5G private network user equipment level flow abnormity monitoring system, method and device and medium
Through the 5G private network user equipment-level traffic abnormality monitoring system, the abnormality detection is used to quickly locate abnormal CPE, solving the problem of UE-level traffic monitoring difficulties and achieving accurate and fast locate abnormal CPE.
Patent Information
- Application Number
- CN202510766016.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-10
AI Technical Summary
In 5G private networks, it is difficult for enterprises to monitor UE-level traffic, resulting in low efficiency in problem positioning. The existing technology needs to gradually check whether the base station and core network are normal, which takes a long time.
Through the 5G private network user equipment-level traffic abnormality monitoring system, the user surface function module and the traffic monitoring module are used to obtain system traffic data, conduct statistics and abnormality detection based on the IP address, and combine the positioning unit and the tracking unit to quickly locate the location and cause of the abnormal CPE.
实现了UE级别的流量监测和统计,能够快速定位异常CPE,减少了问题定位时间,提高了定位精准性和效率。
Smart Images

Figure CN120282265A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a 5G private network user equipment-level traffic anomaly monitoring system, method, device, and medium. Background Art
[0002] At present, the industrial chain is complete, the industry ecosystem is diverse, and the market is vast. Traditional industrial enterprises are accelerating their transformation towards digitalization, networking, and intelligence. Against this background, 5G private networks customized for specific enterprises or organizations have emerged. However, due to the sharing of base stations, it is difficult for enterprises to monitor traffic at the UE (User Equipment) level on the base station side. At the same time, there is a wide variety of CPE (Customer Premises Equipment) purchased by enterprises, and it becomes crucial to monitor and count the traffic of CPEs accessing the private network at the UE level. When problems occur with the current enterprise CPEs, customers first discover the problems, then notify the operator, and then arrange for maintenance personnel to go to the enterprise factory. Often, going to the customer site requires approval. After entering the enterprise factory, it is necessary to first confirm the actual working conditions of the equipment, secondly to confirm whether the signal coverage of the base station is normal, and finally whether the core network is normal. The entire process of locating problems has a long chain and is very time-consuming. How to quickly locate and solve problem CPEs has become an urgent problem to be solved. Summary of the Invention
[0003] The main objective of the embodiments of the present disclosure is to propose a 5G private network user equipment-level traffic anomaly monitoring system, method, device, and medium, aiming to achieve traffic monitoring and statistics at the UE level, and to accurately and quickly locate abnormal CPEs and their problems.
[0004] To achieve the above objective, on the one hand, an embodiment of the present application proposes a 5G private network user equipment-level traffic anomaly monitoring system. The 5G private network user equipment-level traffic anomaly monitoring system includes a user plane function module and a traffic monitoring module; the user plane function module includes a collection unit and a statistics unit; the traffic monitoring module includes an anomaly detection unit, a positioning unit, and a tracking unit; The collection unit is used to obtain system traffic data; The statistics unit is used to statistically analyze the system traffic data according to the IP addresses of multiple different customer premises equipment to obtain the traffic statistical results of each customer premises equipment; The anomaly detection unit is used to determine whether the customer premises equipment has an anomaly according to the traffic statistical results; The positioning unit is used to, when the customer premise equipment has an exception, obtain the terminal information according to the IP address of the customer premise equipment and the mapping relationship between the preset terminal information of the customer premise equipment and the IP address, and determine the location information of the customer premise equipment, where the terminal information includes the location information and the user permanent identifier; The tracking unit is used to trigger signaling tracking and data tracking according to the user permanent identifier, and obtain the exception analysis result of the customer premise equipment.
[0005] In some embodiments, the system further includes a control plane function module, and the control plane function module includes a unified data management module and a session management function module; The session management function module is used to, in response to a first request signal initiated by the customer premise equipment, send a second request signal to the unified data management module, where the first request signal is used to initiate a dialogue process; The unified data management module is used to, in response to the second request signal, establish the mapping relationship between the terminal information of the customer premise equipment and the IP address.
[0006] In some embodiments, the unified data management module is further used to send subscription data to the session management function module, where the subscription data includes the IP address; The session management function module is further used to send a packet detection rule flow description protocol value to the user plane function module according to the subscription data, where the packet detection rule flow description protocol value includes the IP address; The statistics unit of the user plane function module is used to perform statistics on the system traffic data according to the packet detection rule flow description protocol value, and obtain the traffic statistics result of each customer premise equipment.
[0007] In some embodiments, the statistics unit is specifically used for: Perform statistics on the system traffic data according to the IP address, and determine the user traffic data of each customer premise equipment; Divide the user traffic data into first traffic data in multiple different transmission directions according to the transmission direction identifier of the packet detection rule flow description protocol value; Perform statistics on different service types for the first traffic data in each transmission direction respectively according to the service type identifier of the packet detection rule flow description protocol value, and obtain second traffic data of different service types in each transmission direction; Obtain the traffic statistics result according to the first traffic data and the second traffic data.
[0008] In some embodiments, the anomaly detection unit is specifically configured to: Perform time division on the second traffic data based on the time tags of the second traffic data to obtain third traffic data; Separate statistics are performed on the packet loss data of the second traffic data of different service types to obtain a packet loss statistical result; Determine multiple comparison time nodes according to a preset traffic data comparison period; Compare the third traffic data before and after the comparison time node to obtain a comparison result; Judge whether the customer premise equipment has an anomaly according to the third traffic data, the packet loss statistical result, and the comparison result.
[0009] In some embodiments, the positioning unit is specifically configured to send the IP address of the customer premise equipment to the unified data management module, so that the unified data management module sends terminal information to the traffic monitoring module according to the mapping relationship; obtain the location information according to the terminal information; The tracking unit is specifically configured to send tracking instructions to the control plane function module and the user plane function module respectively, so that the control plane function module performs signaling tracking according to the user permanent identifier, and the user plane function module performs data tracking according to the user permanent identifier to obtain the anomaly analysis result, where the tracking instruction includes the user permanent identifier.
[0010] In some embodiments, the system further includes a storage and output module, and the storage and output module includes a display unit and an alarm unit; The display unit is configured to store the user traffic data of all customer premise equipment in a database to obtain a historical traffic database; in response to a traffic display instruction, display each user traffic data in the historical traffic database through a visualization interface; The alarm unit is configured to generate an alarm message when the customer premise equipment has an anomaly; display the alarm message and the anomaly analysis result on the visualization interface.
[0011] On the other hand, an embodiment of the present invention proposes a method for monitoring 5G private network user equipment-level traffic anomalies, including the following steps: Obtain system traffic data; Perform statistics on the system traffic data according to the IP addresses of multiple different customer premise equipment to obtain the traffic statistical result of each customer premise equipment; Judge whether the customer premise equipment has an anomaly according to the traffic statistical result; When an abnormality occurs in the customer premise equipment, the terminal information is obtained according to the IP address of the customer premise equipment and the mapping relationship between the preset terminal information of the customer premise equipment and the IP address, and the location information of the customer premise equipment is determined, where the terminal information includes the location information and the user permanent identifier; According to the user permanent identifier of the terminal information, signaling tracking and data tracking are triggered to obtain the abnormality analysis result of the customer premise equipment.
[0012] On the other hand, an embodiment of the present invention provides an electronic device, including: At least one processor; At least one memory for storing at least one program; When the at least one program is executed by the at least one processor, when the at least one program is executed by the at least one processor, at least one of the processors is caused to implement the 5G private network user equipment-level traffic abnormality monitoring method as described in the previous embodiment.
[0013] On the other hand, an embodiment of the present invention further provides a computer-readable storage medium, and the computer-readable storage medium stores computer-executable instructions for causing a computer to execute the 5G private network user equipment-level traffic abnormality monitoring method as described in the previous embodiment.
[0014] At least one of the above technical solutions of the present invention has at least the following advantages or beneficial effects: A 5G private network user equipment-level traffic anomaly monitoring system, method, device and medium proposed in this application obtain traffic data through a user plane function module, count the traffic data according to the IP addresses of multiple different customer premise equipment, and obtain the traffic statistics results of each different customer premise equipment. The traffic monitoring module analyzes the traffic statistics results to determine whether the customer premise equipment has an anomaly. When an anomaly occurs in the 5G private network user equipment-level traffic anomaly monitoring customer premise equipment, according to the IP address of the 5G private network user equipment-level traffic anomaly monitoring customer premise equipment and the mapping relationship between the terminal information of the preset customer premise equipment and the 5G private network user equipment-level traffic anomaly monitoring IP address, the 5G private network user equipment-level traffic anomaly monitoring terminal information is obtained, and the location information of the 5G private network user equipment-level traffic anomaly monitoring customer premise equipment is determined. Among them, the 5G private network user equipment-level traffic anomaly monitoring terminal information includes the 5G private network user equipment-level traffic anomaly monitoring location information and the user permanent identifier. Then, according to the user permanent identifier, signaling tracking and data tracking are triggered to obtain the anomaly analysis result of the customer premise equipment. This application can implement UE-level traffic monitoring and statistics based on the IP address. When an anomaly is detected in the CPE, the abnormal CPE is determined through the IP address of the traffic statistics result, so as to determine the location information of the abnormal CPE, and then trigger signaling tracking and data tracking to obtain the anomaly analysis result. The anomaly analysis result can determine the reason for the anomaly of the abnormal CPE, realize accurate and rapid positioning of the abnormal CPE and its problems, and enable the back-end personnel not to wait for the problem to reappear. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 is a flowchart of the 5G private network user equipment-level traffic anomaly monitoring method provided by an embodiment of this application; Figure 2 is a schematic structural diagram of the 5G private network user equipment-level traffic anomaly monitoring system provided by an embodiment of this application; Figure 3 is a schematic diagram of the process of establishing a mapping relationship of the 5G private network user equipment-level traffic anomaly monitoring system provided by an embodiment of this application; Figure 4 is a schematic diagram of the process of sending an IP address of the 5G private network user equipment-level traffic anomaly monitoring system provided by an embodiment of this application; Figure 5 is a schematic structural diagram of the storage output module provided by an embodiment of this application; Figure 6 is a schematic diagram of the data interaction process between the terminal and the server provided by an embodiment of this application; Figure 7 is a schematic diagram of the data interaction process between terminals provided by an embodiment of this application; Figure 8It is a schematic diagram of the overall architecture of the 5G private network user equipment-level traffic anomaly monitoring system provided by the embodiments of the present application; Figure 9 It is a schematic diagram of the complete operation process of the 5G private network user equipment-level traffic anomaly monitoring system provided by the embodiments of the present application; Figure 10 It is a schematic diagram of the hardware structure of the electronic device provided by the embodiments of the present application. Specific Embodiments
[0016] In order to make the objectives, technical solutions, and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0017] It should be noted that although the functional modules are divided in the device schematic diagram and the logical sequence is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order from the module division in the device or the sequence in the flowchart. Terms such as "first" and "second" in the specification, claims, and the above-mentioned drawings are used to distinguish similar objects and do not necessarily need to describe a specific order or sequence.
[0018] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of the present application and are not intended to limit the present application.
[0019] First, several terms involved in the present application are analyzed: 5G Core Network (5th Generation Core Network, 5GC): It refers to the core network of the fifth-generation mobile communication system, which is a new mobile network architecture that can provide faster, more secure, and more reliable mobile communication services. The main characteristics of 5GC are the adoption of a distributed architecture, with high scalability, high reliability, and high security, and it can support more types of application services to meet the needs of different users. The network structure of 5GC consists of a control layer and a data layer, and the control layer consists of a control plane and a user plane. The applications of 5GC mainly include smart home, vehicle networking, Internet of Things, intelligent manufacturing, intelligent health, etc., which can provide more efficient, more secure, and more reliable mobile communication services, realize the development of intelligence, networking, dataization, and serviceization, and promote the development and application of mobile communication technology.
[0020] Customer Premises Equipment (CPE): It is a network access device deployed at the user side (such as home, enterprise or factory). As the "border gateway" between the user's internal network and the operator's wide area network, it is responsible for converting external network signals (such as optical fiber, 5G wireless) into locally available Ethernet or Wi-Fi services. Its core functions include physical layer signal conversion (optical signal to electrical signal), user authentication, routing and switching, service quality management, and security protection (firewall, traffic filtering).
[0021] The 5G private network user equipment-level traffic anomaly monitoring system according to the embodiments of the present application can be applied to the 5G core network. Among them, the user plane function module in this system is applied to the user plane function network element (User Plane Function, UPF) of the 5G core network, the session management function module is applied to the session management function network element (Session Management Function, SMF) of the 5G core network, the unified data management module is applied to the unified data management function network element (Unified Data Management, UDM) of the 5G core network, and the traffic monitoring module is applied to the OAM network element (Operation Administration and Maintenance).
[0022] Please refer to Figure 2 , the 5G private network user equipment-level traffic anomaly monitoring system according to the embodiments of the present application includes a user plane function module and a traffic monitoring module; the user plane function module includes a collection unit and a statistics unit; the traffic monitoring module includes an anomaly detection unit, a positioning unit, and a tracking unit; The collection unit is used to obtain system traffic data; The statistics unit is used to statistically analyze the system traffic data according to the IP addresses of multiple different customer premises equipment, and obtain the traffic statistics result of each customer premises equipment; The anomaly detection unit is used to judge whether the customer premises equipment has an anomaly according to the traffic statistics result; The positioning unit is used to, when the customer premises equipment has an anomaly, obtain the terminal information according to the IP address of the customer premises equipment and the mapping relationship between the preset terminal information of the customer premises equipment and the IP address, and determine the location information of the customer premises equipment, where the terminal information includes location information and user permanent identifier; The tracking unit is used to trigger signaling tracking and data tracking according to the user permanent identifier, and obtain the anomaly analysis result of the customer premises equipment.
[0023] Specifically, please refer to Figure 2, the User Plane Function (UPF) module includes a collection unit and a statistics unit. The traffic monitoring module is OAM (Operation Administration and Maintenance). The traffic monitoring module includes an anomaly detection unit, a positioning unit, and a tracking unit. First, the system collects the system traffic data on the UPF side through the collection unit. The system traffic data includes the traffic data of multiple customer premise equipment. The statistics unit will perform statistics on the system traffic data according to the IP address, and can determine the traffic statistics result of each customer premise equipment. The UPF will regularly report the traffic statistics result of each customer premise equipment to the OAM. The anomaly detection unit will analyze the traffic statistics result. Since the traffic statistics result includes the IP address, by determining whether there is an anomaly in the traffic statistics result, it can be determined whether the customer premise equipment has an anomaly. When the customer premise equipment has an anomaly, the positioning unit will obtain the terminal information according to the IP address of the customer premise equipment and the mapping relationship between the preset terminal information of the customer premise equipment and the IP address. Since the terminal information includes the location information and the Subscription Permanent Identifier (SUPI), the location information of the abnormal customer premise equipment can be determined. Further, the tracking unit can perform signaling tracking and data tracking based on the subscription permanent identifier, and can obtain the anomaly analysis result of the abnormal customer premise equipment, realizing the rapid positioning of the abnormal CPE.
[0024] In some embodiments, the system further includes a control plane function module, and the control plane function module includes a unified data management module and a session management function module; The session management function module is used to send a second request signal to the unified data management module in response to the first request signal initiated by the customer premise equipment, where the first request signal is used to initiate a dialogue process; The unified data management module is used to establish a mapping relationship between the terminal information of the customer premise equipment and the IP address in response to the second request signal.
[0025] Specifically, please refer to Figure 3, before collecting the system traffic data, the customer-premises equipment sends a first request signal to the Session Management Function (SMF) module, aiming to establish a session process. After receiving the first request signal, the Session Management Function module sends a second request signal to the Unified Data Management (UDM) module. When the Unified Data Management module receives the second request signal, it establishes a mapping relationship between the terminal information and the IP address of the customer-premises equipment, that is, binds the terminal information and the IP address of the customer-premises equipment. Exemplarily, in an enterprise 5G private network, a corresponding CPE network segment is planned according to the internal enterprise. The 5G private network assigns a fixed IP address to each SUPI number within the corresponding segment. For better demonstration, the actual location of the CPE is also recorded. When an exception occurs, the system can quickly find the corresponding SUPI number, which device, and where the device is according to the IP address.
[0026] In some embodiments, the Unified Data Management module is further configured to send subscription data to the Session Management Function module, where the subscription data includes an IP address; The Session Management Function module is further configured to send a Packet Detection Rule (PDR) flow description protocol value including the IP address to the User Plane Function module according to the subscription data; The statistics unit of the User Plane Function module is configured to perform statistics on the system traffic data according to the Packet Detection Rule flow description protocol value to obtain the traffic statistics result of each customer-premises equipment.
[0027] Specifically, please refer to Figure 4 , after the Unified Data Management (UDM) module establishes a mapping relationship between the terminal information and the IP address of the customer-premises equipment, the Unified Data Management module sends subscription data including a static IP address to the Session Management Function (SMF) module. When the Session Management Function module obtains the subscription data and finds that there is already a static IP address, the SMF does not randomly assign an IP address. Instead, the SMF directly sends the Packet Detection Rule (PDR) flow description protocol value carrying the IP address to the User Plane Function (UPF) module. Subsequently, the UPF can perform packet matching and traffic statistics according to the PDR flow description protocol value. Since the PDR flow description protocol value contains the IP address, the UPF can separately perform statistics on the traffic data of each customer-premises equipment in the system traffic data to obtain the traffic statistics result.
[0028] In some embodiments, the statistics unit is specifically configured to: Perform statistics on the system traffic data according to the IP address to determine the user traffic data of each customer-premises equipment; According to the transmission direction identifier describing the protocol value of the data packet detection rule flow, the user traffic data is divided into multiple first traffic data with different transmission directions; According to the service type identifier describing the protocol value of the data packet detection rule flow, different service type statistics are respectively performed on the first traffic data in each transmission direction to obtain second traffic data of different service types in each transmission direction; Based on the first traffic data and the second traffic data, a traffic statistics result is obtained.
[0029] Specifically, traffic statistics are performed on the uplink and downlink traffic of N3 and N6 on the UPF side of the core network based on IP for types such as TCP, UDP, and ICMP. The N3 interface is the interface between the (R)AN (access network) and the UPF in the 5G core network architecture, and the N6 interface is used to connect the UPF and the external data network (Data Network, DN). First, the statistical unit statistically obtains the user traffic data of each customer premise equipment based on the IP address of the PDR flow description protocol value, and then further statistically processes the user traffic data. According to the transmission direction identifier of the PDR flow description protocol value sent by the SMF, the user traffic data is divided into multiple first traffic data with different transmission directions. The multiple first traffic data include N3 uplink data, N3 downlink data, N6 uplink data, and N6 downlink data. Then, according to the service type identifier of the PDR flow description protocol value, traffic data under different service types of each first traffic data is respectively statistically processed. The service types include TCP, UDP, and ICMP to obtain second traffic data. The second traffic data includes TCP traffic data, UDP traffic data, and ICMP traffic data in all transmission directions. Based on the first traffic data and the second traffic data, a traffic statistics result is obtained. Exemplarily, the format of the traffic statistics result is specifically shown in Table 1.
[0030] Table 1
[0031] In some embodiments, the currently used scenarios in the enterprise 5G private network mainly include: one is that the terminal needs to access the enterprise intranet server, and the common service is uploading and downloading on the corresponding server, that is, Figure 6 the message routing from the terminal to the enterprise server behind N6 as shown; the other is the mutual access of data between terminals, that is, Figure 7 the message routing for mutual access between terminals as shown.
[0032] According to the actual business scenarios of the enterprise (such as TCP, UDP, ICMP, etc.), control the SMF to issue the corresponding type of PDR flow description protocol value (such as permit out 6 from PDN to UE). Among them, from PDN to UE represents the data transmission direction (transmission direction identifier) from the external data network (PDN) to the user equipment (UE), and 6 represents the TCP service (service type identifier). If there are multiple services, multiple flow descriptions can be issued. While the UPF performs PDR matching, it also performs traffic counting.
[0033] The UPF can report UE-level traffic in the format of Table 1. A new configuration can be added to set the reporting period for the UPF to report to the OAM, such as reporting once every 5 minutes. The message transmission between the UPF and the OAM can use grpc (Google Remote Procedure Call). Grpc is a high-performance, cross-language remote procedure call (RPC) framework, based on the HTTP / 2 transport protocol, and uses ProtocolBuffers (Protobuf) as the serialization protocol, which is suitable for microservice architectures, high-concurrency systems, and cross-language call scenarios.
[0034] In some embodiments, the anomaly detection unit is specifically used for: Performing time division on the second traffic data based on the time stamps of the second traffic data to obtain third traffic data; Respectively counting the packet loss data of the second traffic data of different service types to obtain a packet loss statistical result; Determining multiple comparison time nodes according to a preset traffic data comparison period; Comparing the third traffic data before and after the comparison time node to obtain a comparison result; Judging whether the customer premise equipment is abnormal according to the third traffic data, the packet loss statistical result, and the comparison result.
[0035] Specifically, the traffic monitoring module (OAM) will periodically receive the traffic statistical results reported by the UPF. As shown in Table 1, the anomaly detection unit of the traffic monitoring module will respectively count the packet loss data of multiple second traffic data in the traffic statistical results, that is, respectively count the number of packet losses of TCP traffic data, UDP traffic data, and ICMP traffic data in all transmission directions of the second traffic data to obtain a packet loss statistical result.
[0036] The anomaly detection unit performs time division on the second traffic data based on the time tags of the second traffic data to obtain the third traffic data. The transmission of all traffic data has time tags, which can represent the transmission time nodes of a certain type of traffic data. The third traffic data can represent TCP traffic data, UDP traffic data, and ICMP traffic data on a certain time scale, and can also represent the changes in the third traffic data at different times. Further, according to the preset traffic data comparison period, multiple comparison time nodes are determined. The traffic data comparison period is set by user input and can be set to 5 minutes, that is, each comparison time node is 5 minutes apart. Since the third traffic data is based on time division and the comparison time nodes are determined, the third traffic data before and after the corresponding time nodes can be obtained. By comparing the third traffic data before the time node with the third traffic data after the time node, a comparison result can be obtained. By synthesizing the changes in the third traffic data at different times, the packet loss statistics result, and the comparison result, it can be determined whether the CPE is abnormal based on the user traffic data. Exemplarily, traffic data anomalies are mainly divided into three categories. The first category is disconnection, which is relatively easy to monitor, that is, detecting that the CPE has no uplink and downlink traffic. The second category is excessive UPF packet loss. The third category is that enterprise production data generally shows a certain pattern. If the data volume deviates from the normal value by a certain threshold on a certain day, it represents traffic anomaly, and a reasonable threshold needs to be set. For example, at 10 o'clock every day, it is the production peak period and the data volume is about 1G. The average value of the data volume at 10 o'clock in the past 30 days is 1G. When the traffic volume at 10 o'clock on the 31st day exceeds the average value by +-50%, it can be determined as abnormal traffic data and an alarm is reported.
[0037] In some embodiments, the positioning unit is specifically configured to send the IP address of the customer premise equipment to the unified data management module, so that the unified data management module sends the terminal information to the traffic monitoring module according to the mapping relationship; and obtain the location information according to the terminal information; The tracking unit is specifically configured to send tracking instructions to the control plane function module and the user plane function module respectively, so that the control plane function module performs signaling tracking according to the user permanent identifier, and the user plane function module performs data tracking according to the user permanent identifier to obtain the anomaly analysis result, where the tracking instructions include the user permanent identifier.
[0038] Specifically, the anomaly detection unit determines the abnormal user premise equipment through the traffic statistics results. The positioning unit will send the IP address of the abnormal CPE to the Unified Data Management (UDM) module. The UDM will retrieve the mapping relationship of this IP address in the mapping relationship table according to the received IP address, so as to determine the terminal information mapped by this IP address. The UDM will send the terminal information to the traffic monitoring module, and the positioning unit can determine the location information of the abnormal CPE according to the terminal information. The tracking unit can send a signaling tracking instruction to the control plane function module and a data tracking instruction to the user plane function module according to the Subscriber Permanent Identifier (SUPI) in the terminal information. Since the tracking instruction includes the SUPI, it triggers the control plane function module to perform signaling tracking according to the SUPI, and triggers the user plane function module to perform data tracking according to the SUPI, so as to obtain the anomaly analysis result.
[0039] In some embodiments, the system further includes a storage and output module, and the storage and output module includes a display unit and an alarm unit; The display unit is used to store the user traffic data of all customer premise equipment into the database to obtain a historical traffic database; in response to the traffic display instruction, each user traffic data in the historical traffic database is displayed through the visual interface; The alarm unit is used to generate an alarm message when an abnormality occurs in the customer premise equipment; the alarm message and the anomaly analysis result are displayed on the visual interface.
[0040] Specifically, please refer to Figure 5 The storage and output module includes a display unit and an alarm unit. The main function of the storage and output module is to record all data into the database. Based on this database, the traffic of each terminal can be dynamically displayed. The display unit can store the user traffic data obtained by the statistics unit into the database to construct a historical traffic database. When the user inputs a traffic display instruction, each user traffic data in the historical traffic database is displayed through the visual interface to realize the display of CE-level traffic data. When the anomaly detection unit detects an abnormal CPE, the alarm unit automatically generates a corresponding alarm signal, and the alarm signal and the anomaly analysis result are displayed on the visual interface. The alarm signal can be an interface reminder, which can timely remind the back-end maintenance personnel of the occurrence of abnormal situations. The anomaly analysis result is a brief analysis conclusion of the abnormal CPE, which can enable the back-end maintenance personnel to quickly determine the location information of the abnormal CPE, the cause of the anomaly of the abnormal CPE, and the method to repair the anomaly. Exemplarily, the anomaly analysis result can be that the CPE is disconnected and the traffic is interrupted, the UPF packet loss is due to the packet loss indicated by the SMF when the SMF cannot page the CPE, and the alarm is caused by excessive data volume because there are too many devices hung under the CPE, and the network structure can be optimized to share the hung devices, etc.
[0041] Please refer to Figure 1 , Figure 1 which is an optional flowchart of the 5G private network user equipment-level traffic anomaly monitoring method provided by some embodiments of this application. A 5G private network user equipment-level traffic anomaly monitoring method according to an embodiment of the present invention includes but is not limited to steps S100 to S500: Step S100, obtain system traffic data; Step S200, statistically analyze the system traffic data according to the IP addresses of multiple different customer-premises equipment to obtain the traffic statistical results of each customer-premises equipment; Step S300, determine whether the customer-premises equipment is abnormal according to the traffic statistical results; Step S400, when the customer-premises equipment is abnormal, obtain the terminal information according to the IP address of the customer-premises equipment and the mapping relationship between the terminal information and the IP address of the preset customer-premises equipment, and determine the location information of the customer-premises equipment, where the terminal information includes location information and a user permanent identifier; Step S500, trigger signaling tracking and data tracking according to the user permanent identifier of the terminal information to obtain the anomaly analysis result of the customer-premises equipment.
[0042] The 5G private network user equipment-level traffic anomaly monitoring method provided by the embodiments of this application can be applied to terminals, can also be applied to the server side, or can be software running on the terminal or the server side. In some embodiments, the terminal can be a smart phone, a tablet computer, a notebook computer, a desktop computer, etc.; the server side can be configured as an independent physical server, can also be configured as a server cluster or a distributed system composed of multiple physical servers, or can be configured as a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application for implementing the indoor item digital management method, etc., but is not limited to the above forms.
[0043] This application can be used in numerous general-purpose or special-purpose computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This application can also be practiced in a distributed computing environment where tasks are executed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0044] In some embodiments, please refer to Figure 8 , Figure 8 which is a schematic diagram of the overall architecture of a 5G private network traffic monitoring system. This system includes a packet forwarding module, a protocol stack parsing module, a traffic detection module, and a storage output module. Among them, the packet forwarding module and the protocol stack parsing module belong to the UPF. The packet forwarding module differentiates the N3 uplink and downlink data and N6 uplink and downlink data of user traffic data through a packet forwarding thread, and sends the N3 and N6 uplink and downlink data to the protocol stack parsing module. The protocol stack parsing module parses the source address and protocol stack of the N3 and N6 uplink and downlink data, so as to distinguish the source address and count the protocol stack of the N3 and N6 uplink and downlink data. Further, the traffic monitoring module respectively performs TCP / UDP / ICMP traffic statistics, periodic comparison analysis, and packet loss statistics on the N3 and N6 uplink and downlink data, identifies anomalies based on the TCP / UDP / ICMP traffic statistics, periodic comparison analysis, and packet loss statistics, and thus reports anomalies and triggers signaling and data tracking. The traffic monitoring module transmits all traffic data to the storage output module, and the storage output module stores the logs of all traffic data, records all data in the database, and based on this database, the traffic of each terminal can be dynamically displayed, and alarms can be output when anomalies occur.
[0045] In some embodiments, traffic statistics and rate calculation are performed on the uplink and downlink traffic of N3 and N6 on the UPF side of the core network based on IP for TCP, UDP, ICMP and other types. Firstly, this can quickly locate the problematic CPE (no traffic, etc.); secondly, it can detect the problem of uneven CPE traffic load (too many devices are connected under the CPE), and the existing enterprise networking can be optimized; thirdly, big data can perform historical data backtracking analysis and predict future data based on a single CPE. When abnormal traffic is detected, the network management can be automatically notified, and signaling tracking and data tracking can be performed based on the SUPI number of the device to protect the fault scene in time.
[0046] In some embodiments, to ensure the accuracy of UE-level traffic records, first, the relationship between the basic information of the CPE terminal (terminal type and actual terminal location) and the IP address of the CPE needs to be configured on the UDM. Secondly, based on various flow descriptions sent by the SMF side, the UPF can report UE-level traffic in the format of Table 1; finally, the reported data is saved for further traffic data analysis. When the OAM detects abnormal traffic reporting, signaling tracking and data tracking of each network element are synchronously triggered to save the fault scene. Specifically, please refer to Figure 9 , Figure 9 which is the operation flow chart of the 5G private network abnormal traffic monitoring system.
[0047] Firstly, the binding of the CPE device to a fixed IP.
[0048] In the enterprise private network, corresponding CPE network segments will be planned according to the internal enterprise. In the 5G private network, a fixed IP address will be allocated to each SUPI number within the corresponding segment. For better demonstration, the actual location of the CPE will also be recorded. When an abnormality occurs later, the corresponding SUPI number, which device, and where the device is can be quickly found based on the IP.
[0049] After the UE completes registration over the air interface, the UE (CPE) sends a first request signal (pdu req) to the SMF to establish a dialogue process. In response to the first request signal, the SMF sends a second request signal (sdm-subscription) to the UDM. The UDM obtains the static IP address corresponding to the number through the second request signal, binds the IP address with the CPE location information and the SUPI, and then the UDM returns the subscribed data to the SMF. After obtaining the subscribed data, the SMF finds that there is already a static IP address, so the SMF does not randomly allocate an IP address but directly sends the PDR including the UE's IP address to the UPF in the N4 Establish req, so that the UPF can use the PDR for subsequent packet matching and traffic statistics. After receiving the PDR from the SMF, the UPF returns a response signal to the SMF. Then the SMF sends a pdu rsp to the CPE. The pdu rsp usually refers to the response data packet returned by the other party when one party sends a create request (create pdu req) in the communication protocol.
[0050] Then, periodically obtain UE-level traffic statistics.
[0051] According to the actual business scenarios of the enterprise (such as TCP, UDP, ICMP, etc.), the SMF issues the corresponding type of PDR flow description protocol value, such as permit out 6 from PDN to UE, where 6 represents the TCP service. The PDR contains the IP address. If there are multiple services, multiple flow descriptions can be issued. While performing PDR matching, the UPF performs traffic counting. The reporting period of the UPF for the UE can be set by adding a new configuration, and the default is to report once every 5 minutes. The message transmission between the UPF and the OAM uses grpc.
[0052] Finally, further analyze the traffic data and predict abnormal traffic alarms.
[0053] The OAM records the traffic data reported by the UPF based on time for different categories of TCP, UDP, and ICMP, and monitors whether the traffic data is abnormal. When abnormal UE traffic is detected, the OAM sends the UE's IP address to the UDM. The UDM will return the terminal information (supi and CPE location) corresponding to the IP address to the OAM according to the IP address, and then trigger the control plane network element to perform signaling tracking and the user plane network element to perform data tracking according to the terminal information, and save the fault scene in time.
[0054] According to some embodiments of the present application, the embodiments of the present application at least have the following beneficial effects: Implement periodic traffic monitoring at the UE level for all access devices, which is intuitive and clear; Historical traffic data can be saved for comparative analysis of front and back data to optimize the system network; When traffic anomalies are detected, an alarm is reported and signaling and data traces are automatically collected, enabling back-end personnel to no longer wait for problems to recur and locate problems more accurately.
[0055] The following combines Figure 10 to introduce the electronic device of the embodiment of the present application in detail.
[0056] Such as Figure 10 , Figure 10 schematically shows the hardware structure of an electronic device of another embodiment. The electronic device includes: A processor 1100, which can be implemented by a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided by the embodiments of the present disclosure; A memory 1200, which can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM), etc. The memory 1200 can store an operating system and other application programs. When implementing the technical solutions provided by the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 1200 and are called by the processor 1100 to execute the 5G private network user equipment-level traffic anomaly monitoring method of the embodiments of the present disclosure; An input / output interface 1300 for realizing information input and output; A communication interface 1400 for realizing communication interaction between this device and other devices, which can be implemented through wired means (such as USB, network cable, etc.) or through wireless means (such as mobile network, WIFI, Bluetooth, etc.); A bus 1500 for transmitting information between various components of the device (such as the processor 1100, the memory 1200, the input / output interface 1300, and the communication interface 1400); Among them, the processor 1100, the memory 1200, the input / output interface 1300, and the communication interface 1400 are communicatively connected to each other inside the device through the bus 1500.
[0057] An embodiment of the present disclosure also provides a storage medium, which is a computer-readable storage medium. The computer-readable storage medium stores computer-executable instructions for causing a computer to execute the above-mentioned 5G private network user equipment-level traffic anomaly monitoring method.
[0058] As a non-transitory computer-readable storage medium, a memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory can include high-speed random access memory, and can also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory can include a memory remotely provided with respect to the processor, and these remote memories can be connected to the processor through a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0059] The embodiments described in the embodiments of the present disclosure are for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and do not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. Those skilled in the art will know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present disclosure are equally applicable to similar technical problems.
[0060] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present disclosure, and may include more or fewer steps than those shown in the figures, or combine certain steps, or different steps.
[0061] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0062] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and appropriate combinations thereof.
[0063] In the description of the present application and the above-mentioned drawings, terms such as "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0064] It should be understood that in the present application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects and indicates that three relationships can exist. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Among them, A and B can be singular or plural. The character " / " generally means that the associated objects before and after are in an "or" relationship. "At least one (one) of the following" or similar expressions refer to any combination of these items, including any combination of single items (ones) or plural items (ones). For example, at least one (one) of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0065] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical or other forms.
[0066] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0067] In addition, in each embodiment of the present application, each functional unit may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above integrated unit may be implemented in the form of hardware or in the form of a software functional unit.
[0068] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, may be embodied in the form of a software product. The computer software product is stored in a storage medium and includes multiple instructions for causing an electronic device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of the present application. The foregoing storage medium includes: various media that can store programs such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.
[0069] The preferred embodiments of the present disclosure have been described above with reference to the accompanying drawings. However, this does not limit the scope of the rights of the embodiments of the present disclosure. Any modification, equivalent replacement, and improvement made by those skilled in the art without departing from the scope and essence of the embodiments of the present disclosure shall fall within the scope of the rights of the embodiments of the present disclosure.
Claims
1. A 5G private network user equipment-level traffic anomaly monitoring system, characterized in that, The 5G private network user equipment-level traffic anomaly monitoring system includes a user plane function module and a traffic monitoring module; the user plane function module includes an acquisition unit and a statistics unit; the traffic monitoring module includes an anomaly detection unit, a positioning unit, and a tracking unit; The acquisition unit is used to obtain system traffic data; The statistics unit is used to statistically analyze the system traffic data according to the IP addresses of multiple different customer premise devices to obtain the traffic statistics result of each customer premise device; The anomaly detection unit is used to determine whether the customer premise device has an anomaly according to the traffic statistics result; The positioning unit is used to, when the customer premise device has an anomaly, obtain the terminal information according to the IP address of the customer premise device and the mapping relationship between the terminal information of the preset customer premise device and the IP address, and determine the location information of the customer premise device, where the terminal information includes the location information and the user permanent identifier; The tracking unit is used to trigger signaling tracking and data tracking according to the user permanent identifier to obtain the anomaly analysis result of the customer premise device.
2. The 5G private network user equipment-level traffic anomaly monitoring system according to claim 1, wherein, The system further includes a control plane function module, and the control plane function module includes a unified data management module and a session management function module; The session management function module is used to send a second request signal to the unified data management module in response to a first request signal initiated by a customer premise device, where the first request signal is used to initiate a dialogue process; The unified data management module is used to establish the mapping relationship between the terminal information of the customer premise device and the IP address in response to the second request signal.
3. The 5G private network user equipment-level traffic anomaly monitoring system according to claim 2, wherein The unified data management module is further used to send subscription data to the session management function module, where the subscription data includes the IP address; The session management function module is further used to send a packet detection rule flow description protocol value including the IP address to the user plane function module according to the subscription data; The statistics unit of the user plane function module is used to statistically analyze the system traffic data according to the packet detection rule flow description protocol value to obtain the traffic statistics result of each customer premise device.
4. The 5G private network user equipment-level traffic anomaly monitoring system according to claim 3, wherein Specifically, the statistics unit is used for: Statistically analyzing the system traffic data according to the IP address to determine the user traffic data of each customer premise device; Dividing the user traffic data into first traffic data in multiple different transmission directions according to the transmission direction identifier of the packet detection rule flow description protocol value; Performing different service type statistics on the first traffic data in each transmission direction respectively according to the service type identifier of the packet detection rule flow description protocol value to obtain second traffic data of different service types in each transmission direction; Obtaining the traffic statistics result according to the first traffic data and the second traffic data.
5. The 5G private network user equipment-level traffic anomaly monitoring system according to claim 4, characterized in that, Specifically, the anomaly detection unit is used for: Performing time division on the second traffic data based on the time tag of the second traffic data to obtain third traffic data; Statistically analyze the packet loss data of the second traffic data for different service types respectively to obtain a packet loss statistical result; Determine multiple comparison time nodes according to a preset traffic data comparison period; Compare the third traffic data before and after the comparison time node to obtain a comparison result; Judge whether the customer premise equipment is abnormal according to the third traffic data, the packet loss statistical result and the comparison result.
6. The 5G private network user equipment-level traffic anomaly monitoring system according to claim 2, wherein The positioning unit is specifically configured to send the IP address of the customer premise equipment to the unified data management module, so that the unified data management module sends terminal information to the traffic monitoring module according to the mapping relationship; obtain the location information according to the terminal information; The tracking unit is specifically configured to send tracking instructions to the control plane function module and the user plane function module respectively, so that the control plane function module performs signaling tracking according to the user permanent identifier, and the user plane function module performs data tracking according to the user permanent identifier to obtain the abnormal analysis result, where the tracking instruction includes the user permanent identifier.
7. The 5G private network user equipment-level traffic anomaly monitoring system according to claim 1, characterized in that, The system further includes a storage and output module, and the storage and output module includes a display unit and an alarm unit; The display unit is configured to store the user traffic data of all customer premise equipment in a database to obtain a historical traffic database; in response to a traffic display instruction, display each piece of the user traffic data in the historical traffic database through a visualization interface; The alarm unit is configured to generate an alarm message when the customer premise equipment is abnormal; display the alarm message and the abnormal analysis result on the visualization interface.
8. A method for monitoring abnormal traffic at the user equipment level of a 5G private network, characterized in that, Including the following steps: Obtain system traffic data; Statistically analyze the system traffic data according to the IP addresses of multiple different customer premise equipment to obtain a traffic statistical result for each customer premise equipment; Judge whether the customer premise equipment is abnormal according to the traffic statistical result; When the customer premise equipment is abnormal, obtain the terminal information according to the IP address of the customer premise equipment and the mapping relationship between the preset terminal information of the customer premise equipment and the IP address, and determine the location information of the customer premise equipment, where the terminal information includes the location information and the user permanent identifier; Trigger signaling tracking and data tracking according to the user permanent identifier of the terminal information to obtain the abnormal analysis result of the customer premise equipment.
9. An electronic device, characterized in that, Including: At least one processor; At least one memory for storing at least one program; When the at least one program is executed by the at least one processor, the at least one processor implements the 5G private network user equipment-level traffic anomaly monitoring method as claimed in claim 8.
10. A computer-readable storage medium storing a program executable by a processor, characterized in that, The program executable by the processor, when executed by the processor, implements the 5G private network user equipment-level traffic anomaly monitoring method as claimed in claim 8.
Citation Information
Patent Citations
Method for realizing 5G equipment CPE fault alarm real-time reporting based on SLA
CN113573352A
Encrypted traffic detection method, network element, terminal, system, medium and equipment
CN115767451A
Multi-terminal communication system based on Internet of Things
CN119584136A
Sound-Absorbing Foam Panel Comprising a Fabric Layer Composed of Finely Grained Cotton Yarn
KR1020250017048A
Tracking system and method for monitoring and ensuring security of shipments
US20190066042A1