A 5G multi-level processing user data traceability association method based on strong check

By employing multi-level processing and robust verification methods, the problem of insufficient accuracy in 5G user data tracing was resolved, enabling accurate tracing of over ten million users and ensuring data accuracy and system stability.

CN119653324BActive Publication Date: 2026-05-12XIAMEN MEIYABAIKE INFORMATION SECURITY RES INST CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
XIAMEN MEIYABAIKE INFORMATION SECURITY RES INST CO LTD
Filing Date
2024-10-31
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Existing 5G user data tracing technologies do not effectively verify the accuracy of user data, resulting in insufficient accuracy and difficulty in meeting the needs of large-scale users and high traffic.

Method used

A multi-level processing method based on strong verification is adopted. The signaling is parsed by the first-level board and the load is balanced to the second-level board. The second-level board updates and filters user entries, and the third-level board performs user traceability and association. Strong verification is performed using UPF IP and inner IP to ensure data accuracy.

Benefits of technology

It enables accurate user data tracing for over ten million users, solving the problems of inaccurate and error-prone user data, and improving the accuracy of data tracing and the stability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119653324B_ABST
    Figure CN119653324B_ABST
Patent Text Reader

Abstract

The application discloses a 5G multi-level processing user data traceability association method based on strong check, and specifically comprises the following steps: 5G original signaling is input into a first-level processing board card through a load balancing mode. The first-level board card analyzes N11 and N16 signaling, and encapsulates the analyzed data into first-level semi-structured data packets. After receiving the first-level semi-structured data, a second-level board card updates user table items. The second-level board card encapsulates three-code information and tunnel information into second-level structured data, and sends the second-level structured data to a third-level board card according to a learned UPF IP. The third-level board card analyzes and extracts user three codes, position information NCGI, uplink and downlink tunnel numbers allocated to the user, network element IPs, and IP addresses allocated to the user for online surfing. The third-level board card analyzes outer tunnel numbers and outer IP addresses from 5G N3 interface service data. User traceability association is performed by using the outer IP and the tunnel number of the N3 service data. Strong check is performed by using inner IP, IMSI associated with double-side tunnels, and IP associated with base stations, so that the accuracy of user traceability association is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of automated traffic collection and analysis, and in particular, to a method for tracing and associating 5G multi-level processing user data based on strong verification. Background Technology

[0002] Mobile communication has evolved through 1G, 2G, 3G, and 4G, following a ten-year generational development pattern. Each generational leap and technological advancement has greatly promoted industrial upgrading and economic and social development. The rapid development of 4G networks has led to an explosive growth in new services and businesses, while simultaneously creating urgent needs and higher requirements for the next-generation communication technology—5G.

[0003] Currently, the deep integration of 5G with technologies such as cloud computing, big data, artificial intelligence, and big data models will accelerate the application of 5G across various industries, drive business model innovation, promote the diffusion and penetration of 5G technology into all sectors of the economy and society, foster new information products and services, and expand new spaces for the development of the digital economy. How to trace and correlate 5G user data and effectively manage cyberspace security is a significant challenge we currently face.

[0004] Research has revealed that existing 5G user data tracing technologies do not verify the accuracy of user data, resulting in insufficient accuracy. To address the shortcomings of existing solutions and considering the characteristics and needs of specific applications, this invention provides a method for robustly verifying 5G user data in the field of 5G user data tracing, thereby improving the accuracy of user data tracing and correlation. Summary of the Invention

[0005] The purpose of this invention is to overcome the shortcomings of existing methods and, based on the requirements of specific applications and practical situations, provide a 5G multi-level processing user data tracing and association method based on strong verification. This method is used to solve the problems of large 5G original signaling traffic and tens of millions of users. It innovatively uses multi-level processing for user tracing and adopts strong verification to solve problems such as inaccuracy and error susceptibility.

[0006] According to one aspect of the present invention, a 5G multi-level processing user data tracing and association method based on strong verification is proposed, comprising:

[0007] S1 and 5G raw signaling enter the first-level board through load balancing. The first-level board parses N11 and N16 signaling, encapsulates the parsed data into first-level semi-structured data packets, and distributes the data packets to the second-level board through IMSI load balancing.

[0008] S2. The secondary board receives the first-level semi-structured data packet, updates the user table entries, encapsulates the user three codes and tunnel information into secondary structured data, uses UPF IP to learn and filter the secondary structured data, and sends the filtered data to the tertiary board.

[0009] S3. The third-level board parses the received second-level structured data, extracts the user's three codes and location information NCGI, assigns uplink and downlink tunnel numbers and network element IPs to the user, and assigns an Internet IP to the user.

[0010] S4. The three-level board receives service data through the 5G N3 interface and parses the uplink and downlink tunnel number, uplink and downlink network element IP, inner source IP address and inner destination IP address from the service data;

[0011] S5. Use the uplink / downlink tunnel number and the uplink / downlink network element IP to perform user source tracing association, and use the inner source IP address and inner destination IP address to perform strong verification with the IMSI associated with the uplink / downlink tunnel number and the IP associated with the base station.

[0012] Furthermore, step S1 specifically includes the following steps:

[0013] S1.1 Parse the user three codes, location information NCGI and session ID from the Nsmf_PDUSession_CreateSMContext Request signaling, encapsulate the user three codes, location information NCGI and session ID into semi-structured data, denoted as semi_data_a, and load balance it to the secondary board through imis;

[0014] S1.2 Parse the smContextRef from the Nsmf_PDUSession_CreateSMContext Response signaling, encapsulate the smContextRef into semi-structured data using imis, denoted as semi_data_b, and load balance it to the secondary board through imis;

[0015] S1.3. Parse the IMSI, smContextRef and tunnel information from the user's three codes from the Namf_Communication_N1N2MessageTransfer signaling, encapsulate them into semi-structured data, denoted as semi_data_c, and load balance the semi_data_c to the secondary board through IMSI.

[0016] S1.4. Parse the smContextRef and tunnel information from the Nsmf_PDUSession_UpdateSMContext Request signaling, encapsulate it into semi-structured data, denoted as semi_data_d, and send it to the secondary board via broadcast.

[0017] S1.5. Parse the smContextRef from the Nsmf_PDUSession_ReleaseSMContext Request signaling, mark the user offline, encapsulate it as semi-structured data denoted as semi_data_e, and send it to the secondary board via broadcast.

[0018] Furthermore, the specific processing steps for the secondary board to receive the first-level semi-structured data packets and update user entries include:

[0019] S2.1 Receive the semi-structured data semi_data_a and establish an imsiInfo table entry associated with imsi, wherein the imsiInfo includes the user's three codes, location information NCGI, uplink and downlink tunnel numbers assigned to the user, network element IP, and internet access IP assigned to the user;

[0020] S2.2 Receive the semi-structured data of semi_data_b and create the smContextRef->imis table entry;

[0021] S2.3 Receive the semi-structured data (semi_data_c) and update the imsi->imsiInfo table entry;

[0022] S2.4 Receive semi-structured data (semi_data_d), search for the smContextRef->imis table entry, obtain the imis, and update the imsi->imsiInfo table entry through the imsi;

[0023] S2.5 Receive semi-structured data (semi_data_e), search for the smContextRef->imis table entry, obtain the imis, search for the imsi->imsiInfo table entry through the imsi, and delete it when the user logs off.

[0024] After receiving the semi-structured data from the first-level board, the second-level board updates the user table entries. Since the second-level board stores user table entries according to IMSI load balancing, multiple boards can be stacked to store more than ten million users.

[0025] Each time a secondary board receives semi-structured data, it encapsulates the user's three-code and tunnel information into secondary structured data, and then sends it to the associated tertiary board based on the learned UPF IP. By filtering the destination UPF IP, the tertiary board does not need to store tens of millions of users; it only needs to store locally relevant users.

[0026] Furthermore, step S3 specifically includes:

[0027] S3.1 Establish user association entries, including establishing association entries for the uplink and downlink tunnel numbers, user three codes, location information NCGI, and Internet IP;

[0028] S3.2 Establish a base station IP association table entry, including using the location information NCGI to extract the gNB ID and establish the gNB ID associated with the base station IP.

[0029] Furthermore, in step S4, the uplink and downlink tunnel numbers plus the downlink network element IP records are Teid_N3_Up+UPFIP and Teid_N3_Down+gNode IP, and the inner source IP address and inner destination IP address records are IPv4_Src_Inner, Ipv4_Dst_Innder, Ipv6_Src_Inner, and Ipv6_Dst_Innder.

[0030] Furthermore, the user tracing association using the uplink / downlink tunnel number and the uplink / downlink network element IP specifically includes: using the Teid_N3_Up+UPF IP as the key to look up the Teid+Ip->UserInfo table entry to obtain the first user information, and simultaneously using the Teid_N3_Down+gNode IP as the key to look up the Teid+Ip->UserInfo table entry to obtain the second user information.

[0031] The strong verification specifically includes:

[0032] S5.1 The user information queried using the Teid_N3_Up+UPF IP and the Teid_N3_Down+gNode IP must be consistent;

[0033] S5.2. Verify the user's Internet IP with the inner IP. If the inner IP is IPv4, then IPv4_Src_Inner or Ipv4_Dst_Innder needs to be consistent with the UE IPv4 in the associated user information table. If the inner IP is an IPv6 prefix, then the prefix of Ipv6_Src_Inner or Ipv6_Dst_Innder needs to be consistent with the UE IPv6 prefix in the associated user information table. The inner IP includes the inner source IP address and the inner destination IP address.

[0034] S5.3 The base station IP corresponding to the associated location information NCGI must be consistent with the base station IP of the N3 interface service data, including: using the base station ID extracted by the location information NCGI to look up the gNB ID->gNB IP table entry, and obtaining the base station IP that is consistent with the gNB IP parsed from the N3 interface service data.

[0035] According to a second aspect of the invention, a computer-readable storage medium is provided on which one or more computer programs are stored, which, when executed by a computer processor, implement the method described above.

[0036] The above-described one or more technical solutions in the embodiments of this application have at least one of the following technical effects:

[0037] This invention provides a 5G multi-level processing user data tracing and association method based on strong verification. It addresses the challenges of large 5G raw signaling traffic and tens of millions of users by innovatively employing multi-level processing for user tracing and using strong verification to resolve inaccuracies and error-prone situations. This invention is applicable to scenarios involving 5G traffic parsing and user data tracing. Attached Figure Description

[0038] The accompanying drawings are included to provide a further understanding of the embodiments and are incorporated in and constitute a part of this specification. The drawings illustrate embodiments and, together with the description, serve to explain the principles of the invention. Other embodiments and many anticipated advantages of the embodiments will be readily recognized as they become better understood through reference to the following detailed description. Elements in the drawings are not necessarily to scale. The same reference numerals refer to corresponding similar parts.

[0039] Figure 1 A schematic flowchart of a 5G multi-level processing user data tracing and association method based on strong verification according to an embodiment of the present invention is shown.

[0040] Figure 2 A schematic diagram of a user tracing association strong verification process according to an embodiment of the present invention is shown.

[0041] Figure 3This is a schematic diagram of the structure of a computer system suitable for implementing the electronic devices of the present application embodiments. Detailed Implementation

[0042] The present application will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings.

[0043] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. This application will now be described in detail with reference to the accompanying drawings and embodiments.

[0044] Figure 1 A flowchart illustrating a 5G multi-level processing user data tracing and association method based on strong verification according to an embodiment of the present invention is shown, as follows: Figure 1 As shown:

[0045] S1 and 5G raw signaling enter the first-level board through load balancing. The first-level board parses N11 and N16 signaling, encapsulates the parsed data into first-level semi-structured data packets, and distributes the data packets to the second-level board through IMSI load balancing.

[0046] S1.1 Parse the user three codes, location information NCGI and session ID from the Nsmf_PDUSession_CreateSMContext Request signaling, encapsulate the user three codes, location information NCGI and session ID into semi-structured data, denoted as semi_data_a, and load balance it to the secondary board through imis;

[0047] S1.2 Parse the smContextRef from the Nsmf_PDUSession_CreateSMContext Response signaling, encapsulate the smContextRef into semi-structured data using imis, denoted as semi_data_b, and load balance it to the secondary board through imis;

[0048] S1.3. Parse the IMSI, smContextRef and tunnel information from the user's three codes from the Namf_Communication_N1N2MessageTransfer signaling, encapsulate them into semi-structured data, denoted as semi_data_c, and load balance the semi_data_c to the secondary board through IMSI.

[0049] S1.4. Parse the smContextRef and tunnel information from the Nsmf_PDUSession_UpdateSMContext Request signaling, encapsulate it into semi-structured data, denoted as semi_data_d, and send it to the secondary board via broadcast.

[0050] S1.5. Parse the smContextRef from the Nsmf_PDUSession_ReleaseSMContext Request signaling, mark the user offline, encapsulate it as semi-structured data denoted as semi_data_e, and send it to the secondary board via broadcast.

[0051] Here, IMS stands for Management Information System; IMSI load balancing refers to the use of load balancing technology in mobile communication networks to distribute IMSI requests across multiple processing units, thereby reducing the load on individual processing units and improving the overall system's processing capacity and response speed. This technology can prevent any single server from becoming overloaded, thus improving network flexibility and availability.

[0052] smContextRef represents a session management context reference, an identifier used in the 5G core network to uniquely identify a session management context. smContextRef is used as a key to associate with relevant information in the mis system.

[0053] In the 5G core network, N11 is the interface between AMF and SMF, and has functions such as PDU session creation, modification and management. N3 is the interface between the base station gNobe and UPF, and is used to carry user plane data.

[0054] The AMF IP and SMF IP corresponding to the N11 signaling generated by the same user's internet access are not necessarily constant; they change as the user moves. Therefore, locking the user's network element IP is not suitable. Meanwhile, for tens of millions of users, a single board cannot meet the storage requirements. Therefore, a multi-level processing approach is adopted to achieve a solution for high traffic volumes and tens of millions of users.

[0055] In some embodiments, the parsed information is encapsulated into a semi-structured data format, such as JSON or XML, which can be used to encapsulate the information into highly readable semi-structured data.

[0056] IMSI load balancing can be achieved through IMSI hashing algorithms or IMSI range partitioning.

[0057] S2. The secondary board receives the first-level semi-structured data packet, updates the user table entries, encapsulates the user three codes and tunnel information into secondary structured data, uses UPF IP to learn and filter the secondary structured data, and sends the filtered data to the tertiary board.

[0058] The specific processing steps for the secondary board to receive the primary semi-structured data packet and update user entries include:

[0059] S2.1 Receive the semi-structured data semi_data_a and establish an imsiInfo table entry associated with imsi, wherein the imsiInfo includes the user's three codes, location information NCGI, uplink and downlink tunnel numbers assigned to the user, network element IP, and internet access IP assigned to the user;

[0060] S2.2 Receive the semi-structured data of semi_data_b and create the smContextRef->imis table entry;

[0061] S2.3 Receive the semi-structured data (semi_data_c) and update the imsi->imsiInfo table entry;

[0062] S2.4 Receive semi-structured data (semi_data_d), search for the smContextRef->imis table entry, obtain the imis, and update the imsi->imsiInfo table entry through the imsi;

[0063] S2.5 Receive semi-structured data (semi_data_e), search for the smContextRef->imis table entry, obtain the imis, search for the imsi->imsiInfo table entry through the imsi, and delete it when the user logs off.

[0064] The user's three codes are IMSI, IMEI, and MSISDN, where IMSI represents the International Mobile Subscriber Identity, IMEI represents the International Mobile Equipment Identity, and MSISDN represents the user's mobile phone number.

[0065] After receiving the semi-structured data from the first-level board, the second-level board updates the user table entries. Since the second-level board stores user table entries according to IMSI load balancing, multiple boards can be stacked to store more than ten million users.

[0066] Each time a secondary board receives semi-structured data, it encapsulates the user's three-code and tunnel information into secondary structured data, and then sends it to the associated tertiary board based on the learned UPF IP. By filtering the destination UPF IP, the tertiary board does not need to store tens of millions of users; it only needs to store locally relevant users.

[0067] S3. The third-level board parses the received second-level structured data, extracts the user's three codes and location information NCGI, assigns uplink and downlink tunnel numbers and network element IPs to the user, and assigns an Internet IP to the user.

[0068] After receiving the structured data from the second level, the third-level board parses and extracts the user's three codes (IMSI, IMEI, MSISDN), location information NCGI, uplink and downlink tunnel numbers and network element IPs assigned to the user (recorded as Teid_up, UPF IP, Teid_down, and gNodeIp, respectively), and the IP address assigned to the user for internet access, which is recorded as UE IP. The UE IP includes the UE IPv4 and UE IPv6 prefixes.

[0069] S3.1 Establish user association entries, including establishing association entries for the uplink and downlink tunnel numbers, user three codes, location information NCGI, and Internet IP;

[0070] In this embodiment, the specific associated table entries are as follows:

[0071]

[0072] S3.2 Establish a base station IP association table entry, including using the location information NCGI to extract the gNB ID and establish the gNB ID associated with the base station IP.

[0073] The 5G NR Cell Global Identifier (NCGI) consists of the Public Land Mobile Network Identifier (PLMN ID) to which the cell belongs and the NR Cell Identifier (NCI), and its specific components are as follows:

[0074] NCGI=PLMN ID+NCI(gNB ID+Cell ID)

[0075] The gNB ID is extracted using the location information parsed by N11 via NCGI, and a gNB ID-base station IP association is established. In this embodiment, the specific association entries are as follows:

[0076]

[0077]

[0078] S4. The three-level board receives service data through the 5G N3 interface and parses the uplink and downlink tunnel number, uplink and downlink network element IP, inner source IP address and inner destination IP address from the service data;

[0079] The uplink and downlink tunnel numbers plus the downlink network element IP records are Teid_N3_Up+UPF IP and Teid_N3_Down+gNodeIP, and the inner source IP address and inner destination IP address records are IPv4_Src_Inner, Ipv4_Dst_Innder, Ipv6_Src_Inner, and Ipv6_Dst_Innder.

[0080] The N3 interface is used in the 5G core network to carry user plane data. It connects the User Plane Function (UPF) and the data network in the 5G core network. Through the N3 interface, the uplink and downlink network element IPs, uplink and downlink tunnel numbers, and inner layer IPs of a single data stream can be extracted.

[0081] In this embodiment, IPv4_Src_Inner represents the source IP address of the inner IPv4 packet in the tunneling technology, and Ipv4_Dst_Innder represents the destination address of the inner IPv4 packet in the tunneling technology. Similarly, Ipv6_Src_Inner represents the source address of the inner IPv6 packet in the tunneling technology, and Ipv6_Dst_Innder represents the destination address of the inner IPv6 packet in the tunneling technology.

[0082] S5. Use the uplink / downlink tunnel number and the uplink / downlink network element IP to perform user source tracing association, and use the inner source IP address and inner destination IP address to perform strong verification with the IMSI associated with the uplink / downlink tunnel number and the IP associated with the base station.

[0083] The user tracing association using the uplink / downlink tunnel number and the uplink / downlink network element IP specifically includes: using the Teid_N3_Up+UPF IP as the key to look up the Teid+Ip->UserInfo table entry to obtain the first user information, and simultaneously using the Teid_N3_Down+gNode IP as the key to look up the Teid+Ip->UserInfo table entry to obtain the second user information.

[0084] The strong verification specifically includes:

[0085] S5.1 The user information queried using the Teid_N3_Up+UPF IP and the Teid_N3_Down+gNode IP must be consistent;

[0086] S5.2. Verify the user's Internet IP with the inner IP. If the inner IP is IPv4, then IPv4_Src_Inner or Ipv4_Dst_Innder needs to be consistent with the UE IPv4 in the associated user information table. If the inner IP is an IPv6 prefix, then the prefix of Ipv6_Src_Inner or Ipv6_Dst_Innder needs to be consistent with the UE IPv6 prefix in the associated user information table. The inner IP includes the inner source IP address and the inner destination IP address.

[0087] S5.3 The base station IP corresponding to the associated location information NCGI must be consistent with the base station IP of the N3 interface service data, including: using the base station ID extracted by the location information NCGI to look up the gNB ID->gNB IP table entry, and obtaining the base station IP that is consistent with the gNB IP parsed from the N3 interface service data.

[0088] This embodiment uses three conditions for strong verification:

[0089] 1) When using N3 service data, the IMSI associated with different tunnel numbers and network element IPs in the uplink and downlink of the same flow must be consistent.

[0090] 2) N3 service data inner layer IP:

[0091] If it is IPv4, the inner IPv4 (source or destination IP) of the N3 interface service data needs to be consistent with the associated user UE IPv4;

[0092] If it is IPv6, the inner IPv6 prefix (source or destination IP) of the N3 interface service data needs to be consistent with the associated user UE IPv6 prefix.

[0093] 3) Extract the base station ID using the associated NCGI table entry, look up the table entry Key(gNode ID)->Value(gNodeIP), and compare the gNode IP with the outer IP (source or destination IP) of the currently parsed N3 interface service data.

[0094] In some alternative embodiments, such as Figure 2 The diagram illustrates a user tracing association strong verification process according to an embodiment of the present invention.

[0095] Using N11 interface signaling parsing, extract user three codes (IMSI, IMEI, MSISDN), location information NCGI, UE IP, and uplink / downlink tunnel number, and establish Key (Teid+IP)Value (IMSI, IMEI, MSISDN, NCGI, UE IPv4, UE IPv6 prefix) table entries, as well as Key (gNode ID)->Value (gNode IP) table entries.

[0096] User tracing and association are performed using the outer IP address and tunnel number of N3 business data.

[0097] Strong verification is performed using the inner IP, the IMSI associated with the dual tunnels, and the IP associated with the base station to ensure the accuracy of user tracing and association.

[0098] In summary, this invention describes an architecture design for 5G core network signaling processing, aiming to solve the signaling processing and resource management problems during large-scale user access. Through a hierarchical processing mechanism, the following main problems can be effectively addressed:

[0099] 1) Large-scale user processing achieves distributed storage of user table information across multiple boards, enabling support for tens of millions of users. This includes: Level 1 boards: performing initial parsing of raw signaling and encapsulating it into semi-structured data packets; Level 2 boards: performing load balancing based on IMSI (International Mobile Subscriber Identity), distributing the semi-structured data packets across different Level 2 boards. Each board processes only a portion of the user data, thus avoiding bottlenecks caused by storing too much user table information on a single board.

[0100] 2) Load balancing: The primary processing board receives 5G raw signaling through load balancing to ensure that the processing load of each board is uniform; IMSI load balancing: Load balancing is performed among the secondary boards according to IMSI, so that multiple secondary boards can process user table updates in parallel, thereby improving the overall system throughput.

[0101] 3) User table entry information bottleneck: By distributing user table entry information across multiple secondary boards, the bottleneck problem of storing user table entry information on a single board is solved, thereby enabling support for a larger scale of user access.

[0102] 4) UPF IP filtering: The level 3 board filters and sends the learned UPF IP to the level 3 associated board. This reduces the storage pressure on the level 3 board, allowing it to store only the user data related to the local area, instead of all the data of all users.

[0103] 5) Efficient management of user information: The third-level board further processes the second-level structured data, extracts key user information (such as IMSI, IMEI, MSISDN, NCGI, etc.), and assigns tunnel numbers and network element IPs to users, thereby achieving efficient management and updating of user information.

[0104] 6) Business data parsing: The Level 3 board parses the business data of the N3 interface to extract the tunnel number and IP information of the outer and inner layers, thereby enabling effective management and routing of user business data.

[0105] This architecture addresses the signaling processing and resource management challenges of large-scale user access, specifically including: 1) Distributed storage: User table information is stored in a distributed manner across multiple levels of boards, supporting large-scale user access. 2) Load balancing: Load balancing among multiple levels of boards ensures even processing load on each board, improving overall system throughput. 3) Efficient management: Through hierarchical processing and filtering, efficient management and updating of user information are achieved, ensuring system efficiency. 4) Resource optimization: By rationally allocating resources such as user information and tunnel numbers, the utilization efficiency of system resources is optimized. This architecture design enables the system to cope with the challenges brought by large-scale user access while ensuring system stability and efficiency.

[0106] The following is for reference. Figure 3 It shows a schematic diagram of the structure of a computer system 300 suitable for implementing electronic devices according to embodiments of the present application. Figure 3 The electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.

[0107] like Figure 3 As shown, the computer system 300 includes a central processing unit (CPU) 301, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 302 or programs loaded from storage section 308 into random access memory (RAM) 303. The RAM 303 also stores various programs and data required for the operation of the system 300. The CPU 301, ROM 302, and RAM 303 are interconnected via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.

[0108] The following components are connected to I / O interface 305: an input section 306 including a keyboard, mouse, etc.; an output section 307 including a liquid crystal display (LCD) and speakers, etc.; a storage section 308 including a hard disk, etc.; and a communication section 309 including a network interface card such as a LAN card and a modem, etc. The communication section 309 performs communication processing via a network such as the Internet. A drive 310 is also connected to I / O interface 305 as needed. A removable medium 311, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on drive 310 as needed so that computer programs read from it can be installed into storage section 308 as needed.

[0109] Specifically, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a computer-readable storage medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 309, and / or installed from removable medium 311. When the computer program is executed by central processing unit (CPU) 301, it performs the functions defined in the methods of this application. It should be noted that the computer-readable storage medium of this application can be a computer-readable signal medium or a computer-readable storage medium or any combination thereof. The computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in connection with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can also be any computer-readable storage medium other than a computer-readable storage medium that can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. Program code contained on a computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0110] Computer program code for performing the operations of this application can be written in one or more programming languages ​​or a combination thereof. Programming languages ​​include object-oriented programming languages—such as Java, Smalltalk, and C++—as well as conventional procedural programming languages—such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0111] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0112] The modules described in the embodiments of this application can be implemented in software or in hardware.

[0113] On the other hand, this application also provides a computer-readable storage medium, which may be included in the electronic device described in the above embodiments; or it may exist independently and not assembled into the electronic device. The computer-readable storage medium carries one or more programs, which, when executed by the electronic device, cause the following: 5G raw signaling enters the primary processing board through load balancing. The primary board purely parses N11 and N16 signaling, encapsulating the parsed data into a primary semi-structured data packet. The secondary board, upon receiving the primary semi-structured data, updates the user entries. The secondary board encapsulates the three-code information and tunnel information into secondary structured data, filtering and sending it to the tertiary board based on the learned UPF IP. The tertiary board parses and extracts the user's three-code, location information NCGI, uplink / downlink tunnel number and network element IP assigned to the user, and the IP address assigned to the user for internet access. The tertiary board parses the outer tunnel number and outer IP address from the 5G N3 interface service data. User tracing and association are performed using the outer IP and tunnel number of the N3 service data. Strong verification is performed using the inner IP, the IMSI associated with the dual tunnels, and the IP associated with the base station to ensure the accuracy of user tracing and association.

[0114] The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in this application is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described inventive concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this application.

Claims

1. A 5G multi-level processing user data tracing and association method based on strong verification, characterized in that, Includes the following steps: S1 and 5G raw signaling enter the first-level board through load balancing. The first-level board parses N11 and N16 signaling, encapsulates the parsed data into first-level semi-structured data packets, and distributes the data packets to the second-level board through IMSI load balancing. S2. The secondary board receives the first-level semi-structured data packet, updates the user table entries, and encapsulates the user's three codes and tunnel information into secondary structured data. It uses UPF IP to learn and filter the secondary structured data and sends the filtered data to the tertiary board. The user's three codes include: IMSI International Mobile Subscriber Identity, IMEI International Mobile Equipment Identity, and MSISDN user's mobile phone number. S3. The third-level board parses the received second-level structured data, extracts the user's three codes and location information NCGI, assigns uplink and downlink tunnel numbers and network element IPs to the user, and assigns an Internet IP to the user. S4. The Level 3 board receives service data through the 5G N3 interface and parses the uplink / downlink tunnel number, uplink / downlink network element IP, inner source IP address, and inner destination IP address from the service data. The uplink / downlink tunnel number and uplink / downlink network element IP are recorded as Teid_N3_Up+UPF IP and Teid_N3_Down+gNode IP, and the inner source IP address and inner destination IP address are recorded as IPv4_Src_Inner, Ipv4_Dst_Innder, Ipv6_Src_Inner, and Ipv6_Dst_Innder. S5. User source tracing is performed using the uplink / downlink tunnel number and the uplink / downlink network element IP. Strong verification is performed using the inner source IP address and inner destination IP address associated with the IMSI and the IP associated with the base station. The strong verification specifically includes: S5.1 The user information queried using the Teid_N3_Up+UPF IP and the Teid_N3_Down+gNode IP must be consistent; S5.

2. Verify the user's Internet IP with the inner IP. If the inner IP is IPv4, then IPv4_Src_Inner or Ipv4_Dst_Innder needs to be consistent with the UE IPv4 in the associated user information table. If the inner IP is an IPv6 prefix, then the prefix of Ipv6_Src_Inner or Ipv6_Dst_Innder needs to be consistent with the UE IPv6 prefix in the associated user information table. The inner IP includes the inner source IP address and the inner destination IP address. S5.3 The base station IP corresponding to the associated location information NCGI must be consistent with the base station IP of the N3 interface service data, including: using the base station ID extracted by the location information NCGI to look up the gNB ID->gNB IP table entry, and obtaining the base station IP that is consistent with the gNB IP parsed from the N3 interface service data.

2. The user data tracing and association method according to claim 1, characterized in that, The specific steps of step S1 also include: S1.1 Parse the user three codes, location information NCGI and session ID from the Nsmf_PDUSession_CreateSMContext Request signaling, encapsulate the user three codes, location information NCGI and session ID into semi-structured data, denoted as semi_data_a, and load balance it to the secondary board through imis; S1.2 Parse the smContextRef from the Nsmf_PDUSession_CreateSMContext Response signaling, encapsulate the smContextRef into semi-structured data using imis, denoted as semi_data_b, and load balance it to the secondary board through imis; S1.

3. Parse the IMSI, smContextRef and tunnel information from the user's three codes from the Namf_Communication_N1N2MessageTransfer signaling, encapsulate them into semi-structured data, denoted as semi_data_c, and load balance the semi_data_c to the secondary board through IMSI. S1.

4. Parse the smContextRef and tunnel information from the Nsmf_PDUSession_UpdateSMContext Request signaling, encapsulate it into semi-structured data, denoted as semi_data_d, and send it to the secondary board via broadcast. S1.

5. Parse the smContextRef from the Nsmf_PDUSession_ReleaseSMContext Request signaling, mark the user offline, encapsulate it as semi-structured data denoted as semi_data_e, and send it to the secondary board via broadcast.

3. The user data tracing and association method according to claim 2, characterized in that, The specific processing steps for the secondary board to receive the primary semi-structured data packet and update user entries include: S2.1 Receive the semi-structured data semi_data_a and establish an imsiInfo table entry associated with imsi, wherein the imsiInfo includes the user's three codes, location information NCGI, uplink and downlink tunnel numbers assigned to the user, network element IP, and internet access IP assigned to the user; S2.2 Receive the semi-structured data of semi_data_b and create the smContextRef->imis table entry; S2.3 Receive the semi-structured data (semi_data_c) and update the imsi->imsiInfo table entry; S2.4 Receive semi-structured data (semi_data_d), search for the smContextRef->imis table entry, obtain the imis, and update the imsi->imsiInfo table entry through the imsi; S2.5 Receive semi-structured data (semi_data_e), search for the smContextRef->imis table entry, obtain the imis, search for the imsi->imsiInfo table entry through the imsi, and delete it when the user logs off.

4. The user data tracing and association method according to claim 1, characterized in that, The processing step S3 further includes: S3.1 Establish user association entries, including establishing association entries for the uplink and downlink tunnel numbers, user three codes, location information NCGI, and Internet IP; S3.2 Establish a base station IP association table entry, including using the location information NCGI to extract the gNB ID and establish the gNB ID associated with the base station IP.

5. The user data tracing and association method according to claim 1, characterized in that, The user tracing association using the uplink / downlink tunnel number and the uplink / downlink network element IP specifically includes: using the Teid_N3_Up+UPF IP as the key to look up the Teid+Ip->UserInfo table entry to obtain the first user information, and simultaneously using the Teid_N3_Down+gNode IP as the key to look up the Teid+Ip->UserInfo table entry to obtain the second user information.

6. A computer program product, characterized in that, It stores a computer program that, when executed by a processor, implements the method as described in any one of claims 1-5.

7. A computing system, characterized in that, It includes a processor and a memory, the processor being configured to perform the method as described in any one of claims 1-5.