.
[0039] In one possible design of the fifth aspect, the fourth request message further includes an event identifier, which is used to indicate that the event should be reported; the event report includes the identifier of the application service and the event identifier.
[0040] Sixthly, embodiments of this application provide a service-aware method, which can be executed by a session management function network element or a module (such as a chip) applied in the session management function network element.
[0041] The method includes: a session management function network element receiving a fifth request message from a network data analysis function network element, the fifth request message being used to request the mirroring of packets in a session of a terminal device; the session management function network element sending a sixth request message to a user plane function network element, the sixth request message including detection rules and forwarding rules, the detection rules being used to detect the service flow of a session of a terminal device, and the forwarding rules including a mirroring forwarding indication being used to indicate the forwarding of the mirrored packets.
[0042] In one possible design of the sixth aspect, the fifth request message includes flow description information, which is used to indicate the mirror image of a packet in the session of the forwarding terminal device that matches the flow description information; the detection rule includes the flow description information.
[0043] In one possible design of the sixth aspect, the detection rule includes wildcard indication information, which is used to forward mirrors of all packets in the session of the terminal device.
[0044] The above technical solution, by including flow description information or wildcard indication information in the detection rules, allows the session management function network element to clearly inform the user plane function network element which packets in the terminal device's session need to be mirrored, thereby facilitating the user plane function network element to perform corresponding processing.
[0045] In one possible design of the sixth aspect, the fifth request message also includes a mirror destination address, which is the address in the network data analysis function network element that receives the mirror.
[0046] In one possible design of the sixth aspect, the method further includes: the session management function network element receiving the image from the user plane function network element, and sending the image to the network data analysis function network element according to the destination address of the image; or, the forwarding rule further includes the destination address of the image.
[0047] Seventhly, embodiments of this application provide a service awareness method, which can be executed by a user plane function network element or a module (such as a chip) applied in the user plane function network element.
[0048] The method includes: a user plane function network element receiving a sixth request message from a session management function network element, the sixth request message including detection rules and forwarding rules, the detection rules being used to detect service flows in a session of a terminal device, and the forwarding rules including a mirror forwarding indication being used to indicate the mirroring of packets in a session of the terminal device; the user plane function network element detecting packets in a session of the terminal device according to the detection rules; and the user plane function network element sending the mirrored packets to a session management function network element or a network data analysis function network element according to the mirror forwarding indication.
[0049] In one possible design of the seventh aspect, the detection rule includes flow description information; the method further includes: the user plane function network element sending a mirror image of a packet in the terminal device's session that matches the flow description information to the session management function network element or the network data analysis function network element based on the flow description information.
[0050] In one possible design of the seventh aspect, the detection rule includes wildcard indication information; the method further includes: the user plane function network element sending a mirror image of all packets in the session of the terminal device to the session management function network element or the network data analysis function network element according to the wildcard indication information.
[0051] In one possible design of the seventh aspect, the forwarding rule further includes a mirror destination address; the user plane function network element sending the mirror to the network data analysis function network element includes: the user plane function network element sending the mirror to the network data analysis function network element according to the mirror destination address.
[0052] Eighthly, embodiments of this application provide a service awareness method, which can be executed by an application function network element or a module (such as a chip) applied in the application function network element.
[0053] The method includes: an application function network element sending a fourth request message to a network data analysis function network element, the fourth request message being used to request the analysis of an event of the service flow of the application service, the event being an application start event or an application end event, the fourth request message including the identifier of the application service and packet detection feature information, the packet detection feature information being used to indicate the matching features of the service flow of the application service; and the application function network element receiving an event report from the network data analysis function network element, the event report being used to indicate the event.
[0054] In one possible design of the eighth aspect, the packet detection feature information includes statistical features and / or header features of packets in the service flow of the application service.
[0055] In one possible design of the eighth aspect, the fourth request message also includes flow description information, which is used to indicate the service flow to which the packet detection feature information applies.
[0056] In one possible design of the eighth aspect, the fourth request message further includes an event identifier, which is used to indicate that the event should be reported; the event report includes the identifier of the application service and the event identifier.
[0057] The beneficial effects of any of the possible designs in aspects six through eight above can be found in the corresponding description in aspect five, and will not be repeated here.
[0058] Ninthly, embodiments of this application provide a service awareness method, which can be executed by an application function network element or a module (such as a chip) applied in the application function network element.
[0059] The method includes: an application function network element sending a seventh request message to a policy control function network element, the seventh request message being used to obtain a mirror image of a packet in a session of a terminal device, the seventh request message including a mirror destination address, the mirror destination address being the address in the application function network element that receives the mirror image; the application function network element receiving the mirror image from a user plane function network element; and the application function network element performing application detection based on the mirror image.
[0060] In the above technical solution, the application function network element can send forwarding rules to the user plane function network element through the policy control function network element and the session management function network element to obtain the image of the packets in the session of the terminal device, and then perform application detection based on the image of the received packets. This enables the application function network element to perceive the type of application service actually initiated by the terminal device, which facilitates the AF to execute corresponding management decisions based on the application service currently initiated by the terminal device.
[0061] In one possible design of the ninth aspect, the seventh request message further includes flow description information, which is used to indicate the mirror image of a packet in the session of the forwarding terminal device that matches the flow description information.
[0062] In the above technical solution, by carrying flow description information in the seventh request message, the application function network element can request to forward the mirror image of the packet in the session of the terminal device that matches the flow description information, without having to forward the mirror image of all packets, thereby reducing the amount of data of packets transmitted between network elements and making full use of network resources.
[0063] In a tenth aspect, embodiments of this application provide a service awareness method, which can be executed by a policy control function network element or a module (such as a chip) applied in the policy control function network element.
[0064] The method includes: a policy control function network element receiving a seventh request message from an application function network element, the seventh request message being used to obtain a mirror of a packet in a session of a terminal device, the seventh request message including a mirror destination address, the mirror destination address being the address in the application function network element that receives the mirror; the policy control function network element sending an eighth request message to a session management function network element, the eighth request message being used to request the forwarding of the mirror, the eighth request message including the mirror destination address.
[0065] In one possible design of the tenth aspect, the seventh request message further includes flow description information, which is used to indicate the mirror image of a packet in the session of the forwarding terminal device that matches the flow description information; the eighth request message also includes the flow description information.
[0066] Eleventhly, embodiments of this application provide a service awareness method, which can be executed by a session management function network element or a module (such as a chip) applied in the session management function network element.
[0067] The method includes: a session management function network element receiving an eighth request message from a policy control function network element, the eighth request message being used to request the mirroring of packets in the session of a terminal device, the eighth request message including a mirroring destination address, the mirroring destination address being the address in the application function network element that receives the mirrored packets; the session management function network element sending a ninth request message to a user plane function network element, the ninth request message including detection rules and forwarding rules, the detection rules being used to detect service flows in the session of the terminal device, the forwarding rules being used to mirror and forward packets in the session of the terminal device, the forwarding rules including a mirroring forwarding indication and the mirroring destination address, the mirroring forwarding indication being used to indicate the forwarding of the mirrored packets.
[0068] In one possible design of the eleventh aspect, the detection rule includes flow description information, which is used to indicate the mirror image of a packet in a session of a forwarding terminal device that matches the flow description information.
[0069] In one possible design of the eleventh aspect, the detection rule includes wildcard indication information, which is used to forward mirrors of all packets in the session of the terminal device.
[0070] In the above technical solution, by including flow description information or wildcard indication information in the detection rules, the session management function network element can clearly inform the user plane function network element which packets in the terminal device's session need to be forwarded, thereby facilitating the user plane function network element to perform corresponding processing.
[0071] In a twelfth aspect, embodiments of this application provide a service awareness method, which can be executed by a user plane function network element or a module (such as a chip) applied in the user plane function network element.
[0072] The method includes: a user plane function network element receiving detection rules and forwarding rules from a session management function network element. The detection rules are used to detect service flows in the session of the terminal device, and the forwarding rules are used to mirror and forward packets in the session of the terminal device. The forwarding rules include a mirror forwarding instruction and a mirror destination address, where the mirror destination address is the address in the application function network element that receives the mirror; the user plane function network element detects packets in the session of the terminal device according to the detection rules; and the user plane function network element sends the mirror to the application function network element according to the mirror forwarding instruction and the mirror destination address.
[0073] In one possible design of the twelfth aspect, the detection rule includes flow description information; the method further includes: the user plane function network element sending a mirror image of a packet in the terminal device's session that matches the flow description information to the application function network element based on the flow description information.
[0074] In one possible design of the twelfth aspect, the detection rule includes wildcard indication information; the method further includes: the user plane function network element sending a mirror image of all packets in the session of the terminal device to the application function network element according to the wildcard indication information.
[0075] The beneficial effects of any of the possible designs in aspects 10 to 12 above can be found in the corresponding description in aspect 9, and will not be repeated here.
[0076] In a thirteenth aspect, embodiments of this application provide a communication device that may have the function of an application function network element implementing any of the above-mentioned aspects or possible designs, or the function of a policy control function network element implementing any of the above-mentioned aspects or possible designs, or the function of a session management function network element implementing any of the above-mentioned aspects or possible designs, or the function of a user plane function network element implementing any of the above-mentioned aspects or possible designs, or the function of a network data analysis function network element implementing any of the above-mentioned aspects or possible designs. This device may be a network device or a chip included in a network device.
[0077] The functions of the aforementioned communication device can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules, units, or means corresponding to the aforementioned functions.
[0078] In one possible design, the device includes a processing module and a transceiver module. The processing module is configured to support the device in performing functions corresponding to application function network elements in any of the above-mentioned aspects or designs, or functions corresponding to policy control function network elements in any of the above-mentioned aspects or designs, or functions corresponding to session management function network elements in any of the above-mentioned aspects or designs, or functions corresponding to user plane function network elements in any of the above-mentioned aspects or designs, or functions corresponding to network data analysis function network elements in any of the above-mentioned aspects or designs. The transceiver module supports communication between the device and other communication devices. For example, when the device is a session management function network element, it can send a first request message to a user plane function network element. The communication device may also include a storage module coupled to the processing module, which stores necessary program instructions and data for the device. As an example, the processing module can be a processor, the communication module can be a transceiver, and the storage module can be a memory. The memory can be integrated with the processor or separated from it.
[0079] In another possible design, the device includes a processor and may also include memory. The processor is coupled to the memory and can be used to execute computer program instructions stored in the memory to cause the device to perform the methods in any of the above aspects or aspects of the possible design. Optionally, the device also includes a communication interface, to which the processor is coupled. When the device is a network device, the communication interface may be a transceiver or an input / output interface; when the device is a chip included in a network device, the communication interface may be the chip's input / output interface. Optionally, the transceiver may be a transceiver circuit, and the input / output interface may be an input / output circuit.
[0080] In a fourteenth aspect, embodiments of this application provide a chip system comprising: a processor coupled to a memory for storing programs or instructions, wherein when the programs or instructions are executed by the processor, the chip system implements any of the above-mentioned aspects or any possible design methods in each aspect.
[0081] Optionally, the chip system also includes an interface circuit for exchanging code instructions with the processor.
[0082] Optionally, the chip system may include one or more processors, which can be implemented in hardware or software. When implemented in hardware, the processor may be a logic circuit, integrated circuit, etc. When implemented in software, the processor may be a general-purpose processor that reads software code stored in memory.
[0083] Optionally, the chip system may contain one or more memories. These memories may be integrated with the processor or disposed separately. For example, the memory may be a non-transitory processor, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or disposed on separate chips.
[0084] In a fifteenth aspect, embodiments of this application also provide a computer-readable storage medium storing instructions that, when executed on a communication device, cause the methods in any of the above aspects or any possible designs to be performed.
[0085] In a sixteenth aspect, embodiments of this application also provide a computer program product comprising a computer program or instructions that, when executed by a communication device, cause the methods in any of the above-described aspects or aspects to be performed.
[0086] In a seventeenth aspect, embodiments of this application also provide a communication system, which includes a session management function network element for performing the methods described in the third aspect or any possible design of the third aspect, and a user plane function network element for performing the methods described in the fourth aspect or any possible design of the fourth aspect.
[0087] Optionally, the communication system may further include application function network elements for performing the methods described in the first aspect or any possible design of the first aspect, and policy control function network elements for performing the methods described in the second aspect or any possible design of the second aspect.
[0088] In an eighteenth aspect, embodiments of this application also provide a communication system, which includes a network data analysis function network element for performing the methods in the sixth aspect or any possible design of the sixth aspect, and a session management function network element for performing the methods in the seventh aspect or any possible design of the seventh aspect.
[0089] Optionally, the communication system may further include application function network elements for performing the methods described in the fifth aspect or any possible design of the fifth aspect, and user plane function network elements for performing the methods described in the eighth aspect or any possible design of the eighth aspect.
[0090] In a nineteenth aspect, embodiments of this application also provide a communication system, which includes an application function network element for performing the methods described in the ninth aspect or any possible design of the ninth aspect, and a user plane function network element for performing the methods described in the twelfth aspect or any possible design of the twelfth aspect.
[0091] Optionally, the communication system may further include a policy control function network element for performing the methods in the tenth aspect or any of the possible designs in the tenth aspect, and a session management function network element for performing the methods in the eleventh aspect or any of the possible designs in the eleventh aspect. Attached Figure Description
[0092] Figure 1a , Figure 1b and Figure 1c A schematic diagram of a communication system provided in an embodiment of this application;
[0093] Figure 2a This is a schematic diagram of a 5G network architecture based on a service-oriented architecture.
[0094] Figure 2b This is a schematic diagram of a 5G network architecture based on a point-to-point interface.
[0095] Figure 3 A schematic diagram illustrating a service awareness method provided in an embodiment of this application;
[0096] Figure 4 A schematic diagram illustrating another service awareness method provided in an embodiment of this application;
[0097] Figure 5 A schematic diagram illustrating yet another service awareness method provided in an embodiment of this application;
[0098] Figure 6 and Figure 7 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application. Detailed Implementation
[0099] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The specific operating methods in the method embodiments can also be applied to the device embodiments or system embodiments.
[0100] In order to accurately perceive services and effectively distinguish messages from different application services, this application provides a communication system.
[0101] In the first implementation, such as Figure 1a As shown, the communication system may include session management function network elements and user plane function network elements. Optionally, the communication system may also include application function network elements and policy control function network elements.
[0102] A session management function network element is configured to send a first request message to a user plane function network element. This first request message includes detection rules and usage reporting rules. The detection rules include an application service identifier and packet detection feature information, used to detect the service flow of the application service. The packet detection feature information indicates the matching characteristics of the service flow of the application service. The usage reporting rules include a first event identifier, used to indicate an event for reporting the service flow of the application service, which may be an application start event or an application end event. The element is also configured to receive a first event report from the user plane function network element, used to indicate the event. Optionally, the element is further configured to receive a second request message from a policy control function network element, the second request message requesting subscription to the event. This second request message includes the application service identifier, packet detection feature information, and a second event identifier, used to indicate reporting the event. The element is also configured to send a second event report to the policy control function network element, used to indicate the event. The user plane function network element is used to receive a first request message from the session management function network element; perform application detection on the packets in the received session according to packet detection feature information; and if an event of the service flow of the application service is detected, send a first event report to the session management function network element.
[0103] Optionally, the policy control function network element is configured to send a second request message to the session management function network element; and to receive a second event report from the session management function network element; optionally, it is also configured to receive a third request message from the application function network element, the third request message including an application service identifier, packet detection feature information and a third event identifier, the third event identifier being used to indicate the reporting of the event; and to send a third event report to the application function network element, the third event report being used to indicate the event.
[0104] Optionally, the application function network element is used to send a third request message to the policy control function network element; and to receive a third event report from the policy control function network element.
[0105] In the second implementation, such as Figure 1b As shown, the communication system may include network data analysis function network elements and session management function network elements. Optionally, the communication system may also include application function network elements and user plane function network elements.
[0106] A network data analysis function network element is configured to receive a fourth request message from an application function network element, which requests analysis of events related to the service flow of an application service. These events are either application start events or application end events. The fourth request message includes the identifier of the application service and packet detection feature information, which indicates the matching characteristics of the service flow of the application service. It is also configured to send a fifth request message to a session management function network element, which requests the forwarding of a mirror image of packets within a terminal device's session. Furthermore, it is configured to receive the mirror image from the session management function network element or a user plane function network element. It is configured to perform application detection on the mirror image based on the packet detection feature information. Finally, it is configured to send an event report to the application function network element if the event is detected, which indicates the event. The session management function network element is configured to receive the fifth request message from the network data analysis function network element and send a sixth request message to the user plane function network element. This sixth request message includes detection rules and forwarding rules. The detection rules are used to detect the service flow of a terminal device's session, and the forwarding rules include a mirror forwarding indication, which instructs the forwarding of the mirror image.
[0107] Optionally, the application function network element is used to send a fourth request message to the network data analysis function network element and receive event reports from the network data analysis function network element.
[0108] Optionally, the user plane function network element is used to receive a sixth request message from the session management function network element; to detect service flows in the session of the terminal device according to the detection rules; and to send the image to the session management function network element or the network data analysis function network element according to the image forwarding instruction.
[0109] In the third implementation, such as Figure 1c As shown, the communication system may include application plane function network elements and user plane function network elements. Optionally, the communication system may also include policy control function network elements and session management function network elements.
[0110] An application function network element is used to send a seventh request message to a policy control function network element. This seventh request message is used to obtain a mirror image of packets in a terminal device's session. The seventh request message includes a destination address for the mirror image, which is the address in the application function network element that receives the mirror image. It is also used to receive the mirror image from a user plane function network element and to perform application detection based on the mirror image. The policy control function network element is used to receive the seventh request message from the application function network element and to send an eighth request message to a session management function network element. This eighth request message requests the forwarding of the mirror image and includes the destination address of the mirror image.
[0111] Optionally, the session management function network element is used to receive an eighth request message from the policy control function network element; and to send a ninth request message to the user plane function network element. The ninth request message includes detection rules and forwarding rules. The detection rules are used to detect service flows in the session of the terminal device, and the forwarding rules are used to mirror and forward packets in the session of the terminal device. The forwarding rules include a mirror forwarding indication and the mirror destination address. The mirror forwarding indication is used to indicate the forwarding of the mirror.
[0112] Optionally, the user plane function network element is used to receive detection rules and forwarding rules from the session management function network element; detect packets in the session of the terminal device according to the detection rules; and send the mirror to the application function network element according to the mirror forwarding instruction and the mirror destination address.
[0113] Figure 1a , Figure 1b or Figure 1c The system shown can be used in Figure 2a or Figure 2b The 5G network architecture shown can also be used in future network architectures, such as the sixth generation (6G) network architecture, etc., and this application does not limit it.
[0114] Figure 2a This is a schematic diagram of a 5G network architecture based on a service-oriented architecture. Figure 2a The 5G network architecture shown may include a data network (DN) and a carrier network. The functions of some of these network elements are briefly described below.
[0115] The operator network may include one or more of the following network elements: authentication server function (AUSF) network elements, network exposure function (NEF) network elements, policy control function (PCF) network elements, unified data management (UDM) network elements, unified data repository (UDR) network elements, network repository function (NRF) network elements, application function (AF) network elements, access and mobility management function (AMF) network elements, session management function (SMF) network elements, radio access network (RAN) equipment, user plane function (UPF) network elements, network data analysis function (NWDAF) network elements, and network slice selection function (NSSF) network elements. In the above-mentioned operator network, network elements or equipment other than radio access network equipment can be referred to as core network elements or core network equipment.
[0116] Wireless access network equipment can be a base station, an evolved NodeB (eNodeB), a transmission reception point (TRP), a next-generation NodeB (gNB) in a 5G mobile communication system, a next-generation base station in a 6G mobile communication system, a base station in a future mobile communication system, or an access node in a wireless fidelity (WiFi) system; it can also be a module or unit that performs some of the functions of a base station, for example, it can be a central unit (CU) or a distributed unit (DU). Wireless access network equipment can be a macro base station, a micro base station, an indoor station, a relay node, or a donor node, etc. The embodiments of this application do not limit the specific technology or equipment form used in the wireless access network equipment.
[0117] Terminals communicating with the RAN can also be called terminal equipment, user equipment (UE), mobile station, mobile terminal, etc. Terminals can be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), Internet of Things (IoT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grids, smart furniture, smart offices, smart wearables, smart transportation, smart cities, etc. Terminals can be mobile phones, tablets, computers with wireless transceiver capabilities, wearable devices, vehicles, drones, helicopters, airplanes, ships, robots, robotic arms, smart home devices, etc. The embodiments of this application do not limit the specific technology or device form used in the terminal.
[0118] Base stations and terminals can be fixed or mobile. They can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water; and they can be deployed in the air on aircraft, balloons, and artificial satellites. The embodiments of this application do not limit the application scenarios of base stations and terminals.
[0119] The AMF (Automatic Mobility Management) network element performs functions such as mobility management and access authentication / authorization. In addition, it is responsible for transmitting user policies between the terminal and the PCF (Programmable Default Function).
[0120] The SMF network element performs functions such as session management, execution of control policies issued by the PCF, selection of the UPF, and allocation of Internet Protocol (IP) addresses to terminals.
[0121] UPF network elements, as interfaces with the data network, perform functions such as user plane data forwarding, session / flow-based billing and statistics, and bandwidth limiting.
[0122] UDM network elements perform functions such as managing contracted data and authorizing user access.
[0123] UDR performs data storage and retrieval functions for types of data such as contract data, policy data, and application data.
[0124] NEF network elements are used to support the opening of capabilities and events.
[0125] AF (Application Provider) elements convey application-side requests to the network side, such as Quality of Service (QoS) requirements or user state event subscriptions. AF can be a third-party functional entity or an application service deployed by the operator, such as the IP Multimedia Subsystem (IMS) voice call service.
[0126] The PCF network element is responsible for policy control functions such as billing at the session and service flow levels, QoS bandwidth guarantee and mobility management, and terminal policy decision-making.
[0127] NRF network elements provide network element discovery functionality, offering network element information corresponding to the network element type based on requests from other network elements. NRF also provides network element management services, such as network element registration, updates, deregistration, and network element status subscription and push notifications.
[0128] The AUSF network element is responsible for authenticating users to determine whether to allow users or devices to access the network.
[0129] NSSF network elements are used to select network slices and count users within a network slice.
[0130] The NWDAF network element is responsible for performing analysis functions based on the input information collected from each node, and outputting corresponding analysis results for network operation and maintenance, policy decision-making, user experience evaluation and other scenarios.
[0131] A Domain Provider (DN) is a network located outside the carrier's network. A carrier's network can connect to multiple DNs, and various services can be deployed on a DN, providing data and / or voice services to terminals. For example, a DN might be the private network of a smart factory. Sensors installed in the workshop can act as terminals, and a control server for these sensors is deployed within the DN. The control server provides services to the sensors. Sensors can communicate with the control server, receive instructions from it, and transmit the collected sensor data back to the control server accordingly. Another example is a DN serving as an internal office network for a company. Employees' mobile phones or computers can act as terminals, accessing information and data resources on the company's internal office network.
[0132] Figure 2aNausf, Nnef, Npcf, Nudm, Naf, Namf, and Nsmf are the service interfaces provided by AUSF, NEF, PCF, UDM, AF, AMF, and SMF, respectively, used to invoke the corresponding service operations. N1, N2, N3, N4, and N6 are interface sequence numbers. The meanings of these interface sequence numbers can be found in the definitions in the 3rd Generation Partnership Project (3GPP) standard protocol, and are not limited here.
[0133] Figure 2b This is a schematic diagram of a 5G network architecture based on a point-to-point interface. For a description of the functions of the network elements, please refer to [reference needed]. Figure 2a The functions of the corresponding network elements will not be described in detail here. Figure 2b and Figure 2a The main difference is: Figure 2a The interfaces between the various control plane network elements are service-oriented interfaces. Figure 2b The interfaces between the various control plane network elements are point-to-point interfaces.
[0134] exist Figure 2b In the architecture shown, the interface names and functions between the various network elements are as follows:
[0135] 1) N1: The interface between AMF and the terminal, which can be used to transmit QoS control rules to the terminal.
[0136] 2) N2: The interface between AMF and RAN, which can be used to transmit radio bearer control information from the core network side to the RAN.
[0137] 3) N3: The interface between RAN and UPF, mainly used to transmit uplink and downlink user plane data between RAN and UPF.
[0138] 4) N4: The interface between SMF and UPF, which can be used to transmit information between the control plane and the user plane, including the distribution of forwarding rules, QoS control rules, traffic statistics rules, etc. from the control plane to the user plane, as well as the reporting of information from the user plane.
[0139] 5) N5: The interface between AF and PCF, which can be used for application service request distribution and network event reporting.
[0140] 6) N6: The interface between UPF and DN, used to transmit uplink and downlink user data streams between UPF and DN.
[0141] 7) N7: The interface between PCF and SMF, which can be used to issue protocol data unit (PDU) session granularity and business data flow granularity control strategies.
[0142] 8) N8: The interface between AMF and UDM, which can be used by AMF to obtain access and mobility management related subscription data and authentication data from UDM, as well as by AMF to register terminal current mobility management related information with UDM.
[0143] 9) N9: User plane interface between UPFs, used to transmit uplink and downlink user data streams between UPFs.
[0144] 10) N10: The interface between SMF and UDM, which can be used by SMF to obtain session management-related subscription data from UDM, and by SMF to register terminal current session-related information with UDM.
[0145] 11) N11: The interface between SMF and AMF, which can be used to transmit PDU session tunnel information between RAN and UPF, transmit control messages sent to the terminal, and transmit radio resource control information sent to RAN, etc.
[0146] 12) N12: The interface between AMF and AUSF, which can be used by AMF to initiate the authentication process to AUSF, and can carry SUCI as the signing identifier;
[0147] 13) N13: The interface between UDM and AUSF, which can be used by AUSF to obtain the user authentication vector from UDM in order to execute the authentication process.
[0148] 14) N15: The interface between PCF and AMF, which can be used to issue terminal policies and access control related policies.
[0149] 15) N35: The interface between UDM and UDR, which can be used by UDM to obtain user subscription data information from UDR.
[0150] 16) N36: The interface between PCF and UDR, which can be used by PCF to obtain policy-related contract data and application data related information from UDR.
[0151] It is understood that the aforementioned network element or function can be a network component in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). Optionally, the aforementioned network element or function can be implemented by one device, multiple devices working together, or a functional module within a single device; this application embodiment does not specifically limit this.
[0152] The application function network element, policy control function network element, session management function network element, user plane function network element, and network data analysis function network element in this application can be respectively Figure 2a or Figure 2b The AF, PCF, SMF, UPF, and NWDAF mentioned here can also refer to network elements in future communications such as 6G networks that have the functions of the aforementioned AF, PCF, SMF, UPF, and NWDAF. This application does not limit this. For ease of description, in the embodiments of this application, AF, PCF, SMF, UPF, and NWDAF will be used as examples of application function network elements, policy control function network elements, session management function network elements, user plane function network elements, and network data analysis function network elements, respectively, to introduce the technical solution provided by this application.
[0153] Example 1
[0154] Please refer to Figure 3 This application provides a business awareness method, which includes:
[0155] Step 301: AF sends request message 1 to PCF. Request message 1 includes the application service ID, packet detection feature information and event ID 1.
[0156] Correspondingly, the PCF receives request message 1 from the AF.
[0157] In this embodiment, request message 1 is used to request the creation or updating of a policy for the service flow of the application service. Request message 1 may be a policy authorization creation / update request message or other messages; this application is not limited to these.
[0158] The packet detection feature information of the application service is used to indicate the matching characteristics of the service flow of the application service. This packet detection feature information can be understood as the matching features provided by the AF to the core network (such as 5GC) for application detection. This packet detection feature information may include the statistical characteristics and / or header characteristics of the packets in the service flow of the application service. The statistical characteristics of the packets may include packet period, packet size, etc. The packet period can be used by the UPF to determine whether the service flow of the application service exists based on the period characteristics of the received packets. The packet size can be used by the UPF to determine whether the service flow of the application service exists based on the size distribution of the received packets within a certain range. The description form of the packet header features can be a combination of other packet headers besides the source address, destination address, protocol type, etc., defined by the current IP packet or Ethernet packet. For example, the Frame ID in the Profinet protocol header, the Function Code in the Modbus protocol header. In terms of specific representation, it can be a target field and its corresponding value, or a matching feature composed of offset + field length + field value. This application does not limit this.
[0159] Event ID 1 is used to indicate the event that reports the service flow of the application. This event can be an application start event or an application stop event. Event ID 1 can be the identifier of the application start event or the application stop event of the service flow. Specifically, the application start event can trigger the PCF to initiate a configuration update process to the terminal device, and the application stop event can trigger the PCF to cancel the previous configuration information of the terminal device.
[0160] Optionally, request message 1 may also include flow description information, which is used to indicate the service flow to which the aforementioned packet detection feature information applies, and can also be understood as identifying the service flow to be matched. This flow description information can be in the form of an IP 5-tuple. If request message 1 does not include flow description information, then all service flows in the session of the terminal device corresponding to request message 1 can be considered as service flows to which the aforementioned packet detection feature information applies (i.e., service flows to be matched).
[0161] In this application, a terminal device session may contain one or more service flows. Different service flows may correspond to different application services, and each service flow may consist of one or more packets. Detecting a packet of a certain application service is equivalent to detecting the service flow of that application service, which can also be referred to as the application start event of detecting the service flow of that application service. After detecting a packet of a certain application service, if no further packets of that application service are detected within a certain period of time, it is equivalent to no longer detecting the service flow of that application service, which can also be referred to as the application end event of detecting the service flow of that application service. Furthermore, the terminal device session may be a protocol data unit (PDU) session, and correspondingly, the session establishment process may be a PDU session establishment process, which will not be elaborated further below.
[0162] Optionally, request message 1 may also include information about the terminal device. This information may include one or more of the following: the terminal device's IP address, its identifier, data network name (DNN), and single-network slice selection assistance information (S-NSSAI). For example, it could be the terminal device's IP address, its identifier and DNN, or its identifier and S-NSSAI. This terminal device information can be used by the PCF to determine the session of the terminal device corresponding to request message 1, or the session of the terminal device where the application service's traffic resides, or the session of the terminal device to be detected. Optionally, the AF may only include the terminal device information in the policy authorization creation request message.
[0163] Optionally, before performing step 301, as shown in step 300, the terminal device may initiate a session establishment process to establish a session for the terminal device.
[0164] It should be noted that the AF can send request message 1 directly or indirectly to the PCF. Sending request message 1 directly from the AF to the PCF means that the AF sends request message 1 directly to the PCF without passing through any other network element. Sending request message 1 indirectly from the AF to the PCF means that the AF sends request message 1 to the PCF through the forwarding of other network elements (such as the NEF). For example, the AF sends request message 1 to the NEF, and the NEF then forwards request message 1 to the PCF. Optionally, when the AF sends request message 1 indirectly to the PCF through the NEF, if request message 1 includes information about the terminal device, this information can also be used by the NEF to locate the PCF providing services for the terminal device's session.
[0165] Step 302: PCF sends request message 2 to SMF. Request message 2 is used to request subscription to the service flow events of the application service. Request message 2 includes the identifier of the application service, packet detection feature information, and event identifier 2.
[0166] Correspondingly, the SMF receives request message 2 from the PCF.
[0167] In this embodiment of the application, the request message 2 may be an event subscription request message, a policy association / control update notification message, or other messages, which are not limited in this application.
[0168] Optionally, request message 2 may also include flow description information, which is used to indicate the service flow to which the packet detection feature information applies.
[0169] Optionally, request message 2 may also include a policy association identifier corresponding to the session of the terminal device. This policy association identifier is used by SMF to determine the session of the terminal device corresponding to request message 2 and to find the context of the session.
[0170] Event identifier 2 and event identifier 1 mentioned above are used to indicate the same event, but event identifier 2 and event identifier 1 may be the same or different, and this application does not make a specific limitation. In this application, the difference between event identifier 2 and event identifier 1 may refer to a different description format of the event identifier, which may include the APP_START / STOP string format or the format of indication information, etc. If event identifier 2 and event identifier 1 are the same, then event identifier 2 may be obtained directly by PCF from AF. If event identifier 2 and event identifier 1 are different, then event identifier 2 may be determined by PCF based on event identifier 1 obtained from AF, and there is a corresponding relationship between event identifier 2 and event identifier 1.
[0171] The PCF can obtain one or more of the aforementioned application service identifiers, packet detection feature information, or flow description information from the AF. For example, if request message 1 includes one or more of the aforementioned information, the PCF can obtain the aforementioned information from request message 1 and then include the aforementioned information in request message 2 and send it to the SMF.
[0172] For example, when the PCF receives request message 1, the PCF can perform policy decisions based on request message 1, generate corresponding policy and charging control (PCC) rules, and send the PCC rules to the SMF via request message 2. The PCC rules may include the identifier of the application service, packet detection feature information, and event identifier. Optionally, the PCC rules may also include flow description information.
[0173] Step 303: SMF sends request message 3 to UPF. Request message 3 includes detection rules and usage reporting rules (URR). The detection rules are used to detect the service flow of the application service. The detection rules include the identifier of the application service and packet detection feature information. The URR includes event identifier 3.
[0174] Correspondingly, the UPF receives request message 3 from the SMF.
[0175] In this embodiment, request message 3 may be an event subscription request message, an N4 session modification request message, or other messages; this application is not limited to any particular type. It should be noted that request message 3 is at the N4 session granularity, and each request message 3 corresponds one-to-one with a session on the terminal device.
[0176] The detection rule can be a packet detection rule (PDR). This PDR is used to detect the service flow of the application service within a session, specifically the service flow of the application service within a terminal device's session, or the packets of the application service within a terminal device's session. The URR is used to perform usage statistics reporting on the service flow of the application service after detecting an event that indicates the service flow of the application service has been detected.
[0177] Optionally, the PDR may also include flow description information, which indicates the service flow to which the packet detection feature information applies. This flow description information may be obtained by the SMF from the PCF.
[0178] Optionally, the URR may also include an event reporting instruction, which instructs the UPF to report a corresponding event report after detecting an event in the service flow of the application service. This event reporting instruction can be understood as an instruction message specifically used to instruct the reporting of application events.
[0179] Event identifier 3 and event identifier 2 mentioned above are used to indicate the same event, but event identifier 3 and event identifier 2 may be the same or different, and this application does not make a specific limitation. In this application, the difference between event identifier 3 and event identifier 2 may refer to a difference in the descriptive form of the event identifier. If event identifier 3 and event identifier 2 are the same, then event identifier 3 may be obtained directly by the SMF from the PCF. If event identifier 3 and event identifier 2 are different, then event identifier 3 may be determined by the SMF based on event identifier 2 obtained from the PCF, and there is a corresponding relationship between event identifier 3 and event identifier 2.
[0180] The identification, packet inspection feature information, flow description information, or event reporting indication of the aforementioned application service can be obtained by the SMF from the PCF. For example, if request message 2 includes one or more of the above information, the SMF can obtain one or more of the above information from the request message, then include the identification, packet inspection feature information, or flow description information of the application service in the PDR, include the event reporting indication in the URR, and then send the PDR and URR to the UPF through request message 3.
[0181] For example, when the SMF receives a PCC rule from the PCF, the SMF can generate an N4 rule based on the PCC rule, and then send the N4 rule to the UPF for execution via request message 3. The N4 rule includes a PDR and a URR. The PDR may include the application service identifier and packet detection feature information; optionally, the PDR may also include flow description information. The URR may also include an event identifier 3; optionally, the URR may also include an event reporting indication, etc.
[0182] Step 304: UPF performs application detection on the received packets in the session based on packet detection feature information.
[0183] In this embodiment, when the UPF receives a PDR from the SMF, the UPF can perform application detection on the packets in the terminal device's session based on the PDR. This can also be understood as performing application detection on the service flow in the terminal device's session based on the PDR. The packets in the terminal device's session refer to the packets transmitted by the terminal device via the user plane.
[0184] It should be understood that, in this application, performing application detection on a message and performing detection on a service flow have similar meanings, and will not be elaborated further here. Performing application detection can refer to determining whether a message of a certain application service has been received or determining which application service the received message belongs to (i.e., determining which application service's service flow the received message belongs to).
[0185] For example, if the PDR includes packet detection feature information but not flow description information, the UPF can perform application detection on packets in the terminal device's session based on the packet detection feature information. In other words, when the PDR does not include flow description information, the UPF can directly perform application detection on packets in the terminal device's session based on the packet detection feature information. Since the UPF typically matches service flows according to the priority order of each PDR in the terminal device's session, packets from service flows in the terminal device's session other than those matched to higher-priority PDRs will be used as the original packets of the packet detection feature information for application detection. In this case, packets in the terminal device's session that match the packet detection feature information can be considered packets from service flows that match the PDR.
[0186] If the PDR includes packet detection feature information and flow description information, the UPF can perform application detection on packets in the terminal device's session that match the flow description information based on the packet detection feature information. In other words, when the PDR includes flow description information, the UPF can first perform application detection on packets in the terminal device's session based on the flow description information, and then perform application detection on packets that match the flow description information in the previous step based on the packet detection feature information. Packets in the terminal device's session that further match the aforementioned flow description information from other service flows (excluding those matching the higher-priority PDR) will be used as the original packets of the packet detection feature information for application detection. In this case, packets in the terminal device's session that match both the flow description information and the packet detection feature information can be considered packets in the service flow that matches the PDR.
[0187] Step 305: If an event of the service flow of the application service is detected, the UPF sends an event report 3 to the SMF, which is used to indicate the event.
[0188] Correspondingly, the SMF receives event reports from the UPF.
[0189] In this embodiment of the application, the UPF detecting the application start event of the service flow of the application service can refer to: the UPF detecting a message in the terminal device session that matches the above packet detection feature information (or packet detection feature information and flow description information).
[0190] The UPF detection of the application end event of the service flow of the application service can refer to: after the UPF detects a packet that matches the above packet detection feature information (or packet detection feature information and flow description information) in the session of the terminal device, it does not detect any more packets that match the above packet detection feature information (or packet detection feature information and flow description information) within a certain period of time.
[0191] The event report 3 is used to report events in the business flow of the application service. The event report 3 may include the identifier of the application service and the event identifier 3.
[0192] Optionally, if the URR sent by the SMF to the UPF includes an event reporting instruction, the UPF may send the aforementioned event report 3 to the SMF according to the event reporting instruction.
[0193] Step 306: SMF sends event report 2 to PCF.
[0194] Correspondingly, the PCF receives event report 2 from the SMF.
[0195] The event report 2 is used to report events in the business flow of the application service. The event report 2 may include the identifier of the application service and the event identifier 2.
[0196] Step 307: PCF sends Event Report 1 to AF.
[0197] Accordingly, AF receives event report 1 from PCF.
[0198] The event report 1 is used to report events in the business flow of the application service. The event report 1 may include the identifier of the application service and the event identifier 1.
[0199] Optionally, if the AF indirectly sends request message 1 to the PCF, the PCF may also indirectly send event report 1 to the AF. For example, the PCF may send event report 1 to the NEF, which in turn sends event report 1 to the AF.
[0200] After receiving the above event report 1, the AF can perform corresponding management actions on the terminal device based on the event report, such as notifying the adjustment of the encoding method, the service message sending cycle, and timed power-off.
[0201] It is understandable that if event identifier 1 and event identifier 2 are the same, then event report 1 and event report 2 can also be the same. Similarly, if event identifier 2 and event identifier 3 are the same, then event report 2 and event report 3 can also be the same.
[0202] In Embodiment 1 of this application, the Application Filter (AF) can subscribe to application events from the Packet Filter (PCF) and provide packet detection feature information for application detection. The PCF can subscribe to application events from the Sub-Signal Filter (SMF), which instructs the UPF to perform application detection. The UPF can perform application detection on packets received from the terminal device's session based on the packet detection feature information and return corresponding event reports to the AF through the SMF and PCF.
[0203] Since UPF can perform service detection on packets in a terminal device's session based on packet detection feature information, the above technical solution can effectively distinguish packets from different application services and accurately determine the service flow of the application service to which the packet belongs. Furthermore, since packet detection feature information can indicate the statistical characteristics and header characteristics of packets in the service flow of an application service, compared to existing technical solutions that only perform detection based on plaintext domain name information in the packet header, the above technical solution can also effectively distinguish packets from different application services even when the packet headers of packets from different application services are the same (e.g., encrypted packets or packets from different application services in industrial applications have the same packet header), thereby accurately determining the type of application service.
[0204] Example 2
[0205] Please refer to Figure 4 Another business-aware method provided in this application includes:
[0206] Step 401, AF sends request message 4 to NWDAF. Request message 4 is used to request the analysis of the service flow of the application service. The event is the application start event or the application end event. The fourth request message includes the identifier of the application service and packet detection feature information. The packet detection feature information is used to indicate the matching features of the service flow of the application service.
[0207] Accordingly, NWDAF receives request message 4 from AF.
[0208] In this embodiment of the application, the request message 4 may be an analysis subscription request message or other messages, and this application does not limit it.
[0209] The packet detection feature information of the application service may include statistical features and / or header features of the packets in the service flow of the application service. For specific implementation methods of packet detection feature information, please refer to the relevant descriptions above, which will not be repeated here.
[0210] Optionally, request message 4 may include flow description information, which is used to indicate the service flow to which the aforementioned packet detection feature information applies, and can also be understood as identifying the service flow to be matched. For specific implementation details regarding the flow description information, please refer to the relevant descriptions above, which will not be repeated here.
[0211] Optionally, the request message 4 may include an event identifier, which is used to indicate an event of the service flow of the application service being reported. The event identifier may be an identifier of the application start event or an identifier of the application end event of the service flow.
[0212] Optionally, request message 1 may include information about the terminal device. This information can be used by NWDAF to determine the session of the terminal device corresponding to request message 4, or the session of the terminal device where the service flow of the application resides, or the session of the terminal device to be detected. Specific implementation details of this terminal device information can be found in the relevant descriptions above and will not be repeated here.
[0213] After NWDAF receives request message 4 from AF, NWDAF can determine the session of the terminal device corresponding to request message 4 and the SMF that provides services for the session of the terminal device based on the information of the terminal device mentioned above, so as to subsequently request the SMF to obtain the image of the messages in the session of the terminal device.
[0214] Optionally, before performing step 401, as shown in step 400, the terminal device initiates a session establishment process to establish a session for the terminal device.
[0215] It should be noted that the AF can send request message 4 directly or indirectly to the NWDAF. Sending request message 4 directly from the AF to the NWDAF means that the AF sends request message 4 directly to the NWDAF without passing through any other network element. Sending request message 4 indirectly from the AF to the NWDAF means that the AF sends request message 4 to the NWDAF through the forwarding of other network elements (such as the NEF). For example, the AF sends request message 4 to the NEF, and the NEF then forwards request message 4 to the NWDAF. Optionally, when the AF sends request message 4 indirectly to the NWDAF through the NEF, if the request message 4 includes information about the terminal device, this information can also be used by the NWDAF to locate the NWDAF that provides services for the terminal device's session.
[0216] Step 402, NWDAF sends request message 5 to SMF, which is used to request the mirroring of packets in the session of the forwarding terminal device.
[0217] Correspondingly, the SMF receives request message 5 from the NWDAF.
[0218] In this embodiment of the application, the request message 5 may be a message subscription request message, an event subscription request message, an event exposure message, or other messages, and this application does not limit it.
[0219] Optionally, request message 5 may include flow description information, which indicates the mirroring of packets in the forwarding terminal device's session that match the flow description information. This flow description information may be obtained by the NWDAF from the AF. For example, if request message 4 includes flow description information, the NWDAF obtains the flow description information from request message 4 and may carry it in request message 5 to send to the SMF. If request message 5 does not include flow description information, it indicates that mirroring of all packets in the forwarding terminal device's session is required.
[0220] Optionally, the request message 5 may also include a mirror destination address, which is the address of the mirror of the message in the session of the receiving terminal device in the NWDAF, used to instruct the SMF or UPF to forward the mirror of the message that meets the requirements (e.g., the mirror of the message in the session of the terminal device that matches the above flow description information) to this address. The mirror destination address may also be called the mirror reporting address, event notification address, or event reporting address, etc., which is not limited in this application.
[0221] Optionally, request message 5 may also include a mirroring forwarding indication, which can be used to indicate the mirroring of packets in a session of the forwarding terminal device. This mirroring forwarding indication can also be understood as indication information used to indicate the mirroring of packets in a session of the forwarding terminal device.
[0222] Step 403: SMF sends request message 6 to UPF. Request message 6 includes detection rules and forwarding rules. The detection rules are used to detect service flows in the session of the terminal device. The forwarding rules include a mirror forwarding indication, which is used to indicate the mirroring of packets in the session of the forwarding terminal device.
[0223] Correspondingly, the UPF receives request message 6 from the SMF.
[0224] In this embodiment, request message 6 may be an event subscription request message, an N4 session modification request message, or other messages; this application is not limited to any particular type. It should be noted that request message 6 is at the N4 session granularity, and each request message 6 corresponds one-to-one with a session on the terminal device.
[0225] The detection rule can be a packet detection rule (PDR), and the forwarding rule can be a forwarding action rule (FAR), which may include the aforementioned mirror forwarding indication.
[0226] The PDR may include flow description information or wildcard indication information. Flow description information indicates which packets in the terminal device's session match the flow description information, while wildcard indication information indicates which packets in the terminal device's session match the flow description information. If the SMF obtains flow description information from the NWDAF (e.g., request message 5 contains flow description information), the SMF can include this flow description information in the PDR, indicating that the UPF needs to report the packets in the terminal device's session that match the flow description information. If the SMF does not obtain flow description information from the NWDAF, the SMF can include wildcard indication information in the PDR, also known as a match-all indication, indicating that the UPF needs to report the packets in the terminal device's session match the flow description information. In this way, the SMF can explicitly tell the UPF which packet images need to be forwarded, thus facilitating the UPF's corresponding processing.
[0227] Optionally, the FAR may also include a mirror destination address, which is used by the UPF to directly forward mirrored packets that meet the requirements to the NWDAF. This mirror destination address can be obtained by the SMF from the NWDAF. For example, when request message 5 includes a mirror destination address, the SMF can include that mirror destination address in the FAR. It should be noted that the FAR may also not include a mirror destination address. If the FAR does not include a mirror destination address, it means that the UPF needs to forward the mirrored packets to the NWDAF through the SMF; that is, the UPF can send the mirrored packets to the SMF, and the SMF will then send the mirrored packets back to the SMF based on the mirror destination address.
[0228] The mirror forwarding instruction sent by the SMF to the UPF and the mirror forwarding instruction sent by the NWDAF to the SMF may be the same or different, and this application does not limit this. The difference in mirror forwarding instructions may refer to differences in their descriptive formats.
[0229] For example, after the SMF receives request message 5, the SMF can generate an N4 rule based on request message 5, and then send the N4 rule to the UPF for execution via request message 6. The N4 rule may include a PDR and a FAR, wherein the PDR may include flow description information or wildcard indication information, and the FAR may include a mirror forwarding indication. Optionally, the FAR may also include a mirror destination address.
[0230] Step 404: UPF detects packets in the terminal device's session according to the detection rules.
[0231] Step 405: UPF sends a mirror of the session packets of the terminal device to SMF or NWDAF according to the mirror forwarding instruction.
[0232] Correspondingly, NWDAF receives mirrored messages from the end device of SMF or UPF in the session.
[0233] For example, after receiving request message 6 from SMF, UPF can perform message matching based on the PDR therein, and then perform message mirroring according to the mirror forwarding instruction in FAR corresponding to the PDR, sending the mirrored message in the session of the terminal device directly or indirectly to NWDAF.
[0234] If the PDR includes flow description information, the UPF can directly or indirectly send mirror images of packets in the terminal device's session that match the flow description information to the NWDAF. If the PDR includes wildcard indication information, the UPF can directly or indirectly send mirror images of all packets in the terminal device's session to the NWDAF.
[0235] In this context, the UPF directly sending the mirror of the terminal device's session messages to the NWDAF can mean that the FAR includes a mirror destination address, which is the address in the NWDAF that receives the mirror of the terminal device's session messages. The UPF can directly send the mirror of the terminal device's session messages to the NWDAF based on this mirror destination address, without going through the SMF for forwarding.
[0236] The UPF can indirectly send the terminal device's session messages to the NWDAF by sending a mirror image of the terminal device's session messages to the NWDAF through the SMF's forwarding. That is, the UPF first sends the mirror image of the terminal device's session messages to the SMF, and then the SMF forwards it to the NWDAF.
[0237] Understandably, the mirrored message described above can also be called a mirrored message. Multiple mirrored messages can form a mirrored service flow, also known as a mirrored service flow. It should also be noted that the mirrored forwarding process of the above messages does not affect the UPF's forwarding of the original messages; that is, the UPF can still send the messages in the terminal device's session to the terminal device via the access network equipment as usual.
[0238] Step 406: NWDAF performs application detection on the mirror image of the received message based on the packet detection feature information.
[0239] The specific implementation of step 406 can be found in the description of step 304 above regarding the UPF performing application detection on the received message based on the packet detection feature information, and will not be repeated here.
[0240] Step 407: If an event of the service flow of the application service is detected, the NWDAF sends an event report to the AF, which is used to indicate the event.
[0241] Correspondingly, the AF receives event reports from the NWDAF.
[0242] The event report may include the identifier of the application service and the event identifier. The event identifier is used to indicate the event of the service flow of the application service. The event identifier may be the identifier of the application start event or the identifier of the application end event of the service flow.
[0243] Upon receiving the event report, the AF can perform corresponding management actions on the terminal device based on the event report, such as notifying adjustments to the encoding method, service message sending cycle, and timed power-off.
[0244] In Embodiment 2 of this application, the AF can request the NWDAF to analyze application events and provide the NWDAF with packet detection feature information for application detection. The NWDAF can obtain the image of the packets in the session of the terminal device from the UPF through the SMF, perform application detection on the image of the received packets according to the packet detection feature information, and return the corresponding event report to the AF.
[0245] Since NWDAF can perform service detection based on the mirroring of packets in a terminal device's session using packet detection feature information, the above technical solution can effectively distinguish packets from different application services and accurately determine the service flow of the application service to which the packet belongs. Furthermore, because packet detection feature information can indicate the statistical characteristics and header characteristics of packets in the service flow of an application service, compared to existing technical solutions that only perform detection based on plaintext domain name information in the packet header, the above technical solution can also effectively distinguish packets from different application services even when the packet headers of packets from different application services are the same (e.g., encrypted packets or packets from different application services in industrial applications have the same packet header), thereby accurately determining the type of application service.
[0246] Example 3
[0247] Please refer to Figure 5 Another business-aware method provided in this application includes:
[0248] Step 501: AF sends a request message 7 to PCF. The request message 7 is used to obtain the mirror of the packets in the session of the terminal device. The request message 7 includes the mirror destination address, which is the address in AF that receives the mirror.
[0249] Correspondingly, the PCF receives request message 7 from the AF.
[0250] In this embodiment of the application, the request message 7 may be a policy authorization creation / update request message or other messages, which are not limited in this application.
[0251] Optionally, request message 7 may include flow description information, which indicates the mirror image of a packet in the session of the forwarding terminal device that matches the flow description information. If request message 7 does not include flow description information, it indicates that mirror images of all packets in the session of the forwarding terminal device are required. For specific implementation details of flow description information, please refer to the relevant descriptions above, which will not be repeated here.
[0252] Optionally, request message 7 may include information about the terminal device. This information is used by PCF to determine the session of the terminal device corresponding to request message 7, or in other words, the session of the terminal device to be detected. For specific implementation details regarding the terminal device information, please refer to the relevant descriptions above, which will not be repeated here.
[0253] Optionally, before performing step 501, as shown in step 500, the terminal device may initiate a session establishment process to establish a session for the terminal device.
[0254] It should be noted that the AF can send request message 7 directly or indirectly to the PCF, similar to the sending of request message 1 above, and will not be repeated here.
[0255] Step 502, PCF sends request message 8 to SMF. Request message 8 is used to request the mirroring of packets in the session of the forwarding terminal device. Request message 8 includes the aforementioned mirroring destination address.
[0256] Correspondingly, the SMF receives request message 8 from the PCF.
[0257] In this embodiment of the application, the request message 8 may be a message subscription request message, an event subscription request message, a policy association / control update notification message, or other messages, which are not limited in this application.
[0258] Optionally, request message 8 may include flow description information, which indicates the mirror image of a packet in the session of the forwarding terminal device that matches the flow description information. This flow description information may be obtained by the PCF from the AF. For example, if request message 7 includes flow description information, the PCF may obtain the flow description information from request message 7 and then include it in request message 8 and send it to the SMF.
[0259] For example, when the PCF receives request message 7 from the AF, the PCF can perform a policy decision based on request message 7, generate a corresponding PCC rule, and send the PCC rule to the SMF via request message 8. The PCC rule may include a mirroring destination address, and optionally also includes flow description information, used to instruct the SMF to send a mirror of a packet in the terminal device's session that matches the flow description information to the aforementioned mirroring destination address.
[0260] Step 503: SMF sends request message 9 to UPF. Request message 9 includes detection rules and forwarding rules. The detection rules are used to detect service flows in the session of the terminal device. The forwarding rules are used to mirror and forward packets in the session of the terminal device. The forwarding rules include mirror forwarding indication and mirror destination address. The mirror forwarding indication is used to indicate the mirroring of packets in the session of the terminal device.
[0261] Correspondingly, the UPF receives request message 9 from the SMF.
[0262] In this embodiment, request message 9 may be a message subscription request message, an event subscription request message, an N4 session modification request message, or other messages; this application is not limited to any of these. It should be noted that request message 9 is at the N4 session granularity, and each request message 9 corresponds one-to-one with a session on the terminal device.
[0263] The detection rule can be PDR, and the forwarding rule can be FAR or packet mirror rule (PMR). This forwarding rule can also be called a mirror rule or a mirror forwarding rule, etc.
[0264] The PDR may include flow description information or wildcard indication information. Flow description information indicates which packets in the session of the forwarding terminal device match the flow description information, while wildcard indication information indicates which packets in the session of the forwarding terminal device match the flow description information. If the SMF obtains flow description information from the PCF (e.g., request message 8 contains flow description information), the SMF can include flow description information in the PDR, indicating that the UPF needs to report the packets in the session of the terminal device that match the flow description information. If the SMF does not obtain flow description information from the NWDAF, the SMF can include wildcard indication information in the PDR, also known as a match-all indication, indicating that the UPF needs to report the packets in the session of the terminal device. In this way, the SMF can explicitly tell the UPF which packet images need to be forwarded, thus facilitating the UPF to perform corresponding processing.
[0265] For example, after receiving a PCC rule from the PCF, the SMF can generate an N4 rule based on the PCC rule, and then send the N4 rule to the UPF for execution via request message 9. The N4 rule includes a PDR and a FAR, or it includes a PDR and a PMR. The PDR includes flow description information or wildcard indication information, and the FAR or PMR includes a mirror forwarding indication and a mirror destination address.
[0266] Step 504: UPF detects packets in the terminal device's session according to the detection rules.
[0267] Step 505: UPF sends a mirror of the session packets of the terminal device to AF according to the mirror forwarding instruction and the mirror destination address.
[0268] Correspondingly, the AF receives a mirror of the session messages from the UPF's terminal device.
[0269] For example, after receiving request message 9 from SMF, UPF can perform packet matching based on the PDR therein, and then perform packet mirroring according to the mirror forwarding instruction and mirror destination address in the FAR corresponding to the PDR, sending the mirrored packets in the terminal device's session to AF. The packet mirroring can also be called mirrored packets, and the mirroring of multiple packets can form a service flow mirror, also known as a mirrored service flow.
[0270] If the PDR includes flow description information, the UPF can send a mirror image of the packets in the terminal device's session that match the flow description information to the AF; if the PDR includes wildcard indication information, the UPF can send a mirror image of all packets in the terminal device's session to the AF. It should be noted that the above packet mirroring and forwarding process does not affect the UPF's forwarding of the original packets.
[0271] Step 506: AF performs application detection based on the mirror image of the received message.
[0272] Subsequently, the AF can determine the type of application service based on the mirror image of the message in the session received from the terminal device, and send the corresponding management command to the terminal device.
[0273] In Embodiment 3 of this application, the Application Filter (AF) can send packet forwarding rules to the UPF via the PCF and SMF to obtain the image of packets in the terminal device's session. Then, it can perform application detection based on the received packet image and make subsequent management decisions. The above technical solution exposes application detection capabilities to the AF, enabling the AF to perceive the type of application service actually initiated by the terminal device, thereby facilitating the AF to execute corresponding management decisions based on the application service currently initiated by the terminal device.
[0274] In this technical solution, the AF can communicate directly with the terminal device, or it can act as a management device for the terminal device without communicating directly with it.
[0275] Figure 6 and Figure 7The diagram illustrates the possible communication devices provided in the embodiments of this application. These communication devices can be used to implement the functions of application function network elements, policy control function network elements, session management function network elements, user plane function network elements, or network data analysis function network elements in the above method embodiments, and thus can also achieve the beneficial effects of the above method embodiments. In the embodiments of this application, the communication device can be an application function network element, policy control function network element, session management function network element, user plane function network element, or network data analysis function network element, or it can be a module (such as a chip) applied to the application function network element, policy control function network element, session management function network element, user plane function network element, or network data analysis function network element.
[0276] like Figure 6 As shown, the communication device 600 includes a processing unit 610 and a transceiver unit 620. The communication device 600 is used to implement the above-mentioned... Figure 3 , Figures 4 to 5 The methods shown in any of the embodiments apply the functions of functional network elements, policy control functional network elements, session management functional network elements, user plane functional network elements, or network data analysis functional network elements.
[0277] When the communication device 600 is used to implement Figure 3 In the method embodiment shown, the function of the session management function network element is as follows: The transceiver unit 620 is configured to send a first request message to the user plane function network element. This first request message includes detection rules and usage reporting rules. The detection rules include the identifier of the application service and packet detection feature information. These detection rules are used to detect the service flow of the application service in the session. The packet detection feature information is used to indicate the matching characteristics of the service flow of the application service. The usage reporting rules include a first event identifier, which is used to indicate the event of reporting the service flow of the application service. This event is either an application start event or an application end event. The transceiver unit 620 is also configured to receive a first event report from the user plane function network element, which is used to indicate the event of the service flow of the application service.
[0278] When the communication device 600 is used to implement Figure 3In the method embodiment shown, the user plane function network element functions as follows: Transceiver unit 620 is configured to receive a first request message from the session management function network element. This first request message includes detection rules and usage reporting rules. The detection rules include an application service identifier and packet detection feature information. These detection rules are used to detect the service flow of the application service in the session. The packet detection feature information is used to indicate the matching characteristics of the application service's service flow. The usage reporting rules include a first event identifier, which indicates an event that reports the service flow of the application service. This event is either an application start event or an application end event. Processing unit 610 is configured to perform application detection on the received packets in the session according to the packet detection feature information. If an event of the application service's service flow is detected, transceiver unit 620 is configured to send a first event report to the session management function network element. This first event report indicates the event.
[0279] When the communication device 600 is used to implement Figure 3 In the method embodiment shown, the policy control function network element functions as follows: Transceiver unit 620 is configured to receive a third request message from the application function network element. This third request message includes an application service identifier, packet detection feature information, and a third event identifier. The packet detection feature information indicates the matching characteristics of the application service's service flow, and the third event identifier indicates an event that reports the application service's service flow, which may be an application start event or an application end event. Transceiver unit 620 is also configured to send a second request message to the session management function network element. This second request message requests subscription to the event. The second request message includes the application service identifier, packet detection feature information, and a second event identifier, which indicates reporting the event. Transceiver unit 620 is also configured to receive a second event report from the session management function network element, which indicates the event. Transceiver unit 620 is also configured to send a third event report to the application function network element, which indicates the event.
[0280] When the communication device 600 is used to implement Figure 3 When applying the functions of the network elements in the method embodiment shown: the transceiver unit 620 is used to send a third request message to the policy control function network element. The third request message includes an identifier of the application service, packet detection feature information, and a third event identifier. The packet detection feature information is used to indicate the matching characteristics of the service flow of the application service, and the third event identifier is used to indicate the event that reports the service flow of the application service. The event is an application start event or an application end event. The transceiver unit 620 is also used to receive a third event report from the policy control function network element. The third event report is used to indicate the event.
[0281] When the communication device 600 is used to implement Figure 4 In the method embodiment shown, the network data analysis function network element functions as follows: Transceiver unit 620 is configured to receive a fourth request message from the application function network element. This fourth request message requests the analysis of events related to the service flow of the application service. These events are either application start events or application end events. The fourth request message includes the identifier of the application service and packet detection feature information. This packet detection feature information indicates the matching characteristics of the service flow of the application service. Transceiver unit 620 is also configured to send a fifth request message to the session management function network element. This fifth request message requests the mirroring of packets in the session of the forwarding terminal device. Processing unit 610 is configured to perform application detection on the mirrored packets received from the session management function network element or the user plane function network element based on the packet detection feature information. If an event related to the service flow of the application service is detected, transceiver unit 620 is also configured to send an event report to the application function network element. This event report indicates the event.
[0282] When the communication device 600 is used to implement Figure 4 In the method embodiment shown, the function of the session management function network element is as follows: the transceiver unit 620 is used to receive a fifth request message from the network data analysis function network element, the fifth request message being used to request the forwarding of the mirroring of packets in the session of the terminal device; the transceiver unit 620 is also used to send a sixth request message to the user plane function network element, the sixth request message including detection rules and forwarding rules, the detection rules being used to detect the service flow of the session of the terminal device, and the forwarding rules including a mirroring forwarding indication, the mirroring forwarding indication being used to indicate the mirroring.
[0283] When the communication device 600 is used to implement Figure 4 In the method embodiment shown, the user plane function network element functions as follows: Transceiver unit 620 is used to receive a sixth request message from the session management function network element. The sixth request message includes detection rules and forwarding rules. The detection rules are used to detect service flows in the session of the terminal device, and the forwarding rules include a mirror forwarding indication, which is used to indicate the forwarding of mirrored packets in the session of the terminal device; processing unit 610 is used to detect packets in the session of the terminal device according to the detection rules; transceiver unit 620 is also used to send the mirrored packets to the session management function network element or the network data analysis function network element according to the mirror forwarding indication.
[0284] When the communication device 600 is used to implement Figure 4When applying the functions of the network element in the method embodiment shown: the transceiver unit 620 is used to send a fourth request message to the network data analysis function network element. The fourth request message is used to request the analysis of the service flow of the application service. The event is an application start event or an application end event. The fourth request message includes the identifier of the application service and packet detection feature information. The packet detection feature information is used to indicate the matching features of the service flow of the application service. The transceiver unit 620 is also used to receive an event report from the network data analysis function network element. The event report is used to indicate the event.
[0285] When the communication device 600 is used to implement Figure 5 In the method embodiment shown, when applying the function of the application function network element: the transceiver unit 620 is used to send a seventh request message to the policy control function network element. The seventh request message is used to obtain the image of the packets in the session of the terminal device. The seventh request message includes the image destination address, which is the address in the application function network element that receives the image; the transceiver unit 620 is also used to receive the image from the user plane function network element; the processing unit 610 is used to perform application detection according to the image.
[0286] When the communication device 600 is used to implement Figure 5 In the method embodiment shown, the policy control function network element functions as follows: the transceiver unit 620 is used to receive a seventh request message from the application function network element. The seventh request message is used to obtain a mirror image of a packet in the session of the terminal device. The seventh request message includes a mirror destination address, which is the address in the application function network element that receives the mirror image. The transceiver unit 620 is also used to send an eighth request message to the session management function network element. The eighth request message is used to request the forwarding of the mirror image. The eighth request message includes the mirror destination address.
[0287] When the communication device 600 is used to implement Figure 5 In the method embodiment shown, the function of the session management function network element is as follows: the transceiver unit 620 is used to receive an eighth request message from the policy control function network element. The eighth request message is used to request the forwarding of the mirroring of packets in the session of the terminal device. The eighth request message includes a mirroring destination address, which is the address in the application function network element that receives the mirrored packet. The transceiver unit 620 is also used to send a ninth request message to the user plane function network element. The ninth request message includes a detection rule and a forwarding rule. The detection rule is used to detect the service flow in the session of the terminal device. The forwarding rule is used to mirror and forward the packets in the session of the terminal device. The forwarding rule includes a mirroring forwarding indication and the mirroring destination address. The mirroring forwarding indication is used to indicate the forwarding of the mirrored packet.
[0288] When the communication device 600 is used to implement Figure 5 In the method embodiment shown, the user plane function network element functions as follows: Transceiver unit 620 is used to receive detection rules and forwarding rules from the session management function network element. The detection rules are used to detect service flows in the session of the terminal device, and the forwarding rules are used to mirror and forward packets in the session of the terminal device. The forwarding rules include a mirror forwarding instruction and a mirror destination address, where the mirror destination address is the address in the application function network element that receives the mirror; processing unit 610 is used to detect packets in the session of the terminal device according to the detection rules; transceiver unit 620 is used to send the mirror to the application function network element according to the mirror forwarding instruction and the mirror destination address.
[0289] The processing unit 620 in this communication device can be implemented by at least one processor or processor-related circuit components, and the transceiver unit 610 can be implemented by at least one transceiver or transceiver-related circuit components or a communication interface. Optionally, the communication device may also include a storage unit, which can be used to store data and / or instructions. The transceiver unit 610 and / or the processing unit 620 can read the data and / or instructions from the storage unit, thereby enabling the communication device to implement the corresponding method. The storage unit can be implemented, for example, by at least one memory. The aforementioned storage unit, processing unit, and transceiver unit can exist separately, or all or part of them can be integrated, such as integrating the storage unit and the processing unit, or integrating the processing unit and the transceiver unit, etc.
[0290] The operation and / or function of each unit in the communication device are respectively for the purpose of realizing Figures 3 to 5 The corresponding process of the method shown is not described in detail here for the sake of brevity.
[0291] like Figure 7 As shown, the communication device 700 includes a processor 710 and an interface circuit 720. The processor 710 and the interface circuit 720 are coupled to each other. It is understood that the interface circuit 720 can be a transceiver or an input / output interface. Optionally, the communication device 700 may also include a memory 730 for storing instructions executed by the processor 710, or storing input data required by the processor 710 to execute instructions, or storing data generated after the processor 710 executes instructions.
[0292] When the communication device 700 is used to achieve Figures 3 to 5 In the method shown, the processor 710 is used to implement the functions of the processing unit 610, and the interface circuit 720 is used to implement the functions of the transceiver unit 620.
[0293] It is understood that the processor in the embodiments of this application can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A general-purpose processor can be a microprocessor or any conventional processor.
[0294] The method steps in the embodiments of this application can be implemented in hardware or by a processor executing software instructions. The software instructions can consist of corresponding software modules, which can be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disks, portable hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and storage medium can reside in an ASIC. Alternatively, the ASIC can reside in a base station or terminal. Of course, the processor and storage medium can also exist as discrete components in the base station or terminal.
[0295] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of this application are performed entirely or partially. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a base station, a user equipment, or other programmable device. The computer program or instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; it can also be an optical medium, such as a digital video optical disc; or it can be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both types of storage media.
[0296] In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of different embodiments are consistent and can be referenced by each other. The technical features of different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0297] In this application, "at least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. In the textual description of this application, the character " / " generally indicates an "or" relationship between the preceding and following related objects; in the formulas of this application, the character " / " indicates a "division" relationship between the preceding and following related objects.
[0298] It is understood that the various numerical designations used in the embodiments of this application are merely for descriptive convenience and are not intended to limit the scope of the embodiments of this application. The order of the process numbers described above does not imply the order of execution; the execution order of each process should be determined by its function and internal logic.
Claims
1. A service awareness method, characterized by, The method comprises: sending a first request message to a user plane function network element, the first request message comprising a detection rule and a usage reporting rule, the detection rule comprising an identifier of an application service and packet detection characteristic information, the detection rule being used for detecting a service flow of the application service in a session, the packet detection characteristic information being used for indicating matching characteristics of the service flow of the application service, the packet detection characteristic information comprising statistical characteristics and / or packet header characteristics of packets in the service flow of the application service, the usage reporting rule comprising a first event identifier, the first event identifier being used for indicating an event of reporting the service flow of the application service, the event being an application start event or an application end event; receiving a first event report from the user plane function network element, the first event report being used for indicating the event of the service flow of the application service.
2. The method of claim 1, wherein, The method further comprises: receiving a second request message from a policy control function network element, the second request message being used for subscribing to the event, the second request message comprising the identifier of the application service, the packet detection characteristic information, and a second event identifier, the second event identifier being used for indicating the event; sending a second event report to the policy control function network element, the second event report being used for indicating the event.
3. The method according to claim 1 or 2, characterized in that, The detection rule further comprises flow description information, the flow description information being used for indicating a service flow to which the packet detection characteristic information is applicable.
4. A service awareness method characterized by, The method comprises: receiving a first request message from a session management function network element, the first request message comprising a detection rule and a usage reporting rule, the detection rule comprising an identifier of an application service and packet detection characteristic information, the detection rule being used for detecting a service flow of the application service in a session, the packet detection characteristic information being used for indicating matching characteristics of the service flow of the application service, the packet detection characteristic information comprising statistical characteristics and / or packet header characteristics of packets in the service flow of the application service, the usage reporting rule comprising a first event identifier, the first event identifier being used for indicating an event of reporting the service flow of the application service, the event being an application start event or an application end event; performing application detection on received packets in the session according to the packet detection characteristic information; if the event of the service flow of the application service is detected, sending a first event report to the session management function network element, the first event report being used for indicating the event.
5. The method of claim 4, wherein, The detection rule further comprises flow description information, the flow description information being used for indicating a service flow to which the packet detection characteristic information is applicable; performing application detection on received packets according to the packet detection characteristic information, comprising: performing application detection on packets in the session that match the flow description information according to the packet detection characteristic information.
6. A communication system characterized by The system comprises a session management function network element and a user plane function network element; The session management function network element is configured to send a first request message to the user plane function network element, the first request message comprising a detection rule and a usage reporting rule, the detection rule comprising an identifier of an application service and packet detection feature information, the detection rule being used to detect a service flow of the application service in a session, the packet detection feature information being used to indicate matching features of the service flow of the application service, the packet detection feature information comprising statistical features and / or packet header features of packets in the service flow of the application service, and the usage reporting rule comprising a first event identifier, the first event identifier being used to indicate an event of reporting the service flow of the application service, the event being an application start event or an application end event. The user plane function network element is configured to receive the first request message from the session management function network element, perform application detection on received packets in the session according to the packet detection feature information, and send a first event report to the session management function network element if the event of the service flow of the application service is detected, the first event report being used to indicate the event. The session management function network element is further configured to receive the first event report from the user plane function network element.
7. The system of claim 6, wherein, The system further comprises a policy control function network element. The policy control function network element is configured to send a second request message to the session management function network element, the second request message being used to request subscription of the event, the second request message comprising an identifier of the application service, the packet detection feature information, and a second event identifier, the second event identifier being used to report the event. The session management function network element is further configured to receive the second request message from the policy control function network element, and send a second event report to the policy control function network element, the second event report being used to indicate the event. The policy control function network element is further configured to receive the second event report from the session management function network element.
8. The system of claim 7, wherein, The system further comprises an application function network element. The application function network element is configured to send a third request message to the policy control function network element, the third request message comprising an identifier of the application service, the packet detection feature information, and a third event identifier, the third event identifier being used to report the event. The policy control function network element is further configured to receive the third request message from the application function network element, and send a third event report to the application function network element, the third event report being used to indicate the event. The application function network element is further configured to receive the third event report from the policy control function network element.
9. A service awareness method characterized by, The method comprises: receiving a fourth request message from an application function network element, the fourth request message being used to request an event of analyzing a service flow of an application service, the event being an application start event or an application end event, the fourth request message comprising an identification of the application service and packet detection characteristic information, the packet detection characteristic information being used to indicate matching characteristics of the service flow of the application service, the packet detection characteristic information comprising statistical characteristics and / or packet header characteristics of packets in the service flow of the application service; sending a fifth request message to a session management function network element, the fifth request message being used to request forwarding of a mirror of packets in a session of a terminal device; performing application detection on the mirror received from the session management function network element or a user plane function network element according to the packet detection characteristic information; if the event of the service flow of the application service is detected, sending an event report to the application function network element, the event report being used to indicate the event.
10. The method of claim 9, wherein, The fourth request message further comprises flow description information, the flow description information being used to indicate a service flow to which the packet detection characteristic information is applicable. The fifth request message comprises the flow description information, the flow description information being used to indicate forwarding of the mirror of the packets in the session of the terminal device that match the flow description information.
11. The method according to claim 9 or 10, characterized in that, The fifth request message further comprises a mirror destination address, the mirror destination address being an address of the network data analysis function network element that receives the mirror.
12. The method according to any one of claims 9 to 11, characterized in that, The fourth request message further comprises an event identification, the event identification being used to indicate reporting of the event. The event report comprises the identification of the application service and the event identification.
13. A service awareness method, characterized by, The method comprises: receiving a fifth request message from a network data analysis function network element, the fifth request message being used to request forwarding of a mirror of packets in a session of a terminal device; sending a sixth request message to a user plane function network element, the sixth request message comprising a detection rule and a forwarding rule, the detection rule being used to detect a service flow of the session of the terminal device, the forwarding rule comprising a mirror forwarding indication, the mirror forwarding indication being used to indicate forwarding of the mirror.
14. The method of claim 13, wherein, The fifth request message comprises flow description information, the flow description information being used to indicate forwarding of the mirror of the packets in the session of the terminal device that match the flow description information. The detection rule comprises the flow description information.
15. The method of claim 13, wherein, The detection rule comprises wildcard indication information, the wildcard indication information being used to forward the mirror of all the packets in the session of the terminal device.
16. The method according to any one of claims 13 to 15, characterized in that, The fifth request message further comprises a mirror destination address, the mirror destination address being an address of the network data analysis function network element that receives the mirror.
17. The method of claim 16, wherein, The method further comprises: receiving the mirror from the user plane function network element and sending the mirror to the network data analysis function network element according to the mirror destination address; or The forwarding rule further comprises the mirror destination address.
18. A communication system, characterized by The system comprises a network data analysis function network element and a session management function network element; wherein The network data analytics function network element is configured to receive a fourth request message from an application function network element, the fourth request message being used to request an event of analyzing a service flow of an application service, the event being an application start event or an application end event, the fourth request message comprising an identifier of the application service and packet detection feature information, the packet detection feature information being used to indicate matching features of the service flow of the application service, the packet detection feature information comprising statistical features and / or packet header features of packets in the service flow of the application service; and send a fifth request message to the session management function network element, the fifth request message being used to request forwarding of a mirror of packets in a session of a terminal device. The session management function network element is configured to receive the fifth request message from the network data analytics function network element, and send a sixth request message to a user plane function network element, the sixth request message comprising a detection rule and a forwarding rule, the detection rule being used to detect a service flow in a session of the terminal device, the forwarding rule comprising a mirror forwarding indication, the mirror forwarding indication being used to indicate forwarding of the mirror. The network data analytics function network element is further configured to receive the mirror from the session management function network element or the user plane function network element, perform application detection on the mirror according to the packet detection feature information, and send an event report to the application function network element, the event report being used to indicate the event.
19. The system of claim 18, wherein, The system further comprises the application function network element. The application function network element is configured to send the fourth request message to the network data analytics function network element, and receive the event report from the network data analytics function network element.
20. The system of claim 18 or 19, wherein, The system further comprises the user plane function network element. The user plane function network element is configured to receive the sixth request message from the session management function network element, detect packets in a session of the terminal device according to the detection rule, and send the mirror to the session management function network element or the network data analytics function network element according to the mirror forwarding indication.
21. A communications device, characterized by comprising means for performing the method of any one of claims 1 to 3, or comprising means for performing the method of any one of claims 13 to 17.
22. A communications device, characterized by comprising means for performing the method of claim 4 or 5.
23. A communications device, characterized by comprising means for performing the method of any one of claims 9 to 12. comprising means for performing the method of any one of claims 9 to 12.
Citation Information
Patent Citations
Policy control method, network element and system
CN110324800A